0% found this document useful (0 votes)
37 views17 pages

IT Mock Test Questions Practice

IT MD-102 Exam Questions with answers
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
37 views17 pages

IT Mock Test Questions Practice

IT MD-102 Exam Questions with answers
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 17

1/13/24, 10:38 PM about:blank

siddhartha karki

20 30

1. You have a Microsoft 365 E5 subscription that contains 1,000 Windows 11 devices. All the devices are enrolled
in Microsoft Intune. You plan to integrate Intune with Microsoft Defender for Endpoint. You need to establish a
service-to-service connection between Intune and Defender for Endpoint. Which settings should you configure
in the Microsoft Intune admin center?

1. Premium add-ons

2. Connectors and tokens

3. Tenant enrollment

4. Microsoft Tunnel Gateway

2. Which device configuration profile type template should you use?

1. Administrative Templates

2. Endpoint protection

3. Device restrictions

4. Custom

3. You have following types of devices enrolled in Microsoft Intune: • Windows 10 • Android • iOS For which types
of devices can you create VPN profiles in Microsoft Intune admin center?

1. Windows 10 only

2. Windows 10 and Android only

3. Windows 10 and iOS only

4. Android and iOS only

5. Windows 10, Android, and iOS

4. You have a Microsoft 365 E5 subscription that contains a user named User1 and a web app named App1.
App1 must only accept modern authentication requests. You plan to create a Conditional Access policy named
about:blank 1/17
1/13/24, 10:38 PM about:blank

CAPolicy1 that will have the following settings: Assignments - Users or workload identities: User1 Cloud apps or
actions: App1 - Access controls - Grant: Block access - You need to block only legacy authentication requests
to App1. Which condition should you add to CAPolicy1?
1. Filter for devices

2. Device platforms

3. User risk

4. Sign-in risk

5. Client apps

5. You have a Windows 10 device named Computer1 enrolled in Microsoft Intune. You need to configure
Computer1 as a public workstation that will run a single customer-facing, full-screen application. Which
configuration profile type template should you use in Microsoft Intune admin center?

1. Shared multi-user device

2. Device restrictions

3. Kiosk

4. Endpoint protection

6. You create a policy set named Set1 and add Comply1 to Set1. Which additional resources can you add to
Set1?

1. Conf1 only

2. Comply2 only

3. Comply2 and Conf1 only

4. CA1, Conf1, and Office1 only

5. Comply2, CA1, Conf1, and Office1

7. You have a Microsoft 365 E5 subscription. The subscription contains 25 computers that run Windows 11 and
are enrolled in Microsoft Intune. You need to onboard the devices to Microsoft Defender for Endpoint. What
should you create in the Microsoft Intune admin center?

1. an attack surface reduction (ASR) policy

2. a security baseline

3. an endpoint detection and response (EDR) policy

4. an account protection policy

about:blank 2/17
1/13/24, 10:38 PM about:blank

5. an antivirus policy

8. What is the maximum number of devices that User1 and User2 can enroll in Intune? To answer, select the
appropriate options in the answer area

1. User 1 can enroll a maximum of 5 devices

2. User 1 can enroll a maximum of 10 devices

3. User 1 can enroll a maximum of 15 devices

4. User 1 can enroll a maximum of 1000 devices

5. User 1 can enroll a maximum of an unlimited number of devices

6. User 2 can enroll a maximum of 5 devices

7. User 2 can enroll a maximum of 10 devices

8. User 2 can enroll a maximum of 15 devices

9. User 2 can enroll a maximum of 1000 devices

10. User 2 can enroll a maximum of an unlimited number of devices

9. To which devices do Policy1 and Policy2 apply? To answer, select the appropriate options in the answer area.
NOTE: Select any of two.

about:blank 3/17
1/13/24, 10:38 PM about:blank

1. Policy 1 : Device1 only

2. Policy 1 : Device2 only

3. Policy 1 : Device3 only

4. Policy 1 : Device4 only

5. Policy 2 : Device1 only

6. Policy 2 : Device2 only

7. Policy 2 : Device3 only

8. Policy 2 : Device4 only

10. You have an Azure AD tenant named contoso.com. You have a workgroup computer named Computer1 that
runs Windows 11. You need to add Computer1 to contoso.com. What should you use?

1. dsregcmd.exe

2. Computer Management

3. netdom.exe

4. the Settings app

11. You install a feature update on a computer that runs Windows 10. How many days do you have to roll back
the update?

1. 5

2. 10

3. 14

about:blank 4/17
1/13/24, 10:38 PM about:blank

4. 30

12. Case Study - 3 For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point. (Select any of Three).

1. Device1 is marked as compliant. - Yes

2. Device1 is marked as compliant. - No

3. Device4 is marked as compliant. - Yes

4. Device4 is marked as compliant. - No

5. Device5 is marked as compliant. - Yes

about:blank 5/17
1/13/24, 10:38 PM about:blank

6. Device5 is marked as compliant. - No

13. Which object should you create in Intune?

1. a deployment profile

2. an app protection policy

3. a device configuration profile

4. a compliance policy

14. You have a Microsoft 365 E5 subscription that contains 100 Windows 10 devices enrolled in Microsoft Intune.
You plan to use Endpoint analytics. You need to create baseline metrics. What should you do first?

1. Modify the Baseline regression threshold.

2. Onboard 10 devices to Endpoint analytics.

3. Create a Log Analytics workspace.

4. Create an Azure Monitor workbook.

15. Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains 100 client
computers that run Windows 10. Currently, your company does NOT have a deployment infrastructure. The
company purchases Windows 11 licenses through a volume licensing agreement. You need to recommend how
to upgrade the computers to Windows 11. The solution must minimize licensing costs. What should you include
in the recommendation?

1. Windows Autopilot

about:blank 6/17
1/13/24, 10:38 PM about:blank

2. Configuration Manager

3. subscription activation

4. Microsoft Deployment Toolkit (MDT)

16. What should you do from the Microsoft Intune admin center?

1. From Device compliance, configure the Compliance policy settings.

2. From Endpoint security, configure the Conditional access settings.

3. From Tenant administration, modify the Diagnostic settings.

4. From Policy1, modify the actions for noncompliance.

17. Which deployment method should you recommend for each department? To answer, select the
appropriate options in the answer area.

1. Sales Configuration Manager

2. Sales Windows Autopilot with automatic registration

3. Sales Windows Autopilot with manual registration

4. Sales Windows Autopilot with OEM registration

5. Marketing Configuration Manager

6. Marketing Windows Autopilot with automatic registration

7. Marketing Windows Autopilot with manual registration

8. Marketing Windows Autopilot with OEM registration

18. You have a Microsoft 365 subscription. You need to provide a user the ability Security defaults and create
Conditional Access policies. The solution must use the principle of least privilege. Which role should you assign
to the user?

about:blank 7/17
1/13/24, 10:38 PM about:blank

1. Global Administrator

2. Conditional Access Administrator

3. Security Administrator

4. Intune Administrator

19. In Microsoft Intune admin center, you define the company’s network as a location named Location1. Which
devices can use network location-based compliance policies?

1. Device1 only

2. Device2 only

3. Device1 and Device2 only

4. Device2 and Device3 only

5. Device1, Device2, and Device3

20. You plan to deploy Windows 11 Pro to 200 new computers by using the Microsoft Deployment Toolkit (MDT)
and Windows Deployment Services(WDS). The company has a Volume Licensing Agreement and uses a
product key to activate Windows 11. You need to ensure that the new computers will be configured to have the
correct product key during the installation. What should you configure?

1. an MDT task sequence

2. the Device settings in Azure AD

3. a WDS boot image

4. a Windows Autopilot deployment profile

21. You have an Azure AD tenant and 100 Windows 10 devices that are Azure AD joined and managed by using
Microsoft Intune. You need to configure Microsoft Defender Firewall and Microsoft Defender Antivirus on the
devices. The solution must minimize administrative effort. Which two actions should you perform? Each correct
answer presents part of the solution. NOTE: Each correct selection is worth one point.

1. To configure Microsoft Defender Antivirus, create a Group Policy Object (GPO) and configure the Windows
Defender Antivirus settings.

2. To configure Microsoft Defender Firewall, create a device configuration profile and configure the Device
restrictions settings

3. To configure Microsoft Defender Antivirus, create a device configuration profile and configure the Endpoint
protection settings.

about:blank 8/17
1/13/24, 10:38 PM about:blank

4. To configure Microsoft Defender Antivirus, create a device configuration profile and configure the Device
restrictions settings.

5. To configure Microsoft Defender Firewall, create a device configuration profile and configure the Endpoint
protection settings.

6. To configure Microsoft Defender Firewall, create a Group Policy Object (GPO) and configure Windows
Defender Firewall with Advanced Security.

22. You have a Microsoft 365 subscription that uses Microsoft Intune Suite. You use Microsoft Intune to manage
devices. Auto-enrollment in Intune is configured. You have 100 Windows 11 devices in a workgroup. You need to
connect the devices to the corporate wireless network and enroll 100 new Windows 11 devices in Intune. What
should you use?

1. a provisioning package

2. a Group Policy Object (GPO)

3. mobile device management (MDM) automatic enrollment

4. a device configuration policy

23. For each of the following statements, select Yes if the statement is true. Otherwise, select No.

1. User 1 receives Notification1 on Device1. - Yes

2. User 1 receives Notification1 on Device1. - No

3. User 2 receives Notification1 on Device2. -Yes

4. User 2 receives Notification1 on Device2. - No

5. User 1 receives Notification1 on Device3. - Yes

6. User 1 receives Notification1 on Device3. - No

24. Which devices can be changed to Windows 11 Enterprise by using subscription activation?

1. Device3 only

2. Device2 and Device3 only

about:blank 9/17
1/13/24, 10:38 PM about:blank

3. Device1 and Device2 only

4. Device1, Device2, and Device3

25. On which virtual machines can you install Windows 11?

1. VM1 only

2. VM3 only

3. VM1 and VM2 only

4. VM2 and VM3 only

5. VM1, VM2, and VM3

26. You have a Microsoft 365 E5 subscription. You need to download a report that lists all the devices that are
NOT enrolled in Microsoft Intune and are assigned an app protection policy. What should you select in the
Microsoft Intune admin center?

1. Reports, and then Device compliance

2. Apps, and then App protection policies

3. Devices, and then Monitor

4. Apps, and then Monitor

27. You have a Microsoft 365 subscription that uses Microsoft Intune Suite. You use Microsoft Intune to manage
devices. You plan to deploy two apps named App1 and App2 to all Windows devices. App1 must be installed
before App2. From the Intune admin center, you create and deploy two Windows app (Win32) apps. You need
to ensure that App1 is installed before App2 on every device. What should you configure?

1. the App1 deployment configurations

2. a dynamic device group

3. detection rule

4. the App2 deployment configurations

28. You have a Microsoft 365 E5 subscription that contains a user named User1 and uses Microsoft Intune Suite.
You use Microsoft Intune to manage devices. You have a device named Devic1 that is enrolled in Intune. You
need to ensure that User1 can use Remote Help from the Intune admin center for Device1. Which three actions
should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth
one point.

1. Deploy the Remote Help app to Device1.

about:blank 10/17
1/13/24, 10:38 PM about:blank

2. Assign the Help Desk Operator role to User1.

3. Assign the Intune Administrator role to User1.

4. Assign a Microsoft 365 E5 license to User1.

5. Rerun device onboarding on Device1.

6. Assign the Remote Help add-on license to User1.

29. Your network contains an Active Directory domain named contoso.com. The domain contains two
computers named Computer1 and Computer2 that run Windows 10. On Computer1, you need to run the Invoke-
Command cmdlet to execute several PowerShell commands on Computer2. What should you do first?

1. On Computer2, run the Enable-PSRemoting cmdlet.

2. On Computer2, add Computer1 to the Remote Management Users group.

3. From Active Directory, configure the Trusted for Delegation setting for the computer account of Computer2.

4. On Computer1, run the New-PSSession cmdlet.

30. You have a Microsoft 365 Business Standard subscription and 100 Windows 10 Pro devices. You purchase a
Microsoft 365 E5 subscription. You need to upgrade the Windows 10 Pro devices to Windows 10 Enterprise. The
solution must minimize administrative effort. Which upgrade method should you use?

1. Windows Autopilot

2. a Microsoft Deployment Toolkit (MDT) lite-touch deployment

3. Subscription Activation

4. an in-place upgrade by using Windows installation media

31. You have 200 computers that run Windows 10. The computers are joined to Azure AD and enrolled in
Microsoft Intune. You need to enable self-service password reset on the sign-in screen. Which settings should
you configure from the Microsoft Intune admin center?

1. Device configuration

2. Device enrollment

3. Conditional access

4. Device compliance

32. You need to create an app configuration policy named Policy1 for the Android Enterprise platform. Which
apps can you manage by using Policy1?

about:blank 11/17
1/13/24, 10:38 PM about:blank

1. App2 only

2. App3 only

3. App1 and App3 only

4. App2 and App3 only

5. App1, App2, and App3

33. Note: This question is part of a series of questions that present the same scenario. Each question in the
series contains a unique solution that might meet the stated goals. Some question sets might have more than
one correct solution, while others might not have a correct solution. After you answer a question in this section,
you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your
company has an Azure AD tenant named contoso.com that contains several Windows 10 devices. When you
join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin. You need to ensure
that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.
Solution: From the Microsoft Entra admin center, you configure automatic mobile device management (MDM)
enrollment. From the Microsoft Intune admin center, you configure the Windows Hello for Business enrollment
options. Does this meet the goal?

1. Yes

2. No

34. You have computers that run Windows 10 and are managed by using Microsoft Intune. Users store their files
in a folder named D:\Folder1. You need to ensure that only a trusted list of applications is granted write access
to D:\Folder1. What should you configure in the device configuration profile?

1. Microsoft Defender Exploit Guard

2. Microsoft Defender Application Guard

3. Microsoft Defender SmartScreen

4. Microsoft Defender Application Control

35. You have a hybrid deployment of Azure AD that contains 50 Windows 10 devices. All the devices are
enrolled in Microsoft Intune. You discover that Group Policy settings override the settings configured in
Microsoft Intune policies. You need to ensure that the settings configured in Microsoft Intune override the Group
Policy settings. What should you do?

1. From Group Policy Management Editor, configure the Computer Configuration settings in the Default
Domain Policy.

2. From the Microsoft Intune admin center, create a custom device profile.

3. From the Microsoft Intune admin center, create an Administrative Templates device profile.

about:blank 12/17
1/13/24, 10:38 PM about:blank

4. From Group Policy Management Editor, configure the User Configuration settings in the Default Domain
Policy.

36. Which devices can be configured by using Windows Autopilot self-deploying mode?

1. Device2 only

2. Device3 only

3. Device1 and Device3 only

4. Device1, Device2, and Device3

37. You have a Microsoft 365 subscription that contains 1,000 iOS devices and includes Microsoft Intune. You
need to prevent the printing of corporate data from managed apps on the devices. What should you
configure?

1. an app configuration policy

2. a security baseline

3. an app protection policy

4. an iOS app provisioning profile

38. You have a Microsoft 365 subscription that uses Microsoft Intune Suite. You use Microsoft Intune to manage
devices. You use Windows Autopilot to deploy Windows 11 to devices. A support engineer reports that when a
deployment fails, they cannot collect deployment logs from failed device. You need to ensure that when a
deployment fails, the deployment logs can be collected. What should you configure?

1. the automatic enrollment settings

2. the Windows Autopilot deployment profile

3. the enrollment status page (ESP) profile

4. the device configuration profile

39. Your network contains an Active Directory domain. The domain contains 2,000 computers that run
Windows 10. You implement hybrid Azure AD and Microsoft Intune. You need to automatically register all the
existing computers to Azure AD and enroll the computers in Intune. The solution must minimize administrative
effort. What should you use?

1. an Autodiscover address record

2. a Group Policy object (GPO)

about:blank 13/17
1/13/24, 10:38 PM about:blank

3. an Autodiscover service connection point (SCP)

4. a Windows Autopilot deployment profile

40. You use Microsoft Intune and Intune Data Warehouse. You need to create a device inventory report that
includes the data stored in the data warehouse. What should you use to create the report?

1. the Company Portal app

2. Endpoint analytics

3. the Azure portal app

4. Microsoft Power BI

41. You use the Microsoft Deployment Toolkit (MDT) to deploy Windows 11. You create a new task sequence by
using the Standard Client Task Sequence template to deploy Windows 11 Enterprise to new computers. The
computers have a single hard disk. You need to modify the task sequence to create a system volume and a
data volume. Which phase should you modify in the task sequence?

