Question

Difficulty: MediumMobile Application Support and Security Settings

An enterprise allows employees to access internal business applications on personal smartphones under a Bring Your Own Device (BYOD) policy. Management mandates that corporate data must be protected against unauthorized data leakage to personal applications, but the company must not have administrative control over personal files or the capability to wipe personal data from the device. Which management strategy should the IT administrator deploy to satisfy this security requirement?

  1. Mobile Application Management (MAM) utilizing containerization and data loss prevention (DLP) policiesAnswer
  2. B
    Full Mobile Device Management (MDM) profile enrollment enforcing mandatory full-device remote wipes
  3. C
    Hardware-level access control restricting device registration based on International Mobile Subscriber Identity (IMSI) numbers
  4. D
    Client account reconfiguration to use POP3 on port 993 for corporate data containment

Answer

Implement Mobile Application Management (MAM) utilizing containerization and data loss prevention (DLP) policies.
Mobile Application Management (MAM) creates an isolated container for corporate applications and data while applying Data Loss Prevention (DLP) rules to prevent copying content to personal apps. Because MAM only manages corporate apps and data, the administrator cannot view or wipe personal files on a BYOD smartphone, fully satisfying all policy requirements.

Step-by-Step Solution

1
Analyze the operational constraints and privacy requirements
Identified that corporate data must be segregated, but personal user data must remain completely untouched and exempt from company control or remote deletion.
BYOD policies require a balance between protecting enterprise assets and respecting user privacy.
2
Evaluate the management scope of MDM versus MAM
MDM controls the hardware and operating system level (enabling full device wipes), whereas MAM controls only enterprise-approved applications and their isolated data containers.
Choosing MDM would allow full device wipes and OS control, violating the user privacy requirement.
3
Select the appropriate security controls
Deploying MAM with containerization and DLP policies restricts corporate data transfers to personal apps while limiting remote wiping capabilities exclusively to corporate containers (selective wipe).
This satisfies both the data security constraint and the personal data privacy constraint.

Key Concept

Mobile Application Management (MAM) vs Mobile Device Management (MDM)
Rate this question