Courseiva

MD-102 Prepare infrastructure for devices Practice Question

Your organization uses Microsoft Defender for Endpoint. You need to ensure that devices onboarding to Microsoft Defender for Endpoint are automatically assigned to a specific device group based on their operating system version. What should you use?

⚠ Common exam trap

Candidates often confuse Microsoft Entra ID dynamic groups (which are for identity and access management) with Defender for Endpoint device group rules (which are for security operations and automation), leading them to choose Option C incorrectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure device group rules in Microsoft Defender for Endpoint using OS version condition.

Device group rules in Microsoft Defender for Endpoint allow you to automatically assign devices to groups based on conditions such as operating system version. This is the correct approach because it uses the built-in grouping engine that evaluates device attributes during onboarding, ensuring consistent and automated assignment without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Manually tag each device in the Microsoft 365 Defender portal.

    Why it's wrong here

    Manual tagging is a one-off administrative action applied per device, so newly onboarding devices are not assigned automatically. It is tempting because tags do drive device group membership, but the requirement is automatic assignment based on OS version, which manual tagging cannot deliver at scale.

  • ✓

    Configure device group rules in Microsoft Defender for Endpoint using OS version condition.

    Why this is correct

    Device group rules in Microsoft Defender for Endpoint evaluate onboarding devices against conditions such as OS version, automatically placing them into the target group. This satisfies the requirement for automatic assignment based on operating system version, avoiding manual tagging or dynamic group queries in Microsoft Entra ID, which cannot drive Defender device group membership.

  • ✗

    Use Microsoft Entra ID dynamic groups based on device OS.

    Why it's wrong here

    Microsoft Entra ID dynamic groups govern access to Entra resources, not Defender for Endpoint device group membership. It is tempting because dynamic membership rules can filter on device OS, but Defender device groups require their own onboarding-time rules instead.

  • ✗

    Create a Microsoft Intune compliance policy that tags devices by OS version.

    Why it's wrong here

    Intune compliance policies evaluate device settings and report compliance state; they do not tag devices for Defender for Endpoint group membership. Device groups are populated by onboarding-time rules matching OS version, so compliance policy tagging never assigns the group.

Go deeper

Related to this question

About these practice questions

One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.