Courseiva
Manage applications →hardMultiple Choice

MD-102 Manage applications Practice Question

You are designing an app protection policy (APP) for Microsoft 365 mobile apps accessing corporate data on iOS devices. The security team requires that when a user opens a work document in the Microsoft Word app, the user must authenticate with Face ID or a passcode. Which setting should you configure?

⚠ Common exam trap

Test-takers frequently confuse 'Require PIN or Face ID for access' with 'Require app PIN when device PIN is not set', mistakenly thinking the latter covers all scenarios, when in fact it only applies conditionally when the device lacks a PIN.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require PIN or Face ID for access (iOS)

The 'Require PIN or Face ID for access (iOS)' setting enforces biometric or passcode authentication specifically when a user launches a managed app or resumes it from the background. This directly meets the requirement that opening a work document in Word triggers Face ID or passcode verification, as the app protection policy (APP) intercepts the app launch and prompts for authentication before granting access to corporate data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Require PIN or Face ID for access (iOS)

    Why this is correct

    This setting enforces biometric or passcode authentication at app launch, directly satisfying the security team's requirement that opening a work document in Word triggers Face ID or passcode verification. It applies at the app layer via Intune app protection policy, independent of device-level enrolment, so corporate data stays protected on iOS.

  • ✗

    Block managed apps from running on jailbroken devices

    Why it's wrong here

    Jailbreak detection blocks managed apps from launching on compromised devices; it never prompts for Face ID or a passcode when a document opens. It is tempting because it is an iOS app protection control, and would be correct if the requirement were to deny access on rooted or jailbroken hardware.

  • ✗

    Encrypt app data

    Why it's wrong here

    Encrypting app data protects corporate files at rest on the device but triggers no authentication prompt when Word opens a document. It is tempting because it is a core app protection policy setting, and would be correct if the requirement were to protect data confidentiality rather than verify user identity at access.

  • ✗

    Require app PIN when device PIN is not set

    Why it's wrong here

    This setting enforces an app PIN only when the device has no PIN configured, so devices with a PIN already set would open Word without the required Face ID or passcode prompt. It is tempting because it is an authentication control, and would be correct if the requirement targeted only unmanaged devices lacking a PIN.

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.