MD-102 Prepare infrastructure for devices Practice Question
Your organization uses Microsoft Defender for Endpoint (Defender XDR) and Intune. You need to ensure that when a device is found to have a critical vulnerability, a remediation action is automatically triggered. Which integration should you configure?
⚠ Common exam trap
MD-102 often tests whether candidates confuse Sentinel (SIEM/SOAR for log analytics) with the native Defender-to-Intune remediation pipeline, causing them to pick the 'automation' answer (Sentinel playbook) instead of the built-in integration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the integration between Microsoft Defender for Endpoint and Microsoft Intune.
The native integration between Microsoft Defender for Endpoint and Microsoft Intune enables automatic remediation of vulnerabilities discovered by Defender's threat and vulnerability management (TVM) component. When Defender XDR surfaces a critical vulnerability, Intune can push remediation actions (patches, configuration changes, app updates) to the affected managed devices without manual intervention. This is the built-in 'security task' workflow that flows from Defender into Intune's endpoint security node.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a Microsoft Sentinel playbook.
Why it's wrong here
A Microsoft Sentinel playbook automates responses to incidents Sentinel ingests, but it does not natively push remediation actions to Intune-managed devices from Defender XDR vulnerability findings. It is tempting because playbooks orchestrate automation, and it would be correct for SIEM-driven incident response workflows.
- ✗
Configure a Microsoft Foundry AI model.
Why it's wrong here
A Microsoft Foundry AI model generates or hosts machine-learning workloads; it holds no connector to Defender XDR vulnerability signals or Intune remediation actions. It is tempting because AI sounds automated, and it would be correct when the requirement is building a custom model, not orchestrating device remediation.
- ✗
Configure a Microsoft Purview data loss prevention policy.
Why it's wrong here
Purview data loss prevention policies inspect and block sensitive information flows such as files and email; they cannot trigger Intune device remediation for a Defender-detected vulnerability. It is tempting because both concern protection, and it would be correct when preventing sensitive data leaving endpoints or cloud apps.
- ✓
Configure the integration between Microsoft Defender for Endpoint and Microsoft Intune.
Why this is correct
The Defender for Endpoint–Intune connector shares device risk and vulnerability findings with Intune, which then applies remediation actions such as pushing scripts or configuration to affected devices. This satisfies the stem's automatic-trigger requirement without manual analyst intervention.
Go deeper
Related to this question
Learn chapter
Managing Microsoft 365 Apps and Office Updates
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.