MD-102 Manage and maintain devices Practice Question
You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. You need to ensure that when a device is reported as lost or stolen, you can remotely wipe the device and prevent access to corporate data. Which action should you perform?
⚠ Common exam trap
A common mix-up: candidates confuse retire with wipe; retire only removes corporate data but leaves personal data and does not prevent device access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Wipe the device
The wipe action remotely resets the device to factory settings, removing all data and preventing access. This is the correct choice for lost or stolen devices because it ensures corporate data is not accessible. Retire, reset, and Fresh Start do not provide the same immediate data protection and remote wipe capability for lost devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fresh Start the device
Why it's wrong here
Fresh Start is a feature that reinstalls Windows and removes pre-installed apps, but it is designed for cleaning up devices, not for lost or stolen scenarios. It does not immediately prevent access to corporate data and may not be available for all device types. It also requires the device to be online and does not provide the same level of data protection as a remote wipe.
- ✗
Reset the device
Why it's wrong here
Resetting a device removes all data and settings, but it is typically used for repurposing or when a device is being returned to a fresh state. It does not provide the same urgency or security-focused options as a wipe for lost or stolen devices, and it may not be available for all device types. It also does not specifically address preventing access to corporate data in a lost scenario.
- ✗
Retire the device
Why it's wrong here
Retiring a device removes corporate data and management but leaves personal data intact and does not prevent access to the device itself. It is intended for devices that are being removed from management, not for lost or stolen scenarios where you need to protect corporate data and potentially wipe the device. It does not provide a remote wipe of the entire device.
- ✓
Wipe the device
Why this is correct
The wipe action in Microsoft Intune performs a factory reset on the device, removing all data including corporate and personal information, and it can be initiated remotely. For lost or stolen devices, this ensures that no data remains accessible. It also supports a option to retain enrollment state and user account for Autopilot, but in a lost scenario, a full wipe is appropriate to protect corporate data.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
Key term
Remote wipe
Remote wipe is a security feature that allows an administrator or user to remotely and permanently delete data from a lost or stolen device to prevent unauthorized access.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.