Courseiva
Protect devices →mediumMultiple Choice

MD-102 Protect devices Practice Question

A hospital uses Intune to manage Windows 10 devices used by doctors. The devices should automatically install critical updates from Windows Update for Business. Which type of policy should the administrator create?

⚠ Common exam trap

It's easy for candidates to confuse 'Device configuration profile (Update settings)' with the correct answer, because both can manage update behavior, but Update rings are the modern, recommended method in Intune for Windows 10 update management, while the legacy Update settings profile is deprecated and lacks features like pause and deferral granularity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update rings for Windows 10

Update rings for Windows 10 are the correct policy type in Intune to manage when and how Windows 10 devices receive updates from Windows Update for Business. This policy allows you to configure deferral periods, pause updates, and set the update behavior (e.g., automatic installation of critical updates) without requiring on-premises WSUS or manual approval.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Device compliance policy

    Why it's wrong here

    Compliance policies evaluate attributes such as BitLocker, firewall and OS version, then flag or remediate non-compliance; they never trigger update installation. They would be correct when conditional access must block devices failing security baselines, not when critical updates must install automatically.

  • ✗

    App protection policy

    Why it's wrong here

    App protection policies safeguard corporate data within mobile apps via encryption, PIN and copy-paste restrictions on iOS and Android. They are correct for BYOD data-leakage control, but they neither target Windows 10 update behaviour nor cause Windows Update for Business to install critical updates.

  • ✓

    Update rings for Windows 10

    Why this is correct

    Update rings for Windows 10 define deferral, deadline and active-hours settings that control how Windows Update for Business delivers quality and feature updates. This is the Intune policy type that automates installation of critical updates on managed Windows 10 devices.

  • ✗

    Device configuration profile (Update settings)

    Why it's wrong here

    A device configuration profile's Update settings control update rings, deadlines and restart behaviour, but Windows Update for Business installation itself is governed by the Update rings policy type. Configuration profiles suit controlling feature or quality update deferrals and active hours, not the automatic installation this scenario requires.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.