Courseiva
Protect devices →mediumMultiple Select

MD-102 Protect devices Practice Question

Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to configure a compliance policy that enforces encryption and firewall settings. Which two settings should you configure in the compliance policy? (Choose two.)

⚠ Common exam trap

The trap here is selecting other security-related settings like Secure Boot or antivirus, which are valuable but do not fulfill the specific encryption and firewall requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require a firewall

To enforce encryption and firewall settings in a Windows compliance policy, you configure 'Require BitLocker' under Device Health and 'Require a firewall' under System Security. These settings directly validate that encryption is active and the firewall is enabled, marking devices noncompliant if either condition fails.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require the device to be marked as compliant by a third-party MDM

    Why it's wrong here

    This setting is used when a device is managed by a third-party MDM and you want to trust its compliance status. It does not enforce encryption or firewall settings natively. Using it would not fulfill the requirement to configure and enforce those specific security controls within Intune.

  • ✗

    Require Windows Defender Antivirus

    Why it's wrong here

    Require Windows Defender Antivirus ensures the antivirus is active and up to date. While important, it addresses malware protection, not encryption or firewall enforcement. The scenario explicitly asks for encryption and firewall settings, so this option does not meet the stated requirements.

  • ✗

    Require Secure Boot to be enabled on the device

    Why it's wrong here

    Secure Boot is a security feature that helps prevent unauthorized firmware and boot loaders. While it is a valuable security control, it does not enforce encryption or firewall settings. The requirement specifically asks for encryption and firewall enforcement, so this setting is not relevant.

  • ✓

    Require a firewall

    Why this is correct

    Require a firewall is a compliance setting under System Security that verifies Microsoft Defender Firewall is enabled on the device. If the firewall is off, the device is marked noncompliant. This directly fulfills the requirement to enforce firewall settings in the compliance policy.

  • ✓

    Require BitLocker

    Why this is correct

    Require BitLocker is a compliance setting under Device Health that ensures the device's OS drive is encrypted. Enabling this setting makes the device noncompliant if BitLocker is not active. This directly enforces encryption for Windows devices, aligning with the requirement to enforce encryption.

Go deeper

Related to this question

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.