Mobile Device Management (MDM) Flashcards
7 cards from real ACSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Mobile Device Management (MDM) flashcards as text
A user's supervised iPhone shows 'Remote Management' in Settings but they cannot remove it. What configuration ensures this?
Answer: MDM enrollment profile installed via ADE with a non-removable flag
ADE-based MDM enrollment profiles are flagged as non-removable, preventing users from unenrolling through Settings.
Which MDM enrollment type is specifically designed to separate personal data from work data on personally owned iPhones?
Answer: User Enrollment
User Enrollment creates a cryptographically separate Managed Apple Account partition, ensuring MDM can only see and manage work data.
An MDM administrator enables 'Managed Open-In' on supervised iPhones. What does this restrict?
Answer: Documents from managed apps cannot be opened in unmanaged apps, and vice versa
Managed Open-In (data loss prevention) prevents corporate documents from leaking into personal apps and personal files from entering managed apps.
Which Apple platform feature, when combined with MDM, allows an organization to bypass Activation Lock on a supervised device without the user's Apple Account credentials?
Answer: Activation Lock bypass code stored by MDM during enrollment
When a supervised device enables Activation Lock, the MDM server can store a bypass code that IT can use to clear the lock without knowing the user's Apple Account password.
A company deploys iPhones via ADE but needs certain devices to receive a different configuration profile based on department. How is this typically achieved?
Answer: Assign devices to different MDM server groups or prestage enrollment groups in Apple Business Manager
Apple Business Manager allows assigning devices to specific MDM servers or enrollment groups, which then apply the appropriate configuration profiles automatically.
What certificate must be renewed annually to maintain MDM communication with Apple devices, and what happens if it expires?
Answer: The APNs certificate used by the MDM server
The APNs certificate used by the MDM provider must be renewed each year; if it expires, the MDM server loses the ability to send push notifications to managed devices.
An MDM admin sends a 'Lock Device' command to a supervised iPhone that already has a passcode set. What is the result?
Answer: The device locks immediately and requires the existing passcode to unlock
The MDM Lock Device command immediately locks the screen, and the user must enter their previously set passcode to regain access; it does not change or override the passcode.