nerdexam
CompTIA

CAS-003 · Question #919

A company s design team is increasingly concerned about intellectual property theft Members of the team often travel to suppliers' offices where they collaborate and share access to their sensitive…

The correct answer is A. Apply MOM and enforce full disk encryption on all design team laptops. Design team members who travel with sensitive IP on laptops need MDM enrollment and full disk encryption to protect that data if a device is lost or stolen at a supplier site.

Enterprise Security Architecture

Question

A company s design team is increasingly concerned about intellectual property theft Members of the team often travel to suppliers' offices where they collaborate and share access to their sensitive data. Which of the following should be implemented?

Options

  • AApply MOM and enforce full disk encryption on all design team laptops
  • BAllow access to sensitive data only through a multifactor-authenticated VDI environment
  • CRequire all sensitive files be saved only on company fileshares accessible only through multifactor-
  • DStore all sensitive data on geographically/ restricted, public-facing SFTP servers authenticated

How the community answered

(58 responses)
  • A
    74% (43)
  • B
    7% (4)
  • C
    3% (2)
  • D
    16% (9)

Why each option

Design team members who travel with sensitive IP on laptops need MDM enrollment and full disk encryption to protect that data if a device is lost or stolen at a supplier site.

AApply MOM and enforce full disk encryption on all design team laptopsCorrect

MDM (Mobile Device Management - likely rendered as 'MOM' due to a scan or OCR error) provides centralized policy enforcement, compliance monitoring, and remote wipe capability for managed endpoints. Pairing MDM with full disk encryption ensures that even if a laptop is physically taken during travel to a supplier's office, the stored intellectual property remains inaccessible without valid credentials.

BAllow access to sensitive data only through a multifactor-authenticated VDI environment

A VDI environment requires stable network connectivity to access and collaborate on data, which cannot be guaranteed at all supplier locations, making real-time collaboration unreliable during travel.

CRequire all sensitive files be saved only on company fileshares accessible only through multifactor-

Restricting files to company fileshares with MFA still depends on network availability and does not protect any data that has been cached or temporarily stored on the local device during a session.

DStore all sensitive data on geographically/ restricted, public-facing SFTP servers authenticated

Placing sensitive intellectual property on public-facing SFTP servers exposes it to internet-based attacks regardless of authentication controls, which is an unsuitable risk posture for valuable design data.

Concept tested: MDM and full disk encryption for traveling employees

Source: https://learn.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started

Topics

#MDM#full disk encryption#intellectual property#mobile security

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice