Question

Difficulty: EasyMobile Device and Embedded System Security

A systems administrator is establishing security baselines for a new fleet of corporate smartphones to protect sensitive local data if a device is lost or stolen. Which TWO security controls should the administrator deploy on these devices to directly protect data at rest and prevent unauthorized access upon physical loss? (Select TWO.)

  1. Enable full-device storage encryptionAnswer
  2. Configure remote wipe functionality via Mobile Device Management (MDM)Answer
  3. C
    Attach physical security cables and locks to the mobile devices
  4. D
    Configure WPA2-Personal pre-shared keys to protect stored file systems

Answer

The correct security controls to protect data on lost or stolen mobile devices are enabling full-device storage encryption and configuring remote wipe functionality via Mobile Device Management (MDM).
Enabling full-device storage encryption and configuring remote wipe capability directly safeguard data on lost or stolen smartphones. Storage encryption ensures that data at rest remains unreadable without valid authentication, while remote wipe allows administrators to clean sensitive files remotely if physical possession of the device cannot be recovered.

Step-by-Step Solution

1
Analyze the security objective.
The target objective is protecting data at rest and mitigating risks if physical control of a mobile device is lost.
Mobile devices are vulnerable to theft and loss, requiring controls focused on local storage confidentiality and emergency data removal.
2
Evaluate options for protecting stored data directly on the hardware.
Full-device storage encryption ensures that raw data cannot be read off the internal flash memory without authentication.
Encryption is the standard control for protecting data at rest.
3
Evaluate options for incident remediation following device loss.
Remote wipe capability allows IT administrators to clear device contents over cellular or Wi-Fi networks.
Erasing data remotely prevents persistent exposure of corporate data.

Key Concept

Mobile data-at-rest protection and lost device remediation (Full-Device Encryption and Remote Wipe)
Rate this question