Free MD-102 Exam Braindumps - New 2024 Microsoft Pratice Exam [Q97-Q122]

Share

Free MD-102 Exam Braindumps - New 2024 Microsoft Pratice Exam

Practice Test for MD-102 Certification Real 2024 Mock Exam

NEW QUESTION # 97
Your network contains an Active Directory domain. The domain contains 1.000 computers that run Windows 11.
You need to configure the Remote Desktop settings of all the computers. The solution must meet the following requirements:
* Prevent the sharing of clipboard contents.
* Ensure that users authenticate by using Network Level Authentication (NLA).
Which two nodes of the Group Policy Management Editor should you use? To answer, select the appropriate nodes in the answer are a. NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 98
You have a Windows 11 capable device named Device1 that runs the 64-bit version of Windows 10 Enterprise and has Microsoft Office 2019 installed. You have the Windows 11 Enterprise images shown in the following table.

Which images can be used to perform an in-place upgrade of Device1?

  • A. image1 only
  • B. lmage2only
  • C. Image1 and Image2

Answer: B


NEW QUESTION # 99
Your network contains an Active Directory domain. The domain contains 1.000 computers that run Windows
11.
You need to configure the Remote Desktop settings of all the computers. The solution must meet the following requirements:
* Prevent the sharing of clipboard contents.
* Ensure that users authenticate by using Network Level Authentication (NLA).
Which two nodes of the Group Policy Management Editor should you use? To answer, select the appropriate nodes in the answer area. NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation


NEW QUESTION # 100
You have a Microsoft Intune subscription.
You are creating a Windows Autopilot deployment profile named Profile1 as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 101
Your company standardizes on Windows 10 Enterprise for all users.
Some users purchase their own computer from a retail store. The computers run Windows 10 Pro.
You need to recommend a solution to upgrade the computers to Windows 10 Enterprise, join the computers to Azure AD, and install several Microsoft Store apps. The solution must meet the following requirements:
* Ensure that any applications installed by the users are retained.
* Minimize user intervention.
What is the best recommendation to achieve the goal?
More than one answer choice may achieve the goal.
Select the BEST answer.

  • A. Windows Deployment Services (WDS)
  • B. Microsoft Deployment Toolkit (MDT)
  • C. Windows Autopilot
  • D. a Windows Configuration Designer provisioning package

Answer: C


NEW QUESTION # 102
You have devices that are not rooted enrolled in Microsoft Intune as shown in the following table.

The devices are members of a group named Group1.
In Intune, you create a device compliance location that has the following configurations:
* Name: Network1
* IPv4 range: 192.168.0.0/16
In Intune. you create a device compliance policy for the Android platform. The policy has the following configurations:
* Name: Policy1
* Device health: Rooted devices: Block
* Locations: Location: Network1
* Mark device noncompliant: Immediately
* Assigned: Group1
The Intune device compliance policy has the following configurations:
* Mark devices with no compliance policy assigned as: Compliant
* Enhanced jailbreak detection: Enabled
* Compliance status validity period (days): 20
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Device1 is marked as compliant. = No Device2 is marked as compliant. = Yes Device3 is marked as compliant. = No Device1 is marked as noncompliant because it is rooted and the device compliance policy Policy1 blocks rooted devices under the Device health setting1.
Device2 is marked as compliant because it is not rooted and it is within the network location Network1 that is specified in the device compliance policy Policy11.
Device3 is marked as noncompliant because it is outside the network location Network1 that is specified in the device compliance policy Policy11. The device compliance location setting requires devices to be in a specific network range to be compliant2.


NEW QUESTION # 103
You have an Azure AD tenant named contoso.com.
You have a workgroup computer named Computer! that runs Windows 11.
You need to add Computer1 to contoso.com.
What should you use?

  • A. dsreecmd.exe
  • B. the Settings app
  • C. netdom.exe
  • D. Computer Management

Answer: A


NEW QUESTION # 104
You have two computers that run Windows 10. The computers are enrolled in Microsoft Intune as shown in the following table.

Windows 10 update rings are defined in Intune as shown in the following table.

You assign the update rings as shown in the following table.

What is the effect of the configurations on Computer1 and Computer2? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/windows/deployment/update/waas-wufb-intune
https://allthingscloud.blog/configure-windows-update-business-using-microsoft-intune/


NEW QUESTION # 105
You have a Microsoft 365 subscription that contains 100 devices enrolled in Microsoft Intune.
You need to review the startup processes and how often each device restarts.
What should you use?

  • A. Intune Data Warehouse
  • B. Azure Monitor
  • C. Device Management
  • D. Endpoint analytics

Answer: A


NEW QUESTION # 106
Your network contains an Active Directory domain. The domain contains a computer named Computer! that runs Windows 11. You need to enable the Windows Remote Management (WinRM) service on Computer1 and perform the following configurations:
* For the WinRM service, set Startup type to Automatic.
* Create a listener that accepts requests from any IP address.
* Enable a firewall exception for WS-Management communications.
Which PowerShell cmdlet should you use?

  • A. Enable-PSSessionConfiguration
  • B. Connect-WSMan
  • C. Enable-PSRemoting
  • D. Invoke-WSManAction

Answer: C


NEW QUESTION # 107
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

In the Microsoft 365 Apps admin center, you create a Microsoft Office customization.
Which users can download the Office customization file from the admin center?

  • A. Admin1, Admin2, and Admin3 only
  • B. Admin3 and Admin4 only
  • C. Admin1 and Admin3 only
  • D. Admin1, Admin2, Admin3. and Admin4
  • E. Admin3 only

Answer: A

Explanation:
Explanation
* Admin1
An application admin has full access to enterprise applications, applications registrations, and application proxy settings.
* Admin2
Mark your app as publisher verified.
In Azure AD this user must be a member of one of the following roles: Application Admin, Cloud Application Admin, or Global Admin.
* Admin3
Office Apps admin - Assign the Office Apps admin role to users who need to do the following:
- Use the Office cloud policy service to create and manage cloud-based policies for Office
- Create and manage service requests
- Manage the What's New content that users see in their Office apps
- Monitor service health
Reference:
Office Apps admin - Assign the Office Apps admin role to users who need to do the following
https://docs.microsoft.com/en-us/azure/active-directory/develop/mark-app-as-publisher-verified


NEW QUESTION # 108
You have a Microsoft 365 E5 subscription that uses Microsoft Intune.
You add apps to Intune as shown in the following table.

You need to create an app configuration policy named Policy1 for the Android Enterprise platform.
Which apps can you manage by using Policyl1?

  • A. App2 and App3 only
  • B. App1, App2, and App3
  • C. App2 only
  • D. App3 only
  • E. App1 and App3 only

Answer: A


NEW QUESTION # 109
You have a Microsoft 365 subscription.
Users have iOS devices that are not enrolled in Microsoft 365 Device Management.
You create an app protection policy for the Microsoft Outlook app as shown in the exhibit. (Click the Exhibit tab.)

You need to configure the policy to meet the following requirements:
Prevent the users from using the Outlook app if the operating system version is less than 12.0.0.
Require the users to use an alphanumeric passcode to access the Outlook app.
What should you configure in an app protection policy for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/intune/app-protection-policy-settings-ios


NEW QUESTION # 110
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 111
You need to meet the technical requirements for the iOS devices.
Which object should you create in Intune?

  • A. An app protection policy
  • B. A compliance policy
  • C. A device configuration profile
  • D. A Deployment profile

Answer: C

Explanation:
Reference:
https://docs.microsoft.com/en-us/intune/device-restrictions-configure
https://docs.microsoft.com/en-us/intune/device-restrictions-ios


NEW QUESTION # 112
You have a Microsoft 365 subscription that includes Microsoft Intune.
You need to implement a Microsoft Defender for Endpoint solution that meets the following requirements:
* Enforces compliance for Defender for Endpoint by using Conditional Access
* Prevents suspicious scripts from running on devices
What should you configure? To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

To enforce compliance for Defender for Endpoint by using Conditional Access, you need to configure an Intune connection in the Defender for Endpoint portal. This allows you to use Intune device compliance policies to evaluate the health and compliance status of devices that are enrolled in Defender for Endpoint.
You can then use Conditional Access policies to block or allow access to cloud apps based on the device compliance status. References:
https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/conditional-access To prevent suspicious scripts from running on devices, you need to configure an attack surface reduction (ASR) rule in Intune. ASR rules are part of the endpoint protection settings that you can apply to devices by using device configuration profiles. You can use the ASR rule "Block Office applications from creating child processes" to prevent Office applications from launching child processes such as scripts or executables.
References:
https://docs.microsoft.com/en-us/mem/intune/protect/endpoint-protection-windows-10#attack-surface-reduction-


NEW QUESTION # 113
You have the device configuration profile shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Users can only access URLs that start with https://contoso.com/ Windows 10 and later devices can have multiple Microsoft Edge instances that each has a single tab he device configuration profile shown in the exhibit is a kiosk browser profile that configures Microsoft Edge to run in kiosk mode. The profile has the following settings:
Kiosk mode: Enabled
Kiosk type: Multi-app
Allowed URLs: https://contoso.com/*
Address bar: Disabled
These settings mean that users can only access URLs that start with https://contoso.com/ and cannot view the address bar in Microsoft Edge. The kiosk type of Multi-app allows users to open multiple instances of Microsoft Edge, but each instance can only have a single tab. Therefore, users cannot access any URL, cannot view the address bar in Microsoft Edge, and can have multiple Microsoft Edge instances that each has a single tab. References:
https://docs.microsoft.com/en-us/mem/intune/configuration/kiosk-settings#kiosk-browser-settings


NEW QUESTION # 114
You have an Azure AD tenant that contains the users shown in the following table.

You have the devices shown in the following table.

You have a Conditional Access policy named CAPolicy1 that