nerdexam
CompTIA

CAS-002 · Question #858

A company has adopted a BYOD program. The company would like to protect confidential information. However, it has been decided that when an employee leaves, the company will not completely wipe the…

The correct answer is C. Utilize an MDM solution with containerization. MDM containerization isolates corporate data in a separate encrypted workspace on a personal device, enabling selective corporate data wipe at offboarding without touching personal content.

Technical Integration of Enterprise Components

Question

A company has adopted a BYOD program. The company would like to protect confidential information. However, it has been decided that when an employee leaves, the company will not completely wipe the personal device. Which of the following would MOST likely help the company maintain security when employees leave?

Options

  • ARequire cloud storage on corporate servers and disable access upon termination
  • BWhitelist access to only non-confidential information
  • CUtilize an MDM solution with containerization
  • DRequire that devices not have local storage

How the community answered

(17 responses)
  • A
    6% (1)
  • C
    82% (14)
  • D
    12% (2)

Why each option

MDM containerization isolates corporate data in a separate encrypted workspace on a personal device, enabling selective corporate data wipe at offboarding without touching personal content.

ARequire cloud storage on corporate servers and disable access upon termination

Revoking cloud server access prevents future data retrieval but does not remove confidential data that may already be cached, downloaded, or synced locally on the personal device.

BWhitelist access to only non-confidential information

Whitelisting access to non-confidential information is a preventive measure but does not address confidential data the employee may have already accessed, saved, or copied before the policy was enforced.

CUtilize an MDM solution with containerizationCorrect

An MDM solution with containerization creates a cryptographically isolated corporate partition on the employee's device, keeping all confidential company data, apps, and credentials separate from personal data. Upon termination, administrators can remotely wipe only the corporate container, removing all confidential information without performing a full device wipe that would destroy personal data. This satisfies both the security requirement and the company's decision not to fully wipe personal devices.

DRequire that devices not have local storage

Prohibiting local storage is technically impractical for a true BYOD device and would make normal device operation impossible, undermining the purpose of a BYOD program.

Concept tested: MDM containerization for BYOD selective wipe

Source: https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy

Topics

#BYOD#MDM#containerization#data protection

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice