MD-102 Protect devices Practice Question
Which TWO actions should you take to ensure that only healthy Windows 10/11 devices can access Microsoft 365 services? (Choose two.)
⚠ Common exam trap
Many candidates confuse device enrollment (Option B) or provisioning (Option C) with ongoing health verification, but neither ensures the device remains healthy at the time of access; only the combination of a compliance policy with attestation checks and a Conditional Access policy that requires compliant device enforces this at authentication time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a device compliance policy that includes health attestation checks
A device compliance policy with health attestation checks uses Windows Health Attestation Service (WHAS) to verify that devices have secure boot, BitLocker enabled, and no kernel-level tampering. This ensures only devices meeting hardware-level security baselines can be marked as compliant, which is a prerequisite for Conditional Access policies that gate access to Microsoft 365 services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a device compliance policy that includes health attestation checks
Why this is correct
Compliance policy defines health criteria.
- ✗
Configure Intune enrollment
Why it's wrong here
Enrollment is required but doesn't enforce health-based access.
- ✗
Use Windows Autopilot to pre-provision devices
Why it's wrong here
Autopilot provisions devices, doesn't control access.
- ✗
Deploy an app protection policy to M365 apps
Why it's wrong here
App protection policies protect data, not device health.
- ✓
Create a Conditional Access policy that requires compliant device
Why this is correct
Conditional Access enforces compliance before access.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 942 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.