SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Intune to manage devices. You need to ensure that corporate data on personally owned devices is removed when a user leaves the company, but personal data remains intact. What should you use?
⚠ Common exam trap
Many candidates confuse 'selective wipe' with 'full wipe' or assume that a Conditional Access policy can enforce data removal, when in fact only selective wipe provides granular corporate data removal while preserving personal data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Selective wipe (retire)
Selective wipe (retire) is the correct choice because it removes only corporate data from a personally owned device enrolled in Microsoft Intune, while preserving the user's personal data. This is achieved by targeting managed app data and corporate profiles, leaving personal apps, photos, and settings intact. It aligns with the requirement to protect corporate information upon employee departure without affecting the user's personal property.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Selective wipe (retire)
Why this is correct
Intune's retire action performs a selective wipe: it deletes only the organization's managed data, such as corporate email, VPN and Wi-Fi profiles, app configs, and protected app containers, then unenrolls the device. It deliberately preserves personal photos, personal apps, and other user data, making it the correct choice for BYOD when you must remove company information without damaging the user's private content.
- ✗
Conditional Access policy
Why it's wrong here
An Microsoft Entra ID/Entra ID Conditional Access policy is an access-control engine, not a data-cleansing tool; it evaluates risk, device compliance, and location to allow or block sign-in sessions. Blocking an unhealthy or out-of-compliance device temporarily prevents it from reaching corporate resources, but it leaves every byte of corporate data already on the device untouched and the device remains enrolled and managed.
- ✗
Full wipe
Why it's wrong here
Intune's full wipe (factory reset) resets the device to its out-of-box state, erasing the OS partitions, all user apps, personal photos, contacts, and the MDM enrollment itself. This is reserved for lost/stolen devices or corporate-owned devices being recycled, since it destroys personal and corporate data indiscriminately rather than isolating and removing only company data.
- ✗
Device compliance policy
Why it's wrong here
A compliance policy defines the expectations a device must meet, such as a minimum OS build, BitLocker enforcement, or being non-rooted, to be considered trustworthy for resource access. When a device falls out of compliance, Intune simply flags it and access is blocked via Conditional Access; compliance evaluation never invokes a wipe or data-deletion operation on the enrolled device.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.