Weekend Special Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Microsoft > Microsoft 365 Certified: Endpoint Administrator Associate > MD-102

MD-102 Endpoint Administrator Question and Answers

Question # 4

You have a Microsoft 365 subscription that contains a user named User1.

You use Microsoft in tune to manage devices that run Windows 11.

You need to remove User1 from the local Administrators group on all enrolled devices. The solution must minimize administrative effort.

What should you configure?

A.

a device compliance policy

B.

an app configuration policy

C.

an account protection policy

Full Access
Question # 5

You have a Windows 11 capable device named Device1 that runs the 64-bit version of Windows 10 Enterprise and has Microsoft Office 2019 installed. You have the Windows 11 Enterprise images shown in the following table.

Which images can be used to perform an in-place upgrade of Device1?

A.

image1 only

B.

lmage2only

C.

Image1 and Image2

Full Access
Question # 6

You have 25 computers that run Windows 10 Pro.

You have a Microsoft 365 E5 subscription that uses Microsoft Intune.

You need to upgrade the computers to Windows 11 Enterprise by using an in-place upgrade. The solution must minimize administrative effort.

What should you use?

A.

Microsoft Deployment Toolkit (MDT) and a default image of Windows 11 Enterprise

B.

Microsoft Configuration Manager and a custom image of Windows 11 Enterprise

C.

Windows Autopilot

D.

Subscription Activation

Full Access
Question # 7

You have a Microsoft 365 ES subscription that uses Microsoft Intune.

You have the apps shown in the following exhibit.

Full Access
Question # 8

You have a Microsoft Intune subscription associated to an Azure AD tenant named contoso.com.

Users use one of the following three suffixes when they sign in to the tenant: us.contoso.com, eu.contoso.com, or contoso.com.

You need to ensure that the users are NOT required to specify the mobile device management (MDM) enrollment URL as part of the enrollment process. The solution must minimize the number of changes.

Which DNS records do you need?

A.

three CNAME records

B.

one CNAME record only

C.

three TXT records

D.

one TXT record only

Full Access
Question # 9

You need to prepare for the deployment of the Phoenix office computers.

What should you do first?

A.

Extract the hardware ID information of each computer to a CSV file and upload the file from the Devices settings in Microsoft Store for Business.

B.

Generalize the computers and configure the Mobility (MDM and MAM) settings from the Azure ActiveDirectory blade in the Azure portal.

C.

Generalize the computers and configure the Device settings from the Azure Active Directory blade in the Azure portal.

D.

Extract the hardware ID information of each computer to an XLSX file and upload the file from the Devices settings in Microsoft Store for Business.

Full Access
Question # 10

You are evaluating which devices are compliant.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 11

You need to meet the technical requirements for the iOS devices.

Which object should you create in Intune?

A.

A compliance policy

B.

An app protection policy

C.

A Deployment profile

D.

A device configuration profile

Full Access
Question # 12

What is the maximum number of devices that User1 and User2 can enroll in Intune? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 13

You need to meet the OOBE requirements for Windows AutoPilot.

Which two settings should you configure from the Azure Active Directory blade? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 14

What should you upgrade before you can configure the environment to support co-management?

A.

the domain functional level

B.

Configuration Manager

C.

the domain controllers

D.

Windows Server Update Services (WSUS)

Full Access
Question # 15

You need to recommend a solution to meet the device management requirements.

What should you include in the recommendation? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 16

What should you configure to meet the technical requirements for the Azure AD-joined computers?

A.

Windows Hello for Business from the Microsoft Intune blade in the Azure portal.

B.

The Accounts options in an endpoint protection profile.

C.

The Password Policy settings in a Group Policy object (GPO).

D.

A password policy from the Microsoft Office 365 portal.

Full Access
Question # 17

What should you use to meet the technical requirements for Azure DevOps?

A.

An app protection policy

B.

Windows Information Protection (WIP)

C.

Conditional access

D.

A device configuration profile

Full Access
Question # 18

You need to capture the required information for the sales department computers to meet the technical

requirements.

Which Windows PowerShell command should you run first?

A.

Install-Module WindowsAutoPilotIntune

B.

Install-Script Get-WindowsAutoPilotInfo

C.

Import-AutoPilotCSV

D.

Get-WindowsAutoPilotInfo

Full Access
Question # 19

You need to meet the device management requirements for the developers.

What should you implement?

A.

folder redirection

B.

Enterprise State Roaming

C.

home folders

D.

known folder redirection in Microsoft OneDrive

Full Access
Question # 20

Which devices are registered by using the Windows Autopilot deployment service?

A.

Device1 only

B.

Device3 only

C.

Device1 and Device3 only

D.

Device1, Device2, and Device3

Full Access
Question # 21

You need to resolve the performance issues in the Los Angeles office.

How should you configure the update settings? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 22

You need to meet the technical requirements for Windows AutoPilot.

Which two settings should you configure from the Azure Active Directory blade? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 23

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Full Access
Question # 24

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 25

User1 and User2 plan to use Sync your settings.

On which devices can the users use Sync your settings? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 26

You need to ensure that computer objects can be created as part of the Windows Autopilot deployment. The solution must meet the technical requirements.

To what should you grant the right to create the computer objects?

A.

Server2

B.

Server1

C.

GroupA

D.

DC1

Full Access
Question # 27

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 28

You implement the planned changes for Connection1 and Connection2

How many VPN connections will there be for User1 when the user signs in to Device 1 and Devke2? To answer select the appropriate options in the answer area.

NOTE; Each correct selection is worth one point.

Full Access
Question # 29

Which users can purchase and assign App1?

A.

User3 only

B.

User1 and User3 only

C.

User1, User2, User3, and User4

D.

User1, User3, and User4 only

E.

User3 and User4 only

Full Access
Question # 30

Which user can enroll Device6 in Intune?

A.

User4 and User2 only

B.

User4 and User 1 only

C.

User1, User2, User3, and User4

D.

User4. User Land User2 only

Full Access
Question # 31

You implement Boundary1 based on the planned changes.

Which devices have a network boundary of 192.168.1.0/24 applied?

A.

Device2 only

B.

Device3 only

C.

Device 1. Device2. and Device5 only

D.

Device 1, Device2, Device3, and Device4 only

Full Access
Question # 32

You use the Microsoft Deployment Toolkit (MDT) to manage Windows 11 deployments.

From Deployment Workbench, you modify the WinPE settings and add PowerShell support.

You need to generate a new set of WinPE boot image files that contain the updated settings.

What should you do?

A.

From the Deployment Shares node, update the deployment share.

B.

From the Advanced Configuration node, create new media.

C.

From the Packages node, import a new operating system package

D.

From the Operating Systems node, import a new operating system.

Full Access
Question # 33

You have a Microsoft 365 subscription. All devices run Windows 10.

You need to prevent users from enrolling the devices in the Windows Insider Program.

What two configurations should you perform from the Microsoft Intune admin center? Each correct answer is a complete solution.

NOTE: Each correct selection is worth one point.

A.

a device restrictions device configuration profile

B.

an app configuration policy

C.

a Windows 10 and later security baseline

D.

a custom device configuration profile

E.

a Windows 10 and later update ring

Full Access
Question # 34

You have a Microsoft Entra tenant named contoso.com that contains a Windows 11 device named Device1 and a user named User1 User! registers Device1 in contoso.com.

Which capability is available to Device1 after registering in contoso.com.

A.

authenticating to cloud resources by using single sign-on (SSO)

B.

enforcing software updates

C.

enforcing hard drive encryption

D.

enforcing compliance policies

Full Access
Question # 35

Your company uses Microsoft Intune to manage devices.

You need to ensure that only Android devices that use Android work profiles can enroll in intune.

Which two configurations should you perform in the device enrollment restrictions? Each correct answer presents part of the solution.

NOTE Each correct selection is worth one point.

A.

From Platform Settings, set Android device administrator Personally Owned to Block.

B.

From Platform Settings, set Android Enterprise (work profile) to Allow.

C.

From Platform Settings, set Android device administrator Personally Owned to Allow

D.

From Platform Settings, set Android device administrator to Block.

Full Access
Question # 36

You have a Microsoft 365 subscription.

You plan to use Windows Autopilot to provision 25 Windows 11 devices.

You need to configure the Out-of-box experience (OOBE) settings.

What should you create in the Microsoft Intune admin center?

A.

an enrollment status page (ESP)

B.

a deployment profile

C.

a compliance policy

D.

a PowerShell script

E.

a configuration profile

Full Access
Question # 37

You have a Microsoft 365 subscription that contains a user named User1. The subscription contains devices enrolled in Microsoft intune as shown in the following table.

Microsoft Edge is available on all the devices.

Intune has the device compliance policies shown in the following table.

The Compliance policy settings are configured as shown in the exhibit. (Click the Exhibit tab.) You create the following Conditional Access policy:

• Name: Policy1

• Assignments

o Users and groups: User1

o Cloud apps or actions: Office 365 SharePoint Online

• Access controls

o Grant Require device to be marked as compliant

• Enable policy: On

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Full Access
Question # 38

You have a Microsoft 365 subscription that includes Microsoft Intune.

You need to implement a Microsoft Defender for Endpoint solution that meets the following requirements:

• Enforces compliance for Defender for Endpoint by using Conditional Access

• Prevents suspicious scripts from running on devices

What should you configure? To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Full Access
Question # 39

You have a Microsoft 365 subscription.

All users have Microsoft 365 apps deployed.

You need to configure Microsoft 365 apps to meet the following requirements:

• Enable the automatic installation of WebView2 Runtime.

• Prevent users from submitting feedback.

Which two settings should you configure in the Microsoft 365 Apps admin center? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 40

You have a Microsoft 365 tenant that uses Microsoft Intune.

From the Microsoft Intune admin center, you plan to create a baseline to monitor the Startup score and the App reliability score of enrolled Windows 10 devices.

You need to identify which tool to use to create the baseline and the minimum number of devices required to create the baseline.

What should you identify? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 41

Your network contains an on-premises Active Directory Domain Services {AD DS) domain that syncs with an Azure AD tenant by using Azure AD Connect.

You use Microsoft Intune and Configuration Manager to manage devices.

You need to recommend a deployment plan for new Windows 11 devices. The solution must meet the following requirements:

• Devices for the marketing department must be joined to the AD DS domain only. The IT department will install complex applications on the devices at build time, before giving the devices to the marketing department users.

• Devices for The sales department must be Azure AD joined. The devices will be shipped directly from the manufacturer to The homes of the sales department users.

• Administrative effort must be minimized.

Which deployment method should you recommend for each department? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Full Access
Question # 42

You have a Microsoft Intune subscription.

You have devices enrolled in intune as shown in the following table.

An app named App1 is installed on each device.

What is the minimum number of app configuration policies required to manage Appl ?

A.

1

B.

2

C.

3

D.

4

E.

5

Full Access
Question # 43

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.

You plan to onboard the following types of devices to Defender for Endpoint:

• macOS

• Linux Server

What should you use to onboard each device? To answer, drag the appropriate tools to the correct device types. Each tool may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Full Access
Question # 44

You have a Microsoft 365 E5 subscription.

You use Microsoft Intune to manage all Windows 11 devices.

You create an attack surface reduction (ASR) policy named Profile1 based on the Attack Surface Reduction Rules profile and assign Profile! to all the devices.

A user reports that an Adobe Reader plug-in is now blocked.

You need to ensure that the plug-in is unblocked.

What should you do?

A.

Create an Endpoint Privilege Management policy and assign the policy to all the devices.

B.

Add a scope tag to Profile1.

C.

Configure ASR Only Per Rule Exclusions in Profile1.

D.

Create a device compliance policy and assign the policy to all the devices.

Full Access
Question # 45

You have a Microsoft 365 subscription.

You use app protection policies to protect corporate data on Android devices.

You need to ensure that any user connecting from an Android device can only access the corporate data if they connect from an app that supports mobile application management (MAM).

What should you configure?

A.

an app configuration policy

B.

a Conditional Access policy

C.

a device configuration profile

D.

a device compliance policy

Full Access
Question # 46

You have a Microsoft 365 E5 subscription and 100 unmanaged iPad devices.

You need to deploy a specific iOS update to the devices. Users must be prevented from manually installing a more recent version of iOS.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

Enroll the devices in Microsoft Intune by using the Intune Company Portal.

B.

Create a compliance policy.

C.

Enroll the devices in Microsoft Intune by using Apple Business Manager.

D.

Create an iOS app provisioning profile.

E.

Create a device configuration profile.

Full Access
Question # 47

You have a Microsoft 365 subscription that includes Microsoft Intune and Microsoft Defender for Endpoint.

Users have devices that run Windows 11.

You deploy a connection from Defender for Endpoint to Intune.

You need to ensure that when a device is enrolled in Intune, the device is onboarded automatically to Defender for Endpoint

What should you configure, and which portal should you use? To answer, select the appropriate options in the answer area

NOTE: Each correct selection is worth one point.

Full Access
Question # 48

You have the on-premises servers shown in the following table.

You have a Microsoft 365 E5 subscription that contains Android and iOS devices. All the devices are managed by using Microsoft Intune.

You need to implement Microsoft Tunnel for Intune. The solution must minimize the number of open firewall ports.

To which server can you deploy a Tunnel Gateway server, and which inbound ports should be allowed on the server to support Microsoft Tunnel connections? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 49

You need to meet the requirements for the MKG department users.

What should you do?

A.

Assign the MKG department users the Purchaser role in Microsoft Store for Business

B.

Download the APPX file for App1 from Microsoft Store for Business

C.

Add App1 to the private store

D.

Assign the MKG department users the Basic Purchaser role in Microsoft Store for Business

E.

Acquire App1 from Microsoft Store for Business

Full Access
Question # 50

You need to meet the technical requirements for the new HR department computers.

How should you configure the provisioning package? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access