View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.
Question 181
Which Intune capability allows administrators to configure Windows devices with security rules designed to reduce commonly exploited attack techniques?
- Device cleanup
- App configuration
- Enrollment restrictions
- Attack Surface Reduction rules
Correct Answer: 4
Explanation
Attack Surface Reduction rules are designed to reduce the ability of malicious software to use commonly exploited behaviors on Windows devices. Organizations can configure supported ASR rules through Intune endpoint security policies and apply them to targeted devices. These rules can help restrict activities associated with credential theft, malicious scripts, Office-based attacks, and other common techniques. Device cleanup manages stale records, app configuration policies manage application settings, and enrollment restrictions control which devices can enroll. ASR rules are therefore appropriate when an organization wants to reduce exposure to common endpoint attack behaviors.
Question 182
Which Intune feature allows administrators to create a policy that configures Windows devices using individual settings selected from a centralized catalog?
- Settings Catalog
- Remote Help
- Device cleanup rules
- Company Portal
Correct Answer: 1
Explanation
The Settings Catalog provides a centralized collection of configurable settings that administrators can use to create Intune configuration policies. Instead of manually creating individual custom configurations, administrators can search the catalog for supported settings, configure their values, and assign the policy to users or devices. This provides granular control over Windows configuration and simplifies policy creation. Remote Help is used for remote assistance, device cleanup rules manage stale device records, and Company Portal provides end-user access to applications and supported device actions. Settings Catalog is therefore the appropriate configuration tool.
Question 183
An administrator wants to assign an application to a group but exclude devices that have a specific operating system version. Which Intune feature can refine the assignment?
- Scope tags
- Assignment filters
- Device categories
- Enrollment restrictions
Correct Answer: 2
Explanation
Assignment filters allow administrators to refine application and policy assignments according to device properties. An administrator can assign an application to a Microsoft Entra group and then use a filter to include or exclude devices based on supported attributes, such as operating system information. This provides more precise targeting without requiring separate groups for every condition. Scope tags control administrative visibility, device categories help classify devices, and enrollment restrictions determine which devices are permitted to enroll. Assignment filters are therefore the appropriate feature for refining an existing application assignment.
Question 184
Which Intune application deployment option is most appropriate for an application that users should install only when they need it?
- Required
- Available
- Uninstall
- Dependency
Correct Answer: 2
Explanation
An Available application assignment makes software accessible to targeted users through Company Portal without automatically installing it. Users can browse the available application and choose to install it when required. This approach is useful for optional business applications that are not necessary on every device. Required assignments automatically deploy applications, while Uninstall assignments remove applications from targeted devices. Dependencies define prerequisite relationships between applications. Therefore, Available is the correct assignment type when users should decide whether and when to install optional software.
Question 185
Which Microsoft Intune feature can configure a managed Windows device to automatically receive a specified Windows feature update version?
- Compliance policy
- Update ring
- Security baseline
- Feature update policy
Correct Answer: 4
Explanation
A feature update policy allows Intune administrators to specify the Windows feature update version that targeted devices should receive or remain on. This provides organizations with greater control over Windows servicing and allows IT teams to test a feature release before deploying it broadly. Update rings manage general update behavior, such as deferrals and restart settings, rather than primarily defining a specific feature version. Security baselines provide recommended security configurations, while compliance policies evaluate device requirements. A feature update policy is therefore the appropriate tool for controlling a target Windows feature release.
Question 186
Which Windows technology helps protect sensitive credentials by placing certain security processes in an isolated virtualization-based environment?
- Credential Guard
- SmartScreen
- BitLocker
- Windows Sandbox
Correct Answer: 1
Explanation
Credential Guard uses virtualization-based security to isolate and protect certain sensitive authentication credentials from the normal Windows operating system environment. This helps reduce the risk of credential theft through attacks targeting Windows authentication components. It is particularly relevant in enterprise environments where compromised credentials could provide attackers with access to additional resources. SmartScreen focuses on reputation-based protection, BitLocker encrypts stored data, and Windows Sandbox provides an isolated environment for temporary application execution. Credential Guard is therefore the technology specifically associated with isolating protected credentials through virtualization-based security.
Question 187
Which Intune capability allows an administrator to determine whether a Win32 application is installed by checking a specific registry value?
- Detection rule
- Requirement rule
- Dependency
- Assignment filter
Correct Answer: 1
Explanation
Detection rules determine whether Intune recognizes a Win32 application as installed on a managed Windows device. One supported detection method can use registry information, allowing administrators to check for a particular registry key or value associated with the application. Accurate detection rules are important because Intune uses their results to determine whether an application deployment has succeeded or whether installation is still required. Requirement rules determine whether a device qualifies for installation, dependencies define prerequisites, and assignment filters refine targeting. Detection rules are therefore the correct mechanism for checking application installation through registry information.
Question 188
Which Intune feature allows administrators to configure an application so that a newer version replaces an older version?
- Dependencies
- Supersedence
- Detection rules
- Requirement rules
Correct Answer: 2
Explanation
Application supersedence allows an administrator to establish a relationship in which a newer application replaces an older application. This is useful when organizations need to upgrade software versions while managing the removal or replacement of previous deployments. Administrators can configure the superseding application and define supported behavior for the older application. Dependencies are used when an application requires another application as a prerequisite. Detection rules identify installation status, while requirement rules determine whether a device meets conditions for deployment. Supersedence is therefore the appropriate capability for controlled application replacement.
Question 189
Which Intune endpoint security policy category is used to configure BitLocker settings on supported Windows devices?
- Antivirus
- Firewall
- Disk encryption
- Account protection
Correct Answer: 3
Explanation
The Disk encryption endpoint security policy in Intune is designed to configure encryption technologies such as BitLocker on supported Windows devices. Administrators can use it to establish encryption requirements and configure related recovery and protection settings. Centralized encryption management helps protect organizational data stored on managed devices. Antivirus policies configure malware protection, Firewall policies manage network traffic controls, and Account protection policies address authentication and account security. Disk encryption is therefore the correct endpoint security category when administrators need to configure BitLocker across managed Windows devices.
Question 190
A company wants Windows devices to download and install monthly quality updates while controlling restart and deferral behavior. Which Intune feature should be configured?
- Feature update policy
- Driver update policy
- Expedite update policy
- Update ring
Correct Answer: 4
Explanation
Update rings provide administrators with controls for the general Windows Update experience on managed devices. Settings can include update deferrals, active hours, restart behavior, user notifications, and other supported servicing options. This makes update rings appropriate for managing recurring quality updates while controlling when devices restart. Feature update policies focus on the Windows feature version, driver update policies manage driver servicing, and expedite update policies are intended to accelerate specific quality updates. Therefore, an update ring is the appropriate choice for controlling normal monthly update and restart behavior.
Question 191
Which Intune feature allows a Windows device to be automatically enrolled into mobile device management when an eligible user signs in?
- Automatic MDM enrollment
- Device query
- Company Portal
- Remote Help
Correct Answer: 1
Explanation
Automatic MDM enrollment allows eligible Windows devices to enroll in Intune when users sign in with organizational identities, provided the required Microsoft Entra and MDM configuration is in place. Administrators can define the appropriate MDM user scope so selected users are automatically enrolled. This reduces the need for users or administrators to perform manual enrollment steps. Device query retrieves endpoint information, Company Portal provides user-facing management capabilities, and Remote Help supports remote assistance. Automatic MDM enrollment is therefore the appropriate capability when device management should begin automatically after user authentication.
Question 192
Which Intune feature provides an end-user interface for accessing applications assigned as Available?
- Settings Catalog
- Company Portal
- Endpoint analytics
- Security baseline
Correct Answer: 2
Explanation
Company Portal provides users with a centralized interface for accessing applications that administrators have made available through Intune. Users can browse the application catalog and initiate installations for optional software. Depending on the platform and organizational configuration, Company Portal can also provide device information and supported management actions. Settings Catalog is used by administrators to configure device settings, Endpoint analytics provides performance and user-experience information, and security baselines provide recommended security configurations. Company Portal is therefore the appropriate user-facing application management interface for available applications.
Question 193
Which Windows Autopilot feature is intended to display the progress of required applications and policies during initial device setup?
- Device cleanup
- Windows LAPS
- Enrollment Status Page
- Storage Sense
Correct Answer: 3
Explanation
The Enrollment Status Page, or ESP, provides visibility into the progress of device setup during supported Windows enrollment and Autopilot deployment scenarios. It can display information about required applications, policies, and device configuration as the deployment proceeds. Organizations can configure ESP to help ensure that important applications and settings are processed before users begin working on the device. Device cleanup manages stale records, Windows LAPS manages local administrator passwords, and Storage Sense manages storage space. ESP is therefore the appropriate feature for monitoring application and policy installation during initial setup.
Question 194
Which Intune feature can be used to configure Microsoft Defender Antivirus settings such as real-time protection?
- Compliance policy
- Endpoint security antivirus policy
- Device category
- Enrollment restriction
Correct Answer: 2
Explanation
The endpoint security antivirus policy in Intune provides configuration options for Microsoft Defender Antivirus on supported Windows devices. Administrators can use this policy to manage settings such as real-time protection, cloud-delivered protection, scanning behavior, and other supported antivirus controls. Compliance policies can evaluate whether certain security requirements are satisfied but do not primarily configure antivirus settings. Device categories organize devices, while enrollment restrictions control which devices can enter Intune management. The endpoint security antivirus policy is therefore the appropriate choice for centrally configuring Microsoft Defender Antivirus.
Question 195
Which Intune capability can define a minimum Windows operating system version that devices must meet to remain compliant?
- Compliance policy
- Configuration profile
- Device category
- Application assignment
Correct Answer: 1
Explanation
An Intune compliance policy can define a minimum operating system version that managed devices must meet. Devices running an unsupported or outdated Windows version can be marked noncompliant according to the configured requirements. This compliance state can then be used with Conditional Access to control access to organizational resources. Configuration profiles are primarily used to configure device settings, device categories organize endpoints, and application assignments manage software deployment. Compliance policy is therefore the appropriate feature when an organization needs to evaluate Windows version requirements as part of its device security posture.
Question 196
Which Intune capability can be used to manage the local administrator password on supported Windows devices and rotate it automatically?
- Windows LAPS
- Credential Guard
- BitLocker
- SmartScreen
Correct Answer: 1
Explanation
Windows LAPS provides centralized management of local administrator account passwords on supported Windows devices. It can automatically generate and rotate passwords according to organizational policies, helping reduce the risks associated with static or shared local administrator credentials. Intune can be used to configure and deploy Windows LAPS policies to managed endpoints. Credential Guard protects sensitive authentication information, BitLocker encrypts stored data, and SmartScreen helps protect users from malicious websites and downloads. Windows LAPS is therefore the appropriate capability when an organization needs automated management and rotation of local administrator passwords.
Question 197
Which Intune capability can provide administrators with information about Windows device startup performance and user experience?
- Device cleanup rules
- Endpoint analytics
- App protection policies
- Enrollment restrictions
Correct Answer: 2
Explanation
Endpoint analytics provides organizations with insights into Windows device performance and user experience. It can help administrators identify issues related to startup performance, application reliability, and other factors that may affect productivity. This information can support troubleshooting and help IT teams determine which devices or configurations require attention. Device cleanup rules manage stale records, app protection policies protect organizational data within supported applications, and enrollment restrictions control device enrollment. Endpoint analytics is therefore the appropriate capability when administrators need centralized insights into endpoint performance and the user experience.
Question 198
Which Intune feature allows administrators to remotely collect supported information from a Windows device for investigation?
- Company Portal
- Device query
- Windows Autopilot
- Update ring
Correct Answer: 2
Explanation
Device query allows administrators to retrieve supported information from managed Windows devices for investigation, troubleshooting, and endpoint management. Instead of manually inspecting every device, administrators can use queries to obtain useful information about device state and configuration. This can help identify issues and support security or operational investigations. Company Portal provides user-facing functionality, Windows Autopilot handles provisioning and deployment, and update rings manage Windows Update behavior. Device query is therefore the appropriate Intune capability when administrators need to retrieve specific information from managed Windows endpoints.
Question 199
Which Intune capability is used to restrict the installation of an application until the device satisfies specified conditions such as operating system architecture?
- Assignment filter
- Detection rule
- Requirement rule
- Dependency
Correct Answer: 3
Explanation
Requirement rules define conditions that a device must satisfy before a Win32 application can be installed. Administrators can configure supported requirements such as operating system architecture, minimum operating system version, available disk space, or other conditions. This prevents applications from being deployed to devices that cannot properly support them. Detection rules determine whether the application is already installed, dependencies identify prerequisite applications, and assignment filters refine targeting based on device properties. Requirement rules are therefore the appropriate configuration when application installation should depend on specific device eligibility conditions.
Question 200
Which Intune action removes organizational data and management from a device while generally preserving personal user data?
- Retire
- Wipe
- Autopilot Reset
- Remote lock
Correct Answer: 1
Explanation
The Retire action removes organizational management and corporate data from a supported device while generally preserving personal user information. It is particularly useful for personally owned devices or situations where an employee no longer needs access to organizational resources. Wipe performs a broader reset and removes device data, while Autopilot Reset prepares a managed Windows device for reuse while retaining important organizational management information. Remote lock only prevents normal access. Retire is therefore the appropriate action when an organization needs to remove its management and data without intentionally erasing the user’s personal information.