CAS-002 · Question #858
A company has adopted a BYOD program. The company would like to protect confidential information. However, it has been decided that when an employee leaves, the company will not completely wipe the…
The correct answer is C. Utilize an MDM solution with containerization. MDM containerization isolates corporate data in a separate encrypted workspace on a personal device, enabling selective corporate data wipe at offboarding without touching personal content.
Question
A company has adopted a BYOD program. The company would like to protect confidential information. However, it has been decided that when an employee leaves, the company will not completely wipe the personal device. Which of the following would MOST likely help the company maintain security when employees leave?
Options
- ARequire cloud storage on corporate servers and disable access upon termination
- BWhitelist access to only non-confidential information
- CUtilize an MDM solution with containerization
- DRequire that devices not have local storage
How the community answered
(17 responses)- A6% (1)
- C82% (14)
- D12% (2)
Why each option
MDM containerization isolates corporate data in a separate encrypted workspace on a personal device, enabling selective corporate data wipe at offboarding without touching personal content.
Revoking cloud server access prevents future data retrieval but does not remove confidential data that may already be cached, downloaded, or synced locally on the personal device.
Whitelisting access to non-confidential information is a preventive measure but does not address confidential data the employee may have already accessed, saved, or copied before the policy was enforced.
An MDM solution with containerization creates a cryptographically isolated corporate partition on the employee's device, keeping all confidential company data, apps, and credentials separate from personal data. Upon termination, administrators can remotely wipe only the corporate container, removing all confidential information without performing a full device wipe that would destroy personal data. This satisfies both the security requirement and the company's decision not to fully wipe personal devices.
Prohibiting local storage is technically impractical for a true BYOD device and would make normal device operation impossible, undermining the purpose of a BYOD program.
Concept tested: MDM containerization for BYOD selective wipe
Source: https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy
Topics
Community Discussion
No community discussion yet for this question.