Courseiva

MD-102 Manage and maintain devices Practice Question

Your organization uses Microsoft Intune to manage iOS and Android devices. You need to ensure that corporate data on these devices is protected. Specifically, you want to prevent users from copying corporate data from managed apps to personal apps. You also want to ensure that when a device is lost or stolen, the corporate data can be selectively wiped without affecting personal data. Which Intune feature should you use to achieve these requirements?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

App Protection Policies (MAM).

App Protection Policies (MAM) provide data protection settings such as preventing copy/paste between managed and unmanaged apps, and allow selective wipe of corporate data. Option B is incorrect because device compliance policies focus on device-level settings, not app-level data protection. Option C is incorrect because conditional access policies control access based on compliance, but do not directly prevent copy/paste or provide selective wipe at the app level. Option D is incorrect because device configuration profiles configure device settings, not app data protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    App Protection Policies (MAM).

    Why this is correct

    App Protection Policies apply MAM controls at the app layer, blocking copy-paste and data transfer from managed apps to personal apps, and support selective wipe that removes only corporate data, leaving personal content intact on the enrolled device.

  • ✗

    Device Compliance Policies.

    Why it's wrong here

    Compliance policies only evaluate device state against rules such as encryption or OS version and report non-compliance; they cannot block copy-and-paste between apps or perform selective wipe. They are tempting because they gate access via Conditional Access, which suits enforcing posture requirements rather than app-level data containment.

  • ✗

    Conditional Access Policies.

    Why it's wrong here

    Conditional Access governs sign-in decisions based on user, device and location signals; it cannot stop data copying within an app or selectively erase corporate content. It is tempting because it pairs with compliance signals to restrict access, which is the right tool when the requirement is blocking authentication rather than protecting data on the device.

  • ✗

    Device Configuration Profiles.

    Why it's wrong here

    Device configuration profiles push settings such as Wi-Fi, passcode and restrictions to the OS; they do not create the app-level container that blocks copy-and-paste or enables selective wipe. They are tempting because they enforce device restrictions, which suits locking down hardware settings rather than separating corporate from personal app data.

About these practice questions

One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.