Courseiva

MD-102 · topic practice

Protect devices practice questions

Domain 3 of MD-102 covers keeping endpoints secure with Intune: compliance policies, Conditional Access, device restrictions and configuration profiles, encryption with BitLocker and FileVault, Windows Defender and Attack Surface Reduction, and Defender for Endpoint onboarding. Questions are scenario-based, asking you to pick the setting, policy type, or OMA-URI that produces a described outcome.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Protect devices

What the exam tests

What to know about Protect devices

Be able to build a compliance policy, link it to Conditional Access, and assign configuration or security baseline profiles to the right groups. The single most important thing: know which policy type enforces a setting versus which one only reports device state.

Compliance policies defining minimum OS version, encryption, and jailbreak or rooted detection

Conditional Access requiring compliant or Microsoft Entra hybrid joined devices

Configuration profiles and custom OMA-URI settings for device restrictions and security baselines

BitLocker, FileVault, and Windows Defender Firewall, ASR, and Defender for Endpoint onboarding

Watch out for

Common Protect devices exam traps

  • ▸Confusing compliance policy settings with configuration profile settings, so the device is configured but never marked compliant.
  • ▸Forgetting that Conditional Access needs a separate policy; a compliance policy alone does not block access to resources.
  • ▸Mixing up Microsoft Entra registered, joined, and hybrid joined states, which changes which device controls and policies apply.

Practice set

Protect devices questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full Protect devices explanation →

Your company uses Microsoft Intune to manage iOS devices. You need to ensure that corporate data in Microsoft 365 apps is protected even if a device is compromised. Which App Protection Policy setting should you configure?

You are implementing Microsoft Defender for Endpoint on Windows Server devices managed by Microsoft Intune. After onboarding, the devices show as 'Inactive' in the Microsoft Defender XDR portal. Which action should you take?

Question 3mediummultiple choice
Read the full Protect devices explanation →

You manage Android Enterprise devices with work profiles. A user reports that corporate apps are not appearing in the work profile after enrollment. The device shows as enrolled in Microsoft Intune. What is the most likely cause?

Question 4mediummultiple choice
Read the full Protect devices explanation →

You need to deploy a line-of-business (LOB) iOS app to users in your organization. The app is signed with an enterprise certificate. How should you distribute the app to managed devices?

You have enabled Microsoft Defender for Endpoint on macOS devices. Some macOS devices show a status of 'Sensor disconnected' in the Microsoft Defender XDR portal. The devices are online and can communicate with the internet. Which troubleshooting step should you take first?

Which TWO of the following are valid methods to wipe a Windows 10 device using Microsoft Intune? (Select TWO.)

Which THREE of the following are prerequisites for deploying Microsoft Defender for Endpoint on Windows 10 devices via Microsoft Intune? (Select THREE.)

Which TWO of the following are valid reasons to use Windows Autopilot Reset? (Select TWO.)

Refer to the exhibit. You deploy this compliance policy to Windows 10 devices. A device running Windows 10 version 20H2 (OS build 19042.1234) reports as compliant. However, the device does not have BitLocker enabled. Why is the device compliant?

Exhibit

Refer to the exhibit.

```json
{
  "compliancePolicy": {
    "@odata.type": "#microsoft.graph.windows10CompliancePolicy",
    "passwordRequired": true,
    "passwordMinimumLength": 6,
    "passwordRequiredType": "deviceDefault",
    "requireHealthyDeviceReport": false,
    "osMinimumVersion": "10.0.19041.0",
    "osMaximumVersion": null,
    "mobileOsMinimumVersion": null,
    "storageRequireEncryption": true
  }
}
```
Question 10hardmultiple choice
Read the full Protect devices explanation →

Refer to the exhibit. You apply this configuration profile to Windows 10 devices. A user reports that their device's diagnostic data level is set to 'Full' in Settings > Diagnostics & feedback. What is the most likely reason?

Exhibit

Refer to the exhibit.

```json
{
  "microsoft365BusinessVoice": {
    "@odata.type": "#microsoft.graph.windows10GeneralConfiguration",
    "telemetryLevel": "1 - Basic",
    "enableDeviceManufacturer": "Contoso",
    "enableDeviceModel": "Surface Pro 7",
    "enableDeviceName": "LAPTOP-01",
    "enableDeviceOSVersion": true,
    "enableDeviceOSBuild": true,
    "enableDeviceSerialNumber": true,
    "enableDeviceIMEI": null
  }
}
```
Question 11mediummultiple choice
Read the full Protect devices explanation →

You are configuring a Windows 10 device compliance policy in Microsoft Intune. The policy requires that devices have BitLocker enabled and a minimum OS build version. However, some devices are showing as 'Not compliant' even though they meet the requirements. What is the most likely cause?

