Courseiva
Protect devices →easyMultiple Choice

MD-102 Protect devices Practice Question

Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that corporate data in Microsoft Outlook is protected even if the device is not enrolled in MDM. Which policy should you deploy?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

App protection policy (MAM)

App protection policies (MAM) protect corporate data in apps like Outlook without requiring device enrollment in MDM. Option A (Device compliance policy) requires MDM enrollment. Option B (Device configuration profile) is for device settings, not data protection. Option C (Conditional Access policy) controls access but does not directly protect data within apps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Device compliance policy

    Why it's wrong here

    A device compliance policy only evaluates enrolled devices against rules and reports their state; it cannot protect Outlook data on an unenrolled device. It is the right choice when you need to gate access based on whether enrolled devices meet defined compliance conditions.

  • ✗

    Device configuration profile

    Why it's wrong here

    A device configuration profile delivers settings to enrolled devices, so it cannot reach an unenrolled iOS device at all. Configuration profiles are correct when you must push settings such as Wi-Fi, certificates or restrictions to devices already under Intune management.

  • ✗

    Conditional Access policy

    Why it's wrong here

    Conditional Access governs sign-in and can require app protection policies, but it does not itself wrap or encrypt Outlook data on an unenrolled device. It is correct when you need to block or grant access based on user, device state or location conditions.

  • ✓

    App protection policy (MAM)

    Why this is correct

    App protection policies apply at the app layer via Microsoft Intune, enforcing encryption, PIN and selective wipe on Outlook data without requiring device enrolment. This satisfies the constraint that corporate data must be protected on unenrolled iOS devices.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.