SY0-701 Question 261
Single answerMobile solutions: Mobile device management (MDM)A company allows employees to use personal smartphones to access corporate email, calendars, and internally developed mobile apps. The security team must protect company data without taking control of employees' personal photos, messages, or apps. Several employees have raised privacy concerns after hearing that IT might be able to erase their entire phones if a device is lost. Which MDM approach best meets the company's security and privacy requirements?
- A
Require full device enrollment with device administrator privileges and perform a full factory reset on any lost phone
- B
Use containerization or a work profile through the MDM platform so corporate apps and data can be managed and selectively wiped separately from personal data
- C
Disable screen locks on BYOD devices to reduce user complaints and rely on email passwords to protect company data
- D
Allow access only through unmanaged webmail because MDM cannot separate business data from personal data on employee-owned phones
Show answer and explanation
Correct answer: B
Explanation
For BYOD scenarios, the most appropriate MDM design is usually one that separates enterprise resources from personal content rather than fully controlling the entire device. Common implementations include containerization, managed applications, and platform-specific work profiles. These approaches support selective wipe, which removes only organizational data when a device is lost, an employee leaves the company, or access must be revoked. This aligns with common enterprise mobility best practices and with vendor guidance from platforms such as Microsoft Intune, VMware Workspace ONE, and mobile OS enterprise management frameworks from Apple and Google. Security+ candidates should recognize that MDM is not just about remote wipe; it is also about enforcing security policies while choosing an ownership model and management scope appropriate to the business need. In a privacy-sensitive BYOD deployment, selective management of corporate data is typically preferable to full-device control.
- A. Incorrect.
This is incorrect because full device enrollment with broad control over the entire phone is more appropriate for corporate-owned devices than privacy-sensitive BYOD environments. A full factory reset would remove personal data along with business data, which does not meet the requirement to protect employee privacy. While some organizations do fully manage BYOD devices with user consent, that approach conflicts with the scenario's goal of limiting control over personal content.
- B. Correct.
This is correct because containerization, managed applications, or a work profile is a standard MDM approach for BYOD deployments. It separates corporate data and apps from personal data, allowing the organization to enforce policies such as encryption, PIN requirements, approved app usage, and selective wipe of only business information. This directly addresses both security and employee privacy concerns.
- C. Incorrect.
This is incorrect because disabling screen locks weakens device security and increases the risk of unauthorized access if the phone is lost or stolen. MDM best practices generally enforce device lock, strong authentication, and related controls to protect corporate data. Relying only on an email password does not protect locally cached data, managed apps, or other corporate content on the device.
- D. Incorrect.
This is incorrect because modern MDM and enterprise mobility management solutions do support separation of business and personal data through features such as managed app policies, work profiles, or application containers. Unmanaged webmail may reduce management overhead, but it also limits policy enforcement and typically provides weaker control over data protection, copy/paste restrictions, and selective removal of corporate data.