Microsoft

MD-102 Free Practice Questions — Page 16

Question 157

HOTSPOT - You have a Microsoft 365 subscription that uses Microsoft Intune Suite. You use Intune to manage devices. You need to assess device performance during startup and identify any device models that take longer than average to start. What should you use to assess the device performance, and which portal should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 157
Show Answer
Correct Answer: Use: Endpoint analytics In portal: Microsoft Intune admin center
Explanation:
Endpoint analytics provides startup performance metrics and identifies slow-starting device models. It is accessed from the Microsoft Intune admin center.

Question 158

You have a Microsoft 365 subscription. You have devices enrolled in Microsoft Intune as shown in the following table. To which devices can you deploy apps by using Intune?

A. Device1 only
B. Device1 and Device2 only
C. Device1 and Device3 only
D. Device1, Device2, and Device3 only
E. Device1, Device2, Device3, and Device4
Show Answer
Correct Answer: D
Explanation:
Microsoft Intune supports app deployment to Windows, iOS/iPadOS, Android, and macOS devices. Linux device management does not include Intune app deployment in this context, so the Linux device is excluded.

Question 159

You have a Microsoft 365 subscription that contains 1,000 Android devices enrolled in Microsoft Intune. You create an app configuration policy that contains the following settings: • Device enrollment type: Managed devices • Profile Type: All Profile Types • Platform: Android Enterprise Which two types of apps can be associated with the policy? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

A. Android Enterprise system app
B. Web link
C. Android store app
D. Managed Google Play store app
E. Built-in Android app
Show Answer
Correct Answer: A, D
Explanation:
For an Android Enterprise app configuration policy targeting managed devices with Profile type set to All Profile Types, app configuration can be associated with Android Enterprise system apps and Managed Google Play store apps. Web links are not app targets for managed app configuration, Android store apps are the legacy app type rather than Android Enterprise managed apps, and built-in Android apps are not applicable to Android Enterprise managed app configuration.

Question 161

HOTSPOT - You have an Azure AD tenant named contoso.com that contains the devices shown in the following table. The tenant contains the Azure AD groups shown in the following table. You add an Autopilot deployment profile as shown in the following exhibit. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 161 Illustration for MD-102 question 161 Illustration for MD-102 question 161 Illustration for MD-102 question 161
Show Answer
Correct Answer: No No No
Explanation:
Device1 isn't Intune-enrolled, so 'Convert all targeted devices to Autopilot' won't automatically register it. Device2 is excluded by the assigned exclusion group. Restarting Device3 does not invoke Autopilot deployment; Autopilot applies during OOBE after reset/new provisioning, not a normal restart.

Question 162

HOTSPOT - You have devices enrolled in Microsoft Intune as shown in the following table. You need to identify the following: • Device you can remove from Intune by using the Wipe action. • The enrollment state and the associated user account can be retained on devices that are wiped. What should you identify? To answer, select the appropriate options in the answer area.

Illustration for MD-102 question 162 Illustration for MD-102 question 162
Show Answer
Correct Answer: Devices you can remove from Intune by using the Wipe action: Device1 and Device2 only The enrollment state and the associated user account can be retained on devices that are wiped: Device1 and Device2 only
Explanation:
Wipe isn't available for user-enrolled iOS devices or user-enrolled Android devices in this scenario. The 'retain enrollment state and user account' option is supported only for Windows 10/11 devices (Windows 10 version 1709+), so it applies only to the Windows devices shown.

Question 163

HOTSPOT - You have 100 computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune. You need to configure the following device restrictions: • Block users from browsing to suspicious websites. • Scan all scripts loaded into Microsoft Edge. Which two settings should you configure in the Device restrictions configuration profile? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 163
Show Answer
Correct Answer: Microsoft Defender SmartScreen: - Configure Microsoft Defender SmartScreen (block users from browsing to suspicious websites) Microsoft Defender Antivirus: - Enable script scanning (scan all scripts loaded into Microsoft Edge)
Explanation:
SmartScreen protects users from malicious/suspicious websites. Microsoft Defender Antivirus includes the 'Allow Script Scanning' setting, which scans scripts executed by browsers such as Microsoft Edge.

Question 164

HOTSPOT - You have two Windows 10 devices enrolled in Microsoft Intune as shown in the following table. The Compliance policy settings are configured as shown in the following exhibit. On August 1, you create a compliance policy as shown in the following exhibit. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 164 Illustration for MD-102 question 164 Illustration for MD-102 question 164 Illustration for MD-102 question 164
Show Answer
Correct Answer: No No No
Explanation:
Device1 is excluded from the assigned compliance policy and the tenant setting marks devices with no assigned compliance policy as Not Compliant. Device2 receives the policy but fails the BitLocker requirement, so it is not compliant (during the grace period it is in an In Grace Period/noncompliant state, not compliant). The retire action is not completed on Aug 6; retirement is a scheduled/admin-driven action after the noncompliance workflow, so the statement is false.

Question 165

HOTSPOT - You have a Microsoft 365 subscription that contains the devices shown in the following table. You plan to enroll the devices in Microsoft Intune. How often will the compliance policy check-ins run after each device is enrolled in Intune? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 165 Illustration for MD-102 question 165
Show Answer
Correct Answer: Device1: Every three minutes for 15 minutes, then every 15 minutes for two hours, and then every eight hours Device2: Every 15 minutes for one hour, and then every eight hours
Explanation:
Windows 10/11 devices perform more frequent initial check-ins (3 min, then 15 min, then ~8 hours). iOS devices check in every 15 minutes for the first hour, then approximately every 8 hours.

Question 166

You have 500 computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune. You plan to distribute certificates to the computers by using Simple Certificate Enrollment Protocol (SCEP). You have the servers shown in the following table. NDES issues certificates from the subordinate CA. You are configuring a device configuration profile as shown in the exhibit. (Click the Exhibit tab.) You need to complete the SCEP profile. On which server is the required root certificate located?

A. Server1
B. Server2
C. Server3
D. Server4
Show Answer
Correct Answer: B
Explanation:
In an Intune SCEP deployment, the SCEP profile references a Trusted Root Certificate profile that contains the root CA certificate establishing the trust chain. Even if NDES obtains certificates from the subordinate/issuing CA, client devices must trust the top-level root CA. Therefore the required root certificate is located on the Root CA server (Server2).

Question 167

You have devices enrolled in Microsoft Intune as shown in the following table. For which devices can you manage updates by using Intune?

A. Device1 only
B. Device1 and Device2 only
C. Device1 and Device3 only
D. Device1, Device3, and Device4 only
E. Device1, Device2, Device3, and Device4
Show Answer
Correct Answer: E
Explanation:
Based on current Microsoft Intune capabilities, update management is available across the listed major supported platforms (Windows, Android, iOS/iPadOS, and macOS), so all four enrolled devices can be managed for updates. Older study materials may differ due to historical feature availability, but with current Intune functionality the correct choice is all devices.

$19

Get all 373 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.