Courseiva
Deploy and manage a Microsoft 365 tenantmediumMultiple ChoiceObjective-mapped

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Your company uses Microsoft 365 and has recently deployed Microsoft Intune for mobile device management. You need to ensure that corporate data on iOS devices is protected by preventing users from copying data from managed apps to unmanaged apps. What should you configure?

⚠ Common exam trap

Test-takers frequently confuse the deployment model (MAM without enrollment) with the actual policy configuration (app protection policies), or they mistakenly think device compliance or Conditional Access can control app-level data sharing, which they cannot.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

App protection policies.

App protection policies (APP) are the correct choice because they provide mobile application management (MAM) controls that specifically prevent data transfer between managed and unmanaged apps on iOS devices. Unlike device-level policies, APP operates at the application layer, allowing you to restrict copy/paste, cut, and data sharing actions without requiring device enrollment. This directly addresses the requirement to protect corporate data on iOS devices by blocking data leakage to unmanaged apps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Mobile application management (MAM) without enrollment.

    Why it's wrong here

    MAM without enrollment is a deployment model that lets you apply app protection policies to devices that are not enrolled in Microsoft Intune MDM. However, this model does not itself define the data-transfer restrictions; those restrictions are configured inside an app protection policy. Because the question asks which mechanism contains the setting to restrict copy-paste, choosing MAM without enrollment confuses the delivery channel with the actual policy definition.

  • Device compliance policies.

    Why it's wrong here

    Device compliance policies evaluate device-level conditions such as operating system versions, jailbreak status, and encryption to determine whether a device meets security baselines. These policies do not contain any app-specific settings that govern clipboard behavior or inter-app data sharing. Even if a device is fully compliant, a user could still copy-paste data from a managed app into an unmanaged app unless a separate app protection policy restricts that action.

  • Conditional Access policies.

    Why it's wrong here

    Conditional Access policies operate at the authentication gate and use signals like user identity, location, device compliance, and sign-in risk to grant or block access to Microsoft 365 services. They are evaluated before any app functionality is available, and they cannot enforce granular controls on how data is handled inside an application. Restricting copy-paste requires an app-level policy that remains active on the device after access is granted.

  • App protection policies.

    Why this is correct

    App protection policies in Microsoft Intune are specifically designed to manage data protection at the application layer, including settings to prevent copy-paste of organizational data into unmanaged apps. These policies can be assigned directly to users across devices with or without MDM enrollment, making them the correct mechanism for this scenario. For example, the 'Restrict cut, copy, and paste' policy mode can block the action entirely or allow it only between managed apps.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.