Microsoft

MD-102 Free Practice Questions — Page 16

Question 155

HOTSPOT - You have a Microsoft 365 E5 subscription that uses Microsoft Intune. The subscription contains the resources shown in the following table. User1 is the owner of Device1. You deploy Microsoft 365 Apps Windows 10 and later app types to Intune as shown in the following table. The next day you review the results of the app deployments. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 155 Illustration for MD-102 question 155 Illustration for MD-102 question 155
Show Answer
Correct Answer: Yes No Yes
Explanation:
App1 is configured to show in the Company Portal. Word (App1) is assigned as Required to a user group, not the device group containing Device1, so it isn’t installed on Device1. Excel (App2) is assigned as Required to the device group that includes Device1, so it is installed.

Question 156

HOTSPOT - You have a Microsoft 365 subscription that uses Microsoft Intune Suite. You use Intune to manage devices. You need to assess device performance during startup and identify any device models that take longer than average to start. What should you use to assess the device performance, and which portal should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 156
Show Answer
Correct Answer: Endpoint analytics Microsoft Intune admin center
Explanation:
Endpoint analytics provides startup performance metrics and device model comparisons. It is accessed and managed through the Microsoft Intune admin center.

Question 157

You have a Microsoft 365 subscription. You have devices enrolled in Microsoft Intune as shown in the following table. To which devices can you deploy apps by using Intune?

A. Device1 only
B. Device1 and Device2 only
C. Device1 and Device3 only
D. Device1, Device2, and Device3 only
E. Device1, Device2, Device3, and Device4
Show Answer
Correct Answer: D
Explanation:
Intune supports app deployment to Windows, iOS/iPadOS, Android, and macOS devices. Linux devices can be enrolled for compliance reporting but do not support app deployment. Therefore, apps can be deployed only to Device1, Device2, and Device3, not Device4.

Question 158

You have a Microsoft 365 subscription that contains 1,000 Android devices enrolled in Microsoft Intune. You create an app configuration policy that contains the following settings: • Device enrollment type: Managed devices • Profile Type: All Profile Types • Platform: Android Enterprise Which two types of apps can be associated with the policy? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

A. Android Enterprise system app
B. Web link
C. Android store app
D. Managed Google Play store app
E. Built-in Android app
Show Answer
Correct Answer: A, D
Explanation:
An app configuration policy targeting Android Enterprise managed devices can only be associated with apps that support managed configurations through Android Enterprise. Android Enterprise system apps support managed configurations on fully managed or dedicated devices, and Managed Google Play store apps are designed to receive and use these configurations. Web links, Android store apps (non‑managed), and built‑in Android apps do not support this type of Intune app configuration policy.

Question 160

HOTSPOT - You have an Azure AD tenant named contoso.com that contains the devices shown in the following table. The tenant contains the Azure AD groups shown in the following table. You add an Autopilot deployment profile as shown in the following exhibit. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 160 Illustration for MD-102 question 160 Illustration for MD-102 question 160 Illustration for MD-102 question 160
Show Answer
Correct Answer: Device1: No Device2: No Device3: Yes
Explanation:
Device1 isn’t enrolled in Intune, so it can’t be automatically converted to Autopilot on reset. Device2 is explicitly excluded from the Autopilot profile via Group2, so reset won’t trigger Autopilot. Device3 is already enrolled in Intune, included in the profile, and restarting is sufficient for the self-deploying Autopilot profile to apply.

Question 161

HOTSPOT - You have devices enrolled in Microsoft Intune as shown in the following table. You need to identify the following: • Device you can remove from Intune by using the Wipe action. • The enrollment state and the associated user account can be retained on devices that are wiped. What should you identify? To answer, select the appropriate options in the answer area.

Illustration for MD-102 question 161 Illustration for MD-102 question 161
Show Answer
Correct Answer: Devices you can remove using Wipe: Device1, Device2, Device3, and Device4 Enrollment state and associated user account can be retained: Device1 and Device2 only
Explanation:
The Wipe action is supported across Windows, iOS/iPadOS, and Android platforms listed, so all devices can be wiped. Retaining enrollment state and the associated user account is only supported on Windows 10/11 (version 1709 or later), which applies to the Windows devices only.

Question 162

HOTSPOT - You have 100 computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune. You need to configure the following device restrictions: • Block users from browsing to suspicious websites. • Scan all scripts loaded into Microsoft Edge. Which two settings should you configure in the Device restrictions configuration profile? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 162
Show Answer
Correct Answer: Microsoft Defender SmartScreen Microsoft Defender Antivirus
Explanation:
SmartScreen blocks access to malicious and suspicious websites. Microsoft Defender Antivirus integrates with Microsoft Edge (AMSI) to scan scripts loaded by the browser.

Question 163

HOTSPOT - You have two Windows 10 devices enrolled in Microsoft Intune as shown in the following table. The Compliance policy settings are configured as shown in the following exhibit. On August 1, you create a compliance policy as shown in the following exhibit. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 163 Illustration for MD-102 question 163 Illustration for MD-102 question 163 Illustration for MD-102 question 163
Show Answer
Correct Answer: No Yes No
Explanation:
Device1 is excluded from the compliance policy and devices without an assigned policy are treated as not compliant. Device2 receives the policy and is within the grace period on August 2, so it isn’t yet marked noncompliant. Retirement occurs after the device has been marked noncompliant for the configured duration, which is later than August 6.

Question 164

HOTSPOT - You have a Microsoft 365 subscription that contains the devices shown in the following table. You plan to enroll the devices in Microsoft Intune. How often will the compliance policy check-ins run after each device is enrolled in Intune? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 164 Illustration for MD-102 question 164
Show Answer
Correct Answer: Device1: Every three minutes for 15 minutes, then every 15 minutes for two hours, and then every eight hours Device2: Every 15 minutes for one hour, and then every eight hours
Explanation:
After enrollment, Intune runs compliance check-ins more frequently. Windows 10 devices follow the rapid 3-minute/15-minute schedule before settling to ~8 hours, while iOS devices check every 15 minutes for the first hour and then approximately every 8 hours.

Question 165

You have 500 computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune. You plan to distribute certificates to the computers by using Simple Certificate Enrollment Protocol (SCEP). You have the servers shown in the following table. NDES issues certificates from the subordinate CA. You are configuring a device configuration profile as shown in the exhibit. (Click the Exhibit tab.) You need to complete the SCEP profile. On which server is the required root certificate located?

A. Server1
B. Server2
C. Server3
D. Server4
Show Answer
Correct Answer: B
Explanation:
In an Intune SCEP deployment, devices must trust the root of the certificate chain, not the issuing (subordinate) CA. Although NDES issues certificates from the subordinate CA, the SCEP profile’s **Root Certificate** setting refers to the top-level trusted root CA certificate that anchors the chain of trust. Therefore, the required root certificate is located on the Root CA server, which is Server2.

$19

Get all 373 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.