SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your company uses Microsoft Intune to manage mobile devices. You need to ensure that company data on personal devices is protected if the device is lost or stolen. What should you configure?
⚠ Common exam trap
A common mix-up: candidates confuse 'selective wipe' with 'full wipe' or assume that a Conditional Access policy alone can retroactively protect data already on a device, when in fact only a selective wipe actively removes company data from a lost or stolen personal device.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Selective wipe action
Selective wipe (Option D) is the correct configuration because it removes only corporate data from a personal device while preserving the user's personal apps, photos, and settings. In Microsoft Intune, a selective wipe targets managed app data and company email profiles via Exchange ActiveSync, leaving the device usable for personal purposes. This is the appropriate action for protecting company data on a lost or stolen BYOD device without overstepping into the user's private information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Compliance policy with device health requirements
Why it's wrong here
A Compliance policy with device health requirements is designed to evaluate a device's configuration against defined organizational standards, such as OS version or encryption status. While it can identify devices that do not meet these standards and mark them as non-compliant, it does not possess the capability to directly initiate a device wipe. Instead, non-compliance typically triggers other actions, such as blocking access to corporate resources via Conditional Access.
- ✗
Conditional Access policy requiring compliant devices
Why it's wrong here
A Conditional Access policy requiring compliant devices functions by enforcing access controls to corporate applications and data based on specific conditions, including a device's compliance status. If a device is non-compliant, Conditional Access will block access, preventing unauthorized data exposure. However, this policy type is solely focused on access enforcement and does not include any mechanism to perform a data wipe on the device itself.
- ✗
Full wipe action
Why it's wrong here
A Full wipe action, also known as a factory reset, is an aggressive device management command that completely erases all data, applications, and settings from a device, returning it to its original factory state. This includes personal photos, applications, and user accounts, making it generally inappropriate for Bring Your Own Device (BYOD) scenarios where personal data must be preserved. It is typically reserved for lost or stolen corporate-owned devices or devices being repurposed.
- ✓
Selective wipe action
Why this is correct
A Selective wipe action, often referred to as "Retire" in Microsoft Intune, is the appropriate choice for removing only organizational data while preserving the user's personal information. This action specifically targets and deletes all managed company applications, data, email profiles, and VPN connections that were deployed or configured by Intune. It is ideal for scenarios where an employee leaves the company or a BYOD device is unenrolled, ensuring corporate data security without impacting personal privacy.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Bring Your Own Device
A policy allowing employees to use their personal laptops, smartphones, or tablets for work tasks instead of using company-issued equipment.
Key term
BYOD
BYOD (Bring Your Own Device) is a policy allowing employees to use their personal devices for work tasks, increasing flexibility but introducing security and management challenges.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.