Courseiva

MD-102 Manage and maintain devices Practice Question

You manage a fleet of Windows 11 devices with Microsoft Intune. You need to ensure that when a device is compromised, it can be remotely wiped even if the user is not connected to the corporate network. The devices are Microsoft Entra ID joined and enrolled in Intune. What should you configure?

⚠ Common exam trap

The trap here is thinking that remote wipe requires the device to be on the corporate network or that other security features like WDAG or conditional access can perform a wipe, when in fact only the Wipe action does, and it works over the internet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure the device has an active internet connection and use the 'Wipe' action in Intune.

Intune's Wipe action is designed for remote device wipe. When initiated, the command is queued and delivered to the device over the internet through the Intune service. The device must have an active internet connection to receive the command, but it does not need to be on the corporate network. This makes it effective for compromised devices that are off-site.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a conditional access policy that requires compliant devices.

    Why it's wrong here

    Conditional access policies control access to resources based on conditions, but they do not enable remote wipe. They can block access from noncompliant devices, but they do not initiate a wipe action. Remote wipe is a separate device management action in Intune.

  • ✗

    Deploy a PowerShell script that triggers a factory reset when a specific file is created.

    Why it's wrong here

    A PowerShell script can initiate a factory reset, but it requires the script to be executed on the device, which typically requires the device to be online and the script to be delivered. This method is not reliable for remote wipe because it depends on script execution and does not integrate with Intune's management channel.

  • ✗

    Enable Windows Defender Application Guard.

    Why it's wrong here

    Windows Defender Application Guard (WDAG) isolates browser sessions to protect against malicious websites, but it does not provide remote wipe capabilities. It is a security feature for browsing, not a management action for device wipe. Remote wipe is handled through Intune device actions.

  • ✓

    Ensure the device has an active internet connection and use the 'Wipe' action in Intune.

    Why this is correct

    The Wipe action in Intune can be initiated remotely and will execute when the device next connects to the internet. For Microsoft Entra ID joined devices, the wipe command is delivered via the Intune service. As long as the device has internet access, it will receive and execute the wipe, even if not on the corporate network.

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.