An IT administrator is configuring enterprise security controls for mobile devices accessing corporate data under a Bring Your Own Device (BYOD) deployment model. Match each mobile application security control on the left with its primary operational mechanism on the right.
- Application Containerization (MAM)Isolates enterprise application storage and encryption keys from personal user data without taking control of the entire hardware OS.
- Remote Selective WipeRemoves corporate encryption keys, managed app data, and enterprise email profiles while leaving personal files and photos intact.
- Sideloading RestrictionsEnforces digital signature verification policies to block installation of unverified software packages from unknown sources.
- S/MIME Email ConfigurationProvides public key infrastructure (PKI) based digital signing and end-to-end encryption for mobile email client messages.
Answer
Application Containerization (MAM) pairs with isolating enterprise apps and encryption keys from personal user data without OS-level control. Remote Selective Wipe pairs with removing corporate keys, managed app data, and profiles while leaving personal files intact. Sideloading Restrictions pair with enforcing digital signature verification to block unverified software packages. S/MIME Email Configuration pairs with providing PKI-based digital signing and end-to-end message encryption.
Application Containerization (MAM) isolates corporate data into encrypted sandboxes without taking over the host device hardware. Remote Selective Wipe targetedly clears enterprise containers and keys while maintaining user personal data privacy. Sideloading Restrictions restrict software installations strictly to signed, validated application packages from authorized repositories. S/MIME provides end-to-end security for mobile email using PKI certificates.
Step-by-Step Solution
Key Concept
Mobile Application Support and Security Settings