nerdexam
CompTIA

CAS-002 · Question #581

The Chief Executive Officer (CEO) of a corporation purchased the latest mobile device and wants to connect it to the company's internal network. The Chief Information Security Officer (CISO) was…

The correct answer is C. Encryption of the non-volatile memory and a password or PIN to access the device. Securing a mobile device on a corporate network requires both technical access control and data-at-rest protection. Encrypting non-volatile memory combined with a password or PIN directly addresses the two primary hardware-level risks of a mobile device.

Enterprise Security

Question

The Chief Executive Officer (CEO) of a corporation purchased the latest mobile device and wants to connect it to the company's internal network. The Chief Information Security Officer (CISO) was told to research and recommend how to secure this device. Which of the following recommendations should be implemented to keep the device from posing a security risk to the company?

Options

  • AA corporate policy to prevent sensitive information from residing on a mobile device and
  • BEncryption of the non-volatile memory and a corporate policy to prevent sensitive information
  • CEncryption of the non-volatile memory and a password or PIN to access the device.
  • DA password or PIN to access the device and a corporate policy to prevent sensitive

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    75% (15)
  • D
    15% (3)

Why each option

Securing a mobile device on a corporate network requires both technical access control and data-at-rest protection. Encrypting non-volatile memory combined with a password or PIN directly addresses the two primary hardware-level risks of a mobile device.

AA corporate policy to prevent sensitive information from residing on a mobile device and

A corporate policy is an administrative control that relies entirely on user compliance and provides no technical enforcement or protection if the device is physically accessed by an unauthorized party.

BEncryption of the non-volatile memory and a corporate policy to prevent sensitive information

Encryption and a corporate policy address data storage and acceptable use but omit the access control layer - a password or PIN - that prevents an unauthorized person from unlocking and actively using the device.

CEncryption of the non-volatile memory and a password or PIN to access the device.Correct

Encrypting the non-volatile memory ensures all stored data is cryptographically protected if the device is lost or stolen, while requiring a password or PIN enforces access control that prevents unauthorized users from unlocking the device - together these two technical controls address both unauthorized access and data exposure without relying on user policy compliance.

DA password or PIN to access the device and a corporate policy to prevent sensitive

A password or PIN combined with a policy addresses access control and usage guidelines but leaves stored data unencrypted, meaning it can be recovered by forensic tools if the device is seized or compromised.

Concept tested: Mobile device security - encryption and authentication controls

Source: https://csrc.nist.gov/publications/detail/sp/800-124/rev-2/final

Topics

#mobile device security#encryption#PIN authentication#BYOD

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice