You plan to deploy Windows 11 Pro to 200 new computers by using the Microsoft Deployment Toolkit (MDT) and Windows Deployment Services (WDS).
The company has a Volume Licensing Agreement and uses a product key to activate Windows 11.
You need to ensure that the new computers will be configured to have the correct product key during the installation.
What should you configure?
A. an MDT task sequence
B. the Device settings in Azure AD
C. a WDS boot image
D. a Windows Autopilot deployment profile
Show Answer
Correct Answer: A
Explanation: In MDT deployments, the Windows product key is configured as part of the deployment task sequence (or associated deployment rules/settings used by the task sequence). WDS is used to provide PXE boot images, not to inject product keys. Azure AD device settings and Windows Autopilot profiles are not used for an MDT/WDS-based Windows installation using volume licensing.
Question 193
HOTSPOT
-
Your company has an infrastructure that has the following:
• A Microsoft 365 tenant
• An Active Directory forest
• Microsoft Intune
• A Key Management Service (KMS) server
• A Windows Deployment Services (WDS) server
• An Azure AD Premium tenant
The company purchases 100 new client computers that run Windows.
You need to ensure that the new computers are joined automatically to Azure AD by using Windows Autopilot.
What should you use? To answer, select the appropriate options in the answer area,
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Management tool: Microsoft Intune admin center
Required information from each computer: Device serial number and hardware hash
Explanation: Windows Autopilot device registration is performed through Microsoft Intune (or Microsoft Entra integration), and importing devices requires the device serial number and hardware hash (hardware ID). This enables automatic Azure AD join during Autopilot provisioning.
Question 194
Your network contains an Active Directory domain named contoso.com. The domain contains 25 computers that run Windows 11.
You have a Microsoft 365 subscription
You have an Azure AD tenant that syncs with contoso.com.
You configure hybrid Azure AD join and discover that some of the computers have a registered state of Pending.
You need to ensure that the computers complete the join successfully.
What should you ensure?
A. that Windows is activated on all the computers
B. that the users of the computers are assigned Microsoft 365 licenses
C. that each computer has a line of sight to a domain controller
D. that the computers contain the latest quality updates
Show Answer
Correct Answer: C
Explanation: Devices in a Pending state during Microsoft Entra (Azure AD) hybrid join typically need connectivity to an on-premises domain controller to complete the device registration process. Hybrid-joined devices rely on domain connectivity for the scheduled registration task and related authentication. Windows activation, Microsoft 365 user licenses, and latest quality updates are not prerequisites for completing hybrid Azure AD join.
Question 195
You have a Microsoft 365 tenant that contains the devices shown in the following table.
The devices are managed by using Microsoft Intune.
You create a compliance policy named Policy1 and assign Policy1 to Group1. Policy1 is configured to mark a device as Compliant only if the device security settings match the settings specified in the policy.
You discover that devices that are not members of Group1 are shown as Compliant.
You need to ensure that only devices that are assigned a compliance policy can be shown as Compliant. All other devices must be shown as Not compliant.
What should you do from the Microsoft Intune admin center?
A. From Device compliance, configure the Compliance policy settings.
B. From Endpoint security, configure the Conditional access settings.
C. From Tenant administration, modify the Diagnostic settings.
D. From Policy1, modify the actions for noncompliance.
Show Answer
Correct Answer: A
Explanation: The required setting is a tenant-wide compliance policy setting, not an individual compliance policy action. In Microsoft Intune, under Device compliance > Compliance policy settings, change 'Mark devices with no compliance policy assigned as' from 'Compliant' to 'Not compliant'. This ensures devices that are not assigned any compliance policy are reported as Not compliant. The 'Actions for noncompliance' setting only applies to devices targeted by a specific compliance policy and does not affect untargeted devices.
Question 196
You have a Microsoft 365 subscription that uses Microsoft Intune Suite.
You use Microsoft Intune to manage Windows 11 devices.
You create a new policy set named Set and add five device configuration profiles for Windows 10 and later.
