Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 458 discussion

Actual exam question from Isaca's CISM
Question #: 458
Topic #: 1
[All CISM Questions]

An organization permits the storage and use of its critical and sensitive information on employee-owned smartphones. Which of the following is the BEST security control?

  • A. Monitoring now often the smartphone is used
  • B. Developing security awareness training
  • C. Requiring the backup of the organization s data by the user
  • D. Establishing the authority to remote wipe
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
beever
Highly Voted 1 year, 9 months ago
Selected Answer: B
It should be B - Developing security awareness training since it is on employee-owned smartphones, awareness would be the best security control of it
upvoted 6 times
...
Evedzy
Most Recent 2 months, 3 weeks ago
the main risk with phones is they can be lost so remote wipe is key.
upvoted 1 times
...
03allen
5 months, 2 weeks ago
Selected Answer: B
Does it make sense if you want to wipe other people's data on the same phone? Unless you install a separate enterprise OS. So user awareness is the best solution.
upvoted 1 times
...
POWNED
11 months, 1 week ago
Selected Answer: D
I don't believe awareness training is a control, will have to go with D on this one.
upvoted 2 times
...
Soleandheel
12 months ago
D. Establishing the authority to remote wipe I'm going with D becuase, what if the threat is an insider threat. Maybe one of your employees decides to misuse company data deliberately. Training will not help in this situation. Remote Wipe is the best option in this scenario.
upvoted 2 times
...
oluchecpoint
1 year, 2 months ago
Selected Answer: D
Option D
upvoted 1 times
...
AaronS1990
1 year, 3 months ago
Selected Answer: D
This is D, if lost you need to delete the sensitive data B. Education does nothing. Everyone knows how to use and anyone could lose a phone.
upvoted 2 times
...
Goseu
1 year, 4 months ago
The best security control for what exactly ? I dont think training user is control , D is control but its very far fetched since you allow users to store and use data. It doesn’t feel like a realistic question .
upvoted 1 times
...
Rowlandmarc
1 year, 4 months ago
Selected Answer: B
I believe B is the better of the two... educating the user on appropriate use cases and how to manage the data etc... comparing this to option D which is the single control to wipe it once reported the phone is missing etc... user education provides that much more value
upvoted 2 times
[Removed]
1 year, 4 months ago
educating does nothing if they lose the phone. you need to wipe then
upvoted 2 times
...
...
richck102
1 year, 4 months ago
D. Establishing the authority to remote wipe
upvoted 2 times
...
Saisharan
1 year, 5 months ago
Developing security awareness training (option B) is beneficial, but it alone may not provide sufficient control over the data stored on employee-owned smartphones. So the correct Option D
upvoted 2 times
...
dark_3k03r
1 year, 7 months ago
Selected Answer: D
The correct solution would be (D) as the organization should be able to wipe the device in case it is stolen or misplaced. A. Could cause potential legal issues B. Developing security awareness training would do nothing to control the situation but only make users aware of the situation. C. Requiring the backup of the organization s data by the user does not address the fact that a device may be stolen or misplaced.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...