exam questions

Exam MD-102 All Questions

View all questions & answers for the MD-102 exam

Exam MD-102 topic 1 question 267 discussion

Actual exam question from Microsoft's MD-102
Question #: 267
Topic #: 1
[All MD-102 Questions]

You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Microsoft Entra joined and are enrolled in Microsoft Intune.

You plan to manage Microsoft Defender for Endpoint on the computers.

You need to prevent users from disabling Microsoft Defender for Endpoint.

What should you do?

  • A. From the Microsoft Intune admin center, create a security baseline.
  • B. From the Microsoft Intune admin center, create an antivirus policy.
  • C. From the Microsoft Entra admin center, create a Conditional Access policy.
  • D. From the Microsoft Intune admin center, create a device compliance policy.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AleFCI1908
Highly Voted 7 months ago
Selected Answer: B
In similar previous questions, the keyword was 'tamper.' Now I've learned the steps necessary to apply tamper protection... thanks to the exam topics.
upvoted 7 times
5e80f0c
5 months, 1 week ago
Indeed, I never even knew something like that existed until I read about it here. After looking for it in Intune, I discovered that "Tamper Protection" was found in 2 separate places: 1) Endpoint Security --> Antivirus Policy and option 2) Devices --> Configuration Profile --> Endpoint Protection --> Microsoft Defender Security Center.
upvoted 2 times
...
AleFCI1908
7 months ago
and thanks to you all, guys ;)
upvoted 3 times
...
...
Krayzr
Highly Voted 1 year, 3 months ago
Selected Answer: B
The correct answer is B. From the Microsoft Intune admin center, create an antivirus policy. Here’s the reasoning: Microsoft Defender for Endpoint is an antivirus solution, and its settings can be managed through an antivirus policy in Microsoft Intune. This includes settings that prevent users from disabling the antivirus. Therefore, creating an antivirus policy in the Microsoft Intune admin center would be the appropriate action to take. Option A, creating a security baseline, is not the best choice because security baselines are predefined sets of recommended security settings that might not cover the specific requirement of preventing users from disabling Microsoft Defender for Endpoint. Option C, creating a Conditional Access policy in the Microsoft Entra admin center, is not applicable because Conditional Access policies are used to enforce access controls based on conditions, not to manage antivirus settings. Option D, creating a device compliance policy, is also not the best choice because device compliance policies are used to determine whether a device is compliant with the organization’s rules, not to manage antivirus settings.
upvoted 5 times
...
Meek_Learner
Most Recent 4 months, 2 weeks ago
To prevent users from disabling Microsoft Defender for Endpoint on Windows 11 computers managed through Microsoft Intune, you should create an antivirus policy from the Microsoft Intune admin center. Antivirus policies in Intune allow administrators to enforce Microsoft Defender security settings, ensuring that users cannot disable key protection features. The antivirus policy will include settings to: Enable Tamper Protection, preventing users from modifying security settings. Ensure real-time protection remains enabled. Configure attack surface reduction rules to enhance endpoint security. By using an antivirus policy, you can enforce and maintain Microsoft Defender for Endpoint configurations effectively across your organization's devices.
upvoted 1 times
...
bigreg
8 months, 3 weeks ago
Selected Answer: B
I checked it
upvoted 1 times
...
3661de6
1 year, 1 month ago
Selected Answer: B
B is correct
upvoted 1 times
...
kerimnl
1 year, 2 months ago
Selected Answer: B
B is correct answer
upvoted 1 times
...
Darkfire
1 year, 2 months ago
Selected Answer: B
B should be correct based on: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-tamper-protection-intune?view=o365-worldwide#:~:text=In%20the%20Intune%20admin%20center%2C%20go,Deploy%20the%20policy%20to%20devices.
upvoted 2 times
...
CaTa_LySt
1 year, 3 months ago
To prevent users from disabling Microsoft Defender for Endpoint on the Windows 11 computers enrolled in Microsoft Intune, you should: A. From the Microsoft Intune admin center, create a security baseline. Security baselines in Microsoft Intune provide a set of pre-configured Windows settings and recommended configurations to help secure your devices. By creating a security baseline, you can enforce specific security settings, including those related to Microsoft Defender for Endpoint. This ensures that the recommended security configurations are applied to the Windows 11 computers, and users are prevented from disabling Microsoft Defender for Endpoint. Option B (creating an antivirus policy) might be related to specific settings for Microsoft Defender Antivirus, but using a security baseline is a more comprehensive approach. Options C (Conditional Access policy) and D (device compliance policy) are typically used for access control and compliance checks but may not specifically address the prevention of users disabling Microsoft Defender for Endpoint.
upvoted 1 times
...
kiro_e
1 year, 3 months ago
Could be B, isn't it?
upvoted 3 times
Savior99
1 year, 3 months ago
I would create an Attack surface reduction policy, so i would say B, even if the wording doesn't seem correct
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...