A financial company permits employees to use their personal smartphones (BYOD) for work-related duties. The company's security policy requires that corporate emails and internal documents must be encrypted, isolated from personal applications, and prevented from being copied to unauthorized personal storage. Additionally, IT must maintain the ability to wipe corporate data selectively if an employee resigns, without modifying personal photos, apps, or settings. Which of the following administrative solutions should the technician implement to fulfill these security requirements?
- Enroll devices in a Mobile Application Management (MAM) solution using application containerizationAnswer
- BEnroll devices in full Mobile Device Management (MDM) and configure automated full device remote wipes
- CConfigure corporate email access using POP3 over port 995 with SSL/TLS enabled
- DRestrict app data access by binding the device's cellular IMSI identifier to corporate firewall ACLs
Answer
Enroll devices in a Mobile Application Management (MAM) solution using application containerization.
Mobile Application Management (MAM) combined with containerization isolates enterprise applications into a secure, encrypted sandbox on the user's mobile device. This enforces data loss prevention policies (preventing copy/paste to personal apps) and allows administrators to execute selective wipes of corporate data without impacting the user's personal apps or data.
Step-by-Step Solution
Key Concept
Mobile Application Management (MAM) vs. Mobile Device Management (MDM) Containerization
Estimated Time:1m 30s