MD-102 Manage applications Practice Question
You are configuring an app protection policy in Microsoft Intune for iOS/iPadOS devices. Which setting can you enforce to prevent users from copying data from a managed app and pasting it into an unmanaged app?
⚠ Common exam trap
Many candidates confuse device-level restrictions (like jailbreak detection or backup blocking) with app-level data transfer controls, assuming any security setting prevents copy/paste, when only the specific 'Restrict cut, copy, and paste' setting governs clipboard behavior between managed and unmanaged apps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restrict cut, copy, and paste between other apps
The 'Restrict cut, copy, and paste between other apps' setting in an Intune app protection policy (APP) for iOS/iPadOS directly controls data transfer between managed and unmanaged apps. When set to 'Blocked' or 'Policy Managed with Paste In', it prevents users from copying data from a managed app and pasting it into an unmanaged app, enforcing data leakage prevention at the OS clipboard level via the Intune MAM SDK.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Restrict cut, copy, and paste between other apps
Why this is correct
Restricting cut, copy and paste between other apps blocks clipboard transfer from managed to unmanaged apps on iOS/iPadOS, directly preventing the data-leak scenario. It is an app protection policy setting applied at the app layer.
- ✗
Require a PIN for access
Why it's wrong here
A PIN gates access to the managed app but does not govern clipboard behaviour between apps, so copy-paste into unmanaged apps remains possible. It is tempting because PIN requirements are a core app protection control, and they would be the right setting when the requirement is to enforce authentication before opening corporate data.
- ✗
Prevent iTunes and iCloud backups
Why it's wrong here
Preventing iTunes and iCloud backups stops corporate data being written to unmanaged backup locations; it has no effect on clipboard operations between apps. It is tempting because it is a real data-sharing restriction within app protection policies, and it would be correct if the requirement were to stop managed app data reaching personal backup storage.
- ✗
Block managed apps from running on jailbroken devices
Why it's wrong here
Jailbreak detection blocks managed apps from launching on compromised devices; it does not restrict clipboard sharing between managed and unmanaged apps on compliant devices. It is tempting because it is a genuine app protection policy setting, and it would be correct if the requirement were to deny access on rooted or jailbroken hardware.
Go deeper
Related to this question
Learn chapter
Implementing App Protection Policies (MAM)
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
App protection policy
An app protection policy is a set of rules that controls how data is handled and secured within mobile applications, ensuring corporate information stays safe even on personal devices.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.