MD-102 Manage applications Practice Question
Your organization uses Intune to manage iOS/iPadOS devices. You need to deploy a custom SSL certificate to all devices for accessing an internal web app. Which profile type should you use?
⚠ Common exam trap
Test-takers frequently confuse deploying a trusted root certificate (needed for server trust) with issuing a client certificate (needed for device authentication), leading them to incorrectly choose PKCS or SCEP profiles when the question only requires establishing trust for the server's SSL certificate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Trusted certificate profile
A Trusted certificate profile is used to deploy a root or intermediate CA certificate that the device must trust for certificate-based authentication, such as accessing an internal web app over HTTPS. This profile type simply installs the certificate into the device's trusted root store without generating a private key, which is exactly what is needed when you only need to establish trust for the server certificate presented by the web app.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PKCS certificate profile
Why it's wrong here
A PKCS profile requires the device to generate a key pair and submit a certificate signing request to a CA, so it cannot deliver a pre-issued custom SSL certificate. It is tempting because PKCS is the standard SCEP alternative for certificate enrolment, and would be correct for issuing new device certificates from an enterprise CA.
- ✗
SCEP certificate profile
Why it's wrong here
SCEP is a provisioning protocol that issues certificates from a certificate authority; it cannot deploy an already-issued custom SSL certificate. It is tempting because SCEP profiles are the standard method for delivering identity and Wi-Fi certificates, and would be right if the certificate had to be generated per device by a CA.
- ✓
Trusted certificate profile
Why this is correct
A Trusted certificate profile deploys the root or intermediate CA certificate to iOS/iPadOS devices so they trust the internal web app's server certificate. It satisfies the requirement to install a custom SSL certificate for internal access, unlike SCEP or PKCS profiles, which issue client certificates.
- ✗
Custom configuration profile (preferences)
Why it's wrong here
A custom preferences profile pushes arbitrary property-list keys, not a PKCS#12 certificate payload, so the SSL certificate never installs into the iOS keychain. It is tempting because custom profiles handle settings Intune lacks a template for, and would be correct for app configuration keys rather than certificate delivery.
Go deeper
Related to this question
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.