View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.
Question 21
Which Microsoft service can automatically deploy Windows quality and feature updates according to organizational policies?
- Microsoft Intune
- Windows Autopatch
- Microsoft Defender
- Microsoft Entra ID
Correct Answer: 2
Explanation
Windows Autopatch is a Microsoft service designed to automate the management and deployment of updates for supported Windows devices and applications. It helps organizations keep endpoints current while reducing the amount of manual update management required from IT administrators. Autopatch can use organizational policies and deployment rings to manage how updates are introduced. Microsoft Intune manages devices and policies, Defender focuses on security, and Microsoft Entra ID manages identity and access. Windows Autopatch specifically focuses on keeping supported software and Windows devices updated.
Question 22
Which Microsoft Entra object represents a user account in the organization’s directory?
- User
- Device
- Group policy
- Compliance profile
Correct Answer: 1
Explanation
A user object in Microsoft Entra ID represents an individual identity within an organization’s cloud directory. It can contain information such as the user’s name, sign-in identity, group memberships, authentication methods, and assigned permissions or licenses. Devices are represented separately and can be registered or joined to the directory. Group policies and compliance profiles are management concepts rather than Microsoft Entra user objects. Administrators can use user accounts to control access to applications, resources, and organizational services.
Question 23
Which Windows management approach is most appropriate for applying configuration policies to cloud-managed devices?
- Local Group Policy only
- Registry editing
- Microsoft Intune
- BIOS configuration
Correct Answer: 3
Explanation
Microsoft Intune is designed to manage cloud-enrolled devices and apply configuration policies centrally. Administrators can create configuration profiles that control Windows settings, security options, restrictions, and other endpoint behaviors. These policies can be assigned to users or device groups and applied automatically when devices communicate with the Intune service. Local Group Policy is primarily associated with traditional Active Directory environments, while registry editing and BIOS configuration are lower-level management methods. Intune is therefore appropriate for modern cloud-based endpoint management.
Question 24
Which Windows deployment technology provides a user-driven setup experience while applying organizational policies automatically?
- Windows Autopilot
- Disk Cleanup
- Windows Recovery Environment
- System Restore
Correct Answer: 1
Explanation
Windows Autopilot simplifies Windows deployment by allowing organizations to configure a device’s setup experience before the user receives it. During deployment, the device can connect to organizational services, authenticate the user, enroll into Microsoft Intune, and receive required policies and applications automatically. This reduces the need for technicians to manually configure each computer. Disk Cleanup removes unnecessary files, Windows Recovery Environment provides troubleshooting and recovery tools, and System Restore restores system states. Autopilot is specifically designed for streamlined device provisioning.
Question 25
Which Intune feature evaluates whether a device meets required security standards?
- Configuration profile
- Compliance policy
- Application assignment
- Enrollment restriction
Correct Answer: 2
Explanation
Intune compliance policies evaluate whether managed devices meet organizational security and configuration requirements. Policies can check conditions such as encryption status, password requirements, operating system versions, firewall settings, and other security controls. Compliance results can also work with Microsoft Entra Conditional Access to restrict access when a device is considered noncompliant. Configuration profiles apply settings, application assignments manage software deployment, and enrollment restrictions control which devices can enroll. Compliance policies specifically determine whether managed devices satisfy defined organizational requirements.
Question 26
Which Windows feature provides a virtualized environment for safely testing applications without affecting the main operating system?
- Windows Sandbox
- BitLocker
- Credential Manager
- Disk Management
Correct Answer: 1
Explanation
Windows Sandbox provides a lightweight, isolated desktop environment where administrators and users can test applications or potentially untrusted files without directly affecting the main Windows installation. The sandbox uses virtualization-based isolation and is temporary, meaning its contents are discarded when the session is closed. BitLocker encrypts storage, Credential Manager manages stored credentials, and Disk Management handles storage configuration. Windows Sandbox is therefore useful when a temporary isolated environment is needed for testing or examining potentially risky software.
Question 27
Which Microsoft Entra capability allows administrators to group users or devices for easier policy assignment?
- Groups
- Workbooks
- Connectors
- Recovery keys
Correct Answer: 1
Explanation
Microsoft Entra groups allow administrators to organize users and devices into logical collections. Groups can simplify the assignment of applications, licenses, permissions, and management policies by allowing administrators to target a collection instead of configuring every account individually. Groups can be assigned members manually or through supported dynamic membership rules. Workbooks are associated with monitoring and reporting, connectors integrate services, and recovery keys are used for specific security or recovery purposes. Groups are therefore fundamental to scalable identity and endpoint management.
Question 28
Which Windows feature can protect credentials by using virtualization-based security?
- Windows Hello
- Credential Guard
- Storage Sense
- Remote Assistance
Correct Answer: 2
Explanation
Credential Guard uses virtualization-based security to help isolate and protect certain sensitive authentication information from unauthorized access. By placing protected credential components into an isolated environment, it can reduce the risk of credential theft from attacks targeting the Windows operating system. Windows Hello provides modern authentication, Storage Sense manages storage space, and Remote Assistance enables support interactions. Credential Guard is therefore specifically associated with protecting credentials through hardware- and virtualization-based security capabilities.
Question 29
Which Intune feature allows administrators to deploy Microsoft 365 applications to managed Windows devices?
- App protection policy
- App deployment
- Compliance policy
- Enrollment restriction
Correct Answer: 2
Explanation
Intune application deployment allows administrators to distribute supported applications, including Microsoft 365 applications, to managed devices. Administrators can configure application settings, select target users or device groups, and define whether an application is required, available, or handled through other supported assignment methods. App protection policies primarily protect organizational data inside supported mobile applications, compliance policies evaluate device security, and enrollment restrictions control device enrollment. Application deployment is therefore the appropriate Intune capability for centrally distributing software to managed Windows endpoints.
Question 30
Which Microsoft Entra join type is intended primarily for devices owned and managed by an organization?
- Microsoft Entra joined
- Workgroup joined
- Peer-to-peer joined
- Internet joined
Correct Answer: 1
Explanation
Microsoft Entra joined devices are connected directly to an organization’s Microsoft Entra environment and are commonly used for organization-owned Windows devices managed through cloud services such as Intune. Users can sign in with organizational identities, while administrators can apply centralized policies and security controls. Workgroup computers are not joined to a centralized directory, and the other options are not standard Windows identity-join models. Microsoft Entra join supports modern cloud-based device management and identity scenarios.
Question 31
Which tool can be used to view Windows system and application error logs?
- Device Manager
- Event Viewer
- Task Scheduler
- Disk Management
Correct Answer: 2
Explanation
Event Viewer provides access to Windows logs generated by the operating system, applications, security components, and various services. Administrators can use these logs to investigate errors, warnings, authentication events, service failures, and other system activity. Device Manager focuses on hardware and drivers, Task Scheduler manages scheduled tasks, and Disk Management handles storage configuration. Event Viewer is particularly useful when troubleshooting issues that do not provide enough information through normal user-facing error messages.
Question 32
Which Microsoft security feature helps prevent unauthorized applications from accessing protected folders?
- Controlled folder access
- Storage Sense
- Windows Search
- Remote Desktop
Correct Answer: 1
Explanation
Controlled folder access is a Microsoft Defender feature designed to help protect important folders from unauthorized changes, particularly those associated with ransomware and other malicious software. It can monitor applications attempting to modify protected locations and allow administrators to configure trusted applications when necessary. Storage Sense manages disk space, Windows Search indexes and locates files, and Remote Desktop provides remote access. Controlled folder access therefore provides an additional endpoint protection layer against unauthorized file modification.
Question 33
Which enrollment option is designed to automatically register eligible Windows devices with Intune when they join Microsoft Entra ID?
- Automatic MDM enrollment
- Manual registry editing
- Safe Mode enrollment
- Local printer enrollment
Correct Answer: 1
Explanation
Automatic Mobile Device Management enrollment allows eligible Windows devices to automatically enroll into Microsoft Intune when they are joined or registered with Microsoft Entra ID, depending on the configured environment and enrollment scope. This reduces manual administrative steps and helps ensure that newly managed devices receive organizational policies promptly. Registry editing does not provide centralized enrollment, Safe Mode is a troubleshooting startup mode, and printer enrollment is unrelated to endpoint management. Automatic MDM enrollment supports streamlined cloud-based Windows management.
Question 34
Which Microsoft Entra feature can require a device to be compliant before granting access to an application?
