A mid-size company has no formal policy on mobile hotspot use. Employees regularly tether work laptops to personal phone hotspots to bypass the corporate Wi-Fi filtering. The IT team notices this trend during a network review.
An enterprise security team learns that employees use their personal mobile phones as Wi-Fi hotspots for work laptops. What are the two primary security risks this practice introduces?
- A.(1) The handset's IMEI reaches each tethered laptop because the DHCP option set carries it (the identifier may then be logged by any software there); (2) the carrier typically throttles a tethered session, and the slower link pushes staff back onto public Wi-Fi.
- B.(1) Corporate traffic bypasses perimeter controls (firewall, web proxy, DLP) because it routes through the carrier network rather than the corporate network; (2) the hotspot password may be weak or shared, enabling neighboring devices to join and intercept traffic.
- C.