MD-102 Protect devices Practice Question
Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that corporate data is separated from personal data on the device. Which management approach should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Android Enterprise work profile
Android Enterprise work profile creates a separate container for corporate data, keeping it isolated from personal data on the same device. Android Enterprise fully managed devices are for corporate-owned devices and do not have a personal space. Android Enterprise kiosk mode locks the device to a single app or set of apps, not designed for data separation. Android device administrator is a legacy management method that does not provide data separation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Android Enterprise kiosk mode
Why it's wrong here
Kiosk mode locks a device to a single app or set of apps, giving no personal-use side at all. It is tempting because it strongly isolates corporate apps, and it is correct for dedicated, single-purpose frontline devices, but not where personal and corporate data must coexist.
- ✗
Android Enterprise fully managed
Why it's wrong here
Fully managed mode takes over the entire device, leaving no personal profile to separate corporate data from. It is tempting because it offers strong corporate control, and it is correct for corporate-owned, single-use devices, but the scenario requires a work profile alongside personal use.
- ✓
Android Enterprise work profile
Why this is correct
A work profile creates a separate, managed container on the device, keeping corporate apps and data isolated from the personal profile. This directly satisfies the requirement to separate corporate from personal data on Android Enterprise devices.
- ✗
Android device administrator
Why it's wrong here
Android device administrator is deprecated and provides no work-profile container, so corporate and personal data share one profile. It is tempting as the legacy Intune enrolment method for older Android versions, but it cannot deliver the separation that Android Enterprise work profiles provide.
Go deeper
Related to this question
Learn chapter
Managing Microsoft 365 Apps and Office Updates
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.