NEW
Font size
WorksheetsPost Assessment Intune
Total questions: 38
Worksheet time: 19mins
Which feature of MAM protects corporate data within apps on personal devices?
Conditional Access
App Protection Policies
Device Configuration Profiles
Compliance Policies
You need to prevent data from being copied from a managed app to a non-managed app. Which MAM setting should you configure?
Data Loss Prevention
Access Control Policies
App Restriction Policies
Data Encryption
Which tool in Intune can you use to deploy a Microsoft Store application to Windows devices?
Company Portal
Configuration Profiles
Microsoft Endpoint Manager Admin Center
Azure AD Application Proxy
To ensure users always run the latest version of an application, what deployment option should you choose?
Required Install
Available for Install
Uninstall Previous Version
Automatic Updates
Which Intune role is required to administer applications?
Application Manager
Policy Administrator
App Protection Admin
Global Admin
What is the primary tool for monitoring application deployment in Intune?
Deployment Status Blade
Device Compliance Reports
App Install Logs
Endpoint Analytics
Which Azure AD feature detects and mitigates identity-based threats?
Identity Protection
Conditional Access
MFA Registration Policy
Privileged Identity Management
What is the key benefit of using Conditional Access in Azure AD?
Automatically blocks all users from signing in
Allows access based on user and device conditions
Replaces the need for MFA
Automatically disables inactive accounts
Which feature allows external users to securely access organizational resources in Azure AD?
Guest Access
Privileged Identity Management
Role-Based Access Control
Azure AD Join
What is the purpose of configuring a Terms of Use policy in Azure AD?
To enforce device compliance
To inform users of organizational policies before granting access
To restrict admin access
To enable multi-factor authentication
What is the primary function of device compliance policies in Intune?
To enforce app installation
To validate device health and enforce conditions
To restrict network access
To enable password policies
Which report in Intune can help you monitor compliance policy status?
Device Compliance Overview
Endpoint Analytics
App Deployment Status
Device Enrollment Report
Which reporting feature in Intune provides details about failed app installations?
App Deployment Reports
Device Status Logs
Endpoint Analytics
Compliance Reports
How can you export Intune reports for external analysis?
Use Microsoft Graph API
Download directly from the portal
Automate using PowerShell
All of the above
Which feature in Intune can encrypt data on Windows 10 devices?
BitLocker Profile
App Protection Policies
Windows Information Protection
Device Restriction Profile
To ensure corporate data is not saved to personal locations, which Intune feature should be configured?
App Protection Policies
Device Compliance Policies
Conditional Access Policies
Data Loss Prevention
Which feature of Microsoft Defender for Endpoint provides attack surface reduction?
Vulnerability Management
Advanced Hunting
Threat Analytics
Exploit Guard
How can you monitor Microsoft Defender alerts across multiple endpoints?
Security Center Dashboard
Intune Device Blade
Azure Monitor Logs
Compliance Dashboard
What is the main purpose of Windows Update for Business?
Manage updates through Microsoft Endpoint Configuration Manager
Allow end-users to manually update devices
Control and automate the update process for enterprise devices
Force updates on all devices immediately
Which feature in Windows Update for Business enables phased deployment?
Deployment Rings
Update Channels
Device Groups
Policy Profiles
What is the purpose of Desktop Analytics?
To monitor user activity on desktops
To provide insights for managing Windows updates and deployments
To configure security policies on desktops
To deploy applications to devices
Which key component is required to use Desktop Analytics?
Azure Monitor Integration
Configuration Manager
Intune MDM
Microsoft Defender
Your organization uses Windows Autopilot for setting up new devices. Which type of deployment is best suited for devices that need to join both Azure AD and an on-premises domain?
Self-Deploying Mode
Hybrid Azure AD Join
User-Driven Mode
Reset Deployment
Which component is required for Windows Autopilot to reset a device remotely?
Intune Management Extension
Autopilot Deployment Service
Azure AD Device ID
Windows Recovery Environment
What is a key advantage of using an enterprise desktop over standalone devices?
User-specific customization
Simplified device management
Unrestricted administrative privileges
Reduced hardware costs
Which policy should you configure for securing enterprise desktops against data theft?
User Access Policy
BitLocker Encryption Policy
Internet Usage Policy
Device Enrollment Policy
Which Azure AD licensing plan includes features like Identity Protection and Conditional Access?
Azure AD Free
Azure AD Premium P1
Azure AD Premium P2
Office 365 Plan E3
Which tool provides a graphical representation of user sign-ins in Azure AD?
Log Analytics
Sign-in Logs
Identity Protection Dashboard
Azure Monitor
A user in your organization has forgotten their password. How can you enable self-service password reset?
Enable SSPR in Azure AD and configure authentication methods
Configure a Conditional Access Policy
Deploy Active Directory Federation Services
Add the user to the Global Admin role
What is the purpose of dynamic groups in Azure AD?
To assign roles to specific users
To manage memberships based on rules
To create administrative units
To enforce Conditional Access policies
Which feature in Azure AD allows seamless sign-in for devices that are not domain-joined?
Password Hash Sync
Azure AD Join
Device Registration
Federation Services
What is a prerequisite for enabling Windows Hello for Business?
Active Directory Certificate Services
A device joined to Azure AD
Group Policy configuration
Intune enrollment
What is the main advantage of using Configuration Manager for device enrollment?
Cloud-based management
Offline enrollment capabilities
Support for hybrid deployments
Self-service options
Which client installation method is recommended for large-scale deployment using Configuration Manager?
Manual Installation
Software Push Installation
Group Policy Installation
Automatic Site-wide Installation
Which enrollment method is used for corporate-owned devices shared among multiple users?
BYOD Enrollment
Device Enrollment Manager (DEM)
Azure AD Join
Co-management
How can you ensure only compliant devices are enrolled in Intune?
Enable Device Compliance Policies
Create Enrollment Restrictions
Configure Conditional Access
All of the above
Which device profile type in Intune is used to enforce password policies?
Device Compliance Policy
Endpoint Protection Profile
Device Configuration Profile
Custom Profile
What is required to configure a custom policy in Intune?
OMA-URI Settings
Windows Group Policy Editor
Azure CLI
PowerShell Scripts
