Courseiva
Protect deviceseasyMultiple ChoiceObjective-mapped

MD-102 Protect devices Practice Question

A company uses Microsoft Intune to manage Windows 11 devices. They want to ensure that only devices with a TPM 2.0 and Secure Boot enabled can access corporate resources in Microsoft Entra ID. What should they configure?

⚠ Common exam trap

A common mix-up: candidates confuse provisioning-time enforcement (Autopilot) with runtime compliance enforcement (Conditional Access + compliance policy), mistakenly thinking Autopilot can block access after the device is in use.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a Conditional Access policy that requires device compliance and a device compliance policy that checks TPM 2.0 and Secure Boot

Conditional Access policies in Microsoft Entra ID can require devices to be marked as compliant before granting access to corporate resources. A device compliance policy in Intune can be configured to check for TPM 2.0 and Secure Boot status on Windows 11 devices. Only when both conditions are met will the device be considered compliant, and the Conditional Access policy will enforce that compliance requirement, effectively blocking non-compliant devices from accessing corporate resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure Windows Hello for Business in Intune

    Why it's wrong here

    Windows Hello for Business is for passwordless sign-in, not device health enforcement.

  • Deploy an attack surface reduction rule in Microsoft Defender XDR

    Why it's wrong here

    Attack surface reduction rules mitigate threats but don't enforce device health for access.

  • Use Windows Autopilot to enforce TPM and Secure Boot during provisioning

    Why it's wrong here

    Autopilot provisions devices but doesn't enforce ongoing compliance checks.

  • Create a Conditional Access policy that requires device compliance and a device compliance policy that checks TPM 2.0 and Secure Boot

    Why this is correct

    Conditional Access with compliance policy enforces health requirements before access.

About these practice questions

One of 942 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.