nerdexam
Isaca

CISA · Question #464

Which of the following should be of GREATEST concern to an IS auditor reviewing an organization's mobile device policies and controls in its corporate environment?

The correct answer is B. Not all active devices are enrolled in mobile device management (MDM). Unmanaged devices fall outside corporate controls - lacking enforced encryption, patch management, app restrictions, remote wipe capabilities and other safeguards - making them the greatest risk for data loss, malware infection or unauthorized access.

Submitted by tarun92· Apr 18, 2026Protection of Information Assets

Question

Which of the following should be of GREATEST concern to an IS auditor reviewing an organization’s mobile device policies and controls in its corporate environment?

Options

  • ARemote wipe and lock features are only available with access to the internet
  • BNot all active devices are enrolled in mobile device management (MDM)
  • CThe virtual private network (VPN) policy is not enabled for the internal corporate network
  • DThe mobile authentication policy requires biometrics

How the community answered

(68 responses)
  • A
    4% (3)
  • B
    66% (45)
  • C
    10% (7)
  • D
    19% (13)

Explanation

Unmanaged devices fall outside corporate controls - lacking enforced encryption, patch management, app restrictions, remote wipe capabilities and other safeguards - making them the greatest risk for data loss, malware infection or unauthorized access.

Topics

#Mobile Device Management#Mobile Security#Information Security Controls#Risk Assessment

Community Discussion

No community discussion yet for this question.

Full CISA Practice