nerdexam
CompTIA

CAS-002 · Question #189

An organization determined that each of its remote sales representatives must use a smartphone for email access. The organization provides the same centrally manageable model to each person. Which…

The correct answer is D. Require a PIN and automatic wiping of the smartphone if someone enters a specific number. A PIN combined with automatic device wiping after a fixed number of failed attempts provides the strongest protection for data resident on a smartphone that could be lost or stolen.

Enterprise Security

Question

An organization determined that each of its remote sales representatives must use a smartphone for email access. The organization provides the same centrally manageable model to each person. Which of the following mechanisms BEST protects the confidentiality of the resident data?

Options

  • ARequire dual factor authentication when connecting to the organization's email server.
  • BRequire each sales representative to establish a PIN to access the smartphone and limit
  • CRequire encrypted communications when connecting to the organization's email server.
  • DRequire a PIN and automatic wiping of the smartphone if someone enters a specific number

How the community answered

(50 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    2% (1)
  • D
    92% (46)

Why each option

A PIN combined with automatic device wiping after a fixed number of failed attempts provides the strongest protection for data resident on a smartphone that could be lost or stolen.

ARequire dual factor authentication when connecting to the organization's email server.

Dual-factor authentication secures the connection to the email server but does not protect data already downloaded and stored locally on the device if it falls into unauthorized hands.

BRequire each sales representative to establish a PIN to access the smartphone and limit

A PIN alone without an automatic wipe policy allows unlimited or excessive guessing attempts, making resident data accessible given enough time and persistence.

CRequire encrypted communications when connecting to the organization's email server.

Encrypted communications protect data in transit between the smartphone and the email server but do not protect data that has already been received and is stored at rest on the device.

DRequire a PIN and automatic wiping of the smartphone if someone enters a specific numberCorrect

Requiring a PIN enforces access control on the physical device, and automatic wiping after a specific number of incorrect attempts ensures that resident data is destroyed before an attacker can exhaust all PIN combinations through brute force. Together these controls protect confidentiality of locally stored data regardless of whether the attacker has physical possession of the device, which is the primary threat for mobile devices.

Concept tested: Mobile device PIN and automatic wipe for resident data protection

Source: https://csrc.nist.gov/publications/detail/sp/800-124/rev-2/final

Topics

#mobile device management#remote wipe#PIN policy#data confidentiality

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice