MD-101 Flashcards

1
Q

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

Your company Windows 10 computers that are enrolled in Microsoft Intune. You make use of Intune to manage the servicing channel settings of all company computers.

You receive an enquiry regarding the servicing status of a specific computer. You need to review the necessary policy report.
Solution: You navigate to device status via Device configuration. Does the solution meet the goal?

A. Yes
B. No

A

Answer: B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

Your company Windows 10 computers that are enrolled in Microsoft Intune. You make use of Intune to manage the servicing channel settings of all company computers.

You receive an enquiry regarding the servicing status of a specific computer. You need to review the necessary policy report.

Solution: You navigate to the audit logs via Software updates. Does the solution meet the goal?

A. Yes
B. No

A

Answer: B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

You have been tasked with reusing a Windows 10 computer that was assigned to a user who is no longer with the company.

The computer will be assigned to a new user. You plan to make use of Windows AutoPilot to redeploy the computer.

Which of the following actions should you take FIRST?

A. Reset the computer.
B. Wipe the computer.
C. Create a HTML file containing the computer info.
D. Create a CSV file containing the computer info.

A

Answer: D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Your company has an Active Directory domain that includes a large number of Windows 10 computers.

You have recently configured hybrid Microsoft Azure Active Directory (Azure AD) and Microsoft Intune in the environment.

You want to make sure that all the current computers are automatically registered to Azure AD, as well as enrolled in Intune. The strategy that you employ should reduce the administrative effort required to achieve your goal.

Which of the following actions should you take?

A. You should make use of Windows Reset.
B. You should make use of a Windows AutoPilot deployment profile.
C. You should make use of a n Autodiscover service connection point (SCP).
D. You should make use of a device configuration profile.

A

Answer: B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

You need to consider the underlined segment to establish whether it is accurate.

You have recently created a provisioning package that uses Comp%RAND:1% as the device name.

You will be able to successfully run the package on as much as 5 devices.

Select “No adjustment required” if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.

A. No adjustment required
B. 10
C. 15
D. 20

A

Answer: B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Your company has an Active Directory domain, named weylandindustries.com. the domain is synced to Microsoft Azure Active Directory (Azure AD) and all company computers have been enrolled in Microsoft Intune.

You are preparing to perform a Wipe action on certain company devices.

Which of the following operating systems support the Wipe action? (Choose all that apply.)

A. Windows Vista
B. Windows 8.1
C. Windows 10
D. iOS

A

Answer: B, C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Your company has an Active Directory domain, named weylandindustries.com. the domain is synced to Microsoft Azure Active Directory (Azure AD) and all company computers have been enrolled in Microsoft Intune.

You are preparing to perform a Fresh Start action on certain company devices.

Which of the following operating systems support the Fresh Start action? (Choose all that apply.)

A. Windows Vista
B. Windows 8.1
C. Windows 10
D. iOS

A

Answer: C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations. These workstations have been enrolled in Microsoft Intune.

You have been tasked with making sure that the has self-service password reset enabled on the logon screen. You have navigated to the Microsoft Intune blade.

Which of the following is the setting you should configure?

A. The Device configuration settings.
B. The Device compliance settings
C. The Windows AutoPilot deployment settings
D. The App protection settings

A

Answer: A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

You need to consider the underlined segment to establish whether it is accurate.

Your company’s Microsoft Azure subscription includes an Azure Log Analytics workspace.

After deploying a new Windows 10 computer, which belongs to a workgroup, you are tasked with making sure that you are able to utilize Log Analytics to query events from the new computer.

You configure the new computer’s commercial ID.

Select “No adjustment required” if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.

What should you do on Computer1?

A. No adjustment required.
B. install the Azure Diagnostic extension on the new computer
C. install the Dependency agent on the new computer
D. install the Microsoft Monitoring Agent on the new computer

A

Answer: D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

You need to consider the underlined segment to establish whether it is accurate.

After installing a feature update on a Windows 10 computer, you have 7 days to roll back the update

Select “No adjustment required” if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.

A. No adjustment required.
B. 10
C. 90
D. 30

A

Answer: B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Your company has a Microsoft 365 subscription configured for their environment. All devices in the environment have Windows 10 installed.

You have been instructed to make sure that users are not allowed to enroll devices in the Windows Insider Program.

To achieve your goal, you access Microsoft 365 Device Management.

Which of the following actions should you take?

A. You should configure a Windows 10 security baseline.
B. You should configure an app protection policy.
C. You should configure device restriction policy.
D. You should configure a Windows 10 update ring.

A

Answer: D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

Your company has a hybrid configuration of Microsoft Azure Active Directory (Azure AD). Your company also has a Microsoft 365 subscription.

After creating a conditional access policy for Microsoft Exchange Online, you are tasked with configuring the policy to block access to Exchange Online. However, the policy should allow access for hybrid Azure AD-joined devices

Solution: You should configure the Device platforms settings. Does the solution meet the goal?

A. Yes
B. No

A

Answer: B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

Your company has a hybrid configuration of Microsoft Azure Active Directory (Azure AD). Your company also has a Microsoft 365 subscription.

After creating a conditional access policy for Microsoft Exchange Online, you are tasked with configuring the policy to block access to Exchange Online. However, the policy should allow access for hybrid Azure AD-joined devices

Solution: You should configure the Client apps settings. Does the solution meet the goal?

A. Yes
B. No

A

Answer: B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

Your company has a hybrid configuration of Microsoft Azure Active Directory (Azure AD). Your company also has a Microsoft 365 subscription.

After creating a conditional access policy for Microsoft Exchange Online, you are tasked with configuring the policy to block access to Exchange Online. However, the policy should allow access for hybrid Azure AD-joined devices

Solution: You should configure the Device state settings. Does the solution meet the goal?

A. Yes
B. No

A

Answer: A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Your company makes use of Microsoft Intune to manage computers.

You have been tasked with configuring Windows Hello for Business. You are preparing to create an Intune profile to achieve your goal.

Which of the following is an operating system that supports Windows Hello for Business?

A. Windows Vista
B. Windows 8.1
C. Windows 10
D. macOS

A

Answer: C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Your company has a large number of Android and iOS devices, which are enrolled in Intune.

You are preparing to deploy new Intune policies will apply to devices, based on the version of Android or iOS that is being run.

You are required to make sure that the policies are able to target the devices according to your plan.

Which of the following actions should you take?

A. You should start by accessing Intune and configuring corporate device identifiers.
B. You should start by accessing Microsoft Azure Active Directory (Azure AD) and configuring Device settings.
C. You should start by accessing Microsoft Azure Active Directory (Azure AD) and configuring Application settings.
D. You should start by creating a distribution group.

A

Answer: B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

You need to consider the underlined segment to establish whether it is accurate.

Your company has Microsoft Azure Active Directory (Azure AD) joined Windows 10 Pro computers that have been enrolled in Microsoft Intune.

You have been tasked with making sure that the computers are upgraded to Windows 10 Enterprise.

You start by configuring a device enrollment policy in Intune.

Select “No adjustment required” if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.

What should you configure in Intune?

A. No adjustment required
B. an app protection policy
C. a Windows AutoPilot deployment profile
D. A device configuration profile

A

Answer: D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Your company has a Microsoft 365 subscription.

You have enrolled all the company computers in Microsoft Intune.

You have been tasked with making sure that Microsoft Exchange Online is only accessible from known locations.

Which of the following actions should you take?

A. You should create a device configuration profile.
B. You should create a device compliance policy.
C. You should create a Windows AutoPilot deployment profile.
D. You should create a conditional access policy.

A

Answer: D

19
Q

Your company has a Microsoft 365 subscription.

You have enrolled all the company computers in Microsoft Intune.

You have been tasked with making sure that devices with a high Windows Defender Advanced Threat Protection (Windows Defender ATP) risk score are locked.

Which of the following actions should you take?

A. You should create a device configuration profile.
B. You should create a device compliance policy.
C. You should create a Windows AutoPilot deployment profile.
D. You should create a conditional access policy.

A

Answer: B

20
Q

Your company plans to deploy tablets to 50 meeting rooms.

The tablets run Windows 10 and are managed by using Microsoft Intune. The tablets have an application named App1.

You need to configure the tablets so that any user can use App1 without having to sign in. Users must be prevented from using other applications on the tablets.

Which device configuration profile type should you use?

A. Kiosk
B. Endpoint protection
C. Identity protection
D. Device restrictions

A

Answer: A

21
Q

All of your company’s devices are managed via Microsoft Intune.

conditional access is used to prevent devices that are not compliant with company security policies, from accessing Microsoft 365 services.

You need to access Device compliance to view the non-compliant devices. Where should you access Device compliance from?

A. System Center Configuration Manager
B. Windows Defender Security Center.
C. The Intune admin center.
D. The Azure Active Directory admin center.

A

Answer: C

22
Q

You manage a large number of Windows 10 computers.

You have been tasked with creating a provisioning package that will allow you to remove the Microsoft News and the Xbox Microsoft Store apps, as well as add a VPN connection to the company network.

Which of the following are the customization settings you should configure?

A. Connections and Personalization
B. ConnectivityProfiles and Policies
C. Connections and Policies
D. ConnectivityProfiles and Personalization

A

Answer: B

23
Q

All users at your company have Azure AD joined Windows 10 workstations that are managed via Microsoft Intune.

You have been tasked with making sure that Windows Analytics is used to monitor the workstations centrally.

Which of the following actions should you take?

A. You should create a device configuration profile via Intune.
B. You should create a device compliance policy via Intune.
C. You should create a Windows AutoPilot deployment profile via Intune.
D. You should create an app configuration policy via Intune.

A

Answer: A

24
Q

Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations. These workstations have been enrolled in Microsoft Intune.

You are creating a device configuration profile for the workstations. You have been informed that a custom image should be displayed on the sign-in screen.

Which of the following is a Device restriction setting that should be configured?

A. Locked screen experience
B. Personalization
C. Display
D. General

A

Answer: A

25
Q

Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations. These workstations have been enrolled in Microsoft Intune.

You are creating a device configuration profile for the workstations. You have been informed that a custom image should be displayed as the Desktop background picture.

Which of the following is a Device restriction setting that should be configured?

A. Locked screen experience
B. Personalization
C. Display
D. General

A

Answer: B

26
Q

Your company has a large number of Windows 10 workstations that are managed via Microsoft Intune.

Delivery Optimization is not being used for Windows updates at present.
You want to make sure that Delivery Optimization is configured for all of the workstations. Which of the following actions should you take?

A. You should create a device configuration profile via Intune.
B. You should create a device compliance policy via Intune.
C. You should create a Windows AutoPilot deployment profile via Intune.
D. You should create a conditional access policy via Intune.

A

Answer: A

27
Q

Your company’s environment includes the following:

  • Microsoft Azure Active Directory (Azure AD)
  • Microsoft 365
  • Microsoft Intune
  • Azure Information Protection.

A new security policy declares that enrollment for private devices in Intune is not required. However, to access corporate email information, users have to make use of a PIN for authentication purposes. Also, users are able to access corporate cloud services from their private iOS and Android devices. Furthermore, the copying corporate email information to a cloud storage service should not be allowed, unless users are copying the information to Microsoft OneDrive for Business.

You have to make sure that security policy is enforced. Which of the following actions should you take?

A. You should create a data loss prevention (DLP) policy.
B. You should create a device enrollment policy.
C. You should create an app protection policy.
D. You should create a Windows AutoPilot deployment profile.

A

Answer: C

28
Q

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations. These workstations have been enrolled in Microsoft Intune.

You have been tasked with making sure that the workstations are only able to run applications that you have explicitly permitted.

Solution: You make use of Windows Defender Antivirus. Does the solution meet the goal?

A. Yes
B. No

A

Answer: B

29
Q

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations. These workstations have been enrolled in Microsoft Intune.

You have been tasked with making sure that the workstations are only able to run applications that you have explicitly permitted.

Solution: You make use of Windows Defender SmartScreen. Does the solution meet the goal?

A. Yes
B. No

A

Answer: B

30
Q

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations. These workstations have been enrolled in Microsoft Intune.

You have been tasked with making sure that the workstations are only able to run applications that you have explicitly permitted.

Solution: You make use of Windows Defender Application Guard. Does the solution meet the goal?

A. Yes
B. No

A

Answer: A

31
Q

You are currently making use of the Antimalware Assessment solution in Microsoft Azure Log Analytics.

You have accessed the Protection Status dashboard and find that there is a device that has no real time protection.

Which of the following could be a reason for this occurring?

A. Windows Defender has been disabled.
B. You need to install the Azure Diagnostic extension.
C. Windows Defender Credential Guard is incorrectly configured.
D. Windows Defender System Guard is incorrectly configured.

A

Answer: A

32
Q

You are currently making use of the Antimalware Assessment solution in Microsoft Azure Log Analytics.

You have accessed the Protection Status dashboard and find that there is a device that is not reporting.

Which of the following could be a reason for this occurring?

A. Windows Defender System Guard is incorrectly configured.
B. You need to install the Azure Diagnostic extension.
C. Windows Defender Application Guard is incorrectly configured.
D. The Microsoft Malicious Software Removal tool is installed.

A

Answer: C

33
Q

You need to consider the underlined segment to establish whether it is accurate.

To enable Windows Defender Credential Guard on Windows 10 computers, the computers must have Hyper-V installed.

Select “No adjustment required” if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.

What should you install on the computers?

A. No adjustment required.
B. Windows Defender Smartscreen
C. a virtual machine
D. a container cluster

A

Answer: A

34
Q

You manage one hundred Microsoft Azure Active Directory (Azure AD) joined Windows 10 devices.

You want to make sure that users are unable to join their home PC’s to Azure AD. Which of the following actions should you take?

A. You should configure the Enrollment restriction settings via the Device enrollment blade in the Intune admin center.
B. You should configure the Enrollment restriction settings via the Security & Compliance admin center.
C. You should configure the Enrollment restriction settings via the Azure Active Directory admin center.
D. You should configure the Enrollment restriction settings via the Windows Defender Security Center.

A

Answer: A

35
Q

You need to consider the underlined segment to establish whether it is accurate.

To enable sideloading in Windows 10, you should navigate to the For developers setting via Update & Security in the Settings app.

Select “No adjustment required” if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.

A. No adjustment required.
B. Widows Insider
C. Delivery Optimization
D. Activation

A

Answer: A

36
Q

You need to consider the underlined segment to establish whether it is accurate.

To enable sideload a LOB application in Windows 10, you should run the Install-Package cmdlet.

Select “No adjustment required” if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.

A. No adjustment required.
B. Install-PackageProvider
C. Save-Package
D. Add-AppxPackage

A

Answer: D

37
Q

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

Your company’s environment includes a Microsoft 365 subscription.

Users in the company’s sales division have personal iOS or Android devices that are enrolled in Microsoft Intune. New users are added to the sales division on a monthly basis.

After a mobile application is created for users in the sales division, you are instructed to make sure that the application can only be downloaded by the sales division users

Solution: You start by adding the application to Microsoft Store for Business. Does the solution meet the goal?

A. Yes
B. No

A

Answer: B

38
Q

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

Your company’s environment includes a Microsoft 365 subscription.

Users in the company’s sales division have personal iOS or Android devices that are enrolled in Microsoft Intune. New users are added to the sales division on a monthly basis.

After a mobile application is created for users in the sales division, you are instructed to make sure that the application can only be downloaded by the sales division users

Solution: You start by assigning the application to a group. Does the solution meet the goal?

A. Yes
B. No

A

Answer: B

39
Q

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

Your company’s environment includes a Microsoft 365 subscription.

Users in the company’s sales division have personal iOS or Android devices that are enrolled in Microsoft Intune. New users are added to the sales division on a monthly basis.

After a mobile application is created for users in the sales division, you are instructed to make sure that the application can only be downloaded by the sales division users

Solution: You start by adding the application to Intune. Does the solution meet the goal?

A. Yes
B. No

A

Answer: A

40
Q

You company has a Microsoft Azure Active Directory (Azure AD) tenant that includes Microsoft Intune. All of the Windows 10 devices are enrolled in Intune.

You are preparing to configure a Windows Information Protection (WIP) policy:

You need to make sure that the policy is configured to allow for the logging of unacceptable data sharing, but not blocking the action.

Which of the following is the WIP protection mode that you should use?

A. Block
B. Silent
C. Off
D. Allow Overrides

A

Answer: B

41
Q

Your company has an Active Directory domain, named weylandindustries.com, and a Microsoft Office 365 subscription. The domain is also synced to Microsoft Azure Active Directory (Azure AD).

All company computers are domain-joined, and are running the most recent Microsoft OneDrive sync client.

You are currently configuring OneDrive group policy settings.

Which of the following is the setting that will minimize the disk space consumed by a user profile, when enabled?

A. OneDrive Files On-Demand
B. Silently move known folders to OneDrive
C. Prompt users to move Windows known folders to OneDrive
D. Silently configure OneDrive using the primary Windows account

A

Answer: A

42
Q

You manage your company’s Microsoft 365 subscription.

You are tasked with creating an app protection policy for the Microsoft Outlook app on iOS devices that are not enrolled in Microsoft 365 Device Management.

You have to make sure that the policy is configured to prohibit the users from using the Outlook app if the operating system version is less than 12.0.0. you also have to make sure that an alphanumeric passcode is required for users to access the Outlook app

Which of the following is policy settings that you should configure? (Choose two)

A. Conditional launch
B. Data transfer exemptions
C. Data protection
D. Access requirements

A

Answer: A, D

43
Q

You are responsible for your company’s Microsoft 365 environment, with co-management enabled.

All company computers have been deployed via Microsoft Deployment Toolkit (MDT) , and have Windows 10 installed.

You have been tasked devising a strategy for deploying Microsoft Office 365 ProPlus to new computers. You have to make sure that most recent version is installed at all times, while also reducing the effort required to meet the prerequisites.

Which of the following actions should you take?

A. You should make use of Windows Deployment Services (WDS).
B. You should make use of the Microsoft Deployment Toolkit
C. You should make use of the Office Deployment Tool (ODT).
D. You should make use of a Windows Configuration Designer provisioning package

A

Answer: C