Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your company is deploying Microsoft Intune for mobile device management. You need to ensure that corporate data on personally owned devices is protected without affecting the user's personal data. Which Intune feature should you use?

⚠ Common exam trap

A common mix-up: candidates confuse Conditional Access (which controls access to resources) with App Protection Policies (which protect data within apps), leading them to select Conditional Access for app control when the question specifically asks about protecting corporate data without affecting personal data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

App Protection Policies (MAM)

App Protection Policies (MAM) are the correct choice because they allow you to manage and protect corporate data within applications on personally owned devices without requiring device enrollment. This ensures that corporate data is encrypted, can be selectively wiped, and is prevented from being copied to personal apps, while leaving the user's personal data untouched.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Device compliance policies

    Why it's wrong here

    Device compliance policies evaluate the device's overall health (e.g., OS version, encryption, jailbreak status) and are enforced only after the device is enrolled and managed by Intune MDM. They do not secure individual apps or corporate data within apps; instead, they control device-level access to resources. For a bring-your-own-device (BYOD) scenario where you want to protect data in apps without full device enrollment, compliance policies are not the right tool, as they require device management and don't apply data-loss-prevention controls at the app layer.

  • ✗

    Conditional Access for app control

    Why it's wrong here

    Conditional Access with app control (e.g., 'Require approved client apps' or 'App protection policies') can restrict which apps clients can use to access Exchange Online or SharePoint. However, Conditional Access itself is a gatekeeping mechanism that enforces access conditions at authentication time, not a data-protection feature that encrypts, pins, or restricts copy/paste within an app on a personal device. It works alongside MAM policies, but alone it does not provide granular data-level safeguards such as preventing 'Save As' or restricting sharing between managed and unmanaged apps.

  • ✗

    Windows Autopilot

    Why it's wrong here

    Windows Autopilot is a device provisioning and deployment technology that automates the initial setup and configuration of new Windows devices, including enrolling them in Intune MDM and applying device configuration profiles. It has no role in protecting corporate data inside individual mobile apps or preventing data leakage from applications on personal devices. Autopilot is about getting the device ready for use, not about enforcing app-level data protection policies, so it is unrelated to the scenario described in the question.

  • ✓

    App Protection Policies (MAM)

    Why this is correct

    App Protection Policies (MAM) are specifically designed to protect corporate data within applications without requiring the device to be enrolled in device management. They enforce data-loss prevention (DLP) rules like PIN enforcement, data encryption, restrict cut/copy/paste, and prevent saving corporate data to personal stores. In a BYOD scenario, MAM policies apply to managed apps (e.g., Outlook, Word) and ensure that corporate data is contained, regardless of the device's management state, which directly matches the scenario of securing data on personal mobile devices.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.