CISM · Question #95
Which of the following is the MOST effective data loss control when connecting a personally owned mobile device to the corporate email system?
The correct answer is A. Email must be stored in an encrypted format on the mobile device. Encrypting corporate email data on personally owned mobile devices is the most effective data loss control, as it protects sensitive information even if the device is lost or stolen.
Question
Which of the following is the MOST effective data loss control when connecting a personally owned mobile device to the corporate email system?
Options
- AEmail must be stored in an encrypted format on the mobile device.
- BUsers must agree to the use of biometric multi-factor authentication (MFA).
- CA senior manager must approve each new connection.
- DEmail synchronization must be prevented when connected to a public Wi-Fi hotspot.
How the community answered
(38 responses)- A82% (31)
- B11% (4)
- C5% (2)
- D3% (1)
Why each option
Encrypting corporate email data on personally owned mobile devices is the most effective data loss control, as it protects sensitive information even if the device is lost or stolen.
Encrypting email data on the mobile device ensures that if the device is lost, stolen, or improperly accessed, the sensitive corporate information remains unreadable and protected from unauthorized disclosure, directly addressing data loss. This control specifically targets the confidentiality of data at rest on an endpoint outside corporate control.
Biometric MFA enhances authentication security, preventing unauthorized access to the email system, but it does not directly protect data already synced and stored on a lost or stolen device.
Manager approval provides an administrative control for initial access but does not prevent data loss once the device is connected and data is stored locally.
Preventing synchronization on public Wi-Fi hotspots mitigates man-in-the-middle attacks during transmission but does not protect data at rest on the device itself if the device is compromised.
Concept tested: Mobile device data at rest encryption
Topics
Community Discussion
No community discussion yet for this question.