MD-102 Manage and maintain devices Practice Question
Which TWO actions can you perform in Microsoft Intune to remediate a noncompliant Windows device that has been marked as noncompliant due to missing antivirus? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse Conditional Access policies (which block access but do not fix the issue) with actual remediation actions, or they assume a sync command will resolve noncompliance when it only re-evaluates the existing state.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a proactive remediation script to detect and install antivirus.
Option B is correct because proactive remediations in Intune pair a detection script with a remediation script that runs on the device, so you can detect missing antivirus and automatically install it to bring the device back into compliance. Option D is correct because running a PowerShell script from Intune (via a platform script or device script) lets you execute installation commands for the missing antivirus directly on the Windows device. Option A is not a remediation action; a sync only forces the device to check in and re-evaluate policy/compliance, which does not install antivirus. Option C merely notifies the user and relies on manual action, so it does not remediate the device automatically. Option E is a Conditional Access policy that blocks access rather than fixing the noncompliance, so it is not a remediation action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Send a sync command to the device to re-evaluate compliance.
Why it's wrong here
A sync forces the device to re-report its existing state; it installs nothing, so antivirus remains absent and compliance stays failed. It is tempting because sync is the standard first step when a device's reported status is stale, and it would be correct if the antivirus were already installed but not yet detected.
- ✓
Deploy a proactive remediation script to detect and install antivirus.
Why this is correct
Proactive remediation scripts run detection and remediation logic directly on the device, satisfying the missing-antivirus compliance state without user interaction. Unlike configuration profiles, which enforce settings, this mechanism actively detects the absent antivirus and installs it, restoring compliance as reported to Microsoft Entra ID.
- ✗
Send a notification to the user to install antivirus via Windows Security.
Why it's wrong here
A notification only informs the user; it pushes no installation and cannot guarantee antivirus is deployed, so compliance may remain failed. It is tempting because user notifications are the right choice when remediation requires a manual action the user must perform, such as enrolling or approving something.
- ✓
Run a PowerShell script from Intune to install the missing antivirus.
Why this is correct
Running a PowerShell script from Intune executes remediation directly on the device, satisfying the missing-antivirus compliance failure. Intune's script deployment reaches managed Windows endpoints through the Microsoft Intune Management Extension, allowing silent installation of the required antivirus without user interaction, which restores the device to compliant status against that specific policy condition.
- ✗
Create a Conditional Access policy to block the device until fixed.
Why it's wrong here
Conditional Access blocks access to cloud resources; it does not install antivirus or change device state, so the device stays noncompliant. It is tempting because Conditional Access is the correct tool when the goal is to restrict access for noncompliant devices rather than remediate them.
Go deeper
Related to this question
Learn chapter
Managing Microsoft 365 Apps and Office Updates
Key term
Remediation script
A remediation script is an automated set of instructions that detects and fixes common IT security or configuration issues without manual intervention.
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.