nerdexam
CompTIA

CAS-001 · Question #523

In order to reduce costs and improve employee satisfaction, a large corporation is creating a BYOD policy. It will allow access to email and remote connections to the corporate enterprise from…

The correct answer is B. Encrypt data in transit for remote access. D. Implement NAC to limit insecure devices access. With BYOD, the enterprise cannot fully control personal devices, so the focus shifts to protecting the data and the network perimeter. Encrypting data in transit (B) ensures that even if a personal device is on an untrusted network, the data flowing between it and the corporate…

Enterprise Security

Question

In order to reduce costs and improve employee satisfaction, a large corporation is creating a BYOD policy. It will allow access to email and remote connections to the corporate enterprise from personal devices; provided they are on an approved device list. Which of the following security measures would be MOST effective in securing the enterprise under the new policy? (Select TWO).

Options

  • AProvide free email software for personal devices.
  • BEncrypt data in transit for remote access.
  • CRequire smart card authentication for all devices
  • DImplement NAC to limit insecure devices access.
  • EEnable time of day restrictions for personal devices.

How the community answered

(65 responses)
  • A
    3% (2)
  • B
    78% (51)
  • C
    12% (8)
  • E
    6% (4)

Explanation

With BYOD, the enterprise cannot fully control personal devices, so the focus shifts to protecting the data and the network perimeter. Encrypting data in transit (B) ensures that even if a personal device is on an untrusted network, the data flowing between it and the corporate systems cannot be intercepted. Network Access Control (NAC) (D) evaluates devices against a security policy before granting network access - blocking or quarantining devices that don't meet minimum security standards (e.g., no antivirus, outdated OS). Free email software (A) doesn't address security. Smart card authentication (C) is difficult to deploy on arbitrary personal devices and impractical for BYOD. Time-of-day restrictions (E) are a minor control that does not address the core security risks of unmanaged personal devices.

Topics

#BYOD#NAC#data encryption#mobile device security

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice