Free Practice Test

Free MD 102 Practice Questions – 2026 Updated

MD 102 - Endpoint Administrator Associat…

View Mode
Q: 1

HOTSPOT - You have a Microsoft Entra tenant that contains the groups shown in the following table. MD 102 - Endpoint Administrator Associate question The tenant contains the devices shown in the following table. MD 102 - Endpoint Administrator Associate question The devices have the enrollment restrictions shown in the following table. MD 102 - Endpoint Administrator Associate question For each of the following statements select yes if the statement is true. Otherwise, select No. MD 102 - Endpoint Administrator Associate question

Q: 2

HOTSPOT - Your company has computers that run Windows 10 and are Microsoft Entra joined. The company purchases an Azure subscription. You need to collect Windows events from the Windows 10 computers in Azure. The solution must enable you to create alerts based on the collected events. What should you create in Azure and what should you configure on the computers? To answer, select the appropriate options in the answer area. MD 102 - Endpoint Administrator Associate question

Q: 3

HOTSPOT - You have a Microsoft 365 subscription that contains the devices shown in the following table. MD 102 - Endpoint Administrator Associate question You need to use the remote actions shown in the following table. MD 102 - Endpoint Administrator Associate question For each of the following statements, select Yes if the statement is true. Otherwise select No. MD 102 - Endpoint Administrator Associate question

Q: 4

HOTSPOT - You have a Microsoft 365 E5 subscription. You plan to create a Conditional Access policy named Policy1. You need to ensure that only Passwordless MFA authentication methods are used when administrators attempt to access the Azure portal, Azure PowerShell, or Azure Command- Line Interface (CLI). How should you configure Policy1? To answer, select the appropriate options in the answer area. MD 102 - Endpoint Administrator Associate question

Q: 5

HOTSPOT - You have a Microsoft Entra tenant that contains the users shown in the following table. MD 102 - Endpoint Administrator Associate question When you sign in to the tenant, the available verification methods are shown in the following exhibit. MD 102 - Endpoint Administrator Associate question Which users will be prompted for the verification code method, and which users will be prompted for the text method? To answer, select the appropriate options in the answer area. MD 102 - Endpoint Administrator Associate question

Q: 6

HOTSPOT - You have a Microsoft 365 E5 subscription that uses Microsoft Intune Suite. You need to recommend a solution that meets the following requirements: • Administrators must use a secure connection over a shared screen session to perform remote tasks on a user’ s device. • Administrators must have elevated access to perform remote tasks on a user ’s device. • The solution must follow the principle of least privilege. What should you include in the recommendation for each requirement? To answer, select the appropriate options in the answer area. MD 102 - Endpoint Administrator Associate question

Q: 7

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the devices shown in the following table. MD 102 - Endpoint Administrator Associate question The subscription contains the dynamic device groups shown in the following table. MD 102 - Endpoint Administrator Associate question For each of the following statements, select Yes if the statement is true. Otherwise, select No. MD 102 - Endpoint Administrator Associate question

Q: 8

HOTSPOT - You use the Microsoft Deployment Toolkit (MDT) to deploy Windows 11. You need to modify the deployment share to meet the following requirements: • Ensure that the user who performs the installation is prompted to set the local Administrator password • Define a rule for how to name computers during the deployment. The solution must NOT replace the existing WinPE image. Which file should you modify for each requirement? To answer, select the appropriate options in the answer area, MD 102 - Endpoint Administrator Associate question

Q: 9

HOTSPOT - You have a Microsoft 365 subscription and use the Microsoft Intune Suite. You have the devices shown in the following table. MD 102 - Endpoint Administrator Associate question You plan to implement Microsoft Tunnel for Mobile Application Management (MAM). Which types of tunnels are supported by the devices? To answer, select the appropriate options in the answer area. MD 102 - Endpoint Administrator Associate question

Q: 10

HOTSPOT - You have a Microsoft 365 subscription. You use Microsoft Intune Suite to manage devices. You have the iOS app protection policy shown in the following exhibit. PDF Exam dump Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. Enlarged

Q: 11

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the devices shown in the following table. MD 102 - Endpoint Administrator Associate question You need to implement Microsoft Tunnel for Mobile Application Management (MAM) to provide the devices with access to an on-premises web app named App1. What should you do on each device? To answer, select the appropriate options in the answer area. MD 102 - Endpoint Administrator Associate question

