SC-100 Practice Question: Design solutions that align with security best practices and priorities
Your organization uses Microsoft Intune to manage devices. You need to ensure that only devices with a specific minimum OS version can access corporate resources. Which configuration should you use?
⚠ Common exam trap
It's easy for candidates to confuse enrollment restrictions (which only check OS version at the point of enrollment) with compliance policies (which enforce OS version continuously after enrollment), leading candidates to pick enrollment restrictions as a one-time gate rather than an ongoing control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Device compliance policy with minimum OS version rule
A device compliance policy with a minimum OS version rule is the correct choice because Intune compliance policies evaluate device attributes—including OS version—against defined rules before granting access to corporate resources. When a device fails the minimum OS version check, Conditional Access blocks access until the device is updated or remediated, ensuring only compliant devices can connect.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Device compliance policy with minimum OS version rule
Why this is correct
A device compliance policy with a minimum OS version rule is correct because Intune evaluates the installed OS version against this rule during each compliance check. If the device falls below the threshold, it is marked non-compliant, which can trigger conditional access blocks or end-user remediation prompts. This rule directly enforces that devices remain on a supported OS version as a condition of accessing organizational resources.
- ✗
Device configuration profile
Why it's wrong here
A device configuration profile is incorrect because it simply deploys settings such as Wi-Fi, certificates, or encryption policies to devices without assessing the OS version. Devices receive these configurations regardless of whether they meet any minimum OS requirement, and no compliance status is generated from a configuration profile. It therefore cannot enforce a minimum OS version as a compliance gate.
- ✗
Enrollment restrictions
Why it's wrong here
Enrollment restrictions are incorrect because they only evaluate a device's platform and OS version at the moment of enrollment, preventing unsupported devices from joining Intune. After the device enrolls, these restrictions have no ongoing effect, so a device could later fall out of compliance with your minimum OS standard without being blocked or flagged. They are a one-time gate, not a continuous compliance enforcement mechanism.
- ✗
App protection policy
Why it's wrong here
App protection policies are incorrect because they operate at the application layer, governing behaviors like data sharing, save-as, and access PINs within just protected apps. They do not inspect or set the device's OS version, and they apply even to devices that are not enrolled or that fail OS version requirements. Since they are app-centric rather than device-centric, they cannot enforce a minimum OS version rule for the device itself.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.