Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 70 discussion

Actual exam question from Isaca's CISM
Question #: 70
Topic #: 1
[All CISM Questions]

An information security manager is implementing a bring your own device (BYOD) program. Which of the following would BEST ensure that users adhere to the security standards?

  • A. Publish the standards on the intranet landing page.
  • B. Deploy a device management solution.
  • C. Establish an acceptable use policy.
  • D. Monitor user activities on the network.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
DASH_v
Highly Voted 1 year, 5 months ago
Selected Answer: B
Questions to ask the IM manager, 1. If i don't have a policy but a MDM - would I be able to ensure security? 2. If i have a policy but not a MDM - would I be able to ensure seucurity? I would say the likelihood of saying Yes 1 more over than 2, technincal control is generally more effective than administrative controls in the real world.
upvoted 5 times
...
ServerBrain
Most Recent 1 month, 2 weeks ago
Selected Answer: C
It's not a corporate device, it's a user's device. You can't completely take control and manage personal devices through MDM.
upvoted 1 times
...
vassof95
2 months, 2 weeks ago
Selected Answer: B
It is B as an AUP would heavily rely on a voluntary or trust-based compliance. A technical solution would provide the means to enforce any security standards posed by the policy.
upvoted 1 times
...
Cyber_Soter
5 months, 1 week ago
Selected Answer: C
I think the key word in the question is "adhere" the ONLY thing that would do this is C deploy and MDM. An AUP is also a must but it won't make users "adhere to the security standards.
upvoted 2 times
...
yottabyte
7 months, 4 weeks ago
Selected Answer: C
The questions ask for a deterrent control for the users to abide by. Standards are created from policies so Policies is the correct answer, if the question leans towards a corrective control then it will be MDM. Question clearly states what has to be done on the user side so that the user abide by the standards, it will be policy.
upvoted 3 times
...
nuel_12
8 months ago
Selected Answer: C
C is the best choice, we need to understand that this is managerial position, and the most thing is policy has to be establish first, then the next is how it will be implemented now MDM comes it which are works for engineer.
upvoted 2 times
...
ElDirec
8 months, 3 weeks ago
Selected Answer: B
B - they are talking about standards not policies. Also the word "ensure" means "make them"comply, while an AUP, would "trust they do"
upvoted 4 times
...
AlexJacobson
11 months, 3 weeks ago
Selected Answer: B
Modern tendencies tend to encourage implementing MDM for BYOD, as that's the only way to guarantee adherence to standards. BTW, the questions also says "standards", not "policies" so AUP is also not as relevant here. You are enforcing security standards (and policies if you have them) via MDM.
upvoted 2 times
...
Cyberbug2021
12 months ago
Selected Answer: B
we just agree to disagree :)
upvoted 2 times
...
Viperhunter
12 months ago
Selected Answer: B
Deploying a device management solution is the most effective way to ensure that users adhere to security standards in a bring your own device (BYOD) program. A device management solution allows the organization to enforce security policies, monitor compliance, and remotely manage and secure devices that are used to access organizational resources. This ensures that devices conform to security standards and reduces the risk of security incidents associated with BYOD.
upvoted 3 times
...
Viperhunter
12 months ago
Selected Answer: B
Implementing a device management solution allows the organization to enforce security standards on the devices that connect to the corporate network. This can include features such as device authentication, encryption, remote wiping capabilities, and other security controls. By deploying a device management solution, the organization can have better control over the security posture of devices used in the BYOD program. While publishing standards on the intranet (option A) and establishing an acceptable use policy (option C) are important communication measures, they may not guarantee adherence. Monitoring user activities on the network (option D) is reactive and may not proactively enforce security standards. A device management solution provides a more proactive and effective means of ensuring adherence to security standards for BYOD.
upvoted 2 times
...
acf4e9a
1 year, 1 month ago
Selected Answer: C
It is very straightforward. To make an user adhere to standard must have an acceptable use policy which they are supposed to abide by. The policies can be imported into device management solution as a technical control to ensure the policy is enforced thus answer C should be appropriate and should already include option B.
upvoted 2 times
Cyberbug2021
12 months ago
without B can not enforce C
upvoted 3 times
...
...
oluchecpoint
1 year, 2 months ago
C. Establish an acceptable use policy. An acceptable use policy (AUP) outlines the rules and guidelines that users must follow when using their own devices for work purposes. It sets clear expectations regarding security practices, data protection, and acceptable behaviors. Users are required to read, understand, and agree to the AUP before they are granted access to company resources with their personal devices.
upvoted 2 times
...
Agamennore
1 year, 2 months ago
Selected Answer: C
In a CORPORATE device absolutely B, BUT in a personal one (BYOD) the first action is C
upvoted 3 times
...
AomineDaiki
1 year, 3 months ago
I am going with B here because the emphasized word was "Ensure". Users can read and sign AUPs till the cows come home, but that does not necessarily mean they will adhere to it. If the bolded word was "First" or "Primarily" then maybe AUPs will be the correct answer. If Device management is deployed, people will have no option but to be on their best behavior. (Yes, I know it is their personal device) but if they are conducting organization business with it, and you agree to use your device, there will be some management don't you agree?
upvoted 4 times
...
DavoA
1 year, 4 months ago
Selected Answer: C
Agree with albin_kurti 3
upvoted 2 times
...
ddharia94
1 year, 5 months ago
Selected Answer: C
Policy comes before implementing a solution
upvoted 2 times
[Removed]
1 year, 4 months ago
but policy doesnt ensure users adhere. a centralized management solution does
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...