nerdexam
CompTIA

CAS-002 · Question #104

In order to reduce cost and improve employee satisfaction, a large corporation has decided to allow personal communication devices to access email and to remotely connect to the corporate network…

The correct answer is A. A device lockdown according to policies E. Encrypt data in transit for remote access. Allowing personal devices to access corporate resources requires enforcing minimum security configurations on those devices and encrypting all data transmitted over untrusted networks.

Enterprise Security

Question

In order to reduce cost and improve employee satisfaction, a large corporation has decided to allow personal communication devices to access email and to remotely connect to the corporate network. Which of the following security measures should the IT organization implement? (Select TWO).

Options

  • AA device lockdown according to policies
  • BAn IDS on the internal networks
  • CA data disclosure policy
  • DA privacy policy
  • EEncrypt data in transit for remote access

How the community answered

(32 responses)
  • A
    78% (25)
  • B
    3% (1)
  • C
    13% (4)
  • D
    6% (2)

Why each option

Allowing personal devices to access corporate resources requires enforcing minimum security configurations on those devices and encrypting all data transmitted over untrusted networks.

AA device lockdown according to policiesCorrect

Device lockdown policies enforce baseline security requirements such as screen lock, OS patching, and approved applications on personal devices, preventing unmanaged endpoints from becoming a direct attack vector into corporate resources.

BAn IDS on the internal networks

An IDS monitors internal network traffic for anomalies but does not directly control or secure personal devices connecting from outside the corporate perimeter.

CA data disclosure policy

A data disclosure policy is an administrative governance document that defines rules for sharing data but does not provide any technical protection for remote sessions or devices.

DA privacy policy

A privacy policy governs how the organization handles personal data and has no bearing on the technical security of remote device access.

EEncrypt data in transit for remote accessCorrect

Encrypting data in transit for remote access via VPN or TLS ensures that corporate data cannot be intercepted or read as it traverses the untrusted public networks used by personal devices.

Concept tested: BYOD security controls - device lockdown policy and remote access encryption

Source: https://csrc.nist.gov/publications/detail/sp/800-124/rev-2/final

Topics

#BYOD#device lockdown#remote access#data encryption in transit

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice