Courseiva
Manage and maintain devices →mediumMultiple Choice

MD-102 Manage and maintain devices Practice Question

Your organization uses Microsoft Defender for Endpoint (Microsoft Defender XDR). You need to ensure that all Windows 10 devices report their security health to Microsoft Defender for Endpoint. Some devices are showing as inactive. What is the most likely cause?

⚠ Common exam trap

Many candidates confuse device enrollment (Intune) with sensor onboarding, assuming that a device must be managed by Intune to report to Defender for Endpoint, when in fact any Windows 10 device can be onboarded via a simple script or GPO.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Microsoft Defender for Endpoint sensor is not installed or configured correctly.

The Microsoft Defender for Endpoint sensor is the core component that collects and reports security telemetry from Windows 10 devices to the Defender for Endpoint cloud service. If the sensor is not installed, is missing, or is misconfigured (e.g., due to a corrupted installation or incorrect onboarding script), the device will appear as inactive in the Microsoft 365 Defender portal, even if the device is otherwise healthy and connected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The devices are not enrolled in Microsoft Intune.

    Why it's wrong here

    Intune enrolment governs configuration and compliance management, not the Defender for Endpoint onboarding package or sensor service that produces health telemetry. It is tempting because Intune is the usual delivery route for onboarding scripts, so unenrolled devices often do lack the sensor — but enrolment itself is not the reporting mechanism.

  • ✓

    The Microsoft Defender for Endpoint sensor is not installed or configured correctly.

    Why this is correct

    A missing or misconfigured Microsoft Defender for Endpoint sensor directly prevents telemetry from reaching the service, which is why devices appear inactive. Onboarding requires the sensor to be installed and running, with correct configuration, so any gap in that chain halts health reporting regardless of network or licensing state.

  • ✗

    The devices are not compliant with conditional access policies.

    Why it's wrong here

    Conditional access compliance gates resource access at authentication time; it neither installs nor starts the Defender sensor, so a non-compliant device can still report health normally. It is tempting because compliance states and device risk levels both surface in the same portal views.

  • ✗

    The devices have lost connectivity to the internet.

    Why it's wrong here

    Devices buffer telemetry and upload when connectivity returns, so transient internet loss produces delayed reporting rather than a persistent inactive state. It is tempting because the Defender cloud service does require outbound connectivity, and blocked proxy egress genuinely causes onboarding failures.

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.