nerdexam
CSA

CCSK · Question #137

CCM: A hypothetical start-up company called "IT4Sure" provides a cloud based IT management solution. They are growing rapidly and have some security measures in place but the employees are still…

The correct answer is E. All of the above. A complete MDM policy must address all baseline protection areas simultaneously, as each control targets a distinct threat vector that the others do not cover.

Cloud Security Operations

Question

CCM: A hypothetical start-up company called "IT4Sure" provides a cloud based IT management solution. They are growing rapidly and have some security measures in place but the employees are still using their personal mobile devices for storing and communicating company confidential information. So they decide to provide the employees with company mobile devices and implement a Mobile Device Management policy. Two months later, a customer wants to review IT4Sure's mobile device security practices. Which of the following basic protection measures should the client look for in the company's Mobile Device Management policy?

Options

  • ARegistration of mobile devices
  • BRequirements for physical protection
  • CRequirements for mobile device software versions and for applying patches
  • DMalware protection
  • EAll of the above

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    11% (4)
  • C
    6% (2)
  • D
    3% (1)
  • E
    77% (27)

Why each option

A complete MDM policy must address all baseline protection areas simultaneously, as each control targets a distinct threat vector that the others do not cover.

ARegistration of mobile devices

Registration alone tracks devices but provides no protection against malware infection, software vulnerabilities, or physical theft of an already-registered device.

BRequirements for physical protection

Physical protection requirements address only loss or theft scenarios and do not mitigate logical threats such as malware or exploitation of unpatched software.

CRequirements for mobile device software versions and for applying patches

Patch and software version controls reduce vulnerability exposure but omit physical security requirements, device registration tracking, and malware defense.

DMalware protection

Malware protection addresses only one threat category and leaves devices exposed to risks from unpatched vulnerabilities, physical theft, and unregistered unauthorized devices.

EAll of the aboveCorrect

All listed measures are recognized baseline MDM controls per the CSA Cloud Controls Matrix: device registration ensures only authorized devices access company data, physical protection requirements guard against theft and loss, software version and patch requirements close known vulnerabilities, and malware protection defends against malicious software - each addressing a separate risk layer that a comprehensive MDM policy must cover.

Concept tested: MDM policy baseline controls per CSA CCM

Source: https://cloudsecurityalliance.org/research/cloud-controls-matrix/

Topics

#mobile device management#MDM policy#CCM#device protection

Community Discussion

No community discussion yet for this question.

Full CCSK Practice