Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: myex65

Home > Microsoft > Microsoft 365 Certified: Endpoint Administrator Associate > MD-102

MD-102 Endpoint Administrator Question and Answers

Question # 4

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Full Access
Question # 5

You need to ensure that computer objects can be created as part of the Windows Autopilot deployment. The solution must meet the technical requirements.

To what should you grant the right to create the computer objects?

A.

Server2

B.

Server1

C.

GroupA

D.

DC1

Full Access
Question # 6

Which users can purchase and assign App1?

A.

User3 only

B.

User1 and User3 only

C.

User1, User2, User3, and User4

D.

User1, User3, and User4 only

E.

User3 and User4 only

Full Access
Question # 7

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 8

Which user can enroll Device6 in Intune?

A.

User4 and User2 only

B.

User4 and User 1 only

C.

User1, User2, User3, and User4

D.

User4. User Land User2 only

Full Access
Question # 9

You have the devices shown in the following table.

You plan to implement Microsoft Defender for Endpoint.

You need to identify which devices can be onboarded to Microsoft Defender for Endpoint.

What should you identify?

A.

Device1 only

B.

Device2 only

C.

Device1, Device2 only

D.

Device1, Device2, and Device3 only

E.

Device1, Device2, Device3, and Device4

Full Access
Question # 10

You use the Microsoft Deployment Toolkit (MDT) to deploy Windows 11.

You create a new task sequence by using the Standard Client Task Sequence template to deploy Windows 11 Enterprise to new computers. The computers have a single hard disk.

You need to modify the task sequence to create a system volume and a data volume.

Which phase should you modify in the task sequence?

A.

Initialization

B.

State Restore

C.

Preinstall

D.

Postinstall

Full Access
Question # 11

You have a Windows 11 capable device named Device1 that runs the 64-bit version of Windows 10 Enterprise and has Microsoft Office 2019 installed. You have the Windows 11 Enterprise images shown in the following table.

Which images can be used to perform an in-place upgrade of Device1?

A.

image1 only

B.

lmage2only

C.

Image1 and Image2

Full Access
Question # 12

You use Microsoft Defender for Endpoint to protect computers that run Windows 10.

You need to assess the differences between the configuration of Microsoft Defender for Endpoint and the Microsoft-recommended configuration baseline.

Which tool should you use?

A.

Microsoft Defender for Endpoint Power 81 app

B.

Microsoft Secure Score

C.

Endpoint Analytics

D.

Microsoft 365 Defender portal

Full Access
Question # 13

-

You have a Microsoft 365 subscription. The subscription contains 1,000 computers that run Windows 11 and are enrolled in Microsoft Intune.

You plan to create a compliance policy that has the following options enabled:

• Require Secure Boot to be enabled on the device.

• Require the device to be at or under the machine risk score.

Which two Compliance settings should you configure? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 14

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your company has an Azure AD tenant named contoso.com that contains several Windows 10 devices.

When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin.

You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.

Solution: From the Microsoft Entra admin center, you configure the Authentication methods.

Does this meet the goal?

A.

Yes

B.

No

Full Access
Question # 15

You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Azure AD joined and are enrolled in Microsoft Intune.

You plan to manage Microsoft Defender Antivirus on the computers.

You need to prevent users from disabling Microsoft Defender Antivirus,

What should you do?

A.

From the Microsoft Intune admin center, create a security baseline.

B.

From the Microsoft 365 Defender portal, enable tamper protection.

C.

From the Microsoft Intune admin center, create an account protection policy.

D.

From the Microsoft Intune admin center, create an endpoint detection and response (EDR) policy.

Full Access
Question # 16

Your company has an Azure AD tenant named contoso.com that contains several Windows 10 devices.

When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin.

You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.

Solution: From the Microsoft Entra admin center, you configure automatic mobile device management (MDM) enrollment. From the Microsoft Intune admin center, you configure the Windows Hello for Business enrollment options.

Does this meet the goal?

A.

Yes

B.

No

Full Access
Question # 17

You have a Microsoft 365 E5 tenant that contains Windows devices enrolled in Microsoft Intune as shown in the following table.

You create an Endpoint Privilege Management (EPM) elevation settings policy named ElevationSettmgsl that has the following settings:

• Endpoint Privilege Management: Enabled

o Default elevation response: Require user confirmation

o Validation: Business justification

• Assignments: Group1 Each device contains a file named File1.exe that can be run only by an administrator. You create an EPM elevation rules policy named ElevattonRules1 that has the following settings:

• Rule name: Rule1

o Elevation type: Automatic

o File name: Filel.exe

o File hash:

• Assignments: Group2

For each of the following statements, select Yes if the statement is true. Otherwise, select

NOTE: Each correct selection is worth one point.

Full Access
Question # 18

You have a Microsoft 365 subscription.

You plan to enroll devices in Microsoft Endpoint Manager that have the platforms and versions shown in the following table.

