MD-102 Manage and maintain devices Practice Question
A company uses Microsoft Intune to manage devices. They need to report on which devices have a specific Windows update installed. Which reporting method should be used?
⚠ Common exam trap
Candidates often confuse the Device compliance report (which checks OS version or build) with the Windows Update for Business report (which tracks specific KB installations), leading them to select Option C incorrectly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the Microsoft Intune admin center to view the Windows Update for Business report
The Windows Update for Business report in the Microsoft Intune admin center provides a dedicated view of update compliance, including which devices have installed specific Windows updates. This report aggregates data from the Windows Update service and displays it per device, making it the correct method for identifying devices with a particular update installed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use the Microsoft Intune admin center to view the Windows Update for Business report
Why this is correct
The Windows Update for Business report in the Microsoft Intune admin center aggregates update installation state per device, including specific KBs. It satisfies the requirement to identify which managed devices have a particular Windows update installed, without needing custom scripting or third-party tooling.
- ✗
Use Microsoft 365 Lighthouse
Why it's wrong here
Microsoft 365 Lighthouse reports on tenants, licences, compliance and security baselines for managed service providers, not update-level inventory across Intune-managed devices. It is tempting as a Microsoft reporting portal, but it aggregates tenant health rather than querying per-device Windows update installation state.
- ✗
Use the Device compliance report in Intune
Why it's wrong here
The Device compliance report shows whether devices meet assigned compliance policies, not which specific Windows updates are installed. It is tempting because it lives in Intune reporting, but compliance state reflects policy evaluation, whereas update inventory requires the Windows update report or Update rings reporting.
- ✗
Use Microsoft Defender for Endpoint's advanced hunting
Why it's wrong here
Advanced hunting queries Defender for Endpoint telemetry such as device events and alerts; it does not expose Intune's Windows update installation inventory. It is tempting because it offers powerful KQL querying across endpoints, but the required update data resides in Intune's Windows update reports, not Defender tables.
Go deeper
Related to this question
Learn chapter
Enrolling Devices with Microsoft Intune
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.