nerdexam
CompTIA

CAS-003 · Question #876

To reduce costs, an organization, has decided it will no longer support corporate phones. All employees must use a BYOD device to access the company's collaboration services, which are cloud hosted…

The correct answer is B. MAM, geofencing, and MFA. MAM, geofencing, and MFA satisfy BYOD requirements for app-level control without device agents, location-based access restriction, and strong authentication.

Enterprise Security Architecture

Question

To reduce costs, an organization, has decided it will no longer support corporate phones. All employees must use a BYOD device to access the company's collaboration services, which are cloud hosted. To simplify device management, the end user computing department does not want to deploy agents to the devices. The Chief Information Security Officer (CISO) has identified the following requirements to support access to the service: 1. Only the current and N-1 operating systems are supported. 2. The devices cannot be jail broken. 3. Access is limited through the cloud forward proxy. 4. No company unstructured data is downloaded to local storage. 5. Strong authentication controls are implemented. 6. Any cached organization data is protected. Which of the following controls must be implemented to meet these requirements?

Options

  • ASecure storage, 2FA, and an iris scan
  • BMAM, geofencing, and MFA
  • CVPN, device management, and OTP
  • DMDM, context-aware management, and a PIN

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    73% (19)
  • C
    15% (4)
  • D
    8% (2)

Why each option

MAM, geofencing, and MFA satisfy BYOD requirements for app-level control without device agents, location-based access restriction, and strong authentication.

ASecure storage, 2FA, and an iris scan

Iris scan biometrics require specialized hardware not universally present on BYOD devices, and this combination does not address app-level data containment or the no-local-storage requirement.

BMAM, geofencing, and MFACorrect

Mobile Application Management (MAM) enforces corporate data policies - such as preventing downloads to local storage and protecting cached data - at the application layer without requiring a device-level agent, satisfying the no-agent requirement. Geofencing restricts cloud service access to approved geographic locations, reinforcing the cloud forward proxy access control. MFA fulfills the strong authentication requirement, and together these controls address all six listed requirements without full device enrollment.

CVPN, device management, and OTP

VPN and device management both require agents to be deployed to end-user devices, directly violating the stated requirement that no agents be installed.

DMDM, context-aware management, and a PIN

MDM requires deploying a management agent or profile to the device for full enrollment, which contradicts the end user computing department's explicit requirement to avoid agent deployment.

Concept tested: BYOD management with MAM and MFA without device agents

Source: https://csrc.nist.gov/publications/detail/sp/800-124/rev-2/final

Topics

#BYOD#MAM#MFA#mobile device management

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice