Courseiva
Manage and maintain devicesmediumMultiple ChoiceObjective-mapped

MD-102 Manage and maintain devices Practice Question

Your organization uses Microsoft Intune to manage Windows 10 and iOS devices. You need to deploy a certificate-based authentication solution for Wi-Fi and VPN access. You have set up a Certificate Connector for Microsoft Intune and issued a root CA certificate. You have created a trusted certificate profile for the root CA and a SCEP certificate profile for client certificates. However, iOS devices are failing to enroll for client certificates. You verify that the SCEP profile is correctly configured and assigned. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The SCEP profile does not reference the trusted certificate profile for the root CA, or the trusted certificate profile is not assigned to iOS devices.

For SCEP certificate enrollment on iOS devices, the trusted root CA certificate profile must be deployed first and the SCEP profile must reference it. If the reference is missing or the trusted profile is not assigned to the iOS devices, the SCEP enrollment will fail. Option A is incorrect because the Certificate Connector supports iOS devices. Option B is incorrect because SCEP certificate profiles for device enrollment do not require user affinity; user affinity is only needed for user certificates. Option D is incorrect because device compliance policy is not a prerequisite for SCEP certificate enrollment; non-compliant devices can still enroll for certificates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The Certificate Connector is not configured to support iOS devices.

    Why it's wrong here

    The Certificate Connector for Microsoft Intune supports all platforms, including iOS. Therefore, 'not configured to support iOS' is incorrect; the connector works with iOS by default when configured properly.

  • iOS devices require user affinity for SCEP enrollment, which is not configured.

    Why it's wrong here

    While user affinity is required for user certificates, SCEP certificate profiles for devices do not require user affinity for enrollment. The issue is not user affinity.

  • The SCEP profile does not reference the trusted certificate profile for the root CA, or the trusted certificate profile is not assigned to iOS devices.

    Why this is correct

    iOS devices require a trusted certificate profile for the root CA to be deployed before the SCEP profile, and the SCEP profile must reference that trusted certificate. If the reference is missing or incorrect, the SCEP enrollment will fail.

  • The iOS devices are not compliant with the compliance policy.

    Why it's wrong here

    Device compliance is not a prerequisite for certificate enrollment. Non-compliance would not cause SCEP enrollment failure; the SCEP profile assignment is the key factor.

About these practice questions

One of 942 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.