Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A company wants to use Microsoft Intune to enforce that mobile devices have a PIN of at least 6 characters to access corporate resources. What should they configure?

⚠ Common exam trap

A common mix-up: candidates confuse the enforcement of device settings (Device Compliance Policy) with the configuration of settings (Device Configuration Profile) or app-level protection (App Protection Policy), leading candidates to select D or C instead of A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Device compliance policy

A device compliance policy in Microsoft Intune defines the rules that devices must meet to be considered compliant, such as requiring a PIN of at least 6 characters. When a device is marked non-compliant, Conditional Access can block access to corporate resources. This is the correct mechanism to enforce the PIN requirement at the device level before granting access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Device compliance policy

    Why this is correct

    A Device compliance policy is the correct choice because it specifically defines the security posture and configuration requirements that a mobile device must meet to be considered compliant. This includes setting rules for device-wide security features such as requiring a PIN, specifying its minimum length, or enforcing encryption. Intune evaluates devices against these defined rules and reports their compliance status, which is then used by other policies for access enforcement.

  • Conditional access policy

    Why it's wrong here

    A Conditional access policy is incorrect because its primary function is to grant or block access to corporate resources based on specific conditions, one of which can be a device's compliance status. While it enforces access, it does not define the actual compliance rules, such as the requirement for a device PIN or its complexity. It relies on a device compliance policy to determine whether a device is compliant.

  • App protection policy

    Why it's wrong here

    An App protection policy, also known as a Mobile Application Management (MAM) policy, is incorrect because it focuses on protecting organizational data within specific managed applications. These policies can enforce app-level PINs or restrict actions like copy/paste within an app, but they do not manage or enforce device-wide security settings, such as the operating system's lock screen PIN requirement.

  • Device configuration profile

    Why it's wrong here

    A Device configuration profile is incorrect because its main purpose is to deploy specific settings and features to devices, such as Wi-Fi profiles, VPN settings, or even some security settings like enabling encryption. While it can configure a device to *require* a PIN, it does not actively *evaluate* the device's adherence to that requirement or report its compliance status for enforcement purposes in the same way a compliance policy does.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.