MD-102 Prepare infrastructure for devices Practice Question
Your organization uses Microsoft Intune to manage devices. You need to configure a compliance policy for Windows devices that requires the device to be at a specific OS version and have antivirus enabled. Which TWO settings should you configure in the compliance policy?
⚠ Common exam trap
MD-102 often tests the distinction between compliance settings that validate device state (minimum OS, antivirus, encryption) versus configuration settings that change device state, causing candidates to pick Maximum OS version or Device type by mistake.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require antivirus (Windows Defender)
A Windows compliance policy enforces a required OS build/version by setting the minimum OS version, which blocks devices running older builds than the specified value. Option B (Require antivirus (Windows Defender)) is correct because the compliance policy includes a setting that requires Windows Defender Antivirus to be enabled (and optionally up to date) on the device. Option A (Maximum OS version) is not appropriate here because the requirement is to ensure devices are at least a specific OS version, not to cap them at a maximum version. Option D (Device type) is not a compliance setting for enforcing OS version or antivirus state; it is used for targeting/platform scoping. Option E (Storage encryption) enforces BitLocker/device encryption and does not address the OS version or antivirus requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Maximum OS version
Why it's wrong here
Maximum OS version blocks devices running newer builds than permitted, whereas the requirement is a specific minimum version. It tempts because it is a genuine OS-version compliance setting, and it would be correct when capping upgrades to a validated build, but here the minimum OS version setting is needed.
- ✓
Require antivirus (Windows Defender)
Why this is correct
Requiring antivirus in the Windows compliance policy directly satisfies the stem's second condition: devices must have antivirus enabled. Intune evaluates Windows Defender's real-time protection status through this setting, marking non-compliant devices that lack active antivirus. Combined with the minimum OS version setting, both stated requirements are enforced.
- ✓
Minimum OS version
Why this is correct
Minimum OS version directly enforces the required Windows build by comparing the device's reported OS version against a defined threshold, marking non-compliant devices that fall below it. This satisfies the stem's specific OS version constraint, while antivirus enabled is handled separately by the Defender antivirus requirement setting.
- ✗
Device type
Why it's wrong here
Device type scopes which platforms the compliance policy targets; it cannot enforce an OS version or antivirus state. It tempts because selecting Windows is genuinely required when building the policy, but the stem already assumes Windows devices, so the two required settings are OS version and antivirus.
- ✗
Storage encryption
Why it's wrong here
Storage encryption verifies BitLocker status, an unrelated control that does not check OS version or antivirus. It tempts because encryption is a common Windows compliance setting and would be correct if the requirement were data-at-rest protection, but this scenario demands OS version and antivirus settings instead.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Compliance policy
A compliance policy is a set of rules that ensures devices, users, and applications meet an organization's security and regulatory requirements before they can access corporate resources.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.