mediumMultiple SelectObjective-mapped
MD-102 Practice Question: Deploying Windows 11 using a task sequence in…
A company is deploying Windows 11 using a task sequence in Configuration Manager. They encounter an issue where the task sequence fails on devices that have BitLocker enabled. Which TWO actions should you take to ensure the task sequence completes successfully on BitLocker-enabled devices?
⚠ Common exam trap
Candidates often confuse 'Preprovision BitLocker' (used to enable encryption after OS deployment) with 'Suspend BitLocker' (used to temporarily disable protection during disk operations), leading them to incorrectly select Option A instead of Option C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a 'Suspend BitLocker' step before the 'Format and Partition Disk' step
Suspending BitLocker before the 'Format and Partition Disk' step prevents the task sequence from failing due to BitLocker-protected volumes. When BitLocker is active, the disk cannot be repartitioned or formatted without first suspending protection, as the Trusted Platform Module (TPM) validation and encryption keys would be invalidated. Option D is correct because the boot image must include the BitLocker optional component in WinPE to enable BitLocker-related operations (e.g., suspend, resume, preprovision) during the task sequence execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a 'Preprovision BitLocker' step before the 'Apply Operating System' step
Why it's wrong here
Preprovision is for enabling BitLocker, not for partition operations.
- ✗
Ensure the boot image includes the Microsoft BitLocker Administration and Monitoring (MBAM) optional component
Why it's wrong here
MBAM is not needed; the BitLocker optional component in WinPE is required.
- ✓
Add a 'Suspend BitLocker' step before the 'Format and Partition Disk' step
Why this is correct
Suspending BitLocker allows partition modifications.
- ✓
Ensure the boot image includes the BitLocker optional component in WinPE
Why this is correct
This component is needed to handle BitLocker during deployment.
- ✗
Disable Secure Boot in the device BIOS
Why it's wrong here
Disabling Secure Boot is not recommended and not required.
Go deeper
Related to this question
Learn chapter
Enrolling Devices with Microsoft Intune
Key term
TPM
TPM (Trusted Platform Module) is a dedicated hardware chip on a computer's motherboard that stores cryptographic keys, passwords, and certificates to secure the system against unauthorized access and tampering.
Key term
BitLocker
BitLocker is a full-disk encryption feature built into Windows that protects data by encrypting the entire drive so that unauthorized users cannot access files without the correct recovery key.
About these practice questions
This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.