View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.
Question 381
Which Intune feature can be used to configure Windows devices to automatically install a specific approved feature update version?
- Compliance policy
- Update ring
- Expedite update policy
- Feature update policy
Correct Answer: 4
Explanation
A feature update policy allows administrators to specify the Windows feature update version that managed devices should receive. This provides greater control over Windows servicing and allows organizations to keep devices on an approved version while testing newer releases before broader deployment. Update rings manage general update behavior, expedite update policies accelerate selected quality updates, and compliance policies evaluate device requirements. Feature update policy is therefore the correct choice when administrators need to control the specific Windows feature version deployed to managed devices.
Question 382
Which Intune capability allows administrators to assign different administrative permissions to different IT teams?
- Role-based access control
- Device inventory
- Device category
- Enrollment restriction
Correct Answer: 1
Explanation
Role-based access control, or RBAC, allows organizations to delegate Intune administrative permissions according to job responsibilities. Different IT teams can receive different roles and permissions, helping ensure administrators only have access to the functions required for their work. This supports least-privilege administration and reduces unnecessary administrative access. Device inventory provides endpoint information, device categories classify devices, and enrollment restrictions control which devices can enter management. RBAC is therefore the correct capability when an organization needs to provide different administrative permissions to different IT teams.
Question 383
Which Intune feature can configure a Windows device to require encryption and report whether the requirement is satisfied?
- Settings Catalog
- Security baseline
- Compliance policy
- Company Portal
Correct Answer: 3
Explanation
A compliance policy can evaluate whether a Windows device satisfies an encryption requirement and report the resulting compliance state. Administrators can configure supported compliance conditions, including encryption, operating system version, firewall, antivirus, password, and other security requirements. Settings Catalog and security baselines are primarily used to configure device settings, while Company Portal provides users with access to applications and device-related information. Compliance policy is therefore the correct choice when the objective is to evaluate whether encryption is enabled and use that result as part of the device’s compliance status.
Question 384
Which Windows Autopilot capability allows an IT technician to prepare applications and policies before the device reaches the end user?
- Self-deploying mode
- Pre-provisioning
- User-driven mode
- Autopilot Reset
Correct Answer: 2
Explanation
Windows Autopilot pre-provisioning allows an IT technician or authorized partner to prepare a device before it is delivered to the end user. Required applications, policies, and configurations can be applied during the technician phase, reducing the amount of setup required after the device reaches the user. Self-deploying mode is designed for deployment without traditional user authentication, user-driven mode involves the end user during provisioning, and Autopilot Reset prepares an already deployed device for reuse. Pre-provisioning is therefore the correct capability for technician-assisted preparation.
Question 385
Which Intune application feature determines whether a device satisfies conditions such as operating system architecture before installing a Win32 application?
- Detection rule
- Dependency
- Supersedence
- Requirement rule
Correct Answer: 4
Explanation
Requirement rules define conditions that a device must satisfy before a Win32 application can be installed. Supported conditions can include operating system architecture, minimum operating system version, available disk space, and other application-specific requirements. Detection rules determine whether the application is already installed, dependencies identify prerequisite applications, and supersedence manages replacement of existing applications. Requirement rule is therefore the correct feature when administrators need Intune to verify that a device meets specific technical conditions before attempting a Win32 application installation.
Question 386
Which Microsoft Entra device state combines on-premises Active Directory membership with Microsoft Entra cloud identity?
- Microsoft Entra registered
- Microsoft Entra hybrid joined
- Microsoft Entra joined
- Device Enrollment Manager
Correct Answer: 2
Explanation
Microsoft Entra hybrid joined devices have an identity in Microsoft Entra ID while remaining joined to an on-premises Active Directory domain. This model supports organizations that continue to use traditional domain infrastructure while adopting cloud-based identity and endpoint management. Microsoft Entra registered is commonly associated with personal or bring-your-own-device scenarios, while Microsoft Entra joined devices are directly joined to the cloud identity environment. Device Enrollment Manager is an enrollment role rather than a device identity state. Microsoft Entra hybrid joined is therefore the correct answer.
Question 387
Which Windows feature helps organizations manage and rotate local administrator passwords automatically?
- Windows LAPS
- Credential Guard
- BitLocker
- SmartScreen
Correct Answer: 1
Explanation
Windows LAPS helps organizations manage local administrator passwords by securely storing, generating, and rotating passwords according to configured policies. Regular password rotation reduces the risk associated with static or shared local administrator credentials. Credential Guard protects sensitive authentication information, BitLocker encrypts stored data, and SmartScreen provides reputation-based protection against potentially unsafe content. Windows LAPS is therefore the appropriate Windows security capability when an organization needs centralized management and automatic rotation of local administrator passwords across managed endpoints.
Question 388
Which Intune feature allows administrators to configure Microsoft Defender Firewall rules and settings for managed Windows devices?
- Antivirus policy
- Account protection policy
- Firewall policy
- Disk encryption policy
Correct Answer: 3
Explanation
The Firewall endpoint security policy allows administrators to configure supported Microsoft Defender Firewall settings on managed Windows devices. It can be used to establish consistent firewall behavior and supported network protection configurations across organizational endpoints. Antivirus policies manage malware protection, Account protection handles supported account and authentication settings, and Disk encryption policies manage technologies such as BitLocker. Firewall policy is therefore the correct endpoint security category when administrators need to configure Microsoft Defender Firewall settings centrally through Intune.
Question 389
Which Intune assignment type allows users to choose whether to install an application from Company Portal?
- Required
- Available
- Uninstall
- Dependency
Correct Answer: 2
Explanation
An Available assignment makes an application accessible to targeted users through Company Portal without forcing automatic installation. Users can browse the available applications and choose to install the software when they need it. Required assignments automatically deploy applications, Uninstall assignments remove applications, and dependencies establish prerequisite relationships between applications. Available is therefore the correct assignment type when administrators want to offer optional software through Company Portal while allowing users to decide whether and when to install it.
Question 390
Which Windows action can completely reset a managed device and remove its stored data?
- Restart
- Retire
- Sync
- Wipe
Correct Answer: 4
Explanation
The Wipe action resets a managed device and can remove its stored data, applications, settings, and organizational information according to the selected wipe behavior. It is generally used when a device must be reset for security, reassignment, disposal, or other organizational purposes. Restart simply reboots the device, Retire removes organizational management while generally preserving personal content, and Sync requests communication with Intune. Wipe is therefore the appropriate action when administrators need to perform a broad reset that removes data from the managed device.
Question 391
Which Intune capability allows administrators to view information about application installation and policy deployment results on managed devices?
- Device category
- Enrollment restriction
- Intune reporting
- Scope tag
Correct Answer: 3
Explanation
Intune reporting provides administrators with information about application deployments, policy states, device management results, compliance, and other management activities. These reports can help identify successful deployments, failures, pending operations, and devices requiring additional investigation. Device categories classify devices, enrollment restrictions control which devices can enroll, and scope tags control administrative visibility. Intune reporting is therefore the appropriate capability when administrators need centralized information about application installation and policy deployment outcomes across managed endpoints.
Question 392
Which Windows feature can use reputation information to warn users about potentially dangerous websites and downloads?
- SmartScreen
- Credential Guard
- BitLocker
- Windows LAPS
Correct Answer: 1
Explanation
Microsoft Defender SmartScreen uses reputation-based protection to help warn users about potentially malicious websites, downloads, applications, and files. It can help reduce the likelihood that users will interact with known or suspected unsafe content. Credential Guard protects sensitive authentication information, BitLocker provides storage encryption, and Windows LAPS manages local administrator passwords. SmartScreen is therefore the correct Windows security feature when the requirement involves reputation-based warnings for potentially dangerous websites and downloaded content.
Question 393
Which Intune capability allows administrators to configure supported security settings using a predefined collection recommended by Microsoft?
- Device inventory
- Company Portal
- Assignment filter
- Security baseline
Correct Answer: 4
Explanation
Security baselines provide predefined collections of recommended security settings for supported Windows devices. Administrators can review the settings, modify supported values where necessary, and deploy the baseline to appropriate users or devices. This provides a structured starting point for establishing consistent security configurations across endpoints. Device inventory provides device information, Company Portal is primarily user-facing, and assignment filters refine targeting. Security baseline is therefore the appropriate Intune capability when administrators want to deploy a predefined collection of Microsoft-recommended security configurations.
Question 394
Which Intune capability can narrow an existing policy assignment by evaluating attributes of the target device?
- Device cleanup
- Enrollment Status Page
- Assignment filter
- Remote Help
Correct Answer: 3
Explanation
Assignment filters allow administrators to refine existing Intune assignments by evaluating supported device attributes. For example, filters can be used to include or exclude devices according to characteristics such as operating system, manufacturer, model, or other supported properties. Device cleanup manages stale records, Enrollment Status Page controls deployment progress, and Remote Help provides remote assistance. Assignment filter is therefore the correct capability when administrators need more precise targeting without changing the membership of the underlying Microsoft Entra group.
Question 395
Which Intune endpoint security policy category is used to configure settings related to Windows account security and Windows Hello for Business?
- Account protection
- Firewall
- Antivirus
- Disk encryption
Correct Answer: 1
Explanation
The Account protection endpoint security policy category is used for supported Windows account and authentication security settings. It can include configurations related to Windows Hello for Business and other supported account protection controls. Firewall policies configure network protection, Antivirus policies manage malware protection, and Disk encryption policies configure encryption technologies such as BitLocker. Account protection is therefore the correct endpoint security category when administrators need to manage supported Windows account security and Windows Hello for Business settings through Intune.
Question 396
Which Intune capability can be used to configure a custom Windows setting when the setting is not available through standard configuration profile options?
- Compliance policy
- Custom configuration profile
- Device category
- Endpoint analytics
Correct Answer: 2
Explanation
A custom configuration profile can be used to configure supported Windows settings through OMA-URI when the required setting is not exposed through standard Intune configuration options. Administrators specify the appropriate OMA-URI path, data type, and value according to the supported configuration documentation. Compliance policies evaluate whether devices meet requirements, device categories classify endpoints, and Endpoint analytics provides performance and experience insights. A custom configuration profile is therefore the appropriate solution when administrators need to configure a supported Windows setting that is not available through the standard configuration interface.
Question 397
Which Intune feature allows an organization to remove a managed device’s organizational configuration while generally keeping the user’s personal files intact?
- Retire
- Wipe
- Fresh Start
- Autopilot Reset
Correct Answer: 1
Explanation
The Retire action removes organizational management and supported corporate data from a device while generally preserving personal user content. It is useful when a personally owned device should no longer be managed by the organization or when corporate access needs to be removed without intentionally erasing personal information. Wipe performs a broader reset, Fresh Start reinstalls Windows with supported removal behavior, and Autopilot Reset prepares a managed device for reuse while retaining its organizational provisioning state. Retire is therefore the appropriate action for removing organizational management while preserving personal content.
Question 398
Which Intune application capability allows a newer Win32 application package to replace an older application package?
- Detection rule
- Dependency
- Requirement rule
- Supersedence
Correct Answer: 4
Explanation
Supersedence allows a newer Win32 application package to replace an older application package through Intune. This capability is useful when organizations need to upgrade or transition users from an older software package to a newer version. Administrators can configure the relationship between the applications and define the appropriate replacement behavior. Detection rules determine whether an application is installed, dependencies establish prerequisites, and requirement rules determine whether a device meets installation conditions. Supersedence is therefore the correct capability for managing application replacement and upgrade scenarios.
Question 399
Which Intune capability can retrieve specific information from managed Windows devices for administrative investigation?
- Remote Help
- Device query
- Company Portal
- Windows Autopilot
Correct Answer: 2
Explanation
Device query allows administrators to retrieve supported information from managed Windows devices for troubleshooting, inventory investigation, security analysis, and other administrative purposes. Instead of manually inspecting every endpoint, administrators can use supported queries to obtain specific device information. Remote Help is intended for interactive remote assistance, Company Portal provides user-facing management functionality, and Windows Autopilot handles device provisioning. Device query is therefore the appropriate Intune capability when administrators need to retrieve targeted information from managed Windows endpoints.
Question 400
Which Microsoft Intune capability can enforce access restrictions when a user attempts to access organizational resources from a device that does not meet compliance requirements?
- Device category
- Scope tag
- Conditional Access
- Device inventory
Correct Answer: 3
Explanation
Conditional Access can use device compliance information from Intune when deciding whether a user should be permitted to access protected organizational resources. An organization can configure policies requiring a device to be compliant before access is granted. If the device fails the configured requirements, access can be blocked or otherwise restricted according to the policy. Device categories classify endpoints, scope tags control administrative visibility, and device inventory provides device information. Conditional Access is therefore the appropriate capability for enforcing resource access requirements based on device compliance.