How Can Organizations Prevent Data Loss from Lost Mobile Devices?
An employee who was working remotely lost a mobile device containing company data. Which of the following provides the best solution to prevent future data loss?
Community Votes
50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the distinction between passive protective controls and active management platforms, with the common trap being the selection of encryption for immediate data safety instead of recognizing the broader incident response value of device management.
This question evaluates the optimal technical control to mitigate data loss when a corporate mobile device is misplaced or stolen. While candidate votes are evenly split between MDM and FDE, CompTIA officially prioritizes MDM for its proactive management and recovery capabilities.
Full Disk Encryption (FDE) is the most frequent incorrect choice. Candidates select it because they correctly recognize that encryption renders stolen data unreadable, but they overlook that FDE is a local, passive control that cannot actively locate, lock, or wipe a lost device.
Community Discussion (15 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding the Core Concept
When evaluating security controls for lost or stolen hardware, certification exams often distinguish between protective measures and management frameworks. The scenario specifically asks for the "best solution to prevent future data loss," which in CompTIA's methodology implies a holistic approach that combines deterrence, compliance, and active recovery.Why MDM is the Correct Choice
Mobile Device Management (MDM) is the officially correct answer because it functions as an overarching governance platform. As highlighted by community discussions, MDM empowers IT administrators to centrally enforce security baselines, track device telemetry, lock compromised hardware, and execute remote wipes before sensitive information can be extracted [Comments 5, 8, 9]. Even when offline, MDM ensures that upon reconnection, compliance triggers activate automatically, making it the most sustainable defense against recurring incidents. Furthermore, MDM solutions natively enforce FDE policies, meaning selecting MDM inherently satisfies the encryption requirement while adding critical administrative oversight [Comments 3, 13].Why Other Options Fall Short
Full Disk Encryption (FDE) remains a highly debated distractor. While FDE effectively secures data at rest by requiring authentication to decrypt storage, it operates entirely passively [Comments 1, 10]. It cannot alert administrators, geolocate the hardware, or initiate recovery workflows if the device is permanently lost. Data Loss Prevention (DLP) monitors network traffic and endpoint activity to block unauthorized data transfers, but it does not manage physical asset loss. Endpoint Detection and Response (EDR) focuses on threat hunting, malware remediation, and behavioral analysis for traditional computing environments, making it structurally unsuited for mobile device lifecycle management.Official Reference
Exam Strategy
Always prioritize platform-level solutions that offer centralized control and actionable incident response over isolated cryptographic tools. When exam questions emphasize "preventing future" risks or require ongoing oversight, look for management frameworks like MDM or IAM rather than static protections like encryption.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →