CAS-002 · Question #90
The increasing complexity of attacks on corporate networks is a direct result of more and more corporate employees connecting to corporate networks with mobile and personal devices. In most cases…
The correct answer is C. Risks: Data exfiltration, loss of data via stolen mobile devices, increased data leakage at the. BYOD and personal device usage on corporate networks introduces real risks including data exfiltration, device theft causing data loss, and expanded attack surfaces, with MDM and policy controls as primary mitigations.
Question
The increasing complexity of attacks on corporate networks is a direct result of more and more corporate employees connecting to corporate networks with mobile and personal devices. In most cases simply banning these connections and devices is not practical because they support necessary business needs. Which of the following are typical risks and mitigations associated with this new trend?
Options
- ARisks: Data leakage, lost data on destroyed mobile devices, smaller network attack surface,
- BRisks: Confidentiality leaks through cell conversations, availability of remote corporate data,
- CRisks: Data exfiltration, loss of data via stolen mobile devices, increased data leakage at the
- DRisks: Theft of mobile devices, unsanctioned applications, minimal device storage, call quality
How the community answered
(18 responses)- B6% (1)
- C83% (15)
- D11% (2)
Why each option
BYOD and personal device usage on corporate networks introduces real risks including data exfiltration, device theft causing data loss, and expanded attack surfaces, with MDM and policy controls as primary mitigations.
This option incorrectly states that BYOD results in a 'smaller network attack surface' - in reality, personal devices significantly expand the attack surface.
Confidentiality leaks through cell conversations and 'availability of remote corporate data' are not primary BYOD security risks in an enterprise context and conflate telephony concerns with network security.
Data exfiltration via personal devices, loss of sensitive corporate data through theft or loss of mobile devices, and increased data leakage at the network perimeter are the core, well-documented risks of BYOD. This option accurately pairs these risks with appropriate mitigations such as MDM policies, remote wipe capability, and data loss prevention controls.
While device theft is a valid risk, 'minimal device storage' and 'call quality' are not security risks and are irrelevant to a corporate network security threat model.
Concept tested: BYOD security risks and mobile device management mitigations
Source: https://csrc.nist.gov/publications/detail/sp/800-124/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.