A systems administrator is establishing security baselines for a new fleet of corporate smartphones to protect sensitive local data if a device is lost or stolen. Which TWO security controls should the administrator deploy on these devices to directly protect data at rest and prevent unauthorized access upon physical loss? (Select TWO.)
- Enable full-device storage encryptionAnswer
- Configure remote wipe functionality via Mobile Device Management (MDM)Answer
- CAttach physical security cables and locks to the mobile devices
- DConfigure WPA2-Personal pre-shared keys to protect stored file systems
Answer
The correct security controls to protect data on lost or stolen mobile devices are enabling full-device storage encryption and configuring remote wipe functionality via Mobile Device Management (MDM).
Enabling full-device storage encryption and configuring remote wipe capability directly safeguard data on lost or stolen smartphones. Storage encryption ensures that data at rest remains unreadable without valid authentication, while remote wipe allows administrators to clean sensitive files remotely if physical possession of the device cannot be recovered.
Step-by-Step Solution
Key Concept
Mobile data-at-rest protection and lost device remediation (Full-Device Encryption and Remote Wipe)