nerdexam
CompTIA

CAS-002 · Question #728

A large hospital has implemented BYOD to allow doctors and specialists the ability to access patient medical records on their tablets. The doctors and specialists access patient records over the…

The correct answer is A. Privacy could be compromised as patient records can be viewed in uncontrolled areas. D. Malware may be on BYOD devices which can extract data via key logging and screen. Despite strong technical controls such as remote desktop access, 2FA, and disabled copy functions, two significant residual risks remain: physical viewing of records in uncontrolled environments and malware on personal devices capturing session data.

Enterprise Security

Question

A large hospital has implemented BYOD to allow doctors and specialists the ability to access patient medical records on their tablets. The doctors and specialists access patient records over the hospital's guest WiFi network which is isolated from the internal network with appropriate security controls. The patient records management system can be accessed from the guest network and requires two factor authentication. Using a remote desktop type interface, the doctors and specialists can interact with the hospital's system. Cut and paste and printing functions are disabled to prevent the copying of data to BYOD devices. Which of the following are of MOST concern? (Select TWO).

Options

  • APrivacy could be compromised as patient records can be viewed in uncontrolled areas.
  • BDevice encryption has not been enabled and will result in a greater likelihood of data loss.
  • CThe guest WiFi may be exploited allowing non-authorized individuals access to confidential
  • DMalware may be on BYOD devices which can extract data via key logging and screen
  • ERemote wiping of devices should be enabled to ensure any lost device is rendered

How the community answered

(26 responses)
  • A
    65% (17)
  • B
    8% (2)
  • C
    4% (1)
  • E
    23% (6)

Why each option

Despite strong technical controls such as remote desktop access, 2FA, and disabled copy functions, two significant residual risks remain: physical viewing of records in uncontrolled environments and malware on personal devices capturing session data.

APrivacy could be compromised as patient records can be viewed in uncontrolled areas.Correct

Personal devices used in public or semi-public locations such as hospital hallways, waiting areas, or off-site settings allow bystanders to view patient records displayed on screen, constituting a privacy breach regardless of the technical access controls in place. This physical exposure risk cannot be mitigated by software controls and directly violates patient confidentiality requirements.

BDevice encryption has not been enabled and will result in a greater likelihood of data loss.

Because the remote desktop interface means patient data is processed and displayed server-side without being downloaded or saved to the BYOD device, device encryption has limited impact on preventing data loss in this specific architecture.

CThe guest WiFi may be exploited allowing non-authorized individuals access to confidential

The scenario explicitly states the guest WiFi is isolated with appropriate security controls and access requires two-factor authentication, making unauthorized network access a less likely residual risk compared to the correct answers.

DMalware may be on BYOD devices which can extract data via key logging and screenCorrect

Malware such as keyloggers or screen capture software on an unmanaged BYOD device can record everything displayed during a remote desktop session, including patient records, exfiltrating sensitive data outside of the platform's controls. This threat bypasses the disabled cut-and-paste and printing restrictions because the data is captured at the device level before those controls can apply.

ERemote wiping of devices should be enabled to ensure any lost device is rendered

Since the remote desktop model prevents patient data from being stored locally on BYOD devices, remote wiping of a lost device would not result in patient data being compromised and is therefore not a primary concern.

Concept tested: BYOD residual risk - physical exposure and endpoint malware threats

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-124r2.pdf

Topics

#BYOD#data privacy#keylogging#mobile device security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice