nerdexam
CompTIA

CAS-002 · Question #635

The Chief Executive Officer (CEO) of a corporation purchased the latest mobile device and wants to connect it to the internal network. The Chief Information Security Officer (CISO) was told to…

The correct answer is A. Mitigate and Transfer. This question tests risk response strategy selection when a required business activity introduces security risk. Since the CEO mandates the access, avoidance is not an option.

Enterprise Security

Question

The Chief Executive Officer (CEO) of a corporation purchased the latest mobile device and wants to connect it to the internal network. The Chief Information Security Officer (CISO) was told to research and recommend how to secure this device. Which of the following should be implemented, keeping in mind that the CEO has stated that this access is required?

Options

  • AMitigate and Transfer
  • BAccept and Transfer
  • CTransfer and Avoid
  • DAvoid and Mitigate

How the community answered

(53 responses)
  • A
    74% (39)
  • B
    4% (2)
  • C
    9% (5)
  • D
    13% (7)

Why each option

This question tests risk response strategy selection when a required business activity introduces security risk. Since the CEO mandates the access, avoidance is not an option.

AMitigate and TransferCorrect

Mitigate involves implementing security controls such as MDM, containerization, or device enrollment policies to reduce the risk posed by the unmanaged mobile device. Transfer shifts the residual risk to a third party, such as through cyber insurance. Together these two strategies address the risk without blocking the CEO's required access.

BAccept and Transfer

Accept means acknowledging the risk without taking action to reduce it, which is inappropriate when technical controls can and should be applied to a high-profile executive device.

CTransfer and Avoid

Transfer alone is insufficient without mitigation controls, and Avoid means eliminating the activity entirely, which directly contradicts the CEO's stated requirement for access.

DAvoid and Mitigate

Avoid is not viable because the CEO has mandated the access, making it impossible to eliminate the risk by refusing the connection.

Concept tested: Risk response strategies - mitigate and transfer

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#risk management#mobile security#BYOD#risk treatment

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice