nerdexam
Isaca

CISA · Question #600

To ensure the organization is able to centrally manage mobile devices to protect against data disclosure, it is MOST important for an IS auditor to determine whether:

The correct answer is C. Remote wipe functionality is enabled on mobile devices. The primary risk is data exposure if a mobile device is lost or stolen. A centrally enforced mobile device management (MDM) solution with remote wipe ensures sensitive data can be erased quickly, effectively mitigating disclosure risk. While training and reporting provide…

Submitted by mateo_ar· Apr 18, 2026Protection of Information Assets

Question

To ensure the organization is able to centrally manage mobile devices to protect against data disclosure, it is MOST important for an IS auditor to determine whether:

Options

  • AA mobile security awareness training program exists.
  • BIncident statistics are regularly provided to management.
  • CRemote wipe functionality is enabled on mobile devices.
  • DLost mobile devices can be located remotely.

How the community answered

(45 responses)
  • A
    2% (1)
  • B
    9% (4)
  • C
    73% (33)
  • D
    16% (7)

Explanation

The primary risk is data exposure if a mobile device is lost or stolen. A centrally enforced mobile device management (MDM) solution with remote wipe ensures sensitive data can be erased quickly, effectively mitigating disclosure risk. While training and reporting provide value, they are not preventative. Locating devices is helpful but does not protect data if recovery fails.

Topics

#Mobile device security#Data loss prevention#Remote wipe#Security controls

Community Discussion

No community discussion yet for this question.

Full CISA Practice