Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 225 discussion

Actual exam question from ISC's CISSP
Question #: 225
Topic #: 1
[All CISSP Questions]

Which of the following measures serves as the BEST means for protecting data on computers, smartphones, and external storage devices when traveling to high- risk countries?

  • A. Review applicable destination country laws, forensically clean devices prior to travel, and only download sensitive data over a virtual private network (VPN) upon arriving at the destination.
  • B. Leverage a Secure Socket Layer (SSL) connection over a virtual private network (VPN) to download sensitive data upon arriving at the destination.
  • C. Keep laptops, external storage devices, and smartphones in the hotel room when not in use.
  • D. Use multi-factor authentication (MFA) to gain access to data stored on laptops or external storage devices and biometric fingerprint access control mechanisms to unlock smartphones.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
PeepoK
Highly Voted 1 year, 11 months ago
The answer is D because of the last object in the sentence -> external storage devices.
upvoted 8 times
jackdryan
1 year, 6 months ago
D is correct
upvoted 1 times
...
...
CuteRabbit168
Highly Voted 2 years, 1 month ago
Selected Answer: D
“A” is probably applicable at the point of getting through customs without issues. But downloading sensitive data via VPN when arriving at the destination, without protecting the data at rest while in a high-risk country is unacceptable. D is the best answer
upvoted 7 times
...
1460168
Most Recent 3 months, 3 weeks ago
Selected Answer: D
It is D, because of "for protecting data ON computers, smartphones, and external storage devices" It can't be A: How should a VPN protect your local stored data?! It does not make any sense. It is D: Only D takes care of local stored data and how to protect them.
upvoted 1 times
...
CCNPWILL
5 months, 4 weeks ago
Selected Answer: D
C.... to not get robbed! unfortunately, not a good answer for the CISSP exam but a good answer in real life. through this question out. Best answer then would be D. D offers the most COMPREHENSIVE security strategy for this specific scenario.
upvoted 1 times
...
73f8ac3
7 months ago
Selected Answer: A
Many people answer D, but D is focused on general security principles without considering the aspect of traveling to sensitive countries ! One important aspect is the local laws indeed. When you pass through the customs of some countries, you can be asked to show an unlocked computer/device, USA for instance can force you to disclose your Social Network data.
upvoted 2 times
...
hoho2000
8 months, 3 weeks ago
Selected Answer: D
Cant be A, what does local law have anything to do with securing devices? At most is embargo law that you cant import certain crtypography capablities but those are not local laws. Also how does using TLS to download sensitive data be helpful when the sensitive data are in your devices and there is no mention of securing the devices to protect the newly downloaded sensitive data.
upvoted 1 times
...
629f731
10 months, 2 weeks ago
Selected Answer: A
Option A combines legal awareness, proactive measures to clean devices, and secure data transfer practices, making it a comprehensive approach to safeguarding data when traveling to high-risk countries.
upvoted 1 times
...
YesPlease
11 months, 2 weeks ago
Selected Answer: A
Answer A) https://www.colorado.edu/researchinnovation/compliance/export-controls/international-travel/High-Risk-Country-Guidance
upvoted 1 times
...
isaac592
1 year, 1 month ago
Selected Answer: D
D provides the best ways to protect DaR on devices. This is also used in CSfC models/frameworks.
upvoted 2 times
...
homeysl
1 year, 1 month ago
Selected Answer: A
Think like a manager. It's also limiting access to data.
upvoted 1 times
...
74gjd_37
1 year, 2 months ago
Selected Answer: A
Using multi-factor authentication (MFA) to gain access to data stored on laptops or external storage devices can be a good security measure, but it does not provide complete protection for data when traveling to high-risk countries. MFA only protects against unauthorized access to the device, but it does not protect against data theft or data compromise. If a device is lost or stolen, the data stored on it can still be accessed and compromised, even with MFA in place. Therefore, additional measures, such as using a VPN to download data and forensically cleaning devices before travel, should also be employed to fully protect sensitive data when traveling to high-risk countries.
upvoted 4 times
...
Demo25
1 year, 4 months ago
Selected Answer: A
When traveling to high-risk countries, option A is the BEST means for protecting data on computers, smartphones, and external storage devices.
upvoted 1 times
...
liebeskind
1 year, 6 months ago
Selected Answer: A
The Customs of most countries (not necessarily high-risk) have the authorities to confiscate or request to unlock the electronic devices bring into their countries when in doubt of National Security. Failed to comply might result in jail or get killed (in high-risk countries).
upvoted 2 times
...
RVoigt
1 year, 9 months ago
Selected Answer: D
"BEST means for protecting data ON computers" - not in transit/while downloading.
upvoted 5 times
...
shash33
1 year, 10 months ago
Selected Answer: A
According to this article it's "A"
upvoted 1 times
shash33
1 year, 10 months ago
https://www.colorado.edu/researchinnovation/compliance/export-controls/international-travel/High-Risk-Country-Guidance
upvoted 2 times
...
...
DJOEK
1 year, 10 months ago
Selected Answer: A
The best means for protecting data on computers, smartphones, and external storage devices when traveling to high-risk countries is to review applicable destination country laws, forensically clean devices prior to travel, and only download sensitive data over a virtual private network (VPN) upon arriving at the destination (Option A). This approach combines multiple security measures to protect data from potential risks, such as legal issues, data theft, and unauthorized access. Reviewing destination country laws helps to ensure compliance with local regulations, and forensically cleaning devices before travel helps to remove any sensitive data that could potentially be accessed by unauthorized parties. Using a VPN to download sensitive data upon arrival at the destination helps to secure the data in transit and prevent any potential interception or tampering. Option D, using MFA and biometric access control mechanisms, can help to improve the security of devices and data, but it does not address the legal issues or data theft risks.
upvoted 2 times
...
neowoo
1 year, 11 months ago
Selected Answer: D
D is a little more specific for mobile equipments.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...