MD-102 Manage and maintain devices Practice Question
Exhibit
{
"compliancePolicies": [
{
"@odata.type": "#microsoft.graph.windows10CompliancePolicy",
"displayName": "Windows Compliance Policy",
"description": "Requires BitLocker and antivirus",
"requireDeviceGuard": false,
"requireDefender": true,
"requireEncryption": true,
"passwordRequired": true,
"passwordMinimumLength": 6
}
],
"deviceConfigurationPolicies": [
{
"@odata.type": "#microsoft.graph.windows10GeneralConfiguration",
"displayName": "Windows Security Baseline",
"defender": {
"realTimeProtection": true,
"cloudBlockLevel": "high",
"scanParameter": "fullscan"
},
"bitLocker": {
"encryptionMethod": "AES256",
"requireStartupPin": false
}
}
]
}Refer to the exhibit. You have an Intune configuration that includes a compliance policy and a device configuration policy for Windows 10 devices. You deploy both policies to a group of devices. After deployment, some devices are marked as non-compliant even though they have BitLocker enabled and Windows Defender Antivirus running. Which setting is most likely causing the conflict?
⚠ Common exam trap
Many exam-takers assume enabling BitLocker and Defender automatically satisfies all compliance requirements, but Intune compliance policies evaluate each setting independently, so a missing password configuration will cause non-compliance even if other security features are present.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The compliance policy requires password, but the device configuration policy does not configure any password settings, leading to non-compliance.
The compliance policy requires a password, but the device configuration policy does not configure any password settings. In Intune, compliance policies evaluate device settings independently of configuration policies; if a compliance policy mandates a password and the device lacks one (because the configuration policy doesn't enforce it), the device will be marked non-compliant. BitLocker and Defender being enabled do not satisfy a password requirement, so the conflict is the missing password configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The compliance policy requires password, but the device configuration policy does not configure any password settings, leading to non-compliance.
Why this is correct
Intune evaluates compliance independently of configuration. Because the compliance policy mandates a password while the configuration policy sets none, devices without a password are flagged non-compliant even though BitLocker and Defender Antivirus satisfy their own requirements. The password requirement is the conflicting setting.
- ✗
The compliance policy requires encryption, but the device configuration policy does not enforce BitLocker startup PIN, causing compliance failure.
Why it's wrong here
Compliance evaluates BitLocker encryption state, not startup PIN presence; a missing PIN requirement in the configuration policy does not cause non-compliance. It is tempting because BitLocker settings span both policy types, and it would be correct where the compliance policy explicitly requires a startup PIN or TPM protector that the device lacks.
- ✗
The device configuration policy sets scanParameter to 'fullscan', which may interfere with compliance checks.
Why it's wrong here
Scan type governs Defender Antivirus scan behaviour, not BitLocker or antivirus compliance evaluation, so it cannot mark a compliant device non-compliant. It is tempting because configuration policy settings do override compliance expectations, and it would be correct where a scan schedule or type conflicts with an endpoint protection compliance rule.
- ✗
The compliance policy requires Defender, but the device configuration policy sets cloudBlockLevel to 'high', which may conflict with some devices.
Why it's wrong here
cloudBlockLevel sets Defender Antivirus cloud protection aggressiveness; it does not alter BitLocker or compliance evaluation, so it cannot mark a BitLocker-enabled device non-compliant. It is tempting because it is a Defender setting, and it would matter when tuning detection sensitivity, not when reconciling compliance and configuration policy conflicts.
Go deeper
Related to this question
Learn chapter
Implementing App Protection Policies (MAM)
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.