MD-102 Protect devices Practice Question
A company uses Intune to manage macOS devices. They need to deploy a custom configuration profile that enforces FileVault encryption. What is the recommended approach?
⚠ Common exam trap
MD-102 often tests the preference for native Intune policies over third-party tools or manual methods — candidates may overcomplicate by choosing Apple Configurator or JAMF Pro when Intune has a built-in solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an endpoint security disk encryption policy in Intune and assign it to the devices
Intune provides a built-in endpoint security disk encryption policy for macOS that enforces FileVault encryption. This is the recommended approach because it integrates natively with Intune, allows assignment to device groups, and reports compliance status without requiring third-party tools or manual user action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an endpoint security disk encryption policy in Intune and assign it to the devices
Why this is correct
The endpoint security disk encryption policy is the built-in Intune workload for FileVault, applying the required encryption settings to macOS devices without a custom profile. This satisfies the scenario's need to enforce FileVault through a supported policy type.
- ✗
Use Apple Configurator to create the profile and import it into Intune
Why it's wrong here
Apple Configurator profiles are unsigned and cannot enforce FileVault through Intune's settings catalog; Intune's built-in FileVault disk encryption profile is required. It is tempting because Apple Configurator is correct for deploying custom payloads Apple's schema lacks, but FileVault is natively supported.
- ✗
Ask users to manually enable FileVault
Why it's wrong here
Manual enablement leaves FileVault optional, so users can skip it and devices remain unencrypted, breaching the enforced-encryption requirement. It is tempting because FileVault can be turned on by hand, and that would suffice for a small, unmanaged Mac fleet where no MDM configuration profile exists.
- ✗
Use JAMF Pro to manage FileVault
Why it's wrong here
JAMF Pro enforces FileVault through its own MDM channel, but the scenario specifies Intune-managed macOS devices, so a third-party MDM duplicates management and ignores Intune's built-in FileVault profile payload. It would be the right choice only where JAMF already manages the Mac estate.
Go deeper
Related to this question
Learn chapter
Deploying Applications with Intune
Key term
Configuration profile
A configuration profile is a set of settings and policies that can be applied remotely to devices to enforce security, compliance, and customization rules.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.