🏠 Back to Exam Syllabus πŸ“Ί RooCloud on YouTube 🎯 Free CISSP Practice Test

CISSP 9.18 - Mobile Devices (Part 3 of 3)

This episode of the ISC2 Certified Information Systems Security Professional (CISSP) exam prep series closes out the Domain 3 coverage of mobile security, turning from technology to policy β€” how organizations decide whose devices get onto the network, who owns what when things go wrong, and which everyday features deserve a closer look before trouble hits.

What this episode covers

Watch the full episode above for the worked examples and detailed explanations of each concept.

Frequently Asked Questions

How do you handle the flood of credentials on mobile devices?

A credential manager, also called a password vault, securely stores all of a user’s logins behind one master credential, ideally a multi-factor one, and some can auto-fill logins for apps and sites. The vault itself is encrypted, and good ones stretch your master password into a strong key using proven key-derivation methods so it resists cracking.

What makes text messaging a weak spot?

Standard texting services, whether basic messages, multimedia, or the richer modern format, all double as attack vectors for phishing sent by text and messaging spam. Texting can also serve as a second authentication factor, but a code sent by text is the weakest option and should give way to any stronger second factor you have. Keep messaging apps updated and keep sensitive content out of them entirely.

Which deployment models let mobile devices onto your network?

There are four common models that trade cost against control. Bring your own device is cheap and popular but the least secure, choose your own device narrows use to an approved list, corporate-owned personally enabled has the company buy devices that workers also use personally, and the corporate-owned business-only strategy keeps devices strictly for work, which is the most secure and cleanly separates work from personal life.

Users must accept that a security incident may mean their device is examined or even seized, and company-owned devices can carry a master account to allow that access. A personal device used for work loses much of its privacy, and workers may have to accept monitoring even off the clock. Personal devices in business use also increase liability and the odds of a leak, so an acceptable use policy should spell out the boundaries.

Which hardware and connection features deserve extra caution?

Onboard cameras and microphones can quietly capture confidential information, so policy should govern where they may be used, and geofencing can even disable a camera on company grounds. Tethering and hotspots let a device become an unauthorized bridge to the internet that sidesteps your filtering, contactless payments can be cloned unless they require a confirmation or an unlocked device, and SIM cloning lets an attacker hijack a victim’s phone service.

πŸ“š Master the ISC2 CISSP Exam!

Reinforce this lesson with real practice. The RooCloud CISSP Practice Pack gives you 6,000+ exam-style questions, 366 section-wise practice tests and 40 full-length adaptive (CAT) tests across all 8 CISSP domains, with full explanations. Start with a FREE full-length adaptive CISSP test β†’


Reference: This article is based on concepts discussed in CISSP 9.18 - Mobile Devices (Part 3 of 3).