ExamGecko
Home Home / Microsoft / MD-102

Microsoft MD-102 Practice Test - Questions Answers, Page 19

Question list
Search
Search

List of questions

Search

Related questions











You have a Microsoft 365 subscription that includes Microsoft Intune.

You have an update ring named UpdateRingl that contains the following settings:

• Automatic update behavior: Auto install and restart at a scheduled time

• Automatic behavior frequency: First week of the month

• Scheduled install day: Tuesday

• Scheduled install time: 3 AM

From the Microsoft Intone admin center, you select Uninstall for the feature updates of UpdateRing1.

When will devices start to remove the feature updates?

A.

when a user approves the uninstall

A.

when a user approves the uninstall

Answers
B.

as soon as the policy is received

B.

as soon as the policy is received

Answers
C.

next Tuesday

C.

next Tuesday

Answers
D.

the first Tuesday of the next month

D.

the first Tuesday of the next month

Answers
Suggested answer: C

You have a hybrid deployment of Azure AD that contains 50 Windows 10 devices. All the devices are enrolled in Microsoft Intune.

You discover that Group Policy settings override the settings configured in Microsoft Intune policies.

You need to ensure that the settings configured in Microsoft Intune override the Group Policy settings.

What should you do?

A.

From Group Policy Management Editor, configure the Computer Configuration settings in the Default Domain Policy.

A.

From Group Policy Management Editor, configure the Computer Configuration settings in the Default Domain Policy.

Answers
B.

From the Microsoft Intune admin center, create a custom device profile.

B.

From the Microsoft Intune admin center, create a custom device profile.

Answers
C.

From the Microsoft Intune admin center, create an Administrative Templates device profile.

C.

From the Microsoft Intune admin center, create an Administrative Templates device profile.

Answers
D.

From Group Policy Management Editor, configure the User Configuration settings in the Default Domain Policy.

D.

From Group Policy Management Editor, configure the User Configuration settings in the Default Domain Policy.

Answers
Suggested answer: C

HOTSPOT

You have a Microsoft 365 subscription.

You plan to enroll devices in Microsoft Endpoint Manager that have the platforms and versions shown in the following table.

You need to configure device enrollment to meet the following requirements:

Ensure that only devices that have approved platforms and versions can enroll in Endpoint Manager.

Ensure that devices are added to Microsoft Azure Active Directory (Azure AD) groups based on a selection made by users during the enrollment.

Which device enrollment setting should you configure for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 183
Correct answer: Question 183

Explanation:

Reference:

https://docs.microsoft.com/en-us/mem/intune/enrollment/enrollment-restrictions-set

https://docs.microsoft.com/en-us/mem/intune/enrollment/device-group-mapping

HOTSPOT

Your network contains an Active Directory domain. Active Directory is synced with Microsoft Azure Active Directory (Azure AD).

There are 500 Active Directory domain-joined computers that run Windows 10 and are enrolled in Microsoft Intune.

You plan to implement Microsoft Defender Exploit Guard.

You need to create a custom Microsoft Defender Exploit Guard policy, and then distribute the policy to all the computers.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 184
Correct answer: Question 184

Explanation:

Reference:

https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defenderatp/import-export-exploit-protection-emet-xml#manage-or-deploy-a-configuration

https://docs.microsoft.com/en-us/intune/endpoint-protection-windows-10

https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defenderatp/enable-exploit-protection

Your company uses Microsoft Intune.

More than 500 Android and iOS devices are enrolled in the Intune tenant.

You plan to deploy new Intune policies. Different policies will apply depending on the version of Android or iOS installed on the device.

You need to ensure that the policies can target the devices based on their version of Android or iOS.

What should you configure first?

A.

groups that have dynamic membership rules in Azure AD

A.

groups that have dynamic membership rules in Azure AD

Answers
B.

Device categories in Intune

B.

Device categories in Intune

Answers
C.

Corporate device identifiers in Intune

C.

Corporate device identifiers in Intune

Answers
D.

Device settings in Azure AD

D.

Device settings in Azure AD

Answers
Suggested answer: B

DRAG DROP

You have SOO Windows 10 devices enrolled in Microsoft Intune.

You plan to use Exploit protection in Microsoft Intune to enable the following system settings on the devices:

• Data Execution Prevention (DEP)

• Force randomization for images (Mandatory ASlR) You need to configure a Windows 10 device that will be used to create a template file.

Which protection areas on the device should you configure in the Windows Security app before you create the template file? To answer, drag the appropriate protection areas to the correct settings.

Each protection area may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.


Question 186
Correct answer: Question 186

Explanation:

Exploit protection is a feature that helps protect against malware that uses exploits to infect devices and spread. Exploit protection consists of many mitigations that can be applied to either the operating system or individual apps1.

To configure a Windows 10 device that will be used to create a template file for Exploit protection, you need to configure the following protection areas on the device in the Windows Security app:

DEP: Device security. Data Execution Prevention (DEP) is a mitigation that prevents code from running in memory regions marked as non-executable. You can enable DEP system-wide or for specific apps in the Device security section of the Windows Security app1.

Mandatory ASLR: App & browser control. Force randomization for images (Mandatory ASLR) is a mitigation that randomizes the location of executable images in memory, making it harder for attackers to predict where to inject code. You can enable Mandatory ASLR system-wide or for specific apps in the App & browser control section of the Windows Security app1.

You have an Azure AD tenant named contoso.com.

You have a workgroup computer named Computer! that runs Windows 11.

You need to add Computer1 to contoso.com.

What should you use?

A.

dsreecmd.exe

A.

dsreecmd.exe

Answers
B.

Computer Management

B.

Computer Management

Answers
C.

netdom.exe

C.

netdom.exe

Answers
D.

the Settings app

D.

the Settings app

Answers
Suggested answer: A

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to manage Windows 11 devices.

You need to implement passwordless authentication that requires users to use number matching Which authentication method should you use?

A.

Microsoft Authenticator

A.

Microsoft Authenticator

Answers
B.

voice calls

B.

voice calls

Answers
C.

FI002 security keys

C.

FI002 security keys

Answers
D.

text messages

D.

text messages

Answers
Suggested answer: A

You use a Microsoft Intune subscription to manage iOS devices.

You configure a device compliance policy that blocks jailbroken iOS devices.

You need to enable Enhanced jailbreak detection.

What should you configure?

A.

the Compliance policy settings

A.

the Compliance policy settings

Answers
B.

the device compliance policy

B.

the device compliance policy

Answers
C.

a network location

C.

a network location

Answers
D.

a configuration profile

D.

a configuration profile

Answers
Suggested answer: D

DRAG DROP

You have a Microsoft 365 subscription that contains two users named User1 and User2. You need to ensure that the users can perform the following tasks:

• User1 must be able to create groups and manage users.

• User2 must be able to reset passwords for no administrative users.

The solution must use the principle of least privilege.

Which role should you assign to each user? To answer, drag the appropriate roles to the correct users. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.


Question 190
Correct answer: Question 190

Explanation:

Microsoft 365 or Office 365 subscription comes with a set of admin roles that you can assign to users in your organization using the Microsoft 365 admin center. Each admin role maps to common business functions and gives people in your organization permissions to do specific tasks in the admin centers1.

To ensure that User1 can create groups and manage users, you should assign the User Administrator role to User1. This role allows User1 to create and manage all aspects of users and groups, including resetting passwords for non-administrative users1.

To ensure that User2 can reset passwords for non-administrative users, you should assign the Helpdesk Administrator role to User2. This role allows User2 to reset passwords, manage service requests, and monitor service health for non-administrative users1.

Total 301 questions
Go to page: of 31