You need to configure device enrollment to meet the following requirements:

Ensure that only devices that have approved platforms and versions can enroll in Endpoint Manager.

Ensure that devices are added to Microsoft Azure Active Directory (Azure AD) groups based on a selection made by users during the enrollment.

Which device enrollment setting should you configure for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 19

You have a Microsoft 365 subscription that uses Microsoft Intune and contains the users shown in the following table.

You create a policy set named Set1 as shown in the exhibit. (Click the Exhibit tab.)

You enroll devices in Intune as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 20

You have groups that use the Dynamic Device membership type as shown in the following table.

You are deploying Microsoft 365 apps.

You have devices enrolled in Microsoft Intune as shown in the following table.

In the Microsoft Endpoint Manager admin center, you create a Microsoft 365 Apps app as shown in the exhibit. (Click the Exhibit tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 21

You have a Microsoft 365 E5 subscription and 100 computers that run Windows 10.

You need to deploy Microsoft Office Professional Plus 2019 to the computers by using Microsoft Office Deployment Tool (ODT).

What should you use to create a customization file for ODT?

A.

the Microsoft 365 admin center

B.

the Microsoft Intune admin center

C.

the Microsoft Purview compliance portal

D.

the Microsoft 365 Apps admin center

Full Access
Question # 22

Your company has computers that run Windows 10 and are Microsoft Azure Active Directory (Azure AD)-joined.

The company purchases an Azure subscription.

You need to collect Windows events from the Windows 10 computers in Azure. The solution must enable you to create alerts based on the collected events.

What should you create in Azure and what should you configure on the computers? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 23

Your company has 200 computers that run Windows 10. The computers are managed by using Microsoft Intune. Currently, Windows updates are downloaded without using Delivery Optimization. You need to configure the computers to use Delivery Optimization. What should you create in Intune?

A.

a device compliance policy

B.

a Windows 10 update ring

C.

a device configuration profile

D.

an app protection policy

Full Access
Question # 24

You have the MDM Security Baseline profile shown in the MDM exhibit. (Click the MDM tab.)

You have the ASR Endpoint Security profile shown in the ASR exhibit. (Click the ASR tab.)

You plan to deploy both profiles to devices enrolled in Microsoft Intune. You need to identify how the following settings will be configured on the devices:

• Block Office applications from creating executable content

• Block Win32 API calls from Office macro

Currently, the settings are disabled locally on each device.

What are the effective settings on the devices? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 25

You have a workgroup computer named Client1 that runs Windows 11 and connects to a public network.

You need to enable PowerShell remoting on Client1. The solution must ensure that PowerShell remoting connections are accepted from the local subnet only.

Which PowerShell command should you run?

A.

Set-NetFirewallRule -Name "WINRM-HTTP-In-TCP-PUBLIC" -RemoteAddress Any

B.

Set-PSSessionConfiguration -AccessMode Local

C.

Enable-PSRemoting -Force

D.

Enable-PSRemoting -SkipNetworkProfileCheck

Full Access
Question # 26

You have a Microsoft 365 E5 subscription that includes Microsoft Intune. The subscription contains a group named Group! Group1 contains devices enrolled in Intune.

You deploy Remote Help in Intune.

You need to configure Remote Help to only allow support administrators to join Remote Help sessions from the devices in Group1.

Which type of Microsoft Entra object should you create, and which type of policy should you configure7 To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

devices

Full Access
Question # 27

You have a Microsoft 365 subscription that contains a user named User1 and uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices that run Windows 11.

User1 provides remote support for 75 devices in the marketing department.

You need to add User1 to the Remote Desktop Users group on each marketing department device.

What should you configure?

A.

an app configuration policy

B.

a device compliance policy

C.

an account protection policy

D.

a device configuration profile

Full Access
Question # 28

You have a Microsoft Entra tenant that contains the following:

• Windows 11 devices that are joined to Microsoft Entra

• A user that has a display name of User1 and a UPN of user1@contoso.com

You enable Remote Desktop on the Windows 11 devices.

You need to ensure that User1 can use Remote Desktop to connect to the devices.

How should you complete the command that must be run on each device? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 29

You have an Azure AD tenant that contains the devices shown in the following table.

You purchase Windows 11 Enterprise E5 licenses.

Which devices can use Subscription Activation to upgrade to Windows 11 Enterprise?

A.

Device1 only

B.

Device1 and Device2 only

C.

Device1 and Device3 only

D.

Device1, Device2, Device3, and Device4

Full Access
Question # 30

Your network contains an on-premises Active Directory Domain Services {AD DS) domain that syncs with an Azure AD tenant by using Azure AD Connect.

You use Microsoft Intune and Configuration Manager to manage devices.

You need to recommend a deployment plan for new Windows 11 devices. The solution must meet the following requirements:

• Devices for the marketing department must be joined to the AD DS domain only. The IT department will install complex applications on the devices at build time, before giving the devices to the marketing department users.

