Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GIAC Exam GCCC Topic 1 Question 57 Discussion

Actual exam question for GIAC's GCCC exam
Question #: 57
Topic #: 1
[All GCCC Questions]

Executive management approved the storage of sensitive data on smartphones and tablets as long as they were encrypted. Later a vulnerability was announced at an information security conference that allowed attackers to bypass the device's authentication process, making the data accessible. The smartphone manufacturer said it would take six months for the vulnerability to be fixed and distributed through the cellular carriers. Four months after the vulnerability was announced, an employee lost his tablet and the sensitive information became public.

What was the failure that led to the information being lost?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

Claudia
2 days ago
D? Really? I mean, insuring against lost data is a good idea, but it doesn't solve the root cause here. They needed to have a proper risk management process in place.
upvoted 0 times
...
Ranee
3 days ago
I'm going with C. They should have done vulnerability scans to identify which devices were at risk and prioritize patching them. Letting the vulnerability linger for 4 months is just unacceptable.
upvoted 0 times
...
Jean
14 days ago
But shouldn't management have insured against the possibility of the information being lost? That could have prevented this situation too.
upvoted 0 times
...
Becky
17 days ago
I think A is the right answer here. The organization should have reviewed the risk after that vulnerability was announced and made a decision to accept or mitigate it. Relying on the manufacturer's timeline was a major oversight.
upvoted 0 times
...
Elin
18 days ago
Come on, the answer is clearly B. The employees should have kept their devices updated, that's just basic security hygiene. I can't believe they let this happen!
upvoted 0 times
...
Claudia
18 days ago
I agree with Dalene. If they had updated their devices, maybe the vulnerability could have been fixed before the information was lost.
upvoted 0 times
...
Dalene
24 days ago
I think the failure was that employees failed to maintain their devices at the most current software version.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77