MD-102 Manage and maintain devices Practice Question
Your organization uses Microsoft Intune to manage iOS and Android devices. You need to ensure that corporate data on these devices is protected. Specifically, you want to prevent users from copying corporate data from managed apps to personal apps. You also want to ensure that when a device is lost or stolen, the corporate data can be selectively wiped without affecting personal data. Which Intune feature should you use to achieve these requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
App Protection Policies (MAM).
App Protection Policies (MAM) provide data protection settings such as preventing copy/paste between managed and unmanaged apps, and allow selective wipe of corporate data. Option B is incorrect because device compliance policies focus on device-level settings, not app-level data protection. Option C is incorrect because conditional access policies control access based on compliance, but do not directly prevent copy/paste or provide selective wipe at the app level. Option D is incorrect because device configuration profiles configure device settings, not app data protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
App Protection Policies (MAM).
Why this is correct
App Protection Policies apply MAM controls at the app layer, blocking copy-paste and data transfer from managed apps to personal apps, and support selective wipe that removes only corporate data, leaving personal content intact on the enrolled device.
- ✗
Device Compliance Policies.
Why it's wrong here
Compliance policies only evaluate device state against rules such as encryption or OS version and report non-compliance; they cannot block copy-and-paste between apps or perform selective wipe. They are tempting because they gate access via Conditional Access, which suits enforcing posture requirements rather than app-level data containment.
- ✗
Conditional Access Policies.
Why it's wrong here
Conditional Access governs sign-in decisions based on user, device and location signals; it cannot stop data copying within an app or selectively erase corporate content. It is tempting because it pairs with compliance signals to restrict access, which is the right tool when the requirement is blocking authentication rather than protecting data on the device.
- ✗
Device Configuration Profiles.
Why it's wrong here
Device configuration profiles push settings such as Wi-Fi, passcode and restrictions to the OS; they do not create the app-level container that blocks copy-and-paste or enables selective wipe. They are tempting because they enforce device restrictions, which suits locking down hardware settings rather than separating corporate from personal app data.
Go deeper
Related to this question
Learn chapter
Configuring Compliance Policies
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.