Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Your organization is deploying Microsoft Intune to manage Windows 11 devices. You need to ensure that devices automatically receive security updates and that users cannot defer updates. Which configuration profile setting should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Windows 10/11 Update Rings policy with a deadline for quality and feature updates.

The correct option is B: a Windows 10/11 Update Rings policy with a deadline for quality and feature updates. Update Rings in Intune are the purpose-built mechanism for controlling Windows Update behavior on managed devices, and configuring a deadline forces installation of quality and feature updates by a set time, preventing users from deferring them indefinitely. Option A is too vague and device configuration profiles do not provide the update-ring deadline enforcement needed here. Option C only evaluates and reports compliance; it does not install updates or block deferrals. Option D concerns Defender Antivirus security settings, not Windows Update ring scheduling or deadlines.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a device configuration profile to enable automatic updates.

    Why it's wrong here

    A device configuration profile in Intune manages settings like device restrictions, Wi-Fi, or compliance, but it does not control the Windows Update for Business logic that governs update deferrals and deadlines. Enabling automatic updates via a profile only toggles a basic setting and lacks the ability to specify grace periods or force installation windows, so it cannot enforce that devices install quality and feature updates by a required time. Update rings are the dedicated policy type for this behavior, distinct from configuration profiles.

  • ✓

    Create a Windows 10/11 Update Rings policy with a deadline for quality and feature updates.

    Why this is correct

    A Windows 10/11 Update Rings policy in Intune is the correct tool because it maps directly to Windows Update for Business settings, allowing you to configure deferral periods for quality and feature updates, set installation deadlines, and define grace periods. Deadlines force the device to install updates after the specified period even if the user has delayed them, ensuring automatic installation. This is the only option that controls the actual update scheduling behavior rather than just checking or reporting on it.

  • ✗

    Create a compliance policy that requires the device to have the latest updates installed.

    Why it's wrong here

    A compliance policy can verify whether a device has certain updates installed and mark it non-compliant if not, but it does not alter the user's ability to defer updates or control the installation timeline. In practice, a user could keep deferring updates indefinitely, making the device non-compliant without triggering forced installation, and the compliance policy offers no deadline or grace period mechanism. Compliance policies are for conditional access and status reporting, not for enforcing update behavior on the device itself.

  • ✗

    Create an endpoint security policy for Windows Defender Antivirus to enforce update installation.

    Why it's wrong here

    Endpoint security policies for Windows Defender Antivirus are designed to configure real-time protection, scheduled scans, and threat remediation actions, none of which influence Windows Update deferral or deadline settings. While Defender Antivirus might deliver definition updates automatically, it does not manage the quality or feature update rings that govern when Windows 10/11 receives broader OS updates. The endpoint security node does not expose the update ring configuration options, so this policy type is not applicable to the requirement.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.