Which Device Query Table Identifies Installed Patches?

Implement Intune Suite add-on capabilities
Answer Correct answer: A — Target the WindowsQfe table in Device query to identify installed critical security patches.

You have a Microsoft 365 subscription that contains Windows 11 devices enrolled in Microsoft Intune. You need to use Device query to identify whether a critical security patch was installed on a device. Which table should you target?

  1. WindowsQfe Correct Answer
  2. WindowsRegistry
  3. FileInfo
  4. OsVersion
  5. SystemInfo

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Device query uses the WindowsQfe table to list installed patches, testing knowledge of Intune Suite table schemas and the legacy QFE terminology.

The WindowsQfe table in Microsoft Intune Device query is used to identify installed security patches and updates. This page establishes that Quick Fix Engineering (QFE) corresponds to critical patches on Windows devices.

Choosing SystemInfo or OsVersion because they sound related to the operating system, but they do not list individual installed patches.

Community Discussion (4 comments)

Moot2 👍 3 Selected: A
A - Correct QFE
DiligentSam 👍 4
it‘s easy to choose,A Widnows Qfe Quick Fix Engineering
AleFCI1908 👍 3 Selected: A
A QFE is often a quick update meant to fix a critical issue without waiting for the release of more comprehensive updates. It is intended for users or organizations that need an immediate solution to a specific problem https://learn.microsoft.com/it-it/windows/win32/cimwin32prov/win32-quickfixengineering
AleFCI1908 👍 3
A QFE is often a quick update meant to fix a critical issue without waiting for the release of more comprehensive updates. It is intended for users or organizations that need an immediate solution to a specific problem https://learn.microsoft.com/it-it/windows/win32/cimwin32prov/win32-quickfixengineering

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The WindowsQfe table in Intune Device query maps directly to the Win32_QuickFixEngineering WMI class, which lists all the installed updates and hotfixes on a Windows device. Therefore, to find if a critical security patch was installed, querying this table is the correct approach.

Why the Other Options Are Wrong

WindowsRegistry queries registry keys, not installed patches directly. FileInfo provides file details, not patch listings. OsVersion and SystemInfo provide operating system details and general system metrics, neither of which enumerate the installed Quick Fix Engineering updates.

Community Comment Notes

Commenters correctly point out that "QFE" stands for "Quick Fix Engineering," which refers to critical updates. As AleFCI1908 noted, "QFE is often a quick update meant to fix a critical issue" and linked to the official Win32_QuickFixEngineering documentation.

Official Reference

Exam Strategy

Remember that Intune Device query tables map closely to familiar WMI classes. Knowing that 'QFE' stands for Quick Fix Engineering (patches/hotfixes) is essential for selecting the correct table.

Related Analysis

Practice All MD-102 Questions

Access 92 questions with complete answers and detailed explanations.

View Full MD-102 Practice Test →

← Back to MD-102 Study Guide