MD-102 Intune Security Baselines Practice Question
Your organization uses Microsoft Intune to manage Windows 10 devices. You need to deploy a security baseline that enforces BitLocker encryption and Windows Defender Antivirus settings. What is the recommended approach?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the built-in Windows 10 security baseline in Intune.
The recommended approach is to use the built-in Windows 10 security baseline in Intune (Option C). Intune provides pre-configured security baselines that include settings for BitLocker encryption and Windows Defender Antivirus, which can be customized as needed. Option A is incorrect because custom configuration profiles do not provide the pre-built baseline and are more manual. Option B is incorrect because PowerShell scripts are not a baseline and are less manageable at scale. Option D is incorrect because Group Policy from on-premises AD is not integrated with Intune and requires hybrid infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a custom configuration profile using Configuration Manager.
Why it's wrong here
Creating a custom configuration profile using Configuration Manager is incorrect because the scenario explicitly states Microsoft Intune manages the Windows 10 devices. Configuration Manager is a distinct, typically on-premises, management platform, not the tool used for deploying baselines when Intune is the specified manager. This option is tempting as Configuration Manager *does* utilise configuration baselines to deploy security settings, including BitLocker and Windows Defender, and would be the correct approach if Configuration Manager were the primary device management solution.
- ✗
Deploy a PowerShell script via Intune to configure the settings.
Why it's wrong here
Scripts are not a baseline; baselines are preferred for consistency.
- ✓
Use the built-in Windows 10 security baseline in Intune.
Why this is correct
Security baselines are pre-configured policy templates.
- ✗
Apply Group Policy Objects from on-premises Active Directory.
Why it's wrong here
GPOs are not managed via Intune.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Group Policy
Group Policy is a Windows-based feature that allows administrators to centrally manage and enforce settings for users and computers across an organization.
About these practice questions
This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.