View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.
Question 341
Which Intune feature allows administrators to define a grace period before a device is considered noncompliant?
- Assignment filter
- Security baseline
- Device category
- Compliance policy action
Correct Answer: 4
Explanation
Compliance policy actions can define what happens when a device does not meet compliance requirements, including configuring a grace period before the device is treated as noncompliant. This gives users an opportunity to correct an issue before stronger enforcement occurs. Assignment filters control policy targeting, security baselines configure recommended security settings, and device categories classify managed devices. Compliance policy actions are therefore the appropriate feature when administrators want to provide users with a defined period to remediate a compliance issue before enforcement takes effect.
Question 342
Which Microsoft Intune enrollment method automatically enrolls supported Windows devices into MDM when a user signs in with an organizational account?
- Automatic MDM enrollment
- Device cleanup
- Remote Help
- Windows Sandbox
Correct Answer: 1
Explanation
Automatic MDM enrollment allows supported Windows devices to automatically enroll into mobile device management when users sign in with organizational credentials, provided the required Microsoft Entra and Intune configuration is in place. This reduces manual enrollment steps and helps organizations automatically bring eligible devices under management. Device cleanup removes stale records, Remote Help provides remote assistance, and Windows Sandbox provides an isolated testing environment. Automatic MDM enrollment is therefore the appropriate feature when organizations want eligible Windows devices to enter Intune management automatically after user authentication.
Question 343
Which Intune feature allows administrators to manage Windows devices that are connected to both Configuration Manager and Intune?
- Windows Autopilot
- Co-management
- Company Portal
- Windows LAPS
Correct Answer: 2
Explanation
Co-management allows organizations to manage Windows devices using both Microsoft Configuration Manager and Microsoft Intune. This provides a transition path from traditional on-premises management toward cloud-based endpoint management. Organizations can gradually move supported workloads to Intune while continuing to use Configuration Manager for workloads that have not yet been transferred. Windows Autopilot focuses on provisioning, Company Portal provides user-facing functionality, and Windows LAPS manages local administrator passwords. Co-management is therefore the correct solution when both Configuration Manager and Intune need to manage Windows endpoints.
Question 344
Which Intune feature is designed to protect organizational data within supported mobile applications without requiring full device enrollment?
- Device configuration profile
- Security baseline
- App protection policy
- Update ring
Correct Answer: 3
Explanation
App protection policies are designed to protect organizational data inside supported applications, particularly in scenarios where full device enrollment may not be required. They can help control actions such as copying organizational data to unsupported applications, saving data to personal locations, and other supported data-transfer behaviors. Device configuration profiles configure device settings, security baselines provide predefined security configurations, and update rings manage Windows Update behavior. App protection policy is therefore the appropriate Intune feature when the organization needs application-level data protection without necessarily requiring full device management.
Question 345
Which Microsoft Entra authentication method provides passwordless sign-in using a device-bound credential and supported biometric or PIN verification?
- Windows Hello for Business
- BitLocker
- SmartScreen
- Storage Sense
Correct Answer: 1
Explanation
Windows Hello for Business provides passwordless authentication using a device-bound credential protected by the Windows device. Users can authenticate using supported methods such as a PIN or biometric verification, depending on device capabilities and organizational configuration. This approach reduces reliance on traditional passwords while providing strong authentication. BitLocker protects stored data through encryption, SmartScreen provides reputation-based protection, and Storage Sense manages disk space. Windows Hello for Business is therefore the appropriate authentication technology for passwordless sign-in using a device-bound credential.
Question 346
Which Windows security feature helps prevent unauthorized applications from executing by allowing administrators to define application control policies?
- Storage Sense
- File History
- App Control for Business
- Remote Desktop
Correct Answer: 3
Explanation
App Control for Business provides application control capabilities that allow organizations to manage which applications are permitted to run on Windows devices. Administrators can establish policies that restrict unauthorized or untrusted applications, helping reduce the attack surface of managed endpoints. Storage Sense manages storage space, File History provides file backup capabilities, and Remote Desktop enables remote interactive access. App Control for Business is therefore the appropriate security feature when administrators need centralized control over which applications can execute on organizational Windows devices.
Question 347
Which Windows Autopilot capability is intended for devices that need provisioning without user interaction during the initial deployment process?
- User-driven mode
- Pre-provisioning
- Company Portal
- Self-deploying mode
Correct Answer: 4
Explanation
Windows Autopilot self-deploying mode is designed for scenarios where a device should be provisioned without requiring the end user to sign in during the deployment process. It can be useful for shared devices, kiosks, and other specialized endpoints where user interaction is not appropriate during initial provisioning. User-driven mode requires user participation, while pre-provisioning allows a technician to prepare a device before delivery. Company Portal is an application and resource management interface. Self-deploying mode is therefore the correct Autopilot deployment option for minimal user interaction.
Question 348
Which Intune capability can restrict a policy assignment to devices that match a specific device attribute?
- Scope tag
- Assignment filter
- Device cleanup rule
- Compliance action
Correct Answer: 2
Explanation
Assignment filters allow administrators to refine policy and application assignments according to device attributes. For example, an administrator can target or exclude devices based on properties such as operating system, manufacturer, model, or other supported attributes. This provides more precise targeting without requiring changes to Microsoft Entra group membership. Scope tags control which administrative objects administrators can see, device cleanup rules remove stale device records, and compliance actions define responses to compliance states. Assignment filters are therefore the correct capability for attribute-based assignment targeting.
Question 349
Which Intune application feature allows a newer application to replace an older application during deployment?
- Dependency
- Detection rule
- Supersedence
- Requirement rule
Correct Answer: 3
Explanation
Supersedence allows administrators to configure a newer application to replace an older application during deployment. This is useful when an organization is moving users from an outdated application version to a newer package or product. Administrators can configure supported supersedence relationships so that Intune understands which application should replace another. Dependencies identify prerequisite applications, detection rules determine installation state, and requirement rules determine whether a device meets installation conditions. Supersedence is therefore the appropriate feature for managing application replacement through Intune.
Question 350
Which Windows management tool provides a graphical interface for viewing running processes and resource utilization?
- Event Viewer
- Services
- Device Manager
- Task Manager
Correct Answer: 4
Explanation
Task Manager provides a graphical interface for viewing running processes, applications, services, performance information, and resource utilization on Windows devices. Administrators can use it to identify applications consuming excessive CPU, memory, disk, or network resources and to troubleshoot performance issues. Event Viewer focuses on event logs, Services manages Windows services, and Device Manager manages hardware devices and drivers. Task Manager is therefore the correct tool when an administrator needs a quick graphical overview of active processes and system resource consumption.
Question 351
Which Intune feature can configure supported Microsoft Edge settings for managed Windows devices?
- Edge configuration policy
- Device cleanup rule
- Compliance action
- Remote Help
Correct Answer: 1
Explanation
Edge configuration policies in Intune allow administrators to manage supported Microsoft Edge settings across organizational devices. Administrators can configure browser behavior, security-related options, extensions, and other supported settings according to organizational requirements. Device cleanup rules manage stale records, compliance actions define responses to compliance states, and Remote Help provides remote assistance. An Edge configuration policy is therefore the appropriate choice when an organization needs centralized management of Microsoft Edge settings on managed Windows endpoints.
Question 352
Which Intune feature allows administrators to assign administrative permissions according to specific job responsibilities?
- Role-based access control
- Device inventory
- Update ring
- Device category
Correct Answer: 1
Explanation
Role-based access control, or RBAC, allows organizations to delegate Intune administration according to job responsibilities. Administrators can assign predefined roles or create appropriate custom roles and then assign them to users or groups. This helps implement least-privilege administration by ensuring that personnel receive only the permissions necessary for their responsibilities. Device inventory provides endpoint information, update rings manage Windows Update behavior, and device categories classify devices. RBAC is therefore the appropriate feature for controlling administrative permissions according to specific organizational roles.
Question 353
Which Intune endpoint security policy is used to manage BitLocker settings on supported Windows devices?
- Antivirus
- Firewall
- Disk encryption
- Account protection
Correct Answer: 3
Explanation
The Disk encryption endpoint security policy is designed to configure supported disk encryption settings, including BitLocker-related controls, on managed Windows devices. Administrators can use this policy to establish encryption requirements and configure supported BitLocker behavior across organizational endpoints. Antivirus policies manage malware protection, Firewall policies configure network protection, and Account protection manages supported identity and credential-related settings. Disk encryption is therefore the appropriate endpoint security policy category when administrators need to centrally configure BitLocker and related encryption settings.
Question 354
Which Intune capability can identify whether a managed device has sufficient hardware resources for a particular deployment requirement?
- Company Portal
- Scope tag
- Requirement rule
- Remote Help
Correct Answer: 3
Explanation
Requirement rules allow administrators to define conditions that a device must satisfy before a Win32 application can be installed. Supported requirements can include operating system architecture, available disk space, minimum operating system version, and other applicable conditions. This helps prevent software from being deployed to devices that do not meet its technical prerequisites. Company Portal provides user-facing application access, scope tags manage administrative visibility, and Remote Help supports troubleshooting. Requirement rule is therefore the appropriate feature for determining whether a device satisfies predefined installation requirements.
Question 355
Which Windows feature allows users to restore previous versions of personal files from automatically created file backups?
- File History
- SmartScreen
- Credential Guard
- Storage Sense
Correct Answer: 1
Explanation
File History is a Windows feature that can automatically save copies of selected personal files and allow users to restore previous versions when necessary. It is useful for recovering files that were accidentally modified, deleted, or replaced. SmartScreen provides reputation-based protection, Credential Guard protects sensitive authentication information, and Storage Sense manages storage space by automatically removing certain unnecessary files. File History is therefore the correct Windows feature when the requirement is to maintain recoverable previous versions of user files.
Question 356
Which Intune feature provides administrators with a centralized view of device hardware and software information collected from managed endpoints?
- Remote Help
- Device inventory
- App protection policy
- Enrollment Status Page
Correct Answer: 2
Explanation
Device inventory provides administrators with information collected from managed endpoints, including supported hardware, operating system, and software details. This information helps IT teams understand the organization’s device environment, troubleshoot issues, identify device configurations, and support management decisions. Remote Help is designed for remote assistance, app protection policies protect organizational data within supported applications, and the Enrollment Status Page controls deployment progress. Device inventory is therefore the appropriate Intune capability when administrators need centralized information about managed endpoint characteristics.
Question 357
Which Windows update feature controls settings such as update deferrals, restart behavior, and installation schedules for managed devices?
- Feature update policy
- Expedite update policy
- Update ring
- Device compliance policy
Correct Answer: 3
Explanation
Update rings allow administrators to configure Windows Update behavior for managed devices. Depending on supported settings, administrators can control update deferrals, deadlines, restart behavior, active hours, and other servicing options. Feature update policies are used to target specific Windows feature versions, while expedite update policies accelerate deployment of selected quality updates. Compliance policies evaluate whether devices meet organizational requirements rather than directly controlling normal Windows Update behavior. Update ring is therefore the appropriate policy when administrators need to manage general Windows Update servicing behavior.
Question 358
Which Intune feature allows administrators to add descriptive information to managed devices so they can be grouped or identified according to organizational needs?
- Device cleanup
- Device category
- Security baseline
- Conditional Access
Correct Answer: 2
Explanation
Device categories allow administrators to classify managed devices according to organizational needs. Categories can help users and administrators distinguish between different types of devices and can be useful when organizing device management or applying category-based processes. Device cleanup removes stale records, security baselines configure recommended security settings, and Conditional Access controls access to resources based on defined conditions. Device category is therefore the appropriate Intune feature when an organization needs to classify or identify managed devices according to organizational characteristics.
Question 359
Which Microsoft Entra feature can automatically maintain device group membership based on a defined membership rule?
- Scope tags
- Assignment filters
- Dynamic device group
- Enrollment restrictions
Correct Answer: 3
Explanation
Dynamic device groups use membership rules to automatically determine which devices belong to a Microsoft Entra group. When a device’s relevant attributes match the configured rule, the device can be included automatically. This reduces the need for administrators to manually maintain device membership and is useful for targeting Intune policies, applications, and other resources. Scope tags control administrative visibility, assignment filters refine Intune assignments, and enrollment restrictions control which devices can enroll. Dynamic device groups are therefore the correct choice for rule-based automatic device membership.
Question 360
Which Intune device action removes organizational data and management from a device while generally preserving personal content?
- Retire
- Wipe
- Fresh Start
- Autopilot Reset
Correct Answer: 1
Explanation
The Retire action is designed to remove organizational management and supported corporate data from a device while generally preserving personal user content. It is particularly useful when an organization needs to remove its management from a personally owned device or when a device should no longer access corporate resources. Wipe performs a broader reset and can erase device data, Fresh Start reinstalls Windows with supported removal behavior, and Autopilot Reset prepares a device for reuse while retaining its organizational enrollment state. Retire is therefore the appropriate action for removing organizational control while preserving personal content.