CRISC Information Technology and Security Practice Question
A risk practitioner is assessing a proposed bring-your-own-device (BYOD) programme for a law firm where attorneys will access matter files containing privileged client data. The CISO asks which controls are MOST important to reduce the risk of data leakage from lost or compromised personal devices. (Choose two.)
⚠ Common exam trap
The trap here is selecting policy or insurance options because they sound comprehensive, when the scenario asks specifically for controls that reduce data leakage from lost or compromised personal devices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy mobile device management (MDM) with remote wipe and containerization of firm data.
The two controls that actually prevent privileged client data from being exposed when a personal device is lost or compromised are escrowed full-device encryption and MDM with remote wipe plus containerization. Together they protect data at rest and allow selective removal of firm data, while the other choices are policy, perimeter, or financial measures that do not stop the leakage scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require attorneys to sign an acceptable use policy acknowledging that personal devices may be inspected.
Why it's wrong here
An acceptable use policy establishes expectations and legal grounds for inspection, but it is a governance artifact with no technical enforcement. A lost device will not protect privileged data because a signed document exists; the firm still needs encryption and remote wipe to actually prevent disclosure.
- ✗
Block all access to matter files from outside the firm's office network by IP allowlisting.
Why it's wrong here
IP allowlisting would defeat the purpose of BYOD, since attorneys are expected to work from home, court, and client sites. It is a network-perimeter control that does not travel with the device, so a device stolen while connected to an approved network still exposes cached or stored privileged data.
- ✗
Increase cyber insurance limits to cover regulatory fines from client data breaches.
Why it's wrong here
Insurance transfers financial consequence but does nothing to reduce the likelihood or magnitude of privileged data leakage, which is the risk the CISO asked about. It is also a poor fit for a law firm's ethical and contractual duties to safeguard client confidences, which cannot be fully indemnified.
- ✓
Deploy mobile device management (MDM) with remote wipe and containerization of firm data.
Why this is correct
MDM with remote wipe and a managed container lets the firm selectively remove or lock matter files without erasing the attorney's personal photos and apps. Containerization keeps privileged data inside an encrypted, policy-controlled space, so a compromised personal app cannot freely read or exfiltrate client information.
- ✓
Enforce full-device encryption with keys escrowed by the firm and require a device passcode.
Why this is correct
Escrowed full-device encryption ensures that if a personal device is lost or stolen, the privileged client data on it remains unreadable, and the firm retains recovery capability if the attorney leaves. This directly addresses the confidentiality loss scenario and is the most fundamental control for mobile data at rest in a BYOD context.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.