You are managing devices with Microsoft Intune. You need to ensure that only compliant devices can access corporate email. Which TWO components should you configure?
Correct - defines compliance rules that devices must meet to be considered compliant.
Why this answer
To ensure only compliant devices can access corporate email, you need a compliance policy (Option B) that defines device health rules and a Conditional Access policy (Option D) that enforces access based on compliance status. Option C is essentially the same concept as Option B and should not be selected as an additional component. Option A (device configuration profile) sets device settings but does not define compliance.
Option E (app protection policy) protects app data but does not evaluate device compliance.
Exam trap
The trap is that candidates may mistakenly include additional components such as configuration profiles or app protection policies, not realizing that only two components are necessary: Compliance Policy and Conditional Access.