nerdexam
IsacaIsaca

CISM · Question #946

CISM Question #946: Real Exam Question with Answer & Explanation

The correct answer is C: Assess the business need to provide a secure solution.. The most effective action is to assess the business need and provide an approved secure alternative (e.g., managed corporate storage/containerization/CASB controls). This addresses the root cause and enables compliant behavior rather than reacting punitively without solving the u

Submitted by yaw92· Apr 18, 2026Information Security Risk Management

Question

An organization has introduced a new bring your own device (BYOD) program. The security manager has determined that a small number of employees are utilizing free cloud storage services to store company data through their mobile devices. Which of the following is the MOST effective course of action?

Options

  • ADisable the employees' remote access to company email and data.
  • BInitiate remote wipe of the devices.
  • CAssess the business need to provide a secure solution.
  • DAllow the practice to continue temporarily for monitoring purposes.

Explanation

The most effective action is to assess the business need and provide an approved secure alternative (e.g., managed corporate storage/containerization/CASB controls). This addresses the root cause and enables compliant behavior rather than reacting punitively without solving the underlying requirement.

Topics

#BYOD security#Cloud security#Risk mitigation#Security solutions

Community Discussion

No community discussion yet for this question.

Full CISM PracticeBrowse All CISM Questions