Courseiva

MD-102 Prepare infrastructure for devices Practice Question

Your organization uses Microsoft Defender for Endpoint (Defender XDR) to manage endpoint security. You need to ensure that all Windows devices report their security baselines compliance to Intune. Which configuration should you verify?

⚠ Common exam trap

A common mix-up: candidates confuse onboarding to Defender for Endpoint (which enables security telemetry and threat detection) with the separate requirement of configuring and assigning Intune security baselines to enforce and report compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security baselines are configured and assigned in Intune endpoint security

Intune security baselines are the mechanism that defines and enforces security configuration policies on Windows devices. To report compliance with those baselines, the baselines must first be configured and assigned to the devices via Intune endpoint security. Without this assignment, devices have no baseline to compare against, and compliance reporting will not occur.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Devices are onboarded to Defender for Endpoint

    Why it's wrong here

    Defender onboarding enables endpoint detection and response telemetry, but security baseline compliance is computed and reported by Intune itself, so onboarding alone leaves the baseline state unpublished. It is tempting because onboarding is mandatory for Defender XDR scenarios, and would be the right verification when the requirement is device risk visibility rather than baseline reporting.

  • ✗

    Group Policy objects are linked to the domain

    Why it's wrong here

    Group Policy delivers settings to domain-joined machines but does not forward security baseline compliance state to Intune; that reporting flows through MDM enrolment or the Configuration Manager connector. It is tempting because GPO remains a valid way to configure baselines, and would be correct if the target were on-premises policy enforcement without Intune.

  • ✓

    Security baselines are configured and assigned in Intune endpoint security

    Why this is correct

    Security baselines in Intune endpoint security define and assign the configuration settings whose compliance state devices report. Verifying they are configured and assigned ensures Windows devices actually evaluate and surface baseline compliance data to Intune.

  • ✗

    Devices are registered in Microsoft 365 Defender portal

    Why it's wrong here

    Portal registration only surfaces device inventory and alerts; baseline compliance reporting to Intune requires the Configuration Manager/Intune connector or co-management workload settings. It is tempting because Defender XDR onboarding is a genuine prerequisite for Defender features, and would be correct when the goal is threat detection rather than Intune compliance state.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.