View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps.
Question 161
Which Intune feature allows administrators to configure Microsoft Defender for Endpoint integration for managed Windows devices?
- Device category
- Enrollment restriction
- App protection policy
- Endpoint detection and response policy
Correct Answer: 4
Explanation
An endpoint detection and response policy in Intune can be used to configure supported Microsoft Defender for Endpoint settings for managed Windows devices. This integration helps organizations onboard devices to Defender for Endpoint and establish endpoint security capabilities. Defender for Endpoint can provide detection, investigation, and response information to security teams. Device categories organize devices, enrollment restrictions control which devices can enroll, and app protection policies protect application data. An EDR policy is therefore the appropriate Intune capability when the goal is to configure endpoint detection and response integration.
Question 162
Which Intune enrollment scenario is commonly associated with personally owned Windows devices where users need access to organizational resources?
- Microsoft Entra registered
- Self-deploying Autopilot
- Pre-provisioned deployment
- Hybrid Microsoft Entra join
Correct Answer: 1
Explanation
Microsoft Entra registered devices are commonly associated with personally owned or BYOD scenarios where users need access to organizational resources without requiring the device to be fully joined to the organization’s Microsoft Entra environment. Registration establishes a device identity that can support applicable management and access controls. Self-deploying Autopilot is intended for corporate provisioning scenarios, while pre-provisioning prepares corporate devices before delivery. Hybrid Microsoft Entra join is generally used when devices maintain an on-premises Active Directory relationship alongside Microsoft Entra ID. Registration is therefore suitable for many personal-device scenarios.
Question 163
Which Intune capability allows administrators to configure policies using traditional Group Policy-style administrative templates?
- Compliance actions
- Administrative templates
- Device cleanup rules
- Assignment filters
Correct Answer: 2
Explanation
Administrative templates in Intune provide a familiar policy-based method for configuring many Windows settings that administrators may recognize from traditional Group Policy management. They contain supported settings that can be configured and assigned through Intune to managed users or devices. This can help organizations transition certain Windows configuration tasks from on-premises Group Policy to cloud-based management. Compliance actions respond to noncompliant devices, device cleanup rules manage stale records, and assignment filters refine targeting. Administrative templates are therefore the appropriate feature when administrators need template-based Windows configuration through Intune.
Question 164
A company wants to deploy a Windows application and automatically remove an older application version during the deployment. Which Intune feature should be configured?
- Requirement rules
- Detection rules
- Supersedence
- Assignment filters
Correct Answer: 3
Explanation
Application supersedence allows Intune administrators to define that one application should replace another application. This is particularly useful when deploying a newer version and removing an older version as part of the software lifecycle process. The administrator can configure the relationship and supported uninstall behavior for the superseded application. Requirement rules determine whether a device meets installation conditions, detection rules determine whether an application is already installed, and assignment filters refine targeting. Supersedence is therefore the appropriate feature when a newer application version should replace an older deployment.
Question 165
Which Windows security capability helps reduce the risk of malicious applications exploiting vulnerable operating system features?
- Storage Sense
- Delivery Optimization
- File History
- Exploit protection
Correct Answer: 4
Explanation
Exploit protection helps defend Windows devices against exploitation techniques that target vulnerabilities in applications and operating system components. Administrators can configure supported exploit protection settings to provide additional security controls against malicious behavior. This capability is part of Microsoft’s broader endpoint security protections and can complement antivirus and other defensive technologies. Storage Sense manages disk space, Delivery Optimization improves update content distribution, and File History provides file backup capabilities. Exploit protection is therefore the appropriate security capability when the objective is to reduce exposure to software exploitation techniques.
Question 166
Which Intune feature allows administrators to configure settings that reduce the ability of malicious applications to perform common attack techniques?
- Device cleanup rules
- Attack Surface Reduction rules
- Enrollment restrictions
- Device categories
Correct Answer: 2
Explanation
Attack Surface Reduction, or ASR, rules help reduce common attack techniques by restricting behaviors that are frequently abused by malicious software. Administrators can configure supported ASR rules through Intune endpoint security policies and apply them to targeted Windows devices. Depending on the rule, protections can address behaviors involving scripts, Office applications, credential theft, or other attack techniques. Device cleanup rules manage stale records, enrollment restrictions control device registration, and device categories organize endpoints. ASR rules are therefore appropriate when an organization wants to reduce exposure to common endpoint attack behaviors.
Question 167
Which Intune feature provides users with a portal for installing available applications and performing supported device management actions?
- Company Portal
- Settings Catalog
- Endpoint analytics
- Security baseline
Correct Answer: 1
Explanation
Company Portal provides an end-user interface for accessing applications and supported device management functions. Users can browse applications assigned as available, initiate installations, view device information, and perform certain organization-approved actions depending on the platform and configuration. Settings Catalog is an administrator-facing tool for configuring device settings. Endpoint analytics provides performance and user-experience insights, while security baselines provide collections of recommended security settings. Company Portal is therefore the appropriate interface when users need a central location to access available organizational applications and supported device actions.
Question 168
An organization wants to block access to corporate resources when a device fails required security conditions. Which two Intune and Microsoft Entra capabilities should be combined?
- Company Portal and Storage Sense
- Compliance policies and Conditional Access
- Security baselines and Device Manager
- Windows Sandbox and Remote Help
Correct Answer: 2
Explanation
Intune compliance policies can evaluate whether devices satisfy organizational security requirements, while Microsoft Entra Conditional Access can use the compliance state as part of access decisions. When a device fails the required conditions, Conditional Access can restrict access to protected organizational resources according to the configured policy. This combination connects endpoint security evaluation with identity-based access control. Company Portal, Storage Sense, Windows Sandbox, and Remote Help provide useful management or support functions but do not provide the same compliance-based access control mechanism.
Question 169
Which Intune feature allows administrators to collect detailed information about managed devices for troubleshooting and inventory purposes?
- Device query
- App protection policy
- Windows Update ring
- Enrollment restriction
Correct Answer: 1
Explanation
Device query allows administrators to retrieve information from supported managed devices and use that information for troubleshooting, investigation, and endpoint management. It can provide useful details about the current state of a device without requiring administrators to manually inspect every endpoint. This capability can help identify configuration conditions, hardware information, software states, and other supported device details. App protection policies protect organizational application data, Windows Update rings manage update behavior, and enrollment restrictions control enrollment. Device query is therefore the most appropriate option for retrieving endpoint information.
Question 170
Which Intune policy type can be used to configure Microsoft Defender Firewall rules and settings on Windows devices?
- Compliance policy
- App configuration policy
- Endpoint security firewall policy
- Device cleanup policy
Correct Answer: 3
Explanation
The endpoint security firewall policy in Intune is designed to configure Microsoft Defender Firewall settings on supported Windows devices. Administrators can use this policy to establish firewall behavior and configure supported rules for controlling network traffic. Compliance policies can evaluate firewall status as part of device compliance but are not primarily intended to configure firewall rules. App configuration policies manage supported application settings, while device cleanup policies manage stale device records. Therefore, the endpoint security firewall policy is the appropriate choice for centrally configuring Microsoft Defender Firewall.
Question 171
Which Windows Autopilot capability is designed to automatically configure a device with organizational settings while minimizing user interaction?
- Self-deploying mode
- User-driven mode
- Pre-provisioning
- Autopilot Reset
Correct Answer: 1
Explanation
Windows Autopilot self-deploying mode is designed for scenarios where minimal user interaction is desired during deployment. The device can automatically join Microsoft Entra ID and enroll in Intune while applying required organizational policies and configurations. It can be useful for shared devices, kiosks, or other scenarios where a specific user does not need to perform the initial setup. User-driven mode requires user authentication, while pre-provisioning involves a technician preparing the device before delivery. Autopilot Reset is used to prepare an already deployed device for reuse rather than performing its initial deployment.
Question 172
Which Intune capability can help prevent users from accessing organizational resources when their Windows operating system is below the required version?
- Device category
- Compliance policy
- Company Portal
- Remote Help
Correct Answer: 2
Explanation
An Intune compliance policy can define a minimum operating system version that managed devices must meet. Devices running an older or unsupported Windows version can be marked noncompliant. When combined with Microsoft Entra Conditional Access, the compliance state can be used to restrict access to protected organizational resources. Device categories organize endpoints, Company Portal provides user-facing application and device functions, and Remote Help supports remote assistance. Compliance policies are therefore appropriate when an organization needs to evaluate Windows version requirements as part of its endpoint access strategy.
Question 173
Which Intune feature is designed to provide recommended Windows security settings that administrators can deploy as a standardized configuration?
- Application assignment
- Device query
- Security baseline
- Enrollment Status Page
Correct Answer: 3
Explanation
An Intune security baseline provides a standardized collection of recommended security settings for supported Windows devices. Administrators can deploy the baseline to targeted users or devices and adjust settings when organizational requirements differ from the recommendations. This helps establish consistent security configurations across endpoints and can simplify administration. Application assignments control software deployment, Device query retrieves endpoint information, and the Enrollment Status Page monitors aspects of device setup. A security baseline is therefore the appropriate feature when administrators want to deploy a standardized collection of recommended Windows security configurations.
Question 174
An administrator needs to ensure that a required Win32 application is not installed until another application is present. Which configuration should be used?
- Detection rule
- Assignment filter
- Dependency
- Scope tag
Correct Answer: 3
Explanation
A Win32 application dependency specifies another application that must be installed before the dependent application can be deployed. This is useful when an application requires a supporting component, runtime, framework, or another prerequisite. Intune can use the dependency relationship to manage the appropriate installation sequence. Detection rules determine whether an application is already installed, assignment filters refine targeting, and scope tags control administrative visibility. A dependency is therefore the correct configuration when one application must be installed before another application can be deployed successfully.
Question 175
Which Intune feature can be used to deploy a specific Windows quality update to devices according to an accelerated schedule?
- Feature update policy
- Update ring
- Expedite update policy
- Driver update policy
Correct Answer: 3
Explanation
An expedite update policy is designed to accelerate deployment of specified Windows quality updates to managed devices. Organizations can use this capability when a particular quality or security update needs to reach endpoints more quickly than it would through the normal servicing schedule. Update rings control broader Windows Update behavior, including deferrals and restart settings. Feature update policies manage the targeted Windows feature version, while driver update policies focus on driver servicing. Expedite update policy is therefore the appropriate option when an organization needs to accelerate deployment of a specific quality update.
Question 176
Which Intune administrative feature allows an organization to limit what an administrator can manage according to assigned permissions?
- Role-based access control
- Windows Autopilot
- Device cleanup
- Delivery Optimization
Correct Answer: 1
Explanation
Role-based access control, or RBAC, allows organizations to assign specific administrative permissions to users or groups based on their responsibilities. In Intune, administrators can use built-in roles or create custom roles with selected permissions. This supports delegated administration and the principle of least privilege by ensuring administrators receive only the access required for their duties. Windows Autopilot manages provisioning, device cleanup handles stale records, and Delivery Optimization manages content distribution. RBAC is therefore the appropriate feature when an organization needs to control what administrative actions different IT staff members can perform.
Question 177
Which Windows security feature provides protection against unauthorized access to encrypted data when a device is lost or stolen?
- SmartScreen
- Credential Guard
- Windows LAPS
- BitLocker
Correct Answer: 4
Explanation
BitLocker provides full-volume encryption for supported Windows devices, helping protect data stored on drives if a device is lost or stolen. Without appropriate authentication or recovery information, unauthorized individuals should not be able to access the encrypted contents through normal means. BitLocker can be centrally managed through Intune disk encryption policies on supported devices. SmartScreen protects against malicious websites and downloads, Credential Guard protects sensitive authentication information, and Windows LAPS manages local administrator passwords. BitLocker is therefore the appropriate technology when the primary requirement is protecting stored device data through encryption.
Question 178
Which Intune feature allows administrators to determine whether a managed device meets requirements such as encryption, password settings, and firewall status?
- Configuration profile
- Compliance policy
- Application configuration policy
- Device category
Correct Answer: 2
Explanation
Compliance policies evaluate managed devices against defined organizational requirements. Administrators can configure conditions involving encryption, passwords, firewall status, antivirus protection, operating system versions, and other supported security controls. The resulting compliance state can then be used by Conditional Access to influence access to organizational resources. Configuration profiles primarily configure device settings, application configuration policies manage supported application behavior, and device categories organize endpoints. Compliance policy is therefore the appropriate Intune feature when administrators need to determine whether a device satisfies specified security requirements.
Question 179
Which Intune capability allows administrators to manage applications by specifying installation, uninstallation, detection, requirements, and dependencies?
- Microsoft Store app
- Web app
- Win32 app
- App protection policy
Correct Answer: 3
Explanation
Intune Win32 application management provides extensive deployment controls for traditional Windows desktop applications. Administrators can configure installation and uninstall commands, detection rules, requirement rules, dependencies, return codes, and assignments. These controls make Win32 apps suitable for deploying applications that require custom installation logic or detailed management. Microsoft Store apps use the Store integration, web apps provide access to web-based resources, and app protection policies protect organizational data within supported applications. Win32 app management is therefore the appropriate capability when administrators need detailed control over Windows desktop application deployment.
Question 180
Which Intune action is appropriate when a managed device is lost and the administrator wants to prevent normal access without immediately erasing the device?
- Remote lock
- Wipe
- Retire
- Autopilot Reset
Correct Answer: 1
Explanation
Remote lock allows an administrator to lock a supported managed device remotely, helping prevent normal access when the device is lost or temporarily unavailable. Unlike a Wipe operation, remote lock does not intentionally erase the device’s data. Wipe is used when the device needs to be reset and its data removed, while Retire removes organizational management and corporate data. Autopilot Reset prepares an existing Windows device for reuse. Remote lock is therefore the appropriate action when immediate access prevention is required without performing a complete device reset.