View Mode
Q: 11

You have a Microsoft 365 subscription that contains the devices shown in the following table. MD 102 - Endpoint Administrator Associate question You need to ensure that only devices running trusted firmware or operating system builds can access network resources. Which compliance policy setting should you configure for each device? To answer, drag the appropriate settings to the correct devices. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. MD 102 - Endpoint Administrator Associate question

Drag & Drop
Q: 12
You have a Microsoft 365 tenant that contains the objects shown in the following table. MD 102 - Endpoint Administrator Associate question In the Microsoft Intune admin center, you are creating a Microsoft 365 Apps app named App1. To which objects can you assign App1?
Options
Q: 13

HOTSPOT - Case study - Overview - ADatum Corporation is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. ADatum has a Microsoft 365 E5 subscription. Environment - Network Environment - The network contains an on-premises Active Directory domain named adatum.com. The domain contains the servers shown in the following table. MD 102 - Endpoint Administrator Associate question ADatum has a hybrid Azure AD tenant named adatum.com. Users and Groups - The adatum.com tenant contains the users shown in the following table. MD 102 - Endpoint Administrator Associate question All users are assigned a Microsoft Office 365 license and an Enterprise Mobility + Security E3 license. Enterprise State Roaming is enabled for Group1 and GroupA. Group1 and Group2 have a Membership type of Assigned. Devices - ADatum has the Windows 10 devices shown in the following table. MD 102 - Endpoint Administrator Associate question The Windows 10 devices are joined to Azure AD and enrolled in Microsoft Intune. The Windows 10 devices are configured as shown in the following table. MD 102 - Endpoint Administrator Associate question All the Azure AD joined devices have an executable file named C:\AppA.exe and a folder named D:\Folder1. Microsoft Intune Configuration - Microsoft Intune has the compliance policies shown in the following table. MD 102 - Endpoint Administrator Associate question MD 102 - Endpoint Administrator Associate question The Automatic Enrollment settings have the following configurations: • MDM user scope: GroupA • MAM user scope: GroupB You have an Endpoint protection configuration profile that has the following Controlled folder access settings: • Name: Protection1 • Folder protection: Enable • List of apps that have access to protected folders: C:\*\AppA.exe • List of additional folders that need to be protected: D:\Folder1 • Assignments: - Included groups: Group2, GroupB Windows Autopilot Configuration - ADatum has a Windows Autopilot deployment profile configured as shown in the following exhibit. MD 102 - Endpoint Administrator Associate question Currently, there are no devices deployed by using Windows Autopilot. The Intune connector for Active Directory is installed on Server1. Requirements - Planned Changes - ADatum plans to implement the following changes: • Purchase a new Windows 10 device named Device6 and enroll the device in Intune • New computers will be deployed by using Windows Autopilot and will be hybrid Azure AD joined. • Deployed a network boundary configuration profile that will have the following settings: - Name: Boundary1 - Network boundary: 192.168.1.0/24 - Scope tags: Tag1 - Assignments: - Included groups: Group1, Group2 • Deploy two VPN configuration profiles named Connection1 and Connection2 that will have the following settings: - Name: Connection1 - Connection name: VPN1 - Connection type: L2TP - Assignments: - Included groups: Group1, Group2, GroupA - Excluded groups: -- - Name: Connection2 - Connection name: VPN2 - Connection type: IKEv2 - Assignments: - Included groups: GroupA - Excluded groups: GroupB Technical Requirements - ADatum must meet the following technical requirements: • Users in GroupA must be able to deploy new computers. • Administrative effort must be minimized. You implement the planned changes for Connection1 and Connection2. How many VPN connections will there be for User1 when the user signs in to Device1 and Device2? To answer, select the appropriate options in the answer area. MD 102 - Endpoint Administrator Associate question

Your Answer
Q: 14

You have a Microsoft Entra tenant that contains a device named Device1. Device1 is Microsoft Entra joined. You need to validate the Microsoft Entra ID primary refresh token (PRT) for Device1. Which command should you run?

Options
Q: 15

Your company has an Azure AD tenant named contoso.com that contains several Windows 10 devices. When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin. You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com. Solution: From the Microsoft Entra admin center, you modify the User settings and the Device settings. Does this meet the goal?

Options
Q: 16

HOTSPOT - Case study - Overview - ADatum Corporation is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. ADatum has a Microsoft 365 E5 subscription. Environment - Network Environment - The network contains an on-premises Active Directory domain named adatum.com. The domain contains the servers shown in the following table. Enlarged ADatum has a hybrid Azure AD tenant named adatum.com. Users and Groups - The adatum.com tenant contains the users shown in the following table. All users are assigned a Microsoft Office 365 license and an Enterprise Mobility + Security E3 license. Enterprise State Roaming is enabled for Group1 and GroupA. Group1 and Group2 have a Membership type of Assigned. Devices - ADatum has the Windows 10 devices shown in the following table. The Windows 10 devices are joined to Azure AD and enrolled in Microsoft Intune. The Windows 10 devices are configured as shown in the following table. All the Azure AD joined devices have an executable file named C:\AppA.exe and a folder named D:\Folder1. Microsoft Intune Configuration - Microsoft Intune has the compliance policies shown in the following table. The Automatic Enrollment settings have the following configurations: MDM user scope: GroupA - MAM user scope: GroupB - You have an Endpoint protection configuration profile that has the following Controlled folder access settings: Name: Protection1 - Folder protection: Enable - List of apps that have access to protected folders: C:\*\AppA.exe List of additional folders that need to be protected: D:\Folder1 Assignments: Included groups: Group2, GroupB - Windows Autopilot Configuration - ADatum has a Windows Autopilot deployment profile configured as shown in the following exhibit. Currently, there are no devices deployed by using Windows Autopilot. The Intune connector for Active Directory is installed on Server1. Requirements - Planned Changes - ADatum plans to implement the following changes: Purchase a new Windows 10 device named Device6 and enroll the device in Intune New computers will be deployed by using Windows Autopilot and will be hybrid Azure AD joined. Deployed a network boundary configuration profile that will have the following settings: Name: Boundary1 - Network boundary: 192.168.1.0/24 Scope tags: Tag1 - Assignments: Included groups: Group1, Group2 - Deploy two VPN configuration profiles named Connection1 and Connection2 that will have the following settings: Name: Connection1 - Connection name: VPN1 - Connection type: L2TP - Assignments: Included groups: Group1, Group2, GroupA Excluded groups: -- Name: Connection2 - Connection name: VPN2 - Connection type: IKEv2 - Assignments: Included groups: GroupA - Excluded groups: GroupB - Technical Requirements - ADatum must meet the following technical requirements: Users in GroupA must be able to deploy new computers. Administrative effort must be minimized. For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Your Answer
Q: 17

HOTSPOT - Your network contains an Active Directory domain. The domain contains 1,000 computers that run Windows 11. You need to configure the Remote Desktop settings of all the computers. The solution must meet the following requirements: Prevent the sharing of clipboard contents. Ensure that users authenticate by using Network Level Authentication (NLA). Which two nodes of the Group Policy Management Editor should you use? To answer, select the appropriate nodes in the answer area. img0

Your Answer
Q: 18

HOTSPOT - You have a Microsoft 365 subscription that includes Microsoft Intune. From the Microsoft Intune admin center, you add the apps shown in the following table. MD 102 - Endpoint Administrator Associate question You need to configure the apps to meet the following requirements: App1 must automatically install for all users in the marketing department on any Windows 11 device enrolled in Intune. If a user receives a new device, App1 must install automatically. App2 must be available for download for any user in the HR department from a personal Android device that is not enrolled in Intune. Which assignment should you configure for each app? To answer, select the appropriate options in the answer area. MD 102 - Endpoint Administrator Associate question

Your Answer
Q: 19

HOTSPOT - You have a Microsoft 365 E5 subscription and use Microsoft Intune. You need to deploy new Android devices as shown in the following table. MD 102 - Endpoint Administrator Associate question Which enrollment profile should you use for each device? To answer, select the appropriate options in the answer area. MD 102 - Endpoint Administrator Associate question

Your Answer
Q: 20

DRAG DROP - Your company has a computer named Computer1 that runs Windows 10. Computer1 was used by a user who left the company. You plan to repurpose Computer1 and assign the computer to a new user. You need to redeploy Computer1 by using Windows Autopilot. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. MD 102 - Endpoint Administrator Associate question

Drag & Drop
Question 11 of 20 · Page 2 / 2

Premium Access Includes

  • Quiz Simulator
  • Exam Mode
  • Progress Tracking
  • Question Saving
  • Flash Cards
  • Drag & Drops
  • 3 Months Access
  • PDF Downloads
Get Premium Access
Scroll to Top

FLASH OFFER

Days
Hours
Minutes
Seconds

avail 10% DISCOUNT on YOUR PURCHASE