nerdexam
CompTIA

CAS-003 · Question #363

A company has created a policy to allow employees to use their personally owned devices. The Chief Information Officer (CISO) is getting reports of company data appearing on unapproved forums and an…

The correct answer is A. Disk encryption on the local drive. In a BYOD environment with increased device theft, disk encryption directly protects locally stored company data from being accessed if a device falls into the wrong hands.

Risk Management

Question

A company has created a policy to allow employees to use their personally owned devices. The Chief Information Officer (CISO) is getting reports of company data appearing on unapproved forums and an increase in theft of personal electronic devices. Which of the following security controls would BEST reduce the risk of exposure?

Options

  • ADisk encryption on the local drive
  • BGroup policy to enforce failed login lockout
  • CMultifactor authentication
  • DImplementation of email digital signatures

How the community answered

(33 responses)
  • A
    73% (24)
  • B
    3% (1)
  • C
    6% (2)
  • D
    18% (6)

Why each option

In a BYOD environment with increased device theft, disk encryption directly protects locally stored company data from being accessed if a device falls into the wrong hands.

ADisk encryption on the local driveCorrect

Full disk encryption ensures that even if a personally owned device is stolen, the data on the local drive cannot be accessed without the correct encryption key or credentials. This control directly addresses both reported threats - data appearing on unapproved forums via stolen devices and the rise in physical device theft. It is the most targeted control because it protects data at rest regardless of whether the device's OS is bypassed.

BGroup policy to enforce failed login lockout

Failed login lockout mitigates brute-force OS login attempts but does not protect data if an attacker removes the drive and reads it directly on another system.

CMultifactor authentication

MFA strengthens user authentication but offers no protection for locally stored data once a device is physically stolen and the drive is accessed outside the operating system.

DImplementation of email digital signatures

Email digital signatures verify sender identity and message integrity in transit but have no effect on data stored locally on a device.

Concept tested: BYOD data protection via full disk encryption

Source: https://csrc.nist.gov/publications/detail/sp/800-114/rev-1/final

Topics

#BYOD security#disk encryption#data protection#mobile device management

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice