How to Enforce Approved Applications on BYOD Devices?
A company is implementing a policy to allow employees to use their personal equipment for work. However, the company wants to ensure that only company-approved applications can be installed. Which of the following addresses this concern?
Community Votes
53% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you can distinguish between the policy enforcement framework (MDM) and a data isolation technique (containerization), recognizing that only MDM actively governs what can be installed on managed endpoints.
This question evaluates your understanding of BYOD security controls, specifically how organizations restrict software installations on personal hardware. The community consensus identifies MDM as the definitive solution, though a significant portion of candidates mistakenly select containerization due to overlapping BYOD terminology.
Candidates frequently select Containerization, reasoning that separating work apps from personal ones inherently controls installations. However, containerization primarily focuses on data isolation and boundary enforcement, whereas MDM provides the actual administrative controls, whitelisting capabilities, and policy distribution required by the scenario.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Correct Answer: MDM
Mobile Device Management (MDM) is the centralized platform designed to configure, monitor, and enforce security policies across mobile endpoints. In a Bring Your Own Device (BYOD) environment, MDM solutions implement application control mechanisms such as whitelisting or blacklisting, ensuring that only vendor-approved or enterprise-signed applications can be downloaded and executed. As highlighted by experienced professionals in the community, MDM directly addresses the requirement to restrict installations while maintaining the flexibility of personal device usage.Why Other Options Are Incorrect
Containerization creates an isolated runtime environment for corporate applications, effectively separating work data from personal files. While modern MDM platforms often leverage containerization as a feature to protect employee privacy, containerization itself is a technical implementation method rather than a policy enforcement framework. It does not natively dictate installation rules without an underlying management system. Data Loss Prevention (DLP) focuses on monitoring and blocking the unauthorized exfiltration of sensitive information, not on controlling software deployments. File Integrity Monitoring (FIM) tracks unauthorized modifications to critical system files and configurations. It operates reactively or continuously on host-level files and has no functionality related to mobile application approval or BYOD provisioning.Community Insight & Exam Context
The vote split between MDM and Containerization reflects real-world architectural overlaps, but CompTIA prioritizes the administrative control layer. Candidates who selected Containerization were focusing on the "personal equipment" keyword, but the core objective—enforcing an approved application list—is a classic MDM policy function. Always map the action verb (e.g., "ensure only approved applications can be installed") to the management tool that distributes and enforces that rule.Official Reference
- https://www.cisco.com/c/en/us/products/security/mobile-device-management.html
- https://csrc.nist.gov/publications/detail/sp/800-124/final
- CompTIA Security+ SY0-701 Objectives: Domain 1.3 (Implement and Secure Architectures)
Exam Strategy
When encountering BYOD or endpoint management questions, identify whether the scenario asks for policy enforcement, remote configuration, or compliance checking. These keywords point directly to MDM or EMM/UEM solutions. Reserve answers like containerization, sandboxing, or virtualization for questions that explicitly emphasize data isolation, privacy boundaries, or workload separation rather than installation governance.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →