MD-102 Manage and maintain devices Practice Question
A company uses Microsoft Intune to manage macOS devices. A security audit requires that all macOS devices must have FileVault encryption enabled. Compliance policy reports show that 90% of devices are compliant, but 10% are non-compliant. You review the non-compliant devices and find that FileVault is enabled on them. What is the most likely cause of the non-compliance?
⚠ Common exam trap
Candidates often assume enabling FileVault alone satisfies compliance, but Intune requires the recovery key to be escrowed to confirm full manageability and recovery capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The recovery key is not escrowed to Intune.
The most likely cause is that the recovery key is not escrowed to Intune. Even though FileVault is enabled on the device, Intune's compliance policy checks for the presence of the FileVault recovery key in its escrow database. If the key is missing, the device is marked non-compliant because Intune cannot verify full management and recovery capability, which is a key security requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
FileVault is not actually enabled on those devices.
Why it's wrong here
The audit shows FileVault is enabled.
- ✓
The recovery key is not escrowed to Intune.
Why this is correct
Key escrow is required for compliance.
- ✗
The devices are not supervised.
Why it's wrong here
Supervision is not required for FileVault compliance.
- ✗
The compliance policy is not assigned to those devices.
Why it's wrong here
If not assigned, they would not show as non-compliant.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
Courseiva writes every MD-102 question from scratch — 942 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MD-102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses Microsoft Intune to manage macOS devices. They need to enforce FileVault encryption on all Macs. What should they configure?
easy- A.An endpoint security policy for disk encryption.
- ✓ B.A device configuration profile with FileVault settings.
- C.A device compliance policy that requires FileVault.
- D.An app protection policy.
Why B: FileVault encryption on macOS is enforced through a device configuration profile in Microsoft Intune. Specifically, you create a settings catalog or a custom profile that includes the FileVault settings under the 'System Preferences' > 'Security & Privacy' category, which allows you to require FileVault and escrow the recovery key to Intune. This is the native Intune method for managing macOS disk encryption, as endpoint security policies for disk encryption are designed for Windows BitLocker, not macOS.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.