Microsoft MD-102 Practice Test Questions and Exam Dumps Part16 Q301-320

View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.

 

Question 301

Which Intune feature allows administrators to configure multiple Windows security settings from a centralized collection of available policies?

  1. Settings Catalog
  2. Company Portal
  3. Device cleanup
  4. Remote Help

Correct Answer: 1

Explanation

The Settings Catalog provides administrators with a centralized collection of configurable Windows settings that can be searched and added to Intune configuration profiles. It allows organizations to manage a wide range of Windows settings without creating separate custom configurations for every requirement. Administrators can select specific settings, configure their values, and assign the resulting profile to users or devices. Company Portal is user-facing, Device cleanup manages stale records, and Remote Help provides remote assistance. Settings Catalog is therefore the appropriate feature for centralized Windows configuration.

Question 302

Which Microsoft Entra device identity is most appropriate for a Windows device that must maintain both on-premises Active Directory membership and cloud identity integration?

  1. Microsoft Entra registered
  2. Microsoft Entra joined
  3. Microsoft Entra hybrid joined
  4. Device Enrollment Manager

Correct Answer: 3

Explanation

Microsoft Entra hybrid joined devices maintain membership in an on-premises Active Directory domain while also having an identity in Microsoft Entra ID. This configuration is useful for organizations that continue to use traditional domain infrastructure while adopting cloud-based identity and endpoint management. Microsoft Entra joined devices connect directly to Microsoft Entra ID, while registered devices provide a lighter device identity commonly used in personal-device scenarios. Device Enrollment Manager is an Intune enrollment role rather than a device identity type. Microsoft Entra hybrid joined is therefore the correct choice for this environment.

Question 303

Which Intune feature can prevent a Win32 application from installing on a device that does not have enough available disk space?

  1. Detection rule
  2. Requirement rule
  3. Dependency
  4. Supersedence

Correct Answer: 2

Explanation

Requirement rules define conditions that a device must satisfy before a Win32 application can be installed. Available disk space can be configured as one of the supported requirements, helping administrators prevent incompatible or unsuccessful deployments. Detection rules determine whether an application is already installed, dependencies define prerequisite applications, and supersedence manages replacement of existing applications. Requirement rules are therefore the correct mechanism when an application should only install on devices with sufficient available storage. This improves deployment reliability and reduces installation failures caused by inadequate device resources.

Question 304

Which Intune assignment type makes an application available in Company Portal without automatically installing it?

  1. Required
  2. Uninstall
  3. Dependency
  4. Available

Correct Answer: 4

Explanation

An Available assignment makes an application accessible to targeted users through Company Portal while leaving the installation decision to the user. This is useful for optional applications that employees may need but that are not required on every managed device. Required assignments automatically deploy applications, Uninstall assignments remove applications, and dependencies establish prerequisite relationships between applications. Available is therefore the appropriate assignment type when administrators want users to have access to optional software without forcing an automatic installation. Users can select the application from Company Portal and install it when needed.

Question 305

Which Intune policy type can configure supported Microsoft Defender Antivirus settings on managed Windows devices?

  1. Endpoint security antivirus policy
  2. Compliance policy
  3. Device category
  4. Assignment filter

Correct Answer: 1

Explanation

The endpoint security antivirus policy in Intune is designed to configure Microsoft Defender Antivirus settings on supported Windows devices. Administrators can use it to manage supported protections such as real-time protection, cloud-delivered protection, scanning behavior, and other antivirus controls. Compliance policies evaluate whether devices satisfy defined requirements but are not primarily used to configure antivirus settings. Device categories classify devices, while assignment filters refine policy targeting. The endpoint security antivirus policy is therefore the correct choice when administrators need centralized configuration of Microsoft Defender Antivirus.

Question 306

Which Windows Autopilot deployment mode is designed for a device that should be provisioned without requiring the end user to sign in during deployment?

  1. User-driven mode
  2. Pre-provisioning
  3. Self-deploying mode
  4. Hybrid Microsoft Entra join

Correct Answer: 3

Explanation

Self-deploying mode is designed for Windows Autopilot scenarios where the device should be provisioned without requiring the end user to authenticate during the deployment process. It is useful for shared devices, kiosks, and similar scenarios where the endpoint must be prepared for organizational use without a traditional user-driven setup. User-driven mode requires user interaction, while pre-provisioning allows a technician to prepare the device before handoff. Hybrid Microsoft Entra join describes an identity configuration rather than an Autopilot deployment mode. Self-deploying mode is therefore correct.

Question 307

Which Intune capability allows administrators to specify which users or groups are permitted to perform specific management operations?

  1. Device categories
  2. Role-based access control
  3. Update rings
  4. Device inventory

Correct Answer: 2

Explanation

Role-based access control, or RBAC, allows Intune administrators to delegate management permissions according to predefined or customized administrative roles. Organizations can assign appropriate roles to users or groups and restrict the operations they are authorized to perform. This supports least-privilege administration and helps separate responsibilities between different IT teams. Device categories classify devices, update rings manage Windows Update behavior, and device inventory provides endpoint information. RBAC is therefore the appropriate Intune capability when an organization needs to control which administrators can perform particular management operations.

Question 308

Which Windows feature provides reputation-based protection against potentially malicious websites and downloaded files?

  1. Credential Guard
  2. SmartScreen
  3. BitLocker
  4. Windows LAPS

Correct Answer: 2

Explanation

Microsoft Defender SmartScreen provides reputation-based protection that can warn users about potentially malicious websites, downloads, and applications. It uses reputation information to help identify known or suspected threats and reduce the likelihood of users interacting with unsafe content. Credential Guard protects sensitive authentication information, BitLocker encrypts stored data, and Windows LAPS manages local administrator passwords. SmartScreen is therefore the correct Windows security feature when the requirement involves reputation-based protection against potentially malicious websites and downloaded content.

Question 309

Which Intune feature can automatically remove stale device records after devices have not checked in for a configured period?

  1. Device cleanup rules
  2. Compliance policy
  3. Security baseline
  4. App protection policy

Correct Answer: 1

Explanation

Device cleanup rules allow administrators to configure Intune to identify and remove device records that have not checked in for a specified period. This helps maintain an accurate device inventory and reduces administrative clutter caused by devices that are no longer active. Cleanup rules affect management records rather than physically deleting or wiping the device itself. Compliance policies evaluate device requirements, security baselines configure security settings, and app protection policies protect organizational data within supported applications. Device cleanup rules are therefore the appropriate capability for managing stale Intune device records.

Question 310

Which Intune feature can be used to define a specific Windows 11 feature update version that devices should receive?

  1. Update ring
  2. Expedite update policy
  3. Feature update policy
  4. Compliance policy

Correct Answer: 3

Explanation

Feature update policies allow administrators to specify a target Windows feature update version for managed devices. This gives organizations control over Windows servicing and allows IT teams to validate a particular release before deploying it broadly. Update rings manage general update behavior, such as deferrals and restart settings, while expedite update policies accelerate specific quality updates. Compliance policies evaluate whether devices meet organizational requirements. Feature update policy is therefore the appropriate capability when administrators need to control the specific Windows feature version installed on managed endpoints.

Question 311

Which Intune capability allows administrators to configure supported settings using custom OMA-URI values?

  1. Custom configuration profile
  2. Security baseline
  3. Compliance policy
  4. Endpoint analytics

Correct Answer: 1

Explanation

Custom configuration profiles allow administrators to configure supported Windows settings by using OMA-URI paths, data types, and values. This is useful when a required setting is not exposed through the standard Intune configuration interfaces. Because OMA-URI configuration requires accurate paths and supported values, administrators should verify the appropriate configuration information before deploying the policy. Security baselines provide predefined security settings, compliance policies evaluate device conditions, and Endpoint analytics provides performance information. A custom configuration profile is therefore the correct choice when OMA-URI configuration is required.

Question 312

Which Intune feature allows administrators to define what happens when a device fails compliance requirements?

  1. Scope tags
  2. Compliance policy actions
  3. Assignment filters
  4. Device categories

Correct Answer: 2

Explanation

Compliance policy actions allow administrators to configure responses when devices fail compliance requirements. These actions can include marking devices noncompliant and applying configured enforcement behavior after specified conditions or grace periods. Compliance information can also work with Conditional Access to restrict access to organizational resources. Scope tags control administrative visibility, assignment filters refine targeting, and device categories classify endpoints. Compliance policy actions are therefore the appropriate feature when an organization needs to define responses to devices that no longer meet its compliance requirements.

Question 313

Which Windows security feature can isolate sensitive credentials using virtualization-based security?

  1. Windows Sandbox
  2. Credential Guard
  3. SmartScreen
  4. Storage Sense

Correct Answer: 2

Explanation

Credential Guard uses virtualization-based security to isolate and protect certain sensitive authentication credentials from threats operating in the normal Windows environment. This can reduce the risk of credential theft from techniques that target Windows authentication components. Windows Sandbox provides an isolated environment for application testing, SmartScreen provides reputation-based protection, and Storage Sense manages disk space. Credential Guard is therefore the appropriate Windows security technology when the goal is to protect sensitive credentials through an isolated security environment supported by virtualization-based security.

Question 314

Which Intune capability allows administrators to determine whether a device is compliant with requirements such as encryption and operating system version?

  1. Company Portal
  2. Compliance policy
  3. Settings Catalog
  4. Device inventory

Correct Answer: 2

Explanation

Compliance policies evaluate managed devices against defined organizational requirements. Administrators can configure requirements such as supported operating system versions, encryption status, firewall state, antivirus protection, password settings, and other supported conditions. Intune then evaluates the device and assigns a compliance state. Company Portal provides user-facing access, Settings Catalog configures device settings, and device inventory provides hardware and software information. Compliance policy is therefore the appropriate capability when administrators need to determine whether devices satisfy defined security and management requirements.

Question 315

Which Intune endpoint security policy category is used to configure Microsoft Defender Firewall settings?

  1. Antivirus
  2. Account protection
  3. Firewall
  4. Disk encryption

Correct Answer: 3

Explanation

The Firewall endpoint security policy category is used to configure supported Microsoft Defender Firewall settings on managed Windows devices. Administrators can create and assign firewall policies to establish consistent network protection requirements across organizational endpoints. Antivirus policies configure malware protection, Account protection manages supported account and authentication settings, and Disk encryption manages technologies such as BitLocker. Firewall is therefore the correct policy category when an organization needs to centrally configure Microsoft Defender Firewall behavior through Intune.

Question 316

Which Intune application feature allows an administrator to specify that one application must be installed before another application?

  1. Detection rule
  2. Dependency
  3. Supersedence
  4. Requirement rule

Correct Answer: 2

Explanation

Application dependencies allow administrators to establish prerequisite relationships between Win32 applications. When one application depends on another, Intune can process the prerequisite application before attempting to install the dependent application. This is useful for software that requires a runtime, framework, agent, or supporting component. Detection rules determine whether an application is installed, supersedence manages application replacement, and requirement rules define whether a device meets installation conditions. Dependency is therefore the correct feature when an application must be installed before another application can be deployed.

Question 317

Which Intune capability can provide information about Windows device startup performance and user experience?

  1. Endpoint analytics
  2. Enrollment restrictions
  3. Device cleanup
  4. Scope tags

Correct Answer: 1

Explanation

Endpoint analytics provides insights into Windows device performance and user experience. It can help organizations identify issues related to startup performance, application reliability, and other endpoint factors that may affect productivity. Administrators can use these insights to investigate problems and identify devices or configurations that may require attention. Enrollment restrictions control which devices can enroll, device cleanup manages stale records, and scope tags control administrative visibility. Endpoint analytics is therefore the appropriate Intune capability when administrators need information about endpoint performance and the overall user experience.

Question 318

Which Intune action removes organizational management from a device while generally preserving the user’s personal data?

  1. Wipe
  2. Retire
  3. Remote lock
  4. Restart

Correct Answer: 2

Explanation

The Retire action removes organizational management and supported corporate data from a device while generally preserving personal user information. It is particularly useful for personally owned devices when an employee no longer needs organizational access or when corporate management must be removed without intentionally erasing personal content. Wipe performs a broader reset and can remove device data, Remote lock restricts access, and Restart simply reboots the device. Retire is therefore the appropriate action when administrators need to remove organizational management and data while generally leaving personal information intact.

Question 319

Which Microsoft Intune capability allows administrators to retrieve supported information from managed Windows devices by using queries?

  1. Device query
  2. Company Portal
  3. Remote Help
  4. Windows Autopilot

Correct Answer: 1

Explanation

Device query allows administrators to retrieve supported information from managed Windows devices for troubleshooting, inventory analysis, security investigations, and other administrative purposes. Queries can provide useful endpoint information without requiring administrators to manually inspect each device. Company Portal is primarily user-facing, Remote Help provides remote assistance, and Windows Autopilot handles device provisioning and deployment. Device query is therefore the appropriate capability when administrators need to collect specific information from managed Windows endpoints through supported query operations.

Question 320

Which Intune capability can require a managed device to meet compliance requirements before access to protected organizational resources is permitted?

  1. Device categories
  2. Scope tags
  3. Conditional Access
  4. Device cleanup rules

Correct Answer: 3

Explanation

Conditional Access can use Intune compliance status when evaluating whether users should be allowed to access protected organizational resources. An organization can configure a policy that requires a device to be compliant before access is granted. If the device does not satisfy the defined compliance requirements, the Conditional Access policy can block or restrict access according to its configuration. Device categories classify devices, scope tags control administrative visibility, and device cleanup rules manage stale records. Conditional Access is therefore the appropriate capability for enforcing access requirements based on device compliance.