0% acharam este documento útil (0 voto)
1K visualizações336 páginas

Exame MD 102

O documento apresenta um estudo de caso da ADatum Corporation, uma empresa de consultoria com um ambiente de rede que inclui um domínio Active Directory e um locatário híbrido do Azure AD. Ele detalha a configuração de dispositivos Windows 10, políticas do Microsoft Intune e planos de implementação de novos dispositivos e VPNs. O foco é em requisitos técnicos e mudanças planejadas para otimizar a administração e a implantação de computadores.

Enviado por

Leandro Duarte
Direitos autorais
© © All Rights Reserved
Levamos muito a sério os direitos de conteúdo. Se você suspeita que este conteúdo é seu, reivindique-o aqui.
Formatos disponíveis
Baixe no formato PDF, TXT ou leia on-line no Scribd
0% acharam este documento útil (0 voto)
1K visualizações336 páginas

Exame MD 102

O documento apresenta um estudo de caso da ADatum Corporation, uma empresa de consultoria com um ambiente de rede que inclui um domínio Active Directory e um locatário híbrido do Azure AD. Ele detalha a configuração de dispositivos Windows 10, políticas do Microsoft Intune e planos de implementação de novos dispositivos e VPNs. O foco é em requisitos técnicos e mudanças planejadas para otimizar a administração e a implantação de computadores.

Enviado por

Leandro Duarte
Direitos autorais
© © All Rights Reserved
Levamos muito a sério os direitos de conteúdo. Se você suspeita que este conteúdo é seu, reivindique-o aqui.
Formatos disponíveis
Baixe no formato PDF, TXT ou leia on-line no Scribd

27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Tópico 1 - Exame A

Pergunta nº 1 Tópico 1

HOTSPOT -

Estudo de caso -

Visão geral -

A ADatum Corporation é uma empresa de consultoria que tem um escritório principal em Montreal e filiais em Seattle e Nova York.

A ADatum tem uma assinatura do Microsoft 365 E5.

Ambiente -

Ambiente de rede -

A rede contém um domínio do Active Directory local chamado [Link]. O domínio contém os servidores mostrados na tabela a seguir.

A ADatum tem um locatário híbrido do Azure AD chamado [Link].

Usuários e grupos -

O locatário [Link] contém os usuários mostrados na tabela a seguir.

Todos os usuários recebem uma licença do Microsoft Office 365 e uma licença Enterprise Mobility + Security E3.

O Enterprise State Roaming está habilitado para o Group1 e o GroupA.

O Group1 e o Group2 têm um tipo de associação Atribuído.

Dispositivos -

A ADatum tem os dispositivos Windows 10 mostrados na tabela a seguir.

Os dispositivos Windows 10 são associados ao Azure AD e registrados no Microsoft Intune.

Os dispositivos Windows 10 são configurados conforme mostrado na tabela a seguir.

Todos os dispositivos associados ao Azure AD têm um arquivo executável chamado C:\[Link] e uma pasta chamada D:\Folder1.

Configuração do Microsoft Intune -

O Microsoft Intune tem as políticas de conformidade mostradas na tabela a seguir.

[Link] 2/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

As configurações de Registro Automático têm as seguintes configurações:

Escopo do usuário MDM: GrupoA -

Escopo do usuário MAM: GrupoB -

Você tem um perfil de configuração de proteção de endpoint que tem as seguintes configurações de acesso controlado à pasta:

Nome: Protection1 -

Proteção de pasta: Habilitar -

Lista de aplicativos que têm acesso a pastas protegidas: C:\*\[Link]

Lista de pastas adicionais que precisam ser protegidas: D:\Folder1

Atribuições:

Grupos incluídos: Grupo2, GrupoB -

Configuração do Windows Autopilot -

O ADatum tem um perfil de implantação do Windows Autopilot configurado conforme mostrado na exposição a seguir.

[Link] 3/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Atualmente, não há dispositivos implantados usando o Windows Autopilot.

O conector do Intune para o Active Directory está instalado no Server1.

Requisitos -

Alterações planejadas -

A ADatum planeja implementar as seguintes alterações:

Compre um novo dispositivo Windows 10 chamado Device6 e registre o dispositivo no Intune

Novos computadores serão implantados usando o Windows Autopilot e serão unidos ao Azure AD híbrido.

Implantou um perfil de configuração de limite de rede que terá as seguintes configurações:

Nome: Boundary1 -

Limite de rede: [Link]/24

Tags de escopo: Tag1 -

Atribuições:

[Link] 4/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Grupos incluídos: Grupo1, Grupo2 -

Implante dois perfis de configuração de VPN chamados Connection1 e Connection2 que terão as seguintes configurações:

Nome: Connection1 -

Nome da conexão: VPN1 -

Tipo de conexão: L2TP -

Atribuições:

Grupos incluídos: Grupo1, Grupo2, GrupoA

Grupos excluídos: --

Nome: Connection2 -

Nome da conexão: VPN2 -

Tipo de conexão: IKEv2 -

Atribuições:

Grupos incluídos: GrupoA -

Grupos excluídos: GrupoB -

Requisitos técnicos -

O ADatum deve atender aos seguintes requisitos técnicos:

Os usuários no GrupoA devem ser capazes de implantar novos computadores.

O esforço administrativo deve ser minimizado.

Para cada uma das seguintes afirmações, selecione Sim se a afirmação for verdadeira. Caso contrário, selecione Não.

OBSERVAÇÃO: Cada seleção correta vale um ponto.

Resposta correta:

[Link] 5/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Pergunta nº 2 Tópico 1

Estudo de caso -

Visão geral -

A ADatum Corporation é uma empresa de consultoria que tem um escritório principal em Montreal e filiais em Seattle e Nova York.

A ADatum tem uma assinatura do Microsoft 365 E5.

Ambiente -

Ambiente de rede -

A rede contém um domínio do Active Directory local chamado [Link]. O domínio contém os servidores mostrados na tabela a seguir.

A ADatum tem um locatário híbrido do Azure AD chamado [Link].

Usuários e grupos -

O locatário [Link] contém os usuários mostrados na tabela a seguir.

Todos os usuários recebem uma licença do Microsoft Office 365 e uma licença Enterprise Mobility + Security E3.

O Enterprise State Roaming está habilitado para o Group1 e o GroupA.

O Group1 e o Group2 têm um tipo de associação Atribuído.

Dispositivos -

A ADatum tem os dispositivos Windows 10 mostrados na tabela a seguir.

Os dispositivos Windows 10 são associados ao Azure AD e registrados no Microsoft Intune.

Os dispositivos Windows 10 são configurados conforme mostrado na tabela a seguir.

Todos os dispositivos associados ao Azure AD têm um arquivo executável chamado C:\[Link] e uma pasta chamada D:\Folder1.

Configuração do Microsoft Intune -

O Microsoft Intune tem as políticas de conformidade mostradas na tabela a seguir.

[Link] 6/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

As configurações de Registro Automático têm as seguintes configurações:

Escopo do usuário MDM: GrupoA -

Escopo do usuário MAM: GrupoB -

Você tem um perfil de configuração de proteção de endpoint que tem as seguintes configurações de acesso controlado à pasta:

Nome: Protection1 -

Proteção de pasta: Habilitar -

Lista de aplicativos que têm acesso a pastas protegidas: C:\*\[Link]

Lista de pastas adicionais que precisam ser protegidas: D:\Folder1

Atribuições:

Grupos incluídos: Grupo2, GrupoB -

Configuração do Windows Autopilot -

O ADatum tem um perfil de implantação do Windows Autopilot configurado conforme mostrado na exposição a seguir.

[Link] 7/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Atualmente, não há dispositivos implantados usando o Windows Autopilot.

O conector do Intune para o Active Directory está instalado no Server1.

Requisitos -

Alterações planejadas -

A ADatum planeja implementar as seguintes alterações:

Compre um novo dispositivo Windows 10 chamado Device6 e registre o dispositivo no Intune

Novos computadores serão implantados usando o Windows Autopilot e serão unidos ao Azure AD híbrido.

Implantou um perfil de configuração de limite de rede que terá as seguintes configurações:

Nome: Boundary1 -

Limite de rede: [Link]/24

Tags de escopo: Tag1 -

[Link] 8/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Atribuições:

Grupos incluídos: Grupo1, Grupo2 -

Implante dois perfis de configuração de VPN chamados Connection1 e Connection2 que terão as seguintes configurações:

Nome: Connection1 -

Nome da conexão: VPN1 -

Tipo de conexão: L2TP -

Atribuições:

Grupos incluídos: Grupo1, Grupo2, GrupoA

Grupos excluídos: --

Nome: Connection2 -

Nome da conexão: VPN2 -

Tipo de conexão: IKEv2 -

Atribuições:

Grupos incluídos: GrupoA -

Grupos excluídos: GrupoB -

Requisitos técnicos -

O ADatum deve atender aos seguintes requisitos técnicos:

Os usuários no GrupoA devem ser capazes de implantar novos computadores.

O esforço administrativo deve ser minimizado.

Quais dispositivos são registrados usando o serviço de implantação do Windows Autopilot?

A. Somente dispositivo 1

B. Somente dispositivo 3

C. Somente Device1 e Device3

D. Dispositivo1, Dispositivo2 e Dispositivo3

Resposta correta: A

Distribuição de votos na comunidade


Um (84%) Outro

[Link] 9/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Pergunta nº 3 Tópico 1

HOTSPOT -

Estudo de caso -

Visão geral -

A ADatum Corporation é uma empresa de consultoria que tem um escritório principal em Montreal e filiais em Seattle e Nova York.

A ADatum tem uma assinatura do Microsoft 365 E5.

Ambiente -

Ambiente de rede -

A rede contém um domínio do Active Directory local chamado [Link]. O domínio contém os servidores mostrados na tabela a seguir.

A ADatum tem um locatário híbrido do Azure AD chamado [Link].

Usuários e grupos -

O locatário [Link] contém os usuários mostrados na tabela a seguir.

Todos os usuários recebem uma licença do Microsoft Office 365 e uma licença Enterprise Mobility + Security E3.

O Enterprise State Roaming está habilitado para o Group1 e o GroupA.

O Group1 e o Group2 têm um tipo de associação Atribuído.

Dispositivos -

A ADatum tem os dispositivos Windows 10 mostrados na tabela a seguir.

Os dispositivos Windows 10 são associados ao Azure AD e registrados no Microsoft Intune.

Os dispositivos Windows 10 são configurados conforme mostrado na tabela a seguir.

Todos os dispositivos associados ao Azure AD têm um arquivo executável chamado C:\[Link] e uma pasta chamada D:\Folder1.

Configuração do Microsoft Intune -

O Microsoft Intune tem as políticas de conformidade mostradas na tabela a seguir.

[Link] 10/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

As configurações de Registro Automático têm as seguintes configurações:

Escopo do usuário MDM: GrupoA -

Escopo do usuário MAM: GrupoB -

Você tem um perfil de configuração de proteção de endpoint que tem as seguintes configurações de acesso controlado à pasta:

Nome: Protection1 -

Proteção de pasta: Habilitar -

Lista de aplicativos que têm acesso a pastas protegidas: C:\*\[Link]

Lista de pastas adicionais que precisam ser protegidas: D:\Folder1

Atribuições:

Grupos incluídos: Grupo2, GrupoB -

Configuração do Windows Autopilot -

O ADatum tem um perfil de implantação do Windows Autopilot configurado conforme mostrado na exposição a seguir.

[Link] 11/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Atualmente, não há dispositivos implantados usando o Windows Autopilot.

O conector do Intune para o Active Directory está instalado no Server1.

Requisitos -

Alterações planejadas -

A ADatum planeja implementar as seguintes alterações:

Compre um novo dispositivo Windows 10 chamado Device6 e registre o dispositivo no Intune

Novos computadores serão implantados usando o Windows Autopilot e serão unidos ao Azure AD híbrido.

Implantou um perfil de configuração de limite de rede que terá as seguintes configurações:

Nome: Boundary1 -

Limite de rede: [Link]/24

Tags de escopo: Tag1 -

Atribuições:

[Link] 12/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Grupos incluídos: Grupo1, Grupo2 -

Implante dois perfis de configuração de VPN chamados Connection1 e Connection2 que terão as seguintes configurações:

Nome: Connection1 -

Nome da conexão: VPN1 -

Tipo de conexão: L2TP -

Atribuições:

Grupos incluídos: Grupo1, Grupo2, GrupoA

Grupos excluídos: --

Nome: Connection2 -

Nome da conexão: VPN2 -

Tipo de conexão: IKEv2 -

Atribuições:

Grupos incluídos: GrupoA -

Grupos excluídos: GrupoB -

Requisitos técnicos -

O ADatum deve atender aos seguintes requisitos técnicos:

Os usuários no GrupoA devem ser capazes de implantar novos computadores.

O esforço administrativo deve ser minimizado.

Para cada uma das seguintes afirmações, selecione Sim se a afirmação for verdadeira. Caso contrário, selecione Não.

OBSERVAÇÃO: Cada seleção correta vale um ponto.

Resposta correta:

[Link] 13/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Pergunta nº 4 Tópico 1

Estudo de caso -

Visão geral -

A ADatum Corporation é uma empresa de consultoria que tem um escritório principal em Montreal e filiais em Seattle e Nova York.

A ADatum tem uma assinatura do Microsoft 365 E5.

Ambiente -

Ambiente de rede -

A rede contém um domínio do Active Directory local chamado [Link]. O domínio contém os servidores mostrados na tabela a seguir.

A ADatum tem um locatário híbrido do Azure AD chamado [Link].

Usuários e grupos -

O locatário [Link] contém os usuários mostrados na tabela a seguir.

Todos os usuários recebem uma licença do Microsoft Office 365 e uma licença Enterprise Mobility + Security E3.

O Enterprise State Roaming está habilitado para o Group1 e o GroupA.

O Group1 e o Group2 têm um tipo de associação Atribuído.

Dispositivos -

A ADatum tem os dispositivos Windows 10 mostrados na tabela a seguir.

Os dispositivos Windows 10 são associados ao Azure AD e registrados no Microsoft Intune.

Os dispositivos Windows 10 são configurados conforme mostrado na tabela a seguir.

Todos os dispositivos associados ao Azure AD têm um arquivo executável chamado C:\[Link] e uma pasta chamada D:\Folder1.

Configuração do Microsoft Intune -

O Microsoft Intune tem as políticas de conformidade mostradas na tabela a seguir.

[Link] 14/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

As configurações de Registro Automático têm as seguintes configurações:

Escopo do usuário MDM: GrupoA -

Escopo do usuário MAM: GrupoB -

Você tem um perfil de configuração de proteção de endpoint que tem as seguintes configurações de acesso controlado à pasta:

Nome: Protection1 -

Proteção de pasta: Habilitar -

Lista de aplicativos que têm acesso a pastas protegidas: C:\*\[Link]

Lista de pastas adicionais que precisam ser protegidas: D:\Folder1

Atribuições:

Grupos incluídos: Grupo2, GrupoB -

Configuração do Windows Autopilot -

O ADatum tem um perfil de implantação do Windows Autopilot configurado conforme mostrado na exposição a seguir.

[Link] 15/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Atualmente, não há dispositivos implantados usando o Windows Autopilot.

O conector do Intune para o Active Directory está instalado no Server1.

Requisitos -

Alterações planejadas -

A ADatum planeja implementar as seguintes alterações:

Compre um novo dispositivo Windows 10 chamado Device6 e registre o dispositivo no Intune

Novos computadores serão implantados usando o Windows Autopilot e serão unidos ao Azure AD híbrido.

Implantou um perfil de configuração de limite de rede que terá as seguintes configurações:

Nome: Boundary1 -

Limite de rede: [Link]/24

Tags de escopo: Tag1 -

Atribuições:

[Link] 16/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Grupos incluídos: Grupo1, Grupo2 -

Implante dois perfis de configuração de VPN chamados Connection1 e Connection2 que terão as seguintes configurações:

Nome: Connection1 -

Nome da conexão: VPN1 -

Tipo de conexão: L2TP -

Atribuições:

Grupos incluídos: Grupo1, Grupo2, GrupoA

Grupos excluídos: --

Nome: Connection2 -

Nome da conexão: VPN2 -

Tipo de conexão: IKEv2 -

Atribuições:

Grupos incluídos: GrupoA -

Grupos excluídos: GrupoB -

Requisitos técnicos -

O ADatum deve atender aos seguintes requisitos técnicos:

Os usuários no GrupoA devem ser capazes de implantar novos computadores.

O esforço administrativo deve ser minimizado.

Você implementa o Boundary1 com base nas alterações planejadas.

Quais dispositivos têm um limite de rede de [Link]/24 aplicado?

A. Somente dispositivo 2

B. Somente dispositivo 3

C. Somente Device1, Device2 e Device5

D. Somente Device1, Device2, Device3 e Device4

Resposta correta: D

Distribuição de votos na comunidade


E (94%) 6%

[Link] 17/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Pergunta nº 5 Tópico 1

HOTSPOT -

Você tem uma assinatura do Microsoft 365.

Você usa o Microsoft Intune Suite para gerenciar dispositivos.

Você tem a política de proteção de aplicativo iOS mostrada na exposição a seguir.

Use os menus suspensos para selecionar a opção de resposta que completa cada declaração com base nas informações apresentadas no

gráfico.

OBSERVAÇÃO: Cada seleção correta vale um ponto.

Resposta correta:

[Link] 18/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Pergunta nº 6 Tópico 1

ARRASTAR E SOLTAR -

Você tem uma assinatura do Microsoft 365 E5 e um computador que executa o Windows 11.

Você precisa criar uma instalação personalizada do Microsoft 365 Apps for enterprise.

Quais quatro ações você deve executar em sequência? Para responder, mova os cmdlets apropriados da lista de cmdlets para a área de resposta

e organize-os na ordem correta.

Resposta correta:

[Link] 19/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Pergunta nº 7 Tópico 1

Você tem dispositivos registrados no Microsoft Intune, conforme mostrado na tabela a seguir.

Em quais dispositivos você pode aplicar políticas de configuração de aplicativo?

A. Somente dispositivo 2

B. Somente Device1 e Device2

C. Somente Device3 e Device4

D. Somente Device2, Device3 e Device4

E. Dispositivo1, Dispositivo2, Dispositivo3 e Dispositivo4

Resposta correta: C

Distribuição de votos na comunidade


C (100%)

[Link] 20/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Pergunta nº 8 Tópico 1

HOTSPOT -

Você tem um locatário do Azure AD chamado [Link] que contém os dispositivos mostrados na tabela a seguir.

Todos os dispositivos contêm um aplicativo chamado App1 e estão registrados no Microsoft Intune.

Você precisa impedir que os usuários copiem dados do App1 e colem os dados em outros aplicativos.

Que tipo de política e quantas políticas você deve criar no Intune? Para responder, selecione as opções apropriadas na área de resposta.

OBSERVAÇÃO: cada seleção correta vale um ponto.

Resposta correta:

[Link] 21/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Pergunta nº 9 Tópico 1

Você tem uma assinatura do Microsoft 365 que usa o Microsoft Intune Suite.

Você usa o Microsoft Intune para gerenciar dispositivos.

Você planeja implantar dois aplicativos chamados App1 e App2 em todos os dispositivos Windows. O App1 deve ser instalado antes do App2.

No centro de administração do Intune, você cria e implanta dois aplicativos do Windows (Win32).

Você precisa garantir que o App1 seja instalado antes do App2 em todos os dispositivos.

O que você deve configurar?

A. as configurações de implantação do App1

B. um grupo de dispositivos dinâmicos

C. uma regra de detecção

D. as configurações de implantação do App2

Resposta correta: D

Distribuição de votos na comunidade


E (97%)

Pergunta nº 10 Tópico 1

Você tem uma assinatura do Microsoft Intune.

Você tem dispositivos registrados no Intune, conforme mostrado na tabela a seguir.

Um aplicativo chamado App1 é instalado em cada dispositivo.

Qual é o número mínimo de políticas de configuração de aplicativo necessárias para gerenciar o App1?

A. 1

B.2

C.3

D.4

E. 5

Resposta correta: B

Distribuição de votos na comunidade


B (83%) Um (17%)

[Link] 22/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Pergunta nº 11 Tópico 1

Você tem uma assinatura do Microsoft 365 E5 que contém 100 dispositivos iOS registrados no Microsoft Intune.

Você precisa implantar um aplicativo de linha de negócios (LOB) personalizado nos dispositivos usando o Intune.

Qual extensão você deve selecionar para o arquivo do pacote do aplicativo?

A. .intunemac

[Link]

C. .apk

D. .appx

Resposta correta: B

Distribuição de votos na comunidade


B (100%)

Pergunta nº 12 Tópico 1

Você tem uma assinatura do Microsoft 365 E5 que contém um usuário chamado User1 e um aplicativo da Web chamado App1.

O App1 deve aceitar apenas solicitações de autenticação modernas.

Você planeja criar uma política de acesso condicional chamada CAPolicy1 que terá as seguintes configurações:

Atribuições -

Usuários ou identidades de carga de trabalho: User1

Aplicativos ou ações na nuvem: App1 -

Controles de acesso -

Conceder: Bloquear acesso -

Você precisa bloquear apenas solicitações de autenticação herdadas para o App1.

Qual condição você deve adicionar ao CAPolicy1?

A. Filter for devices

B. Device platforms

C. User risk

D. Sign-in risk

E. Client apps

Correct Answer: E

Community vote distribution


E (100%)

[Link] 23/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #13 Topic 1

HOTSPOT -

All users have Microsoft 365 apps deployed.

You need to configure Microsoft 365 apps to meet the following requirements:

Enable the automatic installation of WebView2 Runtime.

Prevent users from submitting feedback.

Which two settings should you configure in the Microsoft 365 Apps admin center? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 24/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #14 Topic 1

You have a Microsoft 365 subscription.

You have 10 computers that run Windows 10 and are enrolled in mobile device management (MDM).

You need to deploy the Microsoft 365 Apps for enterprise suite to all the computers.

What should you do?

A. From the Microsoft Intune admin center, create a Windows 10 device profile.

B. From Azure AD, add an app registration.

C. From Azure AD, add an enterprise application.

D. From the Microsoft Intune admin center, add an app.

Correct Answer: D

Community vote distribution


D (96%) 3%

Question #15 Topic 1

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices.

You have a Windows 11 device named Device1 that is enrolled in Intune. Device1 has been offline for 30 days.

You need to remove Device1 from Intune immediately. The solution must ensure that if the device checks in again, any apps and data provisioned

by Intune are removed. User-installed apps, personal data, and OEM-installed apps must be retained.

What should you use?

A. a Delete action

B. a Retire action

C. a Fresh Start action

D. an Autopilot Reset action

Correct Answer: A

Community vote distribution


A (57%) B (41%)

[Link] 25/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #16 Topic 1

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices.

You need to review the startup times and restart frequencies of the devices.

What should you use?

A. Azure Monitor

B. Intune Data Warehouse

C. Microsoft Defender for Endpoint

D. Endpoint analytics

Correct Answer: D

Community vote distribution


D (100%)

[Link] 26/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #17 Topic 1

HOTSPOT -

You have a Microsoft 365 E5 subscription.

You create a new update rings policy named Policy1 as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

[Link] 27/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

Question #18 Topic 1

You have computers that run Windows 10 and connect to an Azure Log Analytics workspace. The workspace is configured to collect all available

events from the Windows event logs.

The computers have the logged events shown in the following table.

Which events are collected in the Log Analytics workspace?

A. 1 only

B. 2 and 3 only

C. 1 and 3 only

D. 1, 2, and 4 only

E. 1, 2, 3, and 4

Correct Answer: E

Community vote distribution


E (51%) D (49%)

Question #19 Topic 1

You have a Microsoft 365 E5 subscription that contains 10 Android Enterprise devices. Each device has a corporate-owned work profile and is

enrolled in Microsoft Intune.

You need to configure the devices to run a single app in kiosk mode.

Which Configuration settings should you modify in the device restrictions profile?

A. Users and Accounts

B. General

C. System security

D. Device experience

Correct Answer: D

Community vote distribution


D (100%)

[Link] 28/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #20 Topic 1

You have a Microsoft 365 E5 subscription that contains 500 macOS devices enrolled in Microsoft Intune.

You need to ensure that you can apply Microsoft Defender for Endpoint antivirus policies to the macOS devices. The solution must minimize

administrative effort.

What should you do?

A. Onboard the macOS devices to the Microsoft Purview compliance portal.

B. From the Microsoft Intune admin center, create a security baseline.

C. Install Defender for Endpoint on the macOS devices.

D. From the Microsoft Intune admin center, create a configuration profile.

Correct Answer: D

Community vote distribution


D (53%) C (47%)

Question #21 Topic 1

You have an Azure AD tenant and 100 Windows 10 devices that are Azure AD joined and managed by using Microsoft Intune.

You need to configure Microsoft Defender Firewall and Microsoft Defender Antivirus on the devices. The solution must minimize administrative

effort.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A. To configure Microsoft Defender Antivirus, create a Group Policy Object (GPO) and configure the Windows Defender Antivirus settings.

B. To configure Microsoft Defender Firewall, create a device configuration profile and configure the Device restrictions settings.

C. To configure Microsoft Defender Antivirus, create a device configuration profile and configure the Endpoint protection settings.

D. To configure Microsoft Defender Antivirus, create a device configuration profile and configure the Device restrictions settings.

E. To configure Microsoft Defender Firewall, create a device configuration profile and configure the Endpoint protection settings.

F. To configure Microsoft Defender Firewall, create a Group Policy Object (GPO) and configure Windows Defender Firewall with Advanced

Security.

Correct Answer: DE

Community vote distribution


DE (64%) CE (20%) Other

[Link] 29/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #22 Topic 1

You have an Azure AD group named Group1. Group1 contains two Windows 10 Enterprise devices named Device1 and Device2.

You create a device configuration profile named Profile1. You assign Profile1 to Group1.

You need to ensure that Profile1 applies to Device1 only.

What should you modify in Profile1?

A. Assignments

B. Settings

C. Scope (Tags)

D. Applicability Rules

Correct Answer: A

Community vote distribution


A (76%) 13% 11%

Question #23 Topic 1

DRAG DROP -

You have a Microsoft 365 subscription that includes Microsoft Intune.

You need to implement a Microsoft Defender for Endpoint solution that meets the following requirements:

Enforces compliance for Defender for Endpoint by using Conditional Access

Prevents suspicious scripts from running on devices

What should you configure? To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once,

or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 30/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #24 Topic 1

Your network contains an on-premises Active Directory domain and an Azure AD tenant.

The Default Domain Policy Group Policy Object (GPO) contains the settings shown in the following table.

You need to migrate the existing Default Domain Policy GPO settings to a device configuration profile.

Which device configuration profile type template should you use?

A. Administrative Templates

B. Endpoint protection

C. Device restrictions

D. Custom

Correct Answer: C

Community vote distribution


C (50%) A (39%) 11%

Question #25 Topic 1

You have 100 computers that run Windows 10 and connect to an Azure Log Analytics workspace.

Which three types of data can you collect from the computers by using Log Analytics? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

A. failure events from the Security log

B. the list of processes and their execution times

C. the average processor utilization

D. error events from the System log

E. third-party application logs stored as text files

Correct Answer: CDE

Community vote distribution


CDE (54%) BCD (31%) Other

[Link] 31/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #26 Topic 1

You have a Microsoft 365 E5 subscription. The subscription contains 25 computers that run Windows 11 and are enrolled in Microsoft Intune.

You need to onboard the devices to Microsoft Defender for Endpoint.

What should you create in the Microsoft Intune admin center?

A. an attack surface reduction (ASR) policy

B. a security baseline

C. an endpoint detection and response (EDR) policy

D. an account protection policy

E. an antivirus policy

Correct Answer: C

Community vote distribution


C (86%) 14%

Question #27 Topic 1

Your company uses Microsoft Intune to manage devices.

You need to ensure that only Android devices that use Android work profiles can enroll in Intune.

Which two configurations should you perform in the device enrollment restrictions? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A. From Platform Settings, set Android device administrator Personally Owned to Block.

B. From Platform Settings, set Android Enterprise (work profile) to Allow.

C. From Platform Settings, set Android device administrator Personally Owned to Allow.

D. From Platform Settings, set Android device administrator to Block.

Correct Answer: BD

Community vote distribution


BD (87%) 13%

[Link] 32/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #28 Topic 1

HOTSPOT -

You have the device configuration profile shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 33/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #29 Topic 1

HOTSPOT -

You have 100 Windows 10 devices enrolled in Microsoft Intune.

You need to configure the devices to retrieve Windows updates from the internet and from other computers on a local network.

Which Delivery Optimization setting should you configure, and which type of Intune object should you create? To answer, select the appropriate

options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 34/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #30 Topic 1

HOTSPOT -

You have an Azure AD tenant that contains the users shown in the following table.

You have devices enrolled in Microsoft Intune as shown in the following table.

From Intune, you create and send a custom notification named Notification1 to Group1.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

Question #31 Topic 1

You use Microsoft Intune and Intune Data Warehouse.

You need to create a device inventory report that includes the data stored in the data warehouse.

What should you use to create the report?

A. the Company Portal app

B. Endpoint analytics

C. the Azure portal app

D. Microsoft Power BI

Correct Answer: D

Community vote distribution


D (100%)

[Link] 35/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #32 Topic 1

You have a Microsoft 365 E5 subscription and 25 Apple iPads.

You need to enroll the iPads in Microsoft Intune by using the Apple Configurator enrollment method.

What should you do first?

A. Configure an Apply MDM push certificate.

B. Add your user account as a device enrollment manager (DEM).

C. Modify the enrollment restrictions.

D. Upload a file that has the device identifiers for each iPad.

Correct Answer: A

Community vote distribution


A (100%)

[Link] 36/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #33 Topic 1

HOTSPOT -

You have 100 computers that run Windows 10. You have no servers. All the computers are joined to Azure AD.

The computers have different update settings, and some computers are configured for manual updates.

You need to configure Windows Update. The solution must meet the following requirements:

The configuration must be managed from a central location.

Internet traffic must be minimized.

Costs must be minimized.

How should you configure Windows Update? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 37/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #34 Topic 1

You have a Microsoft 365 E5 subscription that contains 150 hybrid Azure AD joined Windows devices. All the devices are enrolled in Microsoft

Intune.

You need to configure Delivery Optimization on the devices to meet the following requirements:

Allow downloads from the internet and from other computers on the local network.

Limit the percentage of used bandwidth to 50.

What should you use?

A. a configuration profile

B. a Windows Update for Business Group Policy setting

C. a Microsoft Peer-to-Peer Networking Services Group Policy setting

D. an Update ring for Windows 10 and later profile

Correct Answer: A

Community vote distribution


A (94%) 3%

Question #35 Topic 1

Your network contains an Active Directory domain named [Link]. The domain contains a computer named Computer1 that runs Windows

10.

You have the groups shown in the following table.

Which groups can you add to Group4?

A. Group2 only

B. Group1 and Group2 only

C. Group2 and Group3 only

D. Group1, Group2, and Group3

Correct Answer: A

Community vote distribution


A (70%) C (17%) 13%

[Link] 38/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #36 Topic 1

DRAG DROP -

You have a Microsoft 365 subscription. The subscription contains computers that run Windows 11 and are enrolled in Microsoft Intune.

You need to create a compliance policy that meets the following requirements:

Requires BitLocker Drive Encryption (BitLocker) on each device

Requires a minimum operating system version

Which setting of the compliance policy should you configure for each requirement? To answer, drag the appropriate settings to the correct

requirements. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view

content.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 39/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #37 Topic 1

HOTSPOT -

You have a Microsoft 365 E5 subscription that uses Microsoft Intune.

You have the Windows 11 devices shown in the following table.

You deploy the device compliance policy shown in the exhibit. (Click the Exhibit tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 40/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #38 Topic 1

DRAG DROP -

You have a Microsoft 365 subscription that contains the devices shown in the following table.

You need to ensure that only devices running trusted firmware or operating system builds can access network resources.

Which compliance policy setting should you configure for each device? To answer, drag the appropriate settings to the correct devices. Each

setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 41/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #39 Topic 1

DRAG DROP -

You have a Microsoft 365 subscription that contains 1,000 Windows 11 devices enrolled in Microsoft Intune.

You plan to create and monitor the results of a compliance policy used to validate the BIOS version of the devices.

Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and

arrange them in the correct order.

Correct Answer:

[Link] 42/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #40 Topic 1

DRAG DROP -

You have a computer that runs Windows 10 and contains two local users named User1 and User2.

You need to ensure that the users can perform the following actions:

User1 must be able to adjust the date and time.

User2 must be able to clear Windows logs.

The solution must use the principle of least privilege.

To which group should you add each user? To answer, drag the appropriate groups to the correct users. Each group may be used once, more than

once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 43/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #41 Topic 1

HOTSPOT -

You have an Azure AD tenant named [Link].

You have the devices shown in the following table.

Which devices can be Azure AD joined, and which devices can be registered in [Link]? To answer, select the appropriate options in the

answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 44/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #42 Topic 1

HOTSPOT -

You have an Azure AD tenant named [Link] that contains the users shown in the following table.

You have a computer named Computer1 that runs Windows 10. Computer1 is in a workgroup and has the local users shown in the following table.

UserA joins Computer1 to Azure AD by using user1@[Link].

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

Question #43 Topic 1

Your network contains an Active Directory domain. The domain contains a user named Admin1. All computers run Windows 10.

You enable Windows PowerShell remoting on the computers.

You need to ensure that Admin1 can establish remote PowerShell connections to the computers. The solution must use the principle of least

privilege.

To which group should you add Admin1?

A. Access Control Assistance Operators

B. Remote Desktop Users

C. Power Users

D. Remote Management Users

Correct Answer: D

Community vote distribution


D (97%)

[Link] 45/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #44 Topic 1

HOTSPOT -

You have a Microsoft Intune subscription.

You are creating a Windows Autopilot deployment profile named Profile1 as shown in the following exhibit. Profile1 will be deployed to Windows

10 devices.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

[Link] 46/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

Question #45 Topic 1

HOTSPOT -

You have a server named Server1 and computers that run Windows 10. Server1 has the Microsoft Deployment Toolkit (MDT) installed.

You plan to upgrade the Windows 10 computers to Windows 11 by using the MDT deployment wizard.

You need create a deployment share on Server1.

What should you do on Server1, and what are the minimum components you should add to the MDT deployment share? To answer, select the

appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 47/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #46 Topic 1

DRAG DROP -

You have a Microsoft Deployment Toolkit (MDT) server named MDT1.

When computers start from the LiteTouchPE_x64.iso image and connect to MDT1, the welcome screen appears as shown in the following exhibit.

You need to prevent the welcome screen from appearing when the computers connect to MDT1.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and

arrange them in the correct order.

Correct Answer:

[Link] 48/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #47 Topic 1

You use Windows Admin Center to remotely administer computers that run Windows 10.

When connecting to Windows Admin Center, you receive the message shown in the following exhibit.

You need to prevent the message from appearing when you connect to Windows Admin Center.

To which certificate store should you import the certificate?

A. Client Authentication Issuers

B. Personal

C. Trusted Root Certification Authorities

Correct Answer: C

Community vote distribution


C (100%)

[Link] 49/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #48 Topic 1

HOTSPOT -

You have an Azure AD tenant named [Link] that contains the devices shown in the following table.

[Link] contains the Azure AD groups shown in the following table.

You add a Windows Autopilot deployment profile. The profile is configured as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

[Link] 50/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

Question #49 Topic 1

HOTSPOT -

Your network contains an Active Directory domain. The domain contains 1,000 computers that run Windows 11.

You need to configure the Remote Desktop settings of all the computers. The solution must meet the following requirements:

Prevent the sharing of clipboard contents.

Ensure that users authenticate by using Network Level Authentication (NLA).

Which two nodes of the Group Policy Management Editor should you use? To answer, select the appropriate nodes in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 51/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #50 Topic 1

HOTSPOT -

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices.

Azure AD joined Windows devices enroll automatically in Intune.

You have the devices shown in the following table.

You are preparing to upgrade the devices to Windows11. All the devices are compatible with Windows 11.

You need to evaluate Windows Autopilot and in-place upgrade as deployment methods to implement Windows 11 Pro on the devices, while

retaining all user settings and applications.

Which devices can be upgraded by using each method? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 52/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #51 Topic 1

DRAG DROP -

You have 100 computers that run Windows 10.

You plan to deploy Windows 11 to the computers by performing a wipe and load installation.

You need to recommend a method to retain the user settings and the user data.

Which three actions should you recommend be performed in sequence? To answer, move the appropriate actions from the list of actions to the

answer area and arrange them in the correct order.

Correct Answer:

[Link] 53/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #52 Topic 1

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices.

You use Windows Autopilot to deploy Windows 11 to devices.

A support engineer reports that when a deployment fails, they cannot collect deployment logs from failed device.

You need to ensure that when a deployment fails, the deployment logs can be collected.

What should you configure?

A. the automatic enrollment settings

B. the Windows Autopilot deployment profile

C. the enrollment status page (ESP) profile

D. the device configuration profile

Correct Answer: C

Community vote distribution


C (100%)

Question #53 Topic 1

You have a Microsoft 365 E5 subscription that contains a user named User1 and uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices.

You have a device named Devic1 that is enrolled in Intune.

You need to ensure that User1 can use Remote Help from the Intune admin center for Device1.

Which three actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A. Deploy the Remote Help app to Device1.

B. Assign the Help Desk Operator role to User1.

C. Assign the Intune Administrator role to User1.

D. Assign a Microsoft 365 E5 license to User1.

E. Rerun device onboarding on Device1.

F. Assign the Remote Help add-on license to User1.

Correct Answer: ABF

Community vote distribution


ABF (81%) Other

[Link] 54/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #54 Topic 1

You have a Windows 11 capable device named Device1 that runs the 64-bit version of Windows 10 Enterprise and has Microsoft Office 2019

installed.

You have the Windows 11 Enterprise images shown in the following table.

Which images can be used to perform an in-place upgrade of Device1?

A. Image1 only

B. Image2 only

C. Image1 and Image2

Correct Answer: B

Community vote distribution


B (100%)

[Link] 55/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #55 Topic 1

HOTSPOT -

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant by using Azure AD

Connect.

You use Microsoft Intune and Configuration Manager to manage devices.

You need to recommend a deployment plan for new Windows 11 devices. The solution must meet the following requirements:

Devices for the marketing department must be joined to the AD DS domain only. The IT department will install complex applications on the

devices at build time, before giving the devices to the marketing department users.

Devices for the sales department must be Azure AD joined. The devices will be shipped directly from the manufacturer to the homes of the sales

department users.

Administrative effort must be minimized.

Which deployment method should you recommend for each department? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth point.

Correct Answer:

[Link] 56/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #56 Topic 1

You have a Microsoft Deployment Toolkit (MDT) deployment share named DS1.

In the Out-of-Box Drivers node, you create folders that contain drivers for different hardware models.

You need to configure the Inject Drivers MDT task to use PnP detection to install the drivers for one of the hardware models.

What should you do first?

A. Import an OS package.

B. Create a selection profile.

C. Add a Gather task to the task sequence.

D. Add a Validate task to the task sequence.

Correct Answer: B

Community vote distribution


B (100%)

Question #57 Topic 1

You have an on-premises server named Server1 that hosts a Microsoft Deployment Toolkit (MDT) deployment share named MDT1.

You need to ensure that MDT1 supports multicast deployments.

What should you install on Server1?

A. Multipath I/O (MPIO)

B. Multipoint Connector

C. Windows Deployment Services (WDS)

D. Windows Server Update Services (WSUS)

Correct Answer: C

Community vote distribution


C (100%)

[Link] 57/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #58 Topic 1

Your company standardizes on Windows 10 Enterprise for all users.

Some users purchase their own computer from a retail store. The computers run Windows 10 Pro.

You need to recommend a solution to upgrade the computers to Windows 10 Enterprise, join the computers to Azure AD, and install several

Microsoft Store apps. The solution must meet the following requirements:

Ensure that any applications installed by the users are retained.

Minimize user intervention.

What is the best recommendation to achieve the goal? More than one answer choice may achieve the goal. Select the BEST answer.

A. Windows Autopilot

B. Microsoft Deployment Toolkit (MDT)

C. a Windows Configuration Designer provisioning package

D. Windows Deployment Services (WDS)

Correct Answer: C

Community vote distribution


C (64%) A (36%)

Question #59 Topic 1

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that

might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your company has an Azure AD tenant named [Link] that contains several Windows 10 devices.

When you join new Windows 10 devices to [Link], users are prompted to set up a four-digit pin.

You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to [Link].

Solution: From the Microsoft Entra admin center, you modify the User settings and the Device settings.

Does this meet the goal?

A. Yes

B. No

Correct Answer: B

Community vote distribution


B (100%)

[Link] 58/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #60 Topic 1

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that

might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your company has an Azure AD tenant named [Link] that contains several Windows 10 devices.

When you join new Windows 10 devices to [Link], users are prompted to set up a four-digit pin.

You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to [Link].

Solution: From the Microsoft Entra admin center, you configure automatic mobile device management (MDM) enrollment. From the Microsoft

Intune admin center, you create and assign a device restrictions profile.

Does this meet the goal?

A. Yes

B. No

Correct Answer: B

Community vote distribution


B (78%) A (22%)

Question #61 Topic 1

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that

might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your company has an Azure AD tenant named [Link] that contains several Windows 10 devices.

When you join new Windows 10 devices to [Link], users are prompted to set up a four-digit pin.

You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to [Link].

Solution: From the Microsoft Entra admin center, you configure automatic mobile device management (MDM) enrollment. From the Microsoft

Intune admin center, you configure the Windows Hello for Business enrollment options.

Does this meet the goal?

A. Yes

B. No

Correct Answer: A

Community vote distribution


A (100%)

[Link] 59/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #62 Topic 1

Case study -

Overview -

Contoso, Ltd. is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York.

Contoso has the users and computers shown in the following table.

The company has IT, human resources (HR), legal (LEG), marketing (MKG), and finance (FIN) departments.

Contoso recently purchased a Microsoft 365 subscription.

The company is opening a new branch office in Phoenix. Most of the users in the Phoenix office will work from home.

Existing Environment -

The network contains an Active Directory domain named [Link] that is synced to Azure AD.

All member servers run Windows Server 2016. All laptops and desktop computers run Windows 10 Enterprise.

The computers are managed by using Microsoft Configuration Manager. The mobile devices are managed by using Microsoft Intune.

The naming convention for the computers is the department acronym, followed by a hyphen, and then four numbers, for example FIN-6785. All the

computers are joined to the on-premises Active Directory domain.

Each department has an organizational unit (OU) that contains a child OU named Computers. Each computer account is in the Computers OU of

its respective department.

Intune Configuration -

The domain has the users shown in the following table.

User2 is a device enrollment manager (DEM) in Intune.

The devices enrolled in Intune are shown in the following table.

The device compliance policies in Intune are configured as shown in the following table.

[Link] 60/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

The device compliance policies have the assignments shown in the following table.

The device limit restrictions in Intune are configured as shown in the following table.

Requirements -

Planned changes -

Contoso plans to implement the following changes:

• Provide new computers to the Phoenix office users. The new computers have Windows 10 Pro preinstalled and were purchased already.

• Implement co-management for the computers.

Technical Requirements -

Contoso must meet the following technical requirements:

• Ensure that the users in a group named Group4 can only access Microsoft Exchange Online from devices that are enrolled in Intune.

• Deploy Windows 10 Enterprise to the computers of the Phoenix office users by using Windows Autopilot.

• Create a provisioning package for new computers in the HR department.

• Block iOS devices from sending diagnostic and usage telemetry data.

• Use the principle of least privilege whenever possible.

• Enable the users in the MKG department to use App1.

• Pilot co-management for the IT department.

You need to meet the technical requirements for the iOS devices.

Which object should you create in Intune?

A. a deployment profile

B. an app protection policy

C. a device configuration profile

D. a compliance policy

Correct Answer: C

Community vote distribution


C (100%)

[Link] 61/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #63 Topic 1

HOTSPOT

Case study

Overview

Contoso, Ltd. is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York.

Contoso has the users and computers shown in the following table.

The company has IT, human resources (HR), legal (LEG), marketing (MKG), and finance (FIN) departments.

Contoso recently purchased a Microsoft 365 subscription.

The company is opening a new branch office in Phoenix. Most of the users in the Phoenix office will work from home.

Existing Environment

The network contains an Active Directory domain named [Link] that is synced to Azure AD.

All member servers run Windows Server 2016. All laptops and desktop computers run Windows 10 Enterprise.

The computers are managed by using Microsoft Configuration Manager. The mobile devices are managed by using Microsoft Intune.

The naming convention for the computers is the department acronym, followed by a hyphen, and then four numbers, for example FIN-6785. All the

computers are joined to the on-premises Active Directory domain.

Each department has an organizational unit (OU) that contains a child OU named Computers. Each computer account is in the Computers OU of

its respective department.

Intune Configuration

The domain has the users shown in the following table.

User2 is a device enrollment manager (DEM) in Intune.

The devices enrolled in Intune are shown in the following table.

[Link] 62/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

The device compliance policies in Intune are configured as shown in the following table.

The device compliance policies have the assignments shown in the following table.

The device limit restrictions in Intune are configured as shown in the following table.

Requirements

Planned changes

Contoso plans to implement the following changes:

• Provide new computers to the Phoenix office users. The new computers have Windows 10 Pro preinstalled and were purchased already.

• Implement co-management for the computers.

Technical Requirements

Contoso must meet the following technical requirements:

• Ensure that the users in a group named Group4 can only access Microsoft Exchange Online from devices that are enrolled in Intune.

• Deploy Windows 10 Enterprise to the computers of the Phoenix office users by using Windows Autopilot.

• Create a provisioning package for new computers in the HR department.

• Block iOS devices from sending diagnostic and usage telemetry data.

• Use the principle of least privilege whenever possible.

• Enable the users in the MKG department to use App1.

• Pilot co-management for the IT department.

You are evaluating which devices are compliant.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

[Link] 63/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 64/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #64 Topic 1

Case study -

Overview -

Contoso, Ltd. is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York.

Contoso has the users and computers shown in the following table.

The company has IT, human resources (HR), legal (LEG), marketing (MKG), and finance (FIN) departments.

Contoso recently purchased a Microsoft 365 subscription.

The company is opening a new branch office in Phoenix. Most of the users in the Phoenix office will work from home.

Existing Environment -

The network contains an Active Directory domain named [Link] that is synced to Azure AD.

All member servers run Windows Server 2016. All laptops and desktop computers run Windows 10 Enterprise.

The computers are managed by using Microsoft Configuration Manager. The mobile devices are managed by using Microsoft Intune.

The naming convention for the computers is the department acronym, followed by a hyphen, and then four numbers, for example FIN-6785. All the

computers are joined to the on-premises Active Directory domain.

Each department has an organizational unit (OU) that contains a child OU named Computers. Each computer account is in the Computers OU of

its respective department.

Intune Configuration -

The domain has the users shown in the following table.

User2 is a device enrollment manager (DEM) in Intune.

The devices enrolled in Intune are shown in the following table.

The device compliance policies in Intune are configured as shown in the following table.

[Link] 65/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

The device compliance policies have the assignments shown in the following table.

The device limit restrictions in Intune are configured as shown in the following table.

Requirements -

Planned changes -

Contoso plans to implement the following changes:

• Provide new computers to the Phoenix office users. The new computers have Windows 10 Pro preinstalled and were purchased already.

• Implement co-management for the computers.

Technical Requirements -

Contoso must meet the following technical requirements:

• Ensure that the users in a group named Group4 can only access Microsoft Exchange Online from devices that are enrolled in Intune.

• Deploy Windows 10 Enterprise to the computers of the Phoenix office users by using Windows Autopilot.

• Create a provisioning package for new computers in the HR department.

• Block iOS devices from sending diagnostic and usage telemetry data.

• Use the principle of least privilege whenever possible.

• Enable the users in the MKG department to use App1.

• Pilot co-management for the IT department.

You need to prepare for the deployment of the Phoenix office computers.

What should you do first?

A. Generalize the computers and configure the Device settings from the Microsoft Entra admin center.

B. Extract the serial number of each computer to an XML file and upload the file from the Microsoft Intune admin center.

C. Extract the hardware ID information of each computer to a CSV file and upload the file from the Microsoft Intune admin center.

D. Generalize the computers and configure the Mobility (MDM and MAM) settings from the Microsoft Entra admin center.

E. Extract the serial number information of each computer to a CSV file and upload the file from the Microsoft Intune admin center.

Correct Answer: C

Community vote distribution


C (100%)

[Link] 66/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #65 Topic 1

HOTSPOT

Case study

Overview

Contoso, Ltd. is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York.

Contoso has the users and computers shown in the following table.

The company has IT, human resources (HR), legal (LEG), marketing (MKG), and finance (FIN) departments.

Contoso recently purchased a Microsoft 365 subscription.

The company is opening a new branch office in Phoenix. Most of the users in the Phoenix office will work from home.

Existing Environment

The network contains an Active Directory domain named [Link] that is synced to Azure AD.

All member servers run Windows Server 2016. All laptops and desktop computers run Windows 10 Enterprise.

The computers are managed by using Microsoft Configuration Manager. The mobile devices are managed by using Microsoft Intune.

The naming convention for the computers is the department acronym, followed by a hyphen, and then four numbers, for example FIN-6785. All the

computers are joined to the on-premises Active Directory domain.

Each department has an organizational unit (OU) that contains a child OU named Computers. Each computer account is in the Computers OU of

its respective department.

Intune Configuration

The domain has the users shown in the following table.

User2 is a device enrollment manager (DEM) in Intune.

The devices enrolled in Intune are shown in the following table.

[Link] 67/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

The device compliance policies in Intune are configured as shown in the following table.

The device compliance policies have the assignments shown in the following table.

The device limit restrictions in Intune are configured as shown in the following table.

Requirements

Planned changes

Contoso plans to implement the following changes:

• Provide new computers to the Phoenix office users. The new computers have Windows 10 Pro preinstalled and were purchased already.

• Implement co-management for the computers.

Technical Requirements

Contoso must meet the following technical requirements:

• Ensure that the users in a group named Group4 can only access Microsoft Exchange Online from devices that are enrolled in Intune.

• Deploy Windows 10 Enterprise to the computers of the Phoenix office users by using Windows Autopilot.

• Create a provisioning package for new computers in the HR department.

• Block iOS devices from sending diagnostic and usage telemetry data.

• Use the principle of least privilege whenever possible.

• Enable the users in the MKG department to use App1.

• Pilot co-management for the IT department.

What is the maximum number of devices that User1 and User2 can enroll in Intune? To answer, select the appropriate options in the answer area.

[Link] 68/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 69/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #66 Topic 1

HOTSPOT

Case study

Overview

Contoso, Ltd. is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York.

Contoso has the users and computers shown in the following table.

The company has IT, human resources (HR), legal (LEG), marketing (MKG), and finance (FIN) departments.

Contoso recently purchased a Microsoft 365 subscription.

The company is opening a new branch office in Phoenix. Most of the users in the Phoenix office will work from home.

Existing Environment

The network contains an Active Directory domain named [Link] that is synced to Azure AD.

All member servers run Windows Server 2016. All laptops and desktop computers run Windows 10 Enterprise.

The computers are managed by using Microsoft Configuration Manager. The mobile devices are managed by using Microsoft Intune.

The naming convention for the computers is the department acronym, followed by a hyphen, and then four numbers, for example FIN-6785. All the

computers are joined to the on-premises Active Directory domain.

Each department has an organizational unit (OU) that contains a child OU named Computers. Each computer account is in the Computers OU of

its respective department.

Intune Configuration

The domain has the users shown in the following table.

User2 is a device enrollment manager (DEM) in Intune.

The devices enrolled in Intune are shown in the following table.

[Link] 70/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

The device compliance policies in Intune are configured as shown in the following table.

The device compliance policies have the assignments shown in the following table.

The device limit restrictions in Intune are configured as shown in the following table.

Requirements

Planned changes

Contoso plans to implement the following changes:

• Provide new computers to the Phoenix office users. The new computers have Windows 10 Pro preinstalled and were purchased already.

• Implement co-management for the computers.

Technical Requirements

Contoso must meet the following technical requirements:

• Ensure that the users in a group named Group4 can only access Microsoft Exchange Online from devices that are enrolled in Intune.

• Deploy Windows 10 Enterprise to the computers of the Phoenix office users by using Windows Autopilot.

• Create a provisioning package for new computers in the HR department.

• Block iOS devices from sending diagnostic and usage telemetry data.

• Use the principle of least privilege whenever possible.

• Enable the users in the MKG department to use App1.

• Pilot co-management for the IT department.

To which devices do Policy1 and Policy2 apply? To answer, select the appropriate options in the answer area.

[Link] 71/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 72/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #67 Topic 1

Your network contains an Active Directory domain named [Link]. The domain contains two computers named Computer1 and Computer2

that run Windows 10.

On Computer1, you need to run the Invoke-Command cmdlet to execute several PowerShell commands on Computer2.

What should you do first?

A. On Computer2, run the Enable-PSRemoting cmdlet.

B. On Computer2, add Computer1 to the Remote Management Users group.

C. From Active Directory, configure the Trusted for Delegation setting for the computer account of Computer2.

D. On Computer1, run the New-PSSession cmdlet.

Correct Answer: A

Community vote distribution


A (92%) 8%

Question #68 Topic 1

You have an Azure AD tenant that contains the devices shown in the following table.

Which devices can be activated by using subscription activation?

A. Device1 only

B. Device1 and Device2 only

C. Device1 and Device3 only

D. Device1, Device2, Device3, and Device4

Correct Answer: C

Community vote distribution


C (100%)

[Link] 73/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #69 Topic 1

You have 25 computers that run Windows 10 Pro.

You have a Microsoft 365 E5 subscription that uses Microsoft Intune.

You need to upgrade the computers to Windows 11 Enterprise by using an in-place upgrade. The solution must minimize administrative effort.

What should you use?

A. Microsoft Deployment Toolkit (MDT) and a default image of Windows 11 Enterprise

B. Microsoft Configuration Manager and a custom image of Windows 11 Enterprise

C. Windows Autopilot

D. Subscription Activation

Correct Answer: D

Community vote distribution


D (44%) A (35%) C (16%) 5%

Question #70 Topic 1

You use the Microsoft Deployment Toolkit (MDT) to manage Windows 11 deployments.

From Deployment Workbench, you modify the WinPE settings and add PowerShell support.

You need to generate a new set of WinPE boot image files that contain the updated settings.

What should you do?

A. From the Deployment Shares node, update the deployment share.

B. From the Advanced Configuration node, create new media.

C. From the Packages node, import a new operating system package.

D. From the Operating Systems node, import a new operating system.

Correct Answer: A

Community vote distribution


A (74%) B (26%)

[Link] 74/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #71 Topic 1

You are replacing 100 company-owned Windows devices.

You need to use the Microsoft Deployment Toolkit (MDT) to securely wipe and decommission the devices. The solution must meet the following

requirements:

• Back up the user state.

• Minimize administrative effort.

Which task sequence template should you use?

A. Standard Client Task Sequence

B. Standard Client Replace Task Sequence

C. Litetouch OEM Task Sequence

D. Sysprep and Capture

Correct Answer: B

Community vote distribution


B (100%)

Question #72 Topic 1

Your network contains an Active Directory domain. The domain contains a computer named Computer1 that runs Windows 11.

You need to enable the Windows Remote Management (WinRM) service on Computer1 and perform the following configurations:

• For the WinRM service, set Startup type to Automatic.

• Create a listener that accepts requests from any IP address.

• Enable a firewall exception for WS-Management communications.

Which PowerShell cmdlet should you use?

A. Connect-WSMan

B. Enable-PSRemoting

C. Invoke-WSManAction

D. Enable-PSSessionConfiguration

Correct Answer: B

Community vote distribution


B (100%)

[Link] 75/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #73 Topic 1

HOTSPOT

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant. The tenant contains

the users shown in the following table.

You assign Windows 10/11 Enterprise E5 licenses to Group1 and User2.

You deploy the devices shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 76/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #74 Topic 1

HOTSPOT

Your network contains an Active Directory domain named [Link], a workgroup, and computers that run Windows 10. The computers are

configured as shown in the following table.

The local Administrator accounts on Computer1, Computer2, and Computer3 have the same user name and password.

On Computer1, Windows Defender Firewall is configured as shown in the following exhibit.

The services on Computer1 have the following states.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

[Link] 77/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

NOTE: Each correct selection is worth one point.

Correct Answer:

Question #75 Topic 1

You have a Hyper-V host that contains the virtual machines shown in the following table.

On which virtual machines can you install Windows 11?

A. VM1 only

B. VM3 only

C. VM1 and VM2 only

D. VM2 and VM3 only

E. VM1, VM2, and VM3

Correct Answer: B

Community vote distribution


B (100%)

[Link] 78/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #76 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that uses Microsoft Intune and contains the users shown in the following table.

Group2 has been assigned in the Enrollment Status Page.

You have the devices shown in the following table.

You capture and upload the hardware IDs of the devices in the marketing department.

You configure Windows Autopilot.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 79/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #77 Topic 1

QUESTION NO: 77 -

You have a Microsoft 365 subscription that contains a user named User1. User1 is assigned a Windows 10/11 Enterprise E3 license.

You use Microsoft Intune Suite to manage devices.

User1 activates the following devices:

• Device1: Windows 11 Enterprise

• Device2: Windows 10 Enterprise

• Device3: Windows 11 Enterprise

How many more devices can User1 activate?

A. 2

B. 3

C. 7

D. 8

Correct Answer: A

Community vote distribution


A (100%)

[Link] 80/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #78 Topic 1

DRAG DROP

Your company has a computer named Computer1 that runs Windows 10.

Computer1 was used by a user who left the company.

You plan to repurpose Computer1 and assign the computer to a new user.

You need to redeploy Computer1 by using Windows Autopilot.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and

arrange them in the correct order.

Correct Answer:

[Link] 81/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #79 Topic 1

You use the Microsoft Deployment Toolkit (MDT) to deploy Windows 11.

You create a new task sequence by using the Standard Client Task Sequence template to deploy Windows 11 Enterprise to new computers. The

computers have a single hard disk.

You need to modify the task sequence to create a system volume and a data volume.

Which phase should you modify in the task sequence?

A. Initialization

B. State Restore

C. Preinstall

D. Postinstall

Correct Answer: C

Community vote distribution


C (100%)

[Link] 82/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #80 Topic 1

You have a Microsoft Deployment Toolkit (MDT) deployment share.

From the Deployment Workbench, you open the New Task Sequence Wizard and select the Standard Client Upgrade Task Sequence task sequence

template.

You discover that there are no operating system images listed on the Select OS page as shown in the following exhibit.

You need to be able to select an operating system image to perform a Windows 11 in-place upgrade.

What should you do?

A. Enable monitoring for the deployment share.

B. Import a full set of source files.

C. Import a custom image file.

D. Run the Update Deployment Share Wizard.

Correct Answer: B

Community vote distribution


B (94%) 6%

[Link] 83/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #81 Topic 1

Your company implements Azure AD, Microsoft 365, Microsoft Intune, and Azure Information Protection.

The company's security policy states the following:

• Personal devices do not need to be enrolled in Intune.

• Users must authenticate by using a PIN before they can access corporate email data.

• Users can use their personal iOS and Android devices to access corporate cloud services.

• Users must be prevented from copying corporate email data to a cloud storage service other than Microsoft OneDrive for Business.

You need to configure a solution to enforce the security policy.

What should you create?

A. a device configuration profile from the Microsoft Intune admin center

B. a data loss prevention (DLP) policy from the Microsoft Purview compliance portal

C. an insider risk management policy from the Microsoft Purview compliance portal

D. an app protection policy from the Microsoft Intune admin center

Correct Answer: D

Community vote distribution


D (100%)

Question #82 Topic 1

You have a Microsoft 365 subscription that contains 500 Android Enterprise devices.

All the devices are enrolled in Microsoft Intune.

You need to deliver bookmarks to the Chrome browser on the devices.

What should you create?

A. a compliance policy

B. a configuration profile

C. an app protection policy

D. an app configuration policy

Correct Answer: D

Community vote distribution


D (83%) Other

[Link] 84/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #83 Topic 1

You have a Microsoft 365 E5 subscription and 100 computers that run Windows 10.

You need to deploy Microsoft Office Professional Plus 2019 to the computers by using Microsoft Office Deployment Tool (ODT).

What should you use to create a customization file for ODT?

A. the Microsoft 365 admin center

B. the Microsoft Intune admin center

C. the Microsoft Purview compliance portal

D. the Microsoft 365 Apps admin center

Correct Answer: D

Community vote distribution


D (100%)

Question #84 Topic 1

You have a Microsoft 365 subscription that contains 1,000 Windows 11 devices enrolled in Microsoft Intune.

You plan to use Intune to deploy an application named App1 that contains multiple installation files.

What should you do first?

A. Prepare the contents of App1 by using the Microsoft Win32 Content Prep Tool.

B. Create an Android application package (APK).

C. Upload the contents of App1 to Intune.

D. Install the Microsoft Deployment Toolkit (MDT).

Correct Answer: A

Community vote distribution


A (92%) 8%

[Link] 85/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #85 Topic 1

HOTSPOT

You have groups that use the Dynamic Device membership type as shown in the following table.

You are deploying Microsoft 365 apps.

You have devices enrolled in Microsoft Intune as shown in the following table.

In the Microsoft Intune admin center, you create a Microsoft 365 Apps app as shown in the exhibit. (Click the Exhibit tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

[Link] 86/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

NOTE: Each correct selection is worth one point.

Correct Answer:

Question #86 Topic 1

You have a Microsoft 365 subscription. All devices run Windows 10.

You need to prevent users from enrolling the devices in the Windows Insider Program.

What two configurations should you perform from the Microsoft Intune admin center? Each correct answer is a complete solution.

NOTE: Each correct selection is worth one point.

A. a device restrictions device configuration profile

B. an app configuration policy

C. a Windows 10 and later security baseline

D. a custom device configuration profile

E. a Windows 10 and later update ring

Correct Answer: DE

Community vote distribution


DE (39%) AE (33%) AD (25%)

[Link] 87/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #87 Topic 1

You have a Microsoft 365 E5 subscription that contains 100 Windows 10 devices enrolled in Microsoft Intune.

You plan to use Endpoint analytics.

You need to create baseline metrics.

What should you do first?

A. Modify the Baseline regression threshold.

B. Onboard 10 devices to Endpoint analytics.

C. Create a Log Analytics workspace.

D. Create an Azure Monitor workbook.

Correct Answer: B

Community vote distribution


B (77%) C (23%)

Question #88 Topic 1

You install a feature update on a computer that runs Windows 10.

How many days do you have to roll back the update?

A. 5

B. 10

C. 14

D. 30

Correct Answer: B

Community vote distribution


B (100%)

[Link] 88/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #89 Topic 1

You have a Microsoft Azure subscription that contains an Azure Log Analytics workspace.

You deploy a new computer named Computer1 that runs Windows 10. Computer1 is in a workgroup.

You need to ensure that you can use Log Analytics to query events from Computer1.

What should you do on Computer1?

A. Join Azure AD.

B. Configure Windows Defender Firewall.

C. Create an event subscription

D. Install the Azure Monitor Agent.

Correct Answer: A

Community vote distribution


A (73%) D (27%)

Question #90 Topic 1

You have a Microsoft 365 E5 subscription and 100 unmanaged iPad devices.

You need to deploy a specific iOS update to the devices. Users must be prevented from manually installing a more recent version of iOS.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A. Create a device configuration profile.

B. Enroll the devices in Microsoft Intune by using the Intune Company Portal.

C. Create a compliance policy.

D. Create an iOS app provisioning profile.

E. Enroll the devices in Microsoft Intune by using Apple Business Manager.

Correct Answer: AE

Community vote distribution


AE (89%) 11%

[Link] 89/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #91 Topic 1

You have a Microsoft 365 subscription that includes Microsoft Intune.

You have an update ring named UpdateRing1 that contains the following settings:

• Automatic update behavior: Auto install and restart at a scheduled time

• Automatic behavior frequency: First week of the month

• Scheduled install day: Tuesday

• Scheduled install time: 3 AM

From the Microsoft Intune admin center, you select Uninstall for the feature updates of UpdateRing1.

When will devices start to remove the feature updates?

A. when a user approves the uninstall

B. as soon as the policy is received

C. next Tuesday

D. the first Tuesday of the next month

Correct Answer: B

Community vote distribution


B (100%)

Question #92 Topic 1

You have a hybrid deployment of Azure AD that contains 50 Windows 10 devices. All the devices are enrolled in Microsoft Intune.

You discover that Group Policy settings override the settings configured in Microsoft Intune policies.

You need to ensure that the settings configured in Microsoft Intune override the Group Policy settings.

What should you do?

A. From Group Policy Management Editor, configure the Computer Configuration settings in the Default Domain Policy.

B. From the Microsoft Intune admin center, create a custom device profile.

C. From the Microsoft Intune admin center, create an Administrative Templates device profile.

D. From Group Policy Management Editor, configure the User Configuration settings in the Default Domain Policy.

Correct Answer: B

Community vote distribution


B (65%) C (32%)

[Link] 90/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #93 Topic 1

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices.

You need to ensure that the startup performance of managed Windows 11 devices is captured and available for review in the Intune admin center.

What should you configure?

A. the Azure Monitor agent

B. a device compliance policy

C. a Conditional Access policy

D. an Intune data collection policy

Correct Answer: D

Community vote distribution


D (100%)

[Link] 91/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #94 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription that uses Microsoft Intune.

Devices are enrolled in Intune as shown in the following table.

The devices are the members of groups as shown in the following table.

You create an iOS/iPadOS update profile as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

[Link] 92/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

NOTE: Each correct selection is worth one point.

Correct Answer:

Question #95 Topic 1

You have a Microsoft Intune deployment that contains the resources shown in the following table.

You create a policy set named Set1 and add Comply1 to Set1.

Which additional resources can you add to Set1?

A. Conf1 only

B. Comply2 only

C. Comply2 and Conf1 only

D. CA1, Conf1, and Office1 only

E. Comply2, CA1, Conf1, and Office1

Correct Answer: C

Community vote distribution


C (100%)

[Link] 93/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #96 Topic 1

You use Microsoft Defender for Endpoint to protect computers that run Windows 10.

You need to assess the differences between the configuration of Microsoft Defender for Endpoint and the Microsoft-recommended configuration

baseline.

Which tool should you use?

A. Microsoft Defender for Endpoint Power BI app

B. Microsoft Secure Score

C. Endpoint Analytics

D. Microsoft 365 Defender portal

Correct Answer: B

Community vote distribution


B (75%) D (25%)

Question #97 Topic 1

You have a Microsoft 365 E5 subscription that contains 1,000 Windows 11 devices. All the devices are enrolled in Microsoft Intune.

You plan to integrate Intune with Microsoft Defender for Endpoint.

You need to establish a service-to-service connection between Intune and Defender for Endpoint.

Which settings should you configure in the Microsoft Intune admin center?

A. Premium add-ons

B. Connectors and tokens

C. Tenant enrollment

D. Microsoft Tunnel Gateway

Correct Answer: B

Community vote distribution


B (93%) 7%

[Link] 94/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #98 Topic 1

DRAG DROP

You have a Microsoft Intune subscription that is configured to use a PFX certificate connector to an on-premises Enterprise certification authority

(CA).

You need to use Intune to configure autoenrollment for Android devices by using public key pair (PKCS) certificates.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and

arrange them in the correct order.

Correct Answer:

[Link] 95/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #99 Topic 1

Your company uses Microsoft Intune.

More than 500 Android and iOS devices are enrolled in the Intune tenant.

You plan to deploy new Intune policies. Different policies will apply depending on the version of Android or iOS installed on the device.

You need to ensure that the policies can target the devices based on their version of Android or iOS.

What should you configure first?

A. groups that have dynamic membership rules in Azure AD

B. Device categories in Intune

C. Corporate device identifiers in Intune

D. Device settings in Azure AD

Correct Answer: A

Community vote distribution


A (72%) B (28%)

[Link] 96/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #100 Topic 1

DRAG DROP

You have 500 Windows 10 devices enrolled in Microsoft Intune.

You plan to use Exploit protection in Microsoft Intune to enable the following system settings on the devices:

• Data Execution Prevention (DEP)

• Force randomization for images (Mandatory ASLR)

You need to configure a Windows 10 device that will be used to create a template file.

Which protection areas on the device should you configure in the Windows Security app before you create the template file? To answer, drag the

appropriate protection areas to the correct settings. Each protection area may be used once, more than once, or not at all. You may need to drag

the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Correct Answer:

Question #101 Topic 1

You have an Azure AD tenant named [Link].

You have a workgroup computer named Computer1 that runs Windows 11.

You need to add Computer1 to [Link].

What should you use?

A. [Link]

B. Computer Management

C. [Link]

D. the Settings app

Correct Answer: D

Community vote distribution


D (94%) 6%

[Link] 97/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #102 Topic 1

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to manage Windows 11 devices.

You need to implement passwordless authentication that requires users to use number matching.

Which authentication method should you use?

A. Microsoft Authenticator

B. voice calls

C. FIDO2 security keys

D. text messages

Correct Answer: A

Community vote distribution


A (100%)

Question #103 Topic 1

You use a Microsoft Intune subscription to manage iOS devices.

You configure a device compliance policy that blocks jailbroken iOS devices.

You need to enable Enhanced jailbreak detection.

What should you configure?

A. the Compliance policy settings

B. the device compliance policy

C. a network location

D. a configuration profile

Correct Answer: B

Community vote distribution


B (92%) 8%

[Link] 98/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #104 Topic 1

DRAG DROP

You have a Microsoft 365 subscription that contains two users named User1 and User2.

You need to ensure that the users can perform the following tasks:

• User1 must be able to create groups and manage users.

• User2 must be able to reset passwords for nonadministrative users.

The solution must use the principle of least privilege.

Which role should you assign to each user? To answer, drag the appropriate roles to the correct users. Each role may be used once, more than

once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 99/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #105 Topic 1

HOTSPOT

You have a Microsoft Intune subscription that has the following device compliance policy settings:

• Mark devices with no compliance policy assigned as: Compliant

• Compliance status validity period (days): 14

On January1, you enroll Windows 10 devices in Intune as shown in the following table.

On January 4, you create the following two device compliance policies:

• Name: Policy1

• Platform: Windows 10 and later

• Require BitLocker: Require

• Mark device noncompliant: 5 days after noncompliance

• Scope (Tags): Tag1

• Name: Policy2

• Platform: Windows 10 and later

• Firewall: Require

• Mark device noncompliant: Immediately

• Scope (Tags): Tag2

On January 5, you assign Policy1 and Policy2 to Group1.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 100/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #106 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that includes Microsoft Intune.

You have computers that run Windows 11 as shown in the following table.

You have the groups shown in the following table.

You create and assign the compliance policies shown in the following table.

The next day, you review the compliance status of the computers.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 101/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #107 Topic 1

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that

might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your company has an Azure AD tenant named [Link] that contains several Windows 10 devices.

When you join new Windows 10 devices to [Link], users are prompted to set up a four-digit pin.

You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to [Link].

Solution: From the Microsoft Entra admin center, you configure the Authentication methods.

Does this meet the goal?

A. Yes

B. No

Correct Answer: B

Community vote distribution


B (100%)

Question #108 Topic 1

You have a Microsoft 365 tenant that contains the objects shown in the following table.

You are creating a compliance policy named Compliance1.

Which objects can you specify in Compliance1 as additional recipients of noncompliance notifications?

A. Group3 and Group4 only

B. Group3, Group4, and Admin1 only

C. Group1, Group2, and Group3 only

D. Group1, Group2, Group3, and Group4 only

E. Group1, Group2, Group3, Group4, and Admin1

Correct Answer: C

Community vote distribution


C (100%)

[Link] 102/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #109 Topic 1

HOTSPOT

You have an Azure AD tenant named [Link] that contains a user named User1. User1 has a user principal name (UPN) of

user1@[Link].

You join a Windows 11 device named Client1 to [Link].

You need to add User1 to the local Administrators group of Client1.

How should you complete the command? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

Question #110 Topic 1

You have a Microsoft 365 subscription.

You need to provide a user the ability Security defaults and create Conditional Access policies. The solution must use the principle of least

privilege.

Which role should you assign to the user?

A. Global Administrator

B. Conditional Access Administrator

C. Security Administrator

D. Intune Administrator

Correct Answer: B

Community vote distribution


B (62%) C (38%)

[Link] 103/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #111 Topic 1

HOTSPOT

In Microsoft Intune, you have the device compliance policies shown in the following table.

The Intune compliance policy settings are configured as shown in the following exhibit.

On June 1, you enroll Windows 10 devices in Intune as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 104/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #112 Topic 1

You have a Microsoft 365 subscription that contains a user named User1 and uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices that run Windows 11.

User provides remote support for 75 devices in the marketing department.

You need to add User1 to the Remote Desktop Users group on each marketing department device.

What should you configure?

A. an app configuration policy

B. a device compliance policy

C. an account protection policy

D. a device configuration profile

Correct Answer: C

Community vote distribution


C (86%) 14%

[Link] 105/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #113 Topic 1

HOTSPOT

You have an Azure AD tenant named [Link] that contains the users shown in the following table.

For [Link], the Mobility (MDM and MAM) settings have the following configurations:

• MDM user scope: Group1

• MAM user scope: Group2

You purchase the devices shown in the following table:

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Correct Answer:

[Link] 106/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #114 Topic 1

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to deploy and manage Windows devices.

You have 100 devices from users that left your company.

You need to repurpose the devices for new users by removing all the data and applications installed by the previous users. The solution must

minimize administrative effort.

What should you do?

A. Deploy a new configuration profile to the devices.

B. Perform a Windows Autopilot reset on the devices.

C. Perform an in-place upgrade on the devices.

D. Perform a clean installation of Windows 11 on the devices.

Correct Answer: B

Community vote distribution


B (100%)

[Link] 107/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #115 Topic 1

HOTSPOT

You create a Windows Autopilot deployment profile.

You need to configure the profile settings to meet the following requirements:

• Automatically enroll new devices and provision system apps without requiring end-user authentication

• Include the hardware serial number in the computer name.

Which two settings should you configure? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

[Link] 108/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

Question #116 Topic 1

You have a computer named Computer1 that runs Windows 11.

A user named User1 plans to use Remote Desktop to connect to Computer1.

You need to ensure that the device of User1 is authenticated before the Remote Desktop connection is established and the sign in page appears.

What should you do on Computer1?

A. Turn on Reputation-based protection

B. Enable Network Level Authentication (NLA)

C. Turn on Network Discovery

D. Configure the Remote Desktop Configuration service

Correct Answer: B

Community vote distribution


B (100%)

[Link] 109/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #117 Topic 1

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices.

You have the devices shown in the following table.

Which devices can be changed to Windows 11 Enterprise by using subscription activation?

A. Device3 only

B. Device2 and Device3 only

C. Device1 and Device2 only

D. Device1, Device2, and Device3

Correct Answer: B

Community vote distribution


B (85%) A (15%)

[Link] 110/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #118 Topic 1

HOTSPOT

Your network contains an Active Directory domain named [Link]. The domain contains two computers named Computer1 and Computer2

that run Windows 10. Remote Desktop is enabled on Computer2.

The domain contains the user accounts shown in the following table.

Computer2 contains the local groups shown in the following table.

The relevant user rights assignments for Computer2 are shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 111/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #119 Topic 1

You have two computers named Computer1 and Computer2 that run Windows 10. Computer2 has Remote Desktop enabled.

From Computer1, you connect to Computer2 by using Remote Desktop Connection.

You need to ensure that you can access the local drives on Computer1 from within the Remote Desktop session.

What should you do?

A. From Computer2, configure the Remote Desktop settings.

B. From Windows Defender Firewall on Computer1, allow Remote Desktop.

C. From Windows Defender Firewall on Computer2, allow File and Printer Sharing.

D. From Computer1, configure the Remote Desktop Connection settings.

Correct Answer: D

Community vote distribution


D (92%) 8%

Question #120 Topic 1

You have a Microsoft 365 subscription that uses Microsoft Intune.

You have five new Windows 11 Pro devices.

You need to prepare the devices for corporate use. The solution must meet the following requirements:

• Install Windows 11 Enterprise on each device.

• Install a Windows Installer (MSI) package named App1 on each device.

• Add a certificate named Certificate1 that is required by App1.

• Join each device to Azure AD.

Which three provisioning options can you use? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

A. subscription activation

B. a custom Windows image

C. an in-place upgrade

D. Windows Autopilot

E. provisioning packages

Correct Answer: BDE

Community vote distribution


BDE (67%) ADE (33%)

[Link] 112/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #121 Topic 1

DRAG DROP

You have a Microsoft Deployment Toolkit (MDT) deployment share named DS1.

You import a Windows 11 image to DS1.

You have an executable installer for an application named App1.

You need to ensure that App1 will be installed for all the task sequences that deploy the image.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and

arrange them in the correct order.

Correct Answer:

[Link] 113/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #122 Topic 1

HOTSPOT

You have the devices shown in the following table.

You need to migrate app data from Device1 to Device2. The data must be encrypted and stored on Server1 during the migration.

Which command should you run on each device? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 114/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #123 Topic 1

You have a Microsoft 365 subscription.

You plan to use Windows Autopilot to provision 25 Windows 11 devices.

You need to configure the Out-of-box experience (OOBE) settings.

What should you create in the Microsoft Intune admin center?

A. an enrollment status page (ESP)

B. a deployment profile

C. a compliance policy

D. a PowerShell script

E. a configuration profile

Correct Answer: B

Community vote distribution


B (100%)

Question #124 Topic 1

You have an Azure AD tenant that contains the devices shown in the following table.

You purchase Windows 11 Enterprise E5 licenses.

Which devices can use Subscription Activation to upgrade to Windows 11 Enterprise?

A. Device1 only

B. Device1 and Device2 only

C. Device1 and Device3 only

D. Device1, Device2, Device3, and Device4

Correct Answer: A

Community vote distribution


A (93%) 7%

[Link] 115/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #125 Topic 1

You have a Microsoft 365 Subscription that uses Microsoft Intune.

You add apps to Intune as shown in the following table.

You need to create an app configuration policy named Policy1 for the Android Enterprise platform.

Which apps can you manage by using Policy1?

A. App2 only

B. App3 only

C. App1 and App3 only

D. App2 and App3 only

E. App1, App2, and App3

Correct Answer: B

Community vote distribution


B (68%) D (32%)

Question #126 Topic 1

You have a Microsoft 365 subscription that uses Microsoft Intune.

You need to ensure that you can deploy apps to Android Enterprise devices.

What should you do first?

A. Create a configuration profile.

B. Add a certificate connector.

C. Configure the Partner device management settings.

D. Link your managed Google Play account to Intune.

Correct Answer: D

Community vote distribution


D (100%)

[Link] 116/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #127 Topic 1

You have a Microsoft 365 tenant that uses Microsoft Intune.

You use the Company Portal app to access and install published apps to enrolled devices.

From the Microsoft Intune admin center, you add a Microsoft Store app.

Which two App information types are visible in the Company Portal?

NOTE: Each correct selection is worth one point.

A. Privacy URL

B. Information URL

C. Developer

D. Owner

Correct Answer: AB

Community vote distribution


AB (92%) 4%

[Link] 117/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #128 Topic 1

HOTSPOT

You have 200 computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune.

You need to set a custom image as the wallpaper and sign-in screen.

Which two settings should you configure in the Device restrictions configuration profile? To answer, select the appropriate settings in the answer

area.

NOTE: Each correct selection is worth one point.

[Link] 118/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

Question #129 Topic 1

You have computers that run Windows 11 Pro. The computers are joined to Azure AD and enrolled in Microsoft Intune.

You need to upgrade the computers to Windows 11 Enterprise.

What should you configure in Intune?

A. a device compliance policy

B. a device cleanup rule

C. a device enrollment policy

D. a device configuration profile

Correct Answer: D

Community vote distribution


D (95%) 5%

[Link] 119/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #130 Topic 1

You have computers that run Windows 10 and are managed by using Microsoft Intune.

Users store their files in a folder named D:\Folder1.

You need to ensure that only a trusted list of applications is granted write access to D:\Folder1.

What should you configure in the device configuration profile?

A. Microsoft Defender Exploit Guard

B. Microsoft Defender Application Guard

C. Microsoft Defender SmartScreen

D. Microsoft Defender Application Control

Correct Answer: A

Community vote distribution


A (78%) D (23%)

[Link] 120/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #131 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription that contains 100 Windows 10 devices enrolled in Microsoft Intune.

You need to create Endpoint security policies to meet the following requirements:

• Hide the Firewall & network protection area in the Windows Security app.

• Disable the provisioning of Windows Hello for Business on the devices.

Which two policy types should you use? To answer, select the policies in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 121/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #132 Topic 1

You have a Microsoft 365 subscription that contains 100 devices enrolled in Microsoft Intune.

You need to review the startup processes and how often each device restarts.

What should you use?

A. Endpoint analytics

B. Device Management

C. Azure Monitor

D. Intune Data Warehouse

Correct Answer: A

Community vote distribution


A (100%)

Question #133 Topic 1

DRAG DROP

You have a Microsoft 365 subscription that contains devices enrolled in Microsoft Intune.

You need to create Endpoint security policies to enforce the following requirements:

• Computers that run macOS must have FileVault enabled.

• Computers that run Windows 10 must have Microsoft Defender Credential Guard enabled.

• Computers that run Windows 10 must have Microsoft Defender Application Control enabled.

Which Endpoint security feature should you use for each requirement? To answer, drag the appropriate features to the correct requirements. Each

feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

Correct Answer:

[Link] 122/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #134 Topic 1

Your company has 200 computers that run Windows 10. The computers are managed by using Microsoft Intune.

Currently, Windows updates are downloaded without using Delivery Optimization.

You need to configure the computers to use Delivery Optimization.

What should you create in Intune?

A. a device compliance policy

B. a Windows 10 update ring

C. a device configuration profile

D. an app protection policy

Correct Answer: C

Community vote distribution


C (100%)

Question #135 Topic 1

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices.

Auto-enrollment in Intune is configured.

You have 100 Windows 11 devices in a workgroup.

You need to connect the devices to the corporate wireless network and enroll 100 new Windows 11 devices in Intune.

What should you use?

A. a provisioning package

B. a Group Policy Object (GPO)

C. mobile device management (MDM) automatic enrollment

D. a device configuration policy

Correct Answer: A

Community vote distribution


A (100%)

[Link] 123/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #136 Topic 1

HOTSPOT

You have a Microsoft 365 tenant that uses Microsoft Intune to manage personal and corporate devices. The tenant contains Windows 10 devices

as shown in the following exhibit.

How will Intune classify each device after the devices are enrolled in Intune automatically? To answer, select the appropriate options in the answer

area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 124/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #137 Topic 1

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices. All devices are in the same time zone.

You create an update rings policy and assign the policy to all Windows devices.

On the November 1, you pause the update rings policy.

All devices remain online.

Without further modification to the policy, on which date will the devices next attempt to update?

A. December 1

B. December 6

C. November 15

D. November 22

Correct Answer: B

Community vote distribution


B (100%)

Question #138 Topic 1

You have a Microsoft 365 E5 subscription that contains the devices shown in the following table.

All devices have Microsoft Edge installed.

From the Microsoft Intune admin center, you create a Microsoft Edge Baseline profile named Edge1.

You need to apply Edge1 to all the supported devices.

To which devices should you apply Edge1?

A. Device1 only

B. Device1 and Device2 only

C. Device1, Device2, and Device3 only

D. Device1, Device2, and Device4 only

E. Device1, Device2, Device3, and Device4

Correct Answer: B

Community vote distribution


B (100%)

[Link] 125/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #139 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that uses Microsoft Intune.

You plan to manage Windows updates by using Intune.

You create an update ring for Windows 10 and later and configure the User experience settings for the ring as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

[Link] 126/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

Question #140 Topic 1

You have a Microsoft 365 tenant.

You have devices enrolled in Microsoft Intune.

You assign a conditional access policy named Policy1 to a group named Group1. Policy1 restricts devices marked as noncompliant from

accessing Microsoft OneDrive for Business.

You need to identify which noncompliant devices attempt to access OneDrive for Business.

What should you do?

A. From the Microsoft Entra admin center, review the Conditional Access Insights and Reporting workbook.

B. From the Microsoft Intune admin center, review Device compliance report.

C. From the Microsoft Intune admin center, review the Noncompliant devices report.

D. From the Microsoft Intune admin center, review the Setting compliance report.

Correct Answer: A

Community vote distribution


A (70%) C (22%) 9%

[Link] 127/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #141 Topic 1

HOTSPOT

You use Microsoft Intune to manage Windows 10 devices.

You are designing a reporting solution that will provide reports on the following:

• Compliance policy trends

• Trends in device and user enrollment

• App and operating system version breakdowns of mobile devices

You need to recommend a data source and a data visualization tool for the design.

What should you recommend? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 128/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #142 Topic 1

Your network contains an Active Directory domain. The domain contains 2,000 computers that run Windows 10.

You implement hybrid Azure AD and Microsoft Intune.

You need to automatically register all the existing computers to Azure AD and enroll the computers in Intune. The solution must minimize

administrative effort.

What should you use?

A. an Autodiscover address record

B. a Group Policy object (GPO)

C. an Autodiscover service connection point (SCP)

D. a Windows Autopilot deployment profile

Correct Answer: B

Community vote distribution


B (89%) 6%

[Link] 129/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #143 Topic 1

HOTSPOT

You have two computers that run Windows 10. The computers are enrolled in Microsoft Intune as shown in the following table.

Windows 10 update rings are defined in Intune as shown in the following table.

You assign the update rings as shown in the following table.

What is the effect of the configurations on Computer1 and Computer2? To answer, select the appropriate options in the answer area.

Correct Answer:

[Link] 130/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #144 Topic 1

HOTSPOT

You have 200 computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune.

You need to configure an Intune device configuration profile to meet the following requirements:

• Prevent Microsoft Office applications from launching child processes.

• Block users from transferring files over FTP.

Which two settings should you configure in the Endpoint protection configuration profile? To answer, select the appropriate settings in the answer

area.

NOTE: Each correct selection is worth one point.

[Link] 131/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

Question #145 Topic 1

You have following types of devices enrolled in Microsoft Intune:

• Windows 10

• Android

• iOS

For which types of devices can you create VPN profiles in Microsoft Intune admin center?

A. Windows 10 only

B. Windows 10 and Android only

C. Windows 10 and iOS only

D. Android and iOS only

E. Windows 10, Android, and iOS

Correct Answer: E

Community vote distribution


E (100%)

[Link] 132/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #146 Topic 1

You are creating a device configuration profile in Microsoft Intune.

You need to configure specific OMA-URI settings in the profile.

Which profile type template should you use?

A. Device restrictions (Windows 10 Team)

B. Identity protection

C. Custom

D. Device restrictions

Correct Answer: C

Community vote distribution


C (100%)

[Link] 133/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #147 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that uses Microsoft Intune and contains the users shown in the following table.

You create a policy set named Set1 as shown in the exhibit. (Click the Exhibit tab.)

You enroll devices in Intune as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

[Link] 134/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

Question #148 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that contains 1,000 iOS devices. The devices are enrolled in Microsoft Intune as follows:

• Two hundred devices are enrolled by using the Intune Company Portal.

• Eight hundred devices are enrolled by using Apple Automated Device Enrollment (ADE).

You create an iOS/iPadOS software updates policy named Policy1 that is configured to install iOS/iPadOS 15.5.

How many iOS devices will Policy1 update, and what should you configure to ensure that only iOS/iPadOS 15.5 is installed? To answer, select the

appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 135/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #149 Topic 1

HOTSPOT

Case study

Overview

ADatum Corporation is a consulting company that has a main office in Montreal and branch offices in Seattle and New York.

ADatum has a Microsoft 365 E5 subscription.

Environment

Network Environment

The network contains an on-premises Active Directory domain named [Link]. The domain contains the servers shown in the following table.

ADatum has a hybrid Azure AD tenant named [Link].

Users and Groups

The [Link] tenant contains the users shown in the following table.

All users are assigned a Microsoft Office 365 license and an Enterprise Mobility + Security E3 license.

Enterprise State Roaming is enabled for Group1 and GroupA.

Group1 and Group2 have a Membership type of Assigned.

Devices

ADatum has the Windows 10 devices shown in the following table.

[Link] 136/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

The Windows 10 devices are joined to Azure AD and enrolled in Microsoft Intune.

The Windows 10 devices are configured as shown in the following table.

All the Azure AD joined devices have an executable file named C:\[Link] and a folder named D:\Folder1.

Microsoft Intune Configuration

Microsoft Intune has the compliance policies shown in the following table.

The Automatic Enrollment settings have the following configurations:

• MDM user scope: GroupA

• MAM user scope: GroupB

You have an Endpoint protection configuration profile that has the following Controlled folder access settings:

• Name: Protection1

• Folder protection: Enable

• List of apps that have access to protected folders: C:\*\[Link]

• List of additional folders that need to be protected: D:\Folder1

• Assignments:

- Included groups: Group2, GroupB

Windows Autopilot Configuration

[Link] 137/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

ADatum has a Windows Autopilot deployment profile configured as shown in the following exhibit.

Currently, there are no devices deployed by using Windows Autopilot.

The Intune connector for Active Directory is installed on Server1.

Requirements

Planned Changes

ADatum plans to implement the following changes:

[Link] 138/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

• Purchase a new Windows 10 device named Device6 and enroll the device in Intune

• New computers will be deployed by using Windows Autopilot and will be hybrid Azure AD joined.

• Deployed a network boundary configuration profile that will have the following settings:

- Name: Boundary1

- Network boundary: [Link]/24

- Scope tags: Tag1

- Assignments:

- Included groups: Group1, Group2

• Deploy two VPN configuration profiles named Connection1 and Connection2 that will have the following settings:

- Name: Connection1

- Connection name: VPN1

- Connection type: L2TP

- Assignments:

- Included groups: Group1, Group2, GroupA

- Excluded groups: --

- Name: Connection2

- Connection name: VPN2

- Connection type: IKEv2

- Assignments:

- Included groups: GroupA

- Excluded groups: GroupB

Technical Requirements

ADatum must meet the following technical requirements:

• Users in GroupA must be able to deploy new computers.

• Administrative effort must be minimized.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 139/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #150 Topic 1

Case study -

Overview -

ADatum Corporation is a consulting company that has a main office in Montreal and branch offices in Seattle and New York.

ADatum has a Microsoft 365 E5 subscription.

Environment -

Network Environment -

The network contains an on-premises Active Directory domain named [Link]. The domain contains the servers shown in the following table.

ADatum has a hybrid Azure AD tenant named [Link].

Users and Groups -

The [Link] tenant contains the users shown in the following table.

All users are assigned a Microsoft Office 365 license and an Enterprise Mobility + Security E3 license.

Enterprise State Roaming is enabled for Group1 and GroupA.

Group1 and Group2 have a Membership type of Assigned.

Devices -

ADatum has the Windows 10 devices shown in the following table.

The Windows 10 devices are joined to Azure AD and enrolled in Microsoft Intune.

The Windows 10 devices are configured as shown in the following table.

[Link] 140/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

All the Azure AD joined devices have an executable file named C:\[Link] and a folder named D:\Folder1.

Microsoft Intune Configuration -

Microsoft Intune has the compliance policies shown in the following table.

The Automatic Enrollment settings have the following configurations:

• MDM user scope: GroupA

• MAM user scope: GroupB

You have an Endpoint protection configuration profile that has the following Controlled folder access settings:

• Name: Protection1

• Folder protection: Enable

• List of apps that have access to protected folders: C:\*\[Link]

• List of additional folders that need to be protected: D:\Folder1

• Assignments:

- Included groups: Group2, GroupB

Windows Autopilot Configuration -

ADatum has a Windows Autopilot deployment profile configured as shown in the following exhibit.

[Link] 141/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Currently, there are no devices deployed by using Windows Autopilot.

The Intune connector for Active Directory is installed on Server1.

Requirements -

Planned Changes -

ADatum plans to implement the following changes:

• Purchase a new Windows 10 device named Device6 and enroll the device in Intune

• New computers will be deployed by using Windows Autopilot and will be hybrid Azure AD joined.

• Deployed a network boundary configuration profile that will have the following settings:

- Name: Boundary1

[Link] 142/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

- Network boundary: [Link]/24

- Scope tags: Tag1

- Assignments:

- Included groups: Group1, Group2

• Deploy two VPN configuration profiles named Connection1 and Connection2 that will have the following settings:

- Name: Connection1

- Connection name: VPN1

- Connection type: L2TP

- Assignments:

- Included groups: Group1, Group2, GroupA

- Excluded groups: --

- Name: Connection2

- Connection name: VPN2

- Connection type: IKEv2

- Assignments:

- Included groups: GroupA

- Excluded groups: GroupB

Technical Requirements -

ADatum must meet the following technical requirements:

• Users in GroupA must be able to deploy new computers.

• Administrative effort must be minimized.

You need to ensure that computer objects can be created as part of the Windows Autopilot deployment. The solution must meet the technical

requirements.

To what should you grant the right to create the computer objects?

A. Server1

B. DC1

C. GroupA

D. Server2

Correct Answer: A

Community vote distribution


A (88%) 13%

[Link] 143/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #151 Topic 1

HOTSPOT -

Case study -

Overview -

ADatum Corporation is a consulting company that has a main office in Montreal and branch offices in Seattle and New York.

ADatum has a Microsoft 365 E5 subscription.

Environment -

Network Environment -

The network contains an on-premises Active Directory domain named [Link]. The domain contains the servers shown in the following table.

ADatum has a hybrid Azure AD tenant named [Link].

Users and Groups -

The [Link] tenant contains the users shown in the following table.

All users are assigned a Microsoft Office 365 license and an Enterprise Mobility + Security E3 license.

Enterprise State Roaming is enabled for Group1 and GroupA.

Group1 and Group2 have a Membership type of Assigned.

Devices -

ADatum has the Windows 10 devices shown in the following table.

The Windows 10 devices are joined to Azure AD and enrolled in Microsoft Intune.

[Link] 144/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

The Windows 10 devices are configured as shown in the following table.

All the Azure AD joined devices have an executable file named C:\[Link] and a folder named D:\Folder1.

Microsoft Intune Configuration -

Microsoft Intune has the compliance policies shown in the following table.

The Automatic Enrollment settings have the following configurations:

• MDM user scope: GroupA

• MAM user scope: GroupB

You have an Endpoint protection configuration profile that has the following Controlled folder access settings:

• Name: Protection1

• Folder protection: Enable

• List of apps that have access to protected folders: C:\*\[Link]

• List of additional folders that need to be protected: D:\Folder1

• Assignments:

- Included groups: Group2, GroupB

Windows Autopilot Configuration -

ADatum has a Windows Autopilot deployment profile configured as shown in the following exhibit.

[Link] 145/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Currently, there are no devices deployed by using Windows Autopilot.

The Intune connector for Active Directory is installed on Server1.

Requirements -

Planned Changes -

ADatum plans to implement the following changes:

• Purchase a new Windows 10 device named Device6 and enroll the device in Intune

• New computers will be deployed by using Windows Autopilot and will be hybrid Azure AD joined.

• Deployed a network boundary configuration profile that will have the following settings:

- Name: Boundary1

[Link] 146/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

- Network boundary: [Link]/24

- Scope tags: Tag1

- Assignments:

- Included groups: Group1, Group2

• Deploy two VPN configuration profiles named Connection1 and Connection2 that will have the following settings:

- Name: Connection1

- Connection name: VPN1

- Connection type: L2TP

- Assignments:

- Included groups: Group1, Group2, GroupA

- Excluded groups: --

- Name: Connection2

- Connection name: VPN2

- Connection type: IKEv2

- Assignments:

- Included groups: GroupA

- Excluded groups: GroupB

Technical Requirements -

ADatum must meet the following technical requirements:

• Users in GroupA must be able to deploy new computers.

• Administrative effort must be minimized.

You implement the planned changes for Connection1 and Connection2.

How many VPN connections will there be for User1 when the user signs in to Device1 and Device2? To answer, select the appropriate options in

the answer area.

NOTE: Each correct selection is worth one point.

[Link] 147/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

[Link] 148/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #152 Topic 1

Case study -

Overview -

ADatum Corporation is a consulting company that has a main office in Montreal and branch offices in Seattle and New York.

ADatum has a Microsoft 365 E5 subscription.

Environment -

Network Environment -

The network contains an on-premises Active Directory domain named [Link]. The domain contains the servers shown in the following table.

ADatum has a hybrid Azure AD tenant named [Link].

Users and Groups -

The [Link] tenant contains the users shown in the following table.

All users are assigned a Microsoft Office 365 license and an Enterprise Mobility + Security E3 license.

Enterprise State Roaming is enabled for Group1 and GroupA.

Group1 and Group2 have a Membership type of Assigned.

Devices -

ADatum has the Windows 10 devices shown in the following table.

The Windows 10 devices are joined to Azure AD and enrolled in Microsoft Intune.

The Windows 10 devices are configured as shown in the following table.

[Link] 149/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

All the Azure AD joined devices have an executable file named C:\[Link] and a folder named D:\Folder1.

Microsoft Intune Configuration -

Microsoft Intune has the compliance policies shown in the following table.

The Automatic Enrollment settings have the following configurations:

• MDM user scope: GroupA

• MAM user scope: GroupB

You have an Endpoint protection configuration profile that has the following Controlled folder access settings:

• Name: Protection1

• Folder protection: Enable

• List of apps that have access to protected folders: C:\*\[Link]

• List of additional folders that need to be protected: D:\Folder1

• Assignments:

- Included groups: Group2, GroupB

Windows Autopilot Configuration -

ADatum has a Windows Autopilot deployment profile configured as shown in the following exhibit.

[Link] 150/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Currently, there are no devices deployed by using Windows Autopilot.

The Intune connector for Active Directory is installed on Server1.

Requirements -

Planned Changes -

ADatum plans to implement the following changes:

• Purchase a new Windows 10 device named Device6 and enroll the device in Intune

• New computers will be deployed by using Windows Autopilot and will be hybrid Azure AD joined.

• Deployed a network boundary configuration profile that will have the following settings:

- Name: Boundary1

[Link] 151/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

- Network boundary: [Link]/24

- Scope tags: Tag1

- Assignments:

- Included groups: Group1, Group2

• Deploy two VPN configuration profiles named Connection1 and Connection2 that will have the following settings:

- Name: Connection1

- Connection name: VPN1

- Connection type: L2TP

- Assignments:

- Included groups: Group1, Group2, GroupA

- Excluded groups: --

- Name: Connection2

- Connection name: VPN2

- Connection type: IKEv2

- Assignments:

- Included groups: GroupA

- Excluded groups: GroupB

Technical Requirements -

ADatum must meet the following technical requirements:

• Users in GroupA must be able to deploy new computers.

• Administrative effort must be minimized.

Which user can enroll Device6 in Intune?

A. User4 and User1 only

B. User4 and User2 only

C. User4, User1, and User2 only

D. User1, User2, User3, and User4

Correct Answer: A

Community vote distribution


A (75%) D (21%) 4%

[Link] 152/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #153 Topic 1

You have a Microsoft 365 subscription that contains 1,000 iOS devices and includes Microsoft Intune.

You need to prevent the printing of corporate data from managed apps on the devices.

What should you configure?

A. an app configuration policy

B. a security baseline

C. an app protection policy

D. an iOS app provisioning profile

Correct Answer: C

Community vote distribution


C (100%)

Question #154 Topic 1

You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

In the Microsoft 365 Apps admin center, you create a Microsoft Office customization.

Which users can download the Office customization file from the admin center?

A. Admin3 only

B. Admin1 and Admin3 only

C. Admin3 and Admin4 only

D. Admin1, Admin2, and Admin3 only

E. Admin1, Admin2, Admin3, Admin4

Correct Answer: C

Community vote distribution


C (83%) D (17%)

[Link] 153/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #155 Topic 1

You have a Microsoft 365 E5 subscription.

You need to download a report that lists all the devices that are NOT enrolled in Microsoft Intune and are assigned an app protection policy.

What should you select in the Microsoft Intune admin center?

A. Reports, and then Device compliance

B. Apps, and then App protection policies

C. Devices, and then Monitor

D. Apps, and then Monitor

Correct Answer: D

Community vote distribution


D (57%) B (21%) 11% 11%

Question #156 Topic 1

You have a Microsoft 365 tenant that contains the objects shown in the following table.

In the Microsoft Intune admin center, you are creating a Microsoft 365 Apps app named App1.

To which objects can you assign App1?

A. Group3 and Group4 only

B. Admin1, Group3, and Group4 only

C. Group1, Group3, and Group4 only

D. Group1, Group2, Group3, and Group4 only

E. Admin1, Group1, Group2, Group3, and Group4

Correct Answer: C

Community vote distribution


C (100%)

[Link] 154/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #157 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription.

You create an app protection policy for Android device named Policy1 as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 155/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #158 Topic 1

You have a Microsoft 365 subscription that includes Microsoft Intune.

You have 500 corporate-owned Android devices enrolled as fully managed devices.

You need to prepare an app named App1 for deployment to the devices.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A. From the Intune Company Portal, download App1.

B. Sync App1 with Intune.

C. From the Managed Google Play Store, approve App1.

D. Create an OEMConfig profile.

Correct Answer: BC

Community vote distribution


BC (83%) AC (17%)

Question #159 Topic 1

You have the Windows 10 devices shown in the following table.

You plan to upgrade the devices to Windows 11 Enterprise.

On which devices can you perform a direct in-place upgrade to Windows 11 Enterprise?

A. Device3 only

B. Device3 and Device 4 only

C. Device2, Device3, and Device4 only

D. Device1, Device3, and Device4 only

E. Device1, Device2, Device3, and Device4 only

Correct Answer: B

Community vote distribution


B (48%) A (48%)

[Link] 156/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #160 Topic 1

HOTSPOT

Your network contains an on-premises Active Directory domain named [Link] that syncs to Azure AD.

A user named User1 uses the domain-joined devices shown in the following table.

In the Microsoft Entra admin center, you assign a Windows 11 Enterprise E5 license to User1.

You need to identify what will occur when User1 next signs in to the devices.

What should you identify for each device? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 157/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #161 Topic 1

HOTSPOT

You have a Microsoft Deployment Toolkit (MDT) deployment share named Share1.

You add Windows 10 images to Share1 as shown in the following table.

Which images can be used in the Standard Client Task Sequence, and which images can be used in the Standard Client Upgrade Task Sequence?

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 158/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #162 Topic 1

DRAG DROP

You have a Microsoft 365 subscription that uses Microsoft Intune.

You plan to use Windows Autopilot to provision 25 Windows 11 devices.

You need to meet the following requirements during device provisioning:

• Display the progress of app and profile deployments.

• Join the devices to Azure AD.

What should you configure to meet each requirement? To answer, drag the appropriate settings to the correct requirements. Each setting may be

used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 159/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #163 Topic 1

Your company has a Remote Desktop Gateway (RD Gateway).

You have a server named Server1 that is accessible by using Remote Desktop Services (RDS) through the RD Gateway.

You need to configure a Remote Desktop connection to connect through the gateway.

Which setting should you configure?

A. Connect from anywhere

B. Server authentication

C. Connection settings

D. Local devices and resources

Correct Answer: A

Community vote distribution


A (65%) C (35%)

Question #164 Topic 1

You have a Microsoft Deployment Toolkit (MDT) deployment share.

You plan to deploy Windows 11 by using the Standard Client Task Sequence template.

You need to modify the task sequence to perform the following actions:

• Format disks to support Unified Extensible Firmware Interface (UEFI).

• Create a recovery partition.

Which phase of the task sequence should you modify?

A. Preinstall

B. PostInstall

C. Install

D. Initialization

Correct Answer: A

Community vote distribution


A (100%)

[Link] 160/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #165 Topic 1

DRAG DROP

Your network contains an Active Directory domain.

You install the Microsoft Deployment Toolkit (MDT) on a server.

You have a custom image of Windows 11.

You need to deploy the image to 100 devices by using MDT.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and

arrange them in the correct order.

Correct Answer:

Question #166 Topic 1

You have the Microsoft Deployment Toolkit (MDT) installed.

You install and customize Windows 11 on a reference computer.

You need to capture an image of the reference computer and ensure that the image can be deployed to multiple computers.

Which command should you run before you capture the image?

A. dism

B. wpeinit

C. sysprep

D. bcdedit

Correct Answer: C

Community vote distribution


C (100%)

[Link] 161/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #167 Topic 1

Your network contains an on-premises Active Directory domain. The domain contains two computers named Computer1 and Computer2 that run

Windows 10.

You install Windows Admin Center on Computer1.

You need to manage Computer2 from Computer1 by using Windows Admin Center.

What should you do on Computer2?

A. Update the TrustedHosts list.

B. Run the Enable-PSRemoting cmdlet.

C. Allow Windows Remote Management (WinRM) through the Microsoft Defender firewall.

D. Add an inbound Microsoft Defender Firewall rule.

Correct Answer: C

Community vote distribution


C (57%) B (43%)

[Link] 162/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #168 Topic 1

HOTSPOT

You have a hybrid Azure AD tenant.

You configure a Windows Autopilot deployment profile as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

[Link] 163/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

Question #169 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices.

You plan to create Windows 11 device builds for the marketing and research departments. The solution must meet the requirements:

• Marketing department devices must support Windows Update for Business.

• Research department devices must have support for feature update versions for up to 36 months from release.

What is the minimum Windows 11 edition required for each department? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 164/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #170 Topic 1

You have an Azure AD tenant named [Link].

You plan to use Windows Autopilot to configure the Windows 10 devices shown in the following table.

Which devices can be configured by using Windows Autopilot self-deploying mode?

A. Device2 only

B. Device3 only

C. Device1 and Device3 only

D. Device1, Device2, and Device3

Correct Answer: B

Community vote distribution


B (100%)

[Link] 165/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #171 Topic 1

HOTSPOT

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant.

You have a Microsoft 365 subscription.

You plan to use Windows Autopilot to deploy new Windows devices.

You plan to create a deployment profile.

You need to ensure that the deployment meets the following requirements:

• Devices must be joined to AD DS regardless of their current working location.

• Users in the marketing department must have a line-of-business (LOB) app installed during the deployment.

The solution must minimize administrative effort.

What should you do for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 166/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #172 Topic 1

You have 200 computers that run Windows 10 and are joined to an Active Directory domain.

You need to enable Windows Remote Management (WinRM) on all the computers by using Group Policy.

Which three actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A. Enable the Allow Remote Shell access setting.

B. Enable the Allow remote server management through WinRM setting.

C. Set the Startup Type of the Windows Remote Management (WS-Management) service to Automatic.

D. Enable the Windows Defender Firewall: Allow inbound Remote Desktop exceptions setting.

E. Set the Startup Type of the Remote Registry service to Automatic.

F. Enable the Windows Defender Firewall: Allow inbound remote administration exception setting.

Correct Answer: BCF

Community vote distribution


BCF (100%)

Question #173 Topic 1

You have a Microsoft 365 Business Standard subscription and 100 Windows 10 Pro devices.

You purchase a Microsoft 365 E5 subscription.

You need to upgrade the Windows 10 Pro devices to Windows 10 Enterprise. The solution must minimize administrative effort.

Which upgrade method should you use?

A. Windows Autopilot

B. a Microsoft Deployment Toolkit (MDT) lite-touch deployment

C. Subscription Activation

D. an in-place upgrade by using Windows installation media

Correct Answer: C

Community vote distribution


C (82%) D (18%)

[Link] 167/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #174 Topic 1

HOTSPOT

You have devices that are not rooted enrolled in Microsoft Intune as shown in the following table.

The devices are members of a group named Group1.

In Intune, you create a device compliance location that has the following configurations:

• Name: Network1

• IPv4 range: [Link]/16

In Intune, you create a device compliance policy for the Android platform. The policy has the following configurations:

• Name: Policy1

• Device health: Rooted devices: Block

• Locations: Location: Network1

• Mark device noncompliant: Immediately

• Assigned: Group1

The Intune device compliance policy has the following configurations:

• Mark devices with no compliance policy assigned as: Compliant

• Enhanced jailbreak detection: Enabled

• Compliance status validity period (days): 20

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 168/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #175 Topic 1

You need to implement mobile device management (MDM) for personal devices that run Windows 11. The solution must meet the following

requirements:

• Ensure that you can manage the personal devices by using Microsoft Intune.

• Ensure that users can access company data seamlessly from their personal devices.

• Ensure that users can only sign in to their personal devices by using their personal account.

What should you use to add the devices to Azure AD?

A. Azure AD registered

B. hybrid Azure AD join

C. Azure AD joined

Correct Answer: A

Community vote distribution


A (85%) C (15%)

[Link] 169/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #176 Topic 1

HOTSPOT

You have a Microsoft 365 subscription.

All computers are enrolled in Microsoft Intune.

You have business requirements for securing your Windows 11 environment as shown in the following table.

What should you implement to meet each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 170/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #177 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that contains two security groups named Group1 and Group2. Microsoft 365 uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices.

You need to assign roles in Intune to meet the following requirements:

• The members of Group1 must manage Intune roles and assignments.

• The members of Group2 must assign existing apps and policies to users and devices.

The solution must follow the principle of least privilege.

Which role should you assign to each group? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 171/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #178 Topic 1

HOTSPOT

You have devices enrolled in Microsoft Intune as shown in the following table.

Intune includes the device compliance policies shown in the following table.

The device compliance policies has the assignments shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 172/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #179 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that contains a user named User1. The subscription contains devices enrolled in Microsoft Intune as

shown in the following table.

Microsoft Edge is available on all the devices.

Intune has the device compliance policies shown in the following table.

The Compliance policy settings are configured as shown in the exhibit. (Click the Exhibit tab.)

You create the following Conditional Access policy:

• Name: Policy1

• Assignments

o Users and groups: User1

o Cloud apps or actions: Office 365 SharePoint Online

• Access controls

o Grant: Require device to be marked as compliant

• Enable policy: On

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

[Link] 173/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

NOTE: Each correct selection is worth one point.

Correct Answer:

Question #180 Topic 1

You have an Azure AD tenant named [Link].

You need to ensure that users are not added automatically to the local Administrators group when they join their Windows 11 device to

[Link].

What should you configure?

A. Windows Autopilot

B. provisioning packages for Windows

C. Security defaults in Azure AD

D. Device settings in Azure AD

Correct Answer: D

Community vote distribution


D (58%) A (42%)

[Link] 174/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #181 Topic 1

Your company has devices enrolled in Microsoft Intune as shown in the following table.

In Microsoft Intune admin center, you define the company’s network as a location named Location1.

Which devices can use network location-based compliance policies?

A. Device1 only

B. Device2 only

C. Device1 and Device2 only

D. Device2 and Device3 only

E. Device1, Device2, and Device3

Correct Answer: E

Community vote distribution


E (90%) 5%

Question #182 Topic 1

You have an Azure subscription.

You have an on-premises Windows 11 device named Device1.

You plan to monitor Device1 by using Azure Monitor.

You create a data collection rule (DCR) named DCR1 in the subscription.

To what should you associate DCR1?

A. Azure Network Watcher

B. Device1

C. a Log Analytics workspace

D. a Monitored Object

Correct Answer: D

Community vote distribution


D (43%) C (40%) B (17%)

[Link] 175/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #183 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices.

You need to configure an update ring that meets the following requirements:

• Fixes and improvements to existing Windows functionality can be deferred for 14 days but will install automatically seven days after that date.

• The installation of new Windows features can be deferred for 90 days but will install automatically 10 days after that date.

• Devices must restart automatically three days after an update is installed.

How should you configure the update ring? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

[Link] 176/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

[Link] 177/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #184 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription.

You need to review and implement Microsoft 365 Defender device onboarding. The solution must meet the following requirements:

• View onboarded devices that have the Chromium-based version for Microsoft Edge installed.

• Download an onboarding package for a Windows 11 device.

• Minimize administrative effort.

Which two settings should you use in the Microsoft 365 Defender portal? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

[Link] 178/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

[Link] 179/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #185 Topic 1

You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Azure AD joined and are enrolled in

Microsoft Intune.

You plan to manage Microsoft Defender Antivirus on the computers.

You need to prevent users from disabling Microsoft Defender Antivirus.

What should you do?

A. From the Microsoft Intune admin center, create a security baseline.

B. From the Microsoft 365 Defender portal, enable tamper protection.

C. From the Microsoft Intune admin center, create an account protection policy.

D. From the Microsoft Intune admin center, create an endpoint detection and response (EDR) policy.

Correct Answer: B

Community vote distribution


B (100%)

[Link] 180/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #186 Topic 1

HOTSPOT

You have 1,000 computers that run Windows 10 and are members of an Active Directory domain.

You need to capture the event logs from the computers to Azure.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 181/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #187 Topic 1

You have a computer named Computer5 that has Windows 10 installed.

You create a Windows PowerShell script named config.ps1.

You need to ensure that config.ps1 runs after feature updates are installed on Computer5.

Which file should you modify on Computer5?

A. [Link]

B. [Link]

C. [Link]

D. [Link]

Correct Answer: B

Community vote distribution


B (100%)

[Link] 182/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #188 Topic 1

HOTSPOT

You have a Microsoft 365 tenant and an internal certification authority (CA).

You need to use Microsoft Intune to deploy the root CA certificate to managed devices.

Which type of Intune policy and profile type template should you use? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 183/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #189 Topic 1

HOTSPOT

Your company uses Microsoft Defender for Endpoint. Microsoft Defender for Endpoint includes the device groups shown in the following table.

You onboard a computer to Microsoft Defender for Endpoint as shown in the following exhibit.

What is the effect of the Microsoft Defender for Endpoint configuration? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 184/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #190 Topic 1

You manage 1,000 devices by using Microsoft Intune.

You review the Device compliance trends report.

For how long will the report display trend data?

A. 30 days

B. 60 days

C. 90 days

D. 365 days

Correct Answer: B

Community vote distribution


B (54%) A (46%)

Question #191 Topic 1

You have a Microsoft 365 E5 subscription that contains 100 iOS devices enrolled in Microsoft Intune.

You need to ensure that notifications of iOS updates are deferred for 30 days after the updates are released.

What should you create?

A. an iOS app provisioning profile

B. a device configuration profile based on the Device features templates

C. an update policy for iOS/iPadOS

D. a device configuration profile based on the Device restrictions template

Correct Answer: D

Community vote distribution


D (75%) C (25%)

[Link] 185/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #192 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that uses Microsoft Intune and contains 100 Windows 10 devices.

You need to create Intune configuration profiles to perform the following actions on the devices:

• Deploy a custom Start layout.

• Rename the local Administrator account.

Which profile type template should you use for each action? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 186/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #193 Topic 1

HOTSPOT

You have a Microsoft 365 subscription.

You plan to enable Microsoft Intune enrollment for the following types of devices:

• Existing Windows 11 devices managed by using Configuration Manager

• Personal iOS devices

The solution must minimize user disruption.

Which enrollment method should you use for each device type? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 187/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #194 Topic 1

You have a Windows 10 device named Device1 that is joined to Active Directory and enrolled in Microsoft Intune.

Device1 is managed by using Group Policy and Intune.

You need to ensure that the Intune settings override the Group Policy settings.

What should you configure?

A. a device configuration profile

B. a device compliance policy

C. an MDM Security Baseline profile

D. a Group Policy Object (GPO)

Correct Answer: A

Community vote distribution


A (100%)

[Link] 188/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #195 Topic 1

HOTSPOT

You have an Azure AD Premium P2 subscription that contains the users shown in the following table.

You purchase the devices shown in the following table.

You configure automatic mobile device management (MDM) and mobile application management (MAM) enrollment by using the following

settings:

• MDM user scope: Group1

• MAM user scope: Group2

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 189/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #196 Topic 1

HOTSPOT

You have the MDM Security Baseline profile shown in the MDM exhibit. (Click the MDM tab.)

You have the ASR Endpoint Security profile shown in the ASR exhibit. (Click the ASR tab.)

[Link] 190/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

You plan to deploy both profiles to devices enrolled in Microsoft Intune.

You need to identify how the following settings will be configured on the devices:

• Block Office applications from creating executable content

• Block Win32 API calls from Office macro

Currently, the settings are disabled locally on each device.

What are the effective settings on the devices? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

[Link] 191/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

[Link] 192/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #197 Topic 1

DRAG DROP

You have an on-premises Active Directory domain that syncs to Azure AD tenant.

The tenant contains computers that run Windows 10. The computers are hybrid Azure AD joined and enrolled in Microsoft Intune.

The Microsoft Office settings on the computers are configured by using a Group Policy Object (GPO).

You need to migrate the GPO to Intune.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and

arrange them in the correct order.

Correct Answer:

[Link] 193/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #198 Topic 1

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains 100 client computers that run Windows 10.

Currently, your company does NOT have a deployment infrastructure.

The company purchases Windows 11 licenses through a volume licensing agreement.

You need to recommend how to upgrade the computers to Windows 11. The solution must minimize licensing costs.

What should you include in the recommendation?

A. Windows Autopilot

B. Configuration Manager

C. subscription activation

D. Microsoft Deployment Toolkit (MDT)

Correct Answer: D

Community vote distribution


D (90%) 5%

Question #199 Topic 1

You have a Microsoft 365 subscription that contains a user named User1 and uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices that run Windows 11.

You need to remove User1 from the local Administrators group on all enrolled devices.

What should you configure?

A. a device compliance policy

B. an account protection policy

C. an app configuration policy

Correct Answer: B

Community vote distribution


B (100%)

[Link] 194/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #200 Topic 1

HOTSPOT

You have computers that run Windows 10 and are configured by using Windows Autopilot.

A user performs the following tasks on a computer named Computer1:

• Creates a VPN connection to the corporate network

• Installs a Microsoft Store app named App1

• Connections to a Wi-Fi network

You perform a Windows Autopilot Reset on Computer1.

What will be the state of the computer when the user signs in? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 195/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #201 Topic 1

HOTSPOT

You have a Microsoft Deployment Toolkit (MDT) solution that is used to manage Windows 11 deployment tasks.

MDT contains the operating system images shown in the following table.

You need to perform a Windows 11-place upgrade on several computers that run Windows 10.

From the Deployment Workbench, you open the New Task Sequence Wizard.

You need to identify which task sequence template and which operating system image to use for the task sequence. The solution must minimize

administrative effort.

What should you identify? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 196/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #202 Topic 1

You have a workgroup computer named Client1 that runs Windows 11 and connects to a public network.

You need to enable PowerShell remoting on Client1. The solution must ensure that PowerShell remoting connections are accepted from the local

subnet only.

Which PowerShell command should you run?

A. Set-PSSessionConfiguration –AccessMode Local

B. Enable-PSRemoting –SkipNetworkProfileCheck

C. Enable-PSRemoting –Force

D. Set-NetFirewallRule –Name “WINRM-HTTP-In-TCP-PUBLIC” –RemoteAddress Any

Correct Answer: B

Community vote distribution


B (100%)

[Link] 197/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #203 Topic 1

HOTSPOT

You have a Microsoft 365 subscription.

You need to enable passwordless authentication for all users. The solution must meet the following requirements:

• Users in the research department cannot use mobile devices and must authenticate from unmanaged Linux devices by using an alternative

method.

• To access services, users in the sales department must authenticate by using their mobile phone.

• Administrative effort must be minimized.

Which authentication method should you use for each department? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 198/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #204 Topic 1

HOTSPOT

You have a Microsoft 365 subscription.

Users have iOS devices that are not enrolled in Microsoft Intune.

You create an app protection policy for the Microsoft Outlook app as shown in the exhibit. (Click the Exhibit tab.)

You need to configure the policy to meet the following requirements:

• Prevent the users from using the Outlook app if the operating system version is less than 12.0.0.

• Require the users to use an alphanumeric passcode to access the Outlook app.

What should you configure in an app protection policy for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

[Link] 199/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

Question #205 Topic 1

You manage 1,000 computers that run Windows 10. All the computers are enrolled in Microsoft Intune. You manage the servicing channel settings

of the computers by using Intune.

You need to review the servicing status of a computer.

What should you do?

A. From Device configuration – Profiles, view the device status.

B. From Software updates, view the Per update ring deployment state.

C. From Software updates, view the audit logs.

D. From Device compliance, view the device compliance.

Correct Answer: B

Community vote distribution


B (100%)

[Link] 200/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #206 Topic 1

HOTSPOT

Your network contains an Active Directory domain. Active Directory is synced with Azure AD.

There are 500 Active Directory domain-joined computers that run Windows 10 and are enrolled in Microsoft Intune.

You plan to implement Microsoft Defender Exploit Guard.

You need to create a custom Microsoft Defender Exploit Guard policy, and then distribute the policy to all the computers.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 201/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #207 Topic 1

You have a Microsoft Intune subscription associated to an Azure AD tenant named [Link].

Users use one of the following three suffixes when they sign in to the tenant: [Link], [Link], or [Link].

You need to ensure that the users are NOT required to specify the mobile device management (MDM) enrollment URL as part of the enrollment

process. The solution must minimize the number of changes.

Which DNS records do you need?

A. one TXT record only

B. three CNAME records

C. three TXT records

D. one CNAME record only

Correct Answer: B

Community vote distribution


B (90%) 10%

[Link] 202/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #208 Topic 1

HOTSPOT

You have a Microsoft 365 subscription.

You plan to enroll devices in Microsoft Intune that have the platforms and versions shown in the following table.

You need to configure device enrollment to meet the following requirements:

• Ensure that only devices that have approved platforms and versions can enroll in Microsoft Intune.

• Ensure that devices are added to Azure AD groups based on a selection made by users during the enrollment.

Which device enrollment setting should you configure for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 203/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #209 Topic 1

HOTSPOT

You have a Microsoft 365 tenant that uses Microsoft Intune and contains the devices shown in the following table.

In Microsoft Intune Endpoint security, you need to configure a disk encryption policy for each device.

Which encryption type should you use for each device, and which role-based access control (RBAC) role in Intune should you use to manage the

encryption keys? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 204/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #210 Topic 1

DRAG DROP

Your company has a Microsoft 365 E5 tenant.

All the devices of the company are enrolled in Microsoft Intune.

You need to create advanced reports by using custom queries and visualizations from raw Microsoft Intune data.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and

arrange them in the correct order.

Correct Answer:

[Link] 205/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #211 Topic 1

DRAG DROP

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.

You plan to onboard the following types of devices to Defender for Endpoint:

• macOS

• Linux Server

What should you use to onboard each device? To answer, drag the appropriate tools to the correct device types. Each tool may be used once, more

than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Correct Answer:

Question #212 Topic 1

You have a Windows 10 device named Computer1 enrolled in Microsoft Intune.

You need to configure Computer1 as a public workstation that will run a single customer-facing, full-screen application.

Which configuration profile type template should you use in Microsoft Intune admin center?

A. Shared multi-user device

B. Device restrictions

C. Kiosk

D. Endpoint protection

Correct Answer: C

Community vote distribution


C (100%)

[Link] 206/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #213 Topic 1

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to manage Windows 11 devices.

You create a new policy set named Set and add five device configuration profiles for Windows 10 and later.

You create a device compliance policy named Policy1.

You need to ensure that when users are assigned the device configuration profiles in Set1, they are always assigned Policy1 also.

What should you configure?

A. the assignments of Policy1

B. the Policy1 configurations

C. the assignments of Set1

D. the Set1 configurations

Correct Answer: D

Community vote distribution


D (65%) C (29%) 6%

[Link] 207/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #214 Topic 1

HOTSPOT

Your network contains an on-premises Active Directory domain that contains the locations shown in the following table.

In Microsoft Intune, you enroll the Windows 10 devices shown in the following table.

You have a Delivery Optimization device configuration profile applied to all the devices. The profile is configured as shown in the following exhibit.

From which devices can Device1 and Device2 get updates? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

[Link] 208/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

Question #215 Topic 1

You have 200 computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune.

You need to enable self-service password reset on the sign-in screen.

Which settings should you configure from the Microsoft Intune admin center?

A. Device configuration

B. Device enrollment

C. Conditional access

D. Device compliance

Correct Answer: A

Community vote distribution


A (100%)

[Link] 209/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #216 Topic 1

HOTSPOT

You have a Microsoft 365 tenant that uses Microsoft Intune.

From the Microsoft Intune admin center, you plan to create a baseline to monitor the Startup score and the App reliability score of enrolled

Windows 10 devices.

You need to identify which tool to use to create the baseline and the minimum number of devices required to create the baseline.

What should you identify? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 210/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #217 Topic 1

You are implementing Microsoft Intune Suite.

You enroll devices in Intune as shown in the following table.

The performance of which devices can be analyzed by using Endpoint analytics?

A. Device1 only

B. Device1 and Device2 only

C. Device1, Device2, and Device3 only

D. Device1, Device2, and Device4 only

E. Device1, Device2, Device3, and Device4

Correct Answer: B

Community vote distribution


B (100%)

Question #218 Topic 1

You have the devices shown in the following table.

You plan to implement Microsoft Defender for Endpoint.

You need to identify which devices can be onboarded to Microsoft Defender for Endpoint.

What should you identify?

A. Device1 only

B. Device2 only

C. Device1, Device2 only

D. Device1, Device2, and Device3 only

E. Device1, Device2, Device3, and Device4

Correct Answer: D

Community vote distribution


D (71%) E (29%)

[Link] 211/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #219 Topic 1

You have a Microsoft 365 subscription.

You use app protection policies to protect corporate data on Android devices.

You need to ensure that any user connecting from an Android device can only access the corporate data if they connect from an app that supports

mobile application management (MAM).

What should you configure?

A. an app configuration policy

B. a Conditional Access policy

C. a device configuration profile

D. a device compliance policy

Correct Answer: B

Community vote distribution


B (100%)

Question #220 Topic 1

Your company has a Microsoft 365 subscription.

All the users in the finance department own personal devices that run iOS or Android. All the devices are enrolled in Microsoft Intune.

The finance department adds new users each month.

The company develops a mobile application named App1 for the finance department users.

You need to ensure that only the finance department users can download App1.

What should you do first?

A. Register App1 in Azure AD.

B. Add App1 to the vendor stores for iOS and Android applications.

C. Add App1 to a Microsoft Deployment Toolkit (MDT) deployment share.

D. Add App1 to Intune.

Correct Answer: D

Community vote distribution


D (100%)

[Link] 212/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #221 Topic 1

DRAG DROP

You have a Microsoft 365 subscription that contains the devices shown in the following table.

You need to configure the Microsoft Edge settings for each device.

What should you use? To answer, drag the appropriate Intune features to the correct devices. Each feature may be used once, more than once, or

not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 213/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #222 Topic 1

You have a Microsoft 365 E5 subscription that uses Microsoft Intune. The subscription contains the users shown in the following table.

Group2 and Group3 are members of Group1.

All the users use Microsoft Excel.

From the Microsoft Intune admin center, you create the policies shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 214/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #223 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription that contains a computer named Computer1 that runs Windows 11. Computer1 is enrolled in Microsoft

Intune.

You need to deploy an app named App1 to Computer1. The App1 installation will use multiple files.

What should you use to package App1, and which file format will be used? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 215/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #224 Topic 1

You have a Microsoft 365 tenant that contains the devices shown in the following table.

The devices are managed by using Microsoft Intune.

You create a compliance policy named Policy1 and assign Policy1 to Group1. Policy1 is configured to mark a device as Compliant only if the

device security settings match the settings specified in the policy.

You discover that devices that are not members of Group1 are shown as Compliant.

You need to ensure that only devices that are assigned a compliance policy can be shown as Compliant. All other devices must be shown as Not

compliant.

What should you do from the Microsoft Intune admin center?

A. From Device compliance, configure the Compliance policy settings.

B. From Endpoint security, configure the Conditional access settings.

C. From Tenant administration, modify the Diagnostic settings.

D. From Policy1, modify the actions for noncompliance.

Correct Answer: A

Community vote distribution


A (80%) D (20%)

[Link] 216/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #225 Topic 1

HOTSPOT

Your company has an infrastructure that has the following:

• A Microsoft 365 tenant

• An Active Directory forest

• Microsoft Intune

• A Key Management Service (KMS) server

• A Windows Deployment Services (WDS) server

• An Azure AD Premium tenant

The company purchases 100 new client computers that run Windows.

You need to ensure that the new computers are joined automatically to Azure AD by using Windows Autopilot.

What should you use? To answer, select the appropriate options in the answer area,

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 217/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #226 Topic 1

You have an Azure AD tenant named [Link].

You plan to purchase 25 computers that run Windows 11. You plan to deliver the computers directly to users.

You need to ensure that during the out-of-box experience (OBE), users are prompted to sign in, and then the computers are configured to use

Microsoft Intune.

Which two components should you configure? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A. a provisioning package

B. automatic enrollment

C. an [Link] answer file

D. a Windows Autopilot deployment profile for self-deploying mode

E. a Windows Autopilot deployment profile for user-driven mode

Correct Answer: BE

Community vote distribution


BE (87%) 13%

Question #227 Topic 1

You need to assign the same deployment profile to all the computers that are configured by using Windows Autopilot.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A. Create an Azure AD group that has dynamic membership rules and uses the ZTDID tag.

B. Create an Azure AD group that has dynamic membership rules and uses the operatingSystem tag.

C. Assign a Windows Autopilot deployment profile to a group.

D. Join the computers to Azure AD.

E. Create a Group Policy object (GPO) that is linked to a domain.

F. Join the computers to an on-premises Active Directory domain.

Correct Answer: AC

Community vote distribution


AC (100%)

[Link] 218/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #228 Topic 1

DRAG DROP

You have a Microsoft Deployment Toolkit (MDT) deployment share that has a path of D:\MDTShare.

You need to add a feature pack to the boot image.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and

arrange them in the correct order.

Correct Answer:

[Link] 219/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #229 Topic 1

You plan to deploy Windows 11 Pro to 200 new computers by using the Microsoft Deployment Toolkit (MDT) and Windows Deployment Services

(WDS).

The company has a Volume Licensing Agreement and uses a product key to activate Windows 11.

You need to ensure that the new computers will be configured to have the correct product key during the installation.

What should you configure?

A. an MDT task sequence

B. the Device settings in Azure AD

C. a WDS boot image

D. a Windows Autopilot deployment profile

Correct Answer: A

Community vote distribution


A (100%)

[Link] 220/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #230 Topic 1

HOTSPOT

You manage a Microsoft Deployment Toolkit (MDT) deployment share named DS1. DS1 contains an Out-of-Box Drivers folder named Windows 11

x64 that has subfolders in the format of {make name}\{model name}.

You need to modify a deployment task sequence to ensure that all the drivers in the folder that match the make and model of the computers are

installed without using PnP detection or selection profiles.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 221/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #231 Topic 1

HOTSPOT

You use the Microsoft Deployment Toolkit (MDT) to deploy Windows 11.

You need to modify the deployment share to meet the following requirements:

• Ensure that the user who performs the installation is prompted to set the local Administrator password

• Define a rule for how to name computers during the deployment.

The solution must NOT replace the existing WinPE image.

Which file should you modify for each requirement? To answer, select the appropriate options in the answer area,

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 222/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #232 Topic 1

HOTSPOT

You have an Azure AD tenant that contains the following:

• Windows 11 devices that are joined to Azure AD

• A user that has a display name of User1 and a UPN of user1@[Link]

You enable Remote Desktop on the Windows 11 devices.

You need to ensure that User1 can use Remote Desktop to connect to the devices.

How should you complete the command that must be run on each device? To answer, select the appropriate options in the answer area

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 223/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #233 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that contains the devices shown in the following table.

All the devices will be reimaged and licensed by using subscription activation.

The devices are assigned to the users shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 224/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #234 Topic 1

Your network contains an Active Directory domain. The domain contains 10 computers that run Windows 10. Users in the finance department use

the computers.

You have a computer named Computer1 that runs Windows 10.

From Computer1, you plan to run a script that executes Windows PowerShell commands on the finance department computers.

You need to ensure that you can run the PowerShell commands on the finance department computers from Computer.

What should you do on the finance department computers?

A. From Windows PowerShell, run the Enable-MMAgent cmdlet.

B. From the local Group Policy, enable the Allow Remote Shell Access setting.

C. From Windows PowerShell, run the Enable-PSRemoting cmdlet.

D. From the local Group Policy, enable the Turn on Script Execution setting.

Correct Answer: C

Community vote distribution


C (89%) 11%

Question #235 Topic 1

You have a Microsoft 365 subscription that includes Microsoft Intune.

You plan to use Windows Autopilot to deploy Windows 11 devices.

You need to meet the following requirements during Autopilot provisioning:

• Display the app and profile configuration progress.

• Block users from using the devices until all apps and profiles are installed

What should you configure?

A. an app configuration policy

B. an app protection policy

C. an enrollment device platform restriction

D. an enrollment status page

Correct Answer: D

Community vote distribution


D (100%)

[Link] 225/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #236 Topic 1

HOTSPOT

You have a Microsoft 365 subscription. The subscription contains 1,000 computers that run Windows 11 and are enrolled in Microsoft Intune.

You plan to create a compliance policy that has the following options enabled:

• Require Secure Boot to be enabled on the device.

• Require the device to be at or under the machine risk score.

Which two Compliance settings should you configure? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 226/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #237 Topic 1

Your network contains an Active Directory domain named [Link]. The domain contains 25 computers that run Windows 11.

You have a Microsoft 365 subscription

You have an Azure AD tenant that syncs with [Link].

You configure hybrid Azure AD join and discover that some of the computers have a registered state of Pending.

You need to ensure that the computers complete the join successfully.

What should you ensure?

A. that Windows is activated on all the computers

B. that the users of the computers are assigned Microsoft 365 licenses

C. that each computer has a line of sight to a domain controller

D. that the computers contain the latest quality updates

Correct Answer: C

Community vote distribution


C (100%)

Question #238 Topic 1

You have devices enrolled in Microsoft Intune as shown in the following table.

For which devices can you manage updates by using Intune?

A. Device1 only

B. Device1 and Device2 only

C. Device1 and Device3 only

D. Device1, Device3, and Device4 only

E. Device1, Device2, Device3, and Device4

Correct Answer: E

Community vote distribution


E (85%) A (15%)

[Link] 227/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #239 Topic 1

You have 500 computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune.

You plan to distribute certificates to the computers by using Simple Certificate Enrollment Protocol (SCEP).

You have the servers shown in the following table.

NDES issues certificates from the subordinate CA.

You are configuring a device configuration profile as shown in the exhibit. (Click the Exhibit tab.)

You need to complete the SCEP profile.

On which server is the required root certificate located?

A. Server1

B. Server2

C. Server3

D. Server4

Correct Answer: B

Community vote distribution

[Link] 228/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics
B (53%) C (47%)

Question #240 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that contains the devices shown in the following table.

You plan to enroll the devices in Microsoft Intune.

How often will the compliance policy check-ins run after each device is enrolled in Intune? To answer, select the appropriate options in the answer

area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 229/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #241 Topic 1

HOTSPOT

You have two Windows 10 devices enrolled in Microsoft Intune as shown in the following table.

The Compliance policy settings are configured as shown in the following exhibit.

On August 1, you create a compliance policy as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

[Link] 230/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 231/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #242 Topic 1

HOTSPOT

You have 100 computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune.

You need to configure the following device restrictions:

• Block users from browsing to suspicious websites.

• Scan all scripts loaded into Microsoft Edge.

Which two settings should you configure in the Device restrictions configuration profile? To answer, select the appropriate settings in the answer

area.

NOTE: Each correct selection is worth one point.

[Link] 232/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

[Link] 233/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #243 Topic 1

HOTSPOT

You have devices enrolled in Microsoft Intune as shown in the following table.

You need to identify the following:

• Device you can remove from Intune by using the Wipe action.

• The enrollment state and the associated user account can be retained on devices that are wiped.

What should you identify? To answer, select the appropriate options in the answer area.

Correct Answer:

[Link] 234/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #244 Topic 1

HOTSPOT

You have an Azure AD tenant named [Link] that contains the devices shown in the following table.

The tenant contains the Azure AD groups shown in the following table.

You add an Autopilot deployment profile as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

[Link] 235/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 236/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #245 Topic 1

HOTSPOT

You have the Microsoft Deployment Toolkit (MDT) installed in three sites as shown in the following table.

You use Distributed File System (DFS) Replication to replicate images in a share named Production.

You configure the following settings in the [Link] file.

You plan to deploy Windows 10 to the computers shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

[Link] 237/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

Question #246 Topic 1

You have a Microsoft 365 subscription that contains 1,000 Android devices enrolled in Microsoft Intune.

You create an app configuration policy that contains the following settings:

• Device enrollment type: Managed devices

• Profile Type: All Profile Types

• Platform: Android Enterprise

Which two types of apps can be associated with the policy? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

A. Android Enterprise system app

B. Web link

C. Android store app

D. Managed Google Play store app

E. Built-in Android app

Correct Answer: AD

Community vote distribution


AD (100%)

[Link] 238/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #247 Topic 1

You have a Microsoft 365 subscription.

You have devices enrolled in Microsoft Intune as shown in the following table.

To which devices can you deploy apps by using Intune?

A. Device1 only

B. Device1 and Device2 only

C. Device1 and Device3 only

D. Device1, Device2, and Device3 only

E. Device1, Device2, Device3, and Device4

Correct Answer: D

Community vote distribution


D (95%) 5%

[Link] 239/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #248 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription that uses Microsoft Intune. The subscription contains the resources shown in the following table.

User1 is the owner of Device1.

You deploy Microsoft 365 Apps Windows 10 and later app types to Intune as shown in the following table.

The next day you review the results of the app deployments.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 240/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #249 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Intune to manage devices.

You need to assess device performance during startup and identify any device models that take longer than average to start.

What should you use to assess the device performance, and which portal should you use? To answer, select the appropriate options in the answer

area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 241/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #250 Topic 1

DRAG DROP

Your on-premises network contains an Active Directory Domain Services (AD DS) domain.

You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains five virtual machines and is NOT connected to the

on-premises network.

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You purchase Windows 365 Enterprise licenses.

You need to deploy Cloud PC. The solution must meet the following requirements:

• All users must be able to access their Cloud PC at any time without any restrictions.

• The users must be able to connect to the virtual machines on VNet1.

How should you configure the provisioning policy for Windows 365? To answer, drag the appropriate options to the correct settings. Each option

may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 242/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #251 Topic 1

HOTSPOT

Your network contains an Active Directory domain.

The domain contains four computers named Computer1, Computer2, Computer3, and Computer4 that run Windows 10.

You perform the following actions:

• On Computer1, you install Windows Admin Center and configure Windows Defender Firewall to allow incoming communication over TCP ports

80,443, and 6516.

• On Computer2, you run the Enable-PSRemoting cmdlet.

• On Computer3, you configure Windows Defender Firewall to allow Windows Remote Management (WinRM) traffic.

• On Computer4, you run the winrm quickconfig command.

You need to manage the computers remotely by using Windows Admin Center.

From which computers can you connect to Windows Admin Center, and which computers can you manage by using Windows Admin Center? To

answer, select the appropriate options in the answer are.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 243/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #252 Topic 1

You have a Hyper-V host. The host contains virtual machines that run Windows 10 as shown in following table.

Which virtual machines can be upgraded to Windows 11?

A. VM1 only

B. VM2 only

C. VM2 and VM3 only

D. VM1, VM2, and VM3

Correct Answer: B

Community vote distribution


B (100%)

Question #253 Topic 1

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Intune to manage all devise.

Users have iOS devices with Microsoft apps installed.

You need to prevent users from cutting, copying, and pasting data between Microsoft Excel and other apps installed on the devices.

What should you configure?

A. an app protection policy

B. an app configuration policy

C. an iOS app provisioning profile

D. policies for Microsoft Office apps

Correct Answer: A

Community vote distribution


A (100%)

[Link] 244/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #254 Topic 1

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Intune to manage devices.

You need to review details about device wipes initiated through Intune.

Which report should you review?

A. Noncompliant devices

B. Assignment status

C. Windows health attestation report

D. Device actions

Correct Answer: D

Community vote distribution


D (100%)

Question #255 Topic 1

You have a Microsoft 365 subscription. The subscription contains 500 computers that run Windows 11 and are enrolled in Microsoft Intune.

You need to manage the deployment of monthly security updates. The solution must meet the following requirements:

• Updates must be deployed to a group of test computers for quality assurance.

• Updates must be deployed automatically 15 days after the quality assurance testing.

What should you create in the Microsoft Intune admin center?

A. a device configuration profile

B. a feature update policy

C. a security baseline

D. an update ring

Correct Answer: D

Community vote distribution


D (100%)

[Link] 245/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #256 Topic 1

HOTSPOT

Your company has computers that run Windows 10 and are Microsoft Entra joined.

The company purchases an Azure subscription.

You need to collect Windows events from the Windows 10 computers in Azure. The solution must enable you to create alerts based on the

collected events.

What should you create in Azure and what should you configure on the computers? To answer, select the appropriate options in the answer area.

Correct Answer:

[Link] 246/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #257 Topic 1

You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Azure AD joined and are enrolled in

Microsoft Intune.

You plan to manage Microsoft Defender Antivirus on the computers.

You need to prevent users from disabling Microsoft Defender for Endpoint.

What should you do?

A. From the Microsoft Intune admin center, create an attack surface reduction (ASR) policy.

B. From the Microsoft 365 Defender portal, enable tamper protection.

C. From the Microsoft Intune admin center, create an account protection policy.

D. From the Microsoft Entra admin center, create a Conditional Access policy.

Correct Answer: B

Community vote distribution


B (100%)

Question #258 Topic 1

You have a Microsoft 365 subscription that has Windows 365 Enterprise licenses.

You plan to use a custom Windows 11 image as a template for Cloud PCs.

You have a Hyper-V virtual machine that runs Windows 11 and has the following configurations:

• Name: VM1

• Disk size: 64 GB

• Disk format: VHDX

• Disk type: Fixed size

• Generation: Generation 2

You need to ensure that you can use VM1 as a source for the custom image.

What should you do on VM1 first?

A. Change the disk type to Dynamically expanding.

B. Change the disk format to the VHD.

C. Change the generation to Generation 1.

D. Increase the disk size.

Correct Answer: B

Community vote distribution


B (100%)

[Link] 247/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #259 Topic 1

HOTSPOT

Your on-premises network contains an Active Directory domain named [Link]. The domain contains a user account named Admin1 and the

resources shown in the following table.

You have a Microsoft 365 E5 subscription.

You have a Microsoft Entra tenant that syncs with [Link].

Admin1 plans to use Windows Autopilot to deploy 100 Windows 11 devices. The deployment must meet the following requirements:

• The devices must be Microsoft Entra hybrid joined during the deployment.

• Computer objects must be created in OU1.

You need to configure Server1 and Active Directory delegation to support the deployment.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 248/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #260 Topic 1

You have a Microsoft 365 subscription.

Each user is assigned a Windows 365 Enterprise license.

You need to deploy Cloud PCs that will be Microsoft Entra hybrid joined.

What should you do first?

A. Create an Azure network connection (ANC).

B. Create a provisioning policy.

C. Create a configuration profile in Microsoft Intune.

D. Upload a custom image.

Correct Answer: A

Community vote distribution


A (100%)

[Link] 249/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #261 Topic 1

Your on-premises network contains an Active Directory Domain Services (AD DS) domain named [Link].

The domain contains a domain controller named [Link].

You have a Microsoft 365 E5 subscription that uses Microsoft Intune Suite.

You have an Azure subscription that contains the resources shown in the following table.

The subscription contains the virtual networks shown in the following table.

You plan to deploy Windows 365 Enterprise Cloud PC.

You need to create an Azure network connection (ANC) that will use Microsoft Entra hybrid join.

Which virtual network can you use for the ANC?

A. VNet1 only

B. VNet2 only

C. VNet3 only

D. VNet1 and VNet2

E. VNet1 and VNet3

Correct Answer: A

Community vote distribution


A (100%)

[Link] 250/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #262 Topic 1

DRAG DROP

You have a Microsoft 365 E5 subscription that includes Microsoft Intune.

The subscription contains Android Enterprise devices that are enrolled in Intune and have personally-owned work profiles. All the Android devices

are members of a group named Group1.

You need to ensure that end users and Intune administrators receive an email message when an Android device does NOT have an up-to-date

security provider.

Which actions should you perform from the Microsoft Intune admin center in sequence? To answer, drag the appropriate actions to the correct

order. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 251/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #263 Topic 1

HOTSPOT

You have a Microsoft 365 subscription.

You have 25 Microsoft Surface Hub devices that you plan to manage by using Microsoft Intune.

You need to configure the devices to meet the following requirements:

• Enable Windows Hello for Business.

• Configure Microsoft Defender SmartScreen to block users from running unverified files.

Which profile type template should you use for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 252/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #264 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription that contains the security groups shown in the following table.

The subscription contains devices that run Windows 11, version 21H2 as shown in the following table.

You have a feature update deployment profile named Deployment1 as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 253/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #265 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription that uses Microsoft Intune.

You need to ensure that users can only enroll devices that meet the following requirements:

• Android devices that support the use of work profiles.

• iOS devices that run iOS 11.0 or later.

Which two restrictions should you modify? To answer, select the restrictions in the answer area.

NOTE: Each correct selection is worth one point.

[Link] 254/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

Question #266 Topic 1

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Intune to manage Windows 11 devices.

You need to implement Windows Local Administrator Password Solution (Windows LAPS).

What should you configure?

A. a configuration profile

B. an account protection policy

C. an app protection policy

D. a device compliance policy

Correct Answer: B

Community vote distribution


B (89%) 11%

[Link] 255/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #267 Topic 1

You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Microsoft Entra joined and are

enrolled in Microsoft Intune.

You plan to manage Microsoft Defender for Endpoint on the computers.

You need to prevent users from disabling Microsoft Defender for Endpoint.

What should you do?

A. From the Microsoft Intune admin center, create a security baseline.

B. From the Microsoft Intune admin center, create an antivirus policy.

C. From the Microsoft Entra admin center, create a Conditional Access policy.

D. From the Microsoft Intune admin center, create a device compliance policy.

Correct Answer: B

Community vote distribution


B (100%)

Question #268 Topic 1

You have a Microsoft 365 subscription that includes Microsoft Intune.

You need to deploy a custom app to Android devices. The app uses the APK file format.

Which type of app should you select for the deployment?

A. built-in

B. Android store

C. Managed Google Play

D. line-of-business (LOB)

E. web link

Correct Answer: D

Community vote distribution


D (83%) C (17%)

[Link] 256/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #269 Topic 1

You have a Microsoft 365 E5 subscription.

You use Microsoft Intune to manage all devices.

You need to prepare a Win32 app named [Link] for deployment.

What should you do first?

A. From the Microsoft Intune admin center, create an app configuration policy.

B. Change [Link] to the INTUNEWIN format.

C. From the Microsoft 365 Apps admin center, create a deployment configuration.

D. Upload [Link] to Azure Blob Storage.

Correct Answer: B

Community vote distribution


B (100%)

Question #270 Topic 1

You have a Microsoft 365 E5 subscription that includes Microsoft Intune.

For macOS devices, you create an update policy named Policy1 that has the following settings:

• All other updates (OS, built-in apps): Download and install

• Assignments:

• Included groups: All Devices

Which two types of updates can be downloaded and installed by using Policy1? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A. configuration file

B. macOS

C. firmware

D. critical

E. built-in app

Correct Answer: BE

Community vote distribution


BE (94%) 6%

[Link] 257/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #271 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription that includes Microsoft Intune. The subscription contains a group named Group1. Group1 contains

devices enrolled in Intune.

You deploy Remote Help in Intune.

You need to configure Remote Help to only allow support administrators to join Remote Help sessions from the devices in Group1.

Which type of Microsoft Entra object should you create, and which type of policy should you configure? To answer, select the appropriate options

in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 258/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #272 Topic 1

You have a Microsoft 365 E5 subscription that includes Microsoft Intune and contains a user named Admin1.

Admin1 must use the Microsoft Intune admin center to perform the following tasks:

• Create and assign apps and policies to users and devices by using Intune.

• Create, assign, and delete Windows 365 Cloud PC provisioning policies.

You need to assign the required roles to Admin1. The solution must meet the following requirements:

• Follow the principle of least privilege.

• Minimize administrative effort.

What should you do?

A. Assign Admin1 the Help Desk Operator role.

B. Assign Admin1 the Cloud PC Reader role.

C. Assign Admin1 the Cloud PC Administrator role.

D. Create a custom Microsoft Entra role and assign the role to Admin1.

E. Create a custom Intune role and assign the role to Admin1.

Correct Answer: E

Community vote distribution


E (50%) C (38%) 13%

Question #273 Topic 1

You have a Microsoft 365 subscription that includes Microsoft Intune. The subscription contains Windows 11 devices enrolled in Intune. The

subscription contains three groups named Departement1, Department2, and Department3.

You need to deploy Microsoft 365 Apps to the Windows 11 devices. The solution must meet the following requirements:

• Users in Department1 and Department2 must receive the full Microsoft 365 Apps suite, including Microsoft Project and Visio.

• Users in Department3 must receive the full Microsoft 365 Apps suite, including Microsoft Project, but without Visio.

• All other users must receive the full Microsoft 365 Apps suite without Microsoft Project or Visio.

What is the minimum number of deployments you should create?

A. 1

B. 2

C. 3

D. 4

Correct Answer: C

Community vote distribution


C (100%)

[Link] 259/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #274 Topic 1

You have a Microsoft 365 E5 subscription that uses Microsoft Intune.

You configure Intune to send log data to Log Analytics.

You need to review events involving devices that fail to enroll in Intune.

What should you monitor?

A. operational logs

B. audit logs

C. the Intune Device log

D. device compliance organizational logs

Correct Answer: A

Community vote distribution


A (100%)

Question #275 Topic 1

You have a Microsoft 365 subscription that includes Microsoft Intune. The subscription contains corporate-owned, fully managed Android

Enterprise devices.

You plan to deploy a configuration profile that will have a device restrictions profile type named Profile1. Profile1 will assign maintenance windows

for system updates.

What should you configure from the Configuration settings for Profile1?

A. Device experience

B. General

C. Connectivity

D. Power Settings

Correct Answer: B

Community vote distribution


B (80%) A (20%)

[Link] 260/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #276 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription.

You use Microsoft Intune to manage Windows 365 Cloud PC devices.

You need to deploy a Windows 365 Security Baseline to the Cloud PC devices. The solution must meet the following requirements:

• Block data execution prevention.

• Enable virtualization-based security (VBS) and Secure Boot.

What should you configure for the Windows 365 Security Baseline profile? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 261/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #277 Topic 1

You have a Microsoft 365 subscription that includes Microsoft Intune.

You create a new Android app protection policy named Policy1 that prevents screen captures in all Microsoft apps.

You discover that an unmanaged email client installed on Android devices can still capture screens.

You need to ensure that users can only use Microsoft apps to access email.

What should you do?

A. Create a Conditional Access policy.

B. Create a compliance policy.

C. Modify the Data protection settings of Policy1.

D. Modify the assignments of Policy1.

Correct Answer: A

Community vote distribution


A (100%)

Question #278 Topic 1

You have a Microsoft 365 E5 subscription.

All Windows devices are enrolled in Microsoft Intune.

You need to create an app protection policy named Policy1 and apply Policy1 to the devices.

What can you protect by using Policy1?

A. Microsoft Outlook

B. Microsoft OneDrive

C. Microsoft Teams

D. Microsoft Edge

Correct Answer: D

Community vote distribution


D (87%) 13%

[Link] 262/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #279 Topic 1

You have a Microsoft 365 E5 subscription.

You use Microsoft Intune to manage all Windows 11 devices.

You create an attack surface reduction (ASR) policy named Profile1 based on the Attack Surface Reduction Rules profile and assign Profile1 to all

the devices.

A user reports that an Adobe Reader plug-in is now blocked.

You need to ensure that the plug-in is unblocked.

What should you do?

A. Create an Endpoint Privilege Management policy and assign the policy to all the devices.

B. Add a scope tag to Profile1.

C. Configure ASR Only Per Rule Exclusions in Profile1.

D. Create a device compliance policy and assign the policy to all the devices.

Correct Answer: C

Community vote distribution


C (100%)

Question #280 Topic 1

You have a Microsoft 365 E5 subscription.

All devices are enrolled in Microsoft Intune.

You need to ensure that devices that have NOT checked in for 30 days are deleted from Intune.

What should you configure from the Microsoft Intune admin center?

A. a device limit restriction

B. automatic enrollment

C. a device clean-up rule

D. a configuration profile

Correct Answer: C

Community vote distribution


C (100%)

[Link] 263/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #281 Topic 1

You have a Microsoft 365 E5 subscription.

All devices are enrolled in Microsoft Intune.

You create a Conditional Access policy named Policy1 that requires multifactor authentication (MFA).

You need to ensure that Policy1 only applies to devices marked as noncompliant.

Which settings of Policy1 should you configure?

A. Device platforms under Conditions

B. Filter for devices under Conditions

C. Target resources

D. Grant

E. Session

Correct Answer: B

Community vote distribution


B (76%) D (24%)

[Link] 264/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #282 Topic 1

HOTSPOT

You have a Microsoft Entra tenant that contains the devices shown in the following table.

The tenant contains the groups shown in the following table.

You create a Windows Autopilot deployment profile as shown in the Deployment Profile exhibit. (Click the Deployment Profile tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

[Link] 265/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 266/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #283 Topic 1

HOTSPOT

You have a Microsoft 365 tenant that uses Microsoft Intune to manage the devices shown in the following table.

You need to deploy a compliance solution that meets the following requirements:

• Marks the devices as Not Compliant if they do not meet compliance policies

• Remotely locks noncompliant devices

What is the minimum number of compliance policies required, and which devices support the remote lock action? To answer, select the

appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 267/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #284 Topic 1

HOTSPOT

Your network contains an on-premises Active Directory Domain Services (AD DS) domain.

You have a Microsoft 365 E5 subscription that includes Microsoft Intune and syncs with the AD DS domain.

Windows Local Administrator Password Solution (Windows LAPS) is enabled in Microsoft Entra ID.

The subscription has the custom roles shown in the following table.

Microsoft Entra contains the users shown in the following table.

You have the devices shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 268/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #285 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription and use Microsoft Intune.

You purchase 50 Windows devices.

You configure automatic enrollment to Intune for Microsoft Entra joined devices.

You need to use a provisioning package to join the devices to Microsoft Entra.

What should you use to create the provisioning package, and what is the maximum amount of time you can use the package for bulk enrollment?

To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 269/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #286 Topic 1

You have a Microsoft 365 E5 subscription.

You need to configure the automated investigation and response (AIR) remediation level for a device named Device1 to require approval for all

folders.

What should you create?

A. a security group

B. a device group

C. an administrative unit

D. an action group

Correct Answer: B

Community vote distribution


B (100%)

[Link] 270/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #287 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription.

You need to route Microsoft Intune logs to an Azure resource that supports the use of visuals, monitoring, and alerting.

Which settings should you configure in Intune, and which resource should you use? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 271/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #288 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription that includes Microsoft Intune.

You need to configure a compliance policy for the iOS/iPadOS platform. The solution must meet the following requirements:

• Require jailbroken devices to be marked as noncompliant.

• Mark devices without a password lock as noncompliant.

Which compliance policy settings should you configure for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 272/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #289 Topic 1

You have a Microsoft Intune subscription.

You have devices enrolled in Intune as shown in the following table.

An app named App1 is installed on each device.

What is the minimum number of app configuration policies required to manage App1?

A. 1

B. 2

C. 3

D. 4

E. 5

Correct Answer: B

Community vote distribution


B (100%)

[Link] 273/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #290 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription. All devices are enrolled in Microsoft Intune.

You have a device group named Group1 that contains five Windows 11 devices.

You need to ensure that the devices in Group1 automatically receive new Windows 11 builds before the builds are released to the public.

What should you configure in Intune? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 274/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #291 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription and use Microsoft Intune. The subscription contains a Microsoft Entra tenant that syncs with an on-

premises Active Directory Domain Services (AD DS) domain. The tenant has Windows Local Administrator Password Solution (Windows LAPS)

enabled.

You have the Windows devices shown in the following table.

You have an Endpoint security policy that is configured as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 275/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #292 Topic 1

You have a Microsot Entra tenant named [Link].

You have a workgroup computer named Computer1 that runs Windows 11.

You need to add Computer1 to [Link].

What should you use?

A. the Settings app

B. Computer Management

C. [Link]

Correct Answer: A

Community vote distribution


A (100%)

[Link] 276/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #293 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that includes Microsoft Intune.

From the Microsoft Intune admin center, you add the apps shown in the following table.

You need to configure the apps to meet the following requirements:

• App1 must automatically install for all users in the marketing department on any Windows 11 device enrolled in Intune. If a user receives a new

device, App1 must install automatically.

• App2 must be available for download for any user in the HR department from a personal Android device that is not enrolled in Intune.

Which assignment should you configure for each app? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 277/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #294 Topic 1

You have a Microsoft 365 Business Standard subscription and 100 Windows 10 Pro devices that are joined to Microsoft Entra.

You purchase Microsoft 365 E5 licenses for all users.

You need to upgrade the Windows 10 Pro devices to Windows 10 Enterprise. The solution must minimize administrative effort.

Which upgrade method should you use?

A. a Microsoft Deployment Toolkit (MDT) lite-touch deployment

B. Subscription Activation

C. an in-place upgrade by using Windows installation media

D. Windows Autopilot

Correct Answer: B

Community vote distribution


B (100%)

Question #295 Topic 1

You have a Microsoft 365 subscription.

You have 10 computers that run Windows 10 and are enrolled in Microsoft Intune.

You need to deploy the Microsoft 365 Apps for enterprise suite to all the computers.

What should you do?

A. From the Microsoft Intune admin center, add an app.

B. From the Microsoft Intune admin center, create a Windows 10 and later device profile.

C. From the Microsoft Entra admin center, add an enterprise application.

D. From the Microsoft Entra admin center, add an app registration.

Correct Answer: A

Community vote distribution


A (100%)

[Link] 278/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #296 Topic 1

You have a Microsoft 365 E5 subscription.

You have a Windows device named Device1 that is enrolled in Microsoft Intune.

On January 1,2024, you assign an app named App1 to Device1 as a required app.

The install of App1 fails.

What is the next date that Intune will attempt to install App1?

A. January 2, 2024

B. January 5, 2024

C. January 8, 2024

D. January 31, 2024

Correct Answer: A

Community vote distribution


A (100%)

Question #297 Topic 1

You have a Microsoft 365 E5 subscription that contains the devices shown in the following table.

All the devices are enrolled in Microsoft Intune and have Microsoft 365 Apps for enterprise installed.

On which devices can you use the Cloud Policy service for Microsoft 365 to manage Microsoft 365 Apps for enterprise?

A. Device2 only

B. Device1 and Device2 only

C. Device1, Device2, and Device3 only

D. Device1, Device2, and Device4 only

E. Device1, Device2, Device3, and Device4

Correct Answer: E

Community vote distribution


E (100%)

[Link] 279/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #298 Topic 1

HOTSPOT

You have an Azure subscription that is linked to a Microsoft Entra tenant. The tenant contains the devices shown in the following table.

You install the Azure Monitor Agent on all supported devices.

You create a monitored object (MO) and associate the MO to a data collection rule (DCR) named DCR1.

You configure DCR1 as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Correct Answer:

[Link] 280/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #299 Topic 1

You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Microsoft Entra joined and are

enrolled in Microsoft Intune.

You plan to manage Microsoft Defender for Endpoint on the computers.

You need to prevent users from disabling Microsoft Defender for Endpoint.

What should you do?

A. From the Microsoft Intune admin center, create an attack surface reduction (ASR) policy.

B. From the Microsoft Intune admin center, create an account protection policy.

C. From the Microsoft Defender portal, enable tamper protection.

D. From the Microsoft Intune admin center, create a device compliance policy.

Correct Answer: C

Community vote distribution


C (100%)

Question #300 Topic 1

You have a Microsoft 365 E5 subscription.

You need to manage operating system updates for corporate-owned Android Enterprise devices enrolled in Microsoft Intune.

What should you use?

A. a compliance policy

B. an Android FOTA deployment

C. an Endpoint security policy

D. a configuration profile

Correct Answer: D

Community vote distribution


D (100%)

[Link] 281/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #301 Topic 1

You have a Microsoft 365 subscription.

You use Microsoft Intune to manage devices.

You plan to deploy two apps named App1 and App2 to all Windows devices. App1 must be installed before App2.

From the Intune admin center, you create and deploy two Windows app (Win32) apps.

You need to ensure that App1 is installed before App2 on every device.

What should you configure?

A. the App1 deployment configurations

B. a dynamic device group

C. the App2 deployment configurations

Correct Answer: C

Community vote distribution


C (100%)

[Link] 282/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #302 Topic 1

HOTSPOT

You have a Microsoft Entra tenant that contains the users shown in the following table.

When you sign in to the tenant, the available verification methods are shown in the following exhibit.

Which users will be prompted for the verification code method, and which users will be prompted for the text method? To answer, select the

appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

[Link] 283/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

Question #303 Topic 1

You have a Microsoft 365 subscription that contains Windows 11 devices enrolled in Microsoft Intune.

You need to use Device query to identify whether a critical security patch was installed on a device.

Which table should you target?

A. WindowsQfe

B. WindowsRegistry

C. FileInfo

D. OsVersion

E. SystemInfo

Correct Answer: A

Community vote distribution


A (100%)

Question #304 Topic 1

You have a Microsoft 365 E5 subscription.

All Windows devices are enrolled in Microsoft Intune.

You need to deploy the Remote Help app to all the devices. The solution must minimize administrative effort.

Which type of app should you deploy?

A. Windows app (Win32)

B. line-of-business (LOB)

C. Microsoft 365

D. Microsoft Store

Correct Answer: A

Community vote distribution


A (100%)

[Link] 284/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #305 Topic 1

You have a Microsoft 365 subscription that contains devices enrolled in Microsoft Intune as shown in the following table.

On which devices can you use Device query?

A. Device1 only

B. Device1 and Device2 only

C. Device1 and Device3 only

D. Device1, Device2, and Device3

Correct Answer: A

Community vote distribution


A (100%)

Question #306 Topic 1

You have a Microsoft 365 E5 subscription.

You need to use Device query to gather information about all the devices that are managed by using Microsoft Intune.

What should you do first?

A. Enable Windows license verification.

B. Onboard the devices to Microsoft Defender for Endpoint.

C. Onboard the devices to Endpoint analytics.

D. Create a compliance policy for all the devices.

Correct Answer: C

Community vote distribution


C (100%)

[Link] 285/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #307 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription that contains two devices named Device1 and Device2.

You manage the devices by using Microsoft Intune.

You need to use Device query to meet the following requirements:

• Identify the Windows build on a device.

• Validate whether a folder exists on the C drive of a device.

Which table should you target for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 286/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #308 Topic 1

You have a Microsoft 365 E5 subscription and use Microsoft Intune.

You plan to implement a Microsoft Cloud PKI solution that will deploy personal user certificates to all Windows devices.

What is the minimum number of configuration profiles required to support the solution?

A. 1

B. 2

C. 3

D. 4

Correct Answer: C

Community vote distribution


C (60%) B (40%)

[Link] 287/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #309 Topic 1

DRAG DROP

You have a Microsoft 365 subscription that contains the following devices enrolled in Microsoft Intune:

• A corporate-owned Windows device named Device1

• A personally-owned Android device named Device2

You need to use a remote action on each device. The solution must meet the following requirements:

• Repurpose Device1 by returning the device to the factory default settings.

• Remove only corporate data from Device2 and remove the device from Intune when the device checks in.

Which remote action should you use on each device? To answer, drag the appropriate remote actions to the correct devices. Each remote action

may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

Correct Answer:

[Link] 288/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #310 Topic 1

You have a Microsoft 365 E5 subscription.

You need to enroll Android Enterprise devices in Microsoft Intune by using zero-touch enrollment.

What should you do first?

A. From the Microsoft Intune admin center, configure enrollment restrictions.

B. From the Microsoft Intune admin center, create a zero-touch configuration.

C. From the Microsoft Intune admin center, link a Managed Google Play account.

D. From the zero-touch enrollment portal, create a zero-touch configuration.

Correct Answer: C

Community vote distribution


C (100%)

Question #311 Topic 1

You have a Microsoft Entra tenant named [Link] that contains a group named Contoso Help Desk.

You need to ensure that Contoso Help Desk is added to the local Administrators group whenever a Windows device is joined to [Link].

What should you do?

A. Assign the Cloud Device Administrator role to Contoso Help Desk.

B. Assign the Microsoft Entra Joined Device Local Administrator role to Contoso Help Desk.

C. Configure the Enterprise State Roaming settings.

D. Enable Microsoft Entra Local Administrator Password Solution (LAPS) for [Link].

Correct Answer: B

Community vote distribution


B (100%)

[Link] 289/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #312 Topic 1

HOTSPOT

You have a Microsoft Entra tenant.

You are creating a dynamic device group named Group1.

Group1 will include only Windows devices that are Microsoft Entra registered.

How should you configure the dynamic membership rule for Group1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 290/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #313 Topic 1

DRAG DROP

You have a Microsoft 365 E5 subscription that is linked to a Microsoft Entra tenant named [Link]. The subscription contains a user named

User1 and a new Windows 11 device named Device1.

User1 must enroll Device1 in Microsoft Intune automatically.

You need to ensure that all other users cannot use automatic enrollment.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and

arrange them in the correct order.

Correct Answer:

[Link] 291/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #314 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription that contains three Windows devices named Device1, Device2, and Device3.

Each device contains two apps named App1 and App2.

You manage the devices by using Microsoft Intune.

The subscription contains the groups shown in the following table.

You have an Endpoint Privilege Management (EPM) elevation settings policy named Policy1 that has the following settings:

• Endpoint Privilege Management: Enabled

• Default elevation response: Require user confirmation

• Validation: Windows authentication

• Assignments: Group1, Group2

You create an Endpoint Privilege Management elevation rules policy named RulesPolicy1 that has the following settings:

• Rule name: Rule1

• Elevation type: Automatic

• Child process behavior: Deny all

• File name: [Link]

• Assignments: Group1

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 292/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #315 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription and use Microsoft Intune.

You need to deploy new Android devices as shown in the following table.

Which enrollment profile should you use for each device? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 293/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #316 Topic 1

You have a Microsoft 365 subscription and use Microsoft Intune Suite.

The subscription contains devices enrolled in Intune as shown in the following table.

Which devices support Device query?

A. Device1 only

B. Device2 only

C. Device1 and Device2 only

D. Device1, Device2, Device3, and Device4

Correct Answer: A

Community vote distribution


A (100%)

Question #317 Topic 1

You have a Microsoft 365 E5 subscription that contains devices enrolled in Microsoft Intune.

You plan to use Device query to provide on-demand information about the state of the devices. The solution must minimize costs.

What should you do first?

A. Use the Collect diagnostics remote action.

B. Purchase the Intune Advanced Analytics add-on.

C. Purchase the Intune Suite add-on.

D. Onboard the devices to Endpoint analytics.

Correct Answer: D

Community vote distribution


D (56%) B (44%)

[Link] 294/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #318 Topic 1

You have a Microsoft Entra tenant that contains the devices shown in the following table.

On which devices can you implement Endpoint Privilege Management (EPM)?

A. Device1 only

B. Device1 and Device2 only

C. Device1 and Device3 only

D. Device1, Device3, and Device4 only

E. Device1, Device2, Device3, and Device4

Correct Answer: A

Community vote distribution


A (100%)

[Link] 295/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #319 Topic 1

HOTSPOT

You have a Microsoft 365 ES subscription and use Microsoft Intune Suite.

You manage the following types of devices:

• Windows 11

• Android

• iOS

You need to implement Microsoft Tunnel for Mobile Application Management (MAM) to provide the devices with access to on-premises company

apps.

What should you deploy first, and which device types can use Tunnel for MAM? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 296/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #320 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that includes Microsoft Intune and Microsoft Defender for Endpoint.

Users have devices that run Windows 11.

You deploy a connection from Defender for Endpoint to Intune.

You need to ensure that when a device is enrolled in Intune, the device is onboarded automatically to Defender for Endpoint.

What should you configure, and which portal should you use? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 297/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #321 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription that contains the devices shown in the following table.

The subscription contains the dynamic device groups shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 298/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #322 Topic 1

DRAG DROP

You have a Microsoft 365 subscription.

You plan to enroll devices in Microsoft Intune.

You need to meet the following requirements:

• Only allow the enrollment of devices that have a specific international mobile equipment identifier (IMEI).

• Support the enrollment and management of up to 1,000 devices.

Which enrollment setting should you configure for each requirement? To answer, drag the appropriate settings to the correct requirements. Each

setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 299/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #323 Topic 1

HOTSPOT

You have a hybrid environment that contains a Microsoft Entra tenant and an on-premises Active Directory Domain Services (AD DS) domain. The

environment contains the devices shown in the following table.

Which Microsoft Entra join type can each device use? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 300/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #324 Topic 1

You have a Microsoft 365 E5 subscription that contains a group named Group1.

You need to ensure that only the members of Group1 can join devices to the Microsoft Entra tenant.

What should you configure in the Microsoft Entra admin center?

A. Device settings

B. Mobility

C. Enterprise State Roaming

D. User settings

Correct Answer: A

Question #325 Topic 1

You have a Microsoft Entra tenant named [Link] that contains a Windows 11 device named Device1 and a user named User1.

User1 registers Device1 in [Link].

Which capability is available to Device1 after registering in [Link]?

A. authenticating to cloud resources by using single sign-on (SSO)

B. enforcing compliance policies

C. enforcing software updates

D. enforcing hard drive encryption

Correct Answer: A

Community vote distribution


A (100%)

[Link] 301/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #326 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription that contains the devices shown in the following table.

You need to create two dynamic device groups named Group1 and Group2. The solution must meet the following requirements:

• Group1 must contain Device1 and Device2 only.

• Group2 must contain Device1 and Device3 only.

Which device membership rule should you configure for each group? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 302/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #327 Topic 1

You have a Microsoft 365 E5 subscription.

You need to create a dynamic device group that will contain any device that has the word Marketing in its name.

Which device membership rule should you use?

A. ([Link] -in "Marketing")

B. ([Link] -in "*Marketing*")

C. ([Link] -contains "Marketing")

D. ([Link] -contains "*Marketing*")

Correct Answer: C

Community vote distribution


C (100%)

Question #328 Topic 1

You have a Microsoft 365 E5 subscription.

You need to ensure that when a Windows device is joined to the Microsoft Entra tenant, the device is enrolled automatically in Microsoft Intune.

What should you configure?

A. the Windows Information Protection (WIP) user scope

B. the Enterprise State Roaming settings

C. the Microsoft Entra join and registration settings

D. the mobile device management (MDM) user scope

Correct Answer: D

Community vote distribution


D (100%)

[Link] 303/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #329 Topic 1

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the

problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also

possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Entra tenant named [Link].

You purchase an Android device named Device1.

You need to register Device1 in [Link].

Solution: You use the Microsoft Intune Company Portal app.

Does this meet the goal?

A. Yes

B. No

Correct Answer: A

Community vote distribution


A (86%) 14%

Question #330 Topic 1

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the

problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also

possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Entra tenant named [Link].

You purchase an Android device named Device1.

You need to register Device1 in [Link].

Solution: You use Microsoft Entra Connect.

Does this meet the goal?

A. Yes

B. No

Correct Answer: B

Community vote distribution


B (100%)

[Link] 304/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #331 Topic 1

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the

problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also

possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Entra tenant named [Link].

You purchase an Android device named Device1.

You need to register Device1 in [Link].

Solution: You use the Microsoft Authenticator app.

Does this meet the goal?

A. Yes

B. No

Correct Answer: B

Community vote distribution


B (67%) A (33%)

[Link] 305/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #332 Topic 1

HOTSPOT

You have a Microsoft 365 E5 tenant that contains Windows devices enrolled in Microsoft Intune as shown in the following table.

You create an Endpoint Privilege Management (EPM) elevation settings policy named ElevationSettings1 that has the following settings:

• Endpoint Privilege Management: Enabled

• Default elevation response: Require user confirmation

• Validation: Business justification

• Assignments: Group1

Each device contains a file named [Link] that can be run only by an administrator.

You create an EPM elevation rules policy named ElevationRules1 that has the following settings:

• Rule name: Rule1

• Elevation type: Automatic

• File name: [Link]

• File hash:

• Assignments: Group2

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 306/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #333 Topic 1

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the

problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also

possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft 365 E5 subscription. The subscription contains devices that are Microsoft Entra joined and enrolled in Microsoft Intune.

You create a user named User1.

You need to ensure that User1 can rotate BitLocker recovery keys by using Intune.

Solution: From the Microsoft Entra admin center, you assign the Helpdesk Administrator role to User1.

Does this meet the goal?

A. Yes

B. No

Correct Answer: B

Community vote distribution


B (67%) A (33%)

Question #334 Topic 1

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the

problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also

possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft 365 E5 subscription. The subscription contains devices that are Microsoft Entra joined and enrolled in Microsoft Intune.

You create a user named User1.

You need to ensure that User1 can rotate BitLocker recovery keys by using Intune.

Solution: From the Microsoft Intune admin center, you assign the Help Desk Operator role to User1.

Does this meet the goal?

A. Yes

B. No

Correct Answer: A

Community vote distribution


A (70%) B (30%)

[Link] 307/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #335 Topic 1

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the

problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also

possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft 365 E5 subscription. The subscription contains devices that are Microsoft Entra joined and enrolled in Microsoft Intune.

You create a user named User1.

You need to ensure that User1 can rotate BitLocker recovery keys by using Intune.

Solution: From the Microsoft Intune admin center, you assign the Endpoint Security Manager role to User1.

Does this meet the goal?

A. Yes

B. No

Correct Answer: A

Community vote distribution


A (63%) B (38%)

Question #336 Topic 1

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the

problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also

possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Entra tenant named [Link].

You purchase an Android device named Device1.

You need to register Device1 in [Link].

Solution: You use the Google Chrome app.

Does this meet the goal?

A. Yes

B. No

Correct Answer: B

Community vote distribution


B (100%)

[Link] 308/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #337 Topic 1

You have a Microsoft 365 E5 subscription that contains devices enrolled in Microsoft intune.

You need to review security tasks in the Microsoft Intune admin center.

What should you do first?

A. Integrate Intune with Microsoft Defender for Endpoint.

B. Implement the ServiceNow connector.

C. Implement the Mobile Threat Defense connector.

D. Deploy an attack surface reduction (ASR) policy.

E. Deploy an Intune security baseline for Microsoft Defender for Endpoint.

Correct Answer: A

Community vote distribution


E (100%)

Question #338 Topic 1

You have a Microsoft 365 E5 subscription.

You purchase the following types of devices:

• Windows

• Android

• iOS

You plan to enroll the devices in Microsoft Intune.

You need to configure enrollment restrictions.

For which device types can you configure device manufacturer restrictions?

A. Android only

B. Windows only

C. Android and iOS only

D. Windows and iOS only

E. Windows, Android, and iOS

Correct Answer: A

Community vote distribution


A (67%) E (33%)

[Link] 309/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #339 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that contains the devices shown in the following table.

You need to use the remote actions shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 310/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #340 Topic 1

HOTSPOT

You have a Microsoft Entra tenant that contains the groups shown in the following table.

The tenant contains the devices shown in the following table.

The devices have the enrollment restrictions shown in the following table.

For each of the following statements select yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 311/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #341 Topic 1

You have a Microsoft Entra tenant that contains a device named Device1. Device1 is Microsoft Entra joined.

You need to validate the Microsoft Entra ID primary refresh token (PRT) for Device1.

Which command should you run?

A. klist tgt

B. dsregcmd /status

C. query session

D. [Link] query state=all

Correct Answer: B

Community vote distribution


B (100%)

Question #342 Topic 1

Your on-premises network contains an Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant.

You need to enable users to connect to Microsoft 365 services from their personal Windows devices by using single sign-on (SSO). The solution

must minimize organizational control of the devices.

Which join type should you use?

A. Microsoft Entra registered

B. Microsoft Entra joined

C. Active Directory domain-joined

D. Microsoft Entra hybrid joined

Correct Answer: A

Community vote distribution


A (100%)

[Link] 312/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #343 Topic 1

HOTSPOT

You have a Microsoft Entra tenant that contains the devices shown in the following table.

Which devices can be Microsoft Entra joined, and which devices can be Microsoft Entra registered? To answer, select the appropriate options in

the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 313/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #344 Topic 1

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant named

[Link].

You need to deploy 100 Windows 11 devices to [Link]. The solution must meet the following requirements:

• Ensure that from the devices, users can access shares on an on-premises file server without being prompted for credentials.

• Minimize reliance on the on-premises infrastructure for device identity management.

Which join type should you use?

A. Active Directory domain-joined

B. Microsoft Entra hybrid joined

C. Microsoft Entra joined

D. Microsoft Entra registered

Correct Answer: B

Community vote distribution


C (67%) B (33%)

Question #345 Topic 1

You have a Microsoft 365 E5 subscription that contains a device named Device1.

Device1 is Microsoft Entra joined.

You manage Device1 by using Microsoft Intune.

You need to use a remote action to reset the device as quickly as possible, if the device is turned off, the action must resume after the device is

powered on.

Which remote action should you use?

A. Autopilot reset

B. Wipe

C. Retire

D. Delete

Correct Answer: B

Community vote distribution


B (100%)

[Link] 314/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #346 Topic 1

You have a Microsoft 365 subscription that contains devices enrolled in Microsoft intune as shown in the following table.

You need to use a bulk device action to send custom notifications.

To which devices can you send the custom notifications?

A. Device1 only

B. Device2 only

C. Device3 only

D. Device2 and Device3 only

E. Device1, Device2, and Device3

Correct Answer: C

Community vote distribution


C (71%) 14% 14%

[Link] 315/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #347 Topic 1

DRAG DROP

You have a Microsoft 365 E5 subscription and use Microsoft Intune.

You need to use Microsoft Cloud PKI to deploy personal user certificates to all Windows devices.

Which four actions should you perform in sequence? To answer move the appropriate actions from the list of actions to the answer area and

arrange them in the correct order.

Correct Answer:

[Link] 316/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #348 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription that uses Microsoft Intune Suite.

You need to recommend a solution that meets the following requirements:

• Administrators must use a secure connection over a shared screen session to perform remote tasks on a user’s device.

• Administrators must have elevated access to perform remote tasks on a user’s device.

• The solution must follow the principle of least privilege.

What should you include in the recommendation for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 317/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #349 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that contains devices enrolled in Microsoft Intune as shown in the following table.

You plan to use the following remote actions on the devices:

• Collect diagnostics

• Locate device

• Remote lock

Which remote actions does each device support? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

[Link] 318/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Correct Answer:

Question #350 Topic 1

You have a Microsoft 365 subscription and use Microsoft Intune Suite.

You plan to use Microsoft Cloud PKI to support the signing and encryption of email messages.

What should you do first?

A. Create a root certification authority (CA).

B. Create a device compliance policy.

C. Create device configuration SCEP certificate profiles.

D. Create device configuration trusted certificate profiles.

E. Create an issuing certification authority (CA).

Correct Answer: A

[Link] 319/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #351 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription that contains the devices shown in the following table.

You need to implement Microsoft Tunnel for Mobile Application Management (MAM) to provide the devices with access to an on-premises web

app named App1.

What should you do on each device? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 320/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #352 Topic 1

You have a Microsoft 365 subscription.

You plan to enroll 25 new devices in Microsoft Intune.

You need to configure an enrollment notification for the new devices.

Which two types of notifications can you use? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

A. SMS

B. Microsoft Teams message

C. phone call

D. push

E. email

Correct Answer: DE

Community vote distribution


DE (100%)

[Link] 321/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #353 Topic 1

HOTSPOT

You have a Microsoft Entra tenant named [Link] that contains the users shown in the following table.

For [Link], you configure the following Microsoft Entra join and registration settings:

• Users may join devices to Microsoft Entra: Selected

o Selected: Group1

You purchase the devices shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 322/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #354 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription that contains a Windows device named Device1.

Device1 was onboarded to Microsoft Defender for Endpoint by using a local script.

You use Microsoft Intune to manage Device1.

You plan to use the machine risk score in a compliance policy.

You need to ensure that the machine risk score is evaluated based on data from Defender for Endpoint.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 323/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #355 Topic 1

HOTSPOT

You have a Microsoft 365 subscription and use Microsoft Intune.

You have the Endpoint Privilege Management (EPM) elevation settings policy shown in the following exhibit.

No EPM elevation rules policies are configured.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 324/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #356 Topic 1

You have a Microsoft 365 E5 subscription that contains the following types of devices:

• Windows 11

• Android

• iOS

All the devices are enrolled in Microsoft Intune.

You need to use Intune to deploy apps from the Enterprise App Catalog.

To which device types can you deploy the apps?

A. Windows 11 only

B. Windows 11 and Android only

C. Windows 11 and is only

D. Android and iOS only

E. Windows 11, Android, and iOS

Correct Answer: A

Question #357 Topic 1

You have a Microsoft 365 E5 subscription and use Microsoft Intune Suite.

You plan to use Intune to run remediation script packages.

What should you do first in the Microsoft Intune admin center?

A. Enable Windows diagnostic data in processor configuration.

B. Enable Windows license verification.

C. Configure the Derived Credential settings.

D. Upload a Windows enterprise certificate.

Correct Answer: B

[Link] 325/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #358 Topic 1

HOTSPOT

You have a Microsoft 365 subscription that contains 5,000 Windows devices enrolled in Microsoft Intune.

You plan to use the Sync and Collect diagnostics bulk device actions.

What is the maximum number of devices you can include in each action? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 326/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #359 Topic 1

HOTSPOT

You manage devices by using Microsoft Intune. Automatic Intune enrollment is disabled.

Users report that they must enter the mobile device management (MDM) server address during device enrollment.

To reduce user interaction during device enrollment, you plan to create the following CNAME DNS hostname records:

• [Link]

• [Link]

You need to configure a fully qualified domain name (FQDN) for each CNAME record to redirect enrollment requests to the Intune servers.

How should you configure each FQDN? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 327/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #360 Topic 1

You have a Microsoft 365 E5 subscription and use Microsoft Intune.

You need to use a Sync bulk device action on all corporate-owned Windows devices.

What is the maximum number of devices you can include the action?

A. 25

B. 50

C. 100

D. 500

E. 1000

Correct Answer: C

[Link] 328/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #361 Topic 1

HOTSPOT

You have a Microsoft Entra tenant named [Link] that contains the users shown in the following table.

The tenant contains a standalone workgroup computer named Computer1 that runs Window 11. Computer1 contains the local users shown in the

following table.

Computer1 needs to be joined to [Link].

Which local users can join Computer1 to [Link], and the Microsoft Entra credentials of which user can be used? To answer, select the

appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 329/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #362 Topic 1

HOTSPOT

You have a Microsoft Entra tenant named [Link] that contains the dynamic membership groups shown in the following table.

You add devices to [Link] as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 330/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #363 Topic 1

You have a Microsoft 365 E5 subscription.

You have a Microsoft Intune enrollment profile for Android Enterprise devices that has the following settings:

• Name: Profile1

• Token type: Corporate-owned, fully managed

You need to enroll a new Android device in Intune by using Profile1.

What should you use to enroll the device?

A. a QR code

B. the Company Portal app

C. the Microsoft Authenticator app

D. the Intune app

Correct Answer: C

Question #364 Topic 1

You use Microsoft Defender for Office 365.

You plan to automate an attack simulation campaign.

Any users that fail the simulation must take additional training based on the simulation results.

What is the maximum number of days the training will be available to the users after the simulation?

A. 7

B. 15

C. 30

D. 45

Correct Answer: C

[Link] 331/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #365 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription.

The subscription contains users that have devices onboarded to Microsoft Defender for Endpoint. Defender for Endpoint is configured to forward

signals to Microsoft Defender for Cloud Apps.

Cloud Discovery identifies a risky web app named App1.

You need to block users from connecting to App1 from Microsoft Edge. Users must be able to bypass the restriction.

Which type of app tag should you use, and what should you configure to integrate Defender for Endpoint with Defender for Cloud Apps? To answer,

select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 332/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #366 Topic 1

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps.

You plan to perform a security audit of all the apps detected by Cloud Discovery.

You need to track which apps were audited. The solution must ensure that the list of audited apps can be displayed in the cloud app catalog.

What should you do?

A. Apply a custom app tag to each app.

B. Deploy Conditional Access App Control.

C. Define each app as a critical asset.

D. Generate a Cloud Discovery snapshot report.

E. Enable app governance.

Correct Answer: A

Question #367 Topic 1

You have a Microsoft 365 E5 subscription that contains Windows 11 devices.

All the devices are onboarded to Microsoft Defender for Endpoint.

You need to compare the configuration of the devices against industry standard benchmarks.

What should you use?

A. Attack surface map

B. Events

C. Security baselines assessment

D. Initiatives

Correct Answer: C

[Link] 333/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #368 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription.

You need to use Microsoft Graph PowerShell to assign a Microsoft 365 E5 license to a new user named user1@[Link].

How should you complete the command? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 334/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #369 Topic 1

HOTSPOT

You have a Microsoft 365 E5 subscription.

You plan to create a Conditional Access policy named Policy1.

You need to ensure that only Passwordless MFA authentication methods are used when administrators attempt to access the Azure portal, Azure

PowerShell, or Azure Command-Line Interface (CLI).

How should you configure Policy1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Correct Answer:

[Link] 335/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Question #370 Topic 1

HOTSPOT

Você tem uma assinatura do Microsoft 365 E5 que contém dispositivos registrados no Microsoft Intune, conforme mostrado na tabela a seguir.

A assinatura contém os usuários mostrados na tabela a seguir.

A função Remote Help Tier1 é configurada conforme mostrado na exposição a seguir.

Para cada uma das seguintes declarações, selecione Sim se a declaração for verdadeira. Caso contrário, selecione Não.

OBSERVAÇÃO: Cada seleção correta vale um ponto.

[Link] 336/337
27/02/2025, 11:07 Exame MD-102 - Perguntas e respostas reais gratuitas, página 1 | ExamTopics

Resposta correta:

Navegue pelo menos 50% para aumentar a taxa de aprovação

Visualizando página 1 de 1 páginas.

Visualizando perguntas 1 - 370 de 370 perguntas

[Link] 337/337

Você também pode gostar