CAS-002 · Question #574
A security manager at Company ABC, needs to perform a risk assessment of a new mobile device which the Chief Information Officer (CIO) wants to immediately deploy to all employees in the company…
The correct answer is A. Ability to remotely wipe the devices, apply security controls remotely, and encrypt the SSD. When assessing mobile device risk, security managers must focus on MDM capabilities like remote wipe, remote policy enforcement, and storage encryption to protect corporate data.
Question
A security manager at Company ABC, needs to perform a risk assessment of a new mobile device which the Chief Information Officer (CIO) wants to immediately deploy to all employees in the company. The product is commercially available, runs a popular mobile operating system, and can connect to IPv6 networks wirelessly. The model the CIO wants to procure also includes the upgraded 160GB solid state hard drive. The producer of the device will not reveal exact numbers but experts estimate that over 73 million of the devices have been sold worldwide. Which of the following is the BEST list of factors the security manager should consider while performing a risk assessment?
Options
- AAbility to remotely wipe the devices, apply security controls remotely, and encrypt the SSD;
- BAbility to remotely administer the devices, apply security controls remotely, and remove the
- CAbility to remotely monitor the devices, remove security controls remotely, and decrypt the
- DAbility to remotely sanitize the devices, apply security controls locally, encrypt the SSD;
How the community answered
(36 responses)- A67% (24)
- B8% (3)
- C19% (7)
- D6% (2)
Why each option
When assessing mobile device risk, security managers must focus on MDM capabilities like remote wipe, remote policy enforcement, and storage encryption to protect corporate data.
Remote wipe allows administrators to erase sensitive data if a device is lost or stolen, remote security control application enforces policies without physical access, and SSD encryption ensures data is unreadable if the device is physically compromised. These three controls together form the core of a mobile device management (MDM) security posture.
The option references removing security controls remotely, which is the opposite of the desired outcome - security controls should be applied, not removed.
Decrypting the SSD and removing security controls remotely would actively weaken device security rather than protect it, making this the least appropriate option.
Applying security controls only locally defeats the purpose of managing a fleet of mobile devices, as remote policy enforcement is essential when employees carry devices off-premises.
Concept tested: Mobile device management security controls and risk assessment
Source: https://learn.microsoft.com/en-us/mem/intune/protect/device-protect
Topics
Community Discussion
No community discussion yet for this question.