ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 179 - SY0-601 discussion

Report
Export

A company recently decided to allow its employees to use their personally owned devices for tasks like checking email and messaging via mobile applications. The company would like to use MDM, but employees are concerned about the loss of personal dat

A.
Which of the following should the IT department implement to BEST protect the company against company data loss while still addressing the employees’ concerns?
Answers
A.
Which of the following should the IT department implement to BEST protect the company against company data loss while still addressing the employees’ concerns?
B.
Enable the remote-wiping option in the MDM software in case the phone is stolen.
Answers
B.
Enable the remote-wiping option in the MDM software in case the phone is stolen.
C.
Configure the MDM software to enforce the use of PINs to access the phone.
Answers
C.
Configure the MDM software to enforce the use of PINs to access the phone.
D.
Configure MDM for FDE without enabling the lock screen.
Answers
D.
Configure MDM for FDE without enabling the lock screen.
E.
Perform a factory reset on the phone before installing the company's applications.
Answers
E.
Perform a factory reset on the phone before installing the company's applications.
Suggested answer: C

Explanation:

MDM software is a type of remote asset-management software that runs from a central server. It is used by businesses to optimize the functionality and security of their mobile devices, including smartphones and tablets. It can monitor and regulate both corporate-owned and personally owned devices to the organization’s policies.

FDE stands for full disk encryption, which is a method of encrypting all data on a device’s storage. FDE can protect data from unauthorized access in case the device is lost or stolen. If a company decides to allow its employees to use their personally owned devices for work tasks, it should configure MDM software to enforce FDE on those devices. This way, the company can protect its data from being exposed if the device falls into the wrong hands. However, employees may be concerned about the loss of personal data if the company also enables the remote-wiping option in the MDM software. Remote wiping is a feature that allows the company to erase all data on a device remotely in case of theft or loss. Remote wiping can also affect personal data on the device, which may not be acceptable to employees. Therefore, a possible compromise is to configure MDM for FDE without enabling the lock screen. This means that the device will be encrypted, but it will not require a password or PIN to unlock it. This way, employees can access their personal data easily, while the company can still protect its data with encryption.

The other options are not correct because:

A. Enable the remote-wiping option in the MDM software in case the phone is stolen. This option may address the company’s concern about data loss, but it may not address the employees’ concern about personal data loss. Remote wiping can erase both work and personal data on the device, which may not be desirable for employees.

B. Configure the MDM software to enforce the use of PINs to access the phone. This option may enhance the security of the device, but it may not address the company’s concern about data loss. PINs can be guessed or bypassed by attackers, and they do not protect data if the device is physically accessed.

D. Perform a factory reset on the phone before installing the company’s applications. This option may address the company’s concern about data loss, but it may not address the employees’ concern about personal data loss. A factory reset will erase all data on the device, including personal data, which may not be acceptable to employees.

According to CompTIA Security+ SY0-601 Exam Objectives 2.4 Given a scenario, implement secure systems design:

“MDM software is a type of remote asset-management software that runs from a central server1. It is used by businesses to optimize the functionality and security of their mobile devices, including smartphones and tablets2.”

“FDE stands for full disk encryption, which is a method of encrypting all data on a device’s storage3.”

Reference: https://www.comptia.org/certifications/security#examdetails https://www.comptia.org/content/guides/comptia-security-sy0-601-exam-objectives https://www.makeuseof.com/what-is-mobile-device-management-mdm-software/

asked 02/10/2024
Padmavathi Jawaharlal
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first