MD-102 Manage and maintain devices Practice Question
Your company uses Microsoft Intune to manage Windows 10 and Windows 11 devices. A security team requires that all devices run a specific antivirus signature version before users can access Microsoft 365 resources. You have already created a compliance policy that requires Microsoft Defender Antivirus to be enabled. You now need to add a rule that evaluates the antivirus signature version. What should you do?
⚠ Common exam trap
The trap here is assuming that a Defender-related configuration profile or a built-in compliance rule can enforce a specific signature version, when only custom compliance settings can evaluate arbitrary properties.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a custom compliance setting to the compliance policy that uses a PowerShell discovery script returning the signature version and a JSON file that validates it.
Intune compliance policies include built-in rules for Defender Antivirus status, but they do not natively expose a rule for a specific signature version. Custom compliance settings close that gap: a PowerShell discovery script reads the current signature version from the device, and a JSON file defines the acceptable values. The resulting compliance state is then honored by conditional access, ensuring only devices with current signatures reach Microsoft 365.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a device configuration profile that sets the Defender signature update interval to every hour and assign it to all devices.
Why it's wrong here
A configuration profile can influence how often Defender attempts updates, but it does not report or enforce a minimum signature version for compliance. If a device cannot reach update servers, its signature version remains stale while still being marked compliant. This option changes update behavior, not compliance evaluation, so it does not satisfy the security requirement.
- ✗
Configure a Windows Defender Application Control policy that blocks access to Microsoft 365 when the signature is older than the required version.
Why it's wrong here
Windows Defender Application Control (WDAC) controls which binaries can execute on a device; it does not evaluate antivirus signature versions or gate access to cloud services. Conditional access decisions are based on Intune compliance state, not WDAC. Using WDAC here would not produce the required compliance signal, so users would not be blocked based on signature version.
- ✗
Add a compliance policy rule that requires the device to be at or below a specific OS build version and rely on that as a proxy for signature currency.
Why it's wrong here
OS build version and antivirus signature version are unrelated. A device can be fully patched yet have outdated Defender signatures if updates are blocked or failing. Using OS build as a proxy creates false compliance signals, allowing devices with stale signatures to access Microsoft 365 resources. This does not meet the explicit requirement to evaluate signature version.
- ✓
Add a custom compliance setting to the compliance policy that uses a PowerShell discovery script returning the signature version and a JSON file that validates it.
Why this is correct
Custom compliance settings in Intune allow a PowerShell discovery script to gather any device property, including Defender signature version, and a JSON file to define the expected values. This is the supported way to evaluate a condition that is not exposed as a built-in compliance rule, and the result feeds directly into the device compliance state used by conditional access.
Go deeper
Related to this question
Learn chapter
Managing Remote Access and VPN Profiles
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Windows 11
Windows 11 is Microsoft's latest desktop operating system, offering a redesigned interface, enhanced security features, and improved support for modern hardware.
About these practice questions
This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.