ExamGecko
Home Home / Microsoft / MD-102

Microsoft MD-102 Practice Test - Questions Answers, Page 9

Question list
Search
Search

List of questions

Search

Related questions











You have a Microsoft Deployment Toolkit (MDT) deployment share named DS1.

in the Out-of-Box Drivers node, you create folders that contain drivers for different hardware models.

You need to configure the Inject Drivers MDT task to use PnP detection to install the drivers for one of the hardware models.

What should you do first?

A.

Import an OS package.

A.

Import an OS package.

Answers
B.

Create a selection profile.

B.

Create a selection profile.

Answers
C.

Add a Gather task to the task sequence.

C.

Add a Gather task to the task sequence.

Answers
D.

Add a Validate task to the task sequence.

D.

Add a Validate task to the task sequence.

Answers
Suggested answer: B

You have an on-premises server named Server! that hosts a Microsoft Deployment Toolkit (MDT) deployment share named MDT1. You need to ensure that MDT1 supports multicast deployments.

What should you install on Server1?

A.

Multipath I/O (MPIO)

A.

Multipath I/O (MPIO)

Answers
B.

Multipoint Connector

B.

Multipoint Connector

Answers
C.

Windows Deployment Services (WDS)

C.

Windows Deployment Services (WDS)

Answers
D.

Windows Server Update Services (WSUS)

D.

Windows Server Update Services (WSUS)

Answers
Suggested answer: C

Your company standardizes on Windows 10 Enterprise for all users.

Some users purchase their own computer from a retail store. The computers run Windows 10 Pro.

You need to recommend a solution to upgrade the computers to Windows 10 Enterprise, join the computers to Azure AD, and install several Microsoft Store apps. The solution must meet the following requirements:

• Ensure that any applications installed by the users are retained.

• Minimize user intervention.

What is the best recommendation to achieve the goal?

More than one answer choice may achieve the goal.

Select the BEST answer.

A.

Windows Autopilot

A.

Windows Autopilot

Answers
B.

Microsoft Deployment Toolkit (MDT)

B.

Microsoft Deployment Toolkit (MDT)

Answers
C.

a Windows Configuration Designer provisioning package

C.

a Windows Configuration Designer provisioning package

Answers
D.

Windows Deployment Services (WDS)

D.

Windows Deployment Services (WDS)

Answers
Suggested answer: A

Your company has an Azure AD tenant named contoso.com that contains several Windows 10 devices.

When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin.

You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.

Solution: From the Microsoft Entra admin center, you modify the User settings and the Device settings.

Does this meet the goal?

A.

Yes

A.

Yes

Answers
B.

No

B.

No

Answers
Suggested answer: B

Your company has an Azure AD tenant named contoso.com that contains several Windows 10 devices.

When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin.

You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.

Solution: From the Microsoft Entra admin center, you configure automatic mobile device management (MDM) enrollment. From the Microsoft Intune admin center, you create and assign a device restrictions profile.

Does this meet the goal?

A.

Yes

A.

Yes

Answers
B.

No

B.

No

Answers
Suggested answer: B

Your company has an Azure AD tenant named contoso.com that contains several Windows 10 devices.

When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin.

You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.

Solution: From the Microsoft Entra admin center, you configure automatic mobile device management (MDM) enrollment. From the Microsoft Intune admin center, you configure the

Windows Hello for Business enrollment options.

Does this meet the goal?

A.

Yes

A.

Yes

Answers
B.

No

B.

No

Answers
Suggested answer: B

HOTSPOT

You have an Azure AD tenant that contains the users shown in the following table.

You have the devices shown in the following table.

You have a Conditional Access policy named CAPolicy1 that has the following settings:

• Assignments

o Users or workload identities: User 1. User1

o Cloud apps or actions: Office 365 Exchange Online

o Conditions: Device platforms: Windows, iOS

• Access controls

o Grant Require multi-factor authentication

You have a Conditional Access policy named CAPolicy2 that has the following settings:

Assignments

o Users or workload identities: Used, User2

o Cloud apps or actions: Office 365 Exch

o Conditions

Device platforms: Android, iOS

Filter for devices

Device matching the rule: Exclude filtered devices from policy

Rule syntax: device. displayName- contains "1"

Access controls

Grant Block access

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Question 87
Correct answer: Question 87

HOTSPOT

You have a Microsoft 365 subscription that contains the devices shown in the following table.

You plan to enroll the devices in Microsoft Intune.

How often will the compliance policy check-ins run after each device is enrolled in Intune? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question 88
Correct answer: Question 88

Explanation:

Box 1: Every three minutes for 15 minutes, then every 15 minutes for two hours, and then around every eight hours

If devices recently enroll, then the compliance, non-compliance, and configuration check-in runs more frequently. The check-ins are estimated at:

Windows 10: Every 3 minutes for 15 minutes, then every 15 minutes for 2 hours, and then around every 8 hours

Box 2: Every 15 minutes for one hour, and then every eight hours iOS/iPadOS: Every 15 minutes for 1 hour, and then around every 8 hours

Reference: https://docs.microsoft.com/en-us/mem/intune/configuration/device-profiletroubleshoot

You have a Microsoft 365 E5 subscription that contains 500 macOS devices enrolled in Microsoft Intune.

You need to ensure that you can apply Microsoft Defender for Endpoint antivirus policies to the macOS devices. The solution must minimize administrative effort.

What should you do?

A.

From the Microsoft Endpoint Manager admin center, create a configuration profile.

A.

From the Microsoft Endpoint Manager admin center, create a configuration profile.

Answers
B.

From the Microsoft Endpoint Manager admin center, create a security baseline.

B.

From the Microsoft Endpoint Manager admin center, create a security baseline.

Answers
C.

Onboard the macOS devices to the Microsoft 365 compliance center.

C.

Onboard the macOS devices to the Microsoft 365 compliance center.

Answers
D.

Install Defender for Endpoint on the macOS devices.

D.

Install Defender for Endpoint on the macOS devices.

Answers
Suggested answer: D

Explanation:

Just install, and use Defender for Endpoint on Mac.

Reference: https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/microsoftdefender-endpoint-mac

HOTSPOT

You have the on-premises servers shown in the following table.

You have a Microsoft 365 E5 subscription that contains Android and iOS devices. All the devices are managed by using Microsoft Intune.

You need to implement Microsoft Tunnel for Intune. The solution must minimize the number of open firewall ports.

To which server can you deploy a Tunnel Gateway server, and which inbound ports should be allowed on the server to support Microsoft Tunnel connections? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question 90
Correct answer: Question 90

Explanation:

Box 1: Server4

Microsoft Tunnel is a VPN gateway solution for Microsoft Intune that runs in a container on Linux and allows access to on-premises resources from iOS/iPadOS and Android Enterprise devices using modern authentication and Conditional Access.

Box 2: TCP 443 and UDP 443 only

Some traffic goes to your public facing IP address for the Tunnel. The VPN channel will use TCP, TLS, UDP, and DTLS over port 443.

By default, port 443 is used for both TCP and UDP, but this can be customized via the Intune Saerver Configuration – Server port setting. If changing the default port (443) ensure your inbound firewall rules are adjusted to the custom port.

Incorrect:

TCP 1723 is not used.

Reference: https://docs.microsoft.com/en-us/mem/intune/protect/microsoft-tunnel-overview

Total 301 questions
Go to page: of 31