SY0-501 · Question #284
A new hire wants to use a personally owned phone to access company resources. The new hire expresses concern about what happens to the data on the phone when they leave the company. Which of the…
The correct answer is D. Storage segmentation. Storage segmentation in mobile device management (MDM) allows for the separation of company data from personal data on a personally owned device, enabling selective removal of only corporate information upon an employee's departure without affecting personal files.
Question
A new hire wants to use a personally owned phone to access company resources. The new hire expresses concern about what happens to the data on the phone when they leave the company. Which of the following portions of the company's mobile device management configuration would allow the company data to be removed from the device without touching the new hire's data?
Options
- AAsset control
- BDevice access control
- CStorage lock out
- DStorage segmentation
How the community answered
(41 responses)- A12% (5)
- B7% (3)
- C5% (2)
- D76% (31)
Why each option
Storage segmentation in mobile device management (MDM) allows for the separation of company data from personal data on a personally owned device, enabling selective removal of only corporate information upon an employee's departure without affecting personal files.
Asset control focuses on tracking and managing company-owned devices or software licenses, not on segregating or selectively removing data from an employee's personal device.
Device access control determines whether a device can connect to company resources and under what conditions, but it does not describe the mechanism for separating or selectively removing data on the device itself.
Storage lock out typically refers to completely blocking access to a device's storage, which would prevent access to both company and personal data, rather than allowing for selective removal of only company data.
Storage segmentation, often implemented through work profiles or application protection policies in MDM solutions, creates distinct containers or logical separations for corporate data on a mobile device. This isolation ensures that company data can be selectively wiped or removed from the device without impacting the user's personal applications, photos, or other data, directly addressing the new hire's concern about data privacy upon leaving the company.
Concept tested: MDM data segregation and selective wipe capabilities
Source: https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policies
Topics
Community Discussion
No community discussion yet for this question.