220-1101 Question 46
Single answerBring your own device (BYOD)A small accounting firm allows employees to use personal smartphones and tablets to access company email and cloud storage. After a former employee leaves, management discovers that confidential client files are still synced to the employee's personal tablet. The firm wants to continue its BYOD program but reduce the risk of company data remaining on personal devices after employees leave. Which solution would BEST address this requirement?
- A
Implement a mobile device management (MDM) solution that can enforce security policies and perform selective remote wipes of corporate data
- B
Require all employees to connect only through the office Wi-Fi so the company can block access when employment ends
- C
Disable device screen locks because they can prevent IT from accessing the device during offboarding
- D
Allow access only from devices using the same mobile operating system to simplify user support
Show answer and explanation
Correct answer: A
Explanation
The best answer is to use mobile device management (MDM) with selective wipe capabilities. BYOD programs create a separation challenge between corporate and personal data. Best practice is to manage only the business portion of the device by applying policies, requiring authentication controls, and removing company data during offboarding without affecting personal files. This aligns with common enterprise mobility management practices and guidance from major platform vendors and Microsoft/Google/Apple administrative documentation, which emphasize managed profiles, policy enforcement, and remote or selective data removal for corporate-owned and personally owned devices. Blocking network access alone is not enough because it does not remove already-synced data, and weakening device security controls would increase risk rather than reduce it.
- A. Correct.
Correct. In a BYOD environment, an MDM platform is a standard way to manage personal mobile devices that access organizational resources. MDM can enforce policies such as encryption, passcodes, and approved apps, and many solutions support selective wipe or removal of corporate profiles, email, certificates, and managed data without erasing the employee's personal content. This directly addresses the offboarding problem described in the scenario.
- B. Incorrect.
Incorrect. Restricting access to office Wi-Fi might limit where devices connect from, but it does not solve the core issue of company data already stored on a personal device. Once files or email have been synced locally, simply blocking future network access does not remove the existing data from the device.
- C. Incorrect.
Incorrect. Screen locks are an important mobile security control, not an obstacle to be removed. Disabling them would weaken BYOD security by making lost or stolen devices easier to access. Offboarding should be handled through management tools and account controls, not by reducing device security.
- D. Incorrect.
Incorrect. Standardizing on one mobile operating system may reduce support complexity, but it does not provide a mechanism to remove company data after termination. The scenario is specifically about protecting organizational data on personal devices, which requires management and data control rather than OS uniformity.