A company lets staff use their own smartphones for work email and wants to enforce a passcode policy and be able to remotely wipe corporate data if a phone is lost, without owning the devices. Which technology should the IT team deploy to meet this requirement?
- AA corporate VPN client on each phone so all traffic is encrypted and the devices can be controlled centrally
- BA shared Wi-Fi hotspot profile pushed to each phone so the company controls how the devices connect
- CA full factory reset scheduled on each phone so corporate data is cleared whenever a device is misplaced
- DA mobile device management platform that enrols each phone and applies passcode and remote-wipe policies Correct
Why A is wrong: A VPN secures data in transit and is tempting for corporate access, but it cannot enforce passcodes or remotely wipe a device, so it misses the policy requirement.
Why B is wrong: A managed hotspot profile controls connectivity, which sounds like central control, but it enforces no security policy and offers no remote wipe capability.
Why C is wrong: A factory reset does wipe data, but it is a one-off destructive action a user runs, not an enforceable ongoing policy, and it cannot set passcodes.
Why D is correct: MDM enrolment lets IT push a passcode policy and issue a remote wipe of corporate data on personally owned phones, which is exactly the stated requirement.