Microsoft Microsoft Certifications MD-102 Questions & Answers
Question 101:
You have a Microsoft 365 E5 subscription that contains 100 Windows 10 devices enrolled in Microsoft Intune.
You plan to use Endpoint analytics.
You need to create baseline metrics.
What should you do first?
A. Modify the Baseline regression threshold.
B. Onboard 10 devices to Endpoint analytics.
C. Create a Log Analytics workspace.
D. Create an Azure Monitor workbook.
Correct Answer: C
Onboarding from the Endpoint analytics portal is required for Intune managed devices. Reference: https://docs.microsoft.com/en-us/mem/analytics/enroll-intune
Question 102:
You install a feature update on a computer that runs Windows 10. How many days do you have to roll back the update?
A. 5
B. 10
C. 14
D. 30
Correct Answer: B
Microsoft has changed the time period associated with operating system rollbacks with Windows 10 version 1607, decreasing it to 10 days. Previously, Windows 10 had a 30-day rollback period.
You have a Microsoft Azure subscription that contains an Azure Log Analytics workspace.
You deploy a new computer named Computer1 that runs Windows 10. Computer1 is in a workgroup.
You need to ensure that you can use Log Analytics to query events from Computer1.
What should you do on Computer1?
A. Join Azure AD.
B. Configure Windows Defender Firewall.
C. Create an event subscription
D. Install the Azure Monitor Agent.
Correct Answer: A
The Windows client installer supports latest Windows machines only that are Microsoft Entra joined or Microsoft Entra hybrid joined. https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-windows-client
Question 104:
You have a Microsoft 365 E5 subscription and 100 unmanaged iPad devices.
You need to deploy a specific iOS update to the devices. Users must be prevented from manually installing a more recent version of iOS.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. Create a device configuration profile.
B. Enroll the devices in Microsoft Intune by using the Intune Company Portal.
C. Create a compliance policy.
D. Create an iOS app provisioning profile.
E. Enroll the devices in Microsoft Intune by using Apple Business Manager.
Correct Answer: AB
Configure defer software update in Configuration profiles, but iOS need to be enrolled via Intune company portal.
Question 105:
You have a Microsoft 365 subscription that includes Microsoft Intune.
You have an update ring named UpdateRing1 that contains the following settings:
1.
Automatic update behavior: Auto install and restart at a scheduled time
2.
Automatic behavior frequency: First week of the month
3.
Scheduled install day: Tuesday
4.
Scheduled install time: 3 AM
From the Microsoft Intune admin center, you select Uninstall for the feature updates of UpdateRing1.
When will devices start to remove the feature updates?
A. when a user approves the uninstall
B. as soon as the policy is received
C. next Tuesday
D. the first Tuesday of the next month
Correct Answer: B
Update rings for Windows 10 and later policy in Intune
Uninstall
An Intune administrator can use Uninstall to uninstall (roll back) the latest feature update or the latest quality update for an active or paused update ring. After uninstalling one type, you can then uninstall the other type. Intune doesn't support
or manage the ability of users to uninstall updates.
Important
When you use the Uninstall option, Intune passes the uninstall request to devices immediately.
Windows devices start removal of updates as soon as they receive the change in Intune policy. Update removal isn't limited to maintenance schedules, even when they're configured as part of the update ring.
If the update removal requires a device restart, the device restarts without offering device users an option to delay.
You have a Microsoft 365 subscription. All devices run Windows 10.
You need to prevent users from enrolling the devices in the Windows Insider Program.
What two configurations should you perform from the Microsoft Intune admin center? Each correct answer is a complete solution.
NOTE: Each correct selection is worth one point.
A. a device restrictions device configuration profile
B. an app configuration policy
C. a Windows 10 and later security baseline
D. a custom device configuration profile
E. a Windows 10 and later update ring
Correct Answer: DE
D: Microsoft Intune includes many built-in settings to control different features on a device. You can also create custom profiles, which are created similar to built-in profiles. Custom profiles are great when you want to use device settings and features that aren't built in to Intune. These profiles include features and settings for you to control on devices in your organization. For example, you can create a custom profile that sets the same feature for every Windows device.
E Set up Insider Preview builds using Intune
1.
Log in to the Azure portal and select Intune.
2.
Go to Software Updates > Windows 10 Update Rings and select + Create to make an Update Ring policy. Add a name and select the Settings section to configure its settings.
You have a Microsoft 365 subscription that contains 1,000 Windows 11 devices enrolled in Microsoft Intune.
You plan to use Intune to deploy an application named App1 that contains multiple installation files.
What should you do first?
A. Prepare the contents of App1 by using the Microsoft Win32 Content Prep Tool.
B. Create an Android application package (APK).
C. Upload the contents of App1 to Intune.
D. Install the Microsoft Deployment Toolkit (MDT).
Correct Answer: A
B. An Android application package (APK) is used to deploy Android apps, not Win32 apps.
C. You cannot upload the contents of App1 to Intune until you have prepared the app content by using the Microsoft Win32 Content Prep Tool.
D. The Microsoft Deployment Toolkit (MDT) is used to deploy Windows operating systems and other software to computers, not to manage mobile devices.
Question 108:
Your company implements Azure AD, Microsoft 365, Microsoft Intune, and Azure Information Protection.
The company's security policy states the following:
1.
Personal devices do not need to be enrolled in Intune.
2.
Users must authenticate by using a PIN before they can access corporate email data.
3.
Users can use their personal iOS and Android devices to access corporate cloud services.
4.
Users must be prevented from copying corporate email data to a cloud storage service other than Microsoft OneDrive for Business.
You need to configure a solution to enforce the security policy.
What should you create?
A. a device configuration profile from the Microsoft Intune admin center
B. a data loss prevention (DLP) policy from the Microsoft Purview compliance portal
C. an insider risk management policy from the Microsoft Purview compliance portal
D. an app protection policy from the Microsoft Intune admin center
Correct Answer: D
By implementing app-level policies, you can restrict access to company resources and keep data within the purview of your IT department.
Note: The important benefits of using App protection policies are the following:
Protecting your company data at the app level. Because mobile app management doesn't require device management, you can protect company data on both managed and unmanaged devices. The management is centered on the user identity, which removes the requirement for device management.
End-user productivity isn't affected and policies don't apply when using the app in a personal context. The policies are applied only in a work context, which gives you the ability to protect company data without touching personal data.
App protection policies makes sure that the app-layer protections are in place. For example, you can:
Require a PIN to open an app in a work context Control the sharing of data between apps Prevent the saving of company app data to a personal storage location MDM, in addition to MAM, makes sure that the device is protected. For example, you can require a PIN to access the device, or you can deploy managed apps to the device. You can also deploy apps to devices through your MDM solution, to give you more control over app management.
You have a Microsoft 365 E5 subscription and 100 computers that run Windows 10.
You need to deploy Microsoft Office Professional Plus 2019 to the computers by using Microsoft Office Deployment Tool (ODT).
What should you use to create a customization file for ODT?
A. the Microsoft 365 admin center
B. the Microsoft Intune admin center
C. the Microsoft Purview compliance portal
D. the Microsoft 365 Apps admin center
Correct Answer: D
To work with configuration files in the cloud, sign in to the Microsoft 365 Apps admin center and go to the Device Configuration page under Customization. From that page, you can do the following actions:
To create a new file, select Create, create a configuration file, and then select Done. The configuration file is automatically saved to the cloud as part of your tenant.
To edit an existing file, select the name of the file, make your changes, and then select Done.
To get a link to a configuration file, select the file, select Get Link, and then select Copy. You can use the link to refer to the configuration file when you use the Office Deployment Tool.
You have a Microsoft 365 subscription that contains 500 Android Enterprise devices.
All the devices are enrolled in Microsoft Intune.
You need to deliver bookmarks to the Chrome browser on the devices.
What should you create?
A. a compliance policy
B. a configuration profile
C. an app protection policy
D. an app configuration policy
Correct Answer: D
An app configuration policy is a better way to deliver bookmarks to the Chrome browser on Android devices than a configuration profile.
To deliver bookmarks to the Chrome browser on Android devices, you would create an app configuration policy that specifies the bookmarks that you want to be added to the browser. The policy would then be assigned to your managed devices. Once the policy is applied, the bookmarks will be added to Chrome automatically. To deliver bookmarks using a configuration profile, you would need to create a file that contains the bookmark data. The file would then be pushed to your managed devices. Once the file is on the device, you would need to use a script to
import the bookmarks into Chrome.
This process is more complex and time-consuming than using an app configuration policy. It also requires you to create and maintain a bookmark file, which can be cumbersome if you have a large number of bookmarks or if you need to frequently update them. https://learn.microsoft.com/en-us/mem/intune/apps/apps-configure-chrome-android
Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your MD-102 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.