nerdexam
CompTIA

CAS-002 · Question #133

The Chief Information Officer (CIO) of a technology company is likely to move away from a de- perimeterized model for employee owned devices. This is because there were too many issues with lack of…

The correct answer is B. Update the policy to disallow non-company end-point devices on the corporate network. The documented BYOD failures - unpatched devices, malware incidents, and unencrypted lost devices - are best resolved by prohibiting non-company endpoint devices from the corporate network.

Enterprise Security

Question

The Chief Information Officer (CIO) of a technology company is likely to move away from a de- perimeterized model for employee owned devices. This is because there were too many issues with lack of patching, malware incidents, and data leakage due to lost/stolen devices which did not have full-disk encryption. The `bring your own computing' approach was originally introduced because different business units preferred different operating systems and application stacks. Based on the issues and user needs, which of the following is the BEST recommendation for the CIO to make?

Options

  • AThe de-perimeterized model should be kept as this is major industry trend and other
  • BUpdate the policy to disallow non-company end-point devices on the corporate network.
  • CThe de-perimeterized model should be kept but update company policies to state that non-
  • DUpdate the policy to disallow non-company end-point devices on the corporate network.

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    83% (33)
  • C
    10% (4)
  • D
    5% (2)

Why each option

The documented BYOD failures - unpatched devices, malware incidents, and unencrypted lost devices - are best resolved by prohibiting non-company endpoint devices from the corporate network.

AThe de-perimeterized model should be kept as this is major industry trend and other

Continuing the de-perimeterized model because it is an industry trend ignores documented security failures that are actively causing harm to the organization.

BUpdate the policy to disallow non-company end-point devices on the corporate network.Correct

Prohibiting non-company endpoint devices directly removes the root cause of all three identified problems: uncontrolled patching, inconsistent security configurations, and the absence of mandatory full-disk encryption. Company-owned devices can be standardized, enforced with security baselines, and fully managed by IT, resolving all documented risk areas while still accommodating varied OS and application requirements through corporate device management policies.

CThe de-perimeterized model should be kept but update company policies to state that non-

Updating policy without technical enforcement does not prevent users from connecting unpatched or unencrypted personal devices - the same underlying vulnerabilities remain present.

DUpdate the policy to disallow non-company end-point devices on the corporate network.

This option also references disallowing non-company devices but includes additional provisions that do not directly resolve the core endpoint security control gaps identified.

Concept tested: BYOD policy and managed endpoint security control enforcement

Source: https://csrc.nist.gov/publications/detail/sp/800-124/rev-2/final

Topics

#BYOD#endpoint security#de-perimeterization#mobile device management

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice