Microsoft

MD-102 Free Practice Questions — Page 10

Question 93

You have a Microsoft Entra tenant that contains the devices shown in the following table. On which devices can you implement Endpoint Privilege Management (EPM)?

A. Device1 only
B. Device1 and Device2 only
C. Device1 and Device3 only
D. Device1, Device3, and Device4 only
E. Device1, Device2, Device3, and Device4
Show Answer
Correct Answer: A
Explanation:
Endpoint Privilege Management (EPM) requires devices to be running Windows 10 or Windows 11, be Microsoft Entra joined or Microsoft Entra hybrid joined (not merely registered/workplace-joined), and be enrolled in Microsoft Intune or co-managed. Based on the device properties, only Device1 meets all of these requirements. The other devices fail due to unsupported join type, lack of Intune enrollment, or unsupported operating system. Therefore, EPM can be implemented on Device1 only.

Question 94

HOTSPOT - You have a hybrid environment that contains a Microsoft Entra tenant and an on-premises Active Directory Domain Services (AD DS) domain. The environment contains the devices shown in the following table. Which Microsoft Entra join type can each device use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 94 Illustration for MD-102 question 94
Show Answer
Correct Answer: Device1: Microsoft Entra registered, Microsoft Entra joined, or Microsoft Entra hybrid joined Device2: Microsoft Entra registered only
Explanation:
Windows 11 devices can support all three Entra join types, including hybrid join if they are (or can be) domain-joined to on-prem AD DS. iOS devices do not support Entra join or hybrid join and can only be Entra registered.

Question 95

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the devices shown in the following table. The subscription contains the dynamic device groups shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 95 Illustration for MD-102 question 95 Illustration for MD-102 question 95
Show Answer
Correct Answer: No Yes Yes
Explanation:
Group1 requires Windows + deviceTrustType = AzureAD (Entra joined). Group2 requires deviceTrustType = Workplace (Entra registered). Device1 is Hybrid joined (ServerAD) → matches neither group. Device2 is Entra joined Windows → matches Group1; not Workplace. Device3 is Entra registered (Workplace) → matches Group2.

Question 96

You have a Microsoft 365 E5 subscription that contains devices enrolled in Microsoft Intune. You plan to use Device query to provide on-demand information about the state of the devices. The solution must minimize costs. What should you do first?

A. Use the Collect diagnostics remote action.
B. Purchase the Intune Advanced Analytics add-on.
C. Purchase the Intune Suite add-on.
D. Onboard the devices to Endpoint analytics.
Show Answer
Correct Answer: B
Explanation:
Device query requires Microsoft Intune Advanced Analytics. A Microsoft 365 E5 subscription includes Endpoint Analytics but does not include Advanced Analytics. To enable Device query while minimizing cost, you should purchase the Intune Advanced Analytics add-on rather than the more expensive Intune Suite. Onboarding to Endpoint Analytics alone is insufficient without the required Advanced Analytics license.

Question 97

You have a Microsoft 365 subscription and use Microsoft Intune Suite. The subscription contains devices enrolled in Intune as shown in the following table. Which devices support Device query?

A. Device1 only
B. Device2 only
C. Device1 and Device2 only
D. Device1, Device2, Device3, and Device4
Show Answer
Correct Answer: A
Explanation:
Device query in Microsoft Intune (part of Intune Advanced Analytics / Intune Suite) is currently supported only on corporate-owned, Intune-managed Windows 10 or later devices that are Microsoft Entra joined or hybrid joined and enrolled in Endpoint Analytics. Microsoft Entra registered (workplace-joined) devices are not supported, and non-Windows platforms such as iOS and Android are not supported. Based on these requirements, only Device1 meets all criteria.

Question 98

HOTSPOT - You have a Microsoft 365 E5 subscription and use Microsoft Intune. You need to deploy new Android devices as shown in the following table. Which enrollment profile should you use for each device? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 98 Illustration for MD-102 question 98
Show Answer
Correct Answer: Device1: Corporate-owned dedicated devices Device2: Corporate-owned, fully managed user devices Device3: Corporate-owned devices with work profile
Explanation:
Device1 is shared by shift workers for a single task, which fits Android Enterprise dedicated (kiosk/shared) devices. Device2 is assigned to one user for work only, requiring full device management. Device3 must support both work and personal use and allow QR-code enrollment, which is provided by corporate-owned devices with a work profile (COPE).

Question 99

DRAG DROP - You have a Microsoft 365 subscription. You plan to enroll devices in Microsoft Intune. You need to meet the following requirements: • Only allow the enrollment of devices that have a specific international mobile equipment identifier (IMEI). • Support the enrollment and management of up to 1,000 devices. Which enrollment setting should you configure for each requirement? To answer, drag the appropriate settings to the correct requirements. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 99
Show Answer
Correct Answer: Corporate device identifiers Device enrollment managers
Explanation:
Corporate device identifiers let you restrict enrollment to devices with pre-registered IMEI numbers. Device enrollment managers can enroll and manage up to 1,000 devices per account.

Question 100

HOTSPOT - You have a Microsoft 365 subscription that includes Microsoft Intune and Microsoft Defender for Endpoint. Users have devices that run Windows 11. You deploy a connection from Defender for Endpoint to Intune. You need to ensure that when a device is enrolled in Intune, the device is onboarded automatically to Defender for Endpoint. What should you configure, and which portal should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 100
Show Answer
Correct Answer: Configure: An endpoint detection and response (EDR) profile In portal: Microsoft Intune admin center
Explanation:
When Microsoft Defender for Endpoint is connected to Intune, Windows 11 devices are automatically onboarded by deploying an EDR profile from Intune. This built-in EDR policy handles the Defender onboarding without requiring a separate onboarding package or use of the Defender portal.

Question 101

HOTSPOT - You have a Microsoft Entra tenant that contains the users shown in the following table. When you sign in to the tenant, the available verification methods are shown in the following exhibit. Which users will be prompted for the verification code method, and which users will be prompted for the text method? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 101 Illustration for MD-102 question 101 Illustration for MD-102 question 101
Show Answer
Correct Answer: Verification code: User3 and User4 only Text: User1 only
Explanation:
Verification code appears for users with authenticator/OATH-based methods available at sign-in (User3 and User4). Text (SMS) appears only for users with a registered mobile phone number and no stronger default prompt, which applies to User1.

Question 102

DRAG DROP - You have a Microsoft 365 subscription that contains the following devices enrolled in Microsoft Intune: • A corporate-owned Windows device named Device1 • A personally-owned Android device named Device2 You need to use a remote action on each device. The solution must meet the following requirements: • Repurpose Device1 by returning the device to the factory default settings. • Remove only corporate data from Device2 and remove the device from Intune when the device checks in. Which remote action should you use on each device? To answer, drag the appropriate remote actions to the correct devices. Each remote action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

Illustration for MD-102 question 102
Show Answer
Correct Answer: Device1: Wipe Device2: Retire
Explanation:
Wipe resets a corporate Windows device to factory default settings, which is required for repurposing. Retire removes only corporate data from a personally owned Android device and unenrolls it from Intune when the device next checks in.

$19

Get all 373 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.