MD-102 Manage and maintain devices Practice Question
You manage devices enrolled in Microsoft Intune. You need to configure a device compliance policy for Windows 11 devices that requires BitLocker to be enabled and Secure Boot to be enabled. Which two settings should you configure in the compliance policy? (Choose two.)
⚠ Common exam trap
The trap here is selecting TPM or code integrity, which are prerequisites or related features, but do not directly verify that BitLocker and Secure Boot are enabled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require Secure Boot to be enabled on the device
To enforce BitLocker and Secure Boot, the compliance policy must include the 'Require BitLocker' and 'Require Secure Boot to be enabled on the device' settings. These directly evaluate the encryption and firmware security states. Other settings like TPM or code integrity are related but do not confirm that BitLocker and Secure Boot are active.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require Trusted Platform Module (TPM)
Why it's wrong here
Requiring a TPM checks for the presence of a TPM chip, which is a prerequisite for BitLocker and Secure Boot. However, it does not verify that BitLocker or Secure Boot are actually enabled. A device with a TPM but disabled BitLocker would still pass this check, failing the requirement.
- ✓
Require Secure Boot to be enabled on the device
Why this is correct
The 'Require Secure Boot to be enabled on the device' setting verifies that Secure Boot is active. If Secure Boot is disabled, the device is noncompliant. This meets the requirement to enforce Secure Boot on Windows 11 devices.
- ✗
Require a minimum OS version
Why it's wrong here
A minimum OS version setting ensures devices run a specific Windows build or higher. It does not check BitLocker or Secure Boot status. This setting is useful for ensuring updates but does not address the encryption or firmware security requirements in the scenario.
- ✗
Require code integrity
Why it's wrong here
Code integrity checks whether drivers and system files are digitally signed. While related to security, it does not verify that Secure Boot is enabled. Enabling code integrity would not satisfy the requirement for Secure Boot, and it may not be supported on all devices.
- ✓
Require BitLocker
Why this is correct
The 'Require BitLocker' setting in a Windows compliance policy checks whether BitLocker Drive Encryption is enabled on the device. If BitLocker is not enabled, the device is marked noncompliant. This directly satisfies the requirement to ensure BitLocker is enabled.
Go deeper
Related to this question
Learn chapter
Configuring Compliance Policies
Key term
Windows 11
Windows 11 is Microsoft's latest desktop operating system, offering a redesigned interface, enhanced security features, and improved support for modern hardware.
Key term
TPM
TPM (Trusted Platform Module) is a dedicated hardware chip on a computer's motherboard that stores cryptographic keys, passwords, and certificates to secure the system against unauthorized access and tampering.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.