nerdexam
CompTIA

CAS-003 · Question #589

A government contracting company issues smartphones to employees to enable access to corporate resources. Several employees will need to travel to a foreign country for business purposes and will…

The correct answer is B. Disable location services. Disabling location services via MDM prevents foreign intelligence services from tracking employees' physical movements and locations while in a hostile country.

Risk Management

Question

A government contracting company issues smartphones to employees to enable access to corporate resources. Several employees will need to travel to a foreign country for business purposes and will require access to their phones. However, the company recently received intelligence that its intellectual property is highly desired by the same country's government. Which of the following MDM configurations would BEST reduce the risk of compromise while on foreign soil?

Options

  • ADisable firmware OTA updates.
  • BDisable location services.
  • CDisable push notification services.
  • DDisable wipe

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    74% (34)
  • C
    15% (7)
  • D
    9% (4)

Why each option

Disabling location services via MDM prevents foreign intelligence services from tracking employees' physical movements and locations while in a hostile country.

ADisable firmware OTA updates.

Disabling OTA firmware updates prevents security patches from being applied, which increases the device's vulnerability to known exploits rather than reducing risk.

BDisable location services.Correct

Disabling location services prevents the device from collecting or broadcasting GPS and network-based location data, which a nation-state adversary could intercept, correlate, or use to target employees for surveillance or device seizure. Given the specific intelligence about foreign government interest in the company's IP, physical location tracking is a direct operational security risk. MDM policy can enforce this setting on managed devices before travel begins.

CDisable push notification services.

Disabling push notifications marginally reduces information leakage but does not address the primary threat of physical tracking and surveillance by a foreign government actor.

DDisable wipe

Disabling wipe removes the ability to remotely erase the device if it is lost or confiscated, which substantially increases the risk of data compromise.

Concept tested: MDM policy configuration for international travel risk reduction

Source: https://learn.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started

Topics

#MDM#international travel risk#location services#mobile threat defense

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice