MD-102 Prepare infrastructure for devices Practice Question
You need to ensure that all corporate devices have a standard set of security settings, including disk encryption and firewall configuration. Which Microsoft Intune feature should you use?
⚠ Common exam trap
A common mix-up: candidates confuse compliance policies with configuration profiles, mistakenly thinking that compliance policies can apply settings, when in fact compliance policies only evaluate and report on settings that must already be configured by a profile or other means.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configuration profiles
Configuration profiles in Microsoft Intune are the correct feature to deploy standard security settings such as disk encryption (e.g., BitLocker) and firewall configuration across corporate devices. These profiles define device-level policies that enforce specific configurations, including endpoint protection settings, and can be assigned to groups of devices to ensure consistent security baselines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Update rings
Why it's wrong here
Update rings govern Windows quality and feature update deferral, deadlines and restart behaviour, not disk encryption or firewall configuration. They are tempting because they apply broadly to corporate devices, but the stem requires security settings delivery, which configuration profiles provide.
- ✓
Configuration profiles
Why this is correct
Configuration profiles deliver a standard baseline of device settings, including disk encryption and firewall rules, to targeted groups. This satisfies the stem's requirement for uniform security settings across all corporate devices, unlike compliance policies, which only assess and report state.
- ✗
Device enrollment profiles
Why it's wrong here
Enrollment profiles only control how devices register and which enrolment method or restrictions apply; they configure no disk encryption or firewall settings. They are tempting because they target all corporate devices, yet the requirement is configuration delivery, which configuration profiles handle.
- ✗
Compliance policies
Why it's wrong here
Compliance policies evaluate and report against conditions such as BitLocker and firewall state, marking devices compliant or non-compliant, but they do not deploy those settings. They are tempting because they reference the same security controls, yet remediation requires configuration profiles.
Go deeper
Related to this question
Learn chapter
Deploying Applications with Intune
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.