SY0-701 Security Architecture Practice Question
Exhibit
MDM dashboard excerpt: - iOS device compliance: 84% - Android device compliance: 79% - Email app access policy: Allow if credentials are valid - Noncompliance reasons: outdated OS, no passcode, jailbreak/root indicators - Lost device action: Full factory reset only Security request: Block risky devices from email access and protect employee personal data on BYOD devices.
Based on the exhibit, what is the best next control to prevent noncompliant mobile devices from accessing corporate email while still allowing IT to wipe company data from lost phones?
⚠ Common exam trap
Watch out — candidates often confuse full device wipe with selective wipe, assuming any remote wipe is acceptable, or they underestimate the importance of conditional access to enforce compliance before granting access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforce conditional access so only compliant MDM-enrolled devices can reach email and enable selective wipe for corporate data.
It combines conditional access policies (e.g., Azure AD Conditional Access or Intune compliance policies) to block noncompliant devices from accessing corporate email, while using MDM selective wipe to remove only corporate data (e.g., email, documents) without affecting personal data on the device. This approach enforces security without requiring a full device wipe, preserving user privacy and IT control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enforce conditional access so only compliant MDM-enrolled devices can reach email and enable selective wipe for corporate data.
Why this is correct
Conditional access stops noncompliant or compromised devices from using corporate email even if they have valid credentials. Selective wipe is especially important for BYOD because it removes work data without erasing personal content. Together, these controls support both access control and privacy, which is the correct architectural balance for the scenario.
- ✗
Require users to set a longer password on the email app and keep the current access policy.
Why it's wrong here
Requiring a longer password on the email app only authenticates the user's knowledge factor; it does not validate the device's trust posture. A compromised, rooted, or jailbroken device can present valid credentials and still be used to exfiltrate mail. Conditional access, by contrast, blocks the session before any data flows unless the device is enrolled in MDM and passes compliance checks such as patch level and encryption status.
- ✗
Disable email on all mobile devices and force users to use desktop computers only.
Why it's wrong here
Disabling mobile email entirely is a business-disruptive workaround rather than a security control; it fails to solve the underlying problem of untrusted devices. If employees rely on personal devices, they will likely circumvent the policy using web mail or personal accounts, creating shadow IT with no visibility. A balanced architecture preserves productivity by allowing access only to devices that are compliant and managed.
- ✗
Rely on a remote full factory reset whenever a device is lost or reported stolen.
Why it's wrong here
A remote factory reset only reacts after a device is already lost or stolen; it does nothing to prevent an attacker from accessing email while the device is still in hand or before the wipe is triggered. On BYOD, a full wipe destroys personal photos, contacts, and other data, creating privacy liability. Selective wipe from the MDM removes only corporate data, and pairing it with conditional access reduces the chance a risky device ever connects.
Go deeper
Related to this question
Learn chapter
Cloud Security Fundamentals
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.