220-1102 exam dumps

220-1102 practice question 496 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 496

Select 22.8 Given a scenario, apply common methods for securing mobile devices.

A company allows sales staff to use corporate-owned smartphones to access email, customer records, and a VPN connection while traveling. After one phone was left in a taxi, management asks a technician to recommend controls that will best reduce the risk of data exposure if a device is lost or stolen. Which TWO actions should the technician recommend?

  1. A

    Require a strong screen lock and configure the device to wipe after repeated failed unlock attempts

  2. B

    Disable device encryption to improve battery life and rely on the SIM card PIN for protection

  3. C

    Enable remote lock and remote wipe through the organization's mobile device management platform

  4. D

    Turn off automatic OS and app updates so users are not interrupted during travel

  5. E

    Allow users to install any app they want as long as they avoid public Wi-Fi

Show answer and explanation

Correct answers: A, C

Explanation

The best answers are to enforce a strong screen lock with wipe protections and to enable remote lock/wipe through MDM. For A+ Core 2 mobile device security, common protective methods include screen locks, biometrics, encryption, remote wipe/locator services, MDM policies, and keeping devices patched. Industry best practices from Apple, Google Android Enterprise, and major MDM vendors consistently recommend passcode enforcement, encryption, and remote management for lost-device scenarios. SIM PINs are much more limited than device encryption, and disabling updates or allowing unrestricted apps weakens security rather than improving it.

  • A. Correct.

    This is correct. Requiring a strong screen lock such as a complex PIN, passcode, or biometric backed by a passcode helps prevent casual access to a lost device. Configuring the device to erase data after too many failed login attempts further reduces the chance of brute-force access. This is a common mobile security best practice for protecting locally stored corporate data.

  • B. Incorrect.

    This is incorrect. Disabling device encryption weakens security significantly. Full-device or file-based encryption is a key control for protecting data at rest on mobile devices. A SIM PIN only protects the subscriber identity module from unauthorized cellular use; it does not secure the phone's stored email, files, apps, or cached business data.

  • C. Correct.

    This is correct. Remote lock and remote wipe are standard features in enterprise mobile device management (MDM) or unified endpoint management (UEM) solutions. If a phone is lost or stolen, IT can quickly lock the device, locate it where permitted, and erase corporate data to reduce exposure. This is one of the most effective administrative and technical safeguards for mobile devices used outside the office.

  • D. Incorrect.

    This is incorrect. Disabling operating system and application updates increases risk because security patches would not be applied. Mobile platforms frequently receive updates to fix vulnerabilities and improve protections. Preventing updates for convenience is contrary to security best practices.

  • E. Incorrect.

    This is incorrect. Allowing unrestricted app installation increases the risk of malicious, overly permissive, or data-leaking applications being installed. Avoiding public Wi-Fi alone does not address the larger threat of insecure apps, phishing, excessive permissions, or malware. In managed business environments, app control or approved app lists are preferred.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam