MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Exhibit
Refer to the exhibit.
```json
{
"DeviceConfiguration": {
"Antivirus": {
"DisableRealtimeMonitoring": false,
"PUAProtection": "AuditMode",
"CloudBlockLevel": "High",
"CloudTimeout": 50
}
}
}
```An administrator deployed the above Intune device configuration policy for Microsoft Defender for Endpoint on Windows 10 devices. Users report that some potentially unwanted applications (PUA) are still being installed. What is the most likely cause?
⚠ Common exam trap
The trap is that AuditMode sounds like it still takes action (auditing implies monitoring), so candidates assume PUAs are being detected and blocked — but AuditMode is explicitly non-blocking, which is the exact symptom described.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The PUAProtection setting is in AuditMode and not blocking PUAs.
The PUAProtection setting in the Defender for Endpoint Intune policy has three modes: Off, AuditMode, and Enabled (Block). AuditMode only logs detections without blocking, so PUAs continue to install. To actually block PUAs, the setting must be set to 'Enabled' (Block), not AuditMode.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The cloud timeout value is too low, causing PUA detection to fail.
Why it's wrong here
Cloud timeout (CloudTimeout) only governs how long the endpoint waits for a verdict from the cloud-delivered protection service when scanning unknown or suspicious files. It does not influence the locally evaluated PUA detection engine, which relies on signature and heuristic classification. Even a very low or high cloud timeout value cannot cause PUA detection to fail, so this is not the reason PUAs are appearing.
- ✓
The PUAProtection setting is in AuditMode and not blocking PUAs.
Why this is correct
The PUAProtection setting in AuditMode instructs Microsoft Defender Antivirus to detect potentially unwanted applications and record them in the event log without taking any blocking action. Because AuditMode is only logging findings, users can still install and run PUAs, making this setting the direct cause of the observed behavior. To actually block PUAs, PUAProtection must be set to Enable or Block mode.
- ✗
Cloud-delivered protection is set to High level, which does not affect PUAs.
Why it's wrong here
Cloud-delivered protection level (CloudBlockLevel) determines how aggressively Defender Antivirus queries the Microsoft cloud for verdicts on unknown files, with High meaning the strictest lookup behavior for unclassified samples. It has no influence on the PUA engine, because PUA detection is governed exclusively by the PUAProtection policy setting. Therefore, setting CloudBlockLevel to High does not affect whether PUAs are blocked or audited.
- ✗
Real-time monitoring is disabled.
Why it's wrong here
Real-time monitoring is enabled in this deployment because DisableRealtimeMonitoring is set to false, so the claim that it is disabled is factually incorrect. Moreover, even if real-time scanning were disabled, that alone would not alter PUAProtection behavior; PUA protection is a separate configuration that either audits or blocks based on its own mode. Thus, the cause lies in AuditMode, not in real-time monitoring.
Go deeper
Related to this question
Learn chapter
Intune Device Management
Key term
Device configuration
Device configuration is the process of setting up and customizing the operating system, security policies, applications, and network settings on a device so it can securely connect to and function within an organization's IT environment.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.