nerdexam
CompTIA

CAS-003 · Question #896

Employees who travel internationally have been issued corporate mobile devices. When traveling through border security employees report border police officers have asked them to power on and unlock…

The correct answer is B. Implement full-device encryption and employ biometric authentication. Full-device encryption combined with biometric authentication prevents forensic extraction tools from reading stored data during a forced device connection, making B the strongest protection against border inspection data exposure.

Enterprise Security Architecture

Question

Employees who travel internationally have been issued corporate mobile devices. When traveling through border security employees report border police officers have asked them to power on and unlock the phones and tablets for inspection. Non-compliance with these requests may lead to the devices being confiscated. After the phones have been unlocked, the police connect them to laptops for several minutes. The company rs concerned about potential exposure of IP financial data or other sensitive information. Which of the following is MOST likely to protect the company's data m future situations?

Options

  • AAdministratively require all devices to go through forensic inspection upon return
  • BImplement full-device encryption and employ biometric authentication
  • CInstall a monitoring application to record the border police's behavior
  • DMove the applications and data into a hardware-backed, encrypted container
  • EIssue sanitized mobile devices to the employees poor to travel

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    72% (18)
  • C
    16% (4)
  • E
    4% (1)

Why each option

Full-device encryption combined with biometric authentication prevents forensic extraction tools from reading stored data during a forced device connection, making B the strongest protection against border inspection data exposure.

AAdministratively require all devices to go through forensic inspection upon return

Post-travel forensic inspection is a reactive control that does not prevent data exfiltration that has already occurred during the border crossing event.

BImplement full-device encryption and employ biometric authenticationCorrect

Full-device encryption ensures that when police connect the device to a forensic laptop, all stored data remains unreadable without the encryption key even while the device appears powered on; biometric authentication means re-authenticating the device requires the employee's physical presence, limiting the window of exposure to only the period when the employee is actively authenticated and directly supervising the device.

CInstall a monitoring application to record the border police's behavior

A monitoring application may record the officer's behavior but does not technically prevent data from being copied or read during the laptop connection.

DMove the applications and data into a hardware-backed, encrypted container

A hardware-backed encrypted container protects only the data explicitly stored within it, leaving all other device data unprotected once the employee unlocks the device under compulsion.

EIssue sanitized mobile devices to the employees poor to travel

Issuing sanitized devices prevents employees from having any working applications or data available during travel, rendering the devices non-functional for legitimate business purposes.

Concept tested: Mobile device encryption and biometric authentication for travel

Source: https://csrc.nist.gov/publications/detail/sp/800-124/rev-2/final

Topics

#mobile device security#full-device encryption#international travel#data protection

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice