Courseiva
easyMultiple Choice

CAS-004 Practice Question: A security administrator needs to secure remote…

A security administrator needs to secure remote access for employees using personal devices. The company requires that company data be encrypted and that the device be wiped if lost. Which solution best meets these requirements?

⚠ Common exam trap

It's easy for candidates to confuse network-level controls (NAC, VPN) or access methods (RDP) with device-level data protection, failing to recognize that only MDM provides the required encryption enforcement and remote wipe capabilities on the endpoint itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a mobile device management (MDM) solution that enforces device encryption and supports remote wipe.

Mobile device management (MDM) solutions are specifically designed to enforce security policies on personal devices, including mandatory device encryption (e.g., AES-256 for data at rest) and the ability to perform a remote wipe (factory reset) to destroy company data if the device is lost or stolen. This directly addresses the requirement to protect company data on unmanaged, employee-owned devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use network access control (NAC) to allow only compliant devices onto the network.

    Why it's wrong here

    NAC enforces admission policy at the network edge; it cannot encrypt data at rest on a personal device nor trigger a remote wipe when that device is lost. It is tempting because NAC is the right control for keeping non-compliant endpoints off a corporate LAN, not for protecting data on unmanaged mobile hardware.

  • ✓

    Deploy a mobile device management (MDM) solution that enforces device encryption and supports remote wipe.

    Why this is correct

    MDM enforces encryption at the device level and provides remote wipe, satisfying both stated requirements for personal devices. Unlike app-level controls, it manages the whole device, ensuring company data is encrypted and can be erased if lost. This directly meets the encryption and wipe constraints in the scenario.

  • ✗

    Require employees to connect via a corporate VPN and use two-factor authentication.

    Why it's wrong here

    A VPN with two-factor authentication protects data in transit and strengthens login, but neither encrypts company data stored locally on the personal device nor wipes that device if lost. It is tempting because VPN plus MFA is the standard answer for securing remote connections to internal resources.

  • ✗

    Implement remote desktop protocol (RDP) gateways for all remote access.

    Why it's wrong here

    RDP gateways broker remote sessions to internal hosts, so data stays server-side, but they provide no mechanism to encrypt or remotely wipe company data already resident on the personal device. They are tempting because RDP gateways are correct when centralising access to desktop environments for thin-client or contractor scenarios.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.