MD-102 Manage and maintain devices Practice Question
Your organization uses Microsoft Intune to manage Windows 10 devices. You need to enforce BitLocker encryption on all devices. Some devices are not encrypting even though the policy is assigned. What should you check first?
⚠ Common exam trap
It's easy for candidates to assume the issue is policy-related (e.g., compliance or configuration source) and overlook the fundamental hardware prerequisite of a functional TPM, which is the first thing to verify in any BitLocker troubleshooting workflow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confirm that the device has a compatible TPM chip and that it is enabled.
BitLocker requires a compatible TPM (Trusted Platform Module) chip, version 1.2 or 2.0, that is enabled and activated in the BIOS/UEFI. If the TPM is missing, disabled, or not initialized, the BitLocker policy will apply but encryption will fail silently or remain pending. This is the most common root cause for devices not encrypting despite policy assignment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Confirm that the device has a compatible TPM chip and that it is enabled.
Why this is correct
BitLocker requires a TPM (1.2 or 2.0) that is enabled and initialized.
- ✗
Verify that Secure Boot is disabled in BIOS.
Why it's wrong here
Secure Boot is not required to be disabled; it is often required.
- ✗
Ensure devices are marked as compliant in Intune.
Why it's wrong here
Compliance is separate from BitLocker enforcement.
- ✗
Check if the BitLocker policy is using the Settings catalog.
Why it's wrong here
Settings catalog is the modern way, not a prerequisite.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
TPM
TPM (Trusted Platform Module) is a dedicated hardware chip on a computer's motherboard that stores cryptographic keys, passwords, and certificates to secure the system against unauthorized access and tampering.
Key term
Policy assignment
Policy assignment is the process of attaching a set of rules or permissions to a specific resource, user, or group so that those rules are enforced in a cloud or IT environment.
About these practice questions
Courseiva writes every MD-102 question from scratch — 942 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.