2V0-62.23 · Question #75
Which configuration should be set to limit the ability of users to perform device wipes while still maintaining SSP access and the ability to unenroll?
The correct answer is D. user-based role to disallow Device Wipe. Option D is correct because restricting the Device Wipe action at the user-based role level prevents end users from performing a full factory reset through the Self-Service Portal (SSP), while leaving their SSP access and unenrollment capability intact - unenrollment triggers…
Question
Which configuration should be set to limit the ability of users to perform device wipes while still maintaining SSP access and the ability to unenroll?
Options
- Aadmin-based role to disallow Device Wipe
- Buser-based role to disallow Enterprise Wipe
- Cadmin-based role to disallow Enterprise Wipe
- Duser-based role to disallow Device Wipe
How the community answered
(26 responses)- A15% (4)
- B8% (2)
- C4% (1)
- D73% (19)
Explanation
Option D is correct because restricting the Device Wipe action at the user-based role level prevents end users from performing a full factory reset through the Self-Service Portal (SSP), while leaving their SSP access and unenrollment capability intact - unenrollment triggers an Enterprise Wipe (corporate data only), which is a separate, less destructive action.
Why the distractors fail:
- A targets the wrong audience - admin-based roles govern what administrators can do, not end users in the SSP.
- B disallows Enterprise Wipe at the user level, which breaks unenrollment since unenrolling a device typically executes an Enterprise Wipe; this directly violates the stated requirement.
- C doubles down on both mistakes: wrong role type (admin) and wrong wipe type (Enterprise), which would disrupt admin workflows without protecting against user-initiated full wipes.
Memory tip: Think of it as two axes - who (user vs. admin) and what (Device Wipe = nuclear option vs. Enterprise Wipe = corporate data only). The question is about protecting users from nuking their own device, so you need a user role blocking the Device (full) wipe - not the Enterprise wipe they need for unenrollment.
Topics
Community Discussion
No community discussion yet for this question.