MD-102 Manage and maintain devices Practice Question
A company uses Microsoft Intune to manage macOS devices. They need to enforce FileVault encryption on all Macs. What should they configure?
⚠ Common exam trap
Candidates often confuse 'endpoint security policies' (which are Windows-only for disk encryption) with device configuration profiles (which handle macOS FileVault), leading them to select Option A instead of B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A device configuration profile with FileVault settings.
FileVault encryption on macOS is enforced through a device configuration profile in Microsoft Intune. Specifically, you create a settings catalog or a custom profile that includes the FileVault settings under the 'System Preferences' > 'Security & Privacy' category, which allows you to require FileVault and escrow the recovery key to Intune. This is the native Intune method for managing macOS disk encryption, as endpoint security policies for disk encryption are designed for Windows BitLocker, not macOS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An endpoint security policy for disk encryption.
Why it's wrong here
Endpoint security policies exist for Windows; for macOS, device configuration is used.
- ✓
A device configuration profile with FileVault settings.
Why this is correct
Device configuration profiles can enforce FileVault on macOS.
- ✗
A device compliance policy that requires FileVault.
Why it's wrong here
Compliance policies only report non-compliance; they don't enforce encryption.
- ✗
An app protection policy.
Why it's wrong here
App protection policies do not apply to device-level encryption.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Device configuration
Device configuration is the process of setting up and customizing the operating system, security policies, applications, and network settings on a device so it can securely connect to and function within an organization's IT environment.
About these practice questions
Courseiva writes every MD-102 question from scratch — 942 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.