Microsoft MD-102 Practice Test Questions and Exam Dumps Part17 Q321-340

View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.

 

Question 321

Which Intune feature allows administrators to control whether personally owned Windows devices can enroll?

  1. Enrollment restrictions
  2. Device cleanup rules
  3. Scope tags
  4. Update rings

Correct Answer: 1

Explanation

Enrollment restrictions allow Intune administrators to control which types of devices can enroll into device management. Administrators can configure platform restrictions and ownership-related settings to prevent unsupported or unwanted devices from enrolling. This is particularly useful when an organization wants to restrict personally owned Windows devices while allowing corporate-owned endpoints. Device cleanup rules remove stale records, scope tags control administrative visibility, and update rings manage Windows Update behavior. Enrollment restrictions are therefore the appropriate feature for controlling which device types and ownership categories are permitted to enroll in Intune.

Question 322

Which Microsoft Entra device state is commonly used when a user adds a personal device for access to organizational resources without fully joining it to the organization?

  1. Microsoft Entra joined
  2. Microsoft Entra registered
  3. Microsoft Entra hybrid joined
  4. Device Enrollment Manager

Correct Answer: 2

Explanation

Microsoft Entra registered is commonly used for personally owned devices that need an organizational identity for accessing resources without becoming fully joined to the organization’s Microsoft Entra environment. This model supports bring-your-own-device scenarios and can work with additional management or application protection controls. Microsoft Entra joined is intended for devices fully joined to the cloud identity environment, while hybrid joined combines on-premises Active Directory with Microsoft Entra ID. Device Enrollment Manager is an enrollment role rather than a device identity state. Microsoft Entra registered is therefore correct.

Question 323

Which Windows Autopilot capability allows an IT technician or partner to prepare a device before it is delivered to the end user?

  1. Self-deploying mode
  2. User-driven deployment
  3. Pre-provisioning
  4. Device cleanup

Correct Answer: 3

Explanation

Windows Autopilot pre-provisioning allows an IT technician, reseller, or other authorized party to prepare a device before delivering it to the end user. During pre-provisioning, required applications, policies, and organizational configurations can be applied before the user receives the device. This can reduce the amount of setup the user must complete during first sign-in. User-driven deployment requires user participation, while self-deploying mode is intended for scenarios where user authentication is not required during provisioning. Pre-provisioning is therefore the appropriate choice for technician-assisted preparation.

Question 324

Which Intune application assignment type automatically installs an application on targeted managed devices?

  1. Available
  2. Uninstall
  3. Required
  4. Dependency

Correct Answer: 3

Explanation

A Required application assignment instructs Intune to automatically deploy an application to the targeted users or devices. This assignment type is appropriate for mandatory applications such as security agents, business software, or organizational tools that every applicable endpoint must have. Available assignments allow users to install applications from Company Portal when needed. Uninstall assignments remove applications, while dependencies identify prerequisite applications. Required is therefore the correct assignment type when administrators need an application to be automatically installed on targeted managed devices.

Question 325

Which Windows management technology enables mobile device management policies to be applied to Windows without traditional Group Policy?

  1. MDM
  2. SMB
  3. DNS
  4. NTFS

Correct Answer: 1

Explanation

Mobile Device Management, or MDM, allows Windows devices to receive management policies through modern cloud-based management platforms such as Microsoft Intune. MDM uses supported management interfaces to configure settings, enforce security requirements, deploy applications, and perform management actions without requiring traditional domain-based Group Policy for every configuration. SMB is a file and printer sharing protocol, DNS provides name resolution, and NTFS is a Windows file system. MDM is therefore the correct technology for applying modern Windows management policies through Intune.

Question 326

Which Intune feature can use a device attribute to include or exclude devices from a policy assignment without changing group membership?

  1. Security baseline
  2. Assignment filter
  3. Device category
  4. Compliance policy

Correct Answer: 2

Explanation

Assignment filters allow administrators to refine Intune policy and application assignments based on device attributes. They can be used to include or exclude devices from an assignment without requiring administrators to modify the underlying Microsoft Entra group membership. This provides more precise targeting for configuration profiles, applications, compliance policies, and other supported workloads. Security baselines provide predefined security configurations, device categories classify devices, and compliance policies evaluate device requirements. Assignment filters are therefore the appropriate feature for refining assignments according to device attributes.

Question 327

Which Windows feature can automatically manage local administrator passwords by generating and rotating unique passwords?

  1. Windows Hello for Business
  2. Windows LAPS
  3. Credential Guard
  4. BitLocker

Correct Answer: 2

Explanation

Windows LAPS, or Windows Local Administrator Password Solution, manages local administrator passwords by securely generating, storing, and rotating passwords according to configured policies. This helps reduce the security risks associated with using identical or static local administrator credentials across multiple devices. Windows Hello for Business provides passwordless authentication, Credential Guard helps protect authentication credentials, and BitLocker provides disk encryption. Windows LAPS is therefore the appropriate feature when an organization needs centralized management and regular rotation of local administrator passwords on Windows devices.

Question 328

Which Intune feature provides users with a self-service location for installing applications that have been assigned as available?

  1. Company Portal
  2. Endpoint analytics
  3. Settings Catalog
  4. Windows Autopilot

Correct Answer: 1

Explanation

Company Portal provides users with a self-service interface for accessing applications, devices, and supported organizational resources managed through Intune. When an application is assigned as Available, users can typically locate it in Company Portal and choose whether to install it. Endpoint analytics focuses on endpoint performance and user experience, Settings Catalog provides administrative configuration options, and Windows Autopilot supports device provisioning. Company Portal is therefore the correct choice when users need a self-service interface for discovering and installing optional applications assigned through Intune.

Question 329

Which Intune feature is specifically designed to deploy Microsoft 365 Apps such as Word, Excel, and PowerPoint to managed Windows devices?

  1. Web app
  2. Microsoft 365 Apps
  3. App protection policy
  4. Device configuration profile

Correct Answer: 2

Explanation

The Microsoft 365 Apps application type in Intune is designed to deploy supported Microsoft 365 productivity applications to managed devices. Administrators can configure which Office applications and supported settings should be included in the deployment and then assign the application to appropriate users or devices. Web apps provide shortcuts to browser-based resources, app protection policies protect organizational data within supported applications, and configuration profiles manage device settings. Microsoft 365 Apps is therefore the appropriate application type when deploying applications such as Word, Excel, and PowerPoint through Intune.

Question 330

Which Windows feature helps protect files in selected folders from unauthorized modification by potentially malicious applications?

  1. SmartScreen
  2. Credential Guard
  3. Controlled folder access
  4. Storage Sense

Correct Answer: 3

Explanation

Controlled folder access is a Microsoft Defender feature designed to help protect selected folders against unauthorized changes by potentially malicious applications. It can reduce the impact of ransomware and similar threats by restricting untrusted applications from modifying protected locations. SmartScreen provides reputation-based protection, Credential Guard protects sensitive authentication information, and Storage Sense helps manage disk space. Controlled folder access is therefore the appropriate security feature when the requirement is to prevent unauthorized applications from modifying files in protected folders.

Question 331

Which Intune feature can provide a predefined collection of Microsoft-recommended security configuration settings for Windows devices?

  1. Security baseline
  2. Device category
  3. Assignment filter
  4. Company Portal

Correct Answer: 1

Explanation

Security baselines provide predefined collections of recommended security settings that administrators can deploy to supported Windows devices. They help organizations establish a consistent security configuration without manually creating every individual setting. Administrators can review and customize supported baseline settings before assigning them to users or devices. Device categories classify endpoints, assignment filters refine targeting, and Company Portal provides user-facing functionality. Security baseline is therefore the correct choice when an organization wants a centralized collection of recommended Windows security configurations.

Question 332

Which Windows Autopilot feature displays deployment progress and can prevent users from accessing the desktop until required configurations are completed?

  1. Windows LAPS
  2. Enrollment Status Page
  3. Endpoint analytics
  4. Company Portal

Correct Answer: 2

Explanation

The Enrollment Status Page, or ESP, displays deployment progress during Windows Autopilot and enrollment scenarios and can control whether the user is allowed to reach the Windows desktop before required configurations are completed. It can track the installation of required applications and the application of device configurations during provisioning. Windows LAPS manages local administrator passwords, Endpoint analytics provides performance insights, and Company Portal offers user-facing application management. The Enrollment Status Page is therefore the correct feature for controlling and displaying deployment progress during device provisioning.

Question 333

Which Intune policy is primarily used to evaluate whether Windows devices meet requirements rather than directly configure most device settings?

  1. Compliance policy
  2. Settings Catalog
  3. Administrative template
  4. Security baseline

Correct Answer: 1

Explanation

A compliance policy evaluates whether a managed device satisfies defined organizational requirements. Examples can include operating system version, encryption status, firewall state, antivirus protection, password requirements, and other supported conditions. Compliance policies can also work with Conditional Access to help control access to organizational resources based on device compliance status. Settings Catalog, Administrative Templates, and Security Baselines are primarily configuration mechanisms. Compliance policy is therefore the correct choice when the main requirement is to evaluate whether a device meets defined security or management conditions.

Question 334

Which Intune feature allows administrators to configure Windows settings using traditional policy-style templates for supported settings?

  1. Device query
  2. Administrative Templates
  3. Remote Help
  4. Device cleanup

Correct Answer: 2

Explanation

Administrative Templates in Intune provide policy-style configuration settings for supported Windows devices. They offer a familiar approach for administrators who have previously managed Windows through traditional Group Policy templates. Administrators can configure supported settings and assign the resulting profile to users or devices. Device query retrieves endpoint information, Remote Help provides remote assistance, and device cleanup manages stale records. Administrative Templates are therefore the appropriate Intune feature when administrators need to configure Windows using template-based policy settings.

Question 335

Which Windows update policy allows administrators to accelerate the installation of a specific quality update when a device needs urgent remediation?

  1. Update ring
  2. Feature update policy
  3. Expedite update policy
  4. Compliance policy

Correct Answer: 3

Explanation

An Expedite update policy can accelerate the deployment of specific Windows quality updates when organizations need devices to receive an update quickly. This is useful when a particular security update requires rapid deployment rather than waiting for the normal update ring schedule. Update rings control broader Windows Update behavior, feature update policies target Windows feature versions, and compliance policies evaluate device requirements. Expedite update policy is therefore the correct option when administrators need to speed up deployment of a specific quality update across applicable managed devices.

Question 336

Which Intune capability can help administrators remotely assist a user by viewing or controlling a supported managed device?

  1. Remote Help
  2. Device cleanup
  3. Assignment filter
  4. Scope tag

Correct Answer: 1

Explanation

Remote Help is an Intune capability that allows authorized support personnel to remotely assist users on supported managed devices. It is designed for troubleshooting and support scenarios where an administrator or help-desk technician needs to interact with a user’s device remotely. Device cleanup manages inactive device records, assignment filters refine policy targeting, and scope tags control administrative visibility. Remote Help is therefore the appropriate capability when an organization needs a supported remote assistance solution integrated with its endpoint management environment.

Question 337

Which Intune application mechanism determines whether a Win32 application is already installed on a device?

  1. Requirement rule
  2. Detection rule
  3. Dependency
  4. Assignment filter

Correct Answer: 2

Explanation

Detection rules determine whether a Win32 application is already installed or otherwise meets the configured detection condition. Intune uses the detection result to determine whether an application installation is required or whether the desired state has already been reached. Requirement rules determine whether the device is eligible for installation, dependencies define prerequisite applications, and assignment filters control targeting. Detection rule is therefore the correct mechanism when administrators need Intune to determine whether a Win32 application is present on a managed device.

Question 338

Which device action is generally appropriate when an administrator needs to immediately reboot a managed Windows device remotely?

  1. Wipe
  2. Retire
  3. Restart
  4. Fresh Start

Correct Answer: 3

Explanation

The Restart action allows administrators to remotely reboot a managed device without performing a broader device reset or removing organizational management. It can be useful when troubleshooting, completing configuration changes, or applying certain management operations that require a restart. Wipe resets the device and can remove data, Retire removes organizational management while generally preserving personal data, and Fresh Start reinstalls Windows while removing applications according to its configuration. Restart is therefore the appropriate action when the primary requirement is simply to remotely reboot the device.

Question 339

Which Microsoft Intune feature helps administrators identify hardware information such as device model, manufacturer, and operating system details?

  1. Device inventory
  2. Remote Help
  3. Conditional Access
  4. Security baseline

Correct Answer: 1

Explanation

Device inventory provides administrators with information collected from managed endpoints, including supported hardware and software details. This information can help IT teams identify device models, manufacturers, operating system information, and other endpoint characteristics useful for management and troubleshooting. Remote Help is used for remote assistance, Conditional Access controls resource access based on configured conditions, and security baselines configure security settings. Device inventory is therefore the appropriate Intune capability when administrators need centralized information about managed device hardware and software characteristics.

Question 340

Which Intune capability can automatically assign devices to a Microsoft Entra group based on device properties such as operating system or manufacturer?

  1. Static group membership
  2. Dynamic device group
  3. Device Enrollment Manager
  4. Scope tag

Correct Answer: 2

Explanation

Dynamic device groups in Microsoft Entra ID can automatically include devices based on defined membership rules that evaluate device properties. Administrators can use attributes such as operating system, manufacturer, model, or other supported properties to create dynamic membership rules. This allows device groups to update automatically as device information changes, reducing manual administration. Static groups require membership to be managed directly, Device Enrollment Manager is an enrollment role, and scope tags control administrative visibility. Dynamic device group is therefore the appropriate solution for property-based automatic device membership.