Microsoft MD-102 Practice Test Questions and Exam Dumps Part8 Q141-160

View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.

 

Question 141

Which Windows Autopilot capability allows IT staff to install applications and policies before the end user receives the device?

  1. Self-deploying mode
  2. User-driven mode
  3. Autopilot Reset
  4. Pre-provisioning

Correct Answer: 4

Explanation

Windows Autopilot pre-provisioning allows IT technicians, partners, or authorized personnel to prepare a Windows device before it is delivered to the end user. During the technician phase, required applications, policies, certificates, and other organizational configurations can be applied. This reduces setup time for the user and helps ensure the device is ready when delivered. User-driven mode requires the user to participate in deployment, while self-deploying mode minimizes user interaction. Autopilot Reset is intended for reusing an existing managed device rather than initially preparing it.

Question 142

Which Intune feature can restrict enrollment based on the device platform or ownership type?

  1. Enrollment restrictions
  2. Compliance policy
  3. Security baseline
  4. Configuration profile

Correct Answer: 1

Explanation

Intune enrollment restrictions allow administrators to control which types of devices can enroll in the organization’s management environment. Restrictions can be configured according to supported platforms and, where applicable, ownership scenarios such as personally owned or corporate-owned devices. This helps organizations prevent unsupported or unauthorized devices from entering management. Compliance policies operate after enrollment to evaluate device requirements, while security baselines and configuration profiles configure settings on managed devices. Enrollment restrictions are therefore the appropriate capability when the requirement concerns controlling which devices are allowed to enroll.

Question 143

Which Intune policy provides administrators with individual Windows settings that can be searched and configured without manually creating custom OMA-URI entries?

  1. Administrative template
  2. Security baseline
  3. Settings Catalog
  4. Compliance policy

Correct Answer: 3

Explanation

The Intune Settings Catalog provides a searchable collection of individual device configuration settings. Administrators can locate a required Windows setting, configure its value, and deploy the resulting policy to targeted users or devices. This can be easier than creating custom OMA-URI configurations when the required setting is already available in the catalog. Administrative templates provide collections of settings based on supported policy templates, while security baselines focus on recommended security configurations. Compliance policies evaluate device conditions rather than primarily configuring device settings. Settings Catalog is therefore the appropriate choice for granular configuration.

Question 144

A company wants to automatically install a Win32 application only on 64-bit Windows devices. Which configuration should be used?

  1. Detection rule
  2. Requirement rule
  3. Assignment filter
  4. Dependency

Correct Answer: 2

Explanation

Win32 application requirement rules can specify conditions that a device must satisfy before Intune installs the application. One supported condition can distinguish operating system architecture, allowing administrators to target applications to appropriate 64-bit or 32-bit environments. Detection rules determine whether an application is already installed, rather than whether the device is eligible for installation. Dependencies define prerequisite applications, while assignment filters provide additional targeting based on device properties. A requirement rule is therefore the appropriate mechanism when installation should occur only on devices meeting a specific architecture condition.

Question 145

Which Intune feature is used to manage Microsoft Defender Antivirus configuration on Windows devices?

  1. Device enrollment restriction
  2. App protection policy
  3. Compliance policy
  4. Endpoint security antivirus policy

Correct Answer: 4

Explanation

The Intune endpoint security antivirus policy provides settings for configuring Microsoft Defender Antivirus on supported Windows devices. Administrators can use it to manage protections such as real-time protection, cloud-delivered protection, scanning behavior, and other antivirus-related settings. This policy is focused specifically on endpoint antivirus configuration. Compliance policies can evaluate whether certain security requirements are met, but they are not primarily intended to configure Defender Antivirus. Enrollment restrictions control device registration, while app protection policies protect data within supported applications. Therefore, the endpoint security antivirus policy is the appropriate choice.

Question 146

Which Microsoft Entra device identity is commonly used when a Windows device maintains an on-premises Active Directory domain relationship while also being represented in Microsoft Entra ID?

  1. Microsoft Entra registered
  2. Microsoft Entra joined
  3. Hybrid Microsoft Entra joined
  4. Workgroup

Correct Answer: 3

Explanation

Hybrid Microsoft Entra joined devices maintain a relationship with an on-premises Active Directory domain while also having a corresponding device identity in Microsoft Entra ID. This configuration is commonly used by organizations that operate a hybrid identity environment and still depend on traditional domain-based services. Microsoft Entra joined devices are directly joined to the cloud directory, while registered devices are generally associated with scenarios where full device joining is not required. Workgroup devices have no organizational Active Directory domain relationship. Hybrid Microsoft Entra join therefore fits the described environment.

Question 147

Which Intune feature allows an administrator to configure a device policy so that it applies only to devices matching specific attributes?

  1. Assignment filters
  2. Scope tags
  3. Device cleanup rules
  4. Enrollment restrictions

Correct Answer: 1

Explanation

Assignment filters allow administrators to refine policy and application assignments using device attributes. An administrator can assign a configuration to a broader Microsoft Entra group and then use a filter to include or exclude devices based on supported properties. This provides precise targeting without requiring numerous manually maintained groups. Scope tags control administrative visibility, device cleanup rules address stale device records, and enrollment restrictions control whether devices can enroll. Assignment filters are therefore particularly useful when an organization needs a policy to apply only to devices that meet specific characteristics.

Question 148

Which Intune application assignment allows users to install an application themselves through Company Portal when they need it?

  1. Required
  2. Available
  3. Uninstall
  4. Excluded

Correct Answer: 2

Explanation

An Available application assignment makes an application accessible to targeted users through Company Portal so that they can choose whether to install it. This assignment type is useful for optional applications that users may need but that should not be automatically installed on every device. A Required assignment automatically installs the application according to the deployment configuration. An Uninstall assignment removes an application, while an exclusion prevents selected users or devices from receiving an assignment. Available is therefore the correct assignment type when users should control installation of optional software.

Question 149

Which Windows feature can help protect sensitive authentication credentials by isolating them using virtualization-based security?

  1. SmartScreen
  2. BitLocker
  3. Credential Guard
  4. Storage Sense

Correct Answer: 3

Explanation

Credential Guard uses virtualization-based security to isolate certain sensitive authentication information from the normal Windows operating system environment. This helps reduce the risk that attackers can obtain protected credentials through techniques targeting the operating system. Credential Guard is particularly relevant to enterprise endpoint security because stolen credentials can potentially be used to access additional organizational resources. SmartScreen focuses on reputation-based protection for websites and downloads, BitLocker encrypts stored data, and Storage Sense manages disk space. Credential Guard is therefore the feature specifically associated with protecting credentials through isolation.

Question 150

An administrator wants a managed Windows device to remove user data while retaining organizational management information so the device can be reused. Which action is appropriate?

  1. Retire
  2. Remote lock
  3. Wipe
  4. Autopilot Reset

Correct Answer: 4

Explanation

Autopilot Reset is designed to prepare a Windows device for reuse while retaining important organizational management information and identity. It removes user-specific data, settings, and applications while keeping the device in an organizationally managed state. This makes it useful when a corporate device is being reassigned to another employee. Retire removes organizational management and corporate data, while Wipe performs a broader device reset. Remote lock only prevents normal access. Autopilot Reset therefore provides the appropriate balance when an organization wants to remove the previous user’s information while preserving management readiness.

Question 151

Which Intune feature allows administrators to configure policies that determine whether a device meets organizational security requirements?

  1. Compliance policy
  2. Configuration profile
  3. App configuration policy
  4. Device category

Correct Answer: 1

Explanation

Intune compliance policies define requirements that managed devices must satisfy to be considered compliant. Administrators can configure conditions involving operating system versions, password settings, encryption, firewall status, antivirus protection, and other supported security requirements. Devices that fail the configured conditions can be marked noncompliant, and Conditional Access can use that state when making access decisions. Configuration profiles primarily configure device settings, app configuration policies manage supported application settings, and device categories organize endpoints. Compliance policies are therefore the appropriate tool for determining whether devices meet organizational security requirements.

Question 152

Which Intune capability can configure Windows Update settings such as update deferrals and restart behavior?

  1. Feature update policy
  2. Update ring
  3. Security baseline
  4. Compliance policy

Correct Answer: 2

Explanation

Windows Update rings in Intune provide controls for how Windows devices receive and process updates. Administrators can configure settings such as update deferral periods, restart behavior, active hours, notifications, and related servicing options. This makes update rings useful for controlling the general Windows Update experience across device groups. Feature update policies focus on keeping devices on a specified Windows feature version, while security baselines provide recommended security settings. Compliance policies determine whether devices meet requirements. Therefore, an update ring is the appropriate choice for managing general update behavior.

Question 153

Which Windows Autopilot feature allows an administrator to monitor application and policy installation during device deployment?

  1. Device cleanup
  2. Remote Help
  3. Windows LAPS
  4. Enrollment Status Page

Correct Answer: 4

Explanation

The Enrollment Status Page, or ESP, provides information about the progress of Windows device setup during supported enrollment and Autopilot deployment scenarios. It can display the status of device configuration and required application installation, helping administrators and users identify whether setup is progressing successfully. Administrators can configure ESP to help ensure that important policies and applications are processed before users begin working on the device. Device cleanup manages stale records, Remote Help supports remote assistance, and Windows LAPS manages local administrator passwords. ESP is therefore the correct deployment-monitoring feature.

Question 154

Which endpoint security policy category should be used to configure Microsoft Defender Firewall settings through Intune?

  1. Disk encryption
  2. Account protection
  3. Firewall
  4. Antivirus

Correct Answer: 3

Explanation

The Intune endpoint security Firewall policy category is designed to configure Microsoft Defender Firewall settings on supported managed devices. Administrators can use this policy to establish firewall behavior and supported rules that help control network traffic. Disk encryption policies manage BitLocker and other encryption settings, account protection policies address authentication and account security, and antivirus policies configure malware protection. Because the requirement specifically concerns Microsoft Defender Firewall, the Firewall endpoint security policy is the appropriate choice for centralized configuration across managed Windows devices.

Question 155

Which Intune feature can help ensure that an application is installed only after its prerequisite application has been installed?

  1. Detection rule
  2. Dependency
  3. Scope tag
  4. Compliance action

Correct Answer: 2

Explanation

Application dependencies allow administrators to specify prerequisite applications that must be installed before another application can be deployed. This is useful when a business application requires a runtime, framework, agent, or another supporting component. Intune can use the dependency relationship to manage the installation sequence. Detection rules determine whether an application is already installed, scope tags control administrative visibility, and compliance actions define responses to noncompliant devices. Dependencies therefore provide the appropriate mechanism when one application must be installed before another can be successfully deployed.

Question 156

Which Intune feature can automatically remove stale device records after devices have not checked in for a configured period?

  1. Device cleanup rules
  2. Compliance policy
  3. Assignment filters
  4. App protection policy

Correct Answer: 1

Explanation

Device cleanup rules help organizations maintain a cleaner Intune device inventory by removing stale device records based on a configured period of inactivity. This is useful in environments where devices are replaced, retired, or no longer communicating with Intune but their records remain in the administrative portal. Compliance policies evaluate device requirements, assignment filters refine policy targeting, and app protection policies protect organizational data within supported applications. Device cleanup rules are therefore specifically suited to managing inactive or outdated device records and reducing unnecessary administrative clutter.

Question 157

Which Intune capability can protect corporate data inside supported mobile applications without requiring full device enrollment?

  1. Device compliance
  2. Windows Autopilot
  3. Security baseline
  4. App protection policy

Correct Answer: 4

Explanation

Intune app protection policies can protect corporate data within supported applications, including in many scenarios where a personal device is not fully enrolled for device management. Administrators can configure controls for actions such as copy and paste, data transfer, saving organizational files, and application access requirements. This makes app protection especially useful for BYOD environments where organizations need to secure business information without taking full control of the personal device. Device compliance evaluates enrolled device conditions, Windows Autopilot manages Windows provisioning, and security baselines configure endpoint security settings.

Question 158

Which Microsoft Entra group type is most suitable when membership should automatically change according to device attributes?

  1. Assigned user group
  2. Dynamic device group
  3. Distribution group
  4. Static security group

Correct Answer: 2

Explanation

A dynamic device group automatically evaluates configured membership rules against device attributes. Devices that meet the rule can be added to the group, while devices that no longer meet the criteria can be removed automatically. This makes dynamic device groups useful for scalable Intune assignments, especially when policies need to target devices based on properties such as operating system, ownership, or other supported attributes. Assigned or static groups require membership to be maintained more directly, while distribution groups are intended primarily for communication. Dynamic device groups therefore provide automated device-based membership.

Question 159

Which Intune application feature determines whether a Win32 application has already been installed successfully?

  1. Requirements
  2. Dependencies
  3. Detection rules
  4. Assignment filters

Correct Answer: 3

Explanation

Detection rules determine whether Intune recognizes a Win32 application as installed on a managed Windows device. Administrators can configure supported detection methods based on information such as files, folders, registry values, or other application indicators. If the detection rule does not find the expected condition, Intune may consider the application absent and attempt deployment again. Requirements determine whether a device qualifies for installation, dependencies identify prerequisite applications, and assignment filters refine targeting. Detection rules are therefore essential for accurately determining the installation state of Win32 applications.

Question 160

Which Intune action should an administrator use to request that a managed device retrieve newly assigned policies without resetting or restarting it?

  1. Sync
  2. Wipe
  3. Retire
  4. Remote lock

Correct Answer: 1

Explanation

The Sync action requests that a managed device communicate with Intune and check for newly available policies, applications, and configuration changes. It is commonly used during troubleshooting when a device has not yet received a recently assigned policy or application. Sync does not intentionally erase data or reset the device. Wipe removes device data according to the selected reset behavior, Retire removes organizational management and corporate data, and Remote lock restricts access to the device. Therefore, Sync is the appropriate and least disruptive action for requesting updated management instructions.