Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Intune to manage devices. You need to design a compliance policy that requires devices to have a minimum OS version and be encrypted. Which policy type should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a device compliance policy in Microsoft Intune.

The correct option is D: Create a device compliance policy in Microsoft Intune. Compliance policies are specifically designed to define rules such as minimum OS version, encryption status, and other security settings that devices must meet, and they evaluate device state against these requirements. Device configuration profiles (A) push settings to devices but do not evaluate compliance, while Conditional Access policies (B) use compliance results to grant or block access rather than define the requirements themselves. App protection policies (C) protect app data on mobile devices and do not enforce OS version or device encryption compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a device configuration profile in Microsoft Intune.

    Why it's wrong here

    A device configuration profile in Microsoft Intune deploys settings such as restrictions, certificates, or Wi-Fi profiles to devices, but it does not evaluate whether a device meets security requirements. It only pushes the desired configuration; it never assesses the device state or generates a compliance verdict. Therefore, creating a configuration profile alone cannot enforce conditions like OS version or encryption as a gate to access.

  • ✗

    Create a Conditional Access policy in Microsoft Entra ID.

    Why it's wrong here

    A Conditional Access policy in Microsoft Entra ID consumes the compliance state of a device as a signal to allow or block access, but it does not contain the rules that define what compliance means. The actual compliance criteria—such as minimum OS version, disk encryption, or jailbreak detection—must be authored as a separate device compliance policy in Intune. Without that compliance policy, the Conditional Access condition has no underlying evaluation to enforce.

  • ✗

    Create an app protection policy in Microsoft Intune.

    Why it's wrong here

    An app protection policy (APP) in Microsoft Intune, also known as MAM, governs how users interact with corporate data inside specific applications, such as preventing copy/paste or requiring a PIN to open an app. It operates at the app layer and applies regardless of device enrollment, so it cannot assess device-level attributes like OS build, device encryption, or root status. To evaluate those device properties and mark the device as compliant, you need a compliance policy, not an APP.

  • ✓

    Create a device compliance policy in Microsoft Intune.

    Why this is correct

    A device compliance policy in Microsoft Intune is the correct mechanism because it defines the rules that a device must satisfy to be considered compliant, including required OS versions, encryption, password complexity, and threat-level results from Mobile Threat Defense. Once assigned, the Intune service evaluates each device against those rules, assigns a remediation status, and reports the compliance state to Microsoft Entra ID for Conditional Access to block non-compliant devices.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.