Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium

A company is implementing a new BYOD (Bring Your Own Device) policy. To mitigate the risk of malware or data leakage from personal applications and data interfering with corporate resources on an employee's device, they decide to create isolated environments for corporate applications. What security concept is being utilized?

  1. AFull Disk Encryption (FDE)
  2. BData Loss Prevention (DLP)
  3. CApplication Sandboxing
  4. DVirtual Private Network (VPN)
Show answer & explanation

Correct answer: C. Application Sandboxing

Application sandboxing creates an isolated execution environment for applications, restricting their access to system resources and other applications. In a BYOD context, this prevents personal apps from accessing or corrupting corporate data and vice versa, mitigating risks of malware spread and data leakage.

Why the other options are wrong

  • A. FDE encrypts the entire disk, protecting data at rest, but doesn't isolate applications during use.
  • B. DLP monitors and prevents sensitive data from leaving the organization, but doesn't create isolated app environments.
  • D. A VPN provides a secure, encrypted connection to a private network, not application isolation on an endpoint.

Application Sandboxing

A security mechanism for isolating applications in a restricted execution environment (a 'sandbox'). This limits the application's access to system resources, other applications, and sensitive data, preventing malicious or buggy software from affecting the rest of the system.

  • Isolates applications.
  • Restricts resource access.
  • Prevents malware spread.
  • Common in web browsers, mobile OS, and BYOD.

Memory trick: Sandboxing is like putting a naughty child in a playpen.

More Security Concepts questions