exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 747 discussion

Actual exam question from Isaca's CISM
Question #: 747
Topic #: 1
[All CISM Questions]

Which of the following is the BEST way to reduce the risk associated with a bring your own device (BYOD) program?

  • A. Implement a mobile device policy and standard.
  • B. Provide employee training on secure mobile device practices.
  • C. Implement a mobile device management (MDM) solution.
  • D. Require employees to install an effective anti-malware app.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Souvik124
Highly Voted 2 years, 3 months ago
The best way to reduce the risk associated with a bring your own device (BYOD) program is to implement a mobile device management (MDM) solution. Therefore, the correct answer is option C.
upvoted 8 times
AlexJacobson
1 year, 4 months ago
Literally all you're doing in all questions is copying part of the question and "bolting on" the answer you think is correct (that most likely ChatGPT selected for you).
upvoted 1 times
...
...
03allen
Most Recent 11 months, 2 weeks ago
Selected Answer: C
implement the MDM
upvoted 1 times
...
Cks29
1 year, 3 months ago
I opted A because i think it should be in your policy to use MDM first. Then you implement and configured a solution according to standard. So A encompasses C, but i have seen here the solution is oftenly techincal.
upvoted 1 times
Salilgen
1 year, 3 months ago
Question asks about BEST action not about FIRST action
upvoted 1 times
...
...
SilverFox
1 year, 6 months ago
Selected Answer: C
Implement MDM
upvoted 2 times
...
Marcovic00
1 year, 6 months ago
Selected Answer: C
I always go with technical solutions as policies will not always be followed
upvoted 2 times
...
Bl1024
1 year, 8 months ago
Selected Answer: C
As per johndeer11 answer with ISACA ref.
upvoted 2 times
...
oluchecpoint
1 year, 9 months ago
Selected Answer: C
Option C
upvoted 1 times
...
[Removed]
1 year, 10 months ago
Selected Answer: C
From the CISM Review Manual, 15th Edition, by ISACA: "The information security manager should ensure that an appropriate level of control is maintained for all mobile devices that access corporate resources. Mobile device management (MDM) systems can provide control over mobile devices, allowing the organization to enforce policies, manage device settings, monitor compliance with corporate policies, and remotely wipe or lock lost or stolen devices."
upvoted 4 times
...
richck102
1 year, 11 months ago
C. Implement a mobile device management (MDM) solution.
upvoted 4 times
...
omaigret
2 years, 3 months ago
may be use of FIRST instead of BEST in the question so not to choose MDM as the answer
upvoted 1 times
...
Broesweelies
2 years, 4 months ago
Selected Answer: A
Implementing a mobile device policy and standard is the best way to reduce the risk associated with a bring your own device (BYOD) program. The policy should outline the acceptable use of mobile devices in the workplace and establish guidelines for securing sensitive information and complying with regulatory requirements. The standard should specify the minimum technical requirements for mobile devices, such as encryption, password protection, and anti-malware software, and should also outline the steps that employees must take to secure their devices and protect sensitive information. By establishing a clear policy and standard, the organization can ensure that all mobile devices are used in a secure and compliant manner, which will help to reduce the risk of a security breach. The policy and standard should be communicated to employees and reinforced through training and awareness programs.
upvoted 4 times
...
Boomers
2 years, 4 months ago
Selected Answer: A
Implementing a mobile device policy and standard is the best way to reduce the risk associated with a bring your own device (BYOD) program. A mobile device policy and standard provides clear guidelines for employees on what is expected of them when using their own devices for work purposes. This includes guidelines for secure device configuration, password protection, software updates, and acceptable use of the device. The policy and standard also provide clear instructions on what to do in the event of a lost or stolen device, data breach, or other security incident. By establishing a clear policy and standard for mobile device use, organizations can reduce the risk of security incidents and ensure that sensitive information is protected.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...