Pre-Winter Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

MD-102 Questions and Answers

Question # 6

You have a Microsoft 365 subscription that contains 1,000 Windows 11 Enterprise devices and a user named User1. The devices are Microsoft Entra joined and enrolled in Microsoft Intune.

Internet access from the devices is routed through a proxy that blocks outbound traffic, unless a URL pattern is allowed explicitly.

You need to prepare the environment for Endpoint analytics. The solution must meet the following requirements:

• Ensure that the devices can upload data required for Endpoint analytics.

• Ensure that User1 can view Endpoint analytics scores and performance reports.

• Follow the principle of least privilege

What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Question # 6

Full Access
Question # 7

You have a Microsoft 365 E5 subscription. You are implementing Microsoft Defender for Cloud Apps. You need to ensure that you can create OAuth app policies.

Solution: You add an API token to Defender for Cloud Apps. Does this meet the goal?

A.

Yes

B.

No

Full Access
Question # 8

You have a Microsoft 365 subscription that uses Microsoft Intune.

You have five new Windows 11 Pro devices.

You need to prepare the devices for corporate use. The solution must meet the following requirements:

• Install Windows 11 Enterprise on each device.

• Install a Windows Installer (MSI) package named App1 on each device.

• Add a certificate named Certificate1 that is required by App1.

• Join each device to Azure AD.

Which three provisioning options can you use? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

A.

subscription activation

B.

a custom Windows image

C.

an in-place upgrade

D.

Windows Autopilot

E.

provisioning packages

Full Access
Question # 9

You have a Microsoft 365 E5 subscription.

You create an app protection policy for Android device named Policy1 as shown in the following exhibit.

Question # 9

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Question # 9

Full Access
Question # 10

You have a Microsoft Deployment Toolkit (MDT) server named MDT1.

When computers start from the LiteTouchPE_x64.lso image and connect to MDT1. the welcome screen appears as shown In the following exhibit.

Question # 10

You need to prevent the welcome screen from appearing when the computers connect to MDT1.

Which three actions should you perform in sequence? To answer move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Question # 10

Full Access
Question # 11

You create a device configuration profile named Profile1.

You need to ensure that Filter1 is applied to Profile1. The solution must minimize administrative effort.

What should you do first in the Assignments settings of Profile17?

A.

From Included groups, select Add all users

B.

From Excluded groups, select Add groups

C.

From Included groups, select Add all devices

D.

From Included groups, select Add groups

Full Access
Question # 12

You need to capture the required information for the sales department computers to meet the technical

requirements.

Which Windows PowerShell command should you run first?

A.

Install-Module WindowsAutoPilotIntune

B.

Install-Script Get-WindowsAutoPilotInfo

C.

Import-AutoPilotCSV

D.

Get-WindowsAutoPilotInfo

Full Access
Question # 13

You have a Microsoft 365 E5 subscription that includes Microsoft Intune.

You need to configure a compliance policy for the iOS/iPadOS platform. The solution must meet the following requirements:

• Require jailbroken devices to be marked as noncompliant.

• Mark devices without a password lock as noncompliant.

Which compliance policy settings should you configure for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 13

Full Access
Question # 14

Your company has devices enrolled in Microsoft Intune as shown in the following table.

Question # 14

In Microsoft Endpoint Manager, you define the company ' s network as a location named Location1.

Which devices can use network location-based compliance policies?

A.

Device2 and Device3 only

B.

Device2 only

C.

Device1 and Device2 only

D.

Device1 only

E.

Device1, Device2, and Device3

Full Access
Question # 15

You have 200 computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune. You need to set a custom image as the wallpaper and sign-in screen.

Which two settings should you configure in the Device restrictions configuration profile? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Question # 15

Full Access
Question # 16

You have a Microsoft 365 subscription.

All users have Microsoft 365 apps deployed.

You need to configure Microsoft 365 apps to meet the following requirements:

• Enable the automatic installation of WebView2 Runtime.

• Prevent users from submitting feedback.

Which two settings should you configure in the Microsoft 365 Apps admin center? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Question # 16

Full Access
Question # 17

You have a Microsoft 365 subscription that uses Microsoft Intune. The subscription contains 1,000 Windows 11 Enterprise devices that are Microsoft Entra joined.

The subscription has a Conditional Access policy that requires the devices be marked as compliant before users can access Microsoft 365 apps.

You have a custom line-of-business (LOB) app named App1 deployed to the devices. The installed version of App1 is unavailable in the built-in compliance policies and settings for Windows devices.

You need to extend compliance evaluation to ensure that Intune marks the devices as compliant based on the detected App1 version.

What should you do in the compliance policy?

A.

Create a PowerShell remediation and add a detection rule that evaluates the App1 version.

B.

Create an endpoint security policy and add a reusable settings group for the App1 version.

C.

Create a PowerShell discovery script and add a JSON file that defines the compliant App1 version.

D.

Create a device configuration profile for Windows and add a custom OMA-URI for the App1 version.

Full Access
Question # 18

You ate implementing Microsoft Intune Suite.

You enroll devices in Intune as shown in the following table.

Question # 18

The performance of which devices can be analyzed by using Endpoint analytics?

A.

Device1 only

B.

Device1 and Device2 only

C.

Device1. Device2. and Device} only

D.

Device1. Device2, and Device4 only

E.

Device1. Device2. Device3. and Device4

Full Access
Question # 19

You have a Microsoft 365 E5 subscription that uses Microsoft Intune.

You need to ensure that users can only enroll devices that meet the following requirements:

• Android devices that support the use of work profiles.

• iOS devices that run iOS 16.0 or later.

Which two restrictions should you modify? To answer, select the restrictions in the answer area.

NOTE: Each correct selection is worth one point.

Question # 19

Full Access
Question # 20

You need to implement mobile device management (MDM) for personal devices that run Windows 11. The solution must meet the following requirements:

• Ensure that you can manage the personal devices by using Microsoft Intune.

• Ensure that users can access company data seamlessly from their personal devices.

• Ensure that users can only sign in to their personal devices by using their personal account

What should you use to add the devices to Azure AD?

A.

hybrid Microsoft Entra join

B.

Microsoft Entra joined

C.

Microsoft Entra registered

Full Access
Question # 21

You have a Microsoft Entra tenant that contains the groups shown in the following table.

Question # 21

Microsoft Intune is configured with the enrollment restrictions shown in the following table.

Question # 21

You purchase the devices shown in the following table.

Question # 21

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 21

Full Access
Question # 22

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant.

You have a Microsoft 365 subscription

You plan to use Windows Autopilot to deploy new Windows devices.

You plan to create a deployment profile.

You need to ensure that The deployment meets the following requirements:

• Devices must be joined to AD DS regardless of their current working location.

• Users in the marketing department must have a Iine-of-business (LOB) app installed during the deployment.

The solution must minimize administrative effort.

What should you do for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 22

Full Access
Question # 23

You have a Microsoft 365 E5 subscription that contains 100 iOS devices enrolled in Microsoft Intune.

You need to deploy a custom line-of-business (LOB) app to the devices by using Intune.

Which extension should you select for the app package file?

A.

.intunemac

B.

apk

C.

jpa

D.

.appx

Full Access
Question # 24

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Entra tenant named contoso.com.

You purchase an Android device named Device1.

You need to register Device1 in contoso.com.

Solution; You use the Microsoft Intune Company Portal app.

Does this meet the goal?

A.

Yes

B.

No

Full Access
Question # 25

You have a Windows 10 device named Device! that is joined to Active Directory and enrolled in Microsoft Intune.

Device1 is managed by using Group Policy and Intune.

You need to ensure that the Intune settings override the Group Policy settings.

What should you configure?

A.

a device configuration profile

B.

a device compliance policy

C.

an MDM Security Baseline profile

D.

a Group Policy Object (GPO)

Full Access
Question # 26

Your on-premises network contains an Active Directory domain named contoso.com. The domain contains a user account named Admin1 and the resources shown in the following table.

Question # 26

You have a Microsoft 365 E5 subscription.

You have a Microsoft Entra tenant that syncs with contoso.com.

Admin! plans to use Windows Autopilot to deploy 10X3 Windows 11 devices. The deployment must meet the following requirements:

• The devices must be Microsoft Entra hybrid joined during the deployment.

• Computer objects must be created in 0U1.

You need to configure Server1 and Active Directory delegation to support the deployment.

How should you configure Server1, and on which resource should you configure delegated permissions? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 26

Full Access
Question # 27

You need to recommend a solution to meet the device management requirements.

What should you include in the recommendation? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 27

Full Access
Question # 28

You need to meet the technical requirements for the iOS devices.

Which object should you create in Intune?

A.

A compliance policy

B.

An app protection policy

C.

A Deployment profile

D.

A device configuration profile

Full Access
Question # 29

To which devices do Policy1 and Policy2 apply? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 29

Full Access
Question # 30

You are evaluating which devices are compliant.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 30

Full Access
Question # 31

What should you use to meet the technical requirements for Azure DevOps?

A.

An app protection policy

B.

Windows Information Protection (WIP)

C.

Conditional access

D.

A device configuration profile

Full Access
Question # 32

What should you configure to meet the technical requirements for the Azure AD-joined computers?

A.

Windows Hello for Business from the Microsoft Intune blade in the Azure portal.

B.

The Accounts options in an endpoint protection profile.

C.

The Password Policy settings in a Group Policy object (GPO).

