Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your organization, Northwind Traders, uses Microsoft Intune to manage Windows 10 devices. You have created a compliance policy that requires devices to have BitLocker enabled. After assigning the policy, you notice that some devices are reporting as non-compliant due to BitLocker not being enabled. You have verified that the devices support BitLocker and that the policy is correctly assigned. You need to ensure that BitLocker is enabled on these devices automatically. What should you do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create an endpoint protection configuration profile to enable BitLocker

An endpoint protection configuration profile in Microsoft Intune can be used to enforce BitLocker settings on Windows 10 devices automatically. This profile applies the necessary encryption policies without manual intervention. Option A is wrong because modifying the compliance policy to allow non-compliant devices does not enable BitLocker; it only accepts the non-compliant status. Option C is wrong because Windows update ring policies control update deployment, not BitLocker configuration. Option D is wrong while a PowerShell script could enable BitLocker, it is not the standard or recommended method within Intune; configuration profiles provide a managed, scalable solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Modify the compliance policy to allow non-compliant devices

    Why it's wrong here

    Allowing non-compliance does not enable BitLocker.

  • Create an endpoint protection configuration profile to enable BitLocker

    Why this is correct

    Configuration profiles can automatically enable BitLocker on devices.

  • Create a Windows update ring policy

    Why it's wrong here

    Update ring policies manage updates, not BitLocker.

  • Use a PowerShell script to enable BitLocker manually

    Why it's wrong here

    While possible, Intune provides a built-in configuration profile for endpoint protection.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.