Courseiva
Manage and maintain devices →mediumMultiple Select

MD-102 Manage and maintain devices Practice Question

You manage devices enrolled in Microsoft Intune. You need to configure a device compliance policy for Windows 11 devices that requires BitLocker to be enabled and Secure Boot to be enabled. Which two settings should you configure in the compliance policy? (Choose two.)

⚠ Common exam trap

The trap here is selecting TPM or code integrity, which are prerequisites or related features, but do not directly verify that BitLocker and Secure Boot are enabled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require Secure Boot to be enabled on the device

To enforce BitLocker and Secure Boot, the compliance policy must include the 'Require BitLocker' and 'Require Secure Boot to be enabled on the device' settings. These directly evaluate the encryption and firmware security states. Other settings like TPM or code integrity are related but do not confirm that BitLocker and Secure Boot are active.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require Trusted Platform Module (TPM)

    Why it's wrong here

    Requiring a TPM checks for the presence of a TPM chip, which is a prerequisite for BitLocker and Secure Boot. However, it does not verify that BitLocker or Secure Boot are actually enabled. A device with a TPM but disabled BitLocker would still pass this check, failing the requirement.

  • ✓

    Require Secure Boot to be enabled on the device

    Why this is correct

    The 'Require Secure Boot to be enabled on the device' setting verifies that Secure Boot is active. If Secure Boot is disabled, the device is noncompliant. This meets the requirement to enforce Secure Boot on Windows 11 devices.

  • ✗

    Require a minimum OS version

    Why it's wrong here

    A minimum OS version setting ensures devices run a specific Windows build or higher. It does not check BitLocker or Secure Boot status. This setting is useful for ensuring updates but does not address the encryption or firmware security requirements in the scenario.

  • ✗

    Require code integrity

    Why it's wrong here

    Code integrity checks whether drivers and system files are digitally signed. While related to security, it does not verify that Secure Boot is enabled. Enabling code integrity would not satisfy the requirement for Secure Boot, and it may not be supported on all devices.

  • ✓

    Require BitLocker

    Why this is correct

    The 'Require BitLocker' setting in a Windows compliance policy checks whether BitLocker Drive Encryption is enabled on the device. If BitLocker is not enabled, the device is marked noncompliant. This directly satisfies the requirement to ensure BitLocker is enabled.

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.