Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium

A company is implementing a new BYOD (Bring Your Own Device) policy. To protect corporate data accessed on personal devices, they decide to use a solution that can remotely wipe corporate data without affecting personal data, and enforce specific security policies for corporate applications. Which technology is best suited for this requirement?

  1. AMobile Device Management (MDM)
  2. BVirtual Desktop Infrastructure (VDI)
  3. CMobile Application Management (MAM)
  4. DEndpoint Detection and Response (EDR)
Show answer & explanation

Correct answer: C. Mobile Application Management (MAM)

MAM focuses on managing and securing individual applications and their data, allowing for granular control, including selective wiping of corporate data, without impacting the entire personal device. MDM would manage the entire device, which is less ideal for BYOD.

Why the other options are wrong

  • A. MDM manages the entire device, which would allow full remote wipe and might interfere with personal data, making it less suitable for BYOD where users own the device.
  • B. VDI provides a virtualized desktop environment, which separates corporate data, but it's a different approach than directly managing corporate applications on a personal device.
  • D. EDR is for advanced threat detection and response on endpoints, not primarily for managing corporate data separation on BYOD.

Mobile Application Management (MAM)

Software that enables organizations to manage and secure corporate applications and data on mobile devices, often used in BYOD scenarios to separate business and personal content.

  • Manages applications and data, not the entire device.
  • Allows for selective wiping of corporate data.
  • Enforces policies on specific corporate apps.

Memory trick: MDM controls the phone, MAM controls the apps.

More Endpoint Security questions