Free preview mode
Enjoy the free questions and consider upgrading to gain full access!
MD-101
Free trial
Verified
Question 26
You are currently making use of the Antimalware Assessment solution in Microsoft Azure Log Analytics.
You have accessed the Protection Status dashboard and find that there is a device that has no real time protection.
Which of the following could be a reason for this occurring?
- A: Windows Defender has been disabled.
- B: You need to install the Azure Diagnostic extension.
- C: Windows Defender Credential Guard is incorrectly configured.
- D: Windows Defender System Guard is incorrectly configured.
Question 27
You are currently making use of the Antimalware Assessment solution in Microsoft Azure Log Analytics.
You have accessed the Protection Status dashboard and find that there is a device that is not reporting.
Which of the following could be a reason for this occurring?
- A: Windows Defender System Guard is incorrectly configured.
- B: You need to install the Azure Diagnostic extension.
- C: Windows Defender Application Guard is incorrectly configured.
- D: The Microsoft Malicious Software Removal tool is installed.
Question 28
You need to consider the underlined segment to establish whether it is accurate.
To enable Windows Defender Credential Guard on Windows 10 computers, the computers must have Hyper-V installed.
Select No adjustment required if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.
What should you install on the computers?
- A: No adjustment required.
- B: Windows Defender Smartscreen
- C: a virtual machine
- D: a container cluster
Question 29
You manage one hundred Microsoft Azure Active Directory (Azure AD) joined Windows 10 devices.
You want to make sure that users are unable to join their home PC's to Azure AD.
Which of the following actions should you take?
- A: You should configure the Enrollment restriction settings via the Device enrollment blade in the Intune admin center.
- B: You should configure the Enrollment restriction settings via the Security & Compliance admin center.
- C: You should configure the Enrollment restriction settings via the Azure Active Directory admin center.
- D: You should configure the Enrollment restriction settings via the Windows Defender Security Center.
Question 30
You need to consider the underlined segment to establish whether it is accurate.
To enable sideloading in Windows 10, you should navigate to the For developers setting via Update & Security in the Settings app.
Select No adjustment required if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.
- A: No adjustment required.
- B: Widows Insider
- C: Delivery Optimization
- D: Activation
Question 31
You need to consider the underlined segment to establish whether it is accurate.
To enable sideload a LOB application in Windows 10, you should run the Install-Package cmdlet.
Select No adjustment required if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.
- A: No adjustment required.
- B: Install-PackageProvider
- C: Save-Package
- D: Add-AppxPackage
Question 32
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company's environment includes a Microsoft 365 subscription.
Users in the company's sales division have personal iOS or Android devices that are enrolled in Microsoft Intune. New users are added to the sales division on a monthly basis.
After a mobile application is created for users in the sales division, you are instructed to make sure that the application can only be downloaded by the sales division users
Solution: You start by adding the application to Microsoft Store for Business.
Does the solution meet the goal?
- A: Yes
- B: No
Question 33
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company's environment includes a Microsoft 365 subscription.
Users in the company's sales division have personal iOS or Android devices that are enrolled in Microsoft Intune. New users are added to the sales division on a monthly basis.
After a mobile application is created for users in the sales division, you are instructed to make sure that the application can only be downloaded by the sales division users
Solution: You start by assigning the application to a group.
Does the solution meet the goal?
- A: Yes
- B: No
Question 34
DRAG DROP -
Your company has a number of Windows 7 computers that you want to upgrade to Windows 10.
The computers all have a single MBR disk, and a disabled TPM chip. Also, the computers have hardware virtualization disabled, Data Execution Prevention (DEP) enabled, and UEFI firmware running in BIOS mode.
You have been tasked with making sure that Secure Boot can be used by the computers.
Which of the following actions should you take? Answer by dragging the correct options from the list to the answer area. Choose two.
Select and Place:
Question 35
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company's environment includes a Microsoft 365 subscription.
Users in the company's sales division have personal iOS or Android devices that are enrolled in Microsoft Intune. New users are added to the sales division on a monthly basis.
After a mobile application is created for users in the sales division, you are instructed to make sure that the application can only be downloaded by the sales division users.
Solution: You start by adding the application to Intune.
Does the solution meet the goal?
- A: Yes
- B: No
Question 36
You company has a Microsoft Azure Active Directory (Azure AD) tenant that includes Microsoft Intune. All of the Windows 10 devices are enrolled in Intune.
You are preparing to configure a Windows Information Protection (WIP) policy:
You need to make sure that the policy is configured to allow for the logging of unacceptable data sharing, but not blocking the action.
Which of the following is the WIP protection mode that you should use?
- A: Block
- B: Silent
- C: Off
- D: Allow Overrides
Question 37
Your company has an Active Directory domain, named weylandindustries.com, and a Microsoft Office 365 subscription. The domain is also synced to Microsoft
Azure Active Directory (Azure AD).
All company computers are domain-joined, and are running the most recent Microsoft OneDrive sync client.
You are currently configuring OneDrive group policy settings.
Which of the following is the setting that will minimize the disk space consumed by a user profile, when enabled?
- A: OneDrive Files On-Demand
- B: Silently move known folders to OneDrive
- C: Prompt users to move Windows known folders to OneDrive
- D: Silently configure OneDrive using the primary Windows account
Question 38
You manage your company's Microsoft 365 subscription.
You are tasked with creating an app protection policy for the Microsoft Outlook app on iOS devices that are not enrolled in Microsoft 365 Device Management.
You have to make sure that the policy is configured to prohibit the users from using the Outlook app if the operating system version is less than 12.0.0. You also have to make sure that an alphanumeric passcode is required for users to access the Outlook app.
Which of the following is policy settings that you should configure? (Choose two.)
- A: Conditional launch
- B: Data transfer exemptions
- C: Data protection
- D: Access requirements
Question 39
You are responsible for your company's Microsoft 365 environment, with co-management enabled.
All company computers have been deployed via Microsoft Deployment Toolkit (MDT), and have Windows 10 installed.
You have been tasked devising a strategy for deploying Microsoft Office 365 ProPlus to new computers. You have to make sure that most recent version is installed at all times, while also reducing the effort required to meet the prerequisites.
Which of the following actions should you take?
- A: You should make use of Windows Deployment Services (WDS).
- B: You should make use of the Microsoft Deployment Toolkit
- C: You should make use of the Office Deployment Tool (ODT).
- D: You should make use of a Windows Configuration Designer provisioning package
Question 40
Your company has an Active Directory domain that includes a large number of Windows 10 computers.
You have recently configured hybrid Microsoft Azure Active Directory (Azure AD) and Microsoft Intune in the environment.
You want to make sure that all the current computers are automatically registered to Azure AD, as well as enrolled in Intune. The strategy that you employ should reduce the administrative effort required to achieve your goal.
Which of the following actions should you take?
- A: You should make use of Windows Reset.
- B: You should make use of a Windows AutoPilot deployment profile.
- C: You should make use of a n Autodiscover service connection point (SCP).
- D: You should make use of a device configuration profile.
Question 41
You need to consider the underlined segment to establish whether it is accurate.
You have recently created a provisioning package that uses Comp%RAND:1% as the device name.
You will be able to successfully run the package on as much as 5 devices.
Select No adjustment required if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.
- A: No adjustment required
- B: 10
- C: 15
- D: 20
Question 42
Your company has an Active Directory domain, named weylandindustries.com. The domain is synced to Microsoft Azure Active Directory (Azure AD) and all company computers have been enrolled in Microsoft Intune.
You are preparing to perform a Wipe action on certain company devices.
Which of the following operating systems support the Wipe action? Choose all that apply.
- A: Windows Vista
- B: Windows 8.1
- C: Windows 10
- D: iOS
Question 43
Your company has an Active Directory domain, named weylandindustries.com. The domain is synced to Microsoft Azure Active Directory (Azure AD) and all company computers have been enrolled in Microsoft Intune.
You are preparing to perform a Fresh Start action on certain company devices.
Which of the following operating systems support the Fresh Start action? Choose all that apply.
- A: Windows Vista
- B: Windows 8.1
- C: Windows 10
- D: iOS
Question 44
Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations. These workstations have been enrolled in Microsoft
Intune.
You have been tasked with making sure that the has self-service password reset enabled on the logon screen. You have navigated to the Microsoft Intune blade.
Which of the following is the setting you should configure?
- A: The Device configuration settings.
- B: The Device compliance settings
- C: The Windows AutoPilot deployment settings
- D: The App protection settings
Question 45
HOTSPOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Question 46
You need to ensure that computer objects can be created as part of the Windows Autopilot deployment. The solution must meet the technical requirements.
To what should you grant the right to create the computer objects?
- A: Server2
- B: Server1
- C: GroupA
- D: DC1
Question 47
What should you use to meet the technical requirements for Azure DevOps?
- A: An app protection policy
- B: Windows Information Protection (WIP)
- C: Conditional access
- D: A device configuration profile
Question 48
What should you upgrade before you can configure the environment to support co-management?
- A: the domain functional level
- B: Microsoft Endpoint Configuration Manager
- C: the domain controllers
- D: Windows Server Update Services (WSUS)
Question 49
You need to meet the device management requirements for the developers.
What should you implement?
- A: Enterprise State Roaming
- B: folder redirection
- C: home folders
- D: known folder redirection in Microsoft OneDrive
Question 50
You need to meet the technical requirements for the iOS devices.
Which object should you create in Intune?
- A: A compliance policy
- B: An app protection policy
- C: A deployment profile
- D: A device configuration profile
Free preview mode
Enjoy the free questions and consider upgrading to gain full access!