easyMultiple Choice
CAS-004 Practice Question: A security administrator needs to secure remote…
A security administrator needs to secure remote access for employees using personal devices. The company requires that company data be encrypted and that the device be wiped if lost. Which solution best meets these requirements?
⚠ Common exam trap
It's easy for candidates to confuse network-level controls (NAC, VPN) or access methods (RDP) with device-level data protection, failing to recognize that only MDM provides the required encryption enforcement and remote wipe capabilities on the endpoint itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a mobile device management (MDM) solution that enforces device encryption and supports remote wipe.
Mobile device management (MDM) solutions are specifically designed to enforce security policies on personal devices, including mandatory device encryption (e.g., AES-256 for data at rest) and the ability to perform a remote wipe (factory reset) to destroy company data if the device is lost or stolen. This directly addresses the requirement to protect company data on unmanaged, employee-owned devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use network access control (NAC) to allow only compliant devices onto the network.
Why it's wrong here
NAC enforces admission policy at the network edge; it cannot encrypt data at rest on a personal device nor trigger a remote wipe when that device is lost. It is tempting because NAC is the right control for keeping non-compliant endpoints off a corporate LAN, not for protecting data on unmanaged mobile hardware.
- ✓
Deploy a mobile device management (MDM) solution that enforces device encryption and supports remote wipe.
Why this is correct
MDM enforces encryption at the device level and provides remote wipe, satisfying both stated requirements for personal devices. Unlike app-level controls, it manages the whole device, ensuring company data is encrypted and can be erased if lost. This directly meets the encryption and wipe constraints in the scenario.
- ✗
Require employees to connect via a corporate VPN and use two-factor authentication.
Why it's wrong here
A VPN with two-factor authentication protects data in transit and strengthens login, but neither encrypts company data stored locally on the personal device nor wipes that device if lost. It is tempting because VPN plus MFA is the standard answer for securing remote connections to internal resources.
- ✗
Implement remote desktop protocol (RDP) gateways for all remote access.
Why it's wrong here
RDP gateways broker remote sessions to internal hosts, so data stays server-side, but they provide no mechanism to encrypt or remotely wipe company data already resident on the personal device. They are tempting because RDP gateways are correct when centralising access to desktop environments for thin-client or contractor scenarios.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.