Exam objective
MD-102Configure endpoint security
This objective sits in Protect devices, which carries 18% of the MD-102 Endpoint Administrator exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.
Objective title verbatim from the official objectives. Microsoft Azure exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
You plan ASR rules through Intune. Which platform prerequisite is required for an attack surface reduction (ASR) rule to function?
Correct.
Concept
ASR rules are a Defender Antivirus feature. Most rules list Defender Antivirus as a dependency.
Why B
ASR rules are a Microsoft Defender Antivirus feature.
Source
Microsoft, ASR rules reference, checked August 2026ASR rules are a Microsoft Defender Antivirus feature that's available on any edition of Windows that includes Microsoft Defender Antivirus (for example, Windows 11 Home).
Now you: practice questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
Where do you enable the connection so Intune integrates with Microsoft Defender for Endpoint?
Sample question 2 of 3
After the Intune and Defender for Endpoint connection is established, how are Windows devices onboarded?
Sample question 3 of 3
A compliance policy uses 'Require the device to be at or under the machine risk score' with the recommended balanced setting. Which value is recommended?
That’s 3 of the full MD-102 Endpoint Administrator bank.
Keep going free: 10 questions per certification in bank practice, with no account.
Continue practisingRead the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.