Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Intune to manage devices. You need to ensure that corporate data on personally owned devices is removed when a user leaves the company, but personal data remains intact. What should you use?

⚠ Common exam trap

Many candidates confuse 'selective wipe' with 'full wipe' or assume that a Conditional Access policy can enforce data removal, when in fact only selective wipe provides granular corporate data removal while preserving personal data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Selective wipe (retire)

Selective wipe (retire) is the correct choice because it removes only corporate data from a personally owned device enrolled in Microsoft Intune, while preserving the user's personal data. This is achieved by targeting managed app data and corporate profiles, leaving personal apps, photos, and settings intact. It aligns with the requirement to protect corporate information upon employee departure without affecting the user's personal property.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Selective wipe (retire)

    Why this is correct

    Intune's retire action performs a selective wipe: it deletes only the organization's managed data, such as corporate email, VPN and Wi-Fi profiles, app configs, and protected app containers, then unenrolls the device. It deliberately preserves personal photos, personal apps, and other user data, making it the correct choice for BYOD when you must remove company information without damaging the user's private content.

  • ✗

    Conditional Access policy

    Why it's wrong here

    An Microsoft Entra ID/Entra ID Conditional Access policy is an access-control engine, not a data-cleansing tool; it evaluates risk, device compliance, and location to allow or block sign-in sessions. Blocking an unhealthy or out-of-compliance device temporarily prevents it from reaching corporate resources, but it leaves every byte of corporate data already on the device untouched and the device remains enrolled and managed.

  • ✗

    Full wipe

    Why it's wrong here

    Intune's full wipe (factory reset) resets the device to its out-of-box state, erasing the OS partitions, all user apps, personal photos, contacts, and the MDM enrollment itself. This is reserved for lost/stolen devices or corporate-owned devices being recycled, since it destroys personal and corporate data indiscriminately rather than isolating and removing only company data.

  • ✗

    Device compliance policy

    Why it's wrong here

    A compliance policy defines the expectations a device must meet, such as a minimum OS build, BitLocker enforcement, or being non-rooted, to be considered trustworthy for resource access. When a device falls out of compliance, Intune simply flags it and access is blocked via Conditional Access; compliance evaluation never invokes a wipe or data-deletion operation on the enrolled device.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.