CAS-003 · Question #317
An organization enables BYOD but wants to allow users to access the corporate email, calendar, and contacts from their devices. The data associated with the user's accounts is sensitive, and…
The correct answer is D. Configure and monitor devices with an MDM. MDM is the only solution listed that can enforce all four stated requirements - full-device encryption, remote wipe, unsigned app blocking, and containerization - across personal BYOD devices from a single management plane.
Question
An organization enables BYOD but wants to allow users to access the corporate email, calendar, and contacts from their devices. The data associated with the user's accounts is sensitive, and therefore, the organization wants to comply with the following requirements:
Active full-device encryption Enabled remote-device wipe Blocking unsigned applications Containerization of email, calendar, and contacts Which of the following technical controls would BEST protect the data from attack or loss and meet the above requirements?
Options
- ARequire frequent password changes and disable NFC.
- BEnforce device encryption and activate MAM.
- CInstall a mobile antivirus application.
- DConfigure and monitor devices with an MDM.
How the community answered
(25 responses)- A12% (3)
- B4% (1)
- D84% (21)
Why each option
MDM is the only solution listed that can enforce all four stated requirements - full-device encryption, remote wipe, unsigned app blocking, and containerization - across personal BYOD devices from a single management plane.
Frequent password changes and disabling NFC are minor hardening measures that do not enforce encryption, provide remote wipe, block unsigned apps, or enable containerization of corporate data.
Enforcing device encryption combined with MAM (Mobile Application Management) addresses app-level sandboxing but MAM alone does not provide full-device remote wipe or enforce OS-level full-device encryption the way MDM does.
A mobile antivirus application detects and removes malware but cannot enforce encryption, execute remote wipe, block unsigned applications, or provide containerization of corporate accounts.
An MDM (Mobile Device Management) solution enforces full-device encryption at the OS level, enables remote wipe of enrolled devices, restricts installation of unsigned or unapproved applications through policy, and deploys containerized profiles for corporate email, calendar, and contacts - satisfying all four requirements in a unified, auditable platform.
Concept tested: MDM enforcement of BYOD full-device security policy
Source: https://learn.microsoft.com/en-us/mem/intune/enrollment/device-enrollment
Topics
Community Discussion
No community discussion yet for this question.