MD-102 Protect devices Practice Question
A company uses Microsoft Defender for Endpoint to manage endpoint security. They observe that some devices are not reporting vulnerability data to Microsoft Defender XDR. Which component is most likely misconfigured?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Endpoint sensor on the devices
(Microsoft Defender for Endpoint sensor) is correct. The sensor is the agent installed on devices that collects and reports vulnerability information to Microsoft Defender XDR. If the sensor is misconfigured, missing, or not running, devices will not report vulnerability data. Option A (Microsoft Sentinel workspace) is a SIEM that ingests security data but is not the source of vulnerability data. Option C (Intune MDM authority) manages device compliance and configuration but does not directly collect vulnerability data. Option D (Microsoft Purview compliance portal) handles data governance and compliance, not vulnerability reporting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Sentinel workspace
Why it's wrong here
Sentinel ingests data but is not the source of vulnerability data.
- ✓
Microsoft Defender for Endpoint sensor on the devices
Why this is correct
The sensor collects vulnerability data; missing sensor stops reporting.
- ✗
Intune MDM authority
Why it's wrong here
MDM authority affects management, not vulnerability data collection.
- ✗
Microsoft Purview compliance portal
Why it's wrong here
Purview is for compliance, not endpoint vulnerability.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint is a cloud-delivered enterprise-grade security platform that protects devices, servers, and networks from advanced cyber threats by combining antivirus, endpoint detection and response, and automated investigation and remediation.
Key term
SIEM
SIEM (Security Information and Event Management) is a system that collects and analyzes log data from across an IT environment to detect and respond to security threats in real time.
About these practice questions
Courseiva writes every MD-102 question from scratch — 942 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.