Microsoft MD-102 Practice Test Questions and Exam Dumps Part13 Q241-260

View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.

 

Question 241

Which Microsoft Intune feature allows administrators to configure a device policy using individual Windows settings from a searchable collection?

  1. Settings Catalog
  2. Compliance policy
  3. Device cleanup
  4. Company Portal

Correct Answer: 1

Explanation

The Settings Catalog provides administrators with a searchable collection of Windows settings that can be configured through Intune. Instead of creating numerous custom policies, administrators can search for a specific setting, configure its value, and assign the resulting profile to users or devices. This provides detailed control over Windows configuration while keeping policy management centralized. Compliance policies evaluate whether devices satisfy requirements, device cleanup manages stale records, and Company Portal provides user-facing application and device functions. Settings Catalog is therefore the appropriate feature for configuring individual Windows settings from a centralized catalog.

Question 242

Which Microsoft Entra join type is commonly used when an organization wants Windows devices joined to both on-premises Active Directory and Microsoft Entra ID?

  1. Microsoft Entra registered
  2. Microsoft Entra hybrid joined
  3. Microsoft Entra joined
  4. Device Enrollment Manager

Correct Answer: 2

Explanation

Microsoft Entra hybrid joined devices are joined to an on-premises Active Directory domain while also being registered with Microsoft Entra ID. This configuration is commonly used by organizations transitioning from traditional domain-based management toward cloud-based identity and endpoint management. Microsoft Entra joined devices are joined directly to Microsoft Entra ID without requiring traditional domain membership. Microsoft Entra registered devices generally represent lighter registration scenarios, including many personal-device situations. Device Enrollment Manager is an Intune enrollment capability rather than a Microsoft Entra device join type. Hybrid join therefore matches the described environment.

Question 243

Which Intune application assignment type is used when an administrator wants to remove an application from targeted devices?

  1. Required
  2. Available
  3. Uninstall
  4. Dependency

Correct Answer: 3

Explanation

The Uninstall assignment type instructs Intune to remove a supported application from targeted users or devices. This is useful when an application is no longer approved, has been replaced, or should not remain installed on particular endpoints. Required assignments install applications automatically, Available assignments make applications available for users to install through Company Portal, and dependencies define prerequisite applications. The Uninstall assignment therefore provides the appropriate mechanism when administrators need to centrally remove an application from targeted managed devices.

Question 244

Which Windows Autopilot feature helps ensure that required policies and applications are processed before a user receives access to the desktop?

  1. Windows Update
  2. Enrollment Status Page
  3. Storage Sense
  4. Device query

Correct Answer: 2

Explanation

The Enrollment Status Page, or ESP, can be configured to track and control the provisioning process during supported Windows enrollment scenarios. It can display the progress of required applications, policies, and configuration while the device is being prepared. Organizations can use ESP settings to help ensure that important configurations are processed before users begin working with the device. Windows Update manages operating system updates, Storage Sense manages disk space, and Device query retrieves endpoint information. ESP is therefore the appropriate feature for managing the initial provisioning experience.

Question 245

Which Intune capability allows administrators to assign administrative permissions based on predefined roles?

  1. Scope tags
  2. Device categories
  3. Role-based access control
  4. Assignment filters

Correct Answer: 3

Explanation

Role-based access control, or RBAC, allows Intune administrators to delegate administrative permissions according to predefined or customized roles. Administrators can control which management tasks specific users or groups are permitted to perform, supporting the principle of least privilege. Scope tags can further limit administrative visibility when combined with RBAC. Device categories classify devices, while assignment filters refine policy targeting. RBAC is therefore the appropriate Intune capability when an organization needs to control administrative permissions according to defined responsibilities.

Question 246

Which Windows security technology helps prevent credentials stored in the Windows authentication subsystem from being accessed by malicious processes?

  1. Credential Guard
  2. Storage Sense
  3. Delivery Optimization
  4. File History

Correct Answer: 1

Explanation

Credential Guard uses virtualization-based security to isolate and protect certain sensitive Windows credentials from unauthorized access by malicious processes. By placing protected credential information in an isolated environment, it can reduce the risk of credential theft techniques targeting the operating system. Storage Sense manages disk space, Delivery Optimization improves content distribution, and File History provides file backup capabilities. Credential Guard is therefore the appropriate Windows security technology when the goal is to protect sensitive authentication credentials from malicious processes operating within the normal Windows environment.

Question 247

Which Intune feature can be used to configure a Windows device so that its settings follow organizational requirements even when users change local preferences?

  1. Configuration profile
  2. Device cleanup rule
  3. Remote Help
  4. Company Portal

Correct Answer: 1

Explanation

Configuration profiles allow administrators to centrally configure supported Windows settings and apply organizational requirements to managed devices. Profiles can contain settings for areas such as security, device restrictions, application behavior, and user experience. When assigned appropriately, these configurations help establish consistent endpoint settings across an organization. Device cleanup rules remove stale records, Remote Help provides remote assistance, and Company Portal provides user-facing management functions. A configuration profile is therefore the appropriate Intune feature when administrators need to centrally apply and maintain Windows device settings.

Question 248

Which Microsoft Defender capability is designed to detect, investigate, and respond to advanced threats on organizational endpoints?

  1. Microsoft Defender SmartScreen
  2. Microsoft Defender for Endpoint
  3. Microsoft Defender Firewall
  4. Microsoft Defender Antivirus

Correct Answer: 2

Explanation

Microsoft Defender for Endpoint is an endpoint security platform designed to provide capabilities for threat detection, investigation, response, and endpoint security monitoring. It can integrate with Microsoft Intune to improve visibility and help organizations manage security posture across supported devices. SmartScreen focuses on reputation-based protection, Defender Firewall controls network traffic, and Defender Antivirus provides malware detection and protection. Microsoft Defender for Endpoint is therefore the appropriate capability when an organization requires broader endpoint detection and response functionality rather than a single security control.

Question 249

Which Intune feature can automatically install an application after another required application has been successfully installed?

  1. Assignment filter
  2. Supersedence
  3. Dependency
  4. Detection rule

Correct Answer: 3

Explanation

Application dependencies allow administrators to define prerequisite relationships between Win32 applications. When a dependent application requires another application or component, Intune can process the dependency before installing the main application. This is useful for software that requires runtimes, frameworks, agents, or other supporting components. Assignment filters control which devices receive an application, supersedence manages application replacement, and detection rules determine whether an application is already installed. Dependency is therefore the appropriate Intune capability when one application must be installed before another.

Question 250

Which Microsoft Intune capability can evaluate whether a Windows device has Secure Boot enabled?

  1. Compliance policy
  2. Available application
  3. Scope tag
  4. Device category

Correct Answer: 1

Explanation

Compliance policies can evaluate supported device security conditions, including requirements such as Secure Boot where supported by the platform and configuration. An organization can use compliance requirements to determine whether a device meets its security standards and can combine the resulting compliance state with Conditional Access. Available applications provide optional software, scope tags control administrative visibility, and device categories classify endpoints. Compliance policy is therefore the appropriate capability when an administrator needs to evaluate Secure Boot as part of the device’s compliance posture.

Question 251

Which Windows feature allows users to restore previous versions of personal files that were backed up automatically?

  1. Storage Sense
  2. File History
  3. Delivery Optimization
  4. Windows Sandbox

Correct Answer: 2

Explanation

File History is a Windows feature that can automatically back up supported personal files and allow users to restore previous versions. It can help protect user documents from accidental deletion, modification, or other file-related problems. Storage Sense manages storage space, Delivery Optimization improves the distribution of Windows and application content, and Windows Sandbox provides an isolated environment for testing applications. File History is therefore the appropriate feature when users need to recover earlier versions of backed-up personal files.

Question 252

Which Intune capability allows administrators to specify a minimum amount of available storage before a Win32 application can be installed?

  1. Detection rule
  2. Requirement rule
  3. Supersedence
  4. App protection policy

Correct Answer: 2

Explanation

Win32 application requirement rules can specify conditions that a device must satisfy before Intune installs the application. Supported conditions can include minimum operating system versions, architecture, available disk space, and other deployment requirements. This prevents applications from being installed on devices that do not meet their technical prerequisites. Detection rules determine whether the application is already installed, supersedence manages replacement of applications, and app protection policies protect organizational data within supported applications. Requirement rule is therefore the appropriate choice for enforcing minimum available storage before installation.

Question 253

Which Intune policy is primarily used to configure settings related to Microsoft Defender Antivirus?

  1. Account protection
  2. Disk encryption
  3. Antivirus
  4. Firewall

Correct Answer: 3

Explanation

The Antivirus endpoint security policy category in Intune is designed to configure supported Microsoft Defender Antivirus settings on managed Windows devices. Administrators can use it to manage settings related to malware protection, real-time protection, scanning, cloud-delivered protection, and other supported controls. Account protection focuses on account and authentication security, disk encryption manages encryption technologies such as BitLocker, and firewall policies manage network protection. Antivirus is therefore the correct endpoint security policy category when the objective is to centrally configure Microsoft Defender Antivirus.

Question 254

Which Intune action forces a managed device to contact the Intune service and check for updated policies?

