Courseiva
Manage and maintain devices →mediumMultiple Select

MD-102 Manage and maintain devices Practice Question

Which TWO actions can you perform in Microsoft Intune to remediate a noncompliant Windows device that has been marked as noncompliant due to missing antivirus? (Choose two.)

⚠ Common exam trap

Test-takers frequently confuse Conditional Access policies (which block access but do not fix the issue) with actual remediation actions, or they assume a sync command will resolve noncompliance when it only re-evaluates the existing state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a proactive remediation script to detect and install antivirus.

Option B is correct because proactive remediations in Intune pair a detection script with a remediation script that runs on the device, so you can detect missing antivirus and automatically install it to bring the device back into compliance. Option D is correct because running a PowerShell script from Intune (via a platform script or device script) lets you execute installation commands for the missing antivirus directly on the Windows device. Option A is not a remediation action; a sync only forces the device to check in and re-evaluate policy/compliance, which does not install antivirus. Option C merely notifies the user and relies on manual action, so it does not remediate the device automatically. Option E is a Conditional Access policy that blocks access rather than fixing the noncompliance, so it is not a remediation action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Send a sync command to the device to re-evaluate compliance.

    Why it's wrong here

    A sync forces the device to re-report its existing state; it installs nothing, so antivirus remains absent and compliance stays failed. It is tempting because sync is the standard first step when a device's reported status is stale, and it would be correct if the antivirus were already installed but not yet detected.

  • ✓

    Deploy a proactive remediation script to detect and install antivirus.

    Why this is correct

    Proactive remediation scripts run detection and remediation logic directly on the device, satisfying the missing-antivirus compliance state without user interaction. Unlike configuration profiles, which enforce settings, this mechanism actively detects the absent antivirus and installs it, restoring compliance as reported to Microsoft Entra ID.

  • ✗

    Send a notification to the user to install antivirus via Windows Security.

    Why it's wrong here

    A notification only informs the user; it pushes no installation and cannot guarantee antivirus is deployed, so compliance may remain failed. It is tempting because user notifications are the right choice when remediation requires a manual action the user must perform, such as enrolling or approving something.

  • ✓

    Run a PowerShell script from Intune to install the missing antivirus.

    Why this is correct

    Running a PowerShell script from Intune executes remediation directly on the device, satisfying the missing-antivirus compliance failure. Intune's script deployment reaches managed Windows endpoints through the Microsoft Intune Management Extension, allowing silent installation of the required antivirus without user interaction, which restores the device to compliant status against that specific policy condition.

  • ✗

    Create a Conditional Access policy to block the device until fixed.

    Why it's wrong here

    Conditional Access blocks access to cloud resources; it does not install antivirus or change device state, so the device stays noncompliant. It is tempting because Conditional Access is the correct tool when the goal is to restrict access for noncompliant devices rather than remediate them.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.