Mobile Data Security After Device Theft
A threat actor was able to use a username and password to log in to a stolen company mobile device. Which of the following provides the best solution to increase mobile data security on all employees’ company mobile devices?
Community Votes
55% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the distinction between protecting the entire device versus isolating business applications, with containerization being the superior method for preventing unauthorized access to corporate resources.
This question addresses the best technical control to protect data on a stolen mobile device when credentials are compromised. Containerization is identified as the correct solution to isolate corporate data from personal storage.
Candidates often choose Remote Wipe because it removes data, but this fails if the attacker acts before the wipe occurs or if the device is offline. Full Disk Encryption is also common but less effective if the device is unlocked and the attacker has the password.
Community Discussion (41 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Containerization (Option D) creates a secure, isolated environment on the device that holds corporate data and applications. Even if the attacker logs in with valid credentials, they cannot access the contents of the secure container without specific authentication or bypassing the container's security controls. This ensures that corporate data remains protected regardless of whether the OS-level login is compromised.Why the Other Options Are Wrong
Application management (Option A) controls which apps can be installed but does not inherently protect data once an app is running. Full disk encryption (Option B) protects data at rest, but since the attacker successfully logged in, the volume is likely already decrypted and mounted for use. Remote wipe (Option C) is a reactive measure; it destroys data rather than securing it during the theft, and may fail if the device is offline or wiped by the attacker first.Community Comment Notes
The community comments largely discuss general exam preparation strategies, such as focusing on questions 600-860 and reviewing PBQs. One user noted scoring high by reviewing these specific sections, while another confirmed passing after studying similar scenarios. The comments do not provide specific technical debate on this question but confirm the relevance of mobile security topics in the exam.Exam Strategy
When a question involves 'stolen' devices and 'data security,' look for solutions that isolate business data from personal data or restrict access to specific corporate resources. Prioritize preventive isolation over reactive destruction.
Frequently Asked Questions
Why isn't full disk encryption the best answer?
FDE protects data at rest, but since the attacker successfully logged in, the device is likely unlocked and the data is accessible in memory or via active sessions.
Does remote wipe protect data from theft?
No, remote wipe destroys data. It is a recovery action, not a protection mechanism that allows continued secure operation or prevents immediate access.