SY0-701 Security Architecture Practice Question
Company-owned tablets are used by field staff for both corporate email and approved personal apps. Security must isolate company data from personal data, allow remote wipe of only the corporate workspace, and block access if the device is rooted or encryption is disabled. Which approach best fits?
⚠ Common exam trap
Test-takers frequently confuse a full-device wipe (which destroys personal data) with a selective wipe (which only removes the corporate container), or assume that a VPN or anti-malware app alone can provide the required isolation and compliance enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use MDM or UEM with a managed work profile or container, compliance checks, and selective wipe.
Mobile Device Management (MDM) or Unified Endpoint Management (UEM) with a managed work profile (e.g., Android Work Profile or iOS Managed Open In) creates a separate, encrypted container for corporate data. This allows compliance checks to detect rooted devices or disabled encryption, and enables a selective wipe that removes only the corporate workspace without affecting personal apps or data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a consumer anti-malware app and perform a full-device wipe if the tablet is lost.
Why it's wrong here
A consumer anti-malware app lacks the OS-level management hooks needed to create a secure work container or enforce conditional access policies, so it cannot separate corporate data from personal data on a company-owned tablet. A full-device wipe is an intrusive and unreliable response to loss—it erases the user’s personal photos and apps, and it will not work if the tablet is powered off, offline, or hasn’t been granted the appropriate device administrator privileges. Without enrollment in MDM, there is also no way to check whether the device is eligible (e.g., patched, encrypted, not rooted) before granting access.
- ✓
Use MDM or UEM with a managed work profile or container, compliance checks, and selective wipe.
Why this is correct
An MDM/UEM solution with a managed work profile or container separates corporate apps and data into an isolated, policy-controlled space on the same tablet, leaving personal content untouched. Compliance checks—such as validating passcode strength, OS patch level, and rooting/jailbreak status—allow the system to block access to corporate resources on noncompliant devices. A selective wipe then removes only the managed container and corporate data if needed, preserving the user’s personal information, which perfectly suits company-owned tablets used for both purposes.
- ✗
Install a VPN app on the tablets and let users choose their own lock-screen settings.
Why it's wrong here
Installing a VPN only encrypts the network connection in transit; it does nothing on the device to isolate corporate files, enforce a managed configuration, or control which apps can access corporate data. Allowing users to choose their own lock-screen settings risks enabling weak or no authentication, so any stolen tablet could expose corporate email, documents, or intranet resources without an obstacle. There is also no remote selective-wipe capability or compliance evaluation, leaving the company without a way to revoke access if the device is lost or the employee terminates.
- ✗
Use application allowlisting alone and avoid enrolling the tablets in a management platform.
Why it's wrong here
Application allowlisting limits which apps can be launched but does not build a secure container around corporate data, nor does it provide a way to perform multi-factor authentication, enforce passcode rules, or push managed configurations. Because the tablets are not enrolled in any management platform, the IT team loses the ability to query the device’s security posture, track its location, or run a selective wipe of corporate resources after a separation. On modern mobile OSes, allowlisting alone is also difficult to administer without an MDM/UEM framework, and it can be circumvented by sideloading or OS weaknesses.
Go deeper
Related to this question
Learn chapter
Cloud Security Fundamentals
Key term
Mobile device management
Mobile device management (MDM) is a security solution that allows IT administrators to enroll, configure, monitor, and enforce policies on smartphones, tablets, and other mobile devices used in an organization.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.