The correct answer is D. Set Passwords for Apps to Restrict Others from Accessing Them.
The device already has an operating system passcode, but the weakness appears after the phone is unlocked. The financial application opens directly to sensitive dashboards without requiring any additional application-level authentication. The most direct mitigation is to require a separate password, PIN, biometric prompt, or reauthentication control for sensitive corporate applications.
CEH mobile/BYOD material explains that BYOD introduces security and control challenges because personally owned smartphones and tablets access organizational resources. Mobile Device Management solutions commonly enforce policies such as passcodes, remote locking, remote wipe, root/jailbreak detection, application deployment, monitoring, and policy enforcement .
Option A. Use Encryption Mechanism to Store Data is important for protecting data at rest, especially if the device is lost, but it does not stop access after the phone is already unlocked.
Option B. Set a Strong Passcode on the Device and Change It Relatively Often is already partially implemented because the OS requires a passcode. The issue is lack of app-level verification.
Option C. Maintain a Clear Separation between Business and Personal Data is useful for BYOD governance, but it does not directly prevent an unlocked device from opening sensitive dashboards.
Option D. Set Passwords for Apps to Restrict Others from Accessing Them is correct because it directly mitigates unauthorized access to corporate apps after device unlock.
Therefore, the best answer is D. Set Passwords for Apps to Restrict Others from Accessing Them.