Courseiva
Manage and maintain devicesmediumMultiple ChoiceObjective-mapped

MD-102 Manage and maintain devices Practice Question

Your organization uses Microsoft Intune to manage iOS devices. You need to deploy a custom configuration profile to configure Wi-Fi settings for corporate devices. Which method should you use?

⚠ Common exam trap

Many exam-takers confuse custom configuration profiles with built-in Wi-Fi policies, not realizing that advanced Wi-Fi settings (e.g., custom EAP types, proxy PAC URLs, or per-connection VPN) require a .mobileconfig file rather than the simple UI-based Wi-Fi policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use a custom configuration profile in Intune.

Intune's custom configuration profile allows you to deploy Apple Configurator–generated .mobileconfig files or custom XML/PLIST settings that are not available in the built-in Wi-Fi policy. This is the only method in Intune that supports arbitrary key-value pairs for iOS Wi-Fi configurations, such as EAP-TLS with specific certificate requirements or advanced proxy settings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use a Microsoft Entra ID (Azure AD) device configuration policy.

    Why it's wrong here

    Entra ID does not offer device configuration profiles for iOS.

  • Use a PowerShell script to apply the settings.

    Why it's wrong here

    PowerShell scripts are not supported on iOS.

  • Use a custom configuration profile in Intune.

    Why this is correct

    Custom profiles allow deploying settings not available in built-in templates.

  • Use a Microsoft Defender for Endpoint security policy.

    Why it's wrong here

    Defender for Endpoint is not used for Wi-Fi configuration.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every MD-102 question from scratch — 942 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.