HOTSPOT
-
You have an Azure subscription that is linked to a Microsoft Entra tenant. The tenant contains the devices shown in the following table.
You install the Azure Monitor Agent on all supported devices.
You create a monitored object (MO) and associate the MO to a data collection rule (DCR) named DCR1.
You configure DCR1 as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Show Answer
Correct Answer: Device1 (CPU): No
Device2 (Memory): Yes
Device3 (CPU): No
Explanation: Azure Monitor Agent with DCR performance counters supports Windows devices that are Microsoft Entra joined or hybrid joined. Device1 is only Entra registered, so data isn’t collected. Device2 is Entra joined and supports memory counters. Android devices (Device3) aren’t supported for performance counter collection.
Question 115
You have a Microsoft 365 E5 subscription that contains the devices shown in the following table.
All the devices are enrolled in Microsoft Intune and have Microsoft 365 Apps for enterprise installed.
On which devices can you use the Cloud Policy service for Microsoft 365 to manage Microsoft 365 Apps for enterprise?
A. Device2 only
B. Device1 and Device2 only
C. Device1, Device2, and Device3 only
D. Device1, Device2, and Device4 only
E. Device1, Device2, Device3, and Device4
Show Answer
Correct Answer: E
Explanation: The Cloud Policy service for Microsoft 365 applies policies per user when they sign in to Microsoft 365 Apps for enterprise. It does not require devices to be domain-joined or fully managed. Policies can roam to devices running Windows, macOS, iOS, and Android as long as Microsoft 365 Apps for enterprise are installed and the user signs in. Therefore, all listed devices are supported.
Question 116
HOTSPOT
-
You have a Microsoft 365 E5 subscription that includes Microsoft Intune.
You need to configure a compliance policy for the iOS/iPadOS platform. The solution must meet the following requirements:
• Require jailbroken devices to be marked as noncompliant.
• Mark devices without a password lock as noncompliant.
Which compliance policy settings should you configure for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Require jailbroken devices to be marked as noncompliant:
Device Health
Require a password to unlock mobile devices:
System Security
Explanation: In Intune iOS/iPadOS compliance policies, jailbreak detection is configured under Device Health, while password/PIN requirements are configured under System Security.
Question 117
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You need to route Microsoft Intune logs to an Azure resource that supports the use of visuals, monitoring, and alerting.
Which settings should you configure in Intune, and which resource should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Settings: Diagnostic settings
Resource: A Log Analytics workspace
Explanation: Intune logs are routed via Azure Monitor by configuring Diagnostic settings in the Intune tenant. A Log Analytics workspace supports visualizations, monitoring, and alerting for these logs.
Question 118
You have a Microsoft 365 E5 subscription.
You need to configure the automated investigation and response (AIR) remediation level for a device named Device1 to require approval for all folders.
What should you create?
A. a security group
B. a device group
C. an administrative unit
D. an action group
Show Answer
Correct Answer: B
Explanation: In Microsoft Defender for Endpoint, Automated Investigation and Response (AIR) remediation levels are configured at the device group level. To require approval for all folders for a specific device, you must create a device group, set its automation level to "Require approval for all folders," and then add Device1 to that device group.
Question 119
HOTSPOT
-
You have a Microsoft 365 E5 subscription and use Microsoft Intune.
You purchase 50 Windows devices.
You configure automatic enrollment to Intune for Microsoft Entra joined devices.
You need to use a provisioning package to join the devices to Microsoft Entra.
What should you use to create the provisioning package, and what is the maximum amount of time you can use the package for bulk enrollment? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Use:
Windows Configuration Designer
Maximum amount of time:
180 days
Explanation: Provisioning packages for bulk Microsoft Entra (Azure AD) join are created using Windows Configuration Designer. The bulk enrollment token embedded in the package is valid for a maximum of 180 days.
Question 120
HOTSPOT
-
Your network contains an on-premises Active Directory Domain Services (AD DS) domain.
You have a Microsoft 365 E5 subscription that includes Microsoft Intune and syncs with the AD DS domain.
Windows Local Administrator Password Solution (Windows LAPS) is enabled in Microsoft Entra ID.
The subscription has the custom roles shown in the following table.
Microsoft Entra contains the users shown in the following table.
You have the devices shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User1 – No
User2 – No
User3 – Yes
Explanation: Only devices that back up LAPS to Microsoft Entra ID (Entra joined or Entra hybrid joined) can have passwords read from Entra. Reading the actual password requires microsoft.directory/deviceLocalCredentials/password/read. Device1 is AD DS–joined only, so Entra cannot read its LAPS password. User2 lacks the password/read permission. User3 has password/read permission and Device3 is Entra joined.
Question 121
HOTSPOT
-
You have a Microsoft 365 tenant that uses Microsoft Intune to manage the devices shown in the following table.
You need to deploy a compliance solution that meets the following requirements:
• Marks the devices as Not Compliant if they do not meet compliance policies
• Remotely locks noncompliant devices
What is the minimum number of compliance policies required, and which devices support the remote lock action? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Minimum number of compliance policies required:
4
Devices that support the remote lock action:
Device2, Device3, Device4, and Device5
Explanation: Intune compliance policies are platform-specific, requiring separate policies for Windows 10, Android device administrator, Android Enterprise, and iOS/iPadOS. The remote lock action is supported on Android (both administrator and Enterprise) and on iOS/iPadOS, but not on Windows 10 devices.
Question 122
HOTSPOT
-
You have a Microsoft Entra tenant that contains the devices shown in the following table.
The tenant contains the groups shown in the following table.
You create a Windows Autopilot deployment profile as shown in the Deployment Profile exhibit. (Click the Deployment Profile tab.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Device1: No
Device2: Yes
Device3: No
Explanation: The profile converts only targeted corporate devices to Autopilot. Device1 is personally owned, so it isn’t registered. Device2 is corporate-owned, Entra joined, included in Group1, and not excluded. Device3 is in the excluded Group2, which overrides inclusion, so it isn’t registered.
Question 123
You have a Microsoft 365 E5 subscription.
All devices are enrolled in Microsoft Intune.
You create a Conditional Access policy named Policy1 that requires multifactor authentication (MFA).
You need to ensure that Policy1 only applies to devices marked as noncompliant.
Which settings of Policy1 should you configure?
A. Device platforms under Conditions
B. Filter for devices under Conditions
C. Target resources
D. Grant
E. Session
Show Answer
Correct Answer: B
Explanation: To scope a Conditional Access policy so it applies only to devices marked as noncompliant, you must use **Conditions > Filter for devices** and create a rule based on the device compliance state (IsCompliant = false). The Grant controls enforce requirements (such as MFA) once the policy applies; they do not determine which devices the policy targets.
$19
Get all 373 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.