Courseiva
Manage and maintain devices →mediumMultiple Choice

MD-102 Manage and maintain devices Practice Question

Exhibit

{
  "@odata.type": "#microsoft.graph.windows10CompliancePolicy",
  "passwordRequired": true,
  "passwordMinimumLength": 6,
  "passwordRequiredType": "numeric",
  "requireDeviceEncryption": true,
  "firewallEnabled": true,
  "antivirusEnabled": true,
  "antispywareEnabled": true,
  "tpmRequired": true
}

Refer to the exhibit. You have a compliance policy for Windows 10 devices. A device reports as non-compliant with the reason 'TPM not found'. The device does have a TPM 2.0 chip but it is disabled in BIOS. What should you do to resolve the compliance issue?

⚠ Common exam trap

Many exam-takers assume a 'TPM not found' error indicates missing hardware, leading them to choose motherboard replacement or policy removal, rather than recognizing that a disabled TPM in BIOS is a common configuration issue that can be resolved without hardware changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the TPM in the device's BIOS settings.

The device has a TPM 2.0 chip that is disabled in BIOS. Enabling the TPM in BIOS allows the device to report its TPM presence to Microsoft Intune, satisfying the compliance policy's tpmRequired setting. No hardware replacement, grace period, or policy modification is needed when the TPM is physically present but disabled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Replace the device's motherboard.

    Why it's wrong here

    The motherboard already carries a working TPM 2.0 chip, so replacing it changes nothing — the chip is present but switched off in firmware. Motherboard replacement addresses physically absent or faulty TPM hardware, which is not the condition reported here.

  • ✓

    Enable the TPM in the device's BIOS settings.

    Why this is correct

    Compliance evaluation queries the TPM through Windows, which reports nothing when the chip is disabled in firmware. Enabling TPM in BIOS exposes the 2.0 chip to the OS, letting the policy detect it and clear the 'TPM not found' reason.

  • ✗

    Assign a grace period for the device.

    Why it's wrong here

    A grace period only postpones enforcement; the device still reports non-compliant once it lapses, because the TPM remains disabled in BIOS. Grace periods suit temporary, self-resolving conditions such as a pending update or a user travelling, not a firmware setting that no policy action can change.

  • ✗

    Remove the tpmRequired setting from the compliance policy.

    Why it's wrong here

    Removing tpmRequired stops the policy evaluating the TPM, so the device reports compliant without the chip ever being enabled — the underlying security requirement is abandoned, not met. The setting exists to enforce TPM presence where hardware supports it; deleting it would be right only if no devices in scope had TPMs.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Go deeper

Related to this question

About these practice questions

One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.