220-1102 Security Practice Question
A company's IT policy mandates that all employee smartphones used for work must be capable of being completely erased if the device is lost or stolen. The company uses a Mobile Device Management (MDM) solution. Which MDM feature should the administrator use to satisfy this requirement?
⚠ Common exam trap
It's easy for candidates to confuse remote lock with remote wipe, assuming locking the device is sufficient for data protection, but the policy explicitly requires complete erasure, which only remote wipe can achieve.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remote wipe
Remote wipe is the correct MDM feature because it enables the administrator to send a command that performs a factory reset on the device, erasing all data including corporate and personal information. This satisfies the policy requirement for complete data removal on lost or stolen devices. The MDM solution communicates with the device using protocols like OMA-DM or Apple's MDM protocol to execute the wipe command remotely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remote lock
Why it's wrong here
Remote lock does not delete the device's contents; it merely imposes an authentication barrier (e.g., a PIN, password, or biometric requirement) via a mobile device management (MDM) command. Although this may temporarily protect the data from casual access, the encrypted or unencrypted data remains physically present on the storage medium, and the lock can potentially be bypassed through OS vulnerabilities, forensic tools, or by a thief performing a factory reset that strips the lock without securely erasing the underlying data. Because the policy demands complete erasure, remote lock is insufficient and does not meet the requirement.
- ✓
Remote wipe
Why this is correct
Remote wipe is the correct mechanism because it sends a secure command through the mobile device management (MDM) server to the handset instructing it to perform a factory reset or a cryptographic erase of all user data. A high-security remote wipe often deletes the encryption keys rather than overwriting every byte, making the data cryptographically unavailable and effectively unrecoverable even if the physical storage is later imaged. This process permanently destroys sensitive information on the device, satisfying the company policy's requirement for complete data erasure upon loss.
- ✗
Geofencing
Why it's wrong here
Geofencing does not perform data deletion; it uses GPS, Wi-Fi, or cellular location data to define virtual boundaries that trigger conditional actions, such as locking the screen, disabling the camera, or sending an alert when the device crosses a boundary. While geofencing can be configured to react when a device leaves an authorized area, it merely initiates a policy action and lacks the ability to execute a comprehensive erase of the device's storage. In a loss scenario, the device might be powered off or outside cellular coverage, so the geofencing trigger may never fire, and even if it does, it cannot remotely delete all sensitive data.
- ✗
Containerization
Why it's wrong here
Containerization separates an employee's personal data from corporate data by placing corporate resources and applications inside a cryptographically isolated, sandboxed container managed by an MDM solution. Although containerization allows an administrator to selectively wipe the corporate container when a device is lost, the underlying personal data and other non-containerized data remain intact on the device. Since the company's policy mandates that all employee smartphones—including non-containerized data—be completely erased, containerization fails to provide a mechanism to remotely erase the entire device as required.
Go deeper
Related to this question
Learn chapter
Software Patch Management
Key term
Wipe
Wipe is the process of securely erasing all data from a storage device, making it unrecoverable and preparing the device for reuse or disposal.
Key term
Bring Your Own Device
A policy allowing employees to use their personal laptops, smartphones, or tablets for work tasks instead of using company-issued equipment.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.