SY0-701 Security Architecture Practice Question
Sales representatives use company-managed smartphones for email, CRM, and document access. If a phone is lost, IT must remove only the corporate apps and work data without erasing the employee's personal photos and contacts. Which control should be used?
⚠ Common exam trap
Candidates often confuse full factory reset (option A) with selective wipe, assuming any remote wipe will suffice, but the exam specifically tests the distinction between wiping all data versus only corporate-managed data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use selective wipe through a mobile device management platform.
Mobile Device Management (MDM) platforms support selective wipe, which uses management APIs (e.g., Android Enterprise Work Profile or iOS Managed Open In) to remove only corporate apps, accounts, and data while leaving personal content intact. This satisfies the requirement to protect corporate data without infringing on the employee's personal privacy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform a full factory reset remotely as soon as any device is reported lost.
Why it's wrong here
A full factory reset is an absolute, device-wide erasure that restores the device to its original out-of-box state. On a sales representative's personally owned or mixed-use device, this would delete personal photos, messages, and apps, causing user-relations issues and potentially violating data privacy expectations. MDM selective wipe exists specifically to remove only the corporate-managed data, apps, and profiles while leaving personal content untouched.
- ✓
Use selective wipe through a mobile device management platform.
Why this is correct
Selective wipe, executed through an MDM platform, targets only the corporate container or managed objects on the device, including work email, calendar, VPN profiles, certificates, and managed applications. Because personal data remains intact, this approach aligns with BYOD and COPE deployment models where users retain a privacy expectation. The remote administrative action also supports immediate response to a lost device without the collateral damage of a full factory reset.
- ✗
Disable password complexity so the user can regain access more easily after replacement.
Why it's wrong here
Removing or weakening the device password complexity policy directly reduces the cryptographic barrier protecting the lost device's contents. If an attacker gains physical possession, a weaker lock screen makes it easier to bypass authentication and access stored data, defeating the entire purpose of the device recovery response. The correct action is to remotely lock and selectively wipe the device, not to make it more accessible.
- ✗
Install a VPN profile and assume corporate data is safe if the network traffic is encrypted.
Why it's wrong here
Installing a VPN profile forces the device's network traffic through an encrypted tunnel, protecting data while it is transmitted over untrusted networks. However, it has no effect on data stored locally—emails, attachments, cached files—so if the device is lost, that dormant data remains exposed on the flash storage. A VPN also lacks the ability to remotely wipe or revoke access; encryption at rest and selective wipe are separate controls.
Go deeper
Related to this question
Learn chapter
Data Protection and Encryption at Rest
Key term
Bring Your Own Device
A policy allowing employees to use their personal laptops, smartphones, or tablets for work tasks instead of using company-issued equipment.
Key term
Mobile device management
Mobile device management (MDM) is a security solution that allows IT administrators to enroll, configure, monitor, and enforce policies on smartphones, tablets, and other mobile devices used in an organization.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.