MD-102 Prepare infrastructure for devices Practice Question
Your organization uses Microsoft Defender for Endpoint (Defender XDR) and Intune. You need to ensure that when a device is found to have a critical vulnerability, a remediation action is automatically triggered. Which integration should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the integration between Microsoft Defender for Endpoint and Microsoft Intune.
Microsoft Defender for Endpoint can integrate with Microsoft Intune to automatically trigger remediation actions when critical vulnerabilities are found. Option A is incorrect because Microsoft Sentinel is a SIEM and SOAR platform; while it can automate responses, it is not the direct integration for Intune remediation. Option B is incorrect because Microsoft Foundry is an AI platform, not used for device remediation. Option C is incorrect because Microsoft Purview focuses on data governance and compliance, not device remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a Microsoft Sentinel playbook.
Why it's wrong here
Microsoft Sentinel playbooks are used for security incident response, not for automatic remediation of vulnerabilities detected by Defender for Endpoint.
- ✗
Configure a Microsoft Foundry AI model.
Why it's wrong here
Microsoft Foundry is an AI platform and does not provide integration for vulnerability remediation.
- ✗
Configure a Microsoft Purview data loss prevention policy.
Why it's wrong here
Microsoft Purview data loss prevention policies address data protection, not endpoint vulnerability remediation.
- ✓
Configure the integration between Microsoft Defender for Endpoint and Microsoft Intune.
Why this is correct
The integration between Microsoft Defender for Endpoint and Microsoft Intune allows automatic remediation actions (e.g., patch deployment, device quarantine) when critical vulnerabilities are found.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
SIEM
SIEM (Security Information and Event Management) is a system that collects and analyzes log data from across an IT environment to detect and respond to security threats in real time.
About these practice questions
Courseiva writes every MD-102 question from scratch — 942 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.