Courseiva

MD-102 Prepare infrastructure for devices Practice Question

Your organization uses Microsoft Defender for Endpoint to manage device security. You need to ensure that all Windows devices are reporting security events to Microsoft Defender XDR. You have verified that the Microsoft Defender for Endpoint service is running on the devices. However, some devices show as 'inactive' in the Microsoft Defender XDR console. What is the most likely cause?

⚠ Common exam trap

It's easy for candidates to assume a running service equals full functionality, but the exam tests the distinction between the local service state and the cloud connectivity required for the sensor to report as 'active' in the console.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Microsoft Defender for Endpoint sensor is not connected to the cloud service.

The 'inactive' status in Microsoft Defender XDR indicates that the Defender for Endpoint sensor on the device has lost connectivity to the cloud service. Even if the service is running locally, the sensor must maintain an active HTTPS connection (using TLS 1.2 or higher) to the Defender for Endpoint backend to send telemetry and receive policy updates. Without this cloud connectivity, the device cannot report security events, resulting in the 'inactive' state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The device is not compliant with Intune compliance policies.

    Why it's wrong here

    Intune compliance state governs conditional access and reporting, not whether a device's Defender sensor transmits telemetry to Microsoft Defender XDR. An inactive device has simply stopped sending heartbeat data. Compliance policies would be the correct focus when gating resource access on device health rather than onboarding telemetry.

  • ✗

    The device is not enrolled in Microsoft Intune.

    Why it's wrong here

    Microsoft Defender for Endpoint onboarding is independent of Intune enrolment; devices can onboard directly via script or Group Policy. Inactivity reflects missing telemetry, not missing management enrolment. Intune enrolment would be the correct concern when applying configuration profiles or compliance policies to devices.

  • ✗

    The device does not have Microsoft Defender Antivirus enabled.

    Why it's wrong here

    Microsoft Defender XDR onboarding does not require Defender Antivirus to be the active antimalware; third-party antivirus in passive mode still permits sensor telemetry. Inactivity means the sensor is not reporting. Enabling Defender Antivirus would be correct when the requirement is antivirus protection rather than XDR telemetry.

  • ✓

    The Microsoft Defender for Endpoint sensor is not connected to the cloud service.

    Why this is correct

    An inactive status means the onboarded sensor is not maintaining its channel to the Microsoft Defender for Endpoint cloud service, so telemetry never reaches Microsoft Defender XDR. A running service alone is insufficient; the sensor must be connected for events to appear.

Go deeper

Related to this question

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.