ExamGecko
Home Home / Microsoft / MD-102

Microsoft MD-102 Practice Test - Questions Answers, Page 28

Question list
Search
Search

List of questions

Search

Related questions











You have a Windows 10 device named Computer1 enrolled in Microsoft Intune.

You need to configure Computer1 as a public workstation that will run a single customer-facing, full-screen application.

Which configuration profile type template should you use in Microsoft Intune admin center?

A.

Shared multi-user device

A.

Shared multi-user device

Answers
B.

Device restrictions

B.

Device restrictions

Answers
C.

Kiosk

C.

Kiosk

Answers
D.

Endpoint protection

D.

Endpoint protection

Answers
Suggested answer: C

You plan to deploy Windows 11 Pro to 200 new computers by using the Microsoft Deployment Toolkit (MDT) and Windows Deployment Services (WDS).

The company has a Volume Licensing Agreement and uses a product key to activate Windows 11.

You need to ensure that the new computers will be configured to have the correct product key during the installation.

What should you configure?

A.

an MDT task sequence

A.

an MDT task sequence

Answers
B.

the Device settings in Azure AD

B.

the Device settings in Azure AD

Answers
C.

a WDS boot image

C.

a WDS boot image

Answers
D.

a Windows Autopilot deployment profile

D.

a Windows Autopilot deployment profile

Answers
Suggested answer: A

Explanation:

https://learn.microsoft.com/en-us/answers/questions/856939/how-to-place-windows-product-key-in-the-rules-on-t#:~:text=You%20may%20set%20the%20Product%20Key%20per%20Task%20Sequence%20in%20customsettings.ini



You need to implement mobile device management (MDM) for personal devices that run Windows 11. The solution must meet the following requirements:

* Ensure that you can manage the personal devices by using Microsoft Intune.

* Ensure that users can access company data seamlessly from their personal devices.

* Ensure that users can only sign in to their personal devices by using their personal account.

What should you use to add the devices to Azure AD?

A.

Azure AD registered Most Voted

A.

Azure AD registered Most Voted

Answers
B.

hybrid Azure AD join

B.

hybrid Azure AD join

Answers
C.

Azure AD joined

C.

Azure AD joined

Answers
Suggested answer: A

Explanation:

zure AD registered devices meet all your requirements:

Microsoft Intune management: Azure AD registered devices can be managed by Microsoft Intune, allowing you to configure policies, apply security settings, and distribute apps.

Seamless data access: Users can access company data through approved mobile apps using their personal accounts. Conditional Access policies can ensure secure access while respecting their personal device ownership.

Personal account sign-in: Users can only sign in to their devices using their personal accounts, as Azure AD registered devices don't join the domain and don't require work or school credentials.

Azure AD joined and hybrid Azure AD join wouldn't be suitable choices in this case:

Azure AD joined devices are domain-joined, requiring users to sign in with work or school credentials, violating your requirement for personal accounts.

Hybrid Azure AD join combines on-premises Active Directory with Azure AD, adding complexity and not aligning with your need for purely personal device management.

DRAG DROP

You have a Microsoft 365 subscription that contains devices enrolled in Microsoft Intune.

You need to create Endpoint security policies to enforce the following requirements:

* Computers that run macOS must have FileVault enabled.

* Computers that run Windows 10 must have Microsoft Defender Credential Guard enabled.

* Computers that run Windows 10 must have Microsoft Defender Application Control enabled.

Which Endpoint security feature should you use for each requirement? To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.


Question 274
Correct answer: Question 274

You have a Microsoft 365 tenant that contains the devices shown in the following table.

The devices are managed by using Microsoft Intune.

You create a compliance policy named Policy1 and assign Policy1 to Group1. Policy1 is configured to mark a device as Compliant only if the device security settings match the settings specified in the policy.

You discover that devices that are not members of Group1 are shown as Compliant.

You need to ensure that only devices that are assigned a compliance policy can be shown as Compliant. All other devices must be shown as Not compliant.

What should you do from the Microsoft Intune admin center?

A.

From Device compliance, configure the Compliance policy settings.

A.

From Device compliance, configure the Compliance policy settings.

Answers
B.

From Endpoint security, configure the Conditional access settings.

B.

From Endpoint security, configure the Conditional access settings.

Answers
C.

From Tenant administration, modify the Diagnostic settings.

C.

From Tenant administration, modify the Diagnostic settings.

Answers
D.

From Policy1, modify the actions for noncompliance.

D.

From Policy1, modify the actions for noncompliance.

Answers
Suggested answer: A

Explanation:

https://learn.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started#:~:text=Device%20compliance%20%3E%20Compliance%20policy%20settings

You have a Microsoft 365 subscription that includes Microsoft Intune.

You plan to use Windows Autopilot to deploy Windows 11 devices.

You need to meet the following requirements during Autopilot provisioning:

* Display the app and profile configuration progress.

* Block users from using the devices until all apps and profiles are installed

What should you configure?

A.

an app configuration policy

A.

an app configuration policy

Answers
B.

an app protection policy

B.

an app protection policy

Answers
C.

an enrollment device platform restriction

C.

an enrollment device platform restriction

Answers
D.

an enrollment status page

D.

an enrollment status page

Answers
Suggested answer: D

Explanation:

https://learn.microsoft.com/en-us/mem/intune/enrollment/windows-enrollment-status

HOTSPOT

Your network contains an Active Directory domain.

The domain contains four computer named Computer 1. Computet2. Computed, and Computer4 that run Windows 10. Vou perform the following actions:

* On Computer1, you install Windows Admin Center and configure Windows Defender Firewall to allow incoming communication over TCP pons 80.443. and 6516.

* On Computed, you run the Enable-PS Remoting cmdlet.

* On Computer 3, you configure Windows Defender firewall to allow Windows Remote Management (WinRM) traffic

* On Computer4, you run the winrm quickconfig command.

You need to manage the computers remotely by using Windows Admin Center.

From which computers can you connect to Windows Admin Center, and which computers can you manage by using Windows Admin Center? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 277
Correct answer: Question 277

You have the Windows 10 devices shown in the following table.

You plan to upgrade the devices to Windows 11 Enterprise.

On which devices can you perform a direct in-place upgrade to Windows 11 Enterprise?

A.

Device3 only

A.

Device3 only

Answers
B.

Device 3 and Device 4 only

B.

Device 3 and Device 4 only

Answers
C.

Device2. Device3. and Devtce4 only

C.

Device2. Device3. and Devtce4 only

Answers
D.

Device1. Device3, and Devtce4 only

D.

Device1. Device3, and Devtce4 only

Answers
E.

Device1, Device2. Device3. and Devke4 only

E.

Device1, Device2. Device3. and Devke4 only

Answers
Suggested answer: B

Explanation:

https://learn.microsoft.com/en-us/windows/deployment/upgrade/windows-upgrade-paths https://learn.microsoft.com/en-us/windows/deployment/upgrade/windows-edition-upgrades

You have a Microsoft Deployment Toolkit (MDT) deployment shore.

You plan to deploy Windows 11 by using the Standard Client Task Sequence template.

You need to modify the task sequence to perform the following actions:

* Format disks to support Unified Extensible Firmware Interface (UEFl).

* Create a recovery partition.

Which phase of the Task sequence should you modify?

A.

Preinstall

A.

Preinstall

Answers
B.

Install

B.

Install

Answers
C.

Initialization

C.

Initialization

Answers
D.

Post Install

D.

Post Install

Answers
Suggested answer: A

You have a Microsoft 365 subscription that includes Microsoft Intune.

You have 500 corporate-owned Android devices enrolled as fully managed devices.

You need to prepare an app named App1 for deployment to the devices.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point,

A.

From the Intune Company Portal, download Appl.

A.

From the Intune Company Portal, download Appl.

Answers
B.

Create an OEMConfig profile.

B.

Create an OEMConfig profile.

Answers
C.

From the Managed Google Play Store, approve App1.

C.

From the Managed Google Play Store, approve App1.

Answers
D.

Sync App1 with Intune.

D.

Sync App1 with Intune.

Answers
Suggested answer: C, D

Explanation:

https://learn.microsoft.com/en-us/mem/intune/apps/apps-add-android-for-work

Total 301 questions
Go to page: of 31