QuestionQ75

Security Engineering

During a gap assessment, an organization determines that BYOD use presents a significant risk. The organization has implemented administrative policies that prohibit BYOD use. However, it has not implemented technical controls to prevent unauthorized BYOD assets from accessing the organization's resources. Which of the following solutions should the organization implement to best mitigate the risk posed by BYOD devices?

Choose two
  • A Cloud IAM, to enforce the use of token-based MFA
  • B Conditional access, to enforce user-to-device binding
  • C NAC, to enforce device configuration requirements
  • D PAM, to enforce local password policies
  • E SD-WAN, to enforce web content filtering through external proxies
  • F DLP, to enforce data protection capabilities
Explanation

Conditional access can require a device to be registered and marked compliant before access to organizational resources is granted, tying user access to an approved device. NAC enforces endpoint posture and device-configuration requirements, blocking, restricting, or quarantining devices that do not meet policy. Together, these controls prevent unauthorized or noncompliant BYOD endpoints from gaining access.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!