220-1102 Question 818
Single answerPolicyA company allows employees to use their own smartphones to access corporate email and internal web applications. After a recent incident involving a lost phone that was not screen-locked, management asks the help desk to recommend a policy change that will reduce the risk of data exposure on personally owned devices without banning BYOD. Which policy would BEST address this requirement?
- A
Acceptable use policy requiring employees to avoid personal apps during work hours
- B
BYOD policy requiring device encryption, screen locks, and remote wipe capability before access is granted
- C
Password policy requiring users to change their network password every 30 days
- D
Incident response policy defining who to contact after a device is lost
Show answer and explanation
Correct answer: B
Explanation
The best answer is the BYOD policy because the scenario is specifically about personally owned mobile devices accessing business data. In A+ Core 2, policy questions often focus on matching the correct policy type to the business problem. A BYOD policy should define security requirements for employee-owned devices, such as passcodes or biometric locks, device encryption, remote wipe support through mobile device management or similar controls, and conditions for access to company resources. These measures align with common organizational security best practices and help protect data if a device is lost or stolen. By contrast, an acceptable use policy governs user behavior, a password policy governs authentication requirements, and an incident response policy defines what to do after an event rather than preventing the event.
- A. Incorrect.
This is incorrect. An acceptable use policy defines appropriate behavior when using company resources, such as prohibited activities or general usage expectations. While it may help with conduct and compliance, it does not specifically enforce technical controls on personally owned devices to reduce the risk from a lost or stolen phone.
- B. Correct.
This is correct. A BYOD policy is specifically designed to govern personally owned devices used for business purposes. Requiring encryption, a screen lock, and remote wipe capability directly addresses the risk of unauthorized access and data exposure if a device is lost. These are standard mobile security controls commonly required before granting access to corporate resources.
- C. Incorrect.
This is incorrect. A password policy can improve account security, but changing network passwords every 30 days does not directly mitigate the risk posed by an unprotected lost smartphone. The primary issue in the scenario is missing device-level security controls, not the age of the user's network password.
- D. Incorrect.
This is incorrect. An incident response policy is important for defining reporting and escalation steps after a loss or breach occurs, but it is reactive rather than preventive. The scenario asks for a policy change that reduces the likelihood of data exposure on BYOD devices before an incident happens.