MD-102 Protect devices Practice Question
A company wants to prevent corporate data from being copied from managed apps to personal apps on iOS devices. Which Intune policy should the administrator configure?
⚠ Common exam trap
Many exam-takers confuse App Protection Policies (which control data at the app layer) with Device Compliance Policies (which control device access), leading them to select the wrong option when the question focuses on data leakage prevention between apps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
App protection policy
App Protection Policies (APP) in Microsoft Intune are specifically designed to manage and protect corporate data within applications, regardless of the device enrollment state. On iOS, you can configure data transfer settings such as 'Allow app to transfer data to other apps' to restrict copying corporate data from managed apps to personal apps, using the iOS native inter-app control mechanisms like the Open-In management feature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Device configuration profile
Why it's wrong here
Device configuration profiles push settings to the operating system, such as Wi-Fi or restrictions, and do not govern data movement between managed and personal apps. App protection policies control that. Configuration profiles would be correct for enforcing device-level settings like passcode length or disabling the camera.
- ✗
Device compliance policy
Why it's wrong here
Compliance policies evaluate device settings such as jailbreak status or OS version and mark devices compliant or not; they cannot intercept clipboard actions between apps. App protection policies do that. Compliance policies would be correct for gating access to Microsoft Entra ID resources on device health.
- ✓
App protection policy
Why this is correct
App protection policies enforce data-transfer restrictions at the app layer, blocking cut, copy, and paste from managed apps to unmanaged personal apps on iOS. This directly satisfies the stem's requirement to prevent corporate data leakage between managed and personal apps, without needing device enrolment or MDM-level control.
- ✗
Enrollment restrictions
Why it's wrong here
Enrollment restrictions govern which devices or platforms may enrol, and apply before apps are managed. Blocking copy between managed and personal apps requires an app protection policy. Enrollment restrictions would be correct when excluding personally owned or unsupported devices from Intune enrolment entirely.
Go deeper
Related to this question
Learn chapter
Managing Microsoft 365 Apps and Office Updates
Key term
Device enrollment
Device enrollment is the process of registering a device with a management system so that it can receive policies, apps, and security settings under organizational control.
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.