SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization, Northwind Traders, uses Microsoft Intune to manage Windows 10 devices. You have created a compliance policy that requires devices to have BitLocker enabled. After assigning the policy, you notice that some devices are reporting as non-compliant due to BitLocker not being enabled. You have verified that the devices support BitLocker and that the policy is correctly assigned. You need to ensure that BitLocker is enabled on these devices automatically. What should you do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an endpoint protection configuration profile to enable BitLocker
An endpoint protection configuration profile in Microsoft Intune can be used to enforce BitLocker settings on Windows 10 devices automatically. This profile applies the necessary encryption policies without manual intervention. Option A is wrong because modifying the compliance policy to allow non-compliant devices does not enable BitLocker; it only accepts the non-compliant status. Option C is wrong because Windows update ring policies control update deployment, not BitLocker configuration. Option D is wrong while a PowerShell script could enable BitLocker, it is not the standard or recommended method within Intune; configuration profiles provide a managed, scalable solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Modify the compliance policy to allow non-compliant devices
Why it's wrong here
Allowing non-compliance does not enable BitLocker.
- ✓
Create an endpoint protection configuration profile to enable BitLocker
Why this is correct
Configuration profiles can automatically enable BitLocker on devices.
- ✗
Create a Windows update ring policy
Why it's wrong here
Update ring policies manage updates, not BitLocker.
- ✗
Use a PowerShell script to enable BitLocker manually
Why it's wrong here
While possible, Intune provides a built-in configuration profile for endpoint protection.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.