nerdexam
CompTIA

SY0-501 · Question #408

A company is allowing a BYOD policy for its staff. Which of the following is a best practice that can decrease the risk of users jailbreaking mobile devices?

The correct answer is A. Install a corporately monitored mobile antivirus on the devices.. Installing and monitoring mobile antivirus on BYOD devices allows for the detection of jailbroken devices, enabling organizations to enforce policies and mitigate associated security risks.

Submitted by cyberguy42· Mar 4, 2026Security architecture

Question

A company is allowing a BYOD policy for its staff. Which of the following is a best practice that can decrease the risk of users jailbreaking mobile devices?

Options

  • AInstall a corporately monitored mobile antivirus on the devices.
  • BPrevent the installation of applications from a third-party application store.
  • CBuild a custom ROM that can prevent jailbreaking.
  • DRequire applications to be digitally signed.

How the community answered

(48 responses)
  • A
    83% (40)
  • B
    2% (1)
  • C
    10% (5)
  • D
    4% (2)

Why each option

Installing and monitoring mobile antivirus on BYOD devices allows for the detection of jailbroken devices, enabling organizations to enforce policies and mitigate associated security risks.

AInstall a corporately monitored mobile antivirus on the devices.Correct

Corporately monitored mobile antivirus, often integrated with Mobile Threat Defense (MTD) solutions, includes jailbreak/root detection capabilities, allowing the organization to identify compromised devices and enforce policies, thereby mitigating the risk associated with jailbroken BYOD devices.

BPrevent the installation of applications from a third-party application store.

Preventing third-party app installations is a security measure often circumvented by jailbreaking, but it does not prevent the act of jailbreaking itself, which grants users root access to bypass such restrictions.

CBuild a custom ROM that can prevent jailbreaking.

Building custom ROMs is not a practical or enforceable solution for a BYOD policy, as companies cannot dictate operating system modifications on personal devices.

DRequire applications to be digitally signed.

Requiring digitally signed applications ensures app integrity but does not prevent users from jailbreaking their devices to bypass signature checks or install unsigned software.

Concept tested: BYOD Mobile Device Security and Risk Mitigation

Source: https://learn.microsoft.com/en-us/mem/intune/protect/mobile-threat-defense

Topics

#BYOD#mobile security#jailbreaking#MDM

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice