MD-102 Prepare infrastructure for devices Practice Question
Your company uses Microsoft Intune to manage mobile devices. You need to ensure that corporate data on Android Enterprise work profiles is protected so that users cannot copy and paste data from work apps to personal apps. Which configuration should you implement?
⚠ Common exam trap
MD-102 often tests the difference between app protection policies (MAM, app-level data control) and device configuration/compliance policies (MDM, device-level settings), catching candidates who pick device-level controls for app-level data protection requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an app protection policy that restricts data transfer between work and personal apps.
App protection policies (also called MAM policies) in Intune are designed to protect corporate data at the app layer, independent of device enrollment. For Android Enterprise work profiles, an app protection policy can enforce data transfer restrictions such as blocking copy/paste between work and personal apps, restricting save-as, and controlling sharing. This directly addresses the requirement without affecting the personal side of the device.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an app protection policy that restricts data transfer between work and personal apps.
Why this is correct
An app protection policy enforces data-transfer restrictions at the app layer, blocking copy, paste and share actions between managed work apps and unmanaged personal apps within the Android Enterprise work profile. This directly satisfies the stem's requirement to prevent corporate data leaking from work apps to personal apps.
- ✗
Create a device configuration policy that disables clipboard sharing.
Why it's wrong here
Device configuration policies set OS settings on the device itself; clipboard restrictions between work and personal profiles are enforced through app protection policies, which govern data movement across the work/personal boundary. Device configuration is tempting because it manages device-level settings, but it cannot control cross-profile copy and paste.
- ✗
Create a device compliance policy that requires a work profile.
Why it's wrong here
Compliance policies only evaluate and report whether a device meets conditions such as requiring a work profile; they do not restrict data movement. Requiring a work profile is tempting because it enforces the Android Enterprise enrolment model, which would be correct when gating access on enrolment type rather than preventing clipboard sharing.
- ✗
Create a conditional access policy that blocks personal apps.
Why it's wrong here
Conditional access governs sign-in and session conditions, not intra-device data movement between work and personal apps. Blocking personal apps would be correct for restricting access to corporate resources from unmanaged apps, whereas Android Enterprise work profile app protection policies prevent copy and paste.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Device enrollment
Device enrollment is the process of registering a device with a management system so that it can receive policies, apps, and security settings under organizational control.
Key term
App protection policy
An app protection policy is a set of rules that controls how data is handled and secured within mobile applications, ensuring corporate information stays safe even on personal devices.
About these practice questions
This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.