CAS-002 · Question #227
A corporation implements a mobile device policy on smartphones that utilizes a white list for allowed applications. Recently, the security administrator notices that a consumer cloud based storage…
The correct answer is B. Smartphones can export sensitive data or import harmful data with this application causing. Consumer cloud storage apps on corporate mobile devices create a bidirectional risk - corporate data can be exfiltrated to uncontrolled cloud servers, and malicious files can be imported back onto the device.
Question
A corporation implements a mobile device policy on smartphones that utilizes a white list for allowed applications. Recently, the security administrator notices that a consumer cloud based storage application has been added to the mobile device white list. Which of the following security implications should the security administrator cite when recommending the application's removal from the white list?
Options
- AConsumer cloud storage systems retain local copies of each file on the smartphone, as well
- BSmartphones can export sensitive data or import harmful data with this application causing
- CConsumer cloud storage systems could allow users to download applications to the
- DSmartphones using consumer cloud storage are more likely to have sensitive data remnants
How the community answered
(52 responses)- A4% (2)
- B75% (39)
- C8% (4)
- D13% (7)
Why each option
Consumer cloud storage apps on corporate mobile devices create a bidirectional risk - corporate data can be exfiltrated to uncontrolled cloud servers, and malicious files can be imported back onto the device.
Consumer cloud storage is designed to sync files to the cloud provider's servers, not to maintain additional local copies on the device - the primary risk is the external cloud exposure, not local storage accumulation.
Consumer cloud storage applications sync files between the device and external servers outside corporate control, providing an easy path for users to intentionally or accidentally upload sensitive corporate data (exfiltration) and to download harmful or untrusted files from shared cloud storage back onto the corporate device (malware introduction), making this a DLP and malware risk simultaneously.
Cloud storage apps provide file synchronization functionality, not application installation - downloading executables or apps is the function of app stores, not cloud storage clients.
Data remnants on the device after deprovisioning are a concern but represent a lesser and less immediate risk than the active, ongoing exfiltration and import threat that cloud storage creates while the device is in use.
Concept tested: Mobile BYOD data exfiltration risk via consumer cloud storage
Source: https://csrc.nist.gov/publications/detail/sp/800-124/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.