A fleet administrator configures MDM policy for Android devices to require automatic screen lock after 30 seconds of inactivity. What is the primary security rationale for this policy?
- A.A. Screen lock after 30 seconds prevents battery drain from the display staying on
- B.C. MDM policies require a minimum screen lock timeout to remain compliant with Android Enterprise enrollment requirements
- C.B. Short screen lock timeout limits the window of opportunity for unauthorized physical access after a device is left unattended, such as on a desk or in a meeting room
- D.D. Shorter lock timeouts improve biometric authentication accuracy by requiring more frequent verification
Why C is correct
Short screen lock timeout policies address the physical security risk of unattended devices. If an employee leaves their phone on a conference room table and steps out, a 30-second timeout means the device locks before an opportunistic attacker can access corporate email or apps. Longer timeouts (5+ minutes) create larger windows for unauthorized access. Battery conservation is a secondary benefit. Android Enterprise does not mandate specific timeout values. Lock frequency has no bearing on biometric accuracy.
Know someone studying for Mobile Security Fundamentals? Send them this one.