Looking for more? Click here to get the full PDF with 178+ practice questions for $10 for offline study and deeper preparation.
Question 1
You use a Microsoft Intune subscription to manage iOS devices. You configure a device compliance policy that blocks jailbroken iOS devices. You need to enable Enhanced jailbreak detection. What should you configure?
A. the device compliance policy
B. the Compliance policy settings
C. a network location
D. a configuration profile
Show Answer
Correct Answer:
B. the Compliance policy settings
Question 2
Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations. These workstations have been enrolled in Microsoft Intune. You are creating a device configuration profile for the workstations. You have been informed that a custom image should be displayed on the sign-in screen. Which of the following is a Device restriction setting that should be configured?
A. Locked screen experience
B. Personalization
C. Display
D. General
Show Answer
Correct Answer:
A. Locked screen experience
Question 3
Your company has a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com. All users have computers that run Windows 10. The computers are joined to Azure AD and managed by using Microsoft Intune. You need to ensure that you can centrally monitor the computers by using the Update Compliance solution. What should you create in Intune?
A. a device configuration profile
B. a conditional access policy
C. a device compliance policy
D. an update policy
Show Answer
Correct Answer:
A. a device configuration profile
Question 4
You manage a Microsoft 365 environment that has co-management enabled. All computers run Windows 10 and are deployed by using the Microsoft Deployment Toolkit (MDT). You need to recommend a solution to deploy Microsoft Office 365 ProPlus to new computers. The latest version must always be installed. The solution must minimize administrative effort. What is the best tool to use for the deployment? More than one answer choice may achieve the goal. Select the BEST answer.
A. Microsoft Intune
B. Microsoft Deployment Toolkit
C. Office Deployment Tool (ODT)
D. a Group Policy object (GPO)
E. Microsoft System Center Configuration Manager
Show Answer
Correct Answer:
A. Microsoft Intune
Question 5
You have a Microsoft Intune subscription associated to an Azure Active Directory (Azure AD) tenant named contoso.com. Users use one of the following three suffixes when they sign in to the tenant: us.contoso.com, eu.contoso.com, or contoso.com. You need to ensure that the users are NOT required to specify the mobile device management (MDM) enrollment URL as part of the enrollment process. The solution must minimize the number of changes. Which DNS records do you need?
A. three TXT records
B. one CNAME record only
C. one TXT record only
D. three CNAME records
Show Answer
Correct Answer:
D. three CNAME records
Question 6
You have an Azure Active Directory (Azure AD) tenant and 100 Windows 10 devices that are Azure AD joined and managed by using Microsoft Intune. You need to configure Microsoft Defender Firewall and Microsoft Defender Antivirus on the devices. The solution must minimize administrative effort. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
A. To configure Microsoft Defender Antivirus, create a device configuration profile and configure the Endpoint protection settings
B. To configure Microsoft Defender Firewall, create a device configuration profile and configure the Device restrictions settings
C. To configure Microsoft Defender Firewall, create a Group Policy Object (GPO) and configure Windows Defender Firewall with Advanced Security
D. To configure Microsoft Defender Antivirus, create a Group Policy Object (GPO) and configure Windows Defender Antivirus settings
E. To configure Microsoft Defender Antivirus, create a device configuration profile and configure the Device restrictions settings
F. To configure Microsoft Defender Firewall, create a device configuration profile and configure the Endpoint protection settings
Show Answer
Correct Answer:
E. To configure Microsoft Defender Antivirus, create a device configuration profile and configure the Device restrictions settings
F. To configure Microsoft Defender Firewall, create a device configuration profile and configure the Endpoint protection settings
Question 7
Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations. These workstations have been enrolled in Microsoft Intune. You have been tasked with making sure that the has self-service password reset enabled on the logon screen. You have navigated to the Microsoft Intune blade. Which of the following is the setting you should configure?
A. The Device configuration settings
B. The Device compliance settings
C. The Windows AutoPilot deployment settings
D. The App protection settings
Show Answer
Correct Answer:
A. The Device configuration settings
Question 8
You have an on-premises server named Server1 that hosts a Microsoft Deployment Toolkit (MDT) deployment share named MDT1. You need to ensure that MDT1 supports multicast deployments. What should you install on Server1?
A. Windows Server Update Services (WSUS)
B. Multipath I/O (MPIO)
C. Windows Deployment Services (WDS)
D. Multipoint Connector
Show Answer
Correct Answer:
C. Windows Deployment Services (WDS)
Question 9
You have a Microsoft Azure subscription that contains an Azure Log Analytics workspace. You deploy a new computer named Computer1 that runs Windows 10. Computer1 is in a workgroup. You need to ensure that you can use Log Analytics to query events from Computer1. What should you do on Computer1?
A. Configure the commercial ID
B. Join Azure Active Directory (Azure AD)
C. Create an event subscription
D. Install the Microsoft Monitoring Agent
Show Answer
Correct Answer:
D. Install the Microsoft Monitoring Agent
Question 10
You need to ensure that computer objects can be created as part of the Windows Autopilot deployment. The solution must meet the technical requirements. To what should you grant the right to create the computer objects?
A. Server2
B. Server1
C. GroupA
D. DC1
Show Answer
Correct Answer:
B. Server1
Question 11
You have 100 computers that run Windows 8.1. You need to identify which computers can be upgraded to Windows 10. What should you use?
A. Microsoft Assessment and Planning (MAP) Toolkit
B. Update Compliance in Azure
C. Windows Assessment Toolkit
D. Microsoft Deployment Toolkit (MDT)
Show Answer
Correct Answer:
A. Microsoft Assessment and Planning (MAP) Toolkit
Question 12
You company has a Microsoft Azure Active Directory (Azure AD) tenant that includes Microsoft Intune. All of the Windows 10 devices are enrolled in Intune. You are preparing to configure a Windows Information Protection (WIP) policy: You need to make sure that the policy is configured to allow for the logging of unacceptable data sharing, but not blocking the action. Which of the following is the WIP protection mode that you should use?
A. Block
B. Silent
C. Off
D. Allow Overrides
Show Answer
Correct Answer:
B. Silent
Question 13
Your network contains an Active Directory domain named contoso.com. The domain contains computers that run Windows 10 and are joined to the domain. The domain is synced to Microsoft Azure Active Directory (Azure AD). You create an Azure Log Analytics workspace and deploy the Update Compliance solution. You need to enroll the computers in the Update Compliance solution. Which Group Policy setting should you configure?
A. Specify intranet Microsoft update service location
B. Allow Telemetry
C. Configure the Commercial ID
D. Connected User Experiences and Telemetry
Show Answer
Correct Answer:
C. Configure the Commercial ID
Question 14
You need to meet the device management requirements for the developers. What should you implement?
A. Enterprise State Roaming
B. folder redirection
C. home folders
D. known folder redirection in Microsoft OneDrive
Show Answer
Correct Answer:
A. Enterprise State Roaming
Question 15
You are creating a device configuration profile in Microsoft Intune. You need to configure specific OMA-URI settings in the profile. Which profile type should you use?
A. Identity protection
B. Custom
C. Device restrictions (Windows 10 Team)
D. Device restrictions
Show Answer
Correct Answer:
B. Custom
Question 16
You manage your company's Microsoft 365 subscription. You are tasked with creating an app protection policy for the Microsoft Outlook app on iOS devices that are not enrolled in Microsoft 365 Device Management. You have to make sure that the policy is configured to prohibit the users from using the Outlook app if the operating system version is less than 12.0.0. You also have to make sure that an alphanumeric passcode is required for users to access the Outlook app. Which of the following is policy settings that you should configure? (Choose two.)
A. Conditional launch
B. Data transfer exemptions
C. Data protection
D. Access requirements
Show Answer
Correct Answer:
A. Conditional launch
D. Access requirements
Question 17
You have a Windows 10 device named Device1 that is joined to Active Directory and enrolled in Microsoft Intune. Device 1 is managed by using Group Policy and Intune. You need to ensure that the Intune settings override the Group Policy settings. What should you configure?
A. a device configuration profile
B. an MDM Security Baseline profile
C. a device compliance policy
D. a Group Policy Object (GPO)
Show Answer
Correct Answer:
A. a device configuration profile
Question 18
You need to enable Microsoft Defender Credential Guard on computers that run Windows 10. What should you install on the computers?
A. Hyper-V
B. Microsoft Defender Application Guard
C. a guarded host
D. containers
Show Answer
Correct Answer:
A. Hyper-V
Question 19
You have been tasked with reusing a Windows 10 computer that was assigned to a user who is no longer with the company. The computer will be assigned to a new user. You plan to make use of Windows AutoPilot to redeploy the computer. Which of the following actions should you take FIRST?
A. Reset the computer
B. Wipe the computer
C. Create a HTML file containing the computer info
D. Create a CSV file containing the computer info
Show Answer
Correct Answer:
D. Create a CSV file containing the computer info
Question 20
You need to meet the technical requirements for the IT department. What should you do first?
A. From the Azure Active Directory blade in the Azure portal, enable Seamless single sign-on
B. From the Configuration Manager console, add an Intune subscription
C. From the Azure Active Directory blade in the Azure portal, configure the Mobility (MDM and MAM) settings
D. From the Microsoft Intune blade in the Azure portal, configure the Windows enrollment settings
Show Answer
Correct Answer:
B. From the Configuration Manager console, add an Intune subscription
Aced these? Get the Full Exam
Download the complete MD-101 study bundle with 178+ questions in a single printable PDF.