Courseiva
Security ArchitecturemediumMultiple ChoiceObjective-mapped

SY0-701 Security Architecture Practice Question

Sales representatives use company-managed smartphones for email, CRM, and document access. If a phone is lost, IT must remove only the corporate apps and work data without erasing the employee's personal photos and contacts. Which control should be used?

⚠ Common exam trap

Candidates often confuse full factory reset (option A) with selective wipe, assuming any remote wipe will suffice, but the exam specifically tests the distinction between wiping all data versus only corporate-managed data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use selective wipe through a mobile device management platform.

Mobile Device Management (MDM) platforms support selective wipe, which uses management APIs (e.g., Android Enterprise Work Profile or iOS Managed Open In) to remove only corporate apps, accounts, and data while leaving personal content intact. This satisfies the requirement to protect corporate data without infringing on the employee's personal privacy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Perform a full factory reset remotely as soon as any device is reported lost.

    Why it's wrong here

    A full factory reset is an absolute, device-wide erasure that restores the device to its original out-of-box state. On a sales representative's personally owned or mixed-use device, this would delete personal photos, messages, and apps, causing user-relations issues and potentially violating data privacy expectations. MDM selective wipe exists specifically to remove only the corporate-managed data, apps, and profiles while leaving personal content untouched.

  • Use selective wipe through a mobile device management platform.

    Why this is correct

    Selective wipe, executed through an MDM platform, targets only the corporate container or managed objects on the device, including work email, calendar, VPN profiles, certificates, and managed applications. Because personal data remains intact, this approach aligns with BYOD and COPE deployment models where users retain a privacy expectation. The remote administrative action also supports immediate response to a lost device without the collateral damage of a full factory reset.

  • Disable password complexity so the user can regain access more easily after replacement.

    Why it's wrong here

    Removing or weakening the device password complexity policy directly reduces the cryptographic barrier protecting the lost device's contents. If an attacker gains physical possession, a weaker lock screen makes it easier to bypass authentication and access stored data, defeating the entire purpose of the device recovery response. The correct action is to remotely lock and selectively wipe the device, not to make it more accessible.

  • Install a VPN profile and assume corporate data is safe if the network traffic is encrypted.

    Why it's wrong here

    Installing a VPN profile forces the device's network traffic through an encrypted tunnel, protecting data while it is transmitted over untrusted networks. However, it has no effect on data stored locally—emails, attachments, cached files—so if the device is lost, that dormant data remains exposed on the flash storage. A VPN also lacks the ability to remotely wipe or revoke access; encryption at rest and selective wipe are separate controls.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.