HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains a group named Group1 and 500 mobile devices that run Android or iOS.
You need to create app protection policies and Conditional Access policies for the subscription. The solution must meet the following requirements:
• Encrypt corporate data stored on the mobile devices.
• Automatically remove corporate data stored on a mobile device if the device is offline for 45 days.
• Ensure that only users assigned app protection policies can use mobile devices to access the subscription.
• On the mobile devices used only by Group1, automatically remove corporate data stored on the devices if the devices are offline for 30 days.
What is the minimum number of policies you should create? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: App protection policies are platform-specific (Android and iOS/iPadOS). Because the offline wipe period differs (45 days for most users, 30 days for Group1), you need two policies per platform: 2 × 2 = 4. A single Conditional Access policy can require an approved app/app protection policy for mobile access.
Question 12
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You have 500 Windows devices that are NOT onboarded.
You need to connect Microsoft Intune with Microsoft Defender for Endpoint and onboard the devices. The solution must minimize administrative effort.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point
Show Answer
Correct Answer: Enable the connection: The Microsoft Defender portal
Onboard the devices: The Microsoft Intune admin center
Explanation: The Intune connection is enabled in the Microsoft Defender portal (Settings > Endpoints > Advanced features). To minimize effort for many devices, deploy the Defender for Endpoint onboarding policy through Microsoft Intune.
Question 13
You have a Microsoft 365 E5 subscription and use the Microsoft Intune Suite. The subscription contains a Microsoft SharePoint Online site named Site1 and 500 Windows devices enrolled in Intune.
You have the apps shown in the following table.
You need to deploy the apps to the devices by using Intune.
For which apps must you upload app package files before you can deploy them?
A. App1 only
B. App1 and App2 only
C. App1 and App4 only
D. App1, App2, and App4 only
E. App1, App2, App3, and App4
Show Answer
Correct Answer: A
Explanation: The app package upload requirement depends on app type. Win32 apps require uploading an .intunewin package to Intune, while Microsoft-hosted app types (such as Microsoft Store apps or Microsoft 365 Apps) and web links do not require uploading package files. Based on the scenario, only App1 requires an uploaded app package.
Question 15
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
Microsoft 365 Password: i7A4$3o^HGD3L~=c[9xuOhM%^4:s11Ai
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL “https://portal.office.com”, and press Enter.
The following information is for technical support purposes only:
Lab Instance: 48262079
-
You need to create a Conditional Access policy for the sg-Legal group that requires Android devices to be compliant when they connect to Microsoft Office 365. Access to other apps and devices must NOT be affected.
Show Answer
Correct Answer: Create a Conditional Access policy:
Assignments: Users = sg-Legal
Target resources = Office 365
Conditions: Device platforms = Android
Grant: Require device to be marked as compliant
Enable the policy.
Explanation: This scopes the policy only to the sg-Legal group, only for Microsoft Office 365 cloud apps, and only for Android devices, leaving other apps and device platforms unaffected.
Question 16
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
Microsoft 365 Password: i7A4$3o^HGD3L~=c[9xuOhM%^4:s11Ai
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL “https://portal.office.com”, and press Enter.
The following information is for technical support purposes only:
Lab Instance: 48262079
-
You need to manually register your computer to Windows Autopilot.
The Get-WindowsAutopilotInfo.ps1 PowerShell script is stored in C:\Scripts.
Show Answer
Correct Answer: Open PowerShell as Administrator.
Set-ExecutionPolicy -Scope Process Bypass
cd C:\Scripts
.\Get-WindowsAutopilotInfo.ps1 -Online
Sign in with the required Microsoft 365 admin account when prompted.
Explanation: Temporarily bypass the execution policy, run the Autopilot information script from the specified folder with the online upload option, then authenticate to register the device with Windows Autopilot.
Question 17
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
Microsoft 365 Password: i7A4$3o^HGD3L~=c[9xuOhM%^4:s11Ai
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL “https://portal.office.com”, and press Enter.
The following information is for technical support purposes only:
Lab Instance: 48262079
-
You need to create a configuration profile that will enable Single app, full-screen kiosk mode for Windows 10 and later devices in a group named sg-IT. The solution must sign in a local user named KioskUser automatically and display Microsoft Edge with the https://bing.com homepage.
Show Answer
Correct Answer: Create an Intune configuration profile:
Platform: Windows 10 and later
Profile: Templates > Kiosk
Mode: Single app, full-screen kiosk
User logon: Auto logon
Local user: KioskUser
App: Microsoft Edge
Home URL: https://bing.com
Assign to: sg-IT
Explanation: A Windows kiosk profile configured for single-app full-screen mode with auto logon to the local KioskUser account and Microsoft Edge opening the specified URL satisfies the requirements.
Question 18
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
Microsoft 365 Password: i7A4$3o^HGD3L~=c[9xuOhM%^4:s11Ai
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL “https://portal.office.com”, and press Enter.
The following information is for technical support purposes only:
Lab Instance: 48262079
-
You need to create an endpoint security policy to turn on Windows SmartScreen for all Windows devices.
Show Answer
Correct Answer: Endpoint security → Attack surface reduction → Create Policy
Platform: Windows
Profile: Application Control
Enable Windows SmartScreen
Explanation: Windows SmartScreen is configured through an Endpoint Security Attack Surface Reduction policy using the Application Control profile, then enabling the Windows SmartScreen setting and assigning it to all Windows devices.
Question 19
You have a Microsoft 365 subscription that contains 500 Android devices. The devices are managed by using Microsoft Intune.
You need to ensure that you can manage software updates for the devices by using Android FOTA.
What should you do first?
A. Create a compliance policy.
B. Add a compliance partner.
C. Configure a connector.
D. Add derived credentials.
Show Answer
Correct Answer: C
Explanation: Android FOTA management in Microsoft Intune requires integrating the supported OEM firmware update service before firmware deployments can be configured. The initial step is to configure the appropriate FOTA connector. Compliance policies, compliance partners, and derived credentials are unrelated prerequisites for enabling Android FOTA.
Question 20
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the devices shown in the following table.
All the devices are enrolled in Microsoft Intune.
The devices have apps installed as shown in the following table.
In Intune, you create an app configuration policy named Policy1 that has the following settings:
• Device enrollment type: Managed apps
• Target policy to: All Microsoft Apps
• Assignments
o Included groups: Group1
o Excluded groups: Group2
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
No
Explanation: Managed apps app configuration policies target supported mobile app platforms (Android/iOS), not Windows. Device2 is included and OneDrive is a Microsoft app. Device3 is in both included and excluded groups, and exclusion takes precedence.
Question 21
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains 500 Windows devices enrolled in Microsoft Intune.
You deploy Microsoft Defender for Endpoint.
You need to onboard the devices to Defender for Endpoint. The solution must minimize administrative effort.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Advanced features
An endpoint detection and response (EDR) policy
Explanation: Enable the Microsoft Defender for Endpoint–Intune connection under Advanced features in the Defender portal, then deploy an Intune EDR policy to automatically onboard managed devices with minimal administrative effort.
$19
Get all 373 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.