A field sales representative uses a personal Android smartphone within a corporate Bring Your Own Device (BYOD) program. The organization's security officer requires that sensitive corporate emails and proprietary customer attachments remain encrypted at rest, isolated from personal storage, and protected against copying data into unauthorized personal applications. Furthermore, the corporate IT department must not hold permissions to inspect or remotely wipe the employee's personal photos or private applications. Which configuration setting or management strategy should the IT support technician implement on the device?
- Implement application containerization governed by Mobile Application Management (MAM) policies.Answer
- BEnroll the smartphone into a Mobile Device Management (MDM) profile enforcing full device storage encryption and unrestricted remote wipe permissions.
- CConfigure the corporate mail profile to sync strictly over POP3 using SSL port 993.
- DRegister the device's International Mobile Equipment Identity (IMEI) with the cellular carrier to restrict data access to approved SIM cards.
Answer
Implement application containerization governed by Mobile Application Management (MAM) policies.
Application containerization managed through Mobile Application Management (MAM) creates a secure logical boundary around business apps and data on a personal device. It allows IT administrators to apply Data Loss Prevention (DLP) controls—such as prohibiting data copying to unmanaged apps—and perform selective remote wipes of business content without inspecting or deleting the user's personal photos and applications.
Step-by-Step Solution
Key Concept
Mobile Application Management (MAM) and Application Containerization in BYOD Environments
Estimated Time:2m 0s