Courseiva

MD-102 Manage and maintain devices Practice Question

An organization uses Microsoft Intune for device management. They have a requirement that all Windows devices must have BitLocker enabled. They want to automatically remediate any device that has BitLocker disabled by running a PowerShell script. Which Intune feature should be used?

⚠ Common exam trap

It's easy for candidates to confuse Proactive remediations with simple script deployment, not realizing that Proactive remediations provide a detection-then-remediation loop that automatically re-applies the fix when drift is detected, whereas a one-time script deployment does not.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Proactive remediations with a detection script for BitLocker status and a remediation script to enable BitLocker

Proactive remediations in Microsoft Intune are specifically designed to detect and automatically fix common configuration drift on managed devices. By using a detection script to check BitLocker status and a remediation script to enable BitLocker, this feature meets the requirement for automatic remediation without user interaction or manual re-mediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Device configuration profile to enable BitLocker

    Why it's wrong here

    A configuration profile sets BitLocker settings declaratively but does not run a PowerShell script, and it cannot detect and remediate devices where encryption was disabled outside management. Configuration profiles suit enforcing baseline settings; the stem requires scripted detection and automatic remediation.

  • ✗

    Device compliance policy with a noncompliance action to mark device as non-compliant

    Why it's wrong here

    A compliance policy evaluates state and marks devices non-compliant, but marking alone performs no remediation action. Compliance policies suit gating conditional access and reporting drift; the stem explicitly requires a PowerShell script to run automatically, which is remediation's function.

  • ✗

    PowerShell script deployment with assignment to all devices

    Why it's wrong here

    Script deployment runs once per assignment and reports results, but it does not evaluate device state or trigger re-execution when BitLocker is later disabled. It suits one-off configuration tasks; the stem requires continuous detection and automatic remediation, which is remediation scripts' role.

  • ✓

    Proactive remediations with a detection script for BitLocker status and a remediation script to enable BitLocker

    Why this is correct

    Proactive remediations run a detection script on a schedule and execute a remediation script only when detection reports non-compliance, satisfying the automatic BitLocker enablement requirement. This differs from configuration profiles, which enforce settings but cannot run conditional script logic.

About these practice questions

One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.