nerdexam
Isaca

CISA · Question #92

Which of the following is the BEST preventive control to protect the confidentiality of data on a corporate smartphone in the event it is lost?

The correct answer is A. Encryption of the data stored on the device. Encryption of data stored on a lost corporate smartphone is the best preventive control because it renders the data unreadable to unauthorized individuals, even if the device itself is compromised.

Submitted by the_admin· Apr 18, 2026Protection of Information Assets

Question

Which of the following is the BEST preventive control to protect the confidentiality of data on a corporate smartphone in the event it is lost?

Options

  • AEncryption of the data stored on the device
  • BRemote data wipe program
  • CPassword for device authentication
  • DBiometric authentication for the device

How the community answered

(27 responses)
  • A
    78% (21)
  • B
    15% (4)
  • C
    4% (1)
  • D
    4% (1)

Why each option

Encryption of data stored on a lost corporate smartphone is the best preventive control because it renders the data unreadable to unauthorized individuals, even if the device itself is compromised.

AEncryption of the data stored on the deviceCorrect

Encryption protects data confidentiality by scrambling the information on the device, making it unreadable without the correct decryption key. In the event of device loss, this prevents unauthorized access to the sensitive data, even if the device's physical security or authentication mechanisms are bypassed.

BRemote data wipe program

A remote data wipe program is a reactive control designed to erase data *after* a loss is detected, rather than a preventive measure that protects data confidentiality *at the time of loss*.

CPassword for device authentication

A password for device authentication prevents unauthorized access to the device, but if the device's storage is physically removed or the password is bypassed, the data itself remains unprotected.

DBiometric authentication for the device

Biometric authentication, like a password, controls access to the device itself but does not inherently protect the underlying data if the storage is accessed bypassing the authentication mechanism.

Concept tested: Mobile device data confidentiality protection

Source: https://learn.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-overview

Topics

#Mobile Device Security#Data Confidentiality#Preventive Controls#Encryption

Community Discussion

No community discussion yet for this question.

Full CISA Practice