Courseiva
Protect devices →mediumMultiple Choice

MD-102 Protect devices Practice Question

Your company uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that work apps are sandboxed from personal apps. Which enrollment type should you use?

⚠ Common exam trap

Candidates often confuse COPE with Work profile, assuming COPE is required for sandboxing on corporate-owned devices, but the question focuses on the enrollment type that ensures sandboxing regardless of ownership, making Work profile the correct choice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Work profile

The Work profile enrollment type is correct because it creates a separate, managed container on Android Enterprise devices that isolates work apps and data from personal apps and data. This sandboxing is enforced by the Android Enterprise framework, ensuring that work apps cannot access personal data and vice versa, which meets the requirement for separation without requiring full device management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Fully managed

    Why it's wrong here

    Fully managed enrols the whole device as corporate, giving one work profile with no personal side, so no sandbox boundary between work and personal apps exists. It is tempting because fully managed suits company-owned, single-use devices where personal use is prohibited entirely.

  • ✓

    Work profile

    Why this is correct

    Android Enterprise work profile creates a separate managed profile on the device, isolating corporate apps and data from personal apps. This satisfies the sandboxing requirement by enforcing containerisation between work and personal contexts on the same device.

  • ✗

    Device administrator

    Why it's wrong here

    Device administrator enrolment manages the whole device through legacy Android APIs and cannot create the separate work profile that sandboxes work apps from personal apps. It is tempting because device administrator was the original Intune Android method, but it suits basic device-wide management, not app-level separation.

  • ✗

    Corporate-owned personally enabled (COPE)

    Why it's wrong here

    COPE enrols the entire device as corporate-owned and, unlike a dedicated work profile, does not isolate work apps from personal apps in a separate sandbox. It is tempting because COPE permits personal use on company hardware, but the separation it offers is policy-based, not a work-profile container.

About these practice questions

One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.