200-201 Question 323
Select 3A company has implemented a Mobile Device Management (MDM) solution to secure employee devices accessing corporate resources. During a security review, it was discovered that several unmanaged devices had connected to the corporate network. Which of the following steps should the security operations team take to prevent this issue in the future?
- A
Enforce device enrollment into the MDM before granting network access.
- B
Implement network access control (NAC) to block unmanaged devices.
- C
Disable Wi-Fi access for all mobile devices on the corporate network.
- D
Configure the MDM to require multi-factor authentication (MFA) for device registration.
- E
Allow unmanaged devices to connect but enforce stronger password policies.
Show answer and explanation
Correct answers: A, B, D
Explanation
To prevent unmanaged devices from accessing the corporate network, the security operations team should ensure that all devices are enrolled in the MDM solution. Network access control (NAC) can block unauthorized devices, providing an additional layer of security. Furthermore, requiring multi-factor authentication (MFA) during registration strengthens the enrollment process, ensuring that only authorized users and devices can access corporate resources.
- A. Correct.
Enforcing device enrollment into the MDM ensures that only managed devices are permitted to access corporate resources, enhancing security.
- B. Correct.
Implementing network access control (NAC) adds another layer of defense by blocking unmanaged devices from connecting to the corporate network.
- C. Incorrect.
Disabling Wi-Fi access for all mobile devices would disrupt legitimate business operations and is not a practical security solution.
- D. Correct.
Requiring multi-factor authentication (MFA) during MDM enrollment strengthens the security of the enrollment process, making it harder for unauthorized devices to register.
- E. Incorrect.
Allowing unmanaged devices to connect and enforcing password policies does not address the core issue of preventing unauthorized access to the corporate network.