Microsoft

MD-102 Free Practice Questions — Page 2

Question 11

HOTSPOT - You have a Microsoft 365 E5 subscription that contains a group named Group1 and 500 mobile devices that run Android or iOS. You need to create app protection policies and Conditional Access policies for the subscription. The solution must meet the following requirements: • Encrypt corporate data stored on the mobile devices. • Automatically remove corporate data stored on a mobile device if the device is offline for 45 days. • Ensure that only users assigned app protection policies can use mobile devices to access the subscription. • On the mobile devices used only by Group1, automatically remove corporate data stored on the devices if the devices are offline for 30 days. What is the minimum number of policies you should create? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 11
Show Answer
Correct Answer: App protection policies: 4 Conditional Access policies: 1
Explanation:
App protection policies are platform-specific (Android and iOS/iPadOS). Because the offline wipe period differs (45 days for most users, 30 days for Group1), you need two policies per platform: 2 × 2 = 4. A single Conditional Access policy can require an approved app/app protection policy for mobile access.

Question 12

HOTSPOT - You have a Microsoft 365 E5 subscription. You have 500 Windows devices that are NOT onboarded. You need to connect Microsoft Intune with Microsoft Defender for Endpoint and onboard the devices. The solution must minimize administrative effort. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point

Illustration for MD-102 question 12
Show Answer
Correct Answer: Enable the connection: The Microsoft Defender portal Onboard the devices: The Microsoft Intune admin center
Explanation:
The Intune connection is enabled in the Microsoft Defender portal (Settings > Endpoints > Advanced features). To minimize effort for many devices, deploy the Defender for Endpoint onboarding policy through Microsoft Intune.

Question 13

You have a Microsoft 365 E5 subscription and use the Microsoft Intune Suite. The subscription contains a Microsoft SharePoint Online site named Site1 and 500 Windows devices enrolled in Intune. You have the apps shown in the following table. You need to deploy the apps to the devices by using Intune. For which apps must you upload app package files before you can deploy them?

A. App1 only
B. App1 and App2 only
C. App1 and App4 only
D. App1, App2, and App4 only
E. App1, App2, App3, and App4
Show Answer
Correct Answer: A
Explanation:
The app package upload requirement depends on app type. Win32 apps require uploading an .intunewin package to Intune, while Microsoft-hosted app types (such as Microsoft Store apps or Microsoft 365 Apps) and web links do not require uploading package files. Based on the scenario, only App1 requires an uploaded app package.

Question 15

SIMULATION - Username and password - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and select the username below. To enter your password, place your cursor in the Enter password box and select the password below. Microsoft 365 Username: Microsoft 365 Password: i7A4$3o^HGD3L~=c[9xuOhM%^4:s11Ai If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL “https://portal.office.com”, and press Enter. The following information is for technical support purposes only: Lab Instance: 48262079 - You need to create a Conditional Access policy for the sg-Legal group that requires Android devices to be compliant when they connect to Microsoft Office 365. Access to other apps and devices must NOT be affected.

Show Answer
Correct Answer: Create a Conditional Access policy: Assignments: Users = sg-Legal Target resources = Office 365 Conditions: Device platforms = Android Grant: Require device to be marked as compliant Enable the policy.
Explanation:
This scopes the policy only to the sg-Legal group, only for Microsoft Office 365 cloud apps, and only for Android devices, leaving other apps and device platforms unaffected.

Question 16

SIMULATION - Username and password - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and select the username below. To enter your password, place your cursor in the Enter password box and select the password below. Microsoft 365 Username: Microsoft 365 Password: i7A4$3o^HGD3L~=c[9xuOhM%^4:s11Ai If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL “https://portal.office.com”, and press Enter. The following information is for technical support purposes only: Lab Instance: 48262079 - You need to manually register your computer to Windows Autopilot. The Get-WindowsAutopilotInfo.ps1 PowerShell script is stored in C:\Scripts.

Show Answer
Correct Answer: Open PowerShell as Administrator. Set-ExecutionPolicy -Scope Process Bypass cd C:\Scripts .\Get-WindowsAutopilotInfo.ps1 -Online Sign in with the required Microsoft 365 admin account when prompted.
Explanation:
Temporarily bypass the execution policy, run the Autopilot information script from the specified folder with the online upload option, then authenticate to register the device with Windows Autopilot.

Question 17

SIMULATION - Username and password - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and select the username below. To enter your password, place your cursor in the Enter password box and select the password below. Microsoft 365 Username: Microsoft 365 Password: i7A4$3o^HGD3L~=c[9xuOhM%^4:s11Ai If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL “https://portal.office.com”, and press Enter. The following information is for technical support purposes only: Lab Instance: 48262079 - You need to create a configuration profile that will enable Single app, full-screen kiosk mode for Windows 10 and later devices in a group named sg-IT. The solution must sign in a local user named KioskUser automatically and display Microsoft Edge with the https://bing.com homepage.

Show Answer
Correct Answer: Create an Intune configuration profile: Platform: Windows 10 and later Profile: Templates > Kiosk Mode: Single app, full-screen kiosk User logon: Auto logon Local user: KioskUser App: Microsoft Edge Home URL: https://bing.com Assign to: sg-IT
Explanation:
A Windows kiosk profile configured for single-app full-screen mode with auto logon to the local KioskUser account and Microsoft Edge opening the specified URL satisfies the requirements.

Question 18

SIMULATION - Username and password - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and select the username below. To enter your password, place your cursor in the Enter password box and select the password below. Microsoft 365 Username: Microsoft 365 Password: i7A4$3o^HGD3L~=c[9xuOhM%^4:s11Ai If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL “https://portal.office.com”, and press Enter. The following information is for technical support purposes only: Lab Instance: 48262079 - You need to create an endpoint security policy to turn on Windows SmartScreen for all Windows devices.

Show Answer
Correct Answer: Endpoint security → Attack surface reduction → Create Policy Platform: Windows Profile: Application Control Enable Windows SmartScreen
Explanation:
Windows SmartScreen is configured through an Endpoint Security Attack Surface Reduction policy using the Application Control profile, then enabling the Windows SmartScreen setting and assigning it to all Windows devices.

Question 19

You have a Microsoft 365 subscription that contains 500 Android devices. The devices are managed by using Microsoft Intune. You need to ensure that you can manage software updates for the devices by using Android FOTA. What should you do first?

A. Create a compliance policy.
B. Add a compliance partner.
C. Configure a connector.
D. Add derived credentials.
Show Answer
Correct Answer: C
Explanation:
Android FOTA management in Microsoft Intune requires integrating the supported OEM firmware update service before firmware deployments can be configured. The initial step is to configure the appropriate FOTA connector. Compliance policies, compliance partners, and derived credentials are unrelated prerequisites for enabling Android FOTA.

Question 20

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the devices shown in the following table. All the devices are enrolled in Microsoft Intune. The devices have apps installed as shown in the following table. In Intune, you create an app configuration policy named Policy1 that has the following settings: • Device enrollment type: Managed apps • Target policy to: All Microsoft Apps • Assignments o Included groups: Group1 o Excluded groups: Group2 For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 20 Illustration for MD-102 question 20 Illustration for MD-102 question 20
Show Answer
Correct Answer: No Yes No
Explanation:
Managed apps app configuration policies target supported mobile app platforms (Android/iOS), not Windows. Device2 is included and OneDrive is a Microsoft app. Device3 is in both included and excluded groups, and exclusion takes precedence.

Question 21

HOTSPOT - You have a Microsoft 365 E5 subscription that contains 500 Windows devices enrolled in Microsoft Intune. You deploy Microsoft Defender for Endpoint. You need to onboard the devices to Defender for Endpoint. The solution must minimize administrative effort. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 21
Show Answer
Correct Answer: Advanced features An endpoint detection and response (EDR) policy
Explanation:
Enable the Microsoft Defender for Endpoint–Intune connection under Advanced features in the Defender portal, then deploy an Intune EDR policy to automatically onboard managed devices with minimal administrative effort.

$19

Get all 373 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.