nerdexam
CompTIA

CAS-003 · Question #559

A company recently implemented a new cloud storage solution and installed the required synchronization client on all company devices. A few months later, a breach of sensitive data was discovered…

The correct answer is A. Biometric authentication. The breach originated from a lost personal mobile device that had the cloud synchronization client installed. Biometric authentication (fingerprint, face recognition) ties device access to the physical owner, meaning a person who finds or steals the device cannot unlock it and…

Risk Management

Question

A company recently implemented a new cloud storage solution and installed the required synchronization client on all company devices. A few months later, a breach of sensitive data was discovered. Root cause analysis shows the data breach happened from a lost personal mobile device. Which of the following controls can the organization implement to reduce the risk of similar breaches?

Options

  • ABiometric authentication
  • BCloud storage encryption
  • CApplication containerization
  • DHardware anti-tamper

How the community answered

(44 responses)
  • A
    82% (36)
  • B
    2% (1)
  • C
    11% (5)
  • D
    5% (2)

Explanation

The breach originated from a lost personal mobile device that had the cloud synchronization client installed. Biometric authentication (fingerprint, face recognition) ties device access to the physical owner, meaning a person who finds or steals the device cannot unlock it and access the synced sensitive data. This directly mitigates the root cause-unauthorized access to a lost device. Cloud storage encryption (B) likely already existed and did not prevent the breach. Application containerization (C) separates corporate from personal data but does not block access once the device is unlocked. Hardware anti-tamper (D) addresses physical disassembly of hardware, not the scenario of a lost, functioning device being accessed by an unauthorized user.

Topics

#mobile device security#cloud storage#biometric authentication#data breach

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice