B.4 Microsoft MD-102 Certification Practice Exam
(60 Questions and Answers)
You have configured a Windows server in your network to provide activation for your
Windows workstations using the Key Management Service (KMS).
Which of the following are true concerning activation in this network? (Select two.) - -- By
default, the Windows client systems will attempt to renew their activation status every
seven days.
- KMS activations are valid for 180 days.
-You have created a custom Storage Limits device profile for the laptops on the
manufacturing floor of your company.
You want to make sure that the profile applies to those laptops and all users on those
laptops.
Which of the following should you do to meet your requirements? - -Assign the profile to a
device group.
-You're a system administrator for an international trading company that uses Azure
Active Directory (AD) and Microsoft Intune to manage mobile devices. All company-owned
mobile devices are registered in Azure AD and enrolled in Microsoft Intune.
You've created the following dynamic user groups to manage access to company
resources:
- Managers: jobTitle = "Manager"
- Consultants: jobTitle = "Customer Consultant"
...
You've created your first device compliance policy that does the following:
- Marks a device enrolled in Intune as Not Compliant if BitLocker isn't installed and running
on a managed Windows 11 device.
...
SOLUTION: You check the OfficeAdmin group and notice that the office administrator's user
account isn't listed in the group. You add the office administrator's user account to the
OfficeAdmin group. - -No
-A user contacts you to let you know their Intune-enrolled device has been remotely
locked. What would have caused this? - -The user's device is non-compliant and was
remotely locked.
, -Which of the following are only available in Windows 10 or higher as default Intune
device configuration profiles? (Select two.) - -- Delivery optimization
- Edition upgrade
-You're the systems administrator for a fashion design company that uses Azure Active
Directory (AD) and Microsoft Intune to manage their mobile devices. All company-owned
mobile devices are registered in Azure AD and enrolled in Microsoft Intune.
You have 100 company-owned Windows 11 devices that you need to configure the
following for:
- Apps from the Microsoft store must be blocked from auto-updating.
- Non-Microsoft Store Apps must be blocked from being installed.
- Employees must be able to use all apps that were pre-installed on the device.
- Users must be prevented from changing the installation options that are typically
reserved for system administrators.
- Users must be prevented from installing apps from the internet.
You've created a device restrictions configuration profile and configured the App Store
settings as illustrated below. - -No
-You're the systems administrator for an international trading company that uses Azure
Active Directory (AD) and Microsoft Intune to manage their mobile devices. All company-
owned mobile devices are registered in Azure AD and enrolled in Microsoft Intune.
You've created the following dynamic user groups to manage access to company resources:
- Managers: jobTitle = "Manager"
- Consultants: jobTitle = "Customer Consultant"
...
You've created a conditional access policy that:
- Includes the SalesReps and Consultants user groups.
- Excludes the Managers user group.
...
SOLUTION: You check the sales rep's user account and notice that her job title is still set to
"Manager." You change the job title to "Sales Representative." - -No
-Which of the following are tasks you can perform with the Intune Endpoint Manager?
(Select two.) - -- Duplicate an endpoint security policy.
- Resolve non-adherence conflicts.
(60 Questions and Answers)
You have configured a Windows server in your network to provide activation for your
Windows workstations using the Key Management Service (KMS).
Which of the following are true concerning activation in this network? (Select two.) - -- By
default, the Windows client systems will attempt to renew their activation status every
seven days.
- KMS activations are valid for 180 days.
-You have created a custom Storage Limits device profile for the laptops on the
manufacturing floor of your company.
You want to make sure that the profile applies to those laptops and all users on those
laptops.
Which of the following should you do to meet your requirements? - -Assign the profile to a
device group.
-You're a system administrator for an international trading company that uses Azure
Active Directory (AD) and Microsoft Intune to manage mobile devices. All company-owned
mobile devices are registered in Azure AD and enrolled in Microsoft Intune.
You've created the following dynamic user groups to manage access to company
resources:
- Managers: jobTitle = "Manager"
- Consultants: jobTitle = "Customer Consultant"
...
You've created your first device compliance policy that does the following:
- Marks a device enrolled in Intune as Not Compliant if BitLocker isn't installed and running
on a managed Windows 11 device.
...
SOLUTION: You check the OfficeAdmin group and notice that the office administrator's user
account isn't listed in the group. You add the office administrator's user account to the
OfficeAdmin group. - -No
-A user contacts you to let you know their Intune-enrolled device has been remotely
locked. What would have caused this? - -The user's device is non-compliant and was
remotely locked.
, -Which of the following are only available in Windows 10 or higher as default Intune
device configuration profiles? (Select two.) - -- Delivery optimization
- Edition upgrade
-You're the systems administrator for a fashion design company that uses Azure Active
Directory (AD) and Microsoft Intune to manage their mobile devices. All company-owned
mobile devices are registered in Azure AD and enrolled in Microsoft Intune.
You have 100 company-owned Windows 11 devices that you need to configure the
following for:
- Apps from the Microsoft store must be blocked from auto-updating.
- Non-Microsoft Store Apps must be blocked from being installed.
- Employees must be able to use all apps that were pre-installed on the device.
- Users must be prevented from changing the installation options that are typically
reserved for system administrators.
- Users must be prevented from installing apps from the internet.
You've created a device restrictions configuration profile and configured the App Store
settings as illustrated below. - -No
-You're the systems administrator for an international trading company that uses Azure
Active Directory (AD) and Microsoft Intune to manage their mobile devices. All company-
owned mobile devices are registered in Azure AD and enrolled in Microsoft Intune.
You've created the following dynamic user groups to manage access to company resources:
- Managers: jobTitle = "Manager"
- Consultants: jobTitle = "Customer Consultant"
...
You've created a conditional access policy that:
- Includes the SalesReps and Consultants user groups.
- Excludes the Managers user group.
...
SOLUTION: You check the sales rep's user account and notice that her job title is still set to
"Manager." You change the job title to "Sales Representative." - -No
-Which of the following are tasks you can perform with the Intune Endpoint Manager?
(Select two.) - -- Duplicate an endpoint security policy.
- Resolve non-adherence conflicts.