100-160 exam dumps

100-160 practice question 137 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 137

Select 3

A company has implemented a Bring Your Own Device (BYOD) policy to allow employees to use personal devices for work purposes. During a routine audit, the IT team discovers that several personal devices accessing sensitive customer data are not encrypted, posing a compliance risk. Which of the following actions should the IT team prioritize to address this issue while maintaining compliance with regulations like PCI DSS and GDPR?

  1. A

    Require all BYOD devices to enable full-disk encryption.

  2. B

    Restrict access to sensitive data from unencrypted devices.

  3. C

    Mandate the installation of a company-approved mobile device management (MDM) application on all BYOD devices.

  4. D

    Deploy antivirus software on all BYOD devices.

  5. E

    Disable the BYOD policy entirely to eliminate compliance risks.

Show answer and explanation

Correct answers: A, B, C

Explanation

To comply with regulations like PCI DSS and GDPR, organizations must ensure that sensitive data is protected on all devices, including BYOD devices. Enforcing full-disk encryption, restricting access from non-compliant devices, and using an MDM application are effective measures to mitigate risk and maintain compliance. These actions address the specific security risks posed by unencrypted BYOD devices while allowing the organization to continue leveraging the benefits of BYOD.

  • A. Correct.

    Requiring full-disk encryption ensures that sensitive data stored on the device is protected, which is essential for compliance with regulations like PCI DSS and GDPR.

  • B. Correct.

    Restricting access to sensitive data from unencrypted devices prevents unauthorized or non-compliant devices from jeopardizing the security of sensitive information.

  • C. Correct.

    Mandating an MDM application allows the IT team to enforce security policies, such as encryption and remote wipe capabilities, on personal devices accessing corporate data.

  • D. Incorrect.

    While antivirus software is important for overall device security, it does not directly address the issue of compliance related to data encryption or access controls.

  • E. Incorrect.

    Disabling the BYOD policy entirely is an extreme measure that could disrupt business operations and employee productivity. Properly managing BYOD devices is a more practical solution.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam