220-1102 Question 819
Single answerAppropriate useA technician is configuring smartphones for employees at a financial services company. The company allows mobile devices for business use, but it must reduce the risk of data exposure and legal issues. One employee asks whether it is acceptable to use the company-issued phone to post client account screenshots to a personal social media account to ask friends for advice about a problem. What is the MOST appropriate response from the technician?
- A
It is acceptable if the employee removes the client's name from the screenshot before posting it.
- B
It is acceptable if the social media account is set to private and only trusted friends can view the post.
- C
It is not appropriate because business data should not be shared through personal social media, especially client information or screenshots from a company device.
- D
It is appropriate as long as the employee deletes the post after receiving advice.
Show answer and explanation
Correct answer: C
Explanation
This question focuses on appropriate use in a real workplace scenario. In A+ Core 2, appropriate use includes understanding that company devices, data, and accounts must be used according to organizational policy, security requirements, and legal or regulatory obligations. In a financial environment, client data is especially sensitive, and employees should use approved internal support channels rather than personal social media. Best practices from acceptable use policies, security awareness training, and privacy compliance guidance all support the same conclusion: employees should not share business information, screenshots, or customer data through personal platforms, regardless of privacy settings or later deletion.
- A. Incorrect.
Incorrect. Removing a client's name does not reliably eliminate sensitive information. Screenshots can still contain account numbers, balances, timestamps, internal application details, or other identifying data. Appropriate-use and data-handling policies generally prohibit sharing business information through personal channels, even if some details are redacted.
- B. Incorrect.
Incorrect. A private account does not make the action appropriate. Privacy settings do not guarantee confidentiality, and sharing business or client-related information with unauthorized individuals is still a policy and security violation. This reflects a common misconception that limited visibility makes sensitive-data sharing acceptable.
- C. Correct.
Correct. Appropriate use of company devices includes using them in ways that protect organizational data, customer privacy, and compliance obligations. Posting client-related screenshots to a personal social media account is inappropriate because it exposes potentially sensitive information to unauthorized parties and bypasses approved support and escalation processes.
- D. Incorrect.
Incorrect. Deleting a post later does not prevent exposure. Other users can take screenshots, share the content, or store copies before it is removed. This option is based on the mistaken belief that temporary posting eliminates the security and compliance risk.