CAS-002 · Question #189
An organization determined that each of its remote sales representatives must use a smartphone for email access. The organization provides the same centrally manageable model to each person. Which…
The correct answer is D. Require a PIN and automatic wiping of the smartphone if someone enters a specific number. A PIN combined with automatic device wiping after a fixed number of failed attempts provides the strongest protection for data resident on a smartphone that could be lost or stolen.
Question
An organization determined that each of its remote sales representatives must use a smartphone for email access. The organization provides the same centrally manageable model to each person. Which of the following mechanisms BEST protects the confidentiality of the resident data?
Options
- ARequire dual factor authentication when connecting to the organization's email server.
- BRequire each sales representative to establish a PIN to access the smartphone and limit
- CRequire encrypted communications when connecting to the organization's email server.
- DRequire a PIN and automatic wiping of the smartphone if someone enters a specific number
How the community answered
(50 responses)- A2% (1)
- B4% (2)
- C2% (1)
- D92% (46)
Why each option
A PIN combined with automatic device wiping after a fixed number of failed attempts provides the strongest protection for data resident on a smartphone that could be lost or stolen.
Dual-factor authentication secures the connection to the email server but does not protect data already downloaded and stored locally on the device if it falls into unauthorized hands.
A PIN alone without an automatic wipe policy allows unlimited or excessive guessing attempts, making resident data accessible given enough time and persistence.
Encrypted communications protect data in transit between the smartphone and the email server but do not protect data that has already been received and is stored at rest on the device.
Requiring a PIN enforces access control on the physical device, and automatic wiping after a specific number of incorrect attempts ensures that resident data is destroyed before an attacker can exhaust all PIN combinations through brute force. Together these controls protect confidentiality of locally stored data regardless of whether the attacker has physical possession of the device, which is the primary threat for mobile devices.
Concept tested: Mobile device PIN and automatic wipe for resident data protection
Source: https://csrc.nist.gov/publications/detail/sp/800-124/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.