SY0-701 exam dumps

SY0-701 practice question 260 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 260

Single answerMobile solutions: Mobile device management (MDM)

A company allows employees to use personal smartphones to access corporate email and documents. After several employees leave the company, the security team discovers that business files may still be stored on those devices. Management wants a solution that protects corporate data on employee-owned phones without deleting personal photos, messages, or apps. Which action should the security administrator implement through the company's mobile device management (MDM) platform to BEST meet this requirement?

  1. A

    Enable full device wipe when an employee separates from the company

  2. B

    Require device-level factory reset before each email synchronization

  3. C

    Configure containerization with selective wipe for corporate applications and data

  4. D

    Disable device passcodes so users are not locked out after policy changes

Show answer and explanation

Correct answer: C

Explanation

The best answer is to configure containerization with selective wipe for corporate applications and data. In BYOD deployments, MDM and related enterprise mobility management practices commonly separate business data from personal data so the organization can manage only the corporate portion of the device. During employee offboarding, selective wipe removes managed email profiles, certificates, enterprise apps, and corporate files without erasing personal photos, texts, or apps. This aligns with common vendor and industry best practices for BYOD security, including the principle of least impact on user-owned devices while still maintaining control of organizational data. Full device wipe may be appropriate for corporate-owned devices or high-risk loss scenarios, but it is not the best fit when the requirement specifically says to avoid deleting personal content.

  • A. Incorrect.

    This is incorrect because a full device wipe removes all data on the phone, including personal content. In a BYOD environment, this creates privacy and legal concerns and exceeds the stated requirement. Although full wipe is an MDM capability, it is generally more appropriate for corporate-owned devices or lost/stolen devices when the organization owns the endpoint.

  • B. Incorrect.

    This is incorrect because requiring a factory reset before each email synchronization is not a practical or standard MDM control. It would severely disrupt business operations and is not how MDM platforms protect corporate data. MDM solutions typically enforce policies such as encryption, screen lock, application management, and remote/selective wipe rather than repeated device resets.

  • C. Correct.

    This is correct because containerization separates corporate data and managed applications from the user's personal data on a BYOD device. When an employee leaves, the administrator can use selective wipe to remove only the managed corporate email, files, certificates, and application data while leaving personal content intact. This directly addresses the need to protect company information without affecting employee-owned personal data.

  • D. Incorrect.

    This is incorrect because disabling passcodes would weaken security and conflict with standard mobile security best practices. MDM platforms commonly enforce passcodes, biometrics, encryption, and lock-screen requirements to reduce unauthorized access. Removing passcodes would increase risk rather than help with offboarding or data protection.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam