CMO CMO Data Security & Privacy Management 2 — Questions and Answers
Question 1: What is the purpose of audit logging in the Mobilyze platform?
- To increase device battery life
- To record all user actions for accountability and forensic review (Correct answer)
- To synchronize device clocks
- To compress data files
Correct answer: To record all user actions for accountability and forensic review
Audit logs capture a chronological record of user actions, enabling accountability and supporting forensic investigations.
Question 2: Which practice helps prevent unauthorized physical access to Mobilyze field devices?
- Leaving devices unattended in unlocked vehicles
- Using device locks and storing equipment in secured locations when not in use (Correct answer)
- Disabling screen lock for faster startup
- Labeling devices with operator credentials
Correct answer: Using device locks and storing equipment in secured locations when not in use
Physical security measures like device locks and secured storage prevent theft and unauthorized access to Mobilyze hardware.
Question 3: What is the risk of using public Wi-Fi networks to sync Mobilyze data without a VPN?
- Slower sync speed only
- Data may be intercepted by malicious actors through a man-in-the-middle attack (Correct answer)
- Device battery drains faster
- GPS accuracy is reduced
Correct answer: Data may be intercepted by malicious actors through a man-in-the-middle attack
Public Wi-Fi networks are vulnerable to man-in-the-middle attacks, which can expose unencrypted Mobilyze data to attackers.
Question 4: How often should Mobilyze operator access permissions be reviewed according to security best practices?
- Only when an issue is reported
- At least annually or whenever there is a role change (Correct answer)
- Every five years
- Only during device setup
Correct answer: At least annually or whenever there is a role change
Regular access reviews, at minimum annually or after role changes, ensure permissions remain appropriate and reduce unnecessary access.
Question 5: What type of authentication adds the most protection to Mobilyze operator logins beyond a password?
- Security questions
- Multi-factor authentication (MFA) (Correct answer)
- Longer usernames
- Auto-login cookies
Correct answer: Multi-factor authentication (MFA)
MFA requires a second verification step beyond a password, significantly reducing the risk of unauthorized account access.
Question 6: What is the correct approach for disposing of storage media that contained Mobilyze field data?
- Throw it in a standard recycling bin
- Reformat and reuse without any further steps
- Perform certified data destruction or secure wiping per company policy (Correct answer)
- Leave it with the device in storage
Correct answer: Perform certified data destruction or secure wiping per company policy
Certified data destruction or secure wiping ensures that sensitive Mobilyze data cannot be recovered from disposed media.
What is the purpose of audit logging in the Mobilyze platform?