nerdexam
CompTIA

CAS-003 · Question #385

A security consultant is improving the physical security of a sensitive site and takes pictures of the unbranded building to include m the report Two weeks later, the security consultant misplaces…

The correct answer is C. MicroSD is nor encrypted and contains geotagging information. The two critical security failures here are that the MicroSD card was unencrypted (allowing anyone who removes it to read all data immediately) and that the photos contain EXIF geotag data revealing the precise physical location - '3500 Lacey Road USA' - of what was…

Risk Management

Question

A security consultant is improving the physical security of a sensitive site and takes pictures of the unbranded building to include m the report Two weeks later, the security consultant misplaces the phone. which only has one hour of charge left on it. The person who finds the phone removes the MicroSD card in an attempt to discover Me owner to return it. The person extracts the following data from the phone and EXIF data Irons some files. DCIM Images folder Audio books folder Torrents My TAN xls Consultancy HR Manual doc Camera SM-G950F Exposure time 1/60 s Location 3500 Lacey Road USA Which of the following BEST describes the security problem?

Options

  • AMicroSD is not encrypted and also contains personal data
  • BMicroSD contains a Mixture of personal and work data
  • CMicroSD is nor encrypted and contains geotagging information
  • DMicroSD contains pirated software and Is not encrypted

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    10% (3)
  • C
    58% (18)
  • D
    26% (8)

Explanation

The two critical security failures here are that the MicroSD card was unencrypted (allowing anyone who removes it to read all data immediately) and that the photos contain EXIF geotag data revealing the precise physical location - '3500 Lacey Road USA' - of what was intentionally photographed as an 'unbranded building,' meaning a sensitive, undisclosed site. Publishing this location in a security report or having it exposed on a lost device defeats the entire purpose of the site being unbranded and undisclosed, representing a serious operational security (OPSEC) breach. While the card also contains personal data (A) and mixed personal/work data (B), those are secondary concerns. The torrents folder (D) does not necessarily indicate pirated software, making that option speculative and not the primary security issue.

Topics

#mobile security#data encryption#geotagging#EXIF metadata

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice