Courseiva
hardMultiple Choice

MD-102 Practice Question: A company uses Microsoft Intune to manage Windows…

A company uses Microsoft Intune to manage Windows 10 devices. They have a compliance policy that requires BitLocker to be enabled. Some devices are marked as non-compliant even though BitLocker appears to be on. The administrator runs 'manage-bde -status' on a non-compliant device and sees that the protection status is 'Protection Off'. What is the most likely cause?

⚠ Common exam trap

A common mix-up: candidates confuse 'encrypted' with 'protected'—BitLocker can encrypt a drive without active protection if key protectors are missing, and Intune compliance policies specifically require protection to be on, not just encryption to be present.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The BitLocker key protectors are missing or have been removed.

The compliance policy requires BitLocker to be enabled, but 'manage-bde -status' shows 'Protection Off'. This indicates that while the drive is encrypted, BitLocker is not actively protecting the data because the key protectors (such as the TPM protector) are missing or have been removed. Intune checks the protection status, not just encryption state, so when protectors are absent, the device is marked non-compliant.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The BitLocker key protectors are missing or have been removed.

    Why this is correct

    BitLocker reports Protection Off when valid key protectors, such as TPM, PIN, or recovery password, are absent or removed, even if the volume was previously encrypted. Intune's compliance policy therefore evaluates BitLocker as not enabled, marking the device non-compliant.

  • ✗

    The TPM is not initialized.

    Why it's wrong here

    TPM issues would prevent encryption, but protection off indicates suspension.

  • ✗

    The device has a recovery password protector but no TPM protector.

    Why it's wrong here

    A recovery password protector alone still permits protection to be On; its presence does not produce 'Protection Off'. It is tempting because recovery password protectors are a normal BitLocker configuration, and this arrangement would be valid where TPM is unavailable and a password protector is used instead.

  • ✗

    The device uses a different encryption method (e.g., XTS-AES 256 vs AES 128).

    Why it's wrong here

    The encryption algorithm (XTS-AES 256 versus AES 128) does not govern whether BitLocker protection is active; 'Protection Off' means protectors are suspended or absent regardless of cipher. It is tempting because cipher strength is a genuine BitLocker setting, and it would matter when configuring encryption method via Intune disk encryption policy.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.