mediumMultiple ChoiceObjective-mapped
MD-102 Practice Question: A Microsoft 365 Endpoint Administrator for a…
You are a Microsoft 365 Endpoint Administrator for a medium-sized company that uses Intune to manage Windows 10 and iOS devices. The company recently experienced a malware outbreak on several Windows 10 devices. The security team wants to implement a solution that can automatically remediate threats on Windows 10 devices by isolating them from the network and running a full antivirus scan. They also want to be alerted when a threat is detected. You have already configured Microsoft Defender for Endpoint (MDE) and devices are onboarded. What should you configure in Intune to meet these requirements?
⚠ Common exam trap
Many candidates confuse 'Quarantine device' (a compliance action that only blocks resource access) with the actual network isolation and remediation workflow, or they mistakenly think AppLocker or Firewall rules can replace MDE's automated threat response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a device compliance policy that marks devices with active threats as non-compliant, and configure the non-compliance action to 'Retire device' and 'Send notification'.
It uses Intune's device compliance policy integrated with Microsoft Defender for Endpoint. When MDE detects an active threat on a Windows 10 device, Intune marks it as non-compliant. The configured non-compliance action 'Retire device' will remove the device from management and corporate access, effectively isolating it, while 'Send notification' alerts the security team. This automatically remediates the threat by isolating the device and running a full scan (as part of MDE's response). Option A only blocks resource access without remediation; Option C uses firewall rules which do not provide automated threat response; Option D is incorrect because AppLocker cannot run antivirus scans.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a device compliance policy to require Device Health Attestation (DHA) and set the action for non-compliance to 'Quarantine device'.
Why it's wrong here
DHA does not run scans; it only checks boot integrity.
- ✓
Create a device compliance policy that marks devices with active threats as non-compliant, and configure the non-compliance action to 'Retire device' and 'Send notification'.
Why this is correct
Retire action can be used to isolate and remediate, but a more accurate answer would be to use the 'Quarantine' action; however, Intune's compliance policy can trigger MDE's automatic investigation and remediation. In practice, you would use MDE's automated investigation and remediation capabilities, which can be triggered by compliance policy. Option D is the closest correct answer.
- ✗
Enable Windows Defender Firewall with advanced security and create an inbound rule to block all traffic.
Why it's wrong here
Firewall does not run scans or provide automatic remediation.
- ✗
Configure AppLocker to block all apps and set the action to 'Run antivirus scan'.
Why it's wrong here
AppLocker does not have a 'Run antivirus scan' action.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Compliance policy
A compliance policy is a set of rules that ensures devices, users, and applications meet an organization's security and regulatory requirements before they can access corporate resources.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
One of 942 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.