Courseiva
Protect deviceshardMultiple ChoiceObjective-mapped

MD-102 Protect devices Practice Question

Your organization uses Microsoft Defender for Endpoint (now part of Microsoft Defender XDR) to manage device threat detection. You have integrated Defender for Endpoint with Intune for compliance. Some devices are showing as non-compliant due to 'active threats' that are actually low-risk. How can you adjust the compliance policy to allow low-risk threats?

⚠ Common exam trap

Watch out — candidates often confuse the compliance policy's threat level threshold with the Defender for Endpoint risk score or alert suppression, leading them to incorrectly choose whitelisting or risk score configuration instead of the straightforward compliance policy setting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Set the 'Threat level' in the Intune compliance policy to 'Low'.

The Intune compliance policy includes a 'Threat level' setting that determines the minimum threat severity required for a device to be considered compliant. By setting this value to 'Low', devices with only low-risk threats will be marked as compliant, allowing them to pass the policy check. This directly addresses the scenario where low-risk threats are incorrectly causing non-compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Modify the Conditional Access policy to require device compliance.

    Why it's wrong here

    Conditional Access does not control threat level.

  • Configure the 'Machine risk score' in Defender for Endpoint.

    Why it's wrong here

    The risk score is used by Intune, but the compliance policy setting controls the threshold.

  • Whitelist the specific threats in Defender for Endpoint.

    Why it's wrong here

    Whitelisting is not available for compliance.

  • Set the 'Threat level' in the Intune compliance policy to 'Low'.

    Why this is correct

    This allows devices with low-risk threats to be compliant.

Go deeper

Related to this question

About these practice questions

This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.