CAS-003 · Question #968
A security architect is called into a roadmap planning meeting for the next year of IT protects. One of the protects involves migrating from the current mobile, laptop, and tablet device management…
The correct answer is C. Concerns about personal health data leakage F. Rooting and jailbreaking of mobile devices. The concern is privacy of personal data on BYOD devices managed by a cloud-based MDM. Personal health data leakage (C) is a direct privacy risk: BYOD devices often run health and fitness apps whose data could be accessed or transmitted by an MDM agent, potentially violating…
Question
A security architect is called into a roadmap planning meeting for the next year of IT protects. One of the protects involves migrating from the current mobile, laptop, and tablet device management system to a cloud-based MDM system. The biggest motivator seems to be cost savings but the security architect is concerned about the privacy of the personal data of those using BYOD. Which of the following concerns might convince the group to more strongly consider privacy concerns? (Select TWO)
Options
- AWeak forms of authentication being used
- BUnauthorized remote activation and control of devices
- CConcerns about personal health data leakage
- DUnsigned and unauthorized application usage
- EConcerns about lack of containerization
- FRooting and jailbreaking of mobile devices
How the community answered
(50 responses)- A2% (1)
- B8% (4)
- C72% (36)
- D4% (2)
- E14% (7)
Explanation
The concern is privacy of personal data on BYOD devices managed by a cloud-based MDM. Personal health data leakage (C) is a direct privacy risk: BYOD devices often run health and fitness apps whose data could be accessed or transmitted by an MDM agent, potentially violating HIPAA or other health privacy regulations - a compelling argument to revisit privacy controls before migration. Rooting and jailbreaking (F) removes the OS-level isolation between personal and corporate data, meaning the MDM's visibility into the device could inadvertently (or deliberately) expose personal data to the corporate cloud system. The remaining options - weak authentication (A), unauthorized remote activation (B), unsigned apps (D), and lack of containerization (E) - are legitimate security concerns but relate more to device security posture than to the leakage of users' personal private data.
Topics
Community Discussion
No community discussion yet for this question.