CAS-003 · Question #896
Employees who travel internationally have been issued corporate mobile devices. When traveling through border security employees report border police officers have asked them to power on and unlock…
The correct answer is B. Implement full-device encryption and employ biometric authentication. Full-device encryption combined with biometric authentication prevents forensic extraction tools from reading stored data during a forced device connection, making B the strongest protection against border inspection data exposure.
Question
Employees who travel internationally have been issued corporate mobile devices. When traveling through border security employees report border police officers have asked them to power on and unlock the phones and tablets for inspection. Non-compliance with these requests may lead to the devices being confiscated. After the phones have been unlocked, the police connect them to laptops for several minutes. The company rs concerned about potential exposure of IP financial data or other sensitive information. Which of the following is MOST likely to protect the company's data m future situations?
Options
- AAdministratively require all devices to go through forensic inspection upon return
- BImplement full-device encryption and employ biometric authentication
- CInstall a monitoring application to record the border police's behavior
- DMove the applications and data into a hardware-backed, encrypted container
- EIssue sanitized mobile devices to the employees poor to travel
How the community answered
(25 responses)- A8% (2)
- B72% (18)
- C16% (4)
- E4% (1)
Why each option
Full-device encryption combined with biometric authentication prevents forensic extraction tools from reading stored data during a forced device connection, making B the strongest protection against border inspection data exposure.
Post-travel forensic inspection is a reactive control that does not prevent data exfiltration that has already occurred during the border crossing event.
Full-device encryption ensures that when police connect the device to a forensic laptop, all stored data remains unreadable without the encryption key even while the device appears powered on; biometric authentication means re-authenticating the device requires the employee's physical presence, limiting the window of exposure to only the period when the employee is actively authenticated and directly supervising the device.
A monitoring application may record the officer's behavior but does not technically prevent data from being copied or read during the laptop connection.
A hardware-backed encrypted container protects only the data explicitly stored within it, leaving all other device data unprotected once the employee unlocks the device under compulsion.
Issuing sanitized devices prevents employees from having any working applications or data available during travel, rendering the devices non-functional for legitimate business purposes.
Concept tested: Mobile device encryption and biometric authentication for travel
Source: https://csrc.nist.gov/publications/detail/sp/800-124/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.