MD-102 Protect devices Practice Question
Your organization uses Microsoft Defender for Endpoint (now part of Microsoft Defender XDR) to manage device threat detection. You have integrated Defender for Endpoint with Intune for compliance. Some devices are showing as non-compliant due to 'active threats' that are actually low-risk. How can you adjust the compliance policy to allow low-risk threats?
⚠ Common exam trap
Watch out — candidates often confuse the compliance policy's threat level threshold with the Defender for Endpoint risk score or alert suppression, leading them to incorrectly choose whitelisting or risk score configuration instead of the straightforward compliance policy setting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the 'Threat level' in the Intune compliance policy to 'Low'.
The Intune compliance policy includes a 'Threat level' setting that determines the minimum threat severity required for a device to be considered compliant. By setting this value to 'Low', devices with only low-risk threats will be marked as compliant, allowing them to pass the policy check. This directly addresses the scenario where low-risk threats are incorrectly causing non-compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Modify the Conditional Access policy to require device compliance.
Why it's wrong here
Conditional Access does not control threat level.
- ✗
Configure the 'Machine risk score' in Defender for Endpoint.
Why it's wrong here
The risk score is used by Intune, but the compliance policy setting controls the threshold.
- ✗
Whitelist the specific threats in Defender for Endpoint.
Why it's wrong here
Whitelisting is not available for compliance.
- ✓
Set the 'Threat level' in the Intune compliance policy to 'Low'.
Why this is correct
This allows devices with low-risk threats to be compliant.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.