100-160 exam dumps

100-160 practice question 139 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 139

Select 3

Your organization has implemented a Bring Your Own Device (BYOD) policy. A cybersecurity audit reveals that sensitive customer data is being accessed from an employee's personal device that lacks encryption and proper configuration for secure access. Which of the following steps should be taken to address this issue while ensuring compliance with regulatory standards such as GDPR and HIPAA?

  1. A

    Implement mandatory encryption for all personal devices accessing company data.

  2. B

    Require employees to install a mobile device management (MDM) solution for configuration and app distribution.

  3. C

    Restrict BYOD usage and require employees to only use company-issued devices for work-related tasks.

  4. D

    Develop a policy to conduct regular security audits on employee personal devices.

  5. E

    Ensure employees sign a waiver stating the company is not responsible for data breaches on personal devices.

Show answer and explanation

Correct answers: A, B, D

Explanation

To address the issue of unsecured personal devices in a BYOD environment, it is essential to implement encryption, use an MDM solution for secure configuration management, and conduct regular security audits. These measures help protect sensitive data and ensure compliance with regulatory standards such as GDPR and HIPAA. Simply restricting BYOD or relying on waivers does not align with the organization's policy or address the core cybersecurity risks.

  • A. Correct.

    Correct: Encryption is critical for protecting sensitive data on personal devices and is often a regulatory requirement under frameworks like GDPR and HIPAA.

  • B. Correct.

    Correct: An MDM solution helps enforce security policies, distribute approved apps, and manage device configurations remotely, ensuring secure access to company data.

  • C. Incorrect.

    Incorrect: While this would eliminate BYOD risks, it contradicts the organization's existing BYOD policy and may not be a practical or preferred solution for the organization.

  • D. Correct.

    Correct: Regular security audits on personal devices are necessary to ensure compliance with company policies and regulatory standards.

  • E. Incorrect.

    Incorrect: A waiver does not mitigate the actual security risks or ensure compliance with regulatory standards like GDPR and HIPAA.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam