220-1102 Security Practice Question
A company's security policy requires that all mobile devices be encrypted and capable of being wiped remotely if lost or stolen. Which mobile management solution should the organization implement?
⚠ Common exam trap
A common mix-up: candidates confuse VPN's encryption of network traffic with device-level encryption and management, assuming a VPN can satisfy all security requirements when it only protects data in transit, not data at rest or remote wipe capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mobile Device Management (MDM)
Mobile Device Management (MDM) is the correct solution because it provides centralized policy enforcement for encryption (e.g., requiring BitLocker on Windows or FileVault on macOS) and supports remote wipe capabilities via protocols like Microsoft Exchange ActiveSync or Apple MDM commands. This directly meets the security policy requirements for encrypting devices and wiping them if lost or stolen.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Mobile Device Management (MDM)
Why this is correct
Mobile Device Management (MDM) is a centralized administration platform that enrolls devices and pushes configuration profiles to enforce security policies such as full-disk encryption and password complexity. Once enrolled, IT can remotely issue commands like lock or wipe, either on-demand or automatically when a device becomes non-compliant. This administrative control directly satisfies the policy requirement that all mobile devices be protected and remotely wipable.
- ✗
VPN
Why it's wrong here
A virtual private network (VPN) encrypts traffic in transit between the device and a corporate gateway, protecting data from eavesdropping on untrusted networks. However, a VPN does not alter or inspect local device storage, enforce encryption at rest, or provide an administrative channel for remote wipe. It is purely a connectivity and data-in-transit protection tool, so it cannot enforce the mobile device policy's compliance requirements.
- ✗
Antivirus
Why it's wrong here
Antivirus software focuses on detecting, blocking, and removing malware at the application or file level, and may offer real-time scanning or malicious-app remediation. It lacks the device-level application programming interface (API) access required to enforce encryption settings or issue a remote wipe command across the entire device. While antivirus is a valuable security layer, it is not a policy management framework and thus cannot meet the stated requirement.
- ✗
Firewall
Why it's wrong here
A firewall inspects and filters network traffic based on a ruleset, often at the perimeter or as a host-based filter, but it operates on data as it traverses the network stack. It has no capability to manage local device settings, verify that storage encryption is enabled, or remotely erase the device if it is lost or stolen. Therefore, despite its role in network defense, it is irrelevant to the mobile device encryption and remote-wipe policy.
Go deeper
Related to this question
Learn chapter
Wireless Encryption: WEP, WPA, WPA2, WPA3
Key term
Mobile device management
Mobile device management (MDM) is a security solution that allows IT administrators to enroll, configure, monitor, and enforce policies on smartphones, tablets, and other mobile devices used in an organization.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.