nerdexam
CompTIA

CAS-002 · Question #631

A corporate executive lost their smartphone while on an overseas business trip. The phone was equipped with file encryption and secured with a strong passphrase. The phone contained over 60GB of…

The correct answer is B. Immediately implement a plan to remotely wipe all data from the device. When a device with sensitive corporate data is lost, remote wipe is the highest-priority response to eliminate data exposure risk, regardless of encryption status.

Enterprise Security

Question

A corporate executive lost their smartphone while on an overseas business trip. The phone was equipped with file encryption and secured with a strong passphrase. The phone contained over 60GB of proprietary data. Given this scenario, which of the following is the BEST course of action?

Options

  • AFile an insurance claim and assure the executive the data is secure because it is encrypted.
  • BImmediately implement a plan to remotely wipe all data from the device.
  • CHave the executive change all passwords and issue the executive a new phone.
  • DExecute a plan to remotely disable the device and report the loss to the police.

How the community answered

(55 responses)
  • A
    2% (1)
  • B
    89% (49)
  • C
    2% (1)
  • D
    7% (4)

Why each option

When a device with sensitive corporate data is lost, remote wipe is the highest-priority response to eliminate data exposure risk, regardless of encryption status.

AFile an insurance claim and assure the executive the data is secure because it is encrypted.

Filing an insurance claim does not eliminate the risk; encryption alone is not sufficient assurance because strong passphrases can still be compromised given enough time and resources.

BImmediately implement a plan to remotely wipe all data from the device.Correct

Remotely wiping the device is the best course of action because encryption, while strong, is not an absolute guarantee - passphrases can be brute-forced or vulnerabilities discovered over time. A remote wipe eliminates the data entirely, removing any future risk. Delaying this action while pursuing other steps leaves 60GB of proprietary data unnecessarily at risk.

CHave the executive change all passwords and issue the executive a new phone.

Changing passwords and issuing a new phone addresses access credential risk but does not remove the proprietary data already stored on the lost device.

DExecute a plan to remotely disable the device and report the loss to the police.

Remotely disabling the device prevents further use but does not destroy the data, which can still be extracted from a physically disabled device using forensic tools.

Concept tested: Mobile device management remote wipe policy

Source: https://learn.microsoft.com/en-us/mem/intune/remote-actions/devices-wipe

Topics

#MDM#remote wipe#lost device#mobile data protection

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice