Microsoft MD-102 Practice Test Questions and Exam Dumps Part19 Q361-380

View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.

 

Question 361

Which Intune feature can help administrators identify whether a Windows device is ready for an operating system upgrade based on hardware and compatibility information?

  1. Endpoint analytics
  2. Device cleanup
  3. Scope tags
  4. Company Portal

Correct Answer: 1

Explanation

Endpoint analytics can provide insights that help organizations assess Windows device readiness and identify endpoint issues that may affect deployment and user experience. Readiness information can help administrators determine which devices may require attention before a Windows upgrade or broader deployment. Device cleanup focuses on stale records, scope tags control administrative visibility, and Company Portal provides user-facing access to applications and organizational resources. Endpoint analytics is therefore the appropriate Intune capability when administrators need information that supports Windows readiness and endpoint deployment planning.

Question 362

Which Intune feature allows administrators to collect diagnostic information from a managed Windows device for troubleshooting?

  1. Device category
  2. Collect diagnostics
  3. Update ring
  4. Assignment filter

Correct Answer: 2

Explanation

The Collect diagnostics capability allows administrators to remotely gather supported diagnostic information from managed Windows devices. This can help troubleshoot enrollment problems, policy application issues, application failures, and other endpoint management problems without requiring physical access to the device. Device categories classify endpoints, update rings control Windows Update behavior, and assignment filters refine policy targeting. Collect diagnostics is therefore the appropriate capability when administrators need additional troubleshooting information from a managed Windows device.

Question 363

Which Intune feature allows administrators to configure policies that protect corporate data when users access it through supported mobile applications?

  1. Device compliance policy
  2. Security baseline
  3. App protection policy
  4. Update ring

Correct Answer: 3

Explanation

App protection policies help protect organizational data inside supported mobile applications. They can apply controls to actions such as copying, pasting, saving, and transferring corporate information, depending on the supported application and configured policy. This is particularly useful for mobile scenarios where users may access organizational resources from personally owned devices without full device enrollment. Compliance policies evaluate device conditions, security baselines configure security settings, and update rings manage Windows Update. App protection policy is therefore the correct choice for application-level corporate data protection.

Question 364

Which Windows Autopilot capability allows a device to be reset while keeping its organizational enrollment and management configuration?

  1. Wipe
  2. Retire
  3. Fresh Start
  4. Autopilot Reset

Correct Answer: 4

Explanation

Autopilot Reset allows an organization to quickly prepare a Windows device for reuse while maintaining its Microsoft Entra identity and Intune management connection. It removes user data, applications, and certain settings while preserving the device’s organizational provisioning state. This makes it useful when a device is being reassigned to another employee or returned to a managed state. Wipe performs a broader reset, Retire removes organizational management, and Fresh Start reinstalls Windows with supported removal behavior. Autopilot Reset is therefore the correct choice.

Question 365

Which Intune feature can configure security settings for Windows user accounts, including policies related to local administrator accounts?

  1. Account protection
  2. Device inventory
  3. Assignment filter
  4. Update ring

Correct Answer: 1

Explanation

The Account protection endpoint security policy is designed to configure supported Windows security settings related to accounts and authentication. It can be used for configurations involving local administrator accounts, Windows Hello for Business, and other supported account security controls. Device inventory provides information about managed devices, assignment filters refine targeting, and update rings control Windows Update behavior. Account protection is therefore the appropriate endpoint security policy when administrators need to configure supported security settings involving Windows accounts and authentication.

Question 366

Which Intune application type is designed to deploy a traditional Windows desktop application packaged for managed deployment?

  1. Web app
  2. Win32 app
  3. Microsoft 365 Apps
  4. App protection policy

Correct Answer: 2

Explanation

Win32 apps in Intune are designed to deploy traditional Windows desktop applications using supported application packages and installation commands. Administrators can configure requirements, detection rules, dependencies, return codes, and assignments to control the deployment process. Web apps provide shortcuts to web-based resources, Microsoft 365 Apps is specifically designed for Microsoft 365 application deployment, and app protection policies protect organizational data within supported applications. Win32 app is therefore the appropriate Intune application type for deploying packaged traditional Windows desktop software.

Question 367

Which Windows feature provides an isolated environment where administrators or users can safely test applications without affecting the main operating system?

  1. Storage Sense
  2. Windows Sandbox
  3. File History
  4. Remote Desktop

Correct Answer: 2

Explanation

Windows Sandbox provides a lightweight isolated environment for running applications and testing files without directly affecting the main Windows installation. When supported and enabled, it can be useful for testing potentially untrusted software, examining configurations, or performing temporary experiments. Storage Sense manages disk space, File History helps recover previous versions of files, and Remote Desktop provides remote access to a Windows session. Windows Sandbox is therefore the correct feature when an isolated temporary environment is needed for application testing.

Question 368

Which Microsoft Entra device identity is normally associated with a device that is fully joined to the organization’s cloud identity environment rather than an on-premises domain?

  1. Microsoft Entra registered
  2. Microsoft Entra hybrid joined
  3. Microsoft Entra joined
  4. Device Enrollment Manager

Correct Answer: 3

Explanation

Microsoft Entra joined devices are fully joined to the organization’s Microsoft Entra identity environment and can use cloud-based identity services for authentication and management. This model is commonly used for organizations adopting cloud-first Windows management with Microsoft Intune. Microsoft Entra registered is commonly associated with personally owned or bring-your-own-device scenarios, while hybrid joined devices maintain both on-premises Active Directory and Microsoft Entra identities. Device Enrollment Manager is an Intune enrollment role. Microsoft Entra joined is therefore the correct identity state for a cloud-joined Windows device.

Question 369

Which Intune feature can prevent a device from enrolling when its operating system platform is not permitted by organizational policy?

  1. Enrollment restrictions
  2. Device inventory
  3. Scope tags
  4. Endpoint analytics

Correct Answer: 1

Explanation

Enrollment restrictions allow administrators to control which device platforms and ownership types are permitted to enroll in Intune. Organizations can use platform restrictions to prevent unsupported or unauthorized device types from entering management. This helps maintain compliance with organizational endpoint standards before devices become fully managed. Device inventory provides information about enrolled devices, scope tags control administrative visibility, and Endpoint analytics provides performance insights. Enrollment restrictions are therefore the correct feature when administrators need to prevent enrollment based on operating system platform or other supported enrollment conditions.

Question 370

Which Intune capability can help an administrator determine why a configuration profile is not being applied to a specific device?

  1. Device category
  2. Device diagnostics
  3. Company Portal
  4. App protection policy

Correct Answer: 2

Explanation

Device diagnostics and related troubleshooting capabilities can provide administrators with information useful for investigating policy application problems on managed Windows devices. When a configuration profile does not apply as expected, administrators can review device status, policy results, and collected diagnostic information to identify possible causes. Device categories classify devices, Company Portal provides user-facing management functions, and app protection policies focus on application data protection. Device diagnostics is therefore the most appropriate option when troubleshooting why a configuration profile is not successfully applying to a device.

Question 371

Which Windows security technology uses virtualization-based security to isolate sensitive operating system processes?

  1. Storage Sense
  2. Virtualization-based security
  3. File History
  4. Delivery Optimization

Correct Answer: 2

Explanation

Virtualization-based security, or VBS, uses hardware virtualization capabilities to create isolated security environments within Windows. It can support security technologies that protect sensitive system components and credentials from threats operating in the normal Windows environment. VBS is an important foundation for features such as Credential Guard and certain memory integrity protections. Storage Sense manages disk space, File History provides file recovery capabilities, and Delivery Optimization manages update content distribution. Virtualization-based security is therefore the correct technology for creating isolated security environments using hardware virtualization.

Question 372

Which Intune feature allows administrators to configure supported Windows policies using a searchable catalog of individual settings?

  1. Security baseline
  2. Compliance policy
  3. Settings Catalog
  4. Device cleanup

Correct Answer: 3

Explanation

Settings Catalog provides a searchable collection of individual Windows configuration settings that administrators can select and configure in Intune profiles. It offers a flexible approach to Windows management because administrators can search for specific settings rather than relying only on predefined templates. Security baselines provide collections of recommended security settings, compliance policies evaluate device requirements, and device cleanup manages inactive records. Settings Catalog is therefore the appropriate Intune feature when administrators need to search for and configure individual Windows settings from a centralized catalog.

Question 373

Which Intune application assignment is intended to remove an application from targeted devices?

  1. Required
  2. Available
  3. Uninstall
  4. Dependency

Correct Answer: 3

Explanation

The Uninstall assignment type instructs Intune to remove an application from targeted devices or users, subject to the application’s deployment configuration and supported management behavior. It is useful when an organization needs to remove software that is no longer approved, required, or supported. Required assignments deploy applications automatically, Available assignments allow users to install optional applications, and dependencies establish prerequisite relationships. Uninstall is therefore the appropriate assignment type when administrators need Intune to remove an application from targeted managed endpoints.

Question 374

Which Windows management capability can optimize the distribution of Windows updates and application content across devices on a network?

