nerdexam
CompTIA

CAS-002 · Question #191

A health service provider is considering the impact of allowing doctors and nurses access to the internal email system from their personal smartphones. The Information Security Officer (ISO) has…

The correct answer is B. Compliance may not be supported by all smartphones. C. Equipment loss, theft, and data leakage. F. Not all smartphones natively support encryption. Allowing personal smartphones to access health data raises compliance gaps, data protection risks, and encryption inconsistencies that the ISO must prioritize.

Enterprise Security

Question

A health service provider is considering the impact of allowing doctors and nurses access to the internal email system from their personal smartphones. The Information Security Officer (ISO) has received a technical document from the security administrator explaining that the current email system is capable of enforcing security policies to personal smartphones, including screen lockout and mandatory PINs. Additionally, the system is able to remotely wipe a phone if reported lost or stolen. Which of the following should the Information Security Officer be MOST concerned with based on this scenario? (Select THREE).

Options

  • AThe email system may become unavailable due to overload.
  • BCompliance may not be supported by all smartphones.
  • CEquipment loss, theft, and data leakage.
  • DSmartphone radios can interfere with health equipment.
  • EData usage cost could significantly increase.
  • FNot all smartphones natively support encryption.
  • GSmartphones may be used as rogue access points.

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    83% (30)
  • E
    8% (3)
  • G
    3% (1)

Why each option

Allowing personal smartphones to access health data raises compliance gaps, data protection risks, and encryption inconsistencies that the ISO must prioritize.

AThe email system may become unavailable due to overload.

Email system overload is an operational availability concern, not an information security issue, and is lower priority than data confidentiality risks in a healthcare context.

BCompliance may not be supported by all smartphones.Correct

Personal smartphones vary widely in OS and hardware capabilities, meaning some devices will not support the MDM security policies (PIN enforcement, screen lock, remote wipe) described, creating uncontrollable compliance gaps.

CEquipment loss, theft, and data leakage.Correct

Health data on personal devices significantly increases the risk of data leakage and makes sensitive information harder to control if a device is lost or stolen, even with remote wipe capabilities.

DSmartphone radios can interfere with health equipment.

Radio frequency interference is a physical patient safety concern regulated separately from information security and is not within the ISO's information security purview.

EData usage cost could significantly increase.

Increased data usage costs are a financial and operational concern, not an information security risk.

FNot all smartphones natively support encryption.Correct

Not all smartphone platforms and older devices natively support data-at-rest encryption, leaving health data potentially unprotected even when the email system enforces other policies.

GSmartphones may be used as rogue access points.

While rogue access points are a valid security concern, they are not directly tied to the email access scenario described and are less probable than the selected concerns.

Concept tested: BYOD security risks in regulated healthcare environments

Source: https://csrc.nist.gov/publications/detail/sp/800-124/rev-2/final

Topics

#BYOD#mobile device policy#data leakage#encryption compliance

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice