220-1102 Security Practice Question
A company policy requires that all mobile devices used for work be managed via Microsoft Intune. An employee loses a company-issued smartphone. The IT administrator needs to remotely wipe the device to prevent data loss. Which prerequisite must have been completed on the device for this action to be possible?
⚠ Common exam trap
Many candidates confuse data-at-rest encryption (like BitLocker) with the management enrollment required for remote wipe, assuming encryption alone enables remote data deletion, but encryption only protects data if the device is lost, it does not allow remote commands.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Device enrolled in Intune
For an IT administrator to remotely wipe a device via Microsoft Intune, the device must be enrolled in Intune. Enrollment establishes a management relationship that allows Intune to send commands, including remote wipe, to the device. Without enrollment, Intune has no authority or communication channel to execute a wipe.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
BitLocker encryption enabled
Why it's wrong here
BitLocker encryption protects data at rest by encrypting the storage volume, but it provides no mechanism for an administrator to remotely locate or erase a lost device. Remote wipe requires a management channel, such as an MDM enrollment, that can issue commands down to the OS. Merely enabling local encryption does not register the device with any enterprise management service.
- ✓
Device enrolled in Intune
Why this is correct
Enrolling the device in Intune is the prerequisite step that establishes the mobile device management (MDM) control channel. Once enrolled, the device receives compliant configuration profiles and is managed by Intune, which permits the administrator to trigger a remote wipe either as a full device reset or as a selective corporate-data-only wipe. This management relationship is the only option presented that directly enables enterprise-issued remote wipe commands.
- ✗
Find My Device activated
Why it's wrong here
Find My Device is a consumer-level tracking and erase service tied to a personal account, such as a Microsoft or Google account. It lacks the administrative control, compliance policies, and corporate asset tracking required for enterprise remote wipe. While a user could use Find My Device to erase their own device, the company cannot rely on it to enforce corporate data security or to selectively wipe corporate apps and data.
- ✗
VPN profile installed
Why it's wrong here
A VPN profile establishes an encrypted network tunnel for accessing corporate resources by directing traffic through a VPN gateway. It does not configure a management agent or policy-receiving channel, so the device remains outside the MDM control plane. Installing a VPN profile gives secure connectivity but does not grant the administrator any mechanism to remotely wipe or retire the device.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.