nerdexam
IsacaIsaca

CGEIT · Question #71

CGEIT Question #71: Real Exam Question with Answer & Explanation

The correct answer is C: Educating employees on the increased IT security risk to the enterprise. The primary governance focus when implementing a new BYOD policy should be educating employees on the increased IT security risks introduced to the enterprise.

Submitted by emma.c· Apr 18, 2026Risk Optimization

Question

Which of the following should be the MAIN governance focus when implementing a newly approved bring your own device (BYOD) policy?

Options

  • ARecommending mobile applications that will increase business productivity
  • BTraining employees on the enterprise's chosen mobile device management system
  • CEducating employees on the increased IT security risk to the enterprise
  • DUnderstanding knowledge gaps of IT employees to support different mobile platforms

Explanation

The primary governance focus when implementing a new BYOD policy should be educating employees on the increased IT security risks introduced to the enterprise.

Common mistakes.

  • A. Recommending productivity apps is a potential benefit, not the main governance focus, which is primarily risk and compliance management.
  • B. Training on an MDM system is an operational implementation detail, secondary to the overarching governance focus on risk awareness and mitigation for the enterprise.
  • D. Understanding IT staff knowledge gaps is an internal IT management concern, not the main governance focus for the policy itself regarding enterprise-wide security risk.

Concept tested. BYOD policy governance and security risk

Reference. https://learn.microsoft.com/en-us/mem/intune/fundamentals/byod-introduction

Topics

#BYOD policy#IT security risk#Risk management#Employee awareness

Community Discussion

No community discussion yet for this question.

Full CGEIT PracticeBrowse All CGEIT Questions