exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 12 discussion

Actual exam question from Isaca's CISA
Question #: 12
Topic #: 1
[All CISA Questions]

An employee loses a mobile device resulting in loss of sensitive corporate data. Which of the following would have BEST prevented data leakage?

  • A. Data encryption on the mobile device
  • B. The triggering of remote data wipe capabilities
  • C. Awareness training for mobile device users
  • D. Complex password policy for mobile devices
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
2 months, 1 week ago
Selected Answer: A
Between A and B, I think A is the better answer. Between the loss of the device and remotely wiping it there could be a gap in time, which could be enough for the loss of data. Encryption on the other hand protects without leaving such risk.
upvoted 1 times
2 months, 2 weeks ago
Selected Answer: A
Data encryption is the most effective measure to prevent sensitive data from being accessed by unauthorized parties if a mobile device is lost. Encryption ensures that even if the device falls into the wrong hands, the data remains protected because it is only accessible with the correct decryption key. NOT B because it requires the device to be powered on and connected to a network for the remote wipe command to execute. If the device is offline or inaccessible, this measure may not prevent data leakage.
upvoted 2 times
7 months, 1 week ago
Selected Answer: A
data leakage = confidentiality = encryption. Read again and again the ques, sometimes the terms being used were in a twisted manner.
upvoted 1 times
10 months, 1 week ago
Selected Answer: A
Answer: A
upvoted 1 times
10 months, 2 weeks ago
Selected Answer: C
only awareness can most possibly makes this less chance to happen again
upvoted 1 times
10 months, 3 weeks ago
Selected Answer: B
A encryption is not the answer in this case. It encrypts everything on the device, making it inflexible and having a performance impact on normal use.
upvoted 2 times
1 month ago
Incorrect. You have remote wipe capabilities but the device is unencrpted. Great, I steal the mobile device, and then place it in a faraday cage which blocks incming and outoging signals. Now I have your device and you can't send a command to remotely wipe it, and I have access to the data because you didn't encrypt it. If it was encrypted I wouldn't be able to do anything with it.
upvoted 1 times
1 year, 8 months ago
Selected Answer: A
A is the right answer.
upvoted 1 times
1 year, 9 months ago
Triggering remote data wipe capabilities is an effective measure to mitigate the risk of data leakage. It allows organizations to remotely erase the data on the lost or stolen device to prevent unauthorized access. However, in some cases, the data may still be recoverable if it is not encrypted. Therefore, combining data encryption with remote data wipe provides an even stronger protection against data leakage.
upvoted 2 times
1 year, 10 months ago
Selected Answer: A
Encryption of the data is the most correct answer
upvoted 1 times
2 years, 4 months ago
A is the answer its a preventive control. B is a corrective control
upvoted 3 times
2 years, 4 months ago
Selected Answer: A
Answer is A Encryption helps keep that data safe because no one can access it without the correct password. Remote data wipe capabilities will be triggered only if the Mobile device is registered to an MDLM system and when it is connected to the internet after it is lost or stolen.
upvoted 2 times
2 years, 5 months ago
Selected Answer: B
All encrypted data can be decrypted, may be it will take a million years but if I could erase the data remotely, then data loss has been prevented. So I will go with B
upvoted 1 times
1 month ago
You can block a stolen device from receiving signals to remotely wipe it. You're right maybe the datacould be decrypted years from now, but I'd rather someone leak the data at some time in the distant future where it may not be as useful than right this second if you chose to not encrypt it.
upvoted 1 times
2 years, 5 months ago
Selected Answer: A
A.is correct. The data in the mobile device is fully encrypted. If there is no corresponding key, it is almost impossible for others to crack it.
upvoted 4 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago