20+ practice questions focused on Protect devices — one of the most tested topics on the Microsoft 365 Endpoint Administrator MD-102 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Protect devices PracticeWhich TWO actions can you perform using Microsoft Intune to protect devices from malware?
Explanation: Options D and E are correct because Microsoft Intune can enforce Windows Defender Antivirus real-time protection via endpoint security policies (Antivirus policy template) and configure Windows Defender Firewall rules via endpoint security policies (Firewall policy). Real-time protection detects and blocks malware execution, while firewall rules prevent network-based malware infections and command-and-control traffic. Both are native Intune capabilities for malware protection.
You need to ensure that devices enrolled in Microsoft Intune automatically receive Windows quality updates as soon as they are released. Which update ring setting should you configure?
Explanation: Setting the 'Quality update deferral period (days)' to 0 ensures that devices receive Windows quality updates immediately upon release, with no delay. This directly addresses the requirement for automatic and immediate installation. Option A affects driver updates, not quality updates. Option C affects feature updates, which are separate from quality updates. Option D's 'Microsoft product updates' setting controls updates for other Microsoft products and does not specifically address Windows quality updates.
You manage Windows 10 devices with Intune. After deploying a new compliance policy requiring BitLocker, many devices show as non-compliant. You verify that BitLocker is enabled on the system drive. What is the most likely cause?
Explanation: Intune compliance policies for BitLocker often require encryption on all drives. If the policy specifies 'Require encryption of data storage on device' or 'Require encryption on all drives', then only encrypting the system drive is insufficient. Devices with multiple drives where only the system drive is encrypted will be reported as non-compliant.
Your organization uses Microsoft Intune with co-management and Configuration Manager. Some Windows 10 devices are enrolled in Intune but also managed by Configuration Manager. You need to ensure that the Intune compliance policy is evaluated and enforced on these devices. What should you configure?
Explanation: In co-management, workloads can be configured to be managed by either Configuration Manager or Intune. To have Intune compliance policies evaluated and enforced on co-managed devices, the Device Compliance workload must be set to 'Intune' in the co-management properties. This ensures that compliance policies created in Intune are applied and enforced. Option A is incorrect because the Configuration Manager client setting does not control workload shifting; that is done in the co-management properties. Option B is incorrect because changing the MDM authority is not necessary and could disrupt management. Option C is incorrect because simply assigning the policy to a device group does not enable evaluation if the workload is still managed by Configuration Manager.
Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a managed Google Play app to work profile devices. After deploying, users report that the app is not available in the work profile. What is the most likely cause?
Explanation: Managed Google Play apps must be approved before they can be deployed to work profile devices. Without approval, the app will not appear in the work profile's Play Store.
+15 more Protect devices questions available
Practice all Protect devices questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Protect devices. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Protect devices questions on the MD-102 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Protect devices is tested as part of the Microsoft 365 Endpoint Administrator MD-102 blueprint. Practicing with targeted Protect devices questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free MD-102 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Protect devices is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Protect devices practice session with instant scoring and detailed explanations.
Start Protect devices Practice →