Courseiva
mediumMultiple ChoiceObjective-mapped

220-1102 Practice Question: During a security audit, a technician discovers…

During a security audit, a technician discovers that an employee's company-issued iPhone has been jailbroken. The employee claims they only did it to customize the home screen. Which security risk is most directly associated with a jailbroken device in a corporate environment?

⚠ Common exam trap

The trap here is that candidates focus on the employee's stated reason (customization) and mistakenly choose a non-security answer like 'voids warranty' or 'slower performance,' overlooking the fundamental security principle that jailbreaking breaks app isolation and exposes corporate data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

It bypasses app sandbox restrictions, potentially exposing corporate data.

Jailbreaking removes the iOS sandbox restrictions that normally isolate each app's data and prevent unauthorized access to the file system. Without these restrictions, a malicious or compromised app on the jailbroken device can read, copy, or exfiltrate corporate data stored by other apps (e.g., email, VPN certificates, MDM profiles), directly violating data confidentiality in a corporate environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The device cannot receive iOS updates.

    Why it's wrong here

    Jailbroken devices frequently lose the ability to receive official over-the-air (OTA) iOS updates because the modified system files conflict with the update process. While this prevents access to new security patches and features, making the device vulnerable to known exploits over time, it is a secondary security concern compared to the immediate compromise of core OS security mechanisms like app sandboxing. The inability to update is a symptom of the underlying modification, not the most critical direct security risk.

  • It voids the warranty.

    Why it's wrong here

    Jailbreaking an iOS device typically voids its manufacturer's warranty, meaning Apple or authorized service providers will no longer offer free repairs or support. While this represents a financial and operational risk for the organization by increasing potential repair costs and downtime, it does not directly compromise the security of corporate data residing on the device. Warranty status is a business concern, not a cybersecurity vulnerability.

  • It bypasses app sandbox restrictions, potentially exposing corporate data.

    Why this is correct

    App sandboxing is a fundamental iOS security feature that isolates each application's data and processes from others, preventing unauthorized access or interference. Jailbreaking disables or bypasses these critical sandbox restrictions, allowing malicious or poorly coded applications to access sensitive corporate data stored by other legitimate apps, such as email clients or document management systems. This direct compromise of data isolation creates a severe risk of data leakage and unauthorized access to confidential information.

  • The device will perform slower.

    Why it's wrong here

    Jailbreaking often involves installing additional tweaks, daemons, and modified system files, which can consume extra CPU cycles, RAM, and battery life, potentially leading to noticeable performance degradation. While a slower device can impact user productivity and battery longevity, this is primarily an operational or user experience issue. It does not represent a direct security vulnerability that exposes corporate data or compromises system integrity in the same critical way as bypassing core security features.

About these practice questions

This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.