MD-102 Practice Question: Windows Defender Antivirus real-time protection
Which TWO actions can you perform using Microsoft Intune to protect devices from malware?
⚠ Common exam trap
Candidates often think only antivirus settings (like real-time protection) protect against malware, overlooking that firewall rules also play a crucial role by blocking malicious network traffic. The correct answers are D and E; a common mistake is selecting C (deploying third-party antivirus) or omitting E.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforce Windows Defender Antivirus real-time protection
Option D is correct because Intune can enforce Windows Defender Antivirus settings through endpoint security antivirus policies, including turning on real-time protection, which actively detects and blocks malware on managed Windows devices. Option E is correct because Intune endpoint security firewall policies let you configure Windows Defender Firewall rules (such as blocking inbound/outbound traffic on specific ports or profiles), which helps prevent malware from communicating or spreading across the network. Option A is not provided by Intune itself; network segmentation is typically handled by network security appliances, VLANs, or Azure NSGs rather than Intune device configuration. Option B is not an Intune malware-protection action; email attachment scanning is performed by Exchange Online Protection or Microsoft Defender for Office 365, not by Intune. Option C is not a native Intune malware-protection action in the sense described; while Intune can deploy apps, it does not itself provide antivirus protection, and the built-in Defender controls in D and E are the direct Intune mechanisms for malware protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create network segmentation rules
Why it's wrong here
Intune configures endpoint security policies such as Defender antivirus and attack surface reduction; it has no network segmentation capability, which belongs to Azure virtual network security groups or firewalls. Segmentation is tempting for limiting lateral malware spread in hybrid networks, but the question asks specifically what Intune itself can enforce on devices.
- ✗
Enable email attachment scanning
Why it's wrong here
Intune manages device compliance and Defender policies; email attachment scanning is performed by Microsoft Defender for Office 365 or Exchange Online Protection, not Intune. It is tempting because mail-borne malware is a common infection route, and Defender for Office 365 would be the right control when the requirement is protecting mail flow rather than enrolled devices.
- ✗
Deploy third-party antivirus software
Why it's wrong here
Intune deploys configuration profiles and endpoint security policies; it does not install third-party antivirus products. It is tempting because Intune manages Defender and endpoint protection settings, but third-party AV deployment needs Win32 app packaging or a separate management tool. Intune is correct for Defender antivirus policy and attack surface reduction rules.
- ✓
Enforce Windows Defender Antivirus real-time protection
Why this is correct
Enforcing Windows Defender Antivirus real-time protection through Intune endpoint security policies continuously scans files and processes, blocking malware before execution. This directly satisfies the stem's malware-protection requirement by configuring the antivirus engine on managed Windows devices via the Microsoft Intune security baseline or antivirus policy profile.
- ✓
Configure Windows Defender Firewall rules
Why this is correct
Windows Defender Firewall rules control inbound and outbound network traffic, blocking connections that malware relies on for propagation and command-and-control. This satisfies the stem's malware-protection requirement by filtering traffic at the host level, complementing signature-based antivirus rather than replacing it.
Visual reference
Go deeper
Related to this question
Learn chapter
Managing Microsoft 365 Apps and Office Updates
Key term
Microsoft Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email and collaboration security service that protects organizations against malicious threats like phishing, malware, and spam in email messages and Office 365 apps.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.