SC-100 Practice Question: Design security solutions for applications and data
Your company uses Microsoft Intune to manage mobile devices. You need to ensure that corporate data in Microsoft 365 apps cannot be copied to personal apps on the same device. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
App protection policy (MAM) with 'Restrict cut, copy, and paste'
An App protection policy (MAM) with 'Restrict cut, copy, and paste'. App protection policies in Intune operate at the app layer, so they can block copying corporate data from Microsoft 365 apps into personal apps on the same device, even on unmanaged or BYOD devices. This directly addresses the requirement to prevent data leakage between managed and personal apps. Option B (Conditional Access requiring a compliant device) controls access to resources but does not prevent copy/paste between apps. Option C (device configuration profile with restrictions) applies device-level settings and cannot selectively govern app-to-app data sharing. Option D (device compliance policy) only evaluates and reports device state; it does not enforce app-level copy/paste restrictions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
App protection policy (MAM) with 'Restrict cut, copy, and paste'
Why this is correct
App protection policy (MAM) with 'Restrict cut, copy, and paste' is correct because it applies at the application layer, targeting the clipboard as a data-channel control. This setting explicitly defines which apps can receive data copied from a managed app, typically allowing only other managed apps. It is effective even on unenrolled BYOD devices because it operates through the Intune App SDK/wrapped apps, not through device management. Unlike Conditional Access or device policies, this granular DLP control directly governs data transfer between managed and unmanaged apps.
- ✗
Conditional Access policy requiring compliant device
Why it's wrong here
Conditional Access requiring a compliant device is incorrect because it is an identity and access control mechanism that evaluates device compliance as a signal before granting access to cloud services. It can block sign-in or access from non-compliant devices, but once access is granted on a compliant device, there is no interception of clipboard operations. It lacks any data-loss prevention controls or app-level policies that would restrict cut/copy/paste between applications. Therefore, it addresses who or what can access resources, not how data moves between apps on the device.
- ✗
Device configuration profile with restrictions
Why it's wrong here
Device configuration profile with restrictions is incorrect because Intune device configuration profiles manage OS-level and hardware-level settings via configuration service providers (CSPs), such as password requirements, camera usage, or Bluetooth. There is no built-in device configuration profile setting that restricts clipboard operations per app or distinguishes between managed and unmanaged apps. The 'Restrict cut, copy, and paste' option is not exposed in device restrictions profiles; it exists only within app protection policies. Thus, this profile type cannot prevent data copying at the application level.
- ✗
Device compliance policy for mobile devices
Why it's wrong here
A device compliance policy for mobile devices is incorrect because compliance policies assess a device's security health, including encryption, jailbreak detection, and the minimum OS version, and then mark the device as compliant or noncompliant. They do not contain any settings or actions that govern data movement between applications, such as clipboard restrictions. A compliant device is still fully capable of copying and pasting text from a managed application into any third-party or unmanaged application. Compliance policies merely serve as an entry condition for Conditional Access; they do not enforce in-app data transfer controls.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.