• Devices for The sales department must be Azure AD joined. The devices will be shipped directly from the manufacturer to The homes of the sales department users.

• Administrative effort must be minimized.

Which deployment method should you recommend for each department? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Full Access
Question # 31

Your network contains an Active Directory domain named contoso.com. The domain contains 25 computers that run Windows 11-

You have a Microsoft 365 subscription

You have an Azure AD tenant that syncs with contoso.com.

You configure hybrid Azure AD join and discover that some of the computers have a registered state of Pending.

You need to ensure that the computers complete the join successfully.

What should you ensure?

A.

that Windows is activated on all the computers

B.

that the users of the computers are assigned Microsoft 365 licenses

C.

that each computer has a line of sight to a domain controller

D.

that the computers contain the latest quality updates

Full Access
Question # 32

You need to implement mobile device management (MDM) for personal devices that run Windows 11. The solution must meet the following requirements:

• Ensure that you can manage the personal devices by using Microsoft Intune.

• Ensure that users can access company data seamlessly from their personal devices.

• Ensure that users can only sign in to their personal devices by using their personal account.

What should you use to add the devices to Azure AD?

A.

Azure AD registered Most Voted

B.

hybrid Azure AD join

C.

Azure AD joined

Full Access
Question # 33

You need a new conditional access policy that has an assignment for Office 365 Exchange Online.

You need to configure the policy to meet the technical requirements for Group4.

Which two settings should you configure in the policy? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 34

What is the maximum number of devices that User1 and User2 can enroll in Intune? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 35

You need to meet the technical requirements for the iOS devices.

Which object should you create in Intune?

A.

A compliance policy

B.

An app protection policy

C.

A Deployment profile

D.

A device configuration profile

Full Access
Question # 36

You need to meet the technical requirements for the IT department.

What should you do first?

A.

From the Azure Active Directory blade in the Azure portal, enable Seamless single sign-on.

B.

From the Configuration Manager console, add an Intune subscription.

C.

From the Azure Active Directory blade in the Azure portal, configure the Mobility (MDM and MAM) settings.

D.

From the Microsoft Intune blade in the Azure portal, configure the Windows enrollment settings.

Full Access
Question # 37

You need to meet the technical requirements for the new HR department computers.

How should you configure the provisioning package? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 38

You implement Boundary1 based on the planned changes.

Which devices have a network boundary of 192.168.1.0/24 applied?

A.

Device2 only

B.

Device3 only

C.

Device 1. Device2. and Device5 only

D.

Device 1, Device2, Device3, and Device4 only

Full Access
Question # 39

Which devices are registered by using the Windows Autopilot deployment service?

A.

Device1 only

B.

Device3 only

C.

Device1 and Device3 only

D.

Device1, Device2, and Device3

Full Access
Question # 40

You are evaluating which devices are compliant.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 41

To which devices do Policy1 and Policy2 apply? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 42

You need to prepare for the deployment of the Phoenix office computers.

What should you do first?

A.

Generalize the computers and configure the Mobility (MDM and MAM) settings from the Azure Active Directory admin center.

B.

Extract the hardware ID information of each computer to a CSV file and upload the file from the Microsoft Intune blade in the Azure portal.

C.

Extract the hardware ID information of each computer to an XML file and upload the file from the Devices settings in Microsoft Store for Business.

D.

Extract the serial number information of each computer to a CSV file and upload the file from the Microsoft Intune blade in the Azure portal.

Full Access
Question # 43

You need to prepare for the deployment of the Phoenix office computers.

What should you do first?

A.

Extract the hardware ID information of each computer to a CSV file and upload the file from the Devices settings in Microsoft Store for Business.

B.

Generalize the computers and configure the Mobility (MDM and MAM) settings from the Azure ActiveDirectory blade in the Azure portal.

C.

Generalize the computers and configure the Device settings from the Azure Active Directory blade in the Azure portal.

D.

Extract the hardware ID information of each computer to an XLSX file and upload the file from the Devices settings in Microsoft Store for Business.

Full Access
Question # 44

You need to meet the technical requirements for the LEG department computers.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Full Access
Question # 45

You need to meet the requirements for the MKG department users.

What should you do?

A.

Assign the MKG department users the Purchaser role in Microsoft Store for Business

B.

Download the APPX file for App1 from Microsoft Store for Business

C.

Add App1 to the private store

D.

Assign the MKG department users the Basic Purchaser role in Microsoft Store for Business

E.

Acquire App1 from Microsoft Store for Business

Full Access
Question # 46

You need to resolve the performance issues in the Los Angeles office.

How should you configure the update settings? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 47

What should you use to meet the technical requirements for Azure DevOps?

A.

An app protection policy

B.

Windows Information Protection (WIP)

C.

Conditional access

D.

A device configuration profile

Full Access
Question # 48

You need to recommend a solution to meet the device management requirements.

What should you include in the recommendation? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access