{"id":14344,"date":"2026-09-17T04:41:13","date_gmt":"2026-09-17T04:41:13","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14344"},"modified":"2026-09-17T04:41:13","modified_gmt":"2026-09-17T04:41:13","slug":"microsoft-md-102-practice-test-questions-and-exam-dumps-part10-q181-200","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-md-102-practice-test-questions-and-exam-dumps-part10-q181-200\/","title":{"rendered":"Microsoft MD-102 Practice Test Questions and Exam Dumps Part10 Q181-200"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/md-102-exam-dumps\"><b>Microsoft MD-102 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 181<\/b><\/h3>\n<p><b>Which Intune capability allows administrators to configure Windows devices with security rules designed to reduce commonly exploited attack techniques?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device cleanup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">App configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enrollment restrictions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attack Surface Reduction rules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attack Surface Reduction rules are designed to reduce the ability of malicious software to use commonly exploited behaviors on Windows devices. Organizations can configure supported ASR rules through Intune endpoint security policies and apply them to targeted devices. These rules can help restrict activities associated with credential theft, malicious scripts, Office-based attacks, and other common techniques. Device cleanup manages stale records, app configuration policies manage application settings, and enrollment restrictions control which devices can enroll. ASR rules are therefore appropriate when an organization wants to reduce exposure to common endpoint attack behaviors.<\/span><\/p>\n<h3><b>Question 182<\/b><\/h3>\n<p><b>Which Intune feature allows administrators to create a policy that configures Windows devices using individual settings selected from a centralized catalog?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Settings Catalog<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote Help<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device cleanup rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Company Portal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Settings Catalog provides a centralized collection of configurable settings that administrators can use to create Intune configuration policies. Instead of manually creating individual custom configurations, administrators can search the catalog for supported settings, configure their values, and assign the policy to users or devices. This provides granular control over Windows configuration and simplifies policy creation. Remote Help is used for remote assistance, device cleanup rules manage stale device records, and Company Portal provides end-user access to applications and supported device actions. Settings Catalog is therefore the appropriate configuration tool.<\/span><\/p>\n<h3><b>Question 183<\/b><\/h3>\n<p><b>An administrator wants to assign an application to a group but exclude devices that have a specific operating system version. Which Intune feature can refine the assignment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scope tags<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assignment filters<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device categories<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enrollment restrictions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Assignment filters allow administrators to refine application and policy assignments according to device properties. An administrator can assign an application to a Microsoft Entra group and then use a filter to include or exclude devices based on supported attributes, such as operating system information. This provides more precise targeting without requiring separate groups for every condition. Scope tags control administrative visibility, device categories help classify devices, and enrollment restrictions determine which devices are permitted to enroll. Assignment filters are therefore the appropriate feature for refining an existing application assignment.<\/span><\/p>\n<h3><b>Question 184<\/b><\/h3>\n<p><b>Which Intune application deployment option is most appropriate for an application that users should install only when they need it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Required<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Available<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Uninstall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dependency<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Available application assignment makes software accessible to targeted users through Company Portal without automatically installing it. Users can browse the available application and choose to install it when required. This approach is useful for optional business applications that are not necessary on every device. Required assignments automatically deploy applications, while Uninstall assignments remove applications from targeted devices. Dependencies define prerequisite relationships between applications. Therefore, Available is the correct assignment type when users should decide whether and when to install optional software.<\/span><\/p>\n<h3><b>Question 185<\/b><\/h3>\n<p><b>Which Microsoft Intune feature can configure a managed Windows device to automatically receive a specified Windows feature update version?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compliance policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Update ring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security baseline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Feature update policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A feature update policy allows Intune administrators to specify the Windows feature update version that targeted devices should receive or remain on. This provides organizations with greater control over Windows servicing and allows IT teams to test a feature release before deploying it broadly. Update rings manage general update behavior, such as deferrals and restart settings, rather than primarily defining a specific feature version. Security baselines provide recommended security configurations, while compliance policies evaluate device requirements. A feature update policy is therefore the appropriate tool for controlling a target Windows feature release.<\/span><\/p>\n<h3><b>Question 186<\/b><\/h3>\n<p><b>Which Windows technology helps protect sensitive credentials by placing certain security processes in an isolated virtualization-based environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SmartScreen<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BitLocker<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Windows Sandbox<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Credential Guard uses virtualization-based security to isolate and protect certain sensitive authentication credentials from the normal Windows operating system environment. This helps reduce the risk of credential theft through attacks targeting Windows authentication components. It is particularly relevant in enterprise environments where compromised credentials could provide attackers with access to additional resources. SmartScreen focuses on reputation-based protection, BitLocker encrypts stored data, and Windows Sandbox provides an isolated environment for temporary application execution. Credential Guard is therefore the technology specifically associated with isolating protected credentials through virtualization-based security.<\/span><\/p>\n<h3><b>Question 187<\/b><\/h3>\n<p><b>Which Intune capability allows an administrator to determine whether a Win32 application is installed by checking a specific registry value?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detection rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Requirement rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dependency<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assignment filter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detection rules determine whether Intune recognizes a Win32 application as installed on a managed Windows device. One supported detection method can use registry information, allowing administrators to check for a particular registry key or value associated with the application. Accurate detection rules are important because Intune uses their results to determine whether an application deployment has succeeded or whether installation is still required. Requirement rules determine whether a device qualifies for installation, dependencies define prerequisites, and assignment filters refine targeting. Detection rules are therefore the correct mechanism for checking application installation through registry information.<\/span><\/p>\n<h3><b>Question 188<\/b><\/h3>\n<p><b>Which Intune feature allows administrators to configure an application so that a newer version replaces an older version?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dependencies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Supersedence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detection rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Requirement rules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application supersedence allows an administrator to establish a relationship in which a newer application replaces an older application. This is useful when organizations need to upgrade software versions while managing the removal or replacement of previous deployments. Administrators can configure the superseding application and define supported behavior for the older application. Dependencies are used when an application requires another application as a prerequisite. Detection rules identify installation status, while requirement rules determine whether a device meets conditions for deployment. Supersedence is therefore the appropriate capability for controlled application replacement.<\/span><\/p>\n<h3><b>Question 189<\/b><\/h3>\n<p><b>Which Intune endpoint security policy category is used to configure BitLocker settings on supported Windows devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Disk encryption endpoint security policy in Intune is designed to configure encryption technologies such as BitLocker on supported Windows devices. Administrators can use it to establish encryption requirements and configure related recovery and protection settings. Centralized encryption management helps protect organizational data stored on managed devices. Antivirus policies configure malware protection, Firewall policies manage network traffic controls, and Account protection policies address authentication and account security. Disk encryption is therefore the correct endpoint security category when administrators need to configure BitLocker across managed Windows devices.<\/span><\/p>\n<h3><b>Question 190<\/b><\/h3>\n<p><b>A company wants Windows devices to download and install monthly quality updates while controlling restart and deferral behavior. Which Intune feature should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Feature update policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Driver update policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Expedite update policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Update ring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Update rings provide administrators with controls for the general Windows Update experience on managed devices. Settings can include update deferrals, active hours, restart behavior, user notifications, and other supported servicing options. This makes update rings appropriate for managing recurring quality updates while controlling when devices restart. Feature update policies focus on the Windows feature version, driver update policies manage driver servicing, and expedite update policies are intended to accelerate specific quality updates. Therefore, an update ring is the appropriate choice for controlling normal monthly update and restart behavior.<\/span><\/p>\n<h3><b>Question 191<\/b><\/h3>\n<p><b>Which Intune feature allows a Windows device to be automatically enrolled into mobile device management when an eligible user signs in?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic MDM enrollment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device query<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Company Portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote Help<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Automatic MDM enrollment allows eligible Windows devices to enroll in Intune when users sign in with organizational identities, provided the required Microsoft Entra and MDM configuration is in place. Administrators can define the appropriate MDM user scope so selected users are automatically enrolled. This reduces the need for users or administrators to perform manual enrollment steps. Device query retrieves endpoint information, Company Portal provides user-facing management capabilities, and Remote Help supports remote assistance. Automatic MDM enrollment is therefore the appropriate capability when device management should begin automatically after user authentication.<\/span><\/p>\n<h3><b>Question 192<\/b><\/h3>\n<p><b>Which Intune feature provides an end-user interface for accessing applications assigned as Available?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Settings Catalog<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Company Portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint analytics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security baseline<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Company Portal provides users with a centralized interface for accessing applications that administrators have made available through Intune. Users can browse the application catalog and initiate installations for optional software. Depending on the platform and organizational configuration, Company Portal can also provide device information and supported management actions. Settings Catalog is used by administrators to configure device settings, Endpoint analytics provides performance and user-experience information, and security baselines provide recommended security configurations. Company Portal is therefore the appropriate user-facing application management interface for available applications.<\/span><\/p>\n<h3><b>Question 193<\/b><\/h3>\n<p><b>Which Windows Autopilot feature is intended to display the progress of required applications and policies during initial device setup?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device cleanup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Windows LAPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enrollment Status Page<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage Sense<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Enrollment Status Page, or ESP, provides visibility into the progress of device setup during supported Windows enrollment and Autopilot deployment scenarios. It can display information about required applications, policies, and device configuration as the deployment proceeds. Organizations can configure ESP to help ensure that important applications and settings are processed before users begin working on the device. Device cleanup manages stale records, Windows LAPS manages local administrator passwords, and Storage Sense manages storage space. ESP is therefore the appropriate feature for monitoring application and policy installation during initial setup.<\/span><\/p>\n<h3><b>Question 194<\/b><\/h3>\n<p><b>Which Intune feature can be used to configure Microsoft Defender Antivirus settings such as real-time protection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compliance policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint security antivirus policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device category<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enrollment restriction<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The endpoint security antivirus policy in Intune provides configuration options for Microsoft Defender Antivirus on supported Windows devices. Administrators can use this policy to manage settings such as real-time protection, cloud-delivered protection, scanning behavior, and other supported antivirus controls. Compliance policies can evaluate whether certain security requirements are satisfied but do not primarily configure antivirus settings. Device categories organize devices, while enrollment restrictions control which devices can enter Intune management. The endpoint security antivirus policy is therefore the appropriate choice for centrally configuring Microsoft Defender Antivirus.<\/span><\/p>\n<h3><b>Question 195<\/b><\/h3>\n<p><b>Which Intune capability can define a minimum Windows operating system version that devices must meet to remain compliant?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compliance policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device category<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application assignment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Intune compliance policy can define a minimum operating system version that managed devices must meet. Devices running an unsupported or outdated Windows version can be marked noncompliant according to the configured requirements. This compliance state can then be used with Conditional Access to control access to organizational resources. Configuration profiles are primarily used to configure device settings, device categories organize endpoints, and application assignments manage software deployment. Compliance policy is therefore the appropriate feature when an organization needs to evaluate Windows version requirements as part of its device security posture.<\/span><\/p>\n<h3><b>Question 196<\/b><\/h3>\n<p><b>Which Intune capability can be used to manage the local administrator password on supported Windows devices and rotate it automatically?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Windows LAPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BitLocker<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SmartScreen<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Windows LAPS provides centralized management of local administrator account passwords on supported Windows devices. It can automatically generate and rotate passwords according to organizational policies, helping reduce the risks associated with static or shared local administrator credentials. Intune can be used to configure and deploy Windows LAPS policies to managed endpoints. Credential Guard protects sensitive authentication information, BitLocker encrypts stored data, and SmartScreen helps protect users from malicious websites and downloads. Windows LAPS is therefore the appropriate capability when an organization needs automated management and rotation of local administrator passwords.<\/span><\/p>\n<h3><b>Question 197<\/b><\/h3>\n<p><b>Which Intune capability can provide administrators with information about Windows device startup performance and user experience?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device cleanup rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint analytics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">App protection policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enrollment restrictions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint analytics provides organizations with insights into Windows device performance and user experience. It can help administrators identify issues related to startup performance, application reliability, and other factors that may affect productivity. This information can support troubleshooting and help IT teams determine which devices or configurations require attention. Device cleanup rules manage stale records, app protection policies protect organizational data within supported applications, and enrollment restrictions control device enrollment. Endpoint analytics is therefore the appropriate capability when administrators need centralized insights into endpoint performance and the user experience.<\/span><\/p>\n<h3><b>Question 198<\/b><\/h3>\n<p><b>Which Intune feature allows administrators to remotely collect supported information from a Windows device for investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Company Portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device query<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Windows Autopilot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Update ring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device query allows administrators to retrieve supported information from managed Windows devices for investigation, troubleshooting, and endpoint management. Instead of manually inspecting every device, administrators can use queries to obtain useful information about device state and configuration. This can help identify issues and support security or operational investigations. Company Portal provides user-facing functionality, Windows Autopilot handles provisioning and deployment, and update rings manage Windows Update behavior. Device query is therefore the appropriate Intune capability when administrators need to retrieve specific information from managed Windows endpoints.<\/span><\/p>\n<h3><b>Question 199<\/b><\/h3>\n<p><b>Which Intune capability is used to restrict the installation of an application until the device satisfies specified conditions such as operating system architecture?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assignment filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detection rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Requirement rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dependency<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Requirement rules define conditions that a device must satisfy before a Win32 application can be installed. Administrators can configure supported requirements such as operating system architecture, minimum operating system version, available disk space, or other conditions. This prevents applications from being deployed to devices that cannot properly support them. Detection rules determine whether the application is already installed, dependencies identify prerequisite applications, and assignment filters refine targeting based on device properties. Requirement rules are therefore the appropriate configuration when application installation should depend on specific device eligibility conditions.<\/span><\/p>\n<h3><b>Question 200<\/b><\/h3>\n<p><b>Which Intune action removes organizational data and management from a device while generally preserving personal user data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retire<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wipe<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Autopilot Reset<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote lock<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Retire action removes organizational management and corporate data from a supported device while generally preserving personal user information. It is particularly useful for personally owned devices or situations where an employee no longer needs access to organizational resources. Wipe performs a broader reset and removes device data, while Autopilot Reset prepares a managed Windows device for reuse while retaining important organizational management information. Remote lock only prevents normal access. Retire is therefore the appropriate action when an organization needs to remove its management and data without intentionally erasing the user&#8217;s personal information.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft MD-102 Exam Dumps and Practice Test Dumps. &nbsp; Question 181 Which Intune capability allows administrators to configure Windows devices with security rules designed to reduce commonly exploited attack techniques? Device cleanup App configuration Enrollment restrictions Attack Surface Reduction rules Correct Answer: 4 Explanation Attack Surface Reduction rules are designed to reduce the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14344"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14344"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14344\/revisions"}],"predecessor-version":[{"id":14367,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14344\/revisions\/14367"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14344"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14344"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14344"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}