Q: 12

HOTSPOT - Case study - Overview - ADatum Corporation is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. ADatum has a Microsoft 365 E5 subscription. Environment - Network Environment - The network contains an on-premises Active Directory domain named adatum.com. The domain contains the servers shown in the following table. MD 102 - Endpoint Administrator Associate question ADatum has a hybrid Azure AD tenant named adatum.com. Users and Groups - The adatum.com tenant contains the users shown in the following table. MD 102 - Endpoint Administrator Associate question All users are assigned a Microsoft Office 365 license and an Enterprise Mobility + Security E3 license. Enterprise State Roaming is enabled for Group1 and GroupA. Group1 and Group2 have a Membership type of Assigned. Devices - ADatum has the Windows 10 devices shown in the following table. MD 102 - Endpoint Administrator Associate question The Windows 10 devices are joined to Azure AD and enrolled in Microsoft Intune. The Windows 10 devices are configured as shown in the following table. MD 102 - Endpoint Administrator Associate question All the Azure AD joined devices have an executable file named C:\AppA.exe and a folder named D:\Folder1. Microsoft Intune Configuration - Microsoft Intune has the compliance policies shown in the following table. MD 102 - Endpoint Administrator Associate question MD 102 - Endpoint Administrator Associate question The Automatic Enrollment settings have the following configurations: • MDM user scope: GroupA • MAM user scope: GroupB You have an Endpoint protection configuration profile that has the following Controlled folder access settings: • Name: Protection1 • Folder protection: Enable • List of apps that have access to protected folders: C:\*\AppA.exe • List of additional folders that need to be protected: D:\Folder1 • Assignments: - Included groups: Group2, GroupB Windows Autopilot Configuration - ADatum has a Windows Autopilot deployment profile configured as shown in the following exhibit. MD 102 - Endpoint Administrator Associate question Currently, there are no devices deployed by using Windows Autopilot. The Intune connector for Active Directory is installed on Server1. Requirements - Planned Changes - ADatum plans to implement the following changes: Purchase a new Windows 10 device named Device6 and enroll the device in Intune • New computers will be deployed by using Windows Autopilot and will be hybrid Azure AD joined. • Deployed a network boundary configuration profile that will have the following settings: - Name: Boundary1 - Network boundary: 192.168.1.0/24 - Scope tags: Tag1 - Assignments: - Included groups: Group1, Group2 • Deploy two VPN configuration profiles named Connection1 and Connection2 that will have the following settings: - Name: Connection1 - Connection name: VPN1 - Connection type: L2TP - Assignments: - Included groups: Group1, Group2, GroupA - Excluded groups: -- - Name: Connection2 - Connection name: VPN2 - Connection type: IKEv2 - Assignments: - Included groups: GroupA - Excluded groups: GroupB Technical Requirements - ADatum must meet the following technical requirements: • Users in GroupA must be able to deploy new computers. • Administrative effort must be minimized. For each of the following statements, select Yes if the statement is true. Otherwise, select No. MD 102 - Endpoint Administrator Associate question

Q: 13

You have a Microsoft 365 subscription. You use Microsoft Intune to manage devices. You plan to deploy two apps named App1 and App2 to all Windows devices. App1 must be installed before App2. From the Intune admin center, you create and deploy two Windows app (Win32) apps. You need to ensure that App1 is installed before App2 on every device. What should you configure?

Options
Q: 14

You have 200 computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune. You need to enable self-service password reset on the sign-in screen. Which settings should you configure from the Microsoft Intune admin center?

Options
Q: 15

You plan to deploy Windows 11 Pro to 200 new computers by using the Microsoft Deployment Toolkit (MDT) and Windows Deployment Services (WDS). The company has a Volume Licensing Agreement and uses a product key to activate Windows 11. You need to ensure that the new computers will be configured to have the correct product key during the installation. What should you configure?

Options
Q: 16

You have a Microsoft 365 subscription that includes Microsoft Intune. The subscription contains Windows 11 devices enrolled in Intune. The subscription contains three groups named Departement1, Department2, and Department3. You need to deploy Microsoft 365 Apps to the Windows 11 devices. The solution must meet the following requirements: Users in Department1 and Department2 must receive the full Microsoft 365 Apps suite, including Microsoft Project and Visio. Users in Department3 must receive the full Microsoft 365 Apps suite, including Microsoft Project, but without Visio. All other users must receive the full Microsoft 365 Apps suite without Microsoft Project or Visio. What is the minimum number of deployments you should create?

Options
Q: 17

You have a Windows 10 device named Device1 that is joined to Active Directory and enrolled in Microsoft Intune. Device1 is managed by using Group Policy and Intune. You need to ensure that the Intune settings override the Group Policy settings. What should you configure?

Options
Q: 18

Your company has devices enrolled in Microsoft Intune as shown in the following table. MD 102 - Endpoint Administrator Associate question In Microsoft Intune admin center, you define the company ’s network as a location named Location1. Which devices can use network location-based compliance policies?

Options
Q: 19

You have a Microsoft 365 E5 subscription that contains 100 iOS devices enrolled in Microsoft Intune. You need to ensure that notifications of iOS updates are deferred for 30 days after the updates are released. What should you create?

Options
Q: 20

You have a Microsoft 365 subscription. The subscription contains 500 computers that run Windows 11 and are enrolled in Microsoft Intune. You need to manage the deployment of monthly security updates. The solution must meet the following requirements: Updates must be deployed to a group of test computers for quality assurance. Updates must be deployed automatically 15 days after the quality assurance testing. What should you create in the Microsoft Intune admin center?

Options
Q: 21

You have devices enrolled in Microsoft Intune as shown in the following table. MD 102 - Endpoint Administrator Associate question For which devices can you manage updates by using Intune?

Options
Q: 22

You have a Microsoft Entra tenant named contoso.com. You purchase an Android device named Device1. You need to register Device1 in contoso.com. Solution: You use Microsoft Entra Connect. Does this meet the goal?

Options
Q: 23

You have an Azure AD tenant named contoso.com. You plan to use Windows Autopilot to configure the Windows 10 devices shown in the following table. MD 102 - Endpoint Administrator Associate question Which devices can be configured by using Windows Autopilot self-deploying mode?

Options
Q: 24
Your company implements Azure AD, Microsoft 365, Microsoft Intune, and Azure Information Protection. The company's security policy states the following: Personal devices do not need to be enrolled in Intune. Users must authenticate by using a PIN before they can access corporate email data. Users can use their personal iOS and Android devices to access corporate cloud services. Users must be prevented from copying corporate email data to a cloud storage service other than Microsoft OneDrive for Business. You need to configure a solution to enforce the security policy. What should you create?
Options
Q: 25

DRAG DROP - You have an on-premises Active Directory domain that syncs to Azure AD tenant. The tenant contains computers that run Windows 10. The computers are hybrid Azure AD joined and enrolled in Microsoft Intune. The Microsoft Office settings on the computers are configured by using a Group Policy Object (GPO). You need to migrate the GPO to Intune. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. MD 102 - Endpoint Administrator Associate question

Drag & Drop
Q: 26

DRAG DROP - You have a Microsoft 365 subscription that includes Microsoft Intune. You need to implement a Microsoft Defender for Endpoint solution that meets the following requirements: Enforces compliance for Defender for Endpoint by using Conditional Access Prevents suspicious scripts from running on devices What should you configure? To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. MD 102 - Endpoint Administrator Associate question

Drag & Drop
Q: 27

DRAG DROP - You have a Microsoft Deployment Toolkit (MDT) server named MDT1. When computers start from the LiteTouchPE_x64.iso image and connect to MDT1, the welcome screen appears as shown in the following exhibit. MD 102 - Endpoint Administrator Associate question You need to prevent the welcome screen from appearing when the computers connect to MDT1. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. MD 102 - Endpoint Administrator Associate question

Drag & Drop
Q: 28

DRAG DROP - You have 100 computers that run Windows 10. You plan to deploy Windows 11 to the computers by performing a wipe and load installation. You need to recommend a method to retain the user settings and the user data. Which three actions should you recommend be performed in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. MD 102 - Endpoint Administrator Associate question

Drag & Drop
Q: 29

DRAG DROP - You have a Microsoft Intune subscription that is configured to use a PFX certificate connector to an on-premises Enterprise certification authority (CA). You need to use Intune to configure autoenrollment for Android devices by using public key pair (PKCS) certificates. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. MD 102 - Endpoint Administrator Associate question

Drag & Drop
Q: 30

DRAG DROP - Your company has a Microsoft 365 E5 tenant. All the devices of the company are enrolled in Microsoft Intune. You need to create advanced reports by using custom queries and visualizations from raw Microsoft Intune data. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. MD 102 - Endpoint Administrator Associate question

Drag & Drop
Q: 31

DRAG DROP - You have a Microsoft 365 subscription that contains 1,000 Windows 11 devices enrolled in Microsoft Intune. You plan to create and monitor the results of a compliance policy used to validate the BIOS version of the devices. Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. MD 102 - Endpoint Administrator Associate question

Drag & Drop
Q: 32

DRAG DROP - Your network contains an Active Directory domain. You install the Microsoft Deployment Toolkit (MDT) on a server. You have a custom image of Windows 11. You need to deploy the image to 100 devices by using MDT. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. MD 102 - Endpoint Administrator Associate question

Drag & Drop
Q: 33

DRAG DROP - You have 500 Windows 10 devices enrolled in Microsoft Intune. You plan to use Exploit protection in Microsoft Intune to enable the following system settings on the devices: • Data Execution Prevention (DEP) • Force randomization for images (Mandatory ASLR) You need to configure a Windows 10 device that will be used to create a template file. Which protection areas on the device should you configure in the Windows Security app before you create the template file? To answer, drag the appropriate protection areas to the correct settings. Each protection area may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. MD 102 - Endpoint Administrator Associate question

Drag & Drop
Q: 34

DRAG DROP - You have a computer that runs Windows 10 and contains two local users named User1 and User2. You need to ensure that the users can perform the following actions: User1 must be able to adjust the date and time. User2 must be able to clear Windows logs. The solution must use the principle of least privilege. To which group should you add each user? To answer, drag the appropriate groups to the correct users. Each group may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. MD 102 - Endpoint Administrator Associate question

Drag & Drop
Q: 35

DRAG DROP - You have a Microsoft 365 E5 subscription and a computer that runs Windows 11. You need to create a customized installation of Microsoft 365 Apps for enterprise. Which four actions should you perform in sequence? To answer, move the appropriate cmdlets from the list of cmdlets to the answer area and arrange them in the correct order. Enlarged

Drag & Drop
Question 1 of 35

Shopping Cart
Scroll to Top

FLASH OFFER

Days
Hours
Minutes
Seconds

avail $6 DISCOUNT on YOUR PURCHASE