nerdexam
CompTIA

SY0-501 · Question #76

Which of the following is the GREATEST risk to a company by allowing employees to physically bring their personal smartphones to work?

The correct answer is A. Taking pictures of proprietary information and equipment in restricted areas. The question identifies the greatest risk posed by employees bringing personal smartphones to work, highlighting the potential for direct data exfiltration.

Submitted by rachelw· Mar 4, 2026Threats, vulnerabilities, and mitigations

Question

Which of the following is the GREATEST risk to a company by allowing employees to physically bring their personal smartphones to work?

Options

  • ATaking pictures of proprietary information and equipment in restricted areas.
  • BInstalling soft token software to connect to the company's wireless network.
  • CCompany cannot automate patch management on personally-owned devices.
  • DIncreases the attack surface by having more target devices on the company's campus

How the community answered

(28 responses)
  • A
    75% (21)
  • B
    14% (4)
  • C
    4% (1)
  • D
    7% (2)

Why each option

The question identifies the greatest risk posed by employees bringing personal smartphones to work, highlighting the potential for direct data exfiltration.

ATaking pictures of proprietary information and equipment in restricted areas.Correct

Personal smartphones have high-resolution cameras, allowing employees to easily capture and exfiltrate proprietary information, such as documents or equipment, from restricted areas without being detected by network-based Data Loss Prevention (DLP) solutions. This bypass of digital security measures for physical data exfiltration represents a significant and immediate risk to intellectual property and trade secrets.

BInstalling soft token software to connect to the company's wireless network.

Installing soft token software is a security measure designed to enhance authentication, not an inherent risk, and does not directly facilitate data loss or compromise company systems by itself.

CCompany cannot automate patch management on personally-owned devices.

While true that automated patch management is challenging for personal devices, this is primarily an operational and compliance risk, not the greatest or most direct risk for immediate data exfiltration or intellectual property theft compared to active photography.

DIncreases the attack surface by having more target devices on the company's campus

Increasing the attack surface is a general security concern due to more devices, but it is less specific and potentially less immediate than the direct, intentional exfiltration of sensitive visual data via smartphone cameras, which poses a substantial and immediate data loss risk.

Concept tested: BYOD insider threat, data exfiltration risks

Source: https://learn.microsoft.com/en-us/security/compass/incident-response-playbook-insider-threats

Topics

#BYOD#mobile device risk#data exfiltration#insider threat

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice