Soru

Zorluk: OrtaMobile Device and Embedded System Security

A security administrator is updating Mobile Device Management (MDM) policy profiles for mobile devices connecting to corporate data under a Bring Your Own Device (BYOD) initiative. The security strategy requires isolating corporate data from personal applications to prevent data leakage and prohibiting users from installing unverified applications from unofficial app stores. Which TWO of the following security controls should the administrator implement to meet these requirements? (Select TWO.)

  1. Enforce app containerization with data loss prevention (DLP) copy-paste restrictionsCevap
  2. B
    Configure an immediate full-device remote wipe after a single failed local passcode entry
  3. Restrict app installation sources by disabling app sideloading on all enrolled devicesCevap
  4. D
    Deploy perimeter bollards and physical lockboxes around all remote employee workstations

Cevap

The correct controls are enforcing app containerization with data loss prevention restrictions and disabling application sideloading on all enrolled mobile devices.
The correct options implement containerization (which separates enterprise app data from personal apps via encryption and DLP rules) and disable application sideloading (which stops the installation of third-party apps from unverified sources).

Adım Adım Çözüm

1
Analyze the requirement for isolating corporate data from personal applications on BYOD devices.
Identify that containerization separates personal and enterprise storage spaces, preventing unauthorized data sharing.
Containerization creates a secure encrypted partition managed by MDM.
2
Analyze the requirement to block installations from unverified app stores.
Identify that disabling application sideloading enforces software installation strictly from trusted software repositories.
Sideloading bypasses platform security vetting and increases malware risks.

Anahtar Kavram

Mobile Device Management (MDM) BYOD controls including containerization and restricting application sources (sideloading restrictions).
Bu soruyu puanla