  1. Wipe
  2. Sync
  3. Retire
  4. Remote lock

Correct Answer: 2

Explanation

The Sync action prompts a managed device to check in with the Intune service and retrieve available policy, configuration, application, or other management updates. Administrators commonly use Sync when troubleshooting situations where a policy has been assigned but has not yet appeared on the device. Wipe resets the device according to the selected wipe behavior, Retire removes organizational management and data while generally preserving personal information, and Remote lock restricts device access. Sync is therefore the appropriate action when administrators need to initiate a management check-in.

Question 255

Which Windows security feature can help block users from accessing malicious or suspicious websites through reputation-based protection?

  1. SmartScreen
  2. BitLocker
  3. Credential Guard
  4. Windows LAPS

Correct Answer: 1

Explanation

Microsoft Defender SmartScreen provides reputation-based protection that can help warn users about malicious websites, suspicious downloads, and potentially unwanted content. It uses reputation information to identify known or suspected threats and can help prevent users from interacting with unsafe content. BitLocker protects stored data through encryption, Credential Guard protects sensitive credentials, and Windows LAPS manages local administrator passwords. SmartScreen is therefore the appropriate Windows security feature when the objective is to provide reputation-based protection against malicious or suspicious websites and downloads.

Question 256

Which Intune feature allows administrators to protect organizational data in supported mobile applications by controlling actions such as copy and paste?

  1. App protection policy
  2. Update ring
  3. Enrollment restriction
  4. Device cleanup rule

Correct Answer: 1

Explanation

App protection policies help protect organizational data inside supported applications, particularly in mobile application management scenarios. Administrators can configure controls governing actions such as copying, pasting, saving, or transferring corporate data between applications. These policies can be useful when organizations need data protection without fully enrolling a personally owned device into mobile device management. Update rings manage Windows Update behavior, enrollment restrictions control device enrollment, and device cleanup rules manage stale records. App protection policy is therefore the appropriate capability for controlling corporate data handling within supported applications.

Question 257

Which Windows management technology allows administrators to execute supported management operations through PowerShell and automation tools?

  1. Microsoft Graph
  2. File History
  3. Storage Sense
  4. Windows Sandbox

Correct Answer: 1

Explanation

Microsoft Graph provides APIs that can be used to automate and manage Microsoft cloud services, including supported Intune and Microsoft Entra operations. Administrators and developers can use Microsoft Graph with PowerShell and other automation tools to retrieve information, manage devices, configure policies, and perform other supported administrative tasks. File History provides backup functionality, Storage Sense manages storage, and Windows Sandbox provides an isolated environment. Microsoft Graph is therefore the appropriate technology when an organization wants to automate supported Intune management operations programmatically.

Question 258

Which Windows Autopilot deployment approach is appropriate when a technician prepares a device before the end user receives it?

  1. User-driven deployment
  2. Pre-provisioning
  3. Self-deploying mode
  4. Automatic enrollment

Correct Answer: 2

Explanation

Autopilot pre-provisioning allows a technician or deployment partner to prepare a Windows device before it is delivered to the end user. Required applications, policies, and organizational configurations can be applied during the technician phase, reducing the amount of setup required later. User-driven deployment expects the end user to participate in the provisioning process, while self-deploying mode is intended for scenarios that do not require user authentication during initial deployment. Automatic enrollment concerns MDM enrollment rather than the technician preparation process. Pre-provisioning therefore matches this scenario.

Question 259

Which Intune capability can identify devices that have not recently checked in and help administrators remove their stale management records?

  1. Endpoint analytics
  2. Device cleanup rules
  3. Security baseline
  4. App configuration policy

Correct Answer: 2

Explanation

Device cleanup rules allow administrators to configure Intune to identify devices that have not checked in within a specified period and remove their stale Intune records. This helps maintain an accurate device inventory and reduces administrative clutter caused by inactive endpoints. The cleanup process should be configured carefully because deleting an Intune record is not the same as physically erasing a device. Endpoint analytics focuses on endpoint performance, security baselines configure security settings, and app configuration policies manage application settings. Device cleanup rules are therefore the appropriate capability for managing stale device records.

Question 260

Which Intune capability allows administrators to apply different configuration policies to devices according to selected device attributes without manually creating separate groups?

  1. Scope tags
  2. Device categories
  3. Assignment filters
  4. Enrollment restrictions

Correct Answer: 3

Explanation

Assignment filters allow administrators to refine the targeting of Intune policies and applications using supported device attributes. This makes it possible to assign a policy broadly while excluding or including devices that meet specific conditions. For example, an administrator can use device attributes to target different configurations without maintaining numerous manually managed groups. Scope tags control administrative visibility, device categories classify devices, and enrollment restrictions determine which devices can enroll. Assignment filters are therefore the appropriate capability for dynamically refining policy assignments according to device attributes.