nerdexam
CompTIA

SY0-501 · Question #371

As part of a new BYOD rollout, a security analyst has been asked to find a way to securely store company data on personal devices. Which of the following would BEST help to accomplish this?

The correct answer is B. Implement containerization of company data. To securely store company data on personal BYOD devices while maintaining user privacy, implementing data containerization is the most effective technical solution.

Submitted by lucia.co· Mar 4, 2026Security architecture

Question

As part of a new BYOD rollout, a security analyst has been asked to find a way to securely store company data on personal devices. Which of the following would BEST help to accomplish this?

Options

  • ARequire the use of an eight-character PIN.
  • BImplement containerization of company data.
  • CRequire annual AUP sign-off.
  • DUse geofencing tools to unlock devices while on the premises.

How the community answered

(43 responses)
  • A
    7% (3)
  • B
    79% (34)
  • C
    12% (5)
  • D
    2% (1)

Why each option

To securely store company data on personal BYOD devices while maintaining user privacy, implementing data containerization is the most effective technical solution.

ARequire the use of an eight-character PIN.

Requiring an eight-character PIN primarily secures device access but does not specifically isolate or protect company data from personal data on a BYOD device.

BImplement containerization of company data.Correct

Containerization creates a secure, encrypted sandbox for company applications and data on a personal device, isolating it from the user's personal data. This isolation allows for specific security policies, such as data encryption, access controls, and remote wipe capabilities, to be applied only to the corporate container without affecting the user's personal files.

CRequire annual AUP sign-off.

Requiring annual AUP sign-off is a policy or legal control, not a technical solution for securely storing data on a device.

DUse geofencing tools to unlock devices while on the premises.

Using geofencing to unlock devices controls access based on location, but it does not secure the storage of company data or isolate it from personal data on the device.

Concept tested: BYOD data security via Mobile Application Management (MAM)

Source: https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy-overview

Topics

#BYOD#containerization#mobile device management#data protection

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice