MD-102 Real-time protection Practice Question
Your company uses Microsoft Intune to manage Windows 10 devices. You need to ensure that all devices have Windows Defender Antivirus real-time protection enabled. What should you configure?
⚠ Common exam trap
The trap is that candidates may think both device configuration policies (B) and endpoint security policies (D) are equally correct for a single-answer question. However, the question expects a single method, and device configuration policy is the most straightforward way to set real-time protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a device configuration policy for Windows Defender Antivirus and enable Real-time protection.
A device configuration policy is the most direct method to enforce Windows Defender Antivirus real-time protection, using the Defender CSP to set 'AllowRealtimeMonitoring'. While the Endpoint security node provides a dedicated Antivirus policy, device configuration policies are the straightforward administrative path for granular settings like real-time protection. A compliance policy only checks for antivirus but does not enforce the setting. Administrative Templates can also configure this via GPO-style settings, but they are less direct for this specific requirement in Intune. Therefore, Option B is the best single answer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a device compliance policy requiring antivirus.
Why it's wrong here
Device compliance policies only report on compliance status and can trigger conditional access, but they do not apply configuration settings. Therefore, they cannot enable real-time protection.
- ✓
Create a device configuration policy for Windows Defender Antivirus and enable Real-time protection.
Why this is correct
Correct. A device configuration policy for Windows Defender Antivirus can directly enable Real-time protection using the Defender CSP.
- ✗
Use Administrative Templates to configure Windows Defender Antivirus.
Why it's wrong here
Administrative Templates can also configure Windows Defender Antivirus settings, but they are a type of device configuration policy. While not incorrect, the question specifically asks for 'what should you configure' and both B and D are more direct and commonly used. However, this option is not considered correct in this context because it is less specific than B and D.
- ✗
Use the Endpoint security node to configure Antivirus policies.
Why it's wrong here
Correct. The Endpoint security node in Intune provides Antivirus policies that can enable real-time protection, among other settings. This is a dedicated area for security policies and is a valid method.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Compliance policy
A compliance policy is a set of rules that ensures devices, users, and applications meet an organization's security and regulatory requirements before they can access corporate resources.
About these practice questions
One of 942 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.