- Microsoft Entra Connect
- Conditional Access
- Windows Autopilot
- Microsoft Store
Correct Answer: 2
Explanation
Conditional Access can evaluate device compliance as part of an access decision. When Intune determines whether a device meets organizational requirements, Microsoft Entra Conditional Access can use that compliance status to control access to applications and services. An organization might require devices to have encryption enabled, current security settings, or an approved operating system version before allowing access. Entra Connect synchronizes identities, Windows Autopilot supports deployment, and Microsoft Store distributes applications. Conditional Access provides the access-control decision.
Question 35
Which Windows management tool can stop or start background services?
- Services console
- Event Viewer
- Registry Editor
- Windows Security
Correct Answer: 1
Explanation
The Windows Services console allows administrators to view and manage background services running on a Windows computer. Administrators can start, stop, pause, restart, and configure services, including their startup behavior. This can be useful when troubleshooting applications or operating-system components that depend on specific services. Event Viewer displays logs, Registry Editor manages registry data, and Windows Security provides security-related controls. The Services console is therefore the appropriate tool for controlling the operational state of Windows services.
Question 36
Which Windows feature allows an administrator to remotely connect to a Windows desktop session?
- BitLocker
- Remote Desktop
- Windows Sandbox
- Credential Guard
Correct Answer: 2
Explanation
Remote Desktop allows authorized users or administrators to connect to a Windows computer remotely and interact with its desktop environment. It can be useful for remote administration, troubleshooting, and accessing applications or resources on another computer. Appropriate authentication, authorization, and network security controls should be configured when Remote Desktop is enabled. BitLocker protects stored data, Windows Sandbox provides an isolated environment, and Credential Guard protects authentication information. Remote Desktop is specifically designed for remote interactive access.
Question 37
Which Intune capability can protect corporate data inside supported mobile applications without fully managing the device?
- Application protection policies
- Configuration profiles
- Compliance policies
- Enrollment restrictions
Correct Answer: 1
Explanation
Intune application protection policies, often called app protection policies, can protect organizational data within supported applications even when the entire device is not enrolled in Intune. They can control actions such as copying, pasting, saving, sharing, and accessing corporate data. This approach is useful in bring-your-own-device scenarios where an organization needs to protect business information without taking complete control of a personally owned device. Configuration profiles manage device settings, compliance policies evaluate device status, and enrollment restrictions control enrollment.
Question 38
Which Windows security feature verifies the integrity of the boot process using trusted firmware and software components?
- Windows Firewall
- Secure Boot
- Defender Antivirus
- AppLocker
Correct Answer: 2
Explanation
Secure Boot is a security feature implemented through UEFI firmware that verifies trusted digital signatures during the system startup process. Its purpose is to prevent unauthorized or modified boot components from loading before Windows starts. This helps defend against certain types of boot-level malware. Windows Firewall controls network connections, Defender Antivirus detects malicious software, and AppLocker restricts application execution. Secure Boot specifically focuses on protecting the integrity of the boot chain before the operating system is fully loaded.
Question 39
Which Microsoft Intune capability can provide administrators with reports about device compliance and management status?
- Intune reporting
- Windows Calculator
- Disk Cleanup
- Notepad
Correct Answer: 3
Explanation
Intune provides reporting capabilities that allow administrators to review information about managed devices, compliance status, application deployment, policy results, and other endpoint-management activities. These reports can help identify devices that are noncompliant, applications that failed to install, or policies that are not applying as expected. The information supports troubleshooting and operational monitoring across an organization’s managed endpoints. Windows Calculator, Disk Cleanup, and Notepad are local Windows utilities and do not provide centralized Intune management reporting.
Question 40
Which Windows feature can automatically install security updates and other updates through configured update policies?
- Windows Update
- Device Manager
- Event Viewer
- Task Manager
Correct Answer: 4
Explanation
Windows Update is responsible for delivering operating system updates, including security updates, quality updates, and supported feature updates. In managed environments, administrators can use tools such as Intune and Windows Update for Business policies to control update behavior, deadlines, restart settings, and deployment strategies. Device Manager manages hardware and drivers, Event Viewer displays system logs, and Task Manager monitors processes and resource usage. Windows Update is therefore the core Windows component responsible for receiving and installing operating-system updates.