Courseiva
Protect devices →mediumMultiple Choice

MD-102 Protect devices Practice Question

A company uses Intune to manage macOS devices. They need to deploy a custom configuration profile that enforces FileVault encryption. What is the recommended approach?

⚠ Common exam trap

MD-102 often tests the preference for native Intune policies over third-party tools or manual methods — candidates may overcomplicate by choosing Apple Configurator or JAMF Pro when Intune has a built-in solution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an endpoint security disk encryption policy in Intune and assign it to the devices

Intune provides a built-in endpoint security disk encryption policy for macOS that enforces FileVault encryption. This is the recommended approach because it integrates natively with Intune, allows assignment to device groups, and reports compliance status without requiring third-party tools or manual user action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an endpoint security disk encryption policy in Intune and assign it to the devices

    Why this is correct

    The endpoint security disk encryption policy is the built-in Intune workload for FileVault, applying the required encryption settings to macOS devices without a custom profile. This satisfies the scenario's need to enforce FileVault through a supported policy type.

  • ✗

    Use Apple Configurator to create the profile and import it into Intune

    Why it's wrong here

    Apple Configurator profiles are unsigned and cannot enforce FileVault through Intune's settings catalog; Intune's built-in FileVault disk encryption profile is required. It is tempting because Apple Configurator is correct for deploying custom payloads Apple's schema lacks, but FileVault is natively supported.

  • ✗

    Ask users to manually enable FileVault

    Why it's wrong here

    Manual enablement leaves FileVault optional, so users can skip it and devices remain unencrypted, breaching the enforced-encryption requirement. It is tempting because FileVault can be turned on by hand, and that would suffice for a small, unmanaged Mac fleet where no MDM configuration profile exists.

  • ✗

    Use JAMF Pro to manage FileVault

    Why it's wrong here

    JAMF Pro enforces FileVault through its own MDM channel, but the scenario specifies Intune-managed macOS devices, so a third-party MDM duplicates management and ignores Intune's built-in FileVault profile payload. It would be the right choice only where JAMF already manages the Mac estate.

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.