D.

A password policy from the Microsoft Office 365 portal.

Full Access
Question # 33

You need to prepare for the deployment of the Phoenix office computers.

What should you do first?

A.

Generalize the computers and configure the Mobility (MDM and MAM) settings from the Azure Active Directory admin center.

B.

Extract the hardware ID information of each computer to a CSV file and upload the file from the Microsoft Intune blade in the Azure portal.

C.

Extract the hardware ID information of each computer to an XML file and upload the file from the Devices settings in Microsoft Store for Business.

D.

Extract the serial number information of each computer to a CSV file and upload the file from the Microsoft Intune blade in the Azure portal.

Full Access
Question # 34

You have a Microsoft Deployment Toolkit (MDT) deployment share named Share 1. You add Windows 10 images to Share! as shown in the following table.

Question # 34

Which images can be used in the Standard Client Task Sequence, and which images can be used in the Standard Client Upgrade Task Sequence?

NOTE: Each correct selection is worth one point.

Question # 34

Full Access
Question # 35

You have an on-premises Active Directory domain that syncs to Azure AD tenant.

The tenant contains computers that run Windows 10. The computers are hybrid Azure AD joined and enrolled in Microsoft Intune. The Microsoft Office settings on the computers are configured by using an Group Policy Object (GPO).

You need to migrate the GPO to Intune.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Question # 35

Full Access
Question # 36

You need to meet the technical requirements for the new HR department computers.

How should you configure the provisioning package? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 36

Full Access
Question # 37

You need to meet the requirements for the MKG department users.

What should you do?

A.

Assign the MKG department users the Purchaser role in Microsoft Store for Business

B.

Download the APPX file for App1 from Microsoft Store for Business

C.

Add App1 to the private store

D.

Assign the MKG department users the Basic Purchaser role in Microsoft Store for Business

E.

Acquire App1 from Microsoft Store for Business

Full Access
Question # 38

You need a new conditional access policy that has an assignment for Office 365 Exchange Online.

You need to configure the policy to meet the technical requirements for Group4.

Which two settings should you configure in the policy? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Question # 38

Full Access
Question # 39

You need to meet the technical requirements for the LEG department computers.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Question # 39

Full Access
Question # 40

You need to meet the technical requirements for the IT department.

What should you do first?

A.

From the Azure Active Directory blade in the Azure portal, enable Seamless single sign-on.

B.

From the Configuration Manager console, add an Intune subscription.

C.

From the Azure Active Directory blade in the Azure portal, configure the Mobility (MDM and MAM) settings.

D.

From the Microsoft Intune blade in the Azure portal, configure the Windows enrollment settings.

Full Access
Question # 41

What is the maximum number of devices that User1 and User2 can enroll in Intune? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 41

Full Access
Question # 42

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Question # 42

Full Access
Question # 43

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point

Question # 43

Full Access
Question # 44

You implement the planned changes for Connection1 and Connection2

How many VPN connections will there be for User1 when the user signs in to Device 1 and Devke2? To answer select the appropriate options in the answer area.

NOTE; Each correct selection is worth one point.

Question # 44

Full Access
Question # 45

User1 and User2 plan to use Sync your settings.

On which devices can the users use Sync your settings? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 45

Full Access
Question # 46

Which users can purchase and assign App1?

A.

User3 only

B.

User1 and User3 only

C.

User1, User2, User3, and User4

D.

User1, User3, and User4 only

E.

User3 and User4 only

Full Access
Question # 47

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 47

Full Access
Question # 48

Which user can enroll Device6 in Intune?

A.

User4 and User2 only

B.

User4 and User 1 only

C.

User1, User2, User3, and User4

D.

User4. User Land User2 only

Full Access
Question # 49

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Question # 49

Full Access
Question # 50

Which devices are registered by using the Windows Autopilot deployment service?

A.

Device1 only

B.

Device3 only

C.

Device1 and Device3 only

D.

Device1, Device2, and Device3

Full Access
Question # 51

You need to ensure that computer objects can be created as part of the Windows Autopilot deployment. The solution must meet the technical requirements.

To what should you grant the right to create the computer objects?

A.

Server2

B.

Server1

C.

GroupA

D.

DC1

Full Access
Question # 52

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 52

Full Access
Question # 53

You implement Boundary1 based on the planned changes.

Which devices have a network boundary of 192.168.1.0/24 applied?

A.

Device2 only

B.

Device3 only

C.

Device 1. Device2. and Device5 only

D.

Device 1, Device2, Device3, and Device4 only

Full Access
Question # 54

You have a Microsoft 365 E5 subscription that contains the devices shown in the following table.

Question # 54

All the devices are enrolled in Microsoft Intune.

The devices have apps installed as shown in the following table.

Question # 54

Full Access