1. Initialization

2. State Restore

3. Preinstall

4. Postinstall

42. each of the following statements, select Yes if the statement is true. Otherwise, select No.

1. If Device1 starts in out of box experience (OOBE) mode, the device will be deployed by using Autopilot. - Yes

2. If Device1 starts in out of box experience (OOBE) mode, the device will be deployed by using Autopilot. - No

3. If Device2 starts in out of box experience (OOBE) mode, the device will be deployed by using Autopilot. - Yes

4. If Device2 starts in out of box experience (OOBE) mode, the device will be deployed by using Autopilot. - No

about:blank 14/17
1/13/24, 10:38 PM about:blank

5. If Device3 starts in out of box experience (OOBE) mode, the device will be deployed by using Autopilot. - Yes

6. If Device3 starts in out of box experience (OOBE) mode, the device will be deployed by using Autopilot. - No

43. You have a Microsoft 365 subscription that contains a user named User1 and uses Microsoft Intune Suite.
You use Microsoft Intune to manage devices that run Windows 11. User provides remote support for 75 devices
in the marketing department. You need to add User1 to the Remote Desktop Users group on each marketing
department device. What should you configure?

1. an app configuration policy

2. a device compliance policy

3. an account protection policy

4. a device configuration profile

44. You have a Microsoft 365 subscription that uses Microsoft Intune. You need to ensure that you can deploy
apps to Android Enterprise devices. What should you do first?

1. Create a configuration profile.

2. Add a certificate connector.

3. Configure the Partner device management settings.

4. Link your managed Google Play account to Intune.

45. You have a Microsoft 365 subscription that contains 1,000 Windows 11 devices enrolled in Microsoft Intune.
You plan to use Intune to deploy an application named App1 that contains multiple installation files. What
should you do first?

1. Prepare the contents of App1 by using the Microsoft Win32 Content Prep Tool.

2. Create an Android application package (APK).

3. Upload the contents of App1 to Intune.

4. Install the Microsoft Deployment Toolkit (MDT).

46. You have a Microsoft 365 subscription that uses Microsoft Intune Suite. You use Microsoft Intune to manage
Windows 11 devices. You need to implement passwordless authentication that requires users to use number
matching. Which authentication method should you use?

1. Microsoft Authenticator

2. voice calls

3. FIDO2 security keys

about:blank 15/17
1/13/24, 10:38 PM about:blank

4. text messages

47. select the answer choice that completes each statement based on the information presented in the
graphic.

1. Users who deploy a device by using Profile1 are prevented from modifying any desktop settings

2. Users who deploy a device by using Profile1 can create additional local users on the device

3. Users who deploy a device by using Profile1 can modify the desktop settings for all device users.

4. Users who deploy a device by using Profile1 can modify the desktop settings only for themselves.

5. Users can configure the computer name during the deployment.

6. Users can configure the Cortana settings during the deployment.

7. Users can configure the Keyboard Layout during the deployment.

48. You are replacing 100 company-owned Windows devices. You need to use the Microsoft Deployment
Toolkit (MDT) to securely wipe and decommission the devices. The solution must meet the following
requirements: • Back up the user state. • Minimize administrative effort. Which task sequence template should
you use?

1. Standard Client Task Sequence

2. Standard Client Replace Task Sequence

3. Litetouch OEM Task Sequence

4. Sysprep and Capture

49. Which type of policy and how many policies should you create in Intune? To answer, select the appropriate
options in the answer area. NOTE: Each correct selection is worth one point.(Select any of two)

about:blank 16/17
1/13/24, 10:38 PM about:blank

1. Policy type : App configuration policy

2. Policy type : App protection policy

3. Policy type : Conditional access policy

4. Policy type : Device compliance policy

5. Minimum number of policies : 1

6. Minimum number of policies : 2

7. Minimum number of policies : 3

8. Minimum number of policies : 4

9. Minimum number of policies : 5

50. What should you identify?

1. Device1 only

2. Device2 only

3. Device1, Device2 only

4. Device1, Device2, and Device3 only

5. Device1, Device2, Device3, and Device4

about:blank 17/17

You might also like