How Can Organizations Prevent Data Loss from Lost Mobile Devices?

An employee who was working remotely lost a mobile device containing company data. Which of the following provides the best solution to prevent future data loss?

  1. MDM Source Reference Answer
  2. DLP
  3. FDE
  4. EDR

Community Votes

A
50%
C
50%

50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the distinction between passive protective controls and active management platforms, with the common trap being the selection of encryption for immediate data safety instead of recognizing the broader incident response value of device management.

This question evaluates the optimal technical control to mitigate data loss when a corporate mobile device is misplaced or stolen. While candidate votes are evenly split between MDM and FDE, CompTIA officially prioritizes MDM for its proactive management and recovery capabilities.

Full Disk Encryption (FDE) is the most frequent incorrect choice. Candidates select it because they correctly recognize that encryption renders stolen data unreadable, but they overlook that FDE is a local, passive control that cannot actively locate, lock, or wipe a lost device.

Community Discussion (15 comments)

laternak26 👍 5 Selected: C
Full Disk Encryption (FDE) ensures that all data stored on the device is encrypted, making it inaccessible without proper authentication (such as a password or biometric verification). If the mobile device is lost or stolen, the data remains secure because it is encrypted. This helps protect sensitive company data even if the device is no longer in the employee’s possession. Not A. MDM (Mobile Device Management): While MDM is excellent for managing devices, enforcing security policies, and remotely wiping or locking a lost device, it doesn't directly address the encryption of data. It's more focused on managing device configurations and enforcing security policies.
timotei 👍 1 Selected: C
C, Which of the following gives you honey? Beekeeper(MCM) or Bee (FDE)?
timotei 👍 1 Selected: C
C. MDM can only enforce FDE policy but doesn't prevent data loss whereas FDE itself is a solution to prevent future data loss.
Commando9800 👍 1 Selected: A
Which of the following Provides the best solution. Not is the best solution
Nahidwin 👍 1 Selected: A
A you can lock device or remotely wipe it
f92c9d7 👍 3 Selected: A
MDM solutions allow administrators to remotely manage and secure mobile devices, enforce security policies, and ensure compliance.
Drey09 👍 1 Selected: A
MDM prove uma proteção melhor
Robuste7 👍 1 Selected: A
The solution in this scenario should focus on preventing future data loss. MDM directly tackles the issue by giving the company control over devices, allowing them to prevent data loss proactively through remote wipe capabilities, security enforcement, and monitoring. It’s a comprehensive solution for managing mobile device risks. So the answer can' t be FDE because FDE protects data on the device if it's lost, but it doesn’t prevent future data loss or help manage the device. It’s a reactive solution, not proactive.
jsap 👍 1 Selected: A
MDM solutions are designed to manage and secure mobile devices. They can enforce policies such as: Remote wiping of lost or stolen devices. Requiring strong authentication. Enabling encryption. This directly addresses the risk of data loss by providing organizations with control over remote devices, even if they are lost.
Storcaks 👍 2 Selected: C
Should be FDE. MDM will not help in case a lost/stolen device that is disconnected from internet and sim removed. FDE will still provide protection in that case.
ProudFather 👍 2 Selected: C
Full Disk Encryption (FDE) is the best solution to prevent data loss in this scenario. It encrypts all data stored on the device, including the operating system, applications, and user data. This ensures that even if the device is lost or stolen, the data remains inaccessible to unauthorized individuals.
0ca8ee9 👍 3 Selected: C
While several measures can help mitigate data loss from lost or stolen devices, the best solution to prevent future data loss in this scenario is a combination of Full Disk Encryption (FDE) and Mobile Device Management (MDM), with a strong emphasis on remote wipe capability within the MDM solution.
Fourgehan 👍 2 Selected: A
Mobile Device Management (MDM) is a solution specifically designed to manage, monitor, and secure mobile devices, such as smartphones and tablets, that access company data. MDM allows administrators to enforce security policies on these devices, such as requiring encryption, enforcing password requirements, and remotely wiping devices in the event of loss or theft. This would be the best solution to prevent future data loss in a scenario where an employee loses a mobile device containing sensitive company data
s_plus 👍 2
*Mobile Device Management Data Loss Prevention Full Disk Encryption Endpoint Detection Response
chasingsummer 👍 4 Selected: A
Mobile device management (MDM)

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding the Core Concept

When evaluating security controls for lost or stolen hardware, certification exams often distinguish between protective measures and management frameworks. The scenario specifically asks for the "best solution to prevent future data loss," which in CompTIA's methodology implies a holistic approach that combines deterrence, compliance, and active recovery.

Why MDM is the Correct Choice

Mobile Device Management (MDM) is the officially correct answer because it functions as an overarching governance platform. As highlighted by community discussions, MDM empowers IT administrators to centrally enforce security baselines, track device telemetry, lock compromised hardware, and execute remote wipes before sensitive information can be extracted [Comments 5, 8, 9]. Even when offline, MDM ensures that upon reconnection, compliance triggers activate automatically, making it the most sustainable defense against recurring incidents. Furthermore, MDM solutions natively enforce FDE policies, meaning selecting MDM inherently satisfies the encryption requirement while adding critical administrative oversight [Comments 3, 13].

Why Other Options Fall Short

Full Disk Encryption (FDE) remains a highly debated distractor. While FDE effectively secures data at rest by requiring authentication to decrypt storage, it operates entirely passively [Comments 1, 10]. It cannot alert administrators, geolocate the hardware, or initiate recovery workflows if the device is permanently lost. Data Loss Prevention (DLP) monitors network traffic and endpoint activity to block unauthorized data transfers, but it does not manage physical asset loss. Endpoint Detection and Response (EDR) focuses on threat hunting, malware remediation, and behavioral analysis for traditional computing environments, making it structurally unsuited for mobile device lifecycle management.

Official Reference

Exam Strategy

Always prioritize platform-level solutions that offer centralized control and actionable incident response over isolated cryptographic tools. When exam questions emphasize "preventing future" risks or require ongoing oversight, look for management frameworks like MDM or IAM rather than static protections like encryption.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide