Courseiva

MD-102 Manage and maintain devices Practice Question

You are the endpoint administrator for Contoso Ltd. The company uses Microsoft Intune to manage Windows 11 devices. You need to deploy a critical security update to all devices within 24 hours. The update is a quality update (KB5001234). You have created an update ring policy named 'Critical Ring' assigned to all devices. The policy currently has a deferral period of 7 days. You need to ensure that the update is installed immediately. What should you do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the 'Critical Ring' update ring policy to set the quality update deferral period to 0 days and the deadline for updates to 1 day.

The update ring policy controls deferral and deadline. To install immediately, set deferral to 0 and deadline to 1 day. Creating a feature update policy is for feature updates, not quality updates. Manually approving in WSUS is not relevant as Intune manages updates. Changing the deadline to 7 days would not meet the 24-hour requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the update ring policy deadline to 7 days to ensure devices have enough time.

    Why it's wrong here

    Extending the deadline to 7 days delays enforcement and contradicts the 24-hour requirement, since deferral still blocks installation. It tempts because deadlines do force installation, but a 7-day deadline cannot meet the immediate deployment the scenario demands.

  • ✗

    Create a new feature update policy for KB5001234 and assign it to all devices.

    Why it's wrong here

    Feature update policies target Windows version upgrades, not quality updates, so KB5001234 would never be delivered through one. It tempts because feature update policies do control update deployment timing, but they apply to annual version releases rather than monthly security patches.

  • ✓

    Modify the 'Critical Ring' update ring policy to set the quality update deferral period to 0 days and the deadline for updates to 1 day.

    Why this is correct

    Setting the quality update deferral to 0 days removes the seven-day hold, and a one-day deadline forces installation within the required 24-hour window. Both settings must change together; deferral alone would not guarantee the deadline is enforced on every device.

  • ✗

    Use the Windows Server Update Services (WSUS) console to approve the update for immediate installation.

    Why it's wrong here

    WSUS is a separate on-premises update infrastructure; Intune-managed devices take update policy from Intune, not a WSUS console. It tempts because WSUS does approve updates for installation, but it governs different devices and cannot override the Intune update ring.

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.