220-1101 Mobile Devices Practice Question
A technician is preparing a fleet of corporate Android tablets for field staff who need to access email and a line-of-business app. The security team requires that the devices be encrypted and that a lost tablet cannot be accessed without the user's PIN, even if someone removes the storage. Which of the following should the technician configure?
⚠ Common exam trap
The trap here is treating a lock-screen PIN or work profile as equivalent to encryption, when only file-based encryption with a credential-derived key makes removed storage unreadable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable file-based encryption with a secure lock-screen credential enforced by policy.
File-based encryption ties the decryption keys to the user's lock-screen credential, so storage removed from the tablet cannot be read without the PIN. Enforcing that credential through management policy ensures users cannot weaken it. Work profiles, VPNs, biometrics alone, and disabling USB debugging each provide valuable but different protections that do not encrypt data at rest or gate it on the lock-screen secret.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable a biometric unlock and require a six-digit PIN for the lock screen.
Why it's wrong here
A lock-screen PIN and biometrics control access through the user interface, but they do not by themselves guarantee that the underlying storage is encrypted. If full-disk or file-based encryption is not active, an attacker who removes the flash storage could read its contents offline. The requirement explicitly includes encryption of the device's data at rest, which this option alone does not confirm.
- ✗
Configure a work profile and enforce a VPN for all corporate applications.
Why it's wrong here
A work profile separates corporate apps and data from personal content, and a VPN protects data in transit, but neither encrypts the device's storage at rest. A stolen tablet with an unencrypted volume could still be read offline. These controls address data segregation and network confidentiality, not the at-rest encryption and PIN-gated access the security team demanded.
- ✓
Enable file-based encryption with a secure lock-screen credential enforced by policy.
Why this is correct
File-based encryption encrypts data at rest using keys derived in part from the user's lock-screen credential, so the storage cannot be decrypted without that PIN. Enforcing a strong lock-screen credential through MDM policy ensures the key material is protected, and the device becomes unreadable if the flash storage is removed. This directly satisfies both the encryption and PIN-gated access requirements.
- ✗
Turn on USB debugging and require developer options to be disabled by policy.
Why it's wrong here
Disabling USB debugging reduces the attack surface for ADB-based data extraction, but it does not encrypt storage. An attacker who physically removes the flash chip is unaffected by a debug setting. This option addresses a different threat model and leaves the data readable at rest, so it fails the encryption requirement.
Go deeper
Related to this question
About these practice questions
One of 896 original 220-1101 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.