Microsoft MD-102 Practice Test - Questions Answers, Page 30
List of questions
Related questions
You have a Microsoft 365 E5 subscription.
You use Microsoft Intune to manage all Windows 11 devices.
You create an attack surface reduction (ASR) policy named Profile1 based on the Attack Surface Reduction Rules profile and assign Profile! to all the devices.
A user reports that an Adobe Reader plug-in is now blocked.
You need to ensure that the plug-in is unblocked.
What should you do?
Create an Endpoint Privilege Management policy and assign the policy to all the devices.
Add a scope tag to Profile1.
Configure ASR Only Per Rule Exclusions in Profile1.
Create a device compliance policy and assign the policy to all the devices.
HOTSPOT
You have a Microsoft 365 tenant that uses Microsoft Intune to manage the devices shown in the following table.
You need to deploy a compliance solution that meets the following requirements:
* Marks the devices as Not Compliant if they do not meet compliance policies
* Remotely locks noncompliant devices
What is the minimum number of compliance policies required, and which devices support the remote lock action? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
HOTSPOT
You have a Microsoft 365 E5 subscription. All devices are enrolled in Microsoft Intune.
You have a device group named Group1 that contains five Windows 11 devices.
You need to ensure that the devices in Group1 automatically receive new Windows 11 builds before the builds are released to the public.
What should you configure in Intune? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
HOTSPOT
You have a Microsoft Entra tenant that contains the following:
* Windows 11 devices that are joined to Microsoft Entra
* A user that has a display name of User1 and a UPN of [email protected]
You enable Remote Desktop on the Windows 11 devices.
You need to ensure that User1 can use Remote Desktop to connect to the devices.
How should you complete the command that must be run on each device? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
You have a Microsoft 365 E5 subscription.
All devices are enrolled in Microsoft Intune.
You need to ensure that devices that have NOT checked in for 30 days are deleted from intune.
What should you configure from the Microsoft Intune admin center?
a device limit restriction
automatic enrollment
a device clean-up rule
a configuration profile
You have a Microsoft 365 E5 subscription. All devices are enrolled in Microsoft Intune.
You create a Conditional Access policy named Policy! that requires multifactor authentication (MFA).
You need to ensure that Policy1 only applies to devices marked as noncompliant. Which settings of Policy1 should you configure?
Device platforms under Conditions
Filter for devices under Conditions
Target resources
Grant
Session
HOTSPOT
Your on-premises network contains an Active Directory domain named contoso.com. The domain contains a user account named Admin1 and the resources shown in the following table.
You have a Microsoft 365 E5 subscription.
You have a Microsoft Entra tenant that syncs with contoso.com.
Admin! plans to use Windows Autopilot to deploy 10X3 Windows 11 devices. The deployment must meet the following requirements:
* The devices must be Microsoft Entra hybrid joined during the deployment.
* Computer objects must be created in 0U1.
You need to configure Server1 and Active Directory delegation to support the deployment.
How should you configure Server1, and on which resource should you configure delegated permissions? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
You have 200 computers that run Windows 10. The computers are joined to Microsoft Entra and enrolled in Microsoft Intune. You need to enable self-service password reset on the sign-in screen. Which settings should you configure from the Microsoft Intune admin center?
Conditional access
Device compliance
Device configuration
Device enrollment
HOTSPOT
You have a Microsoft 365 E5 subscription and use Microsoft Intune. The subscription contains a Microsoft Entra tenant that syncs with an on-premises Active Directory Domain Services (AD DS) domain. The tenant has Windows Local Administrator Password Solution (Windows LAPS) enabled.
You have the Windows devices shown in the following table.
You have an Endpoint security policy that is configured as shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
HOTSPOT
You have a Microsoft 365 E5 subscription and use Microsoft Intune.
You purchase 50 Windows devices.
You configure automatic enrollment to Intune for Microsoft Entra joined devices.
You need to use a provisioning package to join the devices to Microsoft Entra.
What should you use to create the provisioning package, and what is the maximum amount of time you can use the package for bulk enrollment? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Question