312-50 exam dumps

312-50 practice question 402 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 402

Single answer▪ Mobile Device Management

A company allows employees to use personal smartphones to access corporate email and internal web applications. During a security assessment, you discover that several devices are jailbroken or rooted, some are missing disk encryption, and one lost phone still has an active corporate email profile. Management wants a Mobile Device Management (MDM) control set that reduces data leakage risk without fully banning BYOD. Which action would be the MOST effective first step to enforce consistent security across enrolled devices?

  1. A

    Deploy an MDM policy that checks device compliance before granting access, requiring screen lock, encryption, and blocking rooted or jailbroken devices; enable selective wipe for corporate data on lost devices

  2. B

    Rely on user awareness training and require employees to sign an acceptable use policy acknowledging they will protect corporate data on their personal devices

  3. C

    Install endpoint antivirus on employee laptops so malware cannot spread from mobile devices into the corporate network

  4. D

    Disable Wi-Fi on all mobile devices and allow access only through cellular networks to reduce exposure to internal threats

Show answer and explanation

Correct answer: A

Explanation

In a BYOD environment, the most practical and defensible first step is to enforce device compliance through MDM before granting access to corporate resources. Common MDM best practices include requiring passcodes or screen locks, enforcing device encryption where supported, identifying rooted or jailbroken devices as noncompliant, and enabling remote or selective wipe for corporate data when a device is lost or an employee separates from the organization. This aligns with enterprise mobility security guidance from major platform and vendor documentation, including Microsoft Intune, VMware Workspace ONE, and mobile platform enterprise guidance from Apple and Android Enterprise. From a CEH perspective, the key point is understanding how attackers can exploit weak mobile governance and how technical controls such as compliance enforcement, access control, and selective wipe reduce attack surface and data leakage risk more effectively than policy-only measures.

  • A. Correct.

    Correct. This is the most effective first step because it uses core MDM capabilities to enforce baseline security controls consistently before allowing access to corporate resources. Compliance checks can identify rooted or jailbroken devices, verify encryption and screen-lock requirements, and deny or quarantine noncompliant devices. Selective wipe is especially appropriate in BYOD environments because it removes corporate data without necessarily erasing personal data. This directly addresses the scenario's problems: unmanaged access, weak device posture, and risk from lost devices.

  • B. Incorrect.

    Incorrect. Security awareness and acceptable use policies are helpful administrative controls, but they do not technically enforce encryption, screen lock, root/jailbreak detection, or remote removal of corporate data. In this scenario, the company already has real device-level risk, so policy alone is insufficient.

  • C. Incorrect.

    Incorrect. Protecting laptops does not solve the primary issue, which is insecure mobile devices directly accessing corporate email and applications. Even if laptop antivirus is useful elsewhere, it does not enforce mobile compliance, detect rooted phones, or wipe data from a lost smartphone. This option reflects a scope mismatch.

  • D. Incorrect.

    Incorrect. Disabling Wi-Fi does not address the central MDM problems in the scenario. Devices could still be lost, rooted, unencrypted, or retain active corporate profiles over cellular connections. Also, many corporate mobile threats are related to device posture and data governance rather than whether traffic uses Wi-Fi or cellular.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam