CISM · Question #39
A user reports a stolen personal mobile device that stores sensitive corporate data. Which of the following will BEST minimize the risk of data exposure?
The correct answer is A. Wipe the device remotely. Remotely wiping a stolen mobile device is the most effective action to immediately minimize the risk of sensitive corporate data exposure.
Question
A user reports a stolen personal mobile device that stores sensitive corporate data. Which of the following will BEST minimize the risk of data exposure?
Options
- AWipe the device remotely
- BRemove user's access to corporate data
- CPrevent the user from using personal mobile devices
- DReport the incident to the police
How the community answered
(51 responses)- A75% (38)
- B4% (2)
- C16% (8)
- D6% (3)
Why each option
Remotely wiping a stolen mobile device is the most effective action to immediately minimize the risk of sensitive corporate data exposure.
Remotely wiping the device immediately deletes all data, including sensitive corporate information, from the stolen mobile device. This action directly prevents unauthorized access to and exposure of the data, making it the most effective immediate control.
Removing user access to corporate data prevents future access but does not protect the data already stored on the stolen device.
Preventing personal mobile device use is a policy decision for the future, not an immediate action to mitigate data exposure from a currently stolen device.
Reporting the incident to the police is a necessary legal and procedural step, but it does not directly mitigate the risk of data exposure from the device itself.
Concept tested: Mobile device incident response
Source: https://learn.microsoft.com/en-us/mem/intune/remote-actions/device-erase
Topics
Community Discussion
No community discussion yet for this question.