You create a device compliance policy named Policy1.
You need to ensure that when users are assigned the device configuration profiles in Set1, they are always assigned Policy1 also.
What should you configure?
A. the assignments of Policy1
B. the Policy1 configurations
C. the assignments of Set1
D. the Set1 configurations
Show Answer
Correct Answer: D
Explanation: To ensure users assigned the device configuration profiles in the policy set also receive the compliance policy, you must add the compliance policy to the policy set itself. That is done by modifying the policy set's configuration (its contents), not by changing assignments or the compliance policy's settings. Once Policy1 is included in Set1, assigning the policy set deploys all included objects together.
Question 197
You have a Windows 10 device named Device1 that is joined to Active Directory and enrolled in Microsoft Intune.
Device1 is managed by using Group Policy and Intune.
You need to ensure that the Intune settings override the Group Policy settings.
What should you configure?
A. a device configuration profile
B. a device compliance policy
C. an MDM Security Baseline profile
D. a Group Policy Object (GPO)
Show Answer
Correct Answer: A
Explanation: Configure the MDMWinsOverGP policy through an Intune device configuration profile (Settings Catalog/Policy CSP). This setting causes supported MDM policies to take precedence over equivalent Group Policy settings on co-managed devices. Compliance policies and security baselines do not enable MDM-over-GP behavior, and a GPO alone does not make Intune override Group Policy.
Question 198
HOTSPOT -
You have a Microsoft 365 subscription that uses Microsoft Intune and contains 100 Windows 10 devices.
You need to create Intune configuration profiles to perform the following actions on the devices:
• Deploy a custom Start layout.
• Rename the local Administrator account.
Which profile type template should you use for each action? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Deploy a custom Start layout: Device restriction
Rename the local Administrator account: Endpoint protection
Explanation: Custom Start layout is configured through the Device restrictions template. Renaming the built-in local Administrator account is available under Endpoint protection > Local device security options (Accounts).
Question 199
You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Azure AD joined and are enrolled in Microsoft Intune.
You plan to manage Microsoft Defender Antivirus on the computers.
You need to prevent users from disabling Microsoft Defender Antivirus.
What should you do?
A. From the Microsoft Intune admin center, create a security baseline.
B. From the Microsoft 365 Defender portal, enable tamper protection.
C. From the Microsoft Intune admin center, create an account protection policy.
D. From the Microsoft Intune admin center, create an endpoint detection and response (EDR) policy.
Show Answer
Correct Answer: B
Explanation: Enableing Microsoft Defender Tamper Protection prevents users and malware from disabling Microsoft Defender Antivirus and other critical security settings. This is managed centrally through the Microsoft 365 Defender portal (and can also be managed via Intune in newer workflows). Security baselines, account protection policies, and EDR policies do not specifically enforce prevention of disabling Defender Antivirus.
Question 200
You have 200 computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune.
You need to enable self-service password reset on the sign-in screen.
Which settings should you configure from the Microsoft Intune admin center?
A. Device configuration
B. Device enrollment
C. Conditional access
D. Device compliance
Show Answer
Correct Answer: A
Explanation: To enable self-service password reset (SSPR) from the Windows 10 sign-in screen for Azure AD-joined, Intune-enrolled devices, you configure an Intune device configuration policy (typically via a Settings Catalog or a Custom OMA-URI policy) that enables the 'Allow AAD Password Reset' setting on the lock/sign-in screen. This is managed under Device configuration in the Intune admin center, not Device enrollment, Conditional access, or Device compliance.
Question 201
DRAG DROP
-
You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.
You plan to onboard the following types of devices to Defender for Endpoint:
• macOS
• Linux Server
What should you use to onboard each device? To answer, drag the appropriate tools to the correct device types. Each tool may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: macOS: Microsoft Intune
Linux Server: Ansible
Explanation: Defender for Endpoint onboarding on macOS is commonly managed through Microsoft Intune (MDM). Linux Server onboarding is supported through configuration management tools such as Ansible.
$19
Get all 373 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.