FC0-U71 Infrastructure Practice Question
An organization issues smartphones to employees and needs to enforce security policies such as remote wipe and mandatory encryption. Which technology should be used to manage these devices centrally?
⚠ Common exam trap
FC0-U71 often tests the confusion between network security technologies (VPN, NAT, DNS) and endpoint management platforms (MDM), tricking candidates who focus on 'security' rather than 'centralized device management'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MDM
Mobile Device Management (MDM) is the centralized platform for enrolling, configuring, and securing employee smartphones. It enforces policies such as mandatory encryption, passcode requirements, and remote wipe, and it can push configuration profiles and certificates to devices over the air. VPN, NAT, and DNS do not provide device policy enforcement or remote management capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPN
Why it's wrong here
A VPN only encrypts network traffic between a device and a private network; it cannot enforce encryption at rest, push policies or trigger a remote wipe. It tempts because it is a familiar remote-access security control, and would be the right choice for securing data in transit over untrusted networks.
- ✗
NAT
Why it's wrong here
NAT translates private IP addresses to public ones for outbound internet access; it cannot push policies, enforce encryption or trigger remote wipes on smartphones. It is tempting because NAT is commonly deployed alongside device networks, but it would be the right answer only when the requirement is address translation for outbound traffic, not mobile device management.
- ✓
MDM
Why this is correct
MDM centrally enforces device-level policies on enrolled smartphones, delivering remote wipe and mandatory encryption through configuration profiles pushed over the air. It satisfies the stem's requirement to manage organisation-issued devices centrally, unlike solutions scoped to applications or identity only, such as Microsoft Entra ID conditional access.
- ✗
DNS
Why it's wrong here
DNS resolves hostnames to IP addresses; it holds no mechanism to deliver configuration profiles, enforce encryption or issue remote wipe commands to smartphones. It is tempting because DNS is ubiquitous in enterprise networks, but it would be correct only when the requirement is name resolution, not centralised mobile device policy enforcement.
Visual reference
Go deeper
Related to this question
About these practice questions
This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.