DRAG DROP
-
You have a Microsoft 365 E5 subscription that includes Microsoft Intune.
The subscription contains Android Enterprise devices that are enrolled in Intune and have personally-owned work profiles. All the Android devices are members of a group named Group1.
You need to ensure that end users and Intune administrators receive an email message when an Android device does NOT have an up-to-date security provider.
Which actions should you perform from the Microsoft Intune admin center in sequence? To answer, drag the appropriate actions to the correct order. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Step 1: From Compliance policies, create a notification message template.
Step 2: Create a compliance policy.
Step 3: Assign policy to Group1.
Explanation: Email notifications for noncompliance require a notification message template first. Then create a compliance policy that includes the security provider compliance setting and configures the notification action for noncompliance, then assign it to the target group.
Question 148
You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Azure AD joined and are enrolled in Microsoft Intune.
You plan to manage Microsoft Defender Antivirus on the computers.
You need to prevent users from disabling Microsoft Defender for Endpoint.
What should you do?
A. From the Microsoft Intune admin center, create an attack surface reduction (ASR) policy.
B. From the Microsoft 365 Defender portal, enable tamper protection.
C. From the Microsoft Intune admin center, create an account protection policy.
D. From the Microsoft Entra admin center, create a Conditional Access policy.
Show Answer
Correct Answer: B
Explanation: Tamper protection prevents users and malware from disabling or changing key Microsoft Defender Antivirus and Defender for Endpoint security settings. ASR policies reduce attack surface but do not prevent Defender from being turned off. Account protection policies manage identity-related protections, and Conditional Access controls access to resources rather than local antivirus settings.
Question 149
HOTSPOT
-
Your company has computers that run Windows 10 and are Microsoft Entra joined.
The company purchases an Azure subscription.
You need to collect Windows events from the Windows 10 computers in Azure. The solution must enable you to create alerts based on the collected events.
What should you create in Azure and what should you configure on the computers? To answer, select the appropriate options in the answer area.
Show Answer
Correct Answer: Resource to create in Azure: An Azure Log Analytics workspace
Configuration on the computers: Install the Azure Monitor Agent
Explanation: Windows event collection and alerting in Azure Monitor uses a Log Analytics workspace as the destination. Windows 10 devices send events by installing the Azure Monitor Agent (typically with a Data Collection Rule) to collect and forward Windows Event Logs.
Question 150
HOTSPOT
-
Your network contains an Active Directory domain.
The domain contains four computers named Computer1, Computer2, Computer3, and Computer4 that run Windows 10.
You perform the following actions:
• On Computer1, you install Windows Admin Center and configure Windows Defender Firewall to allow incoming communication over TCP ports 80,443, and 6516.
• On Computer2, you run the Enable-PSRemoting cmdlet.
• On Computer3, you configure Windows Defender Firewall to allow Windows Remote Management (WinRM) traffic.
• On Computer4, you run the winrm quickconfig command.
You need to manage the computers remotely by using Windows Admin Center.
From which computers can you connect to Windows Admin Center, and which computers can you manage by using Windows Admin Center? To answer, select the appropriate options in the answer are.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Connect from: Computer1 only
Manage: Computer1, Computer2, and Computer4 only
Explanation: Windows Admin Center installed on Windows 10 is accessed locally from that client only. Computer2 (Enable-PSRemoting) and Computer4 (winrm quickconfig) enable and start WinRM. Computer3 only opens the firewall but does not enable/start WinRM, so it cannot be managed.
Question 151
You have a Hyper-V host. The host contains virtual machines that run Windows 10 as shown in following table.
Which virtual machines can be upgraded to Windows 11?
A. VM1 only
B. VM2 only
C. VM2 and VM3 only
D. VM1, VM2, and VM3
Show Answer
Correct Answer: B
Explanation: Windows 11 on Hyper-V requires a Generation 2 VM with Secure Boot, TPM 2.0, and minimum hardware such as at least 2 virtual processor cores. Based on the described options, only VM2 meets the requirements. VM1 lacks the necessary Generation 2/TPM support, and VM3 does not meet the processor requirement.
Question 152
You have a Microsoft 365 subscription that uses Microsoft Intune Suite.
You use Intune to manage all devise.
Users have iOS devices with Microsoft apps installed.
You need to prevent users from cutting, copying, and pasting data between Microsoft Excel and other apps installed on the devices.
What should you configure?
A. an app protection policy
B. an app configuration policy
C. an iOS app provisioning profile
D. policies for Microsoft Office apps
Show Answer
Correct Answer: A
Explanation: App protection policies (Intune MAM) control data protection settings for managed apps, including restricting cut, copy, and paste between Microsoft apps and other apps on iOS. App configuration policies configure app settings, provisioning profiles handle iOS app signing/deployment, and Office app policies do not provide the Intune data transfer controls required.
Question 153
You have a Microsoft 365 subscription that uses Microsoft Intune Suite.
You use Intune to manage devices.
You need to review details about device wipes initiated through Intune.
Which report should you review?
A. Noncompliant devices
B. Assignment status
C. Windows health attestation report
D. Device actions
Show Answer
Correct Answer: D
Explanation: The Device actions report in Intune provides a history and status of remote actions initiated against managed devices, including wipe, retire, restart, sync, and similar actions. The other reports focus on compliance, assignment status, or Windows health attestation rather than administrative wipe operations.
Question 154
You have a Microsoft 365 subscription. The subscription contains 500 computers that run Windows 11 and are enrolled in Microsoft Intune.
You need to manage the deployment of monthly security updates. The solution must meet the following requirements:
• Updates must be deployed to a group of test computers for quality assurance.
• Updates must be deployed automatically 15 days after the quality assurance testing.
What should you create in the Microsoft Intune admin center?
A. a device configuration profile
B. a feature update policy
C. a security baseline
D. an update ring
Show Answer
Correct Answer: D
Explanation: Update rings in Microsoft Intune are designed to manage the deployment of Windows quality (monthly security) updates using staged deployments. You can create separate update rings for a pilot/test group and for production, configuring the production ring with a 15-day quality update deferral so updates are deployed automatically after the testing period. Feature update policies manage Windows feature version upgrades, not monthly security updates. Device configuration profiles and security baselines are not the primary mechanism for staged Windows Update deployment.
Question 155
DRAG DROP
-
Your on-premises network contains an Active Directory Domain Services (AD DS) domain.
You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains five virtual machines and is NOT connected to the on-premises network.
You have a Microsoft 365 subscription that uses Microsoft Intune Suite.
You purchase Windows 365 Enterprise licenses.
You need to deploy Cloud PC. The solution must meet the following requirements:
• All users must be able to access their Cloud PC at any time without any restrictions.
• The users must be able to connect to the virtual machines on VNet1.
How should you configure the provisioning policy for Windows 365? To answer, drag the appropriate options to the correct settings. Each option may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Explanation: Hybrid Join requires line-of-sight to an on-premises domain controller, but VNet1 is not connected to the on-premises network. To allow Cloud PCs to access VMs in VNet1, use an Azure network connection. Enterprise licensing satisfies the requirement for unrestricted, always-available user access; Frontline is intended for shared usage.
Question 156
HOTSPOT
-
You have a Microsoft 365 E5 subscription that uses Microsoft Intune. The subscription contains the resources shown in the following table.
User1 is the owner of Device1.
You deploy Microsoft 365 Apps Windows 10 and later app types to Intune as shown in the following table.
The next day you review the results of the app deployments.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
Yes
Explanation: User1 is targeted by the required Word app through the user group, Device1 is targeted by the required Excel app through the device group, and the app is configured to show in the Company Portal.
$19
Get all 373 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.