A+ Lesson

MDM, Ownership Models, and Profile Security Requirements for A+

Last updated: 6/10/2026

Short answer

MDM is a toolset used to enroll devices, push configuration profiles, deploy apps, and perform remote actions like wipe. Ownership model determines what an organization may enforce: corporate-owned devices can usually be fully managed, while BYOD often requires separation of personal and corporate data (containerization) and user consent. Profile security requirements include password complexity, encryption mandates, app restrictions, and update policies, and must be chosen to balance security and user privacy.

Why it appears on the exam

- Given an ownership model and a required security control (e.g., encryption), indicate whether it can be enforced and how (profile push, user consent, or not enforceable). - Identify which profile settings should be mandatory for corporate-owned devices and optional for BYOD.

Key concepts

Concept 1

Required terms

MDM: Mobile Device Management: a centralized service that enrolls, monitors, and enforces policies on mobile devices. BYOD: Bring Your Own Device: ownership model where employees use personal devices for work and may limit what can be enforced. corporate-owned: Devices owned by the organization where stricter controls and full management are typically permissible.

Example

Enrolling a corporate phone in MDM to enforce device encryption and automatic updates.

Concept 2

How MDM, Ownership Models, and Profile Security Requirements works

MDM is a toolset used to enroll devices, push configuration profiles, deploy apps, and perform remote actions like wipe. Ownership model determines what an organization may enforce: corporate-owned devices can usually be fully managed, while BYOD often requires separation of personal and corporate data (containerization) and user consent. Profile security requirements include password complexity, encryption mandates, app restrictions, and update policies, and must be chosen to balance security and user privacy.

Example

Applying a work profile on a BYOD device that restricts corporate app data and allows the user to keep personal apps separate.

Concept 3

Common confusion

- "MDM equals spying" - MDM can collect inventory and enforce policies, but responsible deployments respect privacy and focus on corporate data control. - "BYOD cannot be secured" - BYOD can be secured via containerization and selective profiles, though full control is limited compared to corporate-owned devices.

Example

Enrolling a corporate phone in MDM to enforce device encryption and automatic updates.

Concept 4

Core 2 (220-1202) question cues

Given an ownership model and a required security control (e.g., encryption), indicate whether it can be enforced and how (profile push, user consent, or not enforceable); Identify which profile settings should be mandatory for corporate-owned devices and optional for BYOD.

Example

Applying a work profile on a BYOD device that restricts corporate app data and allows the user to keep personal apps separate.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.A technician is troubleshooting this situation: Enrolling a corporate phone in MDM to enforce device encryption and automatic updates. What should they identify?

Q2.A technician sees this situation: Applying a work profile on a BYOD device that restricts corporate app data and allows the user to keep personal apps separate. Which answer should they choose?

Q3.Read this A+ scenario: Devices owned by the organization where stricter controls and full management are typically permissible. Which term or action matches it?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8