220-1102 Operational Procedures Practice Question
A company is implementing a bring-your-own-device (BYOD) policy and needs to ensure that corporate data on employee mobile devices is protected. Which of the following is the MOST important technical control to implement?
⚠ Common exam trap
A common mix-up: candidates choose strong passwords or antivirus because they are familiar security basics, but the question specifically asks for the most important control to protect corporate data on BYOD devices, which requires the ability to remove data remotely after loss or termination.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable remote wipe capability for corporate data
In a BYOD environment, the primary risk is that corporate data may be exposed if the device is lost, stolen, or the employee leaves the company. Remote wipe capability allows the organization to selectively erase corporate data from the device without affecting the employee's personal data, directly addressing data protection requirements. While strong passwords and antivirus are useful, they do not provide the ability to remove data after a device is compromised or no longer authorized.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require strong passwords on all devices
Why it's wrong here
Strong passwords are a foundational access control, but they only prevent unauthorized entry at the authentication layer. If a device is lost or stolen, an attacker with sufficient time and tools can often bypass or crack the password via offline brute force or forensic extraction, or the device might be compromised while unlocked. Furthermore, a password does not provide any capability to selectively erase or revoke access to corporate data should the device fall into the wrong hands.
- ✗
Install antivirus software on each device
Why it's wrong here
Antivirus software is a reactive endpoint protection tool that detects known malware signatures and heuristics, but it does not protect data confidentiality if the device is physically compromised. Physical possession allows an attacker to bypass the operating system, extract flash storage, or use forensic tools to read data directly. Even against malware, AV often misses zero-day exploits and advanced persistent threats, and it offers no mechanism for remote data deletion or selective corporate data containment.
- ✓
Enable remote wipe capability for corporate data
Why this is correct
Remote wipe is a Mobile Device Management (MDM) feature that enables an administrator to send a command over the network to delete corporate data from a device. In BYOD scenarios, it is the direct answer to the risk of device loss or theft: the organization can revoke access and erase sensitive information immediately, even when the hardware is out of reach. A granular corporate wipe can selectively remove managed apps, profiles, and email while preserving personal data, which is a key differentiator for BYOD.
- ✗
Use a VPN for all corporate traffic
Why it's wrong here
A VPN encrypts network communications between the device and corporate resources, protecting data while it travels over untrusted networks like public Wi-Fi. However, it provides no protection for data at rest on the device; if the device is physically compromised, the stored corporate data is still accessible. Additionally, a VPN only governs traffic in transit and does not give the organization the ability to remotely delete data or enforce app-level containment, making it a complementary control rather than the core protection.
Go deeper
Related to this question
Learn chapter
Remote Support Tools and Techniques
Key term
Technical control
A technical control is a security mechanism implemented through hardware, software, or firmware that protects the confidentiality, integrity, and availability of IT systems and data.
Key term
Bring Your Own Device
A policy allowing employees to use their personal laptops, smartphones, or tablets for work tasks instead of using company-issued equipment.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.