Courseiva
Manage and maintain devicesmediumMultiple ChoiceObjective-mapped

MD-102 Manage and maintain devices Practice Question

You are managing a fleet of Windows 10 devices with Microsoft Intune. You need to deploy a critical security update that Microsoft released out-of-band. The update must be installed on all devices within 24 hours. You have configured Windows Update for Business policies in Intune, but the update is not being installed on many devices. You check the update compliance reports and see that most devices are showing the update as 'pending'. What should you do to expedite the installation?

⚠ Common exam trap

Test-takers frequently confuse compliance policies with update enforcement, thinking that marking a device non-compliant will force an update, when in reality compliance policies only report status and require a separate update policy with a deadline to trigger installation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create an update policy for Windows 10 and later using the 'Quality update' deployment ring and set the deadline to immediate.

Deploying an out-of-band security update with a deadline set to immediate overrides any deferral periods and forces the update to install within the specified deadline. In Intune, Windows Update for Business policies allow you to create a 'Quality update' deployment ring and set the deadline to immediate (0 days), which instructs Windows Update to download and install the update as soon as possible, bypassing normal deferral delays. This directly addresses the 'pending' status by enforcing a mandatory installation timeline.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Modify the existing Windows Update for Business policy to set the deferral period to 0 days.

    Why it's wrong here

    Deferral period controls how long to wait after release, but the update may still not be installed immediately if deadline is not set.

  • Create a compliance policy that requires the update to be installed and assign it to all devices.

    Why it's wrong here

    Compliance policies do not install updates; they only check compliance status.

  • Use Configuration Manager to push the update via on-premises WSUS.

    Why it's wrong here

    The environment is Intune-only; WSUS is not available.

  • Create an update policy for Windows 10 and later using the 'Quality update' deployment ring and set the deadline to immediate.

    Why this is correct

    An update policy with immediate deadline forces the update installation.

Go deeper

Related to this question

About these practice questions

One of 942 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.