nerdexam
CompTIA

CAS-003 · Question #838

A corporation with a BYOD policy is very concerned about issues that may arise from data ownership. The corporation is investigating a new MDM solution and has gathered the following requirements as…

The correct answer is A. Application-based containerization C. Geofencing. An MDM solution for a BYOD environment must include application containerization for selective corporate data wipe and geofencing for location-based access control to meet the stated requirements.

Technical Integration of Enterprise Security

Question

A corporation with a BYOD policy is very concerned about issues that may arise from data ownership. The corporation is investigating a new MDM solution and has gathered the following requirements as part of the requirements-gathering phase:

Each device must be issued a secure token of trust from the corporate PKI. All corporate applications and local data must be able to be deleted from a central console. Access to corporate data must be restricted on international travel. Devices must be on the latest OS version within three weeks of an OS release. Which of the following should be features in the new MDM solution to meet these requirements? (Choose two.)

Options

  • AApplication-based containerization
  • BEnforced full-device encryption
  • CGeofencing
  • DApplication allow listing
  • EBiometric requirement to unlock device
  • FOver-the-air update restriction

How the community answered

(35 responses)
  • A
    71% (25)
  • B
    9% (3)
  • D
    14% (5)
  • E
    3% (1)
  • F
    3% (1)

Why each option

An MDM solution for a BYOD environment must include application containerization for selective corporate data wipe and geofencing for location-based access control to meet the stated requirements.

AApplication-based containerizationCorrect

Application-based containerization isolates corporate apps and data into a separate, managed partition on the personal device. This enables MDM administrators to remotely wipe only the corporate container from a central console without touching personal data, directly satisfying the requirement to delete all corporate applications and local data centrally.

BEnforced full-device encryption

Full-device encryption protects data at rest from unauthorized physical access but does not address the requirements for remote selective deletion, travel-based access restriction, or OS update enforcement.

CGeofencingCorrect

Geofencing applies location-aware conditional access policies that automatically restrict or block access to corporate resources when a device is detected outside a defined geographic boundary. This directly meets the requirement to restrict corporate data access during international travel by triggering enforcement automatically when the device crosses the geographic policy threshold.

DApplication allow listing

Application allow listing controls which applications are permitted to execute on the device but does not provide containerization, geofencing, or any mechanism to meet the four stated MDM requirements.

EBiometric requirement to unlock device

A biometric unlock requirement is an authentication control that secures device access but does not satisfy any of the four requirements related to data deletion, international travel restrictions, or OS update compliance.

FOver-the-air update restriction

Over-the-air update restriction limits the ability to receive or push OS updates remotely, which directly contradicts the requirement that devices must be on the latest OS version within three weeks of a new OS release.

Concept tested: MDM feature selection for BYOD policy compliance

Source: https://csrc.nist.gov/publications/detail/sp/800-124/rev-2/final

Topics

#BYOD#MDM#geofencing#containerization

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice