A mid-size company has no formal policy on mobile hotspot use. Employees regularly tether work laptops to personal phone hotspots to bypass the corporate Wi-Fi filtering. The IT team notices this trend during a network review.
An enterprise security team learns that employees use their personal mobile phones as Wi-Fi hotspots for work laptops. What are the two primary security risks this practice introduces?
- A.C) (1) The phone's IMEI is exposed to all connected laptops, enabling device tracking; (2) carrier throttling degrades productivity but poses no security risk.
- B.B) (1) Hotspot use drains the phone battery, increasing device failure risk; (2) carrier billing overages may exceed the device budget.
- C.A) (1) Corporate traffic bypasses perimeter controls (firewall, web proxy, DLP) because it routes through the carrier network rather than the corporate network; (2) the hotspot password may be weak or shared, enabling neighboring devices to join and intercept traffic.
- D.D) (1) Personal hotspots always use WEP encryption, which is easily cracked; (2) the phone becomes a rogue DHCP server that corrupts corporate IP assignments.