Question 12hardmultiple choice
Read the full Protect devices explanation →

You manage a fleet of iOS devices enrolled in Microsoft Intune. You need to ensure that only approved corporate devices can access Exchange Online. You configure a Conditional Access policy that requires devices to be compliant with Intune compliance policies. However, some users report that they are still able to access email from personal iOS devices that are not enrolled. What should you check first?

Question 13mediummultiple choice
Read the full Protect devices explanation →

A user reports that they cannot install a company-required app from the Company Portal on their Android device. The app is assigned as 'Available for enrolled devices' in Intune. The device is enrolled and compliant. What is the most likely issue?

Question 14hardmultiple choice
Read the full Protect devices explanation →

You are troubleshooting an issue where Windows 10 devices are not receiving Windows updates from Intune. The update rings are configured, and the devices are enrolled. However, devices show 'Up to date' even though they are missing critical security updates. What should you verify?

Question 15mediummultiple choice
Read the full Protect devices explanation →

You are configuring an app protection policy (MAM) in Intune for iOS and Android devices. The policy should prevent users from copying corporate data to personal apps. Which setting should you configure?

Question 16hardmultiple choice
Read the full Protect devices explanation →

Your organization uses Microsoft Defender for Endpoint (now part of Microsoft Defender XDR) to manage device threat detection. You have integrated Defender for Endpoint with Intune for compliance. Some devices are showing as non-compliant due to 'active threats' that are actually low-risk. How can you adjust the compliance policy to allow low-risk threats?

Which TWO conditions must be met for a Windows 10 device to be considered compliant with an Intune compliance policy that requires BitLocker and Secure Boot?

Which TWO settings must be configured to enable Windows Hello for Business in an Intune policy?

Which TWO methods can be used to enroll Android devices in Microsoft Intune?

Question 20hardmultiple choice
Read the full Protect devices explanation →

Refer to the exhibit. A Windows 10 device with OS build 10.0.19041.1 is evaluated against this compliance policy. The device meets all settings except one: the OS version is 10.0.19041.1, which is below the minimum 10.0.19041.0? Actually it is above. But wait, the device has BitLocker enabled, Secure Boot enabled, and firewall enabled. Which setting will cause the device to be non-compliant?

Exhibit

Refer to the exhibit.

{
  "@odata.type": "#microsoft.graph.windows10CompliancePolicy",
  "passwordRequired": true,
  "passwordMinimumLength": 6,
  "passwordRequiredType": "deviceDefault",
  "passwordMinutesOfInactivityBeforeLock": 5,
  "passwordExpirationDays": 90,
  "passwordPreviousPasswordBlockCount": 5,
  "requireHealthyDevice": false,
  "osMinimumVersion": "10.0.19041.0",
  "osMaximumVersion": "10.0.19043.0",
  "mobileOsMinimumVersion": null,
  "mobileOsMaximumVersion": null,
  "earlyLaunchAntiMalwareDriverEnabled": true,
  "bitLockerEnabled": true,
  "secureBootEnabled": true,
  "codeIntegrityEnabled": true,
  "storageRequireEncryption": true,
  "activeFirewallRequired": true,
  "defenderEnabled": true,
  "defenderVersion": "1.1.1800.0",
  "signatureOutOfDate": false,
  "rtpEnabled": true
}

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Protect devices sessions

Start a Protect devices only practice session

Every question in these sessions is drawn from the Protect devices domain — nothing else.

Related practice questions

Related MD-102 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the MD-102 exam test about Protect devices?
Be able to build a compliance policy, link it to Conditional Access, and assign configuration or security baseline profiles to the right groups. The single most important thing: know which policy type enforces a setting versus which one only reports device state.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Protect devices questions in a focused session?
Yes — the session launcher on this page draws every question from the Protect devices domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other MD-102 topics?
Use the topic links above to move to related areas, or go back to the MD-102 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the MD-102 exam covers. They are not copied from any real exam or dump site.