MD-102 Protect devices Practice Question
A hospital uses Intune to manage Windows 10 devices used by doctors. The devices should automatically install critical updates from Windows Update for Business. Which type of policy should the administrator create?
⚠ Common exam trap
It's easy for candidates to confuse 'Device configuration profile (Update settings)' with the correct answer, because both can manage update behavior, but Update rings are the modern, recommended method in Intune for Windows 10 update management, while the legacy Update settings profile is deprecated and lacks features like pause and deferral granularity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update rings for Windows 10
Update rings for Windows 10 are the correct policy type in Intune to manage when and how Windows 10 devices receive updates from Windows Update for Business. This policy allows you to configure deferral periods, pause updates, and set the update behavior (e.g., automatic installation of critical updates) without requiring on-premises WSUS or manual approval.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Device compliance policy
Why it's wrong here
Compliance policies evaluate attributes such as BitLocker, firewall and OS version, then flag or remediate non-compliance; they never trigger update installation. They would be correct when conditional access must block devices failing security baselines, not when critical updates must install automatically.
- ✗
App protection policy
Why it's wrong here
App protection policies safeguard corporate data within mobile apps via encryption, PIN and copy-paste restrictions on iOS and Android. They are correct for BYOD data-leakage control, but they neither target Windows 10 update behaviour nor cause Windows Update for Business to install critical updates.
- ✓
Update rings for Windows 10
Why this is correct
Update rings for Windows 10 define deferral, deadline and active-hours settings that control how Windows Update for Business delivers quality and feature updates. This is the Intune policy type that automates installation of critical updates on managed Windows 10 devices.
- ✗
Device configuration profile (Update settings)
Why it's wrong here
A device configuration profile's Update settings control update rings, deadlines and restart behaviour, but Windows Update for Business installation itself is governed by the Update rings policy type. Configuration profiles suit controlling feature or quality update deferrals and active hours, not the automatic installation this scenario requires.
Go deeper
Related to this question
Learn chapter
Managing Microsoft 365 Apps and Office Updates
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Windows 10
Windows 10 is a personal computer operating system developed by Microsoft that combines the familiarity of Windows 7 with the modern features of Windows 8, designed to run on a wide range of devices from desktops to tablets.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.