Microsoft

MD-102 Free Practice Questions — Page 9

Question 83

HOTSPOT - You have a Microsoft Entra tenant. You are creating a dynamic device group named Group1. Group1 will include only Windows devices that are Microsoft Entra registered. How should you configure the dynamic membership rule for Group1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 83
Show Answer
Correct Answer: device.deviceTrustType "Workplace"
Explanation:
Microsoft Entra registered devices are identified by deviceTrustType = "Workplace". Combined with device.deviceOSType = "Windows", this includes only Windows devices that are Entra registered.

Question 84

You have a Microsoft Entra tenant named contoso.com that contains a group named Contoso Help Desk. You need to ensure that Contoso Help Desk is added to the local Administrators group whenever a Windows device is joined to contoso.com. What should you do?

A. Assign the Cloud Device Administrator role to Contoso Help Desk.
B. Assign the Microsoft Entra Joined Device Local Administrator role to Contoso Help Desk.
C. Configure the Enterprise State Roaming settings.
D. Enable Microsoft Entra Local Administrator Password Solution (LAPS) for contoso.com.
Show Answer
Correct Answer: B
Explanation:
The Microsoft Entra Joined Device Local Administrator role automatically adds assigned users or groups to the local Administrators group on Microsoft Entra–joined Windows devices at join time. This directly meets the requirement. The other options do not grant local admin rights on joined devices.

Question 85

You have a Microsoft 365 E5 subscription. You need to enroll Android Enterprise devices in Microsoft Intune by using zero-touch enrollment. What should you do first?

A. From the Microsoft Intune admin center, configure enrollment restrictions.
B. From the Microsoft Intune admin center, create a zero-touch configuration.
C. From the Microsoft Intune admin center, link a Managed Google Play account.
D. From the zero-touch enrollment portal, create a zero-touch configuration.
Show Answer
Correct Answer: C
Explanation:
To enroll Android Enterprise devices using zero-touch enrollment, Intune must first be connected to Android Enterprise. Linking a Managed Google Play account in the Microsoft Intune admin center is the prerequisite step that enables all Android Enterprise enrollment methods, including zero-touch. Without this connection, zero-touch configurations cannot be created or used.

Question 86

You have a Microsoft 365 E5 subscription and use Microsoft Intune. You plan to implement a Microsoft Cloud PKI solution that will deploy personal user certificates to all Windows devices. What is the minimum number of configuration profiles required to support the solution?

A. 1
B. 2
C. 3
D. 4
Show Answer
Correct Answer: B
Explanation:
With Microsoft Cloud PKI and Intune, the minimum required configuration profiles to deploy personal user certificates to Windows devices are: 1) A Trusted certificate profile to deploy the Cloud PKI root CA certificate so devices trust the PKI. 2) A certificate enrollment profile (SCEP or PKCS) to request and deploy the personal user certificates from the Cloud PKI issuing CA. A separate trusted certificate profile for the issuing CA is not required because trust is established through the root CA. Therefore, the minimum number of configuration profiles is two.

Question 87

HOTSPOT - You have a Microsoft 365 E5 subscription that contains two devices named Device1 and Device2. You manage the devices by using Microsoft Intune. You need to use Device query to meet the following requirements: • Identify the Windows build on a device. • Validate whether a folder exists on the C drive of a device. Which table should you target for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 87
Show Answer
Correct Answer: Windows build: OSVersion Folder: FileInfo
Explanation:
OSVersion contains operating system details, including the Windows build number. FileInfo exposes files and directories on the device, allowing validation of a folder on the C drive.

Question 88

You have a Microsoft 365 E5 subscription. You need to use Device query to gather information about all the devices that are managed by using Microsoft Intune. What should you do first?

A. Enable Windows license verification.
B. Onboard the devices to Microsoft Defender for Endpoint.
C. Onboard the devices to Endpoint analytics.
D. Create a compliance policy for all the devices.
Show Answer
Correct Answer: C
Explanation:
Device query is part of Intune Advanced Analytics and requires devices to be enrolled in Endpoint analytics before queries can be run. No compliance policy, license verification, or Defender for Endpoint onboarding is the first prerequisite for Device query in Intune.

Question 89

You have a Microsoft 365 subscription that contains Windows 11 devices enrolled in Microsoft Intune. You need to use Device query to identify whether a critical security patch was installed on a device. Which table should you target?

A. WindowsQfe
B. WindowsRegistry
C. FileInfo
D. OsVersion
E. SystemInfo
Show Answer
Correct Answer: A
Explanation:
Device Query in Intune uses tables that mirror Windows management instrumentation data. Security patches and hotfixes installed on Windows are exposed through the Quick Fix Engineering (QFE) data. The WindowsQfe table lists installed updates, hotfix IDs (KB numbers), and install dates, making it the correct table to verify whether a specific critical security patch is installed.

Question 90

You have a Microsoft 365 subscription. You use Microsoft Intune to manage devices. You plan to deploy two apps named App1 and App2 to all Windows devices. App1 must be installed before App2. From the Intune admin center, you create and deploy two Windows app (Win32) apps. You need to ensure that App1 is installed before App2 on every device. What should you configure?

A. the App1 deployment configurations
B. a dynamic device group
C. the App2 deployment configurations
Show Answer
Correct Answer: C
Explanation:
In Intune, installation order between Win32 apps is controlled by configuring dependencies. By configuring App1 as a dependency within the App2 deployment configuration, Intune ensures that App1 is installed first on every device before App2 is installed.

Question 91

HOTSPOT - You have a Microsoft 365 E5 tenant that contains Windows devices enrolled in Microsoft Intune as shown in the following table. You create an Endpoint Privilege Management (EPM) elevation settings policy named ElevationSettings1 that has the following settings: • Endpoint Privilege Management: Enabled • Default elevation response: Require user confirmation • Validation: Business justification • Assignments: Group1 Each device contains a file named File1.exe that can be run only by an administrator. You create an EPM elevation rules policy named ElevationRules1 that has the following settings: • Rule name: Rule1 • Elevation type: Automatic • File name: File1.exe • File hash:

Illustration for MD-102 question 91 Illustration for MD-102 question 91
Show Answer
Correct Answer: No No Yes
Explanation:
Endpoint Privilege Management (EPM) must be enabled by an elevation settings policy before any elevation rules can apply. Elevation rules take precedence over the default elevation response, but only on devices where EPM is enabled. • Device1: EPM is enabled (Group1) and File1.exe is explicitly covered by an Automatic elevation rule (Group2). Automatic rules bypass confirmation and justification → no justification required. • Device2: Receives the elevation rule (Group2) but does not receive an elevation settings policy, so EPM is not enabled. Without EPM, the rule is not enforced → File1.exe cannot run. • Device3: Like Device1, EPM is enabled and the automatic rule applies → File1.exe runs without business justification.

Question 92

You have a Microsoft 365 subscription that contains devices enrolled in Microsoft Intune as shown in the following table. On which devices can you use Device query?

A. Device1 only
B. Device1 and Device2 only
C. Device1 and Device3 only
D. Device1, Device2, and Device3
Show Answer
Correct Answer: A
Explanation:
Device query in Microsoft Intune is currently supported only on corporate-owned devices running Windows 10 or later that are Microsoft Entra (Azure AD) joined. Among the listed devices, only Device1 meets these requirements, so Device query can be used on Device1 only.

$19

Get all 373 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.