MD-102 Prepare infrastructure for devices Practice Question
Your organization uses Microsoft Intune to manage Windows 11 devices. You need to deploy a custom Windows security baseline that includes specific BitLocker settings. What is the best approach to create and assign this configuration?
⚠ Common exam trap
It's easy for candidates to assume baselines can be edited directly like other Intune policies, but Microsoft intentionally locks built-in baselines to enforce consistency, requiring a copy for customization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Copy the built-in Windows security baseline and customize the BitLocker settings in the copy.
Intune's security baselines are designed to be copied and customized rather than edited directly. By copying the built-in Windows security baseline, you preserve the Microsoft-recommended settings as a template while allowing modifications—such as specific BitLocker configurations—in the copy. This approach ensures that the original baseline remains intact for reference or reuse, and the customized copy can be assigned to device groups via Intune's policy assignment workflow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a compliance policy with custom settings to enforce BitLocker.
Why it's wrong here
Security baselines are the appropriate method, not compliance policies.
- ✗
Create a new security baseline from scratch and include the BitLocker settings.
Why it's wrong here
You cannot create a baseline from scratch; you must duplicate an existing one.
- ✓
Copy the built-in Windows security baseline and customize the BitLocker settings in the copy.
Why this is correct
Intune allows you to duplicate a baseline and modify settings.
- ✗
Edit the built-in Windows security baseline and add the BitLocker settings.
Why it's wrong here
Built-in baselines are read-only and cannot be edited.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
BitLocker
BitLocker is a full-disk encryption feature built into Windows that protects data by encrypting the entire drive so that unauthorized users cannot access files without the correct recovery key.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
One of 942 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.