MD-102 Prepare infrastructure for devices Practice Question
Your organization uses Microsoft Defender for Endpoint (part of Microsoft Defender XDR) on all Windows devices. You need to ensure that devices that are not actively reporting to Defender for Endpoint are flagged as non-compliant in Intune. What should you configure?
⚠ Common exam trap
Watch out — candidates often confuse Conditional Access (which enforces compliance) with the compliance policy setting that actually defines what 'non-compliant' means, leading them to pick Option A instead of the correct risk-score setting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a compliance policy setting: 'Require the device to be at or under the machine risk score' with a low score.
Microsoft Defender for Endpoint integrates with Intune compliance policies via the 'Require the device to be at or under the machine risk score' setting. When a device stops reporting to Defender, its risk score escalates above the 'Low' threshold, causing Intune to mark it as non-compliant. This directly meets the requirement to flag non-reporting devices without additional scripting or conditional access complexity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a Conditional Access policy requiring device compliance and blocking access if not compliant.
Why it's wrong here
Conditional Access uses compliance status but does not define compliance rules.
- ✗
Enable 'Require BitLocker' compliance setting.
Why it's wrong here
BitLocker compliance does not check Defender sensor status.
- ✗
Deploy a PowerShell script via Intune that checks the Defender service status and reports to Intune custom compliance.
Why it's wrong here
A PowerShell script checking Defender service status and reporting via Intune custom compliance would only flag non-compliance after the next scheduled compliance check, not in real time. This fails the requirement because Defender for Endpoint’s sensor health state is already evaluated continuously by Microsoft Entra ID device-based conditional access policies, which can block access immediately. It is tempting because custom compliance scripts can verify arbitrary conditions, and would be correct if the requirement were to assess a non-Defender application’s state rather than Defender’s own reporting status.
- ✓
Add a compliance policy setting: 'Require the device to be at or under the machine risk score' with a low score.
Why this is correct
This setting uses Defender for Endpoint risk score to evaluate compliance. If the device is not reporting, the score is not available, causing non-compliance.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Risk score
A risk score is a numerical value that represents the level of risk associated with a given asset, threat, or vulnerability in a security context.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.