Courseiva

MD-102 Manage and maintain devices Practice Question

Your company uses Microsoft Intune to manage Windows 10 and Windows 11 devices. A security team requires that all devices run a specific antivirus signature version before users can access Microsoft 365 resources. You have already created a compliance policy that requires Microsoft Defender Antivirus to be enabled. You now need to add a rule that evaluates the antivirus signature version. What should you do?

⚠ Common exam trap

The trap here is assuming that a Defender-related configuration profile or a built-in compliance rule can enforce a specific signature version, when only custom compliance settings can evaluate arbitrary properties.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a custom compliance setting to the compliance policy that uses a PowerShell discovery script returning the signature version and a JSON file that validates it.

Intune compliance policies include built-in rules for Defender Antivirus status, but they do not natively expose a rule for a specific signature version. Custom compliance settings close that gap: a PowerShell discovery script reads the current signature version from the device, and a JSON file defines the acceptable values. The resulting compliance state is then honored by conditional access, ensuring only devices with current signatures reach Microsoft 365.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a device configuration profile that sets the Defender signature update interval to every hour and assign it to all devices.

    Why it's wrong here

    A configuration profile can influence how often Defender attempts updates, but it does not report or enforce a minimum signature version for compliance. If a device cannot reach update servers, its signature version remains stale while still being marked compliant. This option changes update behavior, not compliance evaluation, so it does not satisfy the security requirement.

  • ✗

    Configure a Windows Defender Application Control policy that blocks access to Microsoft 365 when the signature is older than the required version.

    Why it's wrong here

    Windows Defender Application Control (WDAC) controls which binaries can execute on a device; it does not evaluate antivirus signature versions or gate access to cloud services. Conditional access decisions are based on Intune compliance state, not WDAC. Using WDAC here would not produce the required compliance signal, so users would not be blocked based on signature version.

  • ✗

    Add a compliance policy rule that requires the device to be at or below a specific OS build version and rely on that as a proxy for signature currency.

    Why it's wrong here

    OS build version and antivirus signature version are unrelated. A device can be fully patched yet have outdated Defender signatures if updates are blocked or failing. Using OS build as a proxy creates false compliance signals, allowing devices with stale signatures to access Microsoft 365 resources. This does not meet the explicit requirement to evaluate signature version.

  • ✓

    Add a custom compliance setting to the compliance policy that uses a PowerShell discovery script returning the signature version and a JSON file that validates it.

    Why this is correct

    Custom compliance settings in Intune allow a PowerShell discovery script to gather any device property, including Defender signature version, and a JSON file to define the expected values. This is the supported way to evaluate a condition that is not exposed as a built-in compliance rule, and the result feeds directly into the device compliance state used by conditional access.

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.