Courseiva

MD-102 Manage and maintain devices Practice Question

Exhibit

{
  "@odata.type": "#microsoft.graph.windows10CompliancePolicy",
  "description": "Windows 10 compliance policy requiring encryption",
  "deviceThreatProtectionEnabled": true,
  "deviceThreatProtectionRequiredSecurityLevel": "high",
  "bitLockerEnabled": true,
  "storageRequireEncryption": true,
  "passwordRequired": true,
  "passwordMinimumLength": 6
}

Refer to the exhibit. The JSON snippet shows a device compliance policy for Windows 10. You assign this policy to a device group. Some devices report as noncompliant even though they have BitLocker enabled and meet password requirements. What is the most likely cause?

⚠ Common exam trap

Test-takers frequently assume BitLocker and storageRequireEncryption are redundant or conflicting, but the real issue is the dependency on Microsoft Defender for Endpoint enrollment for threat-based compliance policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The devices are not enrolled in Microsoft Defender for Endpoint.

The deviceThreatProtectionEnabled setting requires devices to be enrolled in Microsoft Defender for Endpoint to report threat levels. Without this enrollment, the compliance policy cannot evaluate the threat status, causing devices to be marked as noncompliant even if BitLocker and password policies are satisfied.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The deviceThreatProtectionEnabled setting should be false.

    Why it's wrong here

    Setting deviceThreatProtectionEnabled to false disables a check; it does not cause compliant devices to fail. It is tempting because threat-protection requirements frequently trigger noncompliance, and would be correct if the policy enabled the setting while devices lacked a valid Microsoft Defender for Endpoint risk score.

  • ✗

    The password minimum length is too short.

    Why it's wrong here

    A longer minimum password length cannot explain noncompliance when devices already meet the stated password requirements, so it fails the scenario's premise. It is tempting because password length is a genuine compliance setting, and raising it would be the correct fix if devices failed the password rule itself.

  • ✗

    The storageRequireEncryption setting conflicts with BitLocker.

    Why it's wrong here

    storageRequireEncryption and BitLocker are complementary, not conflicting; the setting simply requires encryption, which BitLocker satisfies. It is tempting because encryption settings can appear to overlap, and would be the cause if the policy demanded a different encryption method than the one deployed.

  • ✓

    The devices are not enrolled in Microsoft Defender for Endpoint.

    Why this is correct

    Compliance policies referencing Defender for Endpoint signals require the device to be onboarded to Microsoft Defender for Endpoint. Without that enrolment, the compliance engine cannot evaluate the threat-related settings, producing noncompliant results despite BitLocker and password settings being satisfied.

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.