How to Secure Company Mobile Devices After Credential Theft?
A threat actor was able to use a username and password to log in to a stolen company mobile device. Which of the following provides the best solution to increase mobile data security on all employees' company mobile devices?
Community Votes
59% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the critical distinction between at-rest cryptographic protection and centralized management capabilities, with the common trap being the assumption that encryption remains viable once an attacker has successfully authenticated with valid credentials.
This question evaluates the most effective organizational control to secure mobile device data after a credential-based breach. While candidates frequently debate endpoint encryption versus centralized management, the exam prioritizes out-of-band remediation strategies that protect corporate data across the entire device fleet.
Candidates typically choose Full Disk Encryption (B), reasoning that it safeguards data at rest. However, this overlooks the scenario's explicit detail that the threat actor already logged in using valid credentials, which bypasses encryption protections, and misses the organizational focus on scalable MDM-driven response.
Community Discussion (33 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Centralized Mobile Management vs. Endpoint Cryptography
The scenario describes a sophisticated attack where physical theft is combined with credential compromise. In modern mobile environments, Full Disk Encryption (FDE) relies on pre-boot authentication or hardware-bound keys to remain effective. Once an attacker possesses both the device and valid login credentials, they can decrypt and access all data, rendering FDE functionally useless for this specific threat vector.Why Remote Wipe is the Correct Choice
Remote wipe is a foundational capability of Mobile Device Management (MDM) platforms designed specifically for this contingency. By deploying remote wipe policies across all corporate devices, organizations ensure that compromised hardware can be instantly sanitized from a central console. As noted in community discussions, multiple candidates highlight that "encryption means nothing once the attacker logs in," making out-of-band data destruction the only reliable method to prevent persistent corporate data exposure.Why Other Options Are Incorrect
- Application management (A) focuses on app lifecycle, permissions, and updates, but does not provide mechanisms to erase sensitive corporate data upon theft.
- Full disk encryption (B) protects against offline attacks and physical loss without credentials, but fails here because authentication has already been bypassed.
- Containerization (D) isolates corporate apps and data from personal user data, which is valuable for BYOD scenarios. However, it does not automatically purge data if the container itself is breached via valid credentials, and it lacks the immediate remediation capability that remote wipe provides.
Official Reference
- https://www.nist.gov/publications/guide-mobile-device-security
- CompTIA Security+ SY0-701 Exam Objectives 4.4 & 5.4
- NIST Special Publication 800-124 Rev. 2, Section 3.2 (Device Lifecycle Management)
Exam Strategy
When a scenario confirms that an attacker has already authenticated successfully, immediately discard cryptographic controls like encryption, as they are designed to prevent unauthorized access, not mitigate post-compromise threats. Instead, pivot your analysis toward centralized management frameworks (MDM/EMM) and out-of-band remediation tools that allow administrators to enforce policies, isolate, or erase data across your entire device fleet.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →