nerdexam
CompTIA

SY0-501 · Question #415

A security analyst is securing smartphones and laptops for a highly mobile workforce. Priorities include: Remote wipe capabilities Geolocation services Patch management and reporting Mandatory…

The correct answer is A. Implementing MDM software. Implementing Mobile Device Management (MDM) software is the best solution because it provides a comprehensive suite of tools to meet all the listed security requirements for a highly mobile workforce's smartphones and laptops.

Submitted by tarun92· Mar 4, 2026Security architecture

Question

A security analyst is securing smartphones and laptops for a highly mobile workforce. Priorities include:

Remote wipe capabilities Geolocation services Patch management and reporting Mandatory screen locks Ability to require passcodes and pins Ability to require encryption Which of the following would BEST meet these requirements?

Options

  • AImplementing MDM software
  • BDeploying relevant group policies to the devices
  • CInstalling full device encryption
  • DRemoving administrative rights to the devices

How the community answered

(39 responses)
  • A
    74% (29)
  • B
    15% (6)
  • C
    3% (1)
  • D
    8% (3)

Why each option

Implementing Mobile Device Management (MDM) software is the best solution because it provides a comprehensive suite of tools to meet all the listed security requirements for a highly mobile workforce's smartphones and laptops.

AImplementing MDM softwareCorrect

MDM software is designed to centrally manage and secure mobile devices and laptops, offering features such as remote wipe, geolocation services, patch management, and policy enforcement for mandatory screen locks, passcodes/pins, and encryption. This integrated approach addresses all the specified priorities effectively for a diverse mobile fleet.

BDeploying relevant group policies to the devices

Deploying group policies is primarily effective for Windows devices within an Active Directory environment and lacks the universal support for smartphones and comprehensive remote wipe or geolocation features across diverse mobile operating systems that MDM provides.

CInstalling full device encryption

Installing full device encryption only addresses the requirement for encryption and does not provide solutions for remote wipe, geolocation, patch management, mandatory screen locks, or passcode/PIN requirements.

DRemoving administrative rights to the devices

Removing administrative rights enhances security by preventing unauthorized software installations or configuration changes, but it does not directly offer capabilities like remote wipe, geolocation tracking, patch management, or the enforcement of screen lock and passcode policies across a fleet of devices.

Concept tested: Mobile Device Management (MDM) capabilities for endpoint security

Source: https://learn.microsoft.com/en-us/mem/intune/fundamentals/what-is-intune

Topics

#MDM#mobile device management#remote wipe#endpoint security

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice