MD-102 Manage and maintain devices Practice Question
Your organization uses Microsoft Intune to manage Android Enterprise devices (work profile). You need to ensure that corporate data on these devices is encrypted. Additionally, you want to enforce a policy that prevents users from disabling the work profile. You have created a device compliance policy that requires encryption, but some devices are marked as non-compliant even though they have encryption enabled. You suspect that the devices are using file-based encryption instead of full-disk encryption. What should you do to ensure that the devices meet the encryption requirement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the compliance policy is set correctly for Android Enterprise; if needed, re-evaluate the policy assignment.
The issue is likely a misconfiguration of the compliance policy assignment or evaluation. Android Enterprise work profile devices use file-based encryption by default, which Intune considers compliant. If devices are marked non-compliant despite encryption being enabled, you should verify that the compliance policy is correctly assigned to the target groups and re-evaluate the policy. Option A is incorrect because the work profile is already enabled on the device. Option B is incorrect because Intune cannot change the encryption method on Android devices; encryption type is device-specific. Option D is incorrect because device configuration profiles cannot enforce encryption on the work profile; encryption is managed by the device OS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the work profile on the devices via a device configuration profile.
Why it's wrong here
Work profile is already enabled; the issue is encryption compliance.
- ✗
Change the device encryption method to full-disk encryption using a device configuration profile.
Why it's wrong here
Intune cannot change the encryption method on Android devices; it's hardware-dependent.
- ✓
Verify that the compliance policy is set correctly for Android Enterprise; if needed, re-evaluate the policy assignment.
Why this is correct
The compliance policy should correctly assess file-based encryption as compliant; re-evaluation may resolve false non-compliance.
- ✗
Create a device configuration profile that enforces encryption on the work profile.
Why it's wrong here
Encryption is enforced by the OS; configuration profiles cannot enforce encryption.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Policy assignment
Policy assignment is the process of attaching a set of rules or permissions to a specific resource, user, or group so that those rules are enforced in a cloud or IT environment.
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.