nerdexam
CompTIA

CAS-003 · Question #904

A corporation with a BYOO policy is very concerned about issues that may arise from data ownership. The corporation is investigating a new MOM solution and has gathered the following requirements as…

The correct answer is B. Enforced full-device encryption C. Geofencing. Two requirements map directly to specific MDM features. First, 'Access to corporate data must be restricted on international travel' maps precisely to Geofencing (C) - a feature that enforces policy based on the device's geographic location, automatically blocking or limiting…

Enterprise Security Architecture

Question

A corporation with a BYOO policy is very concerned about issues that may arise from data ownership. The corporation is investigating a new MOM solution and has gathered the following requirements as part of the requirements-gathering phase:

  • Each device must be issued a secure token of trust from the corporate PKl
  • Al corporate applications and local data must be able to be deleted from a central console.
  • Access to corporate data must be restricted on international travel
  • Devices must be on the latest OS version within three weeks of an OS release

Which of the following should be features in the new MDM solution to meet these requirements? (Select TWO)

Options

  • AApplication-based containerization
  • BEnforced full-device encryption
  • CGeofencing
  • DApplication allow listing
  • EBiometric requirement to unlock device
  • FOver-the-air update restriction

How the community answered

(34 responses)
  • A
    12% (4)
  • B
    59% (20)
  • D
    3% (1)
  • E
    21% (7)
  • F
    6% (2)

Explanation

Two requirements map directly to specific MDM features. First, 'Access to corporate data must be restricted on international travel' maps precisely to Geofencing (C) - a feature that enforces policy based on the device's geographic location, automatically blocking or limiting access when a device crosses a defined boundary. Second, 'All corporate applications and local data must be able to be deleted from a central console' is best supported by Enforced Full-Device Encryption (B) - encryption ensures that remotely wiped data is irrecoverable, and many MDM remote-wipe functions depend on encryption being active to be effective. Option A (containerization) partially addresses data deletion but is not as comprehensive. Option D (allow listing) is a security control unrelated to the stated requirements. Option E (biometrics) addresses authentication, not data residency or location-based access. Option F (OTA update restriction) would actually prevent meeting the 'latest OS within three weeks' requirement, making it counterproductive.

Topics

#MDM#BYOD#geofencing#mobile device management

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice