220-1101 Question 47
Single answerPolicy enforcementA company allows employees to use personal smartphones for email and calendaring. A technician notices several users have not set a screen lock, and one lost phone recently contained synchronized corporate email. Management wants a solution that can enforce security settings on enrolled mobile devices without requiring technicians to manually configure each phone. Which of the following is the BEST way to enforce this policy?
- A
Deploy a mobile device management (MDM) solution and require enrolled devices to use passcodes and other compliance settings
- B
Enable Bluetooth pairing restrictions on the wireless access points used by employees
- C
Install a stronger antivirus app on each user's desktop computer to protect synchronized mobile data
- D
Require users to sign an acceptable use policy form stating they will lock their phones
Show answer and explanation
Correct answer: A
Explanation
The best answer is to deploy an MDM solution. In A+ Core 1, policy enforcement for mobile devices commonly involves mobile device management because it allows an organization to centrally apply and monitor settings such as passcodes, screen locks, device encryption, remote wipe, and compliance status. This is especially relevant in BYOD environments where corporate data is accessed from personal devices. Administrative controls such as acceptable use policies are important, but they do not technically enforce compliance. Best practices from major platform vendors and enterprise mobility guidance consistently recommend centralized management tools for enforcing mobile security baselines on enrolled devices.
- A. Correct.
Correct. An MDM solution is the standard administrative tool for enforcing mobile security policies such as screen locks, passcode complexity, encryption, remote wipe, and compliance checks on smartphones and tablets. This directly addresses the need to centrally enforce settings on enrolled BYOD or corporate-owned devices rather than relying on manual configuration.
- B. Incorrect.
Incorrect. Wireless access point Bluetooth restrictions do not enforce smartphone lock-screen or passcode policy. Bluetooth and Wi-Fi are separate technologies, and even limiting wireless connectivity would not ensure a lost device is protected from unauthorized local access.
- C. Incorrect.
Incorrect. Desktop antivirus does not control security settings on a user's smartphone. Although endpoint protection is important, it does not solve the mobile policy enforcement problem described in the scenario.
- D. Incorrect.
Incorrect. Having users sign an acceptable use policy helps communicate expectations, but it is an administrative control rather than a technical enforcement mechanism. The scenario specifically asks for a way to enforce settings without relying on users or manual technician intervention.