Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Intune and Microsoft Defender for Endpoint. You need to design a solution that automatically remediates non-compliant devices by running a remediation script. Which Intune component should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remediation policy in Microsoft Intune

The correct option is A, a Remediation policy in Microsoft Intune, because this feature is specifically designed to detect and automatically fix non-compliant devices by running remediation scripts (PowerShell) on them, either on a schedule or when a compliance issue is detected. It pairs with compliance policies to evaluate device state and then executes the script to bring the device back into compliance. Device compliance policies (B) only define and evaluate compliance rules and mark devices compliant or non-compliant; they do not run scripts to remediate. App protection policies (C) protect app data on mobile devices and do not remediate device compliance. Device configuration profiles (D) push settings to devices but do not provide detection-and-remediation script logic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Remediation policy in Microsoft Intune

    Why this is correct

    Remediation policy in Microsoft Intune is a Proactive Remediation feature that pairs detection and remediation PowerShell scripts and runs them on managed Windows devices on a set schedule. When the detection script finds a rule violation, the remediation script automatically executes to restore the device to a compliant state. It reports execution results back to Intune, allowing administrators to verify fixes without manual intervention. This is the only option here that actively performs corrective actions rather than just evaluating or defining state.

  • ✗

    Device compliance policy

    Why it's wrong here

    A device compliance policy defines the evaluation rules—such as required OS minimum versions, BitLocker status, or allowed threat levels—that a device must satisfy to be marked compliant. It generates compliance status and can integrate with Conditional Access to block access, but it does not contain or execute any remediation logic or scripts. When a device falls out of compliance, the policy merely reports the noncompliant state; it cannot run the fix. Thus it checks and gates, but never changes the device.

  • ✗

    App protection policy

    Why it's wrong here

    An app protection policy (APP) applies to line-of-business and Office mobile apps, enforcing data-level controls such as PIN access, copy-paste restrictions, and preventing data save to unmanaged locations. These policies target the application layer and are typically used for BYOD or on unenrolled devices, not for OS or device configuration. Because APP operates inside each app's sandbox, it cannot run PowerShell scripts or modify system settings to correct device-level noncompliance. It protects organizational data, but is unrelated to remediating device configuration drift.

  • ✗

    Device configuration profile

    Why it's wrong here

    A device configuration profile delivers standard configuration service provider (CSP) policies—like password complexity, certificate profiles, VPN settings, or endpoint protections—to devices at enrollment or when synced via MDM. Profiles are declarative: they set a desired state once, but they do not monitor for post-deployment drift and do not run scripts to fix issues. If an end user changes a setting after the profile applies, the profile does not automatically detect or correct it unless another profile update is triggered. So it enforces initial settings, not ongoing proactive remediation.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Intune and Microsoft Defender for Endpoint. You need to design a solution that ensures all Windows 10 devices are running the latest security updates and have real-time protection enabled. If a device is non-compliant, it should be blocked from accessing corporate resources. You have already created a Conditional Access policy that requires compliant devices. You need to configure the compliance requirements and automatic remediation. What should you do?

medium
  • A.Create an Intune device configuration profile that enforces the minimum OS version and enables real-time protection.
  • B.Create an Intune app protection policy that requires the device to have the latest updates and real-time protection.
  • ✓ C.Create an Intune device compliance policy that requires minimum OS version and real-time protection, and create a remediation policy that automatically enables real-time protection if disabled.
  • D.Create an Intune device compliance policy that requires minimum OS version and real-time protection, and use the Conditional Access policy to block non-compliant devices.

Why C: Option C is correct because an Intune device compliance policy is the mechanism that defines the compliance rules (minimum OS version and real-time protection) that Conditional Access evaluates, and a remediation policy (endpoint security/Defender remediation) can automatically turn real-time protection back on for non-compliant devices. This directly satisfies the requirement to configure compliance requirements plus automatic remediation. Option A is wrong because a device configuration profile enforces settings but does not define compliance state for Conditional Access. Option B is wrong because app protection policies protect app data on mobile apps and do not assess OS update level or device real-time protection. Option D is wrong because the Conditional Access policy only blocks access; it does not provide automatic remediation of disabled real-time protection.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.