ACSP Mobile Device Management (MDM) 5 — Questions and Answers
Question 1: A user's supervised iPhone shows 'Remote Management' in Settings but they cannot remove it. What configuration ensures this?
- User Enrollment profile installed manually
- MDM enrollment profile installed via ADE with a non-removable flag (Correct answer)
- A configuration profile distributed via email
- Manual pairing with Apple Configurator without supervision
Correct answer: MDM enrollment profile installed via ADE with a non-removable flag
ADE-based MDM enrollment profiles are flagged as non-removable, preventing users from unenrolling through Settings.
Question 2: Which MDM enrollment type is specifically designed to separate personal data from work data on personally owned iPhones?
- Device Enrollment via ADE
- User Enrollment (Correct answer)
- Open Enrollment via Safari
- Apple Configurator supervised enrollment
Correct answer: User Enrollment
User Enrollment creates a cryptographically separate Managed Apple Account partition, ensuring MDM can only see and manage work data.
Question 3: An MDM administrator enables 'Managed Open-In' on supervised iPhones. What does this restrict?
- Users cannot open any third-party apps
- Documents from managed apps cannot be opened in unmanaged apps, and vice versa (Correct answer)
- The device cannot open attachments from personal email
- Users cannot use AirDrop to receive files
Correct answer: Documents from managed apps cannot be opened in unmanaged apps, and vice versa
Managed Open-In (data loss prevention) prevents corporate documents from leaking into personal apps and personal files from entering managed apps.
Question 4: Which Apple platform feature, when combined with MDM, allows an organization to bypass Activation Lock on a supervised device without the user's Apple Account credentials?
- Recovery Mode restore
- Activation Lock bypass code stored by MDM during enrollment (Correct answer)
- Apple Configurator 2 erase
- System Preferences > Apple Account sign-out
Correct answer: Activation Lock bypass code stored by MDM during enrollment
When a supervised device enables Activation Lock, the MDM server can store a bypass code that IT can use to clear the lock without knowing the user's Apple Account password.
Question 5: A company deploys iPhones via ADE but needs certain devices to receive a different configuration profile based on department. How is this typically achieved?
- Manually install profiles after enrollment
- Assign devices to different MDM server groups or prestage enrollment groups in Apple Business Manager (Correct answer)
- Use Apple Configurator to apply department-specific profiles
- Create separate MDM servers for each department
Correct answer: Assign devices to different MDM server groups or prestage enrollment groups in Apple Business Manager
Apple Business Manager allows assigning devices to specific MDM servers or enrollment groups, which then apply the appropriate configuration profiles automatically.
Question 6: What certificate must be renewed annually to maintain MDM communication with Apple devices, and what happens if it expires?
- The SSL certificate on the MDM server
- The APNs certificate used by the MDM server (Correct answer)
- The device identity certificate
- The VPP token certificate
Correct answer: The APNs certificate used by the MDM server
The APNs certificate used by the MDM provider must be renewed each year; if it expires, the MDM server loses the ability to send push notifications to managed devices.
Question 7: An MDM admin sends a 'Lock Device' command to a supervised iPhone that already has a passcode set. What is the result?
- The device is erased and returns to Setup Assistant
- The device locks immediately and requires the existing passcode to unlock (Correct answer)
- A new 6-digit PIN is set by the MDM server
- The device enters Recovery Mode
Correct answer: The device locks immediately and requires the existing passcode to unlock
The MDM Lock Device command immediately locks the screen, and the user must enter their previously set passcode to regain access; it does not change or override the passcode.
A user's supervised iPhone shows 'Remote Management' in Settings but they cannot remove it.
What configuration ensures this?