MD-102 Protect devices Practice Question
Exhibit
Refer to the exhibit.
{
"@odata.type": "#microsoft.graph.windows10CompliancePolicy",
"description": "Windows 10 compliance policy",
"passwordRequired": true,
"passwordMinimumLength": 6,
"passwordRequiredType": "deviceDefault",
"osMinimumVersion": "10.0.19041.0",
"osMaximumVersion": "10.0.19045.0",
"earlyLaunchAntimalwareDriverEnabled": true,
"secureBootEnabled": true,
"tpmRequired": true,
"deviceThreatProtectionEnabled": true,
"deviceThreatProtectionRequiredSecurityLevel": "medium"
}Refer to the exhibit. A Windows 10 device is enrolled in Intune and has the above compliance policy assigned. The device reports as non-compliant. The device has TPM version 2.0, Secure Boot enabled, and a password of 8 characters. Which of the following is the most likely reason for non-compliance?
⚠ Common exam trap
Many exam-takers assume TPM, Secure Boot, or password length are the most common compliance failures, but the OS version check is often overlooked as a strict requirement that can cause non-compliance even when all hardware security features are present.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The OS version is outside the allowed range.
The compliance policy likely specifies a minimum OS version requirement, such as Windows 10 22H2 or a specific build number. Since the device reports as non-compliant despite meeting TPM 2.0, Secure Boot, and password length requirements, the most probable cause is that the OS version is below the allowed minimum. Intune evaluates OS version against the 'Minimum OS version' setting in the compliance policy, and failure to meet this threshold results in non-compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The OS version is outside the allowed range.
Why this is correct
The policy restricts OS version; the device likely has a newer build.
- ✗
The device does not have a TPM chip.
Why it's wrong here
The device has TPM 2.0.
- ✗
Secure Boot is not enabled.
Why it's wrong here
Secure Boot is enabled.
- ✗
The password length is less than 6 characters.
Why it's wrong here
The password is 8 characters, meeting the minimum.
Go deeper
Related to this question
Learn chapter
Enrolling Devices with Microsoft Intune
Key term
Compliance policy
A compliance policy is a set of rules that ensures devices, users, and applications meet an organization's security and regulatory requirements before they can access corporate resources.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
One of 942 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.