nerdexam
CompTIA

CAS-001 · Question #504

A corporation implements a mobile device policy on smartphones that utilizes a white list for allowed applications. Recently, the security administrator notices that a consumer cloud based storage…

The correct answer is B. Smartphones can export sensitive data or import harmful data with this application causing the. Allowing a consumer cloud storage application on a corporate device creates a bidirectional data risk where sensitive corporate data can be silently exfiltrated to an uncontrolled cloud environment and malicious files can be introduced into the device.

Enterprise Security

Question

A corporation implements a mobile device policy on smartphones that utilizes a white list for allowed applications. Recently, the security administrator notices that a consumer cloud based storage application has been added to the mobile device white list. Which of the following security implications should the security administrator cite when recommending the application's removal from the white list?

Options

  • AConsumer cloud storage systems retain local copies of each file on the smartphone, as well as in
  • BSmartphones can export sensitive data or import harmful data with this application causing the
  • CConsumer cloud storage systems could allow users to download applications to the smartphone.
  • DSmartphones using consumer cloud storage are more likely to have sensitive data remnants on

How the community answered

(46 responses)
  • A
    11% (5)
  • B
    83% (38)
  • C
    4% (2)
  • D
    2% (1)

Why each option

Allowing a consumer cloud storage application on a corporate device creates a bidirectional data risk where sensitive corporate data can be silently exfiltrated to an uncontrolled cloud environment and malicious files can be introduced into the device.

AConsumer cloud storage systems retain local copies of each file on the smartphone, as well as in

Consumer cloud storage applications do not specifically retain extra local copies of files beyond what the OS manages; the primary concern is cloud-side storage of corporate data, not local duplication.

BSmartphones can export sensitive data or import harmful data with this application causing theCorrect

Consumer cloud storage applications automatically sync device contents to third-party cloud infrastructure outside corporate control, meaning sensitive corporate data can be exported without user intent. The same sync mechanism allows harmful or malware-laden files to be imported back to the device from the cloud, creating both a data loss and a malware ingestion vector.

CConsumer cloud storage systems could allow users to download applications to the smartphone.

Cloud storage applications provide file sync functionality, not an application installation channel; they cannot bypass the device whitelist to install unauthorized applications.

DSmartphones using consumer cloud storage are more likely to have sensitive data remnants on

Data remnants are a concern during device disposal or reuse, but the active, ongoing security implication of running a cloud storage app is the live export and import of data, not residual data artifacts.

Concept tested: Mobile data leakage risk from consumer cloud apps

Source: https://csrc.nist.gov/publications/detail/sp/800-124/rev-2/final

Topics

#mobile device management#cloud storage risk#data exfiltration#application whitelist

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice