Courseiva
Manage and maintain deviceshardMultiple ChoiceObjective-mapped

MD-102 Manage and maintain devices Practice Question

Your organization uses Microsoft Intune to manage Android Enterprise devices (work profile). You need to ensure that corporate data on these devices is encrypted. Additionally, you want to enforce a policy that prevents users from disabling the work profile. You have created a device compliance policy that requires encryption, but some devices are marked as non-compliant even though they have encryption enabled. You suspect that the devices are using file-based encryption instead of full-disk encryption. What should you do to ensure that the devices meet the encryption requirement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify that the compliance policy is set correctly for Android Enterprise; if needed, re-evaluate the policy assignment.

The issue is likely a misconfiguration of the compliance policy assignment or evaluation. Android Enterprise work profile devices use file-based encryption by default, which Intune considers compliant. If devices are marked non-compliant despite encryption being enabled, you should verify that the compliance policy is correctly assigned to the target groups and re-evaluate the policy. Option A is incorrect because the work profile is already enabled on the device. Option B is incorrect because Intune cannot change the encryption method on Android devices; encryption type is device-specific. Option D is incorrect because device configuration profiles cannot enforce encryption on the work profile; encryption is managed by the device OS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable the work profile on the devices via a device configuration profile.

    Why it's wrong here

    Work profile is already enabled; the issue is encryption compliance.

  • Change the device encryption method to full-disk encryption using a device configuration profile.

    Why it's wrong here

    Intune cannot change the encryption method on Android devices; it's hardware-dependent.

  • Verify that the compliance policy is set correctly for Android Enterprise; if needed, re-evaluate the policy assignment.

    Why this is correct

    The compliance policy should correctly assess file-based encryption as compliant; re-evaluation may resolve false non-compliance.

  • Create a device configuration profile that enforces encryption on the work profile.

    Why it's wrong here

    Encryption is enforced by the OS; configuration profiles cannot enforce encryption.

Go deeper

Related to this question

About these practice questions

This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.