wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Post Assessment Intune

Total questions: 38

Worksheet time: 19mins

Name
Class
Date
1.

Which feature of MAM protects corporate data within apps on personal devices?

a)

Conditional Access

b)

App Protection Policies

c)

Device Configuration Profiles

d)

Compliance Policies

2.

You need to prevent data from being copied from a managed app to a non-managed app. Which MAM setting should you configure?

a)

Data Loss Prevention

b)

Access Control Policies

c)

App Restriction Policies

d)

Data Encryption

3.

Which tool in Intune can you use to deploy a Microsoft Store application to Windows devices?

a)

Company Portal

b)

Configuration Profiles

c)

Microsoft Endpoint Manager Admin Center

d)

Azure AD Application Proxy

4.

To ensure users always run the latest version of an application, what deployment option should you choose?

a)

Required Install

b)

Available for Install

c)

Uninstall Previous Version

d)

Automatic Updates

5.

Which Intune role is required to administer applications?

a)

Application Manager

b)

Policy Administrator

c)

App Protection Admin

d)

Global Admin

6.

What is the primary tool for monitoring application deployment in Intune?

a)

Deployment Status Blade

b)

Device Compliance Reports

c)

App Install Logs

d)

Endpoint Analytics

7.

Which Azure AD feature detects and mitigates identity-based threats?

a)

Identity Protection

b)

Conditional Access

c)

MFA Registration Policy

d)

Privileged Identity Management

8.

What is the key benefit of using Conditional Access in Azure AD?

a)

Automatically blocks all users from signing in

b)

Allows access based on user and device conditions

c)

Replaces the need for MFA

d)

Automatically disables inactive accounts

9.

Which feature allows external users to securely access organizational resources in Azure AD?

a)

Guest Access

b)

Privileged Identity Management

c)

Role-Based Access Control

d)

Azure AD Join

10.

What is the purpose of configuring a Terms of Use policy in Azure AD?

a)

To enforce device compliance

b)

To inform users of organizational policies before granting access

c)

To restrict admin access

d)

To enable multi-factor authentication

11.

What is the primary function of device compliance policies in Intune?

a)

To enforce app installation

b)

To validate device health and enforce conditions

c)

To restrict network access

d)

To enable password policies

12.

Which report in Intune can help you monitor compliance policy status?

a)

Device Compliance Overview

b)

Endpoint Analytics

c)

App Deployment Status

d)

Device Enrollment Report

13.

Which reporting feature in Intune provides details about failed app installations?

a)

App Deployment Reports

b)

Device Status Logs

c)

Endpoint Analytics

d)

Compliance Reports

14.

How can you export Intune reports for external analysis?

a)

Use Microsoft Graph API

b)

Download directly from the portal

c)

Automate using PowerShell

d)

All of the above

15.

Which feature in Intune can encrypt data on Windows 10 devices?

a)

BitLocker Profile

b)

App Protection Policies

c)

Windows Information Protection

d)

Device Restriction Profile

16.

To ensure corporate data is not saved to personal locations, which Intune feature should be configured?

a)

App Protection Policies

b)

Device Compliance Policies

c)

Conditional Access Policies

d)

Data Loss Prevention

17.

Which feature of Microsoft Defender for Endpoint provides attack surface reduction?

a)

Vulnerability Management

b)

Advanced Hunting

c)

Threat Analytics

d)

Exploit Guard

18.

How can you monitor Microsoft Defender alerts across multiple endpoints?

a)

Security Center Dashboard

b)

Intune Device Blade

c)

Azure Monitor Logs

d)

Compliance Dashboard

19.

What is the main purpose of Windows Update for Business?

a)

Manage updates through Microsoft Endpoint Configuration Manager

b)

Allow end-users to manually update devices

c)

Control and automate the update process for enterprise devices

d)

Force updates on all devices immediately

20.

Which feature in Windows Update for Business enables phased deployment?

a)

Deployment Rings

b)

Update Channels

c)

Device Groups

d)

Policy Profiles

21.

What is the purpose of Desktop Analytics?

a)

To monitor user activity on desktops

b)

To provide insights for managing Windows updates and deployments

c)

To configure security policies on desktops

d)

To deploy applications to devices

22.

Which key component is required to use Desktop Analytics?

a)

Azure Monitor Integration

b)

Configuration Manager

c)

Intune MDM

d)

Microsoft Defender

23.

Your organization uses Windows Autopilot for setting up new devices. Which type of deployment is best suited for devices that need to join both Azure AD and an on-premises domain?

a)

Self-Deploying Mode

b)

Hybrid Azure AD Join

c)

User-Driven Mode

d)

Reset Deployment

24.

Which component is required for Windows Autopilot to reset a device remotely?

a)

Intune Management Extension

b)

Autopilot Deployment Service

c)

Azure AD Device ID

d)

Windows Recovery Environment

25.

What is a key advantage of using an enterprise desktop over standalone devices?

a)

User-specific customization

b)

Simplified device management

c)

Unrestricted administrative privileges

d)

Reduced hardware costs

26.

Which policy should you configure for securing enterprise desktops against data theft?

a)

User Access Policy

b)

BitLocker Encryption Policy

c)

Internet Usage Policy

d)

Device Enrollment Policy

27.

Which Azure AD licensing plan includes features like Identity Protection and Conditional Access?

a)

Azure AD Free

b)

Azure AD Premium P1

c)

Azure AD Premium P2

d)

Office 365 Plan E3

28.

Which tool provides a graphical representation of user sign-ins in Azure AD?

a)

Log Analytics

b)

Sign-in Logs

c)

Identity Protection Dashboard

d)

Azure Monitor

29.

A user in your organization has forgotten their password. How can you enable self-service password reset?

a)

Enable SSPR in Azure AD and configure authentication methods

b)

Configure a Conditional Access Policy

c)

Deploy Active Directory Federation Services

d)

Add the user to the Global Admin role

30.

What is the purpose of dynamic groups in Azure AD?

a)

To assign roles to specific users

b)

To manage memberships based on rules

c)

To create administrative units

d)

To enforce Conditional Access policies

31.

Which feature in Azure AD allows seamless sign-in for devices that are not domain-joined?

a)

Password Hash Sync

b)

Azure AD Join

c)

Device Registration

d)

Federation Services

32.

What is a prerequisite for enabling Windows Hello for Business?

a)

Active Directory Certificate Services

b)

A device joined to Azure AD

c)

Group Policy configuration

d)

Intune enrollment

33.

What is the main advantage of using Configuration Manager for device enrollment?

a)

Cloud-based management

b)

Offline enrollment capabilities

c)

Support for hybrid deployments

d)

Self-service options

34.

Which client installation method is recommended for large-scale deployment using Configuration Manager?

a)

Manual Installation

b)

Software Push Installation

c)

Group Policy Installation

d)

Automatic Site-wide Installation

35.

Which enrollment method is used for corporate-owned devices shared among multiple users?

a)

BYOD Enrollment

b)

Device Enrollment Manager (DEM)

c)

Azure AD Join

d)

Co-management

36.

How can you ensure only compliant devices are enrolled in Intune?

a)

Enable Device Compliance Policies

b)

Create Enrollment Restrictions

c)

Configure Conditional Access

d)

All of the above

37.

Which device profile type in Intune is used to enforce password policies?

a)

Device Compliance Policy

b)

Endpoint Protection Profile

c)

Device Configuration Profile

d)

Custom Profile

38.

What is required to configure a custom policy in Intune?

a)

OMA-URI Settings

b)

Windows Group Policy Editor

c)

Azure CLI

d)

PowerShell Scripts