220-1102 exam dumps

220-1102 practice question 514 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 514

Single answerRemote wipes

A sales manager reports that her company-issued smartphone was left in a rideshare vehicle and cannot be recovered. The phone contains corporate email, cached customer documents, and VPN access. The device is enrolled in the company's mobile device management (MDM) platform and is currently showing as online. Which action should the technician take FIRST to best protect company data?

  1. A

    Initiate a remote wipe from the MDM console and document the incident

  2. B

    Send a text message to the phone asking the finder to return it

  3. C

    Disable the user's email account and wait to see if the phone reconnects later

  4. D

    Remove the device from the MDM platform so it can no longer receive management policies

Show answer and explanation

Correct answer: A

Explanation

For a lost or stolen managed mobile device containing organizational data, best practice is to use the organization's MDM/UEM platform to issue a remote lock or wipe as appropriate, especially when the device is online and recovery is uncertain. In this scenario, the strongest immediate control to protect data confidentiality is a remote wipe. CompTIA A+ Core 2 expects candidates to understand mobile device security procedures such as remote wipe, device lock, and account protection in response to loss or theft. In real environments, technicians should also follow company incident-response policy, document the event, and notify security or management as required. Platform guidance from major vendors such as Microsoft Intune, Apple device management documentation, and Android Enterprise management practices all support using centralized management tools to retire, wipe, or otherwise secure lost corporate devices.

  • A. Correct.

    Correct. Because the device is company-owned, contains sensitive corporate data, is enrolled in MDM, and is currently online, initiating a remote wipe is the most appropriate first step to protect data. Documenting the incident is also part of normal security and incident-response procedure. A remote wipe is specifically intended to remove data from a lost or stolen managed device.

  • B. Incorrect.

    Incorrect. Contacting the finder might seem reasonable for asset recovery, but it does not adequately protect sensitive company data and delays the security response. If the device is accessible to an unauthorized person, the priority is to protect the organization's information, not to rely on voluntary return.

  • C. Incorrect.

    Incorrect. Disabling email access may reduce some exposure, but it does not remove locally stored email, cached files, saved VPN settings, or other corporate data already present on the device. It is a partial mitigation, not the best first action when a remote wipe is available and the device is online.

  • D. Incorrect.

    Incorrect. Removing the device from MDM would be counterproductive because it could prevent the organization from sending the remote wipe or other management commands. The common misconception is that unenrolling a device increases security, but in this scenario it can eliminate the organization's ability to control the lost phone.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam