Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Exhibit

Refer to the exhibit.

```json
{
  "DeviceConfiguration": {
    "Antivirus": {
      "DisableRealtimeMonitoring": false,
      "PUAProtection": "AuditMode",
      "CloudBlockLevel": "High",
      "CloudTimeout": 50
    }
  }
}
```

An administrator deployed the above Intune device configuration policy for Microsoft Defender for Endpoint on Windows 10 devices. Users report that some potentially unwanted applications (PUA) are still being installed. What is the most likely cause?

⚠ Common exam trap

The trap is that AuditMode sounds like it still takes action (auditing implies monitoring), so candidates assume PUAs are being detected and blocked — but AuditMode is explicitly non-blocking, which is the exact symptom described.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The PUAProtection setting is in AuditMode and not blocking PUAs.

The PUAProtection setting in the Defender for Endpoint Intune policy has three modes: Off, AuditMode, and Enabled (Block). AuditMode only logs detections without blocking, so PUAs continue to install. To actually block PUAs, the setting must be set to 'Enabled' (Block), not AuditMode.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The cloud timeout value is too low, causing PUA detection to fail.

    Why it's wrong here

    Cloud timeout (CloudTimeout) only governs how long the endpoint waits for a verdict from the cloud-delivered protection service when scanning unknown or suspicious files. It does not influence the locally evaluated PUA detection engine, which relies on signature and heuristic classification. Even a very low or high cloud timeout value cannot cause PUA detection to fail, so this is not the reason PUAs are appearing.

  • ✓

    The PUAProtection setting is in AuditMode and not blocking PUAs.

    Why this is correct

    The PUAProtection setting in AuditMode instructs Microsoft Defender Antivirus to detect potentially unwanted applications and record them in the event log without taking any blocking action. Because AuditMode is only logging findings, users can still install and run PUAs, making this setting the direct cause of the observed behavior. To actually block PUAs, PUAProtection must be set to Enable or Block mode.

  • ✗

    Cloud-delivered protection is set to High level, which does not affect PUAs.

    Why it's wrong here

    Cloud-delivered protection level (CloudBlockLevel) determines how aggressively Defender Antivirus queries the Microsoft cloud for verdicts on unknown files, with High meaning the strictest lookup behavior for unclassified samples. It has no influence on the PUA engine, because PUA detection is governed exclusively by the PUAProtection policy setting. Therefore, setting CloudBlockLevel to High does not affect whether PUAs are blocked or audited.

  • ✗

    Real-time monitoring is disabled.

    Why it's wrong here

    Real-time monitoring is enabled in this deployment because DisableRealtimeMonitoring is set to false, so the claim that it is disabled is factually incorrect. Moreover, even if real-time scanning were disabled, that alone would not alter PUAProtection behavior; PUA protection is a separate configuration that either audits or blocks based on its own mode. Thus, the cause lies in AuditMode, not in real-time monitoring.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.