NEW
Font size
WorksheetsMD-102-Final_day-AK
Total questions: 36
Worksheet time: 22mins
What is the purpose of using the Microsoft Graph PowerShell SDK in managing Microsoft Entra objects?
To provide a graphical user interface for managing Microsoft Entra objects
Enables the automation and validation of the creation and teardown of environments to help deliver secure and stable application hosting platforms
To enhance the security of Microsoft Entra by enforcing multifactor authentication
What is the primary purpose of creating Guest user accounts in Microsoft Entra ID?
To manage internal employee access to Entra resource
To provide temporary administrative access to Entra services
To assign permissions to users from another Entra tenant or a Microsoft account
What is a benefit of using Microsoft Entra ID versus Active Directory (AD)?
Microsoft Entra ID uses Kerberos authentication for access across applications
Microsoft Entra ID is a cloud-based identity solution
Microsoft Entra ID can query using Lightweight Directory Access Protocol (LDAP)
In addition to the free features of Microsoft Entra ID, what is the minimum Premium version licensing needed to implement risk-based sign-ins?
Office 365
Microsoft Entra ID P2
Microsoft Entra ID P1
What's the minimum RAM requirements to install or upgrade to Windows 11?
1 GB for 32-bit or 2 GB for 64-bit
4 GB
8 GB
Fabrikam is a large Microsoft Volume License customer with a complex IT infrastructure. From a device management perspective, its IT department wants to choose the pace at which it adopts new technology for user devices. It also requires a broad range of options for operating system deployment and device and app management. Which of the following Windows 10/11 editions allows Fabrikam to meet these IT requirements?
Pro edition
Pro for Workstations
Enterprise edition
Your organization is in the process of migrating users to Microsoft 365 E3. You have a mix of Windows 10 editions deployed. You're required to provide conditional access and SSO from anywhere for the Microsoft 365 E3 users using Domain Join with Microsoft Entra ID. Which of the following Windows versions will support this requirement?
Windows 10 Home, Pro, and Enterprise
Windows 10 Pro and Enterprise
Windows 10 Enterprise only
You're the IT Support professional for Contoso, a large enterprise organization that's a Microsoft Volume License customer. Contoso needs to deploy a set of Windows 11 computers for an isolated office that won't be managed for at least six months. Given Contoso's requirements, which of the following Windows 11 editions would be the most suitable for deployment?
Pro edition
Home edition
Enterprise edition
What are the different phases of the enterprise desktop life cycle?
Planning, Purchasing, Deployment, Operations, Support, Upgrade and Retire
Planning, Building, Deployment, Operations, Support, Selling, and Retire
Planning, Purchasing, Deployment, Operations, Selling, and Retirement
Contoso is starting to allow employees to enroll their personal mobile devices on the network. When employees leave the company, IT will disconnect the device from the network and wipe selective information related to company access. What Mobile Device Manager (MDM) enables IT to selectively remove applications and application data without affecting personal data?
Microsoft Intune
Endpoint Analytics
Configuration Manager
Which Configuration Manager console feature gives you the ability to see if a device is connected to its assigned management point?
Client Online Status
Client Activity
Client Check
To manage a Windows computer using Configuration Manager, there are multiple ways to deploy the client. What are the four most common methods of deployment?
Client push, Manual deployment, Configuration Manager application package, Microsoft Intune
Windows update, Manual deployment, OS deployment, Microsoft Intune
Client push, Manual deployment, OS Deployment, Microsoft Intune
What is a benefit for using Microsoft Entra ID in an organization that already has Active Directory Domain Services implemented?
To remove the need for domain controllers
To enable iOS and Android devices to be managed using Group Policy
To offer users the ability to use their personal devices to access organizational resources
What is a benefit from using Microsoft Entra hybrid join?
Organizations can apply OS configurations to employee-owned devices.
To allow continued use of Group Policy to manage domain-joined devices
To automatically configure a broad range of older versions of Windows devices
What are the four phases of the mobile device management lifecycle?
Enroll, Configure, Protect, Retire
Enroll, Configure, Protect, Reset
Enroll, Compliance, Protect, Retire
A retailer wants to provide 25 tablets to floor staff to capture orders and complete card transactions. The Intune admin creates a new Device Enrollment Manager (DEM) account for the restaurant supervisor. What functionality does the DEM user account have?
Enroll in Intune, access email, and configure access to company data
Enroll in Intune, unenroll in Intune, get company applications, and configures access to company data by deploying role-specific applications
Enroll in Intune, unenroll in Intune, get company applications, and configures access to company data by deploying role-specific applications
As an IT administrator, you need to create a device profile for Windows devices that will enable the automation and validation of the creation and teardown of environments to help deliver secure and stable application hosting platforms. Which type of device profile should you create?
Device Security Profile
Device Compliance Profile
Device Configuration Profile
Your organization wants to prevent iOS device users from using the device camera. Which type of profile should you create in Intune?
VPN profile
Wi-Fi profile
Device restrictions profile
Why would you create a custom device profile in Intune?
To add settings that aren't available in Intune or to use settings available in other device profiles
To use only built-in settings in Intune
To restrict access to device settings for all users
Intune policies fall into multiple categories. Which category is commonly used to manage security settings and features on devices, including defining access to company resources?
Conditional access policies
Configuration policies
Device compliance policies
As the Desktop Administrator for Contoso, Holly Dickson is using Intune to help monitor and manage the company's device configuration profiles. One of the company's devices has been experiencing issues that Holly feels is related to a configuration policy setting that's applied to the device. In the Microsoft Intune admin center, Holly navigated to a view of the company's devices, selected the device in question, displayed the configuration policies that apply to the device, and then selected the policy that she feels may be the problem. By doing so, Holly can see any setting in the policy that has a "Conflict" state. What else is displayed regarding the conflicted setting that can help Holly troubleshoot this issue?
All the conflicted devices
All the profiles that have any type of conflict
All the profiles that have the conflicted setting
Contoso's IT department is wanting to assign an app to a device. What is a requirement they must meet before the app can be assigned to a device?
The device must first be enrolled in Intune
The app must be added to Google Play Store or Apple App Store
Microsoft Entra groups must be created for the device
The Contoso IT department purchased licenses for an app built by another company. Contoso is deploying the application internally. They don't have access to the source code. Which tool would be best to use to support application protection policies?
Intune App Wrapping tool
Intune App SDK
Windows Defender SmartScreen
An IT admin wants to manage the client apps that their company's workforce uses. They have identified the apps they want to manage and assign, and added them to Intune. What is the next step in the Microsoft Intune app lifecycle?
Retire the apps from service.
Deploy the apps to users and devices.
Protect the data in the apps.
As the Desktop Administrator for World Wide Importers, Alan Deyoung wants to create Conditional Access policies to provide granular access control over organizational data while allowing users to work from essentially any device and location. In which of the following scenarios will Conditional Access be especially beneficial for World Wide Importers?
Enabling employees to use a corporate application on their personal device
Enabling users to access the corporate e-mail from a public kiosk
Automatically updating devices to the required minimum OS
What are the three deployment models for Windows Hello for Business?
Cloud Only, On-premises, or Hybrid
Cloud Only, Manual, Hybrid
Cloud Only, Manual, On-premises
Contoso's IT department has implemented self-service password reset functionality for its users. What alternative authentication methods are supported on Microsoft Entra ID?
Biometric thumb print, Mobile phone, Alternative email address, Security questions
Office phone, Mobile phone, Text message, Security questions
Office phone, Mobile Phone, Alternative email address, Security questions
Northwind Traders wants to use Microsoft Defender for Endpoint to help prevent, detect, investigate, and respond to advanced threats against its corporate network. What feature of Microsoft Defender for Endpoint will help Northwind Traders to assess the security posture of the organization, see machines that require attention, as well as recommendations for actions to further reduce the attack surface within the company?
Endpoint detection and response capabilities
The Secure score dashboard
Auto investigation and remediation
Contoso has implemented Microsoft Defender Antivirus on all company devices to help prevent spyware and other unwanted software from running on any of its computers. As a best practice, Contoso schedules a daily Quick scan on each device. If Microsoft Defender Antivirus identifies a potentially dangerous file during a scan, what action does it take?
Flags it as being potentially infected
Removes the file
Moves the file to a quarantine area
You're an IT team member responsible for ensuring the security of your organization's cloud applications and services. Your team is planning to implement Microsoft Defender for Cloud Apps. What is the relevance of this solution in today's dynamic work settings?
Microsoft Defender for Cloud Apps is a robust cloud security solution that helps strike a balance between facilitating access and safeguarding crucial data in today's dynamic work settings.
Microsoft Defender for Cloud Apps isn't relevant in today's dynamic work settings.
Microsoft Defender for Cloud Apps is only relevant for large organizations with complex cloud environments.
As a security administrator, what is the prerequisite to set up Microsoft Defender for Cloud Apps?
A license for Office 365 productivity suite
A license for every user protected by Microsoft Defender for Cloud Apps
A license for every user in the organization
Fabrikam experienced an application compatibility issue with its oldest legacy application. Unfortunately, all of its mitigation efforts have failed. What final mitigation method should Fabrikam implement so that it can continue to run this app?
Run the app in compatibility mode
Run the app in a virtualized environment
Modify the security configuration
A team needs to establish a multi-session Windows 11 environment that offers a comprehensive Windows experience with scalability. They also need to deploy Microsoft 365 Apps for enterprise and optimize them for multi-user virtual scenarios. Which service should they use?
Azure Virtual Desktop
Azure Active Directory
Azure DevOps
Contoso is interested in deploying Windows as virtual sessions. The company has 150 users, and it wants a solution that provides ready-to-use Cloud PCs with simple management options. It doesn't want any licensing prerequisites or any dependencies on Active Directory. Given these requirements, which of the following solutions should Contoso use?
Window
Windows 365 Enterprise
Azure Virtual Desktop
Windows 365 Business
Which feature of the Microsoft Intune Suite allows secure access to on-premises resources from mobile devices without requiring full device enrollment?
Microsoft Defender for Endpoint
Endpoint Privilege Management
Microsoft Tunnel
What is a primary benefit of using app protection policies in a BYOD scenario?
Full device management is required
Corporate data within apps is protected and isolated from personal data
Apps are automatically updated without user consent
