Font size
WorksheetsMD-102 Exam Prep-AK
Total questions: 21
Worksheet time: 14mins
You are managing a Microsoft 365 subscription with 10 computers running Windows 10, all of which are enrolled in mobile device management (MDM). You need to deploy Microsoft 365 Apps for enterprise on these devices.
What is the appropriate action to take?
Create a Windows 10 device profile from the Microsoft Intune admin center.
Add an app registration from Azure AD
Add an enterprise application from Azure AD
Add an app from the Microsoft Intune admin center
You are managing a Microsoft 365 E5 subscription that includes 10 Android Enterprise devices. Each device has a corporate-owned work profile and is enrolled in Microsoft Intune. You need to set up these devices to run a single app in kiosk mode.
Which configuration settings should you adjust within the device restrictions profile?
General
Users and Accounts
System security
Device experience
You have an Entra ID group named Group1, which contains two Windows 10 Enterprise devices: Device1 and Device2. You create a device configuration profile named Profile1 and assign it to Group1.
To ensure that Profile1 is applied only to Device1, what should you modify in Profile1?
Assignments
Settings
Scope (Tags)
Applicability Rules
You manage 100 Windows 10 computers that connect to an Azure Log Analytics workspace.
Which three types of data can you collect from these computers using Log Analytics? Each correct answer forms a complete solution.
NOTE: Each correct selection is worth one point.
Failure events from the Security log
List of processes and their execution times
Average processor utilization
Error events from the System log
Third-party application logs stored as text files
You manage a Microsoft 365 E5 subscription that includes 150 hybrid Entra ID joined Windows devices, all of which are enrolled in Microsoft Intune. You need to configure Delivery Optimization on these devices to meet the following requirements:
Allow downloads from the internet and from other computers on the local network.
Limit the bandwidth usage to 50%.
What should you use?
A configuration profile
A Windows Update for Business Group Policy setting
A Microsoft Peer-to-Peer Networking Services Group Policy setting
An Update ring for Windows 10 and later profile
Your network includes an Active Directory domain, with all computers running Windows 10 and a user named Admin1. Windows PowerShell remoting is enabled across the computers.
To ensure Admin1 can initiate remote PowerShell sessions while adhering to the principle of least privilege, which group should Admin1 be added to?
Access Control Assistance Operators
Remote Desktop Users
Power Users
Remote Management Users
You manage devices using Microsoft Intune as part of a Microsoft 365 subscription with Microsoft Intune Suite, and deploy Windows 11 using Windows Autopilot. A support engineer reports difficulty in collecting deployment logs when deployments fail.
To ensure deployment logs can be collected in the event of failure, which setting should you configure?
the automatic enrollment settings
the Windows Autopilot deployment profile
the enrollment status page (ESP) profile
the device configuration profile
Your company has an Entra ID tenant named contoso.com, and users are currently prompted to set up a four-digit PIN when joining Windows 10 devices. You need to ensure they are prompted to set up a six-digit PIN.
Solution: You configure automatic mobile device management (MDM) enrollment from the Microsoft Entra admin center and create and assign a device restrictions profile from the Microsoft Intune admin center.
Yes
No
Your company has an Entra ID tenant named contoso.com that contains several Windows 10 devices.
When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin.
You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.
Solution: From the Microsoft Entra admin center, you modify the User settings and the Device settings.
Does this meet the goal?
Yes
No
Your company has an Entra ID tenant named contoso.com, and when users join new Windows 10 devices, they are prompted to set up a four-digit PIN. You need to ensure that users are prompted to set up a six-digit PIN instead.
Solution: You configure automatic mobile device management (MDM) enrollment from the Microsoft Entra admin center and configure Windows Hello for Business enrollment options from the Microsoft Intune admin center.
Does this meet the goal?
Yes
No
Your company uses Microsoft Entra ID (Azure AD) and Microsoft Intune for device management. You want to ensure that only compliant devices can access corporate resources by applying Conditional Access policies.
Require multi-factor authentication (MFA) for all users.
Device compliance policies in Intune.
Enable passwordless authentication methods.
Configure Microsoft Defender for Endpoint as the default threat protection.
When configuring Self-Service Password Reset (SSPR) policies, which of the following can be used as an authentication method for password reset?
Security questions
IP address
Device serial number
User’s last login time
Which of the following is a primary benefit of using Windows Autopilot for deploying devices in an organization?
Manual image creation is required for each device.
Users need to be physically present at the IT department for setup.
Devices can be automatically configured and enrolled into management without requiring reimaging.
Autopilot only works with on-premises Active Directory environments.
In a hybrid identity scenario using Entra ID (formerly Azure AD) Connect, what is the primary purpose of Password Hash Synchronization (PHS)?
It allows users to reset passwords from on-premises only.
It synchronizes user passwords from Entra ID back to on-premises Active Directory.
It synchronizes password hashes from on-premises Active Directory to Entra ID, enabling users to authenticate using the same password in both environments.
It replaces on-premises Active Directory authentication with cloud-only authentication.
When creating a configuration profile in Microsoft Intune, which of the following settings types can be configured to manage Windows 10/11 devices?
Browser settings
Network printer configurations
Device restrictions
Windows system sounds
Which of the following is a key feature of an App Protection Policy in Microsoft Intune?
Restricting device access to the corporate network
Encrypting data at rest and enforcing data loss prevention (DLP) for apps
Installing mandatory updates on all managed devices
Blocking access to the Microsoft Store for all users
What is the primary purpose of the Endpoint Security policies in Microsoft Intune?
To manage and deploy application updates
To enforce security settings and configurations on devices
To configure user access permissions for cloud applications
To monitor network traffic and performance
Which of the following security features can be configured through Endpoint Security policies in Microsoft Intune to protect Windows 10/11 devices?
User authentication methods
BitLocker encryption settings
Application deployment schedules
Network bandwidth management
What is one of the main benefits of using Microsoft Defender for Endpoint in conjunction with Intune's Endpoint Security policies?
It eliminates the need for user training on security practices.
It provides advanced threat protection and remediation capabilities.
It allows for unlimited device enrollments without restrictions.
It guarantees 100% protection against all cyber threats.
What is a key advantage of using Seamless Single Sign-On (SSO) in a hybrid identity environment?
It requires users to log in multiple times throughout the day.
It simplifies the user experience by allowing automatic logins to cloud resources without additional prompts.
It eliminates the need for device management.
It is only available for on-premises applications.
Which of the following is a key benefit of using Pass-through Authentication (PTA) in a hybrid identity setup?
Users must always change their passwords through the cloud.
It allows users to authenticate against on-premises Active Directory without storing passwords in the cloud.
It completely removes the need for on-premises Active Directory.
It requires extensive configuration of third-party authentication providers.
