312-50 exam dumps

312-50 practice question 403 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 403

Single answer▪ Mobile Device Management

A company allows employees to use personal smartphones to access corporate email, internal chat, and cloud storage. During a security assessment, you discover that several lost or jailbroken devices still retain corporate data because the organization uses only basic screen-lock requirements and has no centralized policy enforcement. Management wants a Mobile Device Management (MDM) control that reduces data exposure on BYOD devices without wiping employees’ personal photos, apps, and messages. Which action is the MOST appropriate recommendation?

  1. A

    Deploy MDM with containerization and selective wipe so corporate data can be isolated and removed without affecting personal content

  2. B

    Enable full-device remote wipe for every BYOD phone so any missing device can be erased completely

  3. C

    Rely on user-managed antivirus apps and require employees to manually delete company files when they leave the organization

  4. D

    Disable device passcodes to reduce user friction, but require VPN access for all mobile applications

Show answer and explanation

Correct answer: A

Explanation

The best recommendation is to deploy an MDM solution that supports containerization and selective wipe for BYOD. In real-world mobile security programs, MDM or unified endpoint management (UEM) platforms are commonly used to enforce device compliance, detect rooted or jailbroken devices, manage enterprise applications, and protect corporate data separately from personal content. For BYOD, selective wipe is preferred over full-device wipe because it aligns with privacy and ownership concerns while still allowing the organization to remove managed email, documents, certificates, VPN profiles, and app data.

This approach is consistent with established mobile security guidance such as NIST SP 800-124 Revision 2, which recommends enterprise mobile management controls, policy enforcement, and separation of organizational data on mobile devices. Platform vendors such as Microsoft Intune, VMware Workspace ONE, and similar enterprise mobility tools also support managed app/container models and selective wipe capabilities for BYOD use cases.

  • A. Correct.

    Correct. In a BYOD environment, MDM containerization separates corporate data and applications from personal data, allowing enforcement of security policies such as encryption, copy/paste restrictions, and managed app access. Selective wipe is specifically designed to remove only enterprise-managed data, certificates, and profiles when a device is lost, compromised, jailbroken, or when the user leaves the company. This directly addresses the scenario’s requirement to reduce data exposure without deleting personal content.

  • B. Incorrect.

    Incorrect. Full-device wipe can protect data, but it is usually too invasive for BYOD because it erases the employee’s personal data as well. The scenario explicitly states management wants to avoid wiping personal photos, apps, and messages. Full wipe is more appropriate for fully corporate-owned devices under stricter ownership and consent models.

  • C. Incorrect.

    Incorrect. User-managed antivirus and manual deletion do not provide centralized policy enforcement, compliance monitoring, or reliable incident response. They also do not address jailbroken devices or ensure enterprise data is removed when a device is lost or an employee separates from the company. This reflects a common misconception that endpoint security apps alone can replace MDM controls.

  • D. Incorrect.

    Incorrect. Disabling passcodes weakens device security and increases the likelihood of unauthorized access if the device is lost or stolen. While VPNs help protect data in transit, they do not isolate corporate data on the device or support selective removal of enterprise content. This option contradicts basic mobile security best practices.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam