CompTIA A+ Core 1 (220-1201)Mobile DevicesMedium
A company allows employees to use their personal smartphones for corporate email and apps under a BYOD (Bring Your Own Device) policy. The MDM administrator wants to keep corporate data completely isolated from the employee's personal apps and files on the same device. Which MDM feature accomplishes this?
- ARemote wipe
- BGeofencing
- CStorage segmentation (containerization)
- DPasscode enforcement
Show answer & explanationAnswer & explanation
Correct answer: C. Storage segmentation (containerization)
Storage segmentation, often called containerization, creates a separate encrypted workspace on the device for corporate data and apps, keeping it isolated from personal data. This allows IT to manage and wipe only the corporate container without affecting personal content.
Why the other options are wrong
- A. Remote wipe erases device data but does not itself isolate personal from corporate data.
- B. Geofencing restricts device functionality based on physical location, not data isolation.
- D. Passcode enforcement secures the whole device but does not separate personal and corporate data.
MDM Containerization (Storage Segmentation)
An MDM feature that creates an isolated, encrypted container on a device to separate corporate apps/data from personal content, commonly used in BYOD environments.
- Enables selective/corporate-only remote wipe
- Keeps personal and corporate data logically separated
- Common in BYOD policies to protect both privacy and company data
Memory trick: 'Container keeps work in its own box'