SY0-701 exam dumps

SY0-701 practice question 262 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 262

Single answerDeployment models: Bring your own device (BYOD) , Corporate-owned, personally enabled (COPE) , Choose your own device (CYOD)

A healthcare company must provide mobile access to email, scheduling, and an internal clinical messaging app for its staff. The security team needs the ability to enforce encryption, require screen locks, remotely wipe corporate data, and ensure devices meet a defined hardware and OS baseline for support. However, leadership also wants employees to have limited personal use of the devices to improve adoption. Which deployment model BEST meets these requirements?

  1. A

    Bring your own device (BYOD)

  2. B

    Corporate-owned, personally enabled (COPE)

  3. C

    Choose your own device (CYOD)

  4. D

    Virtual desktop infrastructure (VDI)

Show answer and explanation

Correct answer: B

Explanation

The best answer is Corporate-owned, personally enabled (COPE). In a COPE model, the organization provides and manages the device, which supports strong administrative control through tools such as MDM or enterprise mobility management (EMM). That control helps enforce common Security+ objectives such as device encryption, lock-screen policies, compliance checks, approved application sets, and selective or full remote wipe. COPE is especially appropriate in regulated environments like healthcare, where protecting sensitive data and maintaining supportable, known-good device configurations are important. BYOD is often chosen for cost savings and user convenience, but it introduces more privacy concerns, less hardware consistency, and more complexity in enforcement. CYOD improves standardization by limiting choices to approved models, but the term does not specifically satisfy the requirement that devices be corporate-owned and personally enabled. This aligns with widely accepted mobile security best practices from enterprise mobility guidance, including recommendations from NIST on mobile device security to use centralized management, enforce policy, and maintain control over devices handling organizational data.

  • A. Incorrect.

    BYOD is incorrect because employees use their own devices, which reduces organizational control over hardware standardization and can complicate enforcement of support baselines. While mobile device management (MDM) can impose some controls on BYOD devices, BYOD does not best fit a requirement for company ownership plus limited personal use.

  • B. Correct.

    COPE is correct because the organization owns and issues the devices, allowing strong security control, standardized hardware/OS baselines, and consistent support. At the same time, COPE permits limited personal use by employees. This makes it a strong fit when the company must enforce encryption, screen locks, remote wipe, and application control while still allowing some personal convenience.

  • C. Incorrect.

    CYOD is incorrect because CYOD allows users to select from a preapproved list of devices, improving standardization compared to BYOD. However, CYOD does not inherently indicate whether the organization or the employee owns the device. The scenario specifically requires corporate ownership with personal use, which aligns more directly with COPE than CYOD.

  • D. Incorrect.

    VDI is incorrect because it is a delivery technology, not a mobile device ownership/deployment model. VDI can reduce data stored on endpoints and improve control over application access, but it does not by itself address the requirement for a device deployment model that allows corporate ownership and personal use.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam