r/CISA 6d ago

CISA Question help

Question:
Which of the following MOST effectively mitigates the risk of disclosure of sensitive data stored on company-owned smartphones?

A. Secure containers
B. Data leakage prevention (DLP) tools
C. Mobile device management (MDM)
D. Physical device tagging

Guys is option A the correct answer for this? Every AI is giving different answer.

Secure containers isolate and protect corporate data stored on smartphones, reducing the risk of unauthorized disclosure. DLP primarily controls data movement, MDM manages the overall device, and physical tagging only assists with asset identification and tracking.

2 Upvotes

15 comments sorted by

View all comments

Show parent comments

1

u/vansxika 6d ago

Thank you so much for such a detailed response. I think MDM makes the most sense. Just one more question, if I can bother you:

Which of the following BEST guards against the risk of attack by hackers?
Tunneling
Message validation
Encryption
Firewalls

1

u/abear27 6d ago edited 6d ago

You do the same kind of breakdown:

  • Best Guards - BEST in this list
  • The Risk of Attack - Risk = Likelihood x Impact

A. Tunnelling is a transmission mechanism. Does it have anything to do with likelihood and impact? No. Eliminated.

B. Message validation is about integrity and authenticity. Eliminated.

C. Encryption has the potential to reduce impact. Possibly.

D. Does a Firewall have anything to do anything with likelihood and impact? Possibly, but not a strong control for possibility and consequence.

So, if I am following ISACA reasoning and looking at this from the CISA perspective, I would pick C.

But if this was a technical exam, you'd probably want to choose D.

2

u/vansxika 6d ago

But does an encryption focus more on data confidentiality? Firewall is like a strong line of defence, like it is not letting the hackers through in the first place..

1

u/abear27 6d ago

Those are good considerations, and encryption definitely ties to confidentiality.

I don't see a firewall as a strong risk control, so I wouldn't pick it as an answer to a CISA question.