CAS-003 · Question #838
A corporation with a BYOD policy is very concerned about issues that may arise from data ownership. The corporation is investigating a new MDM solution and has gathered the following requirements as…
The correct answer is A. Application-based containerization C. Geofencing. An MDM solution for a BYOD environment must include application containerization for selective corporate data wipe and geofencing for location-based access control to meet the stated requirements.
Question
A corporation with a BYOD policy is very concerned about issues that may arise from data ownership. The corporation is investigating a new MDM solution and has gathered the following requirements as part of the requirements-gathering phase:
Each device must be issued a secure token of trust from the corporate PKI. All corporate applications and local data must be able to be deleted from a central console. Access to corporate data must be restricted on international travel. Devices must be on the latest OS version within three weeks of an OS release. Which of the following should be features in the new MDM solution to meet these requirements? (Choose two.)
Options
- AApplication-based containerization
- BEnforced full-device encryption
- CGeofencing
- DApplication allow listing
- EBiometric requirement to unlock device
- FOver-the-air update restriction
How the community answered
(35 responses)- A71% (25)
- B9% (3)
- D14% (5)
- E3% (1)
- F3% (1)
Why each option
An MDM solution for a BYOD environment must include application containerization for selective corporate data wipe and geofencing for location-based access control to meet the stated requirements.
Application-based containerization isolates corporate apps and data into a separate, managed partition on the personal device. This enables MDM administrators to remotely wipe only the corporate container from a central console without touching personal data, directly satisfying the requirement to delete all corporate applications and local data centrally.
Full-device encryption protects data at rest from unauthorized physical access but does not address the requirements for remote selective deletion, travel-based access restriction, or OS update enforcement.
Geofencing applies location-aware conditional access policies that automatically restrict or block access to corporate resources when a device is detected outside a defined geographic boundary. This directly meets the requirement to restrict corporate data access during international travel by triggering enforcement automatically when the device crosses the geographic policy threshold.
Application allow listing controls which applications are permitted to execute on the device but does not provide containerization, geofencing, or any mechanism to meet the four stated MDM requirements.
A biometric unlock requirement is an authentication control that secures device access but does not satisfy any of the four requirements related to data deletion, international travel restrictions, or OS update compliance.
Over-the-air update restriction limits the ability to receive or push OS updates remotely, which directly contradicts the requirement that devices must be on the latest OS version within three weeks of a new OS release.
Concept tested: MDM feature selection for BYOD policy compliance
Source: https://csrc.nist.gov/publications/detail/sp/800-124/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.