nerdexam
Broadcom-VMware

2V0-62.23 · Question #21

An administrator is concerned with data loss on Workspace ONE managed endpoints. Which three configurations should be enabled to further improve the device security posture? (Choose three.)

The correct answer is B. Enable device-level date encryption. C. Configure compliance policies to monitor rooted and jailbroken devices. F. Enable Data Loss Prevention policies. Device-level encryption (B) protects data at rest so that even if a device is stolen or lost, the stored data remains unreadable. Compliance policies for rooted/jailbroken devices (C) detect when OS-level security has been bypassed, which exposes the device to unauthorized data…

Section 3 – Workspace ONE Installation, Configuration, and Setup

Question

An administrator is concerned with data loss on Workspace ONE managed endpoints. Which three configurations should be enabled to further improve the device security posture? (Choose three.)

Options

  • AEnable verbose logging.
  • BEnable device-level date encryption.
  • CConfigure compliance policies to monitor rooted and jailbroken devices.
  • DConfigure compliance policies to monitor Roaming Cell Data Usage.
  • EEnable SMTP integration.
  • FEnable Data Loss Prevention policies.

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    79% (30)
  • D
    11% (4)
  • E
    8% (3)

Explanation

Device-level encryption (B) protects data at rest so that even if a device is stolen or lost, the stored data remains unreadable. Compliance policies for rooted/jailbroken devices (C) detect when OS-level security has been bypassed, which exposes the device to unauthorized data exfiltration. Data Loss Prevention (DLP) policies (F) directly control how sensitive data can be shared, copied, or transmitted from managed apps - making them the most targeted control against data loss.

The distractors target unrelated concerns: verbose logging (A) aids troubleshooting but doesn't prevent data loss; monitoring Roaming Cell Data Usage (D) is a cost/network concern, not a security control; and SMTP integration (E) is for email notification routing, not endpoint protection.

Memory tip: Think "Lock it, Check it, Control it" - B locks the data with encryption, C checks device integrity, and F controls data flow. If an answer doesn't directly prevent data from leaving or being exposed, it's a distractor.

Topics

#Device Encryption#Compliance Policies#Data Loss Prevention#Endpoint Security

Community Discussion

No community discussion yet for this question.

Full 2V0-62.23 Practice