  1. Delivery Optimization
  2. Credential Guard
  3. SmartScreen
  4. BitLocker

Correct Answer: 1

Explanation

Delivery Optimization helps optimize the distribution of Windows updates and supported application content by allowing devices to obtain content through efficient delivery mechanisms. Depending on configuration, devices can use Microsoft content sources and supported peer-based methods to reduce bandwidth consumption and improve distribution efficiency. Credential Guard protects authentication credentials, SmartScreen provides reputation-based protection, and BitLocker encrypts data on storage devices. Delivery Optimization is therefore the correct Windows capability when the goal is to improve the distribution of updates and supported content across managed endpoints.

Question 375

Which Intune feature can help administrators identify applications that are causing performance or reliability problems on managed Windows devices?

  1. Device cleanup
  2. Endpoint analytics
  3. Enrollment restrictions
  4. Scope tags

Correct Answer: 2

Explanation

Endpoint analytics provides insights into endpoint performance and user experience, including information that can help administrators investigate application reliability and other performance-related problems. These insights can help IT teams identify devices or applications that may require attention and prioritize troubleshooting efforts. Device cleanup manages stale device records, enrollment restrictions control which devices can enroll, and scope tags manage administrative visibility. Endpoint analytics is therefore the appropriate Intune capability when administrators need information about application performance or reliability across managed Windows devices.

Question 376

Which Windows feature protects data stored on a device by encrypting the operating system drive?

  1. Windows LAPS
  2. BitLocker
  3. SmartScreen
  4. Windows Hello for Business

Correct Answer: 2

Explanation

BitLocker provides encryption for supported Windows storage volumes, including operating system drives. It helps protect data if a device is lost, stolen, or accessed outside the normal Windows environment. BitLocker can use supported hardware security features such as TPM to help protect encryption keys and secure startup operations. Windows LAPS manages local administrator passwords, SmartScreen provides reputation-based protection, and Windows Hello for Business provides passwordless authentication. BitLocker is therefore the correct technology when the requirement is to protect stored data through drive encryption.

Question 377

Which Intune feature allows administrators to remotely reboot a managed device without performing a reset or removing management?

  1. Restart action
  2. Wipe action
  3. Retire action
  4. Autopilot Reset

Correct Answer: 1

Explanation

The Restart action allows administrators to remotely reboot a managed device while leaving its management configuration and user data in place. A restart can be useful for completing configuration changes, troubleshooting applications, or resolving temporary system conditions that require a reboot. Wipe can erase device data and reset the device, Retire removes organizational management, and Autopilot Reset prepares a device for reuse while maintaining organizational provisioning. Restart is therefore the appropriate remote action when the administrator only needs to reboot the managed endpoint.

Question 378

Which Microsoft Intune capability can apply a policy to devices based on membership in a Microsoft Entra group?

  1. Device inventory
  2. Group-based assignment
  3. Remote Help
  4. Device cleanup

Correct Answer: 2

Explanation

Group-based assignment allows administrators to target Intune applications, policies, and configurations to users or devices through Microsoft Entra group membership. This provides a flexible way to organize deployment targets according to departments, device types, locations, or other organizational requirements. Device inventory provides endpoint information, Remote Help supports remote assistance, and device cleanup removes stale records. Group-based assignment is therefore the correct capability when administrators need to deploy Intune resources to devices or users based on Microsoft Entra group membership.

Question 379

Which Windows security feature can help protect against credential theft by isolating certain authentication secrets from the normal operating system environment?

  1. SmartScreen
  2. Credential Guard
  3. Storage Sense
  4. File History

Correct Answer: 2

Explanation

Credential Guard uses virtualization-based security to isolate and protect certain sensitive authentication information from threats operating within the normal Windows environment. This helps reduce the exposure of credentials to credential-theft techniques that target protected authentication components. SmartScreen focuses on reputation-based protection, Storage Sense manages storage capacity, and File History provides file recovery capabilities. Credential Guard is therefore the appropriate security feature when an organization needs to protect sensitive authentication information through isolation supported by virtualization-based security.

Question 380

Which Intune capability allows administrators to manage policies and applications for devices that are jointly managed by Configuration Manager and Intune?

  1. Windows Sandbox
  2. Co-management
  3. Device cleanup
  4. Company Portal

Correct Answer: 2

Explanation

Co-management enables organizations to manage supported Windows devices using both Configuration Manager and Microsoft Intune. This allows administrators to gradually transition workloads from traditional management to cloud-based management while continuing to use Configuration Manager where appropriate. Different workloads can be assigned to either management platform according to the organization’s migration strategy. Windows Sandbox provides an isolated environment, device cleanup removes stale records, and Company Portal provides user-facing management functions. Co-management is therefore the appropriate capability for jointly managing Windows endpoints through Configuration Manager and Intune.