How to Secure Company Mobile Devices After Credential Theft?

A threat actor was able to use a username and password to log in to a stolen company mobile device. Which of the following provides the best solution to increase mobile data security on all employees' company mobile devices?

  1. Application management
  2. Full disk encryption
  3. Remote wipe Source Reference Answer
  4. Containerization

Community Votes

C
59%
B
41%

59% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the critical distinction between at-rest cryptographic protection and centralized management capabilities, with the common trap being the assumption that encryption remains viable once an attacker has successfully authenticated with valid credentials.

This question evaluates the most effective organizational control to secure mobile device data after a credential-based breach. While candidates frequently debate endpoint encryption versus centralized management, the exam prioritizes out-of-band remediation strategies that protect corporate data across the entire device fleet.

Candidates typically choose Full Disk Encryption (B), reasoning that it safeguards data at rest. However, this overlooks the scenario's explicit detail that the threat actor already logged in using valid credentials, which bypasses encryption protections, and misses the organizational focus on scalable MDM-driven response.

Community Discussion (33 comments)

a4e15bd 👍 23
I would go with B. Here is the reasoning, for an immediate response to a compromised device, remote swipe may be the best option. But the question asks "What is the best solution to increase mobile data security on all employee's devices?" Implementing FDE across all company devices raises the baseline security for the entire organization ensuring that data on all devices is protected. With compromised credentials a remote swipe might even be too late, if you don't find out fast enough that the device has been stolen.
b82faaf 👍 11 Selected: B
B. Full disk encryption (FDE). The question was not asking about the single phone that was stolen (in which case a remote wipe may work after the fact); rather, it asks for "the best solution to increase mobile data security on all employees' company mobile devices".
Linas312 👍 1 Selected: D
The actual answer is MDM, but not here A. irrelevant B. also irrelevant, the actor has already signed in, the encryption is useless at this point C. is more of reaction rather than preventive. Either its B even though technically wrong, or D which is usually paired with MDM.. too many questions like this on these "Theory" exams.. Going with D, closest to the actual answer for this situation and scenario
Anyio 👍 1 Selected: B
B. Full disk encryption Explanation: Full disk encryption ensures that all data on a mobile device is encrypted and cannot be accessed without proper authentication. Even if a device is lost or stolen, the threat actor cannot access the data without the encryption key, adding a critical layer of protection. Other Options: A. Application management: Manages apps on devices but does not directly secure the data stored on the device. C. Remote wipe: Allows erasing data on lost devices but is reactive, requiring the device to be online and detected. It is not a preventative measure for data security. D. Containerization: Segregates personal and corporate data but doesn't protect the entire device, leaving other areas vulnerable.
jbmac 👍 3 Selected: D
The correct answer is: D. Containerization Explanation: Containerization is the best solution to enhance mobile data security in this scenario because it: Creates a secure, isolated environment for company data and applications on mobile devices. Ensures that even if a device is compromised, personal and corporate data remain segregated, reducing the risk to sensitive corporate data. Allows for secure access and management of corporate resources without impacting personal data on the device.
1f2b013 👍 4 Selected: C
Remote wipe allows an organization to erase all data on the device remotely, ensuring that even if a threat actor gains physical access and credentials, they cannot access the company data.
0ca8ee9 👍 7 Selected: C
Full disk encryption means nothing once the attacker logs in. Remote wipe is the most appropriate response.
viktorrdlyi 👍 2 Selected: B
The answer is B. The question is what should they do to increase the security o n employees phone. The question is not saying what should they do. with the stolen phone!!
TriBiT 👍 6 Selected: C
encryption means nothing if they are in using a username and password - remote wipe is need to protect the organization
cyberWoof 👍 1 Selected: B
The condition is "solution to increase mobile data security on all employees' company mobile devices", and that solution is 'B' - FDE
3dk1 👍 2 Selected: D
Even if a threat actor gains access to the device, they would still need to bypass additional authentication mechanisms to access the data within the container. IT administrators can enforce security policies within the container, such as restricting copy/paste functions, disabling screenshots, and requiring strong authentication.
e157c7c 👍 2 Selected: C
To those picking FDE because you wouldn't wipe all users' phones, this is missing the boat. You are implementing a remote wipe solution, NOT wiping everyones' phones. Given the example provided, I can't see anything but C being correct here.
Murtuza 👍 1 Selected: B
B makes sense
paytenj10 👍 1
It says "on ALL employees devices" You aren't going to full wipe every employees mobile devices when only one has been infiltrated. Full disk encryption will increase security going forward.
c7b3ff0 👍 1 Selected: C
I'm gonna keep it short here because Ty already explained it perfectly, but it's not B. "If someone steals a phone AND has your credentials, the device has already been pwned" and remote wiping the stolen device is pretty much your only option. You just have to hope it gets reported and the security team gets to it fast enough. There are other measures they could have taken beforehand that would make the attacker having the username and password less devastating. This would be a big "oops" moment, all you can do is damage control.
famuza77 👍 1
for some reason I thought FDE only worked with Laptops, well in this case I would choose FDE too
dhewa 👍 1 Selected: B
Key word here is on all employees company mobile phones, so why would you wipe everyone`s data when only one device was stolen.
Mich06 👍 2
'Data Protection: Full disk encryption (FDE) encrypts all data stored on a mobile device, ensuring that even if the device is lost or stolen, the data remains inaccessible without the proper authentication key (e.g., a password or PIN). This is crucial for protecting sensitive company information from unauthorized access' The answer is remote wipe because the device has already been accessed using the user name and password'
Ty13 👍 2 Selected: C
C. Remote Wipe Anyone who understands MDM would be able to answer this immediately. Phones are already encrypted - whether it's Android or Apple - otherwise your phone would be a disastrously vulnerable computer. If someone steals a phone AND has your credentials, the device has already been pwned and you have no option but to remote wipe it and hopefully stop them from accessing any further info.
NONS3c 👍 1 Selected: B
because he talk about the future so B is correct
2d97894 👍 1 Selected: B
Key Word: "increase mobile data security"
NONS3c 👍 1 Selected: C
Remote wipe allows the company to erase all data from a lost or stolen mobile device remotely. This ensures that even if a threat actor has access to the device and login credentials, the sensitive company data can be deleted, rendering the device essentially useless from a data standpoint.
Nehaltarek 👍 1 Selected: B
Answer: B the question here isa mind playing , the scenarios is on a stonelen device , however, the quation is asking about a security control on the rest of employee devices , not on the solen device according to ChatGPT: Full Disk Encryption (FDE): This ensures that all data stored on the device is encrypted, making it inaccessible without the correct authentication. Even if a threat actor gains physical access to the device, they won’t be able to read the data without the decryption key. This helps protect sensitive information from unauthorized access. Remote Wipe: Allows for the deletion of data on a stolen device, but it needs to be activated quickly after the device is stolen. If the device is not connected to the internet, remote wipe might not be effective.
17f9ef0 👍 1 Selected: B
Answer is B
myazureexams 👍 3
In that case, containerization would be the best single option. It separates work data from personal data, ensuring that even if a threat actor accesses personal data, they cannot reach the work data. However, it's important to note that this should be complemented with other security measures like strong passwords, two-factor authentication, and regular updates. Containerization and full disk encryption can help protect data on company mobile devices. Containerization separates work data from personal data, and full disk encryption secures data at rest. Additionally, remote wipe allows for deleting data if a device is lost or stolen. The question makes it seem like, we screwed up, what can we do moving forward to protect ALL mobile phones. So in that case you would go with any of the other choices. In the case for this particular phone. Remote wipe makes the most sense. If nothing else is already in place.
Norbe90 👍 3 Selected: C
Threat actor already has accessed the device using username and password, encryption is useless at this point. C is the correct one
suleman1000 👍 1 Selected: B
B. Full disk encryption
nesquick0 👍 4 Selected: C
C. Remote Wipe in this case B.(Full disk Encryption) is useless, since the attacker already logged-in so it has been decrypted.
EfaChux 👍 3 Selected: D
MDM containerization refers to the process of segregating personal and corporate data on personal devices by creating a logical container to enhance corporate data security. By using containerization, even if the thief gains access to device they will not able to access the official and confidential information on the device, also with containerization, remote wipe of the official information is possible.
Justhereforcomptia 👍 2 Selected: B
Also voting for B, FDE is the best solution. Remote wipe is done after the fact of the infiltration, which might take time to do or even be feasible.
nesquick0 👍 1 Selected: C
C. Remote wipe since full disk encryption does not protect the data after you sucessfully logged in with user and password also D. Containerization is not relatable.
nyyankee718 👍 2 Selected: C
Remote wipe, they already have the password
RoRoRoYourBoat 👍 1 Selected: C
C. Remote wipe: This feature allows the company to remotely erase all data on a stolen or lost device, ensuring that sensitive information is not accessible to unauthorized users.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Centralized Mobile Management vs. Endpoint Cryptography

The scenario describes a sophisticated attack where physical theft is combined with credential compromise. In modern mobile environments, Full Disk Encryption (FDE) relies on pre-boot authentication or hardware-bound keys to remain effective. Once an attacker possesses both the device and valid login credentials, they can decrypt and access all data, rendering FDE functionally useless for this specific threat vector.

Why Remote Wipe is the Correct Choice

Remote wipe is a foundational capability of Mobile Device Management (MDM) platforms designed specifically for this contingency. By deploying remote wipe policies across all corporate devices, organizations ensure that compromised hardware can be instantly sanitized from a central console. As noted in community discussions, multiple candidates highlight that "encryption means nothing once the attacker logs in," making out-of-band data destruction the only reliable method to prevent persistent corporate data exposure.

Why Other Options Are Incorrect

  • Application management (A) focuses on app lifecycle, permissions, and updates, but does not provide mechanisms to erase sensitive corporate data upon theft.
  • Full disk encryption (B) protects against offline attacks and physical loss without credentials, but fails here because authentication has already been bypassed.
  • Containerization (D) isolates corporate apps and data from personal user data, which is valuable for BYOD scenarios. However, it does not automatically purge data if the container itself is breached via valid credentials, and it lacks the immediate remediation capability that remote wipe provides.
Ultimately, SY0-701 emphasizes defense-in-depth through centralized governance. Remote wipe represents the most direct, scalable, and authoritative control to neutralize the risk posed by a credential-stolen mobile asset.

Official Reference

Exam Strategy

When a scenario confirms that an attacker has already authenticated successfully, immediately discard cryptographic controls like encryption, as they are designed to prevent unauthorized access, not mitigate post-compromise threats. Instead, pivot your analysis toward centralized management frameworks (MDM/EMM) and out-of-band remediation tools that allow administrators to enforce policies, isolate, or erase data across your entire device fleet.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide