MD-101
Free trial
Verified
Question 1
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company Windows 10 computers that are enrolled in Microsoft Intune. You make use of Intune to manage the servicing channel settings of all company computers.
You receive an enquiry regarding the servicing status of a specific computer.
You need to review the necessary policy report.
Solution: You navigate to device status via Device configuration.
Does the solution meet the goal?
- A: Yes
- B: No
Question 2
You need to consider the underlined segment to establish whether it is accurate.
Your company's Microsoft Azure subscription includes an Azure Log Analytics workspace.
After deploying a new Windows 10 computer, which belongs to a workgroup, you are tasked with making sure that you are able to utilize Log Analytics to query events from the new computer.
You configure the new computer's commercial ID.
Select No adjustment required if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.
What should you do on Computer1?
- A: No adjustment required.
- B: install the Azure Diagnostic extension on the new computer
- C: install the Dependency agent on the new computer
- D: install the Microsoft Monitoring Agent on the new computer
Question 3
You need to consider the underlined segment to establish whether it is accurate.
After installing a feature update on a Windows 10 computer, you have 7 days to roll back the update
Select No adjustment required if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.
- A: No adjustment required.
- B: 10
- C: 90
- D: 30
Question 4
Your company has a Microsoft 365 subscription configured for their environment. All devices in the environment have Windows 10 installed.
You have been instructed to make sure that users are not allowed to enroll devices in the Windows Insider Program.
To achieve your goal, you access Microsoft 365 Device Management.
Which of the following actions should you take?
- A: You should configure a Windows 10 security baseline.
- B: You should configure an app protection policy.
- C: You should configure device restriction policy.
- D: You should configure a Windows 10 update ring.
Question 5
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company has a hybrid configuration of Microsoft Azure Active Directory (Azure AD). Your company also has a Microsoft 365 subscription.
After creating a conditional access policy for Microsoft Exchange Online, you are tasked with configuring the policy to block access to Exchange Online. However, the policy should allow access for hybrid Azure AD-joined devices
Solution: You should configure the Device platforms settings.
Does the solution meet the goal?
- A: Yes
- B: No
Question 6
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company has a hybrid configuration of Microsoft Azure Active Directory (Azure AD). Your company also has a Microsoft 365 subscription.
After creating a conditional access policy for Microsoft Exchange Online, you are tasked with configuring the policy to block access to Exchange Online. However, the policy should allow access for hybrid Azure AD-joined devices
Solution: You should configure the Client apps settings.
Does the solution meet the goal?
- A: Yes
- B: No
Question 7
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company has a hybrid configuration of Microsoft Azure Active Directory (Azure AD). Your company also has a Microsoft 365 subscription.
After creating a conditional access policy for Microsoft Exchange Online, you are tasked with configuring the policy to block access to Exchange Online. However, the policy should allow access for hybrid Azure AD-joined devices
Solution: You should configure the Device state settings.
Does the solution meet the goal?
- A: Yes
- B: No
Question 8
Your company makes use of Microsoft Intune to manage computers.
You have been tasked with configuring Windows Hello for Business. You are preparing to create an Intune profile to achieve your goal.
Which of the following is an operating system that supports Windows Hello for Business?
- A: Windows Vista
- B: Windows 8.1
- C: Windows 10
- D: macOS
Question 9
Your company has a large number of Android and iOS devices, which are enrolled in Intune.
You are preparing to deploy new Intune policies will apply to devices, based on the version of Android or iOS that is being run.
You are required to make sure that the policies are able to target the devices according to your plan.
Which of the following actions should you take?
- A: You should start by accessing Intune and configuring corporate device identifiers.
- B: You should start by accessing Microsoft Azure Active Directory (Azure AD) and configuring Device settings.
- C: You should start by accessing Microsoft Azure Active Directory (Azure AD) and configuring Application settings.
- D: You should start by creating a distribution group.
Question 10
You need to consider the underlined segment to establish whether it is accurate.
Your company has Microsoft Azure Active Directory (Azure AD) joined Windows 10 Pro computers that have been enrolled in Microsoft Intune.
You have been tasked with making sure that the computers are upgraded to Windows 10 Enterprise.
You start by configuring a device enrollment policy in Intune.
Select No adjustment required if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.
What should you configure in Intune?
- A: No adjustment required
- B: an app protection policy
- C: a Windows AutoPilot deployment profile
- D: A device configuration profile
Question 11
Your company has a Microsoft 365 subscription.
You have enrolled all the company computers in Microsoft Intune.
You have been tasked with making sure that Microsoft Exchange Online is only accessible from known locations.
Which of the following actions should you take?
- A: You should create a device configuration profile.
- B: You should create a device compliance policy.
- C: You should create a Windows AutoPilot deployment profile.
- D: You should create a conditional access policy.
Question 12
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company Windows 10 computers that are enrolled in Microsoft Intune. You make use of Intune to manage the servicing channel settings of all company computers.
You receive an enquiry regarding the servicing status of a specific computer.
You need to review the necessary policy report.
Solution: You navigate to the audit logs via Software updates.
Does the solution meet the goal?
- A: Yes
- B: No
Question 13
Your company has a Microsoft 365 subscription.
You have enrolled all the company computers in Microsoft Intune.
You have been tasked with making sure that devices with a high Windows Defender Advanced Threat Protection (Windows Defender ATP) risk score are locked.
Which of the following actions should you take?
- A: You should create a device configuration profile.
- B: You should create a device compliance policy.
- C: You should create a Windows AutoPilot deployment profile.
- D: You should create a conditional access policy.
Question 14
Your company plans to deploy tablets to 50 meeting rooms.
The tablets run Windows 10 and are managed by using Microsoft Intune. The tablets have an application named App1.
You need to configure the tablets so that any user can use App1 without having to sign in. Users must be prevented from using other applications on the tablets.
Which device configuration profile type should you use?
- A: Kiosk
- B: Endpoint protection
- C: Identity protection
- D: Device restrictions
Question 15
All of your company's devices are managed via Microsoft Intune.
Conditional access is used to prevent devices that are not compliant with company security policies, from accessing Microsoft 365 services.
You need to access Device compliance to view the non-compliant devices.
Where should you access Device compliance from?
- A: System Center Configuration Manager
- B: Windows Defender Security Center.
- C: The Intune admin center.
- D: The Azure Active Directory admin center.
Question 16
You manage a large number of Windows 10 computers.
You have been tasked with creating a provisioning package that will allow you to remove the Microsoft News and the Xbox Microsoft Store apps, as well as add a
VPN connection to the company network.
Which of the following are the customization settings you should configure?
- A: Connections and Personalization
- B: ConnectivityProfiles and Policies
- C: Connections and Policies
- D: ConnectivityProfiles and Personalization
Question 17
All users at your company have Azure AD joined Windows 10 workstations that are managed via Microsoft Intune.
You have been tasked with making sure that Windows Analytics is used to monitor the workstations centrally.
Which of the following actions should you take?
- A: You should create a device configuration profile via Intune.
- B: You should create a device compliance policy via Intune.
- C: You should create a Windows AutoPilot deployment profile via Intune.
- D: You should create an app configuration policy via Intune.
Question 18
Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations. These workstations have been enrolled in Microsoft
Intune.
You are creating a device configuration profile for the workstations. You have been informed that a custom image should be displayed on the sign-in screen.
Which of the following is a Device restriction setting that should be configured?
- A: Locked screen experience
- B: Personalization
- C: Display
- D: General
Question 19
Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations. These workstations have been enrolled in Microsoft
Intune.
You are creating a device configuration profile for the workstations. You have been informed that a custom image should be displayed as the Desktop background picture.
Which of the following is a Device restriction setting that should be configured?
- A: Locked screen experience
- B: Personalization
- C: Display
- D: General
Question 20
Your company has a large number of Windows 10 workstations that are managed via Microsoft Intune.
Delivery Optimization is not being used for Windows updates at present.
You want to make sure that Delivery Optimization is configured for all of the workstations.
Which of the following actions should you take?
- A: You should create a device configuration profile via Intune.
- B: You should create a device compliance policy via Intune.
- C: You should create a Windows AutoPilot deployment profile via Intune.
- D: You should create a conditional access policy via Intune.
Question 21
Your company's environment includes the following:
✑ Microsoft Azure Active Directory (Azure AD)
✑ Microsoft 365
✑ Microsoft Intune
✑ Azure Information Protection.
A new security policy declares that enrollment for private devices in Intune is not required. However, to access corporate email information, users have to make use of a PIN for authentication purposes. Also, users are able to access corporate cloud services from their private iOS and Android devices. Furthermore, the copying corporate email information to a cloud storage service should not be allowed, unless users are copying the information to Microsoft OneDrive for
Business.
You have to make sure that security policy is enforced.
Which of the following actions should you take?
- A: You should create a data loss prevention (DLP) policy.
- B: You should create a device enrollment policy.
- C: You should create an app protection policy.
- D: You should create a Windows AutoPilot deployment profile.
Question 22
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations. These workstations have been enrolled in Microsoft
Intune.
You have been tasked with making sure that the workstations are only able to run applications that you have explicitly permitted.
Solution: You make use of Windows Defender Antivirus.
Does the solution meet the goal?
- A: Yes
- B: No
Question 23
You have been tasked with reusing a Windows 10 computer that was assigned to a user who is no longer with the company.
The computer will be assigned to a new user. You plan to make use of Windows AutoPilot to redeploy the computer.
Which of the following actions should you take FIRST?
- A: Reset the computer.
- B: Wipe the computer.
- C: Create a HTML file containing the computer info.
- D: Create a CSV file containing the computer info.
Question 24
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations. These workstations have been enrolled in Microsoft
Intune.
You have been tasked with making sure that the workstations are only able to run applications that you have explicitly permitted.
Solution: You make use of Windows Defender SmartScreen.
Does the solution meet the goal?
- A: Yes
- B: No
Question 25
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations. These workstations have been enrolled in Microsoft
Intune.
You have been tasked with making sure that the workstations are only able to run applications that you have explicitly permitted.
Solution: You make use of Windows Defender Application Guard.
Does the solution meet the goal?
- A: Yes
- B: No
Free preview mode
Enjoy the free questions and consider upgrading to gain full access!