You have a Microsoft 365 E5 subscription.
You need to enroll Android Enterprise devices in Microsoft Intune by using zero-touch enrollment.
What should you do first?
A. From the Microsoft Intune admin center, configure enrollment restrictions.
B. From the Microsoft Intune admin center, create a zero-touch configuration.
C. From the Microsoft Intune admin center, link a Managed Google Play account.
D. From the zero-touch enrollment portal, create a zero-touch configuration.
Show Answer
Correct Answer: C
Explanation: Before you can use Android Enterprise enrollment methods such as zero-touch enrollment, Intune must be connected to a Managed Google Play account. This establishes the Android Enterprise integration required before creating or assigning zero-touch configurations. After the Managed Google Play link is in place, you can configure zero-touch profiles in Intune and associate them with devices in the zero-touch portal.
Question 87
You have a Microsoft 365 E5 subscription and use Microsoft Intune.
You plan to implement a Microsoft Cloud PKI solution that will deploy personal user certificates to all Windows devices.
What is the minimum number of configuration profiles required to support the solution?
A. 1
B. 2
C. 3
D. 4
Show Answer
Correct Answer: C
Explanation: For Microsoft Cloud PKI with Intune deploying personal user certificates via SCEP, the documented minimum certificate configuration profiles are: (1) a Trusted certificate profile for the Cloud PKI root CA, (2) a Trusted certificate profile for the Cloud PKI issuing CA (recommended and used in Microsoft's deployment guidance), and (3) an SCEP certificate profile to enroll the user certificate. Microsoft's configuration guide lists these three profiles as the deployment step.
Sources:
https://learn.microsoft.com/en-us/intune/cloud-pki/configure-ca
Question 88
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains two devices named Device1 and Device2.
You manage the devices by using Microsoft Intune.
You need to use Device query to meet the following requirements:
• Identify the Windows build on a device.
• Validate whether a folder exists on the C drive of a device.
Which table should you target for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Windows build: OSVersion
Folder: FileInfo
Explanation: OSVersion contains the operating system version/build information. FileInfo can be queried to verify whether a specific folder/path exists on the device's C: drive.
Question 89
You have a Microsoft 365 E5 subscription.
You need to use Device query to gather information about all the devices that are managed by using Microsoft Intune.
What should you do first?
A. Enable Windows license verification.
B. Onboard the devices to Microsoft Defender for Endpoint.
C. Onboard the devices to Endpoint analytics.
D. Create a compliance policy for all the devices.
Show Answer
Correct Answer: C
Explanation: Device query in Microsoft Intune requires devices to be enrolled in Endpoint analytics as a prerequisite. Microsoft Defender for Endpoint integration is used for other capabilities, but the prerequisite for using Device query on managed devices is Endpoint analytics enrollment. Therefore, the first step is to onboard the devices to Endpoint analytics.
Question 90
You have a Microsoft 365 subscription that contains Windows 11 devices enrolled in Microsoft Intune.
You need to use Device query to identify whether a critical security patch was installed on a device.
Which table should you target?
A. WindowsQfe
B. WindowsRegistry
C. FileInfo
D. OsVersion
E. SystemInfo
Show Answer
Correct Answer: A
Explanation: The WindowsQfe table contains Quick Fix Engineering (QFE) information, including installed Windows updates and hotfixes. To determine whether a specific security patch has been installed on a Windows device using Intune Device query, query the WindowsQfe table. The other tables expose registry data, file metadata, OS version, or general system information rather than installed hotfix records.
Question 91
You have a Microsoft 365 subscription.
You use Microsoft Intune to manage devices.
You plan to deploy two apps named App1 and App2 to all Windows devices. App1 must be installed before App2.
From the Intune admin center, you create and deploy two Windows app (Win32) apps.
You need to ensure that App1 is installed before App2 on every device.
What should you configure?
A. the App1 deployment configurations
B. a dynamic device group
C. the App2 deployment configurations
Show Answer
Correct Answer: C
Explanation: Configure App2's deployment configuration by adding App1 as a dependency in the Win32 app Dependencies section. Intune installs required dependency apps before the dependent app, ensuring App1 is installed before App2 on every targeted device.
Question 92
HOTSPOT
-
You have a Microsoft 365 E5 tenant that contains Windows devices enrolled in Microsoft Intune as shown in the following table.
You create an Endpoint Privilege Management (EPM) elevation settings policy named ElevationSettings1 that has the following settings:
• Endpoint Privilege Management: Enabled
• Default elevation response: Require user confirmation
• Validation: Business justification
• Assignments: Group1
Each device contains a file named File1.exe that can be run only by an administrator.
You create an EPM elevation rules policy named ElevationRules1 that has the following settings:
• Rule name: Rule1
• Elevation type: Automatic
• File name: File1.exe
• File hash:
Show Answer
Correct Answer: No
No
Yes
Explanation: The elevation settings policy enables EPM and provides default behavior only for files not covered by an elevation rule. Devices 1 and 3 receive both the settings policy and the automatic elevation rule, so File1.exe is elevated automatically without justification. Device2 receives only the rule but not the settings policy, so EPM is not enabled and the rule is not enforced; the user cannot run the admin-only executable.
Question 93
You have a Microsoft 365 subscription that contains devices enrolled in Microsoft Intune as shown in the following table.
On which devices can you use Device query?
A. Device1 only
B. Device1 and Device2 only
C. Device1 and Device3 only
D. Device1, Device2, and Device3
Show Answer
Correct Answer: A
Explanation: Device query in Microsoft Intune is supported for corporate-owned Windows 10 or later devices that are Microsoft Entra joined. Based on the scenario, only Device1 meets these requirements, so Device query can only be used on Device1.
Question 94
You have a Microsoft Entra tenant that contains the devices shown in the following table.
On which devices can you implement Endpoint Privilege Management (EPM)?
A. Device1 only
B. Device1 and Device2 only
C. Device1 and Device3 only
D. Device1, Device3, and Device4 only
E. Device1, Device2, Device3, and Device4
Show Answer
Correct Answer: A
Explanation: Endpoint Privilege Management (EPM) requires a supported Windows 10/11 device that is Microsoft Entra joined or Microsoft Entra hybrid joined and is enrolled in Microsoft Intune (or co-managed with Configuration Manager). Microsoft Entra registered (workplace-joined) devices are not supported, and non-Windows devices are not supported. Based on the described device properties, only Device1 satisfies all requirements.
Question 95
HOTSPOT
-
You have a hybrid environment that contains a Microsoft Entra tenant and an on-premises Active Directory Domain Services (AD DS) domain. The environment contains the devices shown in the following table.
Which Microsoft Entra join type can each device use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Device1: Microsoft Entra joined or Microsoft Entra registered only
Device2: Microsoft Entra registered only
Explanation: Hybrid Microsoft Entra join requires the device to already be joined to on-premises AD DS. A Windows 11 device currently in a workgroup can be Microsoft Entra joined or Microsoft Entra registered, but not hybrid joined in its current state. iOS devices support Microsoft Entra registration, not Entra join or hybrid join.
$19
Get all 373 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.