View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.
Question 41
Which Microsoft Intune feature allows administrators to configure settings for Windows devices without creating traditional Group Policy Objects?
- Configuration profiles
- App protection policies
- Compliance reports
- Enrollment restrictions
Correct Answer: 1
Explanation
Intune configuration profiles allow administrators to deploy and manage Windows device settings through the cloud. They can configure security controls, system restrictions, network settings, Windows Defender options, and many other device behaviors. This provides a modern management approach that can reduce dependence on traditional on-premises Group Policy Objects. App protection policies focus on application data, compliance reports provide monitoring information, and enrollment restrictions control which devices can enroll. Configuration profiles are therefore a core method for applying standardized Windows settings through Intune.
Question 42
Which Microsoft Entra join type is commonly used when an organization wants both on-premises Active Directory and cloud identity management?
- Microsoft Entra registered
- Microsoft Entra hybrid joined
- Workgroup joined
- Local account joined
Correct Answer: 2
Explanation
Microsoft Entra hybrid joined devices are joined to an on-premises Active Directory domain while also being registered with Microsoft Entra ID. This model is useful for organizations transitioning toward cloud management while continuing to use traditional domain-based infrastructure. It allows devices to work with existing domain resources while also supporting Microsoft cloud services and management capabilities. Microsoft Entra registered is commonly associated with personally owned or mobile scenarios, while workgroup and local account configurations do not provide the same hybrid identity integration.
Question 43
Which Intune feature controls how a Windows device should behave when it is reported as noncompliant?
- Compliance policy actions
- Application assignments
- Configuration profiles
- Enrollment categories
Correct Answer: 1
Explanation
Compliance policy actions determine what should happen when a device does not meet defined compliance requirements. Administrators can configure actions such as marking devices noncompliant, sending notifications, or working with Conditional Access to restrict access to organizational resources. Application assignments control software deployment, configuration profiles apply device settings, and enrollment categories help organize enrollment scenarios. Compliance policy actions therefore provide administrators with a way to respond to devices that fail security or configuration requirements.
Question 44
Which Windows command displays detailed information about the computer’s network configuration?
- gpupdate
- ipconfig
- sfc
- tasklist
Correct Answer: 2
Explanation
The ipconfig command displays network configuration information for Windows interfaces. Depending on the options used, administrators can view IP addresses, subnet masks, default gateways, DNS information, DHCP details, and other configuration data. This makes ipconfig useful when troubleshooting connectivity and addressing problems. The gpupdate command refreshes Group Policy, sfc checks protected system files, and tasklist displays running processes. Administrators commonly use ipconfig /all when they need a detailed view of the local system’s network configuration.
Question 45
Which Microsoft Intune feature can automatically remove a device from management after a defined period of inactivity?
- Device cleanup rules
- Compliance policies
- Security baselines
- App configuration policies
Correct Answer: 1
Explanation
Intune device cleanup rules can help remove stale device records from Intune when devices have not checked in for a specified period. This helps administrators maintain a cleaner device inventory and reduces confusion caused by inactive or obsolete records. Cleanup rules do not normally wipe the physical device; they primarily address device records in the management service. Compliance policies evaluate security requirements, security baselines provide recommended settings, and app configuration policies manage application behavior. Device cleanup rules are therefore useful for managing stale endpoint records.
Question 46
Which Microsoft security baseline is designed to provide recommended configuration settings for managed Windows devices?
- Microsoft Defender portal
- Security baseline
- Windows Sandbox
- Microsoft Store
Correct Answer: 2
Explanation
Microsoft Intune security baselines provide groups of recommended security configuration settings that administrators can deploy to managed Windows devices. They are designed to help organizations establish consistent security configurations without manually reviewing every individual setting. Administrators can review the recommended values and customize them when organizational requirements differ. Microsoft Defender provides security monitoring and protection, Windows Sandbox provides isolation, and Microsoft Store distributes applications. Security baselines therefore help establish standardized and security-focused Windows endpoint configurations.
Question 47
Which Windows feature can restore system files and settings to an earlier state without removing personal documents?
- System Restore
- Disk Cleanup
- Storage Sense
- Task Scheduler
Correct Answer: 1
Explanation
System Restore can return certain Windows system files, drivers, registry settings, and installed application configurations to an earlier restore point. It is designed primarily to help recover from configuration changes or software installations that cause problems. System Restore generally does not remove personal documents such as photos or user-created files. Disk Cleanup and Storage Sense focus on reclaiming storage space, while Task Scheduler automates tasks. System Restore is therefore useful when Windows becomes unstable after a significant system or software change.
Question 48
Which Intune policy type can define restrictions such as preventing users from changing certain Windows settings?
- Compliance policy
- Configuration profile
- Device cleanup rule
- Application protection policy
Correct Answer: 2
Explanation
Configuration profiles can apply restrictions and settings that control how managed Windows devices operate. Depending on the available profile type, administrators can restrict access to certain system features, control user settings, configure security options, and manage device functionality. Compliance policies determine whether devices satisfy required conditions, device cleanup rules handle stale records, and application protection policies focus on organizational data within supported applications. Configuration profiles therefore provide a practical mechanism for enforcing device behavior and restrictions across managed endpoints.
Question 49
Which Windows tool is commonly used to identify applications and processes consuming excessive CPU or memory?
- Task Manager
- Registry Editor
- Device Manager
- Disk Management
Correct Answer: 1
Explanation
Task Manager provides information about running applications, processes, CPU usage, memory consumption, disk activity, network activity, and other system resources. Administrators can use it to identify applications or processes that are consuming unusually high amounts of system resources. It can also be used to end unresponsive processes and review startup applications. Registry Editor manages Windows registry settings, Device Manager focuses on hardware and drivers, and Disk Management manages storage devices. Task Manager is therefore a primary troubleshooting tool for resource-related performance issues.
Question 50
Which Windows management technology uses policies from an on-premises Active Directory environment?
- Microsoft Intune
- Group Policy
- Microsoft Defender
- Windows Autopilot
Correct Answer: 2
Explanation
Group Policy is a traditional Windows management technology used with Active Directory domain environments. Administrators can use Group Policy Objects to configure security settings, desktop behavior, software settings, scripts, and many other Windows options across domain-joined computers and users. Intune provides cloud-based endpoint management, Defender focuses on security, and Autopilot supports modern device provisioning. Organizations can use Group Policy alongside Intune during migration or in hybrid environments, but Group Policy remains strongly associated with on-premises Active Directory management.
Question 51
Which Microsoft Intune capability helps organizations manage Windows update deployment in controlled stages?
- Update rings
- App protection
- Device categories
- Enrollment restrictions
Correct Answer: 1
Explanation
Windows update rings in Intune allow administrators to control how updates are deployed to managed Windows devices. Organizations can create different groups with different update behaviors, such as delaying feature updates, configuring deadlines, or controlling restart experiences. This supports staged deployments in which updates can be introduced to selected devices before broader rollout. App protection secures application data, device categories organize managed devices, and enrollment restrictions control device enrollment. Update rings are therefore useful for structured Windows update management.
Question 52
Which Microsoft Entra feature helps prevent users from signing in when their account is disabled or blocked?
- Conditional Access
- Account status
- Windows Autopilot
- Device configuration
Correct Answer: 2
Explanation
The status of a Microsoft Entra user account determines whether the identity is enabled and permitted to authenticate. Administrators can block or disable an account when access should no longer be allowed, such as after an employee leaves an organization. Conditional Access adds additional conditions to access decisions but does not replace the fundamental enabled or disabled state of an account. Windows Autopilot manages deployment, while device configuration controls endpoint settings. Account status is therefore a basic identity control for preventing disabled users from authenticating.
Question 53
Which Intune feature can deploy a specific application to a selected group of users?
- Application assignment
- Security baseline
- Compliance action
- Device cleanup
Correct Answer: 1
Explanation
Application assignments allow Intune administrators to target applications to specific users or device groups. Applications can generally be configured as required, available, or handled through other supported deployment options. Targeting specific groups helps organizations provide different software sets to different departments, roles, or device populations. Security baselines focus on security configurations, compliance actions respond to compliance conditions, and device cleanup manages stale device records. Application assignment is therefore the appropriate feature for controlling which users or devices receive particular software.
Question 54
Which Windows feature can automatically free disk space by removing temporary files?
- Windows Sandbox
- Storage Sense
- Credential Guard
- Windows Hello
Correct Answer: 2
Explanation
Storage Sense is a Windows feature that can automatically manage available disk space by removing unnecessary temporary files and other content according to configured settings. It can help prevent storage from becoming unnecessarily full without requiring administrators or users to manually clean every temporary location. Windows Sandbox provides an isolated environment, Credential Guard protects authentication information, and Windows Hello provides modern authentication. Storage Sense is therefore the Windows feature specifically designed to automate certain storage-cleanup activities.
Question 55
Which Microsoft Intune feature provides a predefined collection of recommended security settings for Windows?
- Device categories
- Security baselines
- App assignments
- Enrollment restrictions
Correct Answer: 2
Explanation
Security baselines in Microsoft Intune provide predefined groups of recommended security settings for supported Windows environments. They help administrators implement a consistent security posture without manually determining every setting from scratch. Administrators can review the baseline, compare it with organizational requirements, and customize settings when necessary. Device categories help organize devices, app assignments control application deployment, and enrollment restrictions determine which devices can enroll. Security baselines are therefore specifically intended to simplify the implementation of recommended Windows security configurations.
Question 56
Which Windows command can refresh computer and user Group Policy settings?
- gpupdate
- ipconfig
- chkdsk
- netstat
Correct Answer: 1
Explanation
The gpupdate command refreshes Group Policy settings on a Windows computer. Administrators can use it when they need newly changed domain policies to be applied without waiting for the next automatic refresh cycle. Options can be used to target computer policies, user policies, or both, and a restart or logoff may sometimes be required depending on the policy. Ipconfig manages network information, chkdsk checks storage volumes, and netstat displays network connections. Gpupdate is therefore the appropriate command for manually refreshing Group Policy.
Question 57
Which Windows feature can isolate an application from the main operating system for security testing?
- Windows Sandbox
- BitLocker
- Credential Guard
- Windows Defender Firewall
Correct Answer: 1
Explanation
Windows Sandbox provides a temporary isolated desktop environment that can be used to run applications separately from the main Windows installation. This can be useful when administrators need to test unfamiliar software or open potentially risky files while reducing the risk of affecting the host environment. The sandbox is discarded when closed, which removes changes made during the session. BitLocker encrypts storage, Credential Guard protects credentials, and Windows Defender Firewall controls network traffic. Sandbox is specifically intended for isolated application execution.
Question 58
Which Intune capability allows administrators to view whether applications installed successfully on managed devices?
- Application monitoring and reporting
- Device enrollment restrictions
- Security baseline
- Windows Hello
Correct Answer: 1
Explanation
Intune application monitoring and reporting provide administrators with information about application deployment status across managed devices. Administrators can review whether applications are installed successfully, identify deployment failures, and investigate devices that have not received required software. This visibility is useful when troubleshooting application deployment and ensuring that organizational software requirements are being met. Enrollment restrictions control device enrollment, security baselines manage recommended security settings, and Windows Hello provides authentication. Application monitoring and reporting are therefore important for software deployment management.
Question 59
Which Windows feature protects network traffic by filtering inbound and outbound connections based on rules?
- Windows Defender Firewall
- Storage Sense
- Device Manager
- BitLocker
Correct Answer: 1
Explanation
Windows Defender Firewall monitors network connections and applies configured rules to control inbound and outbound traffic. Administrators can create or manage rules based on profiles, applications, ports, protocols, addresses, and other criteria. This helps reduce unauthorized network access and limits exposure to unwanted connections. Storage Sense manages disk space, Device Manager manages hardware and drivers, and BitLocker encrypts storage. Windows Defender Firewall is therefore the Windows feature specifically responsible for host-based network traffic filtering.
Question 60
Which Microsoft Intune capability can help identify devices that have not checked in recently?
- Device compliance
- Device inventory and monitoring
- Application protection
- Windows Hello
Correct Answer: 2
Explanation
Intune device inventory and monitoring information can help administrators identify managed devices and review their recent management activity, including device check-in information. This visibility helps administrators locate devices that may be inactive, disconnected, or no longer being managed as expected. Compliance policies determine whether devices satisfy security requirements, application protection policies protect organizational data inside supported applications, and Windows Hello provides authentication. Device inventory and monitoring are therefore useful for maintaining awareness of the current state of managed endpoints.