Microsoft MD-102 Practice Test Questions and Exam Dumps Part11 Q201-220

View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.

 

Question 201

Which Microsoft Intune feature allows administrators to configure recommended security settings across managed Windows devices?

  1. Security baseline
  2. Device category
  3. Company Portal
  4. Enrollment restriction

Correct Answer: 1

Explanation

Security baselines in Microsoft Intune provide predefined groups of recommended security settings that administrators can deploy to supported Windows devices. They help organizations establish a consistent security configuration without manually configuring every individual security setting. Administrators can review the baseline settings, customize them when necessary, and assign the resulting policy to appropriate users or devices. Device categories are used for organization and targeting, Company Portal provides user-facing functionality, and enrollment restrictions control device enrollment. Security baselines are therefore the appropriate choice for applying standardized recommended security configurations.

Question 202

Which Microsoft Entra device identity represents a device that is registered primarily for personal or bring-your-own-device scenarios?

  1. Microsoft Entra joined
  2. Microsoft Entra registered
  3. Microsoft Entra hybrid joined
  4. Configuration Manager enrolled

Correct Answer: 2

Explanation

Microsoft Entra registered devices are commonly associated with personal or bring-your-own-device scenarios where users access organizational resources without fully joining the device to the organization’s Microsoft Entra environment. Registration establishes a device identity that can be used with supported identity and access controls. Microsoft Entra joined devices are generally fully joined to the organization’s cloud identity environment, while hybrid joined devices combine on-premises Active Directory membership with Microsoft Entra registration. Configuration Manager enrollment describes management rather than the Microsoft Entra device identity itself. Microsoft Entra registered is therefore correct.

Question 203

An organization wants to automatically place newly enrolled devices into groups based on device attributes. Which Microsoft Entra capability should administrators use?

  1. Static security group
  2. Device category
  3. Dynamic device group
  4. Scope tag

Correct Answer: 3

Explanation

Dynamic device groups in Microsoft Entra can automatically include or exclude devices based on defined membership rules and device attributes. When a device’s relevant attributes change, group membership can be updated according to the configured rule. This is useful for automatically targeting Intune policies, applications, and compliance configurations without manually maintaining membership. Static groups require administrators to manage membership manually, device categories provide classification information, and scope tags control administrative visibility. Dynamic device groups are therefore appropriate when devices should automatically become members based on their properties.

Question 204

Which Intune enrollment method is designed to allow an organization to enroll and manage a large number of devices using a designated enrollment account?

  1. Windows Autopilot
  2. Device Enrollment Manager
  3. Automatic MDM enrollment
  4. Microsoft Entra registration

Correct Answer: 2

Explanation

Device Enrollment Manager, or DEM, is an Intune capability that allows a designated account to enroll and manage multiple devices. It is useful in scenarios such as shared devices, frontline environments, or deployments where many endpoints must be enrolled without assigning each enrollment operation to a separate standard user. DEM accounts have specific limitations and permissions that administrators should consider before using them. Windows Autopilot is primarily designed for provisioning devices, automatic MDM enrollment relies on user enrollment conditions, and Microsoft Entra registration establishes device identity. DEM is therefore the appropriate choice.

Question 205

Which Windows Autopilot deployment mode is designed to provision a device without requiring the user to enter credentials during the initial deployment?

  1. User-driven mode
  2. Pre-provisioning
  3. Self-deploying mode
  4. Hybrid join deployment

Correct Answer: 3

Explanation

Windows Autopilot self-deploying mode is designed for scenarios where a device should be provisioned with organizational configuration without requiring a user to authenticate during the initial deployment process. It is useful for shared devices, kiosks, and other scenarios where the device is prepared before being assigned to an individual user. User-driven mode requires user interaction and authentication, while pre-provisioning allows technicians or partners to prepare devices before users receive them. Hybrid join refers to the identity configuration. Self-deploying mode is therefore the correct choice for this scenario.

Question 206

Which Intune feature can configure a Windows device to automatically remove temporary files and reclaim disk space?

  1. Storage Sense configuration
  2. Security baseline
  3. Compliance policy
  4. Endpoint analytics

Correct Answer: 1

Explanation

Storage Sense is a Windows capability that can automatically manage storage by removing unnecessary temporary files and other supported items. Intune can be used to configure Storage Sense settings on managed Windows devices through appropriate configuration policies. This helps organizations maintain available disk space without requiring users to manually perform cleanup operations. Security baselines focus on recommended security settings, compliance policies evaluate whether devices satisfy requirements, and Endpoint analytics provides performance insights. Storage Sense configuration is therefore the appropriate option when administrators need automated management of temporary files and storage usage.

Question 207

An administrator needs to configure Microsoft Edge settings for managed Windows devices using Intune. Which policy type is appropriate?

  1. Compliance policy
  2. Administrative templates
  3. Device cleanup rule
  4. Remote Help policy

Correct Answer: 2

Explanation

Administrative templates in Intune provide policy settings that administrators can use to configure applications and Windows behavior. They are commonly used to manage Microsoft Edge settings across organizational devices, including supported browser configurations and user experience controls. Compliance policies evaluate device conditions rather than primarily configuring Edge settings. Device cleanup rules remove stale device records, while Remote Help supports remote assistance. Administrative templates are therefore an appropriate Intune policy type when an organization needs centralized configuration of supported Microsoft Edge settings across managed Windows devices.

Question 208

Which Intune action is most appropriate when a corporate Windows device must be completely reset and its existing data removed before reassignment?

  1. Sync
  2. Restart
  3. Wipe
  4. Remote lock

Correct Answer: 3

Explanation

The Wipe action is designed to reset a device and remove its data according to the selected wipe behavior. It is useful when a corporate device is being retired, repurposed, or reassigned and existing organizational or user data should not remain accessible. Sync only forces the device to check in with Intune, Restart reboots the device, and Remote lock prevents access until the device is unlocked. Administrators should carefully select wipe options because the action can remove data from the device. Wipe is therefore appropriate for a complete reset before reassignment.

Question 209

Which Microsoft Intune capability can help administrators identify devices that have not checked in recently so that stale records can be removed?

  1. Device cleanup rules
  2. Security baselines
  3. App protection policies
  4. Settings Catalog

Correct Answer: 1

Explanation

Device cleanup rules can help organizations identify and remove stale Intune device records based on the configured period since the device last checked in. This helps maintain a cleaner device inventory and reduces confusion caused by outdated records. Administrators should configure cleanup rules carefully because removing an Intune record does not necessarily mean the physical device itself has been erased. Security baselines configure security settings, app protection policies protect organizational data within supported applications, and Settings Catalog configures device settings. Device cleanup rules are therefore the correct capability for stale records.

Question 210

Which Intune feature allows an administrator to configure settings using custom OMA-URI values when a required setting is not available through standard policy interfaces?

  1. Security baseline
  2. Compliance policy
  3. Custom configuration profile
  4. Update ring

Correct Answer: 3

Explanation

Custom configuration profiles can use OMA-URI settings to configure supported Windows management settings that may not be exposed through standard Intune policy interfaces. Administrators specify the appropriate OMA-URI path, data type, and value to deliver the desired configuration through mobile device management. This approach requires accurate knowledge of the supported configuration settings because incorrect values or paths can cause policy failures. Security baselines provide predefined security configurations, compliance policies evaluate device state, and update rings manage Windows Update behavior. A custom configuration profile is therefore the appropriate choice.

Question 211

Which Intune application assignment type automatically installs an application on targeted devices without requiring users to initiate the installation?

  1. Available
  2. Required
  3. Uninstall
  4. Optional

Correct Answer: 2

Explanation

A Required application assignment instructs Intune to deploy the application automatically to targeted users or devices. Depending on the application and configuration, the installation can occur without the user manually selecting the application in Company Portal. This assignment type is useful for mandatory business applications, security software, and other software that the organization expects endpoints to have. Available assignments allow users to initiate installation, while Uninstall assignments remove applications. Required is therefore the appropriate assignment type when the application must be automatically installed on targeted endpoints.

Question 212

Which Microsoft Intune capability allows administrators to provide remote assistance to users on supported managed devices?

  1. Endpoint analytics
  2. Remote Help
  3. Device query
  4. Windows Autopilot

Correct Answer: 2

Explanation

Remote Help is an Intune capability designed to provide secure remote assistance for supported managed devices. It allows authorized support personnel to connect to users’ devices and assist with troubleshooting while applying organizational access controls. This can help support teams resolve endpoint issues without requiring physical access to the device. Endpoint analytics provides performance and experience insights, Device query retrieves supported device information, and Windows Autopilot handles provisioning and deployment. Remote Help is therefore the appropriate capability when administrators or support staff need to assist users remotely.

Question 213

Which Intune policy can determine whether a device has antivirus protection enabled before allowing access through Conditional Access?

  1. Configuration profile
  2. Application policy
  3. Compliance policy
  4. Update ring

Correct Answer: 3

Explanation

A compliance policy can evaluate whether a managed device satisfies required security conditions, including supported antivirus requirements. The resulting compliance state can then be used by Microsoft Entra Conditional Access to restrict access to organizational resources when a device fails the required conditions. Configuration profiles primarily configure settings, application policies manage software behavior or deployment, and update rings manage Windows Update settings. Compliance policies therefore provide the evaluation layer needed to determine whether the device meets the organization’s security requirements before Conditional Access makes an access decision.

Question 214

Which Microsoft Intune feature is used to configure local administrator account protection settings on supported Windows devices?

  1. Account protection
  2. Disk encryption
  3. Antivirus
  4. Firewall

Correct Answer: 1

Explanation

The Account protection endpoint security policy category in Intune provides settings related to account security and supported Windows authentication protections. It can be used to configure appropriate controls around local accounts and Windows security features, depending on the device and policy configuration. Disk encryption focuses on technologies such as BitLocker, antivirus policies configure malware protection, and firewall policies manage network traffic controls. When an administrator needs to configure supported account-related security settings through Intune endpoint security, Account protection is the relevant policy category.

Question 215

An administrator wants to prevent users from installing applications from unauthorized sources on managed Windows devices. Which security capability can help enforce application control?

  1. Delivery Optimization
  2. App Control for Business
  3. Storage Sense
  4. Endpoint analytics

Correct Answer: 2

Explanation

App Control for Business helps organizations control which applications are permitted to run on managed Windows devices. Administrators can establish policies that allow trusted applications while restricting unauthorized or unapproved software. This supports application control and can reduce the risk associated with unknown or malicious programs. Delivery Optimization manages content delivery, Storage Sense manages disk space, and Endpoint analytics provides endpoint performance insights. App Control for Business is therefore the relevant security capability when an organization wants to enforce application execution controls on supported Windows endpoints.

Question 216

Which Windows feature provides hardware-based protection that can help establish trust during the device startup process?

  1. Storage Sense
  2. TPM
  3. Event Viewer
  4. Task Manager

Correct Answer: 2

Explanation

A Trusted Platform Module, or TPM, is a hardware-based security component that can securely store cryptographic information and support platform integrity features. Windows security technologies can use TPM capabilities for operations such as device authentication, BitLocker protection, and Windows Hello for Business. Storage Sense manages disk space, Event Viewer provides system and application logs, and Task Manager displays running processes and resource usage. TPM is therefore the appropriate choice when the requirement involves hardware-based security and establishing trust during supported Windows security operations.

Question 217

Which Intune capability allows administrators to collect and examine endpoint information by running supported queries against managed Windows devices?

  1. Device query
  2. Device cleanup
  3. Company Portal
  4. Enrollment Status Page

Correct Answer: 1

Explanation

Device query enables administrators to retrieve specific information from supported managed Windows devices by using queries. This capability can assist with troubleshooting, inventory investigations, security analysis, and operational tasks. Instead of manually checking each endpoint, administrators can query relevant device information centrally and use the results to identify conditions that require attention. Device cleanup is used to manage stale records, Company Portal is primarily user-facing, and Enrollment Status Page monitors provisioning during enrollment. Device query is therefore the appropriate capability for retrieving endpoint information through supported queries.

Question 218

Which Windows Autopilot capability allows an organization to prepare a device before handing it over to the end user?

  1. Self-deploying mode
  2. Pre-provisioning
  3. Device cleanup
  4. Remote lock

Correct Answer: 2

Explanation

Windows Autopilot pre-provisioning allows an authorized technician, partner, or deployment team to prepare a device before it reaches the end user. During pre-provisioning, required applications, policies, and organizational configurations can be applied so that the user’s initial setup experience is reduced. Self-deploying mode is designed for deployments that do not require user authentication during provisioning, while device cleanup manages stale Intune records and Remote lock restricts access to a device. Pre-provisioning is therefore the appropriate Autopilot capability for preparing devices before user handoff.

Question 219

Which Intune capability helps ensure that a device automatically receives organizational configuration after it enrolls?

  1. Device category
  2. Scope tag
  3. Policy assignment
  4. Hardware inventory

Correct Answer: 3

Explanation

Policy assignments determine which users or devices receive Intune configurations, compliance policies, applications, and other management policies. Administrators can assign policies directly to groups and use supported filters or assignment conditions to refine the targeting. Once a device enrolls and meets the assignment criteria, it can receive the applicable organizational configuration. Device categories classify devices, scope tags control administrative visibility, and hardware inventory provides information about device characteristics. Policy assignment is therefore the key mechanism for ensuring that enrolled devices receive the configurations intended for their assigned users or groups.

Question 220

Which Microsoft Entra feature can require a device to be compliant before a user is permitted to access protected organizational resources?

  1. Microsoft Entra registration
  2. Conditional Access
  3. Dynamic device groups
  4. Device categories

Correct Answer: 2

Explanation

Microsoft Entra Conditional Access can use device compliance as a condition when making access decisions. An organization can configure a policy requiring users to access protected resources only from devices that meet defined Intune compliance requirements. If the device is marked noncompliant, the Conditional Access policy can block or otherwise restrict access according to its configuration. Microsoft Entra registration establishes a device identity, dynamic device groups manage automatic group membership, and device categories provide classification. Conditional Access is therefore the appropriate feature for enforcing access requirements based on device compliance.