MD-102 Protect devices Practice Question
Exhibit
{
"compliancePolicies": [
{
"@odata.type": "#microsoft.graph.windows10CompliancePolicy",
"passwordRequired": true,
"passwordMinimumLength": 6,
"requireDeviceEncryption": true,
"requireSecureBoot": true,
"requireCodeIntegrity": true
}
]
}Refer to the exhibit. The JSON shows a compliance policy for Windows 10 devices. Devices that do not meet the policy are marked as non-compliant. Which diagnostic step would you take to identify why a specific device is non-compliant despite having BitLocker enabled?
⚠ Common exam trap
MD-102 often tests the assumption that BitLocker alone satisfies compliance — candidates forget that policies can require multiple settings, and a device fails if any single setting (like Secure Boot or Code Integrity) is not met.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the device's hardware security features: Secure Boot and Code Integrity.
The compliance policy JSON requires Secure Boot and Code Integrity in addition to BitLocker. Even if BitLocker is enabled, a device will be marked non-compliant if Secure Boot or Code Integrity is disabled or unsupported. Therefore, the correct diagnostic step is to review the device's hardware security features — Secure Boot and Code Integrity — to confirm they meet the policy requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verify the compliance policy is assigned to the device's group.
Why it's wrong here
Confirming group assignment only proves the policy reaches the device; it does not reveal which setting failed. The device already reports non-compliant, so targeting is evidently working. Assignment checks are the right step when a device shows no policy at all, not when a specific setting such as BitLocker state is disputed.
- ✗
Check the device's compliance status in Intune for details.
Why it's wrong here
The status shows non-compliant, but we need specific reasons.
- ✓
Review the device's hardware security features: Secure Boot and Code Integrity.
Why this is correct
Secure Boot and Code Integrity are separate device health attestation signals from BitLocker encryption status, so a device can have BitLocker enabled yet still fail the compliance policy if either is disabled or misconfigured. Reviewing these hardware security features identifies the specific setting causing non-compliance, satisfying the stem's requirement to diagnose why the device fails despite BitLocker.
- ✗
Modify the policy to remove the requireSecureBoot and requireCodeIntegrity settings.
Why it's wrong here
Removing requireSecureBoot and requireCodeIntegrity weakens the policy rather than diagnosing the failure; the device may genuinely lack Secure Boot, which BitLocker alone does not satisfy. Relaxing settings is appropriate when requirements are intentionally obsolete, not to explain why an otherwise compliant device is flagged.
Go deeper
Related to this question
Learn chapter
Updating Devices with Windows Update for Business
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Secure boot
Secure Boot is a security feature that ensures a device starts up using only trusted software that is digitally signed by the manufacturer.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.