MD-102 Protect devices Practice Question
Your company uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that work apps are sandboxed from personal apps. Which enrollment type should you use?
⚠ Common exam trap
Candidates often confuse COPE with Work profile, assuming COPE is required for sandboxing on corporate-owned devices, but the question focuses on the enrollment type that ensures sandboxing regardless of ownership, making Work profile the correct choice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Work profile
The Work profile enrollment type is correct because it creates a separate, managed container on Android Enterprise devices that isolates work apps and data from personal apps and data. This sandboxing is enforced by the Android Enterprise framework, ensuring that work apps cannot access personal data and vice versa, which meets the requirement for separation without requiring full device management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fully managed
Why it's wrong here
Fully managed enrols the whole device as corporate, giving one work profile with no personal side, so no sandbox boundary between work and personal apps exists. It is tempting because fully managed suits company-owned, single-use devices where personal use is prohibited entirely.
- ✓
Work profile
Why this is correct
Android Enterprise work profile creates a separate managed profile on the device, isolating corporate apps and data from personal apps. This satisfies the sandboxing requirement by enforcing containerisation between work and personal contexts on the same device.
- ✗
Device administrator
Why it's wrong here
Device administrator enrolment manages the whole device through legacy Android APIs and cannot create the separate work profile that sandboxes work apps from personal apps. It is tempting because device administrator was the original Intune Android method, but it suits basic device-wide management, not app-level separation.
- ✗
Corporate-owned personally enabled (COPE)
Why it's wrong here
COPE enrols the entire device as corporate-owned and, unlike a dedicated work profile, does not isolate work apps from personal apps in a separate sandbox. It is tempting because COPE permits personal use on company hardware, but the separation it offers is policy-based, not a work-profile container.
Go deeper
Related to this question
Learn chapter
Deploying Applications with Intune
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.