Correct Answer: Clear onboarding requirements tied to user authentication, certificate-based device registration, appropriately scoped authorization distinct from fully managed corporate devices, and a defined device lifecycle (including revocation when a device is lost or an employee departs)
Explanation: Clear onboarding tied to authentication, certificate-based registration, appropriately scoped authorization, and defined lifecycle management (including revocation) together support a secure, manageable BYOD program, unlike shared-password unrestricted access with no registration, certificates with no expiration/revocation, unrestricted access for all onboarded devices, skipping authentication before certificate issuance, or never revoking access after departure.
Correct Answer: Clear onboarding requirements tied to user authentication, certificate-based device registration, appropriately scoped authorization distinct from fully managed corporate devices, and a defined device lifecycle (including revocation when a device is lost or an employee departs)
Explanation: Clear onboarding tied to authentication, certificate-based registration, appropriately scoped authorization, and defined lifecycle management (including revocation) together support a secure, manageable BYOD program, unlike shared-password unrestricted access with no registration, certificates with no expiration/revocation, unrestricted access for all onboarded devices, skipping authentication before certificate issuance, or never revoking access after departure.