Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company uses Microsoft Intune to manage its devices. The security team wants to enforce that all devices running Windows 11 must have BitLocker enabled and a minimum operating system build version. Which Intune policy type should they use?

⚠ Common exam trap

Watch out — candidates often confuse configuration profiles (which apply settings) with compliance policies (which enforce and evaluate those settings), leading them to select A instead of D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Compliance policy

Compliance policies in Microsoft Intune define the rules and settings that devices must meet to be considered compliant, such as requiring BitLocker encryption and a minimum OS build version. When a device fails to meet these conditions, Intune can mark it as non-compliant and trigger conditional access policies to block access to corporate resources. This makes compliance policy the correct choice for enforcing security baselines like BitLocker and OS version requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configuration profile

    Why it's wrong here

    Configuration profiles deploy specific settings to devices, such as Wi-Fi network details, VPN configurations, or password requirements. While they configure settings, they do not actively evaluate a device's current state against a defined security standard or mark it as non-compliant if it fails to meet those conditions, which is the primary function of a compliance policy.

  • Enrollment restriction

    Why it's wrong here

    Enrollment restrictions control which devices and users are permitted to enroll into Microsoft Intune based on criteria like device platform, OS version, or device manufacturer. They act as a gatekeeper for initial device registration, preventing non-compliant devices from even joining management, but do not continuously monitor or enforce ongoing compliance post-enrollment.

  • App protection policy

    Why it's wrong here

    App protection policies, also known as MAM (Mobile Application Management) policies, focus on protecting organizational data within specific mobile applications, regardless of whether the device itself is managed by Intune. They enforce data loss prevention controls like restricting copy/paste, preventing 'save as' to personal storage, or requiring a PIN to access the app, rather than assessing the overall security posture of the device.

  • Compliance policy

    Why this is correct

    Compliance policies define the security baselines and health requirements that devices must meet to be considered compliant within an organization, such as requiring device encryption, a minimum OS version, or an enabled firewall. These policies continuously evaluate device properties against the defined rules and can mark devices as non-compliant, often integrating with Conditional Access to restrict resource access until compliance is restored.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.