MS-900 Describe Microsoft 365 apps and services Practice Question
Exhibit
Refer to the exhibit.
{
"assignment": {
"target": {
"group": "Group_Sales"
},
"settings": [
{
"settingId": "device_lock",
"value": {
"@odata.type": "#microsoft.graph.deviceCompliancePolicySettingState",
"setting": "requirePassword",
"settingName": "Require password to unlock mobile device",
"instanceDisplayName": "Require Password",
"state": "compliant"
}
},
{
"settingId": "encryption",
"value": {
"@odata.type": "#microsoft.graph.deviceCompliancePolicySettingState",
"setting": "requireEncryption",
"settingName": "Require encryption on device",
"instanceDisplayName": "Require Encryption",
"state": "notCompliant"
}
}
]
}
}Refer to the exhibit. The JSON shows a device compliance policy assignment in Microsoft Intune. Based on the exhibit, what is the current compliance status of the devices in the target group?
⚠ Common exam trap
The trap here is that candidates may focus on the password setting being present and compliant, overlooking that the encryption setting is explicitly non-compliant, and assume partial compliance is sufficient for an overall 'Compliant' status.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Not compliant, because the encryption setting is not compliant
The exhibit shows a device compliance policy in Microsoft Intune with two settings: 'require device encryption' set to 'Required' and 'minimum password length' set to '6'. The compliance status for the target group is 'Not compliant, because the encryption setting is not compliant'. This is because the JSON indicates that the encryption requirement is not being met by the devices in the group, likely due to BitLocker or device encryption not being enabled. The password setting alone does not override the encryption non-compliance, as all required settings must be satisfied for a device to be marked compliant.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Not compliant, only because the password setting is missing
Why it's wrong here
This option misidentifies the offending setting. The JSON shows the password setting is present and fully compliant, so the device is not non-compliant because of a missing password. The encryption setting is the one that fails to meet the policy requirement, and because any single failing setting makes the entire device non-compliant, the 'only because' claim is incorrect.
- ✗
Compliant, because both settings are compliant
Why it's wrong here
This option overlooks the encryption setting's non-compliant status. The JSON explicitly indicates that encryption is required but is not satisfied, which means the device cannot be considered compliant. Compliance policies in Microsoft Intune require all configured settings to be met; if even one setting fails, the overall compliance state is 'Not compliant,' so the assertion that both settings are compliant is factually wrong.
- ✓
Not compliant, because the encryption setting is not compliant
Why this is correct
The JSON clearly shows that the encryption setting is required but is not compliant, and in a device compliance policy, any single non-compliant setting causes the entire device to be flagged as not compliant. Even though the password setting is satisfied, the unresolved encryption requirement overrides that and results in a 'Not compliant' status. Microsoft Intune evaluates all rules collectively, so this device is correctly identified as non-compliant due to the encryption setting.
- ✗
Compliant, because the password setting is compliant
Why it's wrong here
This option incorrectly treats the password setting as the sole determinant of compliance. While the password setting may indeed be compliant, a device compliance policy is an aggregate of all rules; the encryption setting is non-compliant and invalidates the overall status. A device is marked 'Compliant' only when every required condition is met, so the presence of a compliant password cannot compensate for the failing encryption requirement.
Go deeper
Related to this question
Learn chapter
Intune Device Compliance and Configuration Policies
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.