Courseiva
Security ArchitectureeasyMultiple SelectObjective-mapped

SY0-701 Security Architecture Practice Question

Company-owned tablets run both business apps and approved personal apps. Which two controls best keep company data separated and support selective wipe? Select two.

⚠ Common exam trap

Candidates often confuse 'selective wipe' with a full device wipe, or assume that user promises (Option C) or convenience features (Option E) are acceptable security controls, when only containerization and managed wipe satisfy the separation and selective wipe requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Mobile device management with a work profile or container for corporate data.

Mobile Device Management (MDM) with a work profile or container creates a separate, encrypted partition on the device for corporate data. This container enforces policies (e.g., app whitelisting, VPN) and isolates business apps from personal apps, ensuring that company data remains protected even if the personal side is compromised.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Mobile device management with a work profile or container for corporate data.

    Why this is correct

    A mobile device management (MDM) work profile—such as Android Enterprise work profile or iOS managed app configuration—creates a cryptographically isolated container where corporate data, apps, and policies are managed separately from the personal environment. The container enforces its own PIN policy, encryption, app allowlisting, and traffic routing rules, so business data remains protected even on a shared device. This is the foundational control because it enables centralized administration without infringing on the user's personal apps and data.

  • Selective remote wipe of only the managed corporate container.

    Why this is correct

    Selective remote wipe targets only the managed corporate container—the container-specific encryption keys and application data are destroyed, while the user's personal photos, messages, and unmanaged apps remain untouched. This is essential for BYOD or corporate-owned personally-enabled (COPE) scenarios where a full wipe would be unacceptable. Importantly, it requires the device to be enrolled with an MDM and the corporate data to be properly containerized at the time of enrollment, which is why it complements rather than replaces container-based separation.

  • Allow users to install any app if they promise not to open work files.

    Why it's wrong here

    Requiring a verbal or written promise not to open work files assumes user behavior is a reliable security control, but technical enforcement is absent. If the device installs arbitrary apps from unapproved stores or sideloads, those apps can request broad permissions and potentially access corporate data via file shares, attachments, or clipboard, even if the user later avoids opening work files. The policy is unenforceable, creates a false sense of security, and violates mobile security best practices that require application allowlisting, integrity verification, and permission hygiene.

  • Store corporate files in the personal photo gallery for easier backup.

    Why it's wrong here

    Storing corporate files in the personal photo gallery removes the technical separation that makes containerized management possible, because the gallery is typically synced to consumer cloud services like iCloud or Google Photos and is accessible to any installed app with storage permissions. This exposes sensitive business data to personal cloud backup, unintended sharing, and third-party app data collection, and it eliminates the ability to perform a selective wipe on that data without erasing the user's personal memories. It also defeats the purpose of the work profile because the corporate data leaves the managed boundary.

  • Disable screen locks so users can access business apps faster.

    Why it's wrong here

    Disabling screen locks—removing PIN, pattern, or biometric authentication—lets anyone who picks up the device access the corporate apps and the underlying managed container without authentication. This violates the principle of least privilege and basic mobile device hardening, as the device's encryption at rest becomes ineffective when an attacker can simply unlock the screen. Even in a low-risk environment, the mobile device can be lost or stolen, and without a lock screen the corporate data is immediately exposed, making this a severe security regression.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.