SY0-701 Question 263
Single answerDeployment models: Bring your own device (BYOD) , Corporate-owned, personally enabled (COPE) , Choose your own device (CYOD)A healthcare company must allow clinicians to access email, messaging, and scheduling apps from mobile devices while reducing support costs and protecting patient data. The security team needs a deployment model that gives employees some personal use of the device, but still lets IT enforce encryption, approved apps, and remote wipe of corporate data if a phone is lost. The company also wants to avoid the privacy concerns of managing employees' fully personal phones. Which deployment model best meets these requirements?
- A
BYOD, because employees use their own phones and IT can fully control the entire device without privacy concerns
- B
COPE, because the company owns the device, can enforce security controls, and may allow limited personal use
- C
CYOD, because employees can pick any personal phone they already own and connect it without corporate management
- D
BYOD, because it eliminates the need for mobile device management while still providing full protection of corporate data
Show answer and explanation
Correct answer: B
Explanation
The best answer is COPE. In a COPE model, the organization owns the mobile device and issues it to the user, but permits personal use within policy. This model is commonly chosen when the business needs stronger administrative control than BYOD typically allows, especially in regulated environments such as healthcare, where protection of sensitive data is critical. Because the company owns the device, IT can more consistently enforce security baselines such as full-device encryption, screen-lock requirements, approved app stores or allowlists, patching, and remote wipe. This also reduces the privacy and legal concerns that arise when employers manage employee-owned devices in a BYOD program.
By contrast, BYOD prioritizes employee-owned devices and usually introduces more privacy, support, and data-separation challenges. CYOD can help standardize support by limiting users to approved device models, but it does not inherently mean the company owns the devices; the defining feature is choice from an approved catalog. Security best practices from enterprise mobility guidance and vendor documentation for MDM/UEM platforms consistently distinguish these models based on ownership, control, privacy tradeoffs, and supportability. For Security+, candidates should recognize that COPE is the strongest fit when an organization wants both corporate control and limited personal use.
- A. Incorrect.
Incorrect. BYOD means employees use personally owned devices for work. Although organizations can apply controls through MDM/UEM, they generally do not have the same level of authority or acceptance to manage the entire device as they would with a corporate-owned asset. This option is especially wrong because it claims there are no privacy concerns, which is a common misconception. Privacy concerns are one of the main tradeoffs with BYOD.
- B. Correct.
Correct. COPE (Corporate-Owned, Personally Enabled) is designed for situations where the organization wants strong control over the device because it owns the hardware, while still permitting limited personal use by the employee. This aligns with the scenario's need for enforced encryption, approved applications, and remote wipe capabilities while avoiding the complications of managing fully personal devices.
- C. Incorrect.
Incorrect. CYOD (Choose Your Own Device) allows users to select from a preapproved list of devices chosen by the organization. It does not mean employees can use any phone they already own without management. CYOD can reduce support complexity compared with unrestricted BYOD, but the key scenario requirement is corporate ownership plus personal use, which points to COPE rather than CYOD.
- D. Incorrect.
Incorrect. BYOD does not eliminate the need for mobile device management. In practice, BYOD environments often rely heavily on MDM/UEM, containerization, conditional access, and policy enforcement to protect business data on employee-owned devices. The statement that BYOD still provides full protection without management is inaccurate and reflects a misunderstanding of how mobile security is implemented.