Courseiva
Question 1,024 of 1,013
Security ArchitectureeasyMultiple ChoiceObjective-mapped

SY0-701 Security Architecture Practice Question

Field staff use company-owned tablets that also run approved personal apps. Security wants corporate email and documents separated from personal data, with the ability to wipe only the work data if a device is lost. What is the best control?

⚠ Common exam trap

Watch out — candidates often think a screen lock or disabling internet is sufficient for data separation, but the exam specifically tests the concept of containerization and selective wipe as the only method that meets both separation and targeted data removal requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use a work profile or container managed by a mobile device management platform.

A work profile or container managed by a mobile device management (MDM) platform creates a separate, encrypted partition on the device for corporate data. This allows the organization to enforce policies and perform a selective wipe of only the work container without affecting personal apps or data, meeting the requirement for separation and targeted remote wipe.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use a work profile or container managed by a mobile device management platform.

    Why this is correct

    A managed work profile or container is the best answer because it separates corporate data from personal applications on the same mobile device. That allows the organization to enforce policies on work data, protect corporate email and documents, and selectively remove only the business container if the tablet is lost or the user leaves. It supports a practical BYOD or COPE style deployment without wiping the user's personal content.

  • Disable all personal apps by removing internet access from the tablet.

    Why it's wrong here

    Blocking internet access on the tablet is an overly broad, network-level control that would break legitimate field operations, including the approved 2FA app and cloud services the company depends on. It also fails to isolate personal apps from corporate data because the OS still treats the entire filesystem, clipboard, and app data as shared, giving no granular per-app policies and no selective-wipe capability. The correct solution needs a managed work container, not a network kill switch.

  • Install only a screen lock and require a longer PIN for the tablet.

    Why it's wrong here

    A screen lock with a longer PIN raises the authentication strength for the whole device, but it is a device-level control that does not separate corporate from personal data. With only this control, work email and documents remain co-mingled with personal apps in the same unmanaged storage, and a lost tablet would still require wiping the entire device, erasing the user's personal data along with company data. Containerization, by contrast, can enforce distinct encryption and remote wipe scoped to corporate resources only.

  • Use a USB cable lock so the tablet cannot be physically moved.

    Why it's wrong here

    A USB cable lock is a physical security control designed to deter theft by anchoring the device to a desk, which is impractical for field staff who need to carry tablets to remote locations. Even when deployed, it provides zero protection for corporate data at rest or in-transit: the tablet's storage remains unencrypted, and a thief or finder could access the work profile if the device is unlocked. It cannot perform selective wiping, enforce container policies, or protect against remote attacks, so it fails the data-separation requirement entirely.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.