wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

MD-102-Final_day-AK

Total questions: 36

Worksheet time: 22mins

Name
Class
Date
1.

What is the purpose of using the Microsoft Graph PowerShell SDK in managing Microsoft Entra objects?

a)

To provide a graphical user interface for managing Microsoft Entra objects

b)


Enables the automation and validation of the creation and teardown of environments to help deliver secure and stable application hosting platforms

c)

To enhance the security of Microsoft Entra by enforcing multifactor authentication

2.

What is the primary purpose of creating Guest user accounts in Microsoft Entra ID?

a)

To manage internal employee access to Entra resource

b)

To provide temporary administrative access to Entra services

c)

To assign permissions to users from another Entra tenant or a Microsoft account

3.

What is a benefit of using Microsoft Entra ID versus Active Directory (AD)?

a)

Microsoft Entra ID uses Kerberos authentication for access across applications

b)


Microsoft Entra ID is a cloud-based identity solution

c)

Microsoft Entra ID can query using Lightweight Directory Access Protocol (LDAP)

4.

In addition to the free features of Microsoft Entra ID, what is the minimum Premium version licensing needed to implement risk-based sign-ins?

a)

Office 365

b)


Microsoft Entra ID P2

c)


Microsoft Entra ID P1

5.

What's the minimum RAM requirements to install or upgrade to Windows 11?

a)

1 GB for 32-bit or 2 GB for 64-bit

b)


4 GB

c)


8 GB

6.

Fabrikam is a large Microsoft Volume License customer with a complex IT infrastructure. From a device management perspective, its IT department wants to choose the pace at which it adopts new technology for user devices. It also requires a broad range of options for operating system deployment and device and app management. Which of the following Windows 10/11 editions allows Fabrikam to meet these IT requirements?

a)

Pro edition

b)

Pro for Workstations

c)

Enterprise edition

7.

Your organization is in the process of migrating users to Microsoft 365 E3. You have a mix of Windows 10 editions deployed. You're required to provide conditional access and SSO from anywhere for the Microsoft 365 E3 users using Domain Join with Microsoft Entra ID. Which of the following Windows versions will support this requirement?

a)

Windows 10 Home, Pro, and Enterprise

b)

Windows 10 Pro and Enterprise

c)

Windows 10 Enterprise only

8.

You're the IT Support professional for Contoso, a large enterprise organization that's a Microsoft Volume License customer. Contoso needs to deploy a set of Windows 11 computers for an isolated office that won't be managed for at least six months. Given Contoso's requirements, which of the following Windows 11 editions would be the most suitable for deployment?

a)


Pro edition

b)

Home edition

c)

Enterprise edition

9.

What are the different phases of the enterprise desktop life cycle?

a)

Planning, Purchasing, Deployment, Operations, Support, Upgrade and Retire

b)

Planning, Building, Deployment, Operations, Support, Selling, and Retire

c)

Planning, Purchasing, Deployment, Operations, Selling, and Retirement

10.

Contoso is starting to allow employees to enroll their personal mobile devices on the network. When employees leave the company, IT will disconnect the device from the network and wipe selective information related to company access. What Mobile Device Manager (MDM) enables IT to selectively remove applications and application data without affecting personal data?

a)

Microsoft Intune

b)

Endpoint Analytics

c)


Configuration Manager

11.

Which Configuration Manager console feature gives you the ability to see if a device is connected to its assigned management point?

a)

Client Online Status

b)

Client Activity

c)

Client Check

12.

To manage a Windows computer using Configuration Manager, there are multiple ways to deploy the client. What are the four most common methods of deployment?

a)

Client push, Manual deployment, Configuration Manager application package, Microsoft Intune

b)

Windows update, Manual deployment, OS deployment, Microsoft Intune

c)

Client push, Manual deployment, OS Deployment, Microsoft Intune

13.

What is a benefit for using Microsoft Entra ID in an organization that already has Active Directory Domain Services implemented?

a)

To remove the need for domain controllers

b)

To enable iOS and Android devices to be managed using Group Policy

c)


To offer users the ability to use their personal devices to access organizational resources

14.

What is a benefit from using Microsoft Entra hybrid join?


a)

Organizations can apply OS configurations to employee-owned devices.

b)


To allow continued use of Group Policy to manage domain-joined devices

c)

To automatically configure a broad range of older versions of Windows devices

15.

What are the four phases of the mobile device management lifecycle?

a)

Enroll, Configure, Protect, Retire

b)

Enroll, Configure, Protect, Reset

c)


Enroll, Compliance, Protect, Retire

16.

A retailer wants to provide 25 tablets to floor staff to capture orders and complete card transactions. The Intune admin creates a new Device Enrollment Manager (DEM) account for the restaurant supervisor. What functionality does the DEM user account have?

a)

Enroll in Intune, access email, and configure access to company data

b)

Enroll in Intune, unenroll in Intune, get company applications, and configures access to company data by deploying role-specific applications

c)

Enroll in Intune, unenroll in Intune, get company applications, and configures access to company data by deploying role-specific applications

17.

As an IT administrator, you need to create a device profile for Windows devices that will enable the automation and validation of the creation and teardown of environments to help deliver secure and stable application hosting platforms. Which type of device profile should you create?

a)

Device Security Profile

b)

Device Compliance Profile

c)

Device Configuration Profile

18.

Your organization wants to prevent iOS device users from using the device camera. Which type of profile should you create in Intune?

a)

VPN profile

b)

Wi-Fi profile

c)


Device restrictions profile

19.

Why would you create a custom device profile in Intune?

a)

To add settings that aren't available in Intune or to use settings available in other device profiles

b)

To use only built-in settings in Intune

c)

To restrict access to device settings for all users

20.

Intune policies fall into multiple categories. Which category is commonly used to manage security settings and features on devices, including defining access to company resources?

a)


Conditional access policies

b)

Configuration policies

c)

Device compliance policies

21.

As the Desktop Administrator for Contoso, Holly Dickson is using Intune to help monitor and manage the company's device configuration profiles. One of the company's devices has been experiencing issues that Holly feels is related to a configuration policy setting that's applied to the device. In the Microsoft Intune admin center, Holly navigated to a view of the company's devices, selected the device in question, displayed the configuration policies that apply to the device, and then selected the policy that she feels may be the problem. By doing so, Holly can see any setting in the policy that has a "Conflict" state. What else is displayed regarding the conflicted setting that can help Holly troubleshoot this issue?

a)


All the conflicted devices

b)

All the profiles that have any type of conflict

c)


All the profiles that have the conflicted setting

22.

Contoso's IT department is wanting to assign an app to a device. What is a requirement they must meet before the app can be assigned to a device?

a)

The device must first be enrolled in Intune

b)

The app must be added to Google Play Store or Apple App Store

c)

Microsoft Entra groups must be created for the device

23.

The Contoso IT department purchased licenses for an app built by another company. Contoso is deploying the application internally. They don't have access to the source code. Which tool would be best to use to support application protection policies?

a)

Intune App Wrapping tool

b)


Intune App SDK

c)

Windows Defender SmartScreen

24.

An IT admin wants to manage the client apps that their company's workforce uses. They have identified the apps they want to manage and assign, and added them to Intune. What is the next step in the Microsoft Intune app lifecycle?

a)

Retire the apps from service.

b)


Deploy the apps to users and devices.

c)

Protect the data in the apps.

25.

As the Desktop Administrator for World Wide Importers, Alan Deyoung wants to create Conditional Access policies to provide granular access control over organizational data while allowing users to work from essentially any device and location. In which of the following scenarios will Conditional Access be especially beneficial for World Wide Importers?

a)

Enabling employees to use a corporate application on their personal device

b)

Enabling users to access the corporate e-mail from a public kiosk

c)


Automatically updating devices to the required minimum OS

26.

What are the three deployment models for Windows Hello for Business?

a)

Cloud Only, On-premises, or Hybrid

b)

Cloud Only, Manual, Hybrid

c)


Cloud Only, Manual, On-premises

27.

Contoso's IT department has implemented self-service password reset functionality for its users. What alternative authentication methods are supported on Microsoft Entra ID?

a)

Biometric thumb print, Mobile phone, Alternative email address, Security questions

b)

Office phone, Mobile phone, Text message, Security questions

c)

Office phone, Mobile Phone, Alternative email address, Security questions

28.

Northwind Traders wants to use Microsoft Defender for Endpoint to help prevent, detect, investigate, and respond to advanced threats against its corporate network. What feature of Microsoft Defender for Endpoint will help Northwind Traders to assess the security posture of the organization, see machines that require attention, as well as recommendations for actions to further reduce the attack surface within the company?

a)

Endpoint detection and response capabilities

b)

The Secure score dashboard

c)


Auto investigation and remediation

29.

Contoso has implemented Microsoft Defender Antivirus on all company devices to help prevent spyware and other unwanted software from running on any of its computers. As a best practice, Contoso schedules a daily Quick scan on each device. If Microsoft Defender Antivirus identifies a potentially dangerous file during a scan, what action does it take?

a)

Flags it as being potentially infected

b)


Removes the file

c)

Moves the file to a quarantine area

30.

You're an IT team member responsible for ensuring the security of your organization's cloud applications and services. Your team is planning to implement Microsoft Defender for Cloud Apps. What is the relevance of this solution in today's dynamic work settings?

a)

Microsoft Defender for Cloud Apps is a robust cloud security solution that helps strike a balance between facilitating access and safeguarding crucial data in today's dynamic work settings.

b)

Microsoft Defender for Cloud Apps isn't relevant in today's dynamic work settings.

c)

Microsoft Defender for Cloud Apps is only relevant for large organizations with complex cloud environments.

31.

As a security administrator, what is the prerequisite to set up Microsoft Defender for Cloud Apps?

a)

A license for Office 365 productivity suite

b)

A license for every user protected by Microsoft Defender for Cloud Apps

c)

A license for every user in the organization

32.

Fabrikam experienced an application compatibility issue with its oldest legacy application. Unfortunately, all of its mitigation efforts have failed. What final mitigation method should Fabrikam implement so that it can continue to run this app?

a)

Run the app in compatibility mode

b)

Run the app in a virtualized environment

c)

Modify the security configuration

33.

A team needs to establish a multi-session Windows 11 environment that offers a comprehensive Windows experience with scalability. They also need to deploy Microsoft 365 Apps for enterprise and optimize them for multi-user virtual scenarios. Which service should they use?

a)

Azure Virtual Desktop

b)

Azure Active Directory

c)


Azure DevOps

34.

Contoso is interested in deploying Windows as virtual sessions. The company has 150 users, and it wants a solution that provides ready-to-use Cloud PCs with simple management options. It doesn't want any licensing prerequisites or any dependencies on Active Directory. Given these requirements, which of the following solutions should Contoso use?

Window

a)

Windows 365 Enterprise

b)

Azure Virtual Desktop

c)


Windows 365 Business

35.

Which feature of the Microsoft Intune Suite allows secure access to on-premises resources from mobile devices without requiring full device enrollment?

a)

Microsoft Defender for Endpoint

b)

Endpoint Privilege Management

c)


Microsoft Tunnel

36.

What is a primary benefit of using app protection policies in a BYOD scenario?

a)


Full device management is required

b)

Corporate data within apps is protected and isolated from personal data

c)


Apps are automatically updated without user consent