Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium

A company is implementing a bring-your-own-device (BYOD) policy. To mitigate the risk of malware spreading from personal devices to the corporate network, the security team decides to isolate corporate applications and data within a secure, encrypted container on each employee's device. What endpoint security concept does this strategy represent?

  1. APatch Management
  2. BApplication Sandboxing
  3. CEndpoint Detection and Response (EDR)
  4. DMobile Device Management (MDM)
Show answer & explanation

Correct answer: B. Application Sandboxing

Application sandboxing involves isolating applications and their data in a restricted environment, preventing them from interacting with other parts of the system or network. In a BYOD context, this strategy creates a secure container for corporate resources, limiting the impact of potential malware on the personal device.

Why the other options are wrong

  • A. Patch management focuses on updating software to fix vulnerabilities, not isolating applications.
  • C. EDR focuses on detecting and responding to threats on endpoints, not primarily on isolating applications proactively.
  • D. MDM is a broader strategy for managing and securing mobile devices, but 'sandboxing' specifically describes the isolation technique.

Application Sandboxing

A security mechanism for isolating running programs, usually to mitigate system failures or software vulnerabilities from spreading.

  • Creates a restricted environment for applications.
  • Limits access to system resources and other applications.
  • Crucial for security in BYOD and web browsing.

Memory trick: Sandbox: A safe play area for apps, separate from the rest of the device.

More Security Concepts questions