Microsoft

MD-102 Free Practice Questions — Page 18

Question 178

DRAG DROP - You have an on-premises Active Directory domain that syncs to Azure AD tenant. The tenant contains computers that run Windows 10. The computers are hybrid Azure AD joined and enrolled in Microsoft Intune. The Microsoft Office settings on the computers are configured by using a Group Policy Object (GPO). You need to migrate the GPO to Intune. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Illustration for MD-102 question 178
Show Answer
Correct Answer: Create a configuration profile. Configure the Administrative Templates settings. Assign the profile.
Explanation:
To migrate GPO-based Office settings to Intune, you first create a device configuration profile. Within that profile, you configure the equivalent Administrative Templates (which map to GPO settings). Finally, you assign the profile to the target devices or users so the settings are applied.

Question 179

HOTSPOT - You have an Azure AD Premium P2 subscription that contains the users shown in the following table. You purchase the devices shown in the following table. You configure automatic mobile device management (MDM) and mobile application management (MAM) enrollment by using the following settings: • MDM user scope: Group1 • MAM user scope: Group2 For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 179 Illustration for MD-102 question 179 Illustration for MD-102 question 179
Show Answer
Correct Answer: Yes No No
Explanation:
Automatic MDM enrollment applies only to Windows devices and only for users included in the MDM user scope. User1 is in Group1 (MDM scope) and Device1 is Windows 10 → automatic enrollment works. Android devices do not support automatic MDM enrollment. User2 is not in the MDM user scope (only MAM), so automatic enrollment does not apply even for Windows devices.

Question 181

You have a Microsoft 365 E5 subscription. You need to download a report that lists all the devices that are NOT enrolled in Microsoft Intune and are assigned an app protection policy. What should you select in the Microsoft Intune admin center?

A. Reports, and then Device compliance
B. Apps, and then App protection policies
C. Devices, and then Monitor
D. Apps, and then Monitor
Show Answer
Correct Answer: D
Explanation:
The required report is available under **Apps > Monitor > App protection status**. This monitoring view provides downloadable reports and includes the **Management type** column, which distinguishes **managed (enrolled)** versus **unmanaged (not enrolled)** devices that are assigned app protection policies. Other sections either focus on device compliance/enrollment or only show policy configuration, not device-level APP status.

Question 182

You have a Microsoft 365 subscription. You use app protection policies to protect corporate data on Android devices. You need to ensure that any user connecting from an Android device can only access the corporate data if they connect from an app that supports mobile application management (MAM). What should you configure?

A. an app configuration policy
B. a Conditional Access policy
C. a device configuration profile
D. a device compliance policy
Show Answer
Correct Answer: B
Explanation:
To ensure users can access corporate data only through apps that support Mobile Application Management (MAM) on Android, you must enforce app-based access conditions. This is done with a Microsoft Entra Conditional Access policy configured with the grant control **Require app protection policy**. Conditional Access integrates with Intune app protection policies to block access from unmanaged or non-MAM-supported apps. App configuration policies, device configuration profiles, and device compliance policies do not enforce app-level access conditions for unmanaged devices.

Question 183

HOTSPOT - You have a Microsoft 365 E5 subscription. You create an app protection policy for Android device named Policy1 as shown in the following exhibit. Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 183 Illustration for MD-102 question 183
Show Answer
Correct Answer: Install the Company Portal app on the device Users only
Explanation:
Android app protection policies for unmanaged devices require the Company Portal to enforce MAM policies. App protection policies target user identities, so assignments apply to users rather than devices.

Question 184

Case study - Overview - ADatum Corporation is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. ADatum has a Microsoft 365 E5 subscription. Environment - Network Environment - The network contains an on-premises Active Directory domain named adatum.com. The domain contains the servers shown in the following table. ADatum has a hybrid Azure AD tenant named adatum.com. Users and Groups - The adatum.com tenant contains the users shown in the following table. All users are assigned a Microsoft Office 365 license and an Enterprise Mobility + Security E3 license. Enterprise State Roaming is enabled for Group1 and GroupA. Group1 and Group2 have a Membership type of Assigned. Devices - ADatum has the Windows 10 devices shown in the following table. The Windows 10 devices are joined to Azure AD and enrolled in Microsoft Intune. The Windows 10 devices are configured as shown in the following table. All the Azure AD joined devices have an executable file named C:\AppA.exe and a folder named D:\Folder1. Microsoft Intune Configuration - Microsoft Intune has the compliance policies shown in the following table. The Automatic Enrollment settings have the following configurations: • MDM user scope: GroupA • MAM user scope: GroupB You have an Endpoint protection configuration profile that has the following Controlled folder access settings: • Name: Protection1 • Folder protection: Enable • List of apps that have access to protected folders: C:\*\AppA.exe • List of additional folders that need to be protected: D:\Folder1 • Assignments: - Included groups: Group2, GroupB Windows Autopilot Configuration - ADatum has a Windows Autopilot deployment profile configured as shown in the following exhibit. Currently, there are no devices deployed by using Windows Autopilot. The Intune connector for Active Directory is installed on Server1. Requirements - Planned Changes - ADatum plans to implement the following changes: • Purchase a new Windows 10 device named Device6 and enroll the device in Intune • New computers will be deployed by using Windows Autopilot and will be hybrid Azure AD joined. • Deployed a network boundary configuration profile that will have the following settings: - Name: Boundary1 - Network boundary: 192.168.1.0/24 - Scope tags: Tag1 - Assignments: - Included groups: Group1, Group2 • Deploy two VPN configuration profiles named Connection1 and Connection2 that will have the following settings: - Name: Connection1 - Connection name: VPN1 - Connection type: L2TP - Assignments: - Included groups: Group1, Group2, GroupA - Excluded groups: -- - Name: Connection2 - Connection name: VPN2 - Connection type: IKEv2 - Assignments: - Included groups: GroupA - Excluded groups: GroupB Technical Requirements - ADatum must meet the following technical requirements: • Users in GroupA must be able to deploy new computers. • Administrative effort must be minimized. Which user can enroll Device6 in Intune?

A. User4 and User1 only
B. User4 and User2 only
C. User4, User1, and User2 only
D. User1, User2, User3, and User4
Show Answer
Correct Answer: A
Explanation:
Only users within the MDM user scope (GroupA) or with tenant-wide administrative privileges can enroll devices into Intune. The MDM user scope is explicitly limited to GroupA, which includes User1 (but not User2). User2 is only in the MAM scope and therefore cannot enroll devices into Intune. User3 lacks sufficient administrative rights. User4 is a Global Administrator and can always enroll devices regardless of MDM scope. Therefore, only User1 and User4 can enroll Device6.

Question 186

HOTSPOT - Your company uses Microsoft Defender for Endpoint. Microsoft Defender for Endpoint includes the device groups shown in the following table. You onboard a computer to Microsoft Defender for Endpoint as shown in the following exhibit. What is the effect of the Microsoft Defender for Endpoint configuration? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 186 Illustration for MD-102 question 186 Illustration for MD-102 question 186
Show Answer
Correct Answer: Computer1 will be a member of: Group3 only If you add the tag demo to Computer1, Computer1 will be a member of: Group1 only
Explanation:
Microsoft Defender for Endpoint device groups are rank-based. If a device matches multiple groups, it is added only to the highest-ranked group. Initially, Computer1 matches Group3 (domain = adatum.com), Group4, and Group5, but Group3 has the highest rank. After adding the tag demo, the device also matches Group1 and Group2, and Group1 has the highest rank overall.

Question 187

You have a computer named Computer5 that has Windows 10 installed. You create a Windows PowerShell script named config.ps1. You need to ensure that config.ps1 runs after feature updates are installed on Computer5. Which file should you modify on Computer5?

A. LiteTouch.wsf
B. SetupConfig.ini
C. Unattend.bat
D. Unattend.xml
Show Answer
Correct Answer: B
Explanation:
Windows feature updates support running custom scripts by configuring SetupConfig.ini, which is read by Windows Setup during feature update installation. By modifying SetupConfig.ini, you can specify commands or scripts (such as a PowerShell .ps1 file) to run after the feature update completes. The other files listed are used for deployment scenarios like MDT (LiteTouch.wsf) or unattended OS installation (Unattend.xml / Unattend.bat), not for post–feature update actions.

Question 188

HOTSPOT - You have a Microsoft 365 subscription. Users have iOS devices that are not enrolled in Microsoft Intune. You create an app protection policy for the Microsoft Outlook app as shown in the exhibit. (Click the Exhibit tab.) You need to configure the policy to meet the following requirements: • Prevent the users from using the Outlook app if the operating system version is less than 12.0.0. • Require the users to use an alphanumeric passcode to access the Outlook app. What should you configure in an app protection policy for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 188 Illustration for MD-102 question 188
Show Answer
Correct Answer: Conditional launch Access requirements
Explanation:
Minimum OS version enforcement is configured under Conditional launch. Requiring an alphanumeric passcode (PIN type) is configured under Access requirements.

Question 189

HOTSPOT - You use the Microsoft Deployment Toolkit (MDT) to deploy Windows 11. You need to modify the deployment share to meet the following requirements: • Ensure that the user who performs the installation is prompted to set the local Administrator password • Define a rule for how to name computers during the deployment. The solution must NOT replace the existing WinPE image. Which file should you modify for each requirement? To answer, select the appropriate options in the answer area, NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 189
Show Answer
Correct Answer: Administrator password: CustomSettings.ini Computer names: CustomSettings.ini
Explanation:
In MDT, deployment rules are defined in CustomSettings.ini. It controls user prompts such as the local Administrator password (via SkipAdminPassword/related rules) and computer naming (e.g., OSDComputerName). Modifying this file does not require regenerating or replacing the WinPE image.

$19

Get all 373 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.