nerdexam
CompTIA

CAS-003 · Question #317

An organization enables BYOD but wants to allow users to access the corporate email, calendar, and contacts from their devices. The data associated with the user's accounts is sensitive, and…

The correct answer is D. Configure and monitor devices with an MDM. MDM is the only solution listed that can enforce all four stated requirements - full-device encryption, remote wipe, unsigned app blocking, and containerization - across personal BYOD devices from a single management plane.

Technical Integration of Enterprise Security

Question

An organization enables BYOD but wants to allow users to access the corporate email, calendar, and contacts from their devices. The data associated with the user's accounts is sensitive, and therefore, the organization wants to comply with the following requirements:

Active full-device encryption Enabled remote-device wipe Blocking unsigned applications Containerization of email, calendar, and contacts Which of the following technical controls would BEST protect the data from attack or loss and meet the above requirements?

Options

  • ARequire frequent password changes and disable NFC.
  • BEnforce device encryption and activate MAM.
  • CInstall a mobile antivirus application.
  • DConfigure and monitor devices with an MDM.

How the community answered

(25 responses)
  • A
    12% (3)
  • B
    4% (1)
  • D
    84% (21)

Why each option

MDM is the only solution listed that can enforce all four stated requirements - full-device encryption, remote wipe, unsigned app blocking, and containerization - across personal BYOD devices from a single management plane.

ARequire frequent password changes and disable NFC.

Frequent password changes and disabling NFC are minor hardening measures that do not enforce encryption, provide remote wipe, block unsigned apps, or enable containerization of corporate data.

BEnforce device encryption and activate MAM.

Enforcing device encryption combined with MAM (Mobile Application Management) addresses app-level sandboxing but MAM alone does not provide full-device remote wipe or enforce OS-level full-device encryption the way MDM does.

CInstall a mobile antivirus application.

A mobile antivirus application detects and removes malware but cannot enforce encryption, execute remote wipe, block unsigned applications, or provide containerization of corporate accounts.

DConfigure and monitor devices with an MDM.Correct

An MDM (Mobile Device Management) solution enforces full-device encryption at the OS level, enables remote wipe of enrolled devices, restricts installation of unsigned or unapproved applications through policy, and deploys containerized profiles for corporate email, calendar, and contacts - satisfying all four requirements in a unified, auditable platform.

Concept tested: MDM enforcement of BYOD full-device security policy

Source: https://learn.microsoft.com/en-us/mem/intune/enrollment/device-enrollment

Topics

#BYOD#MDM#mobile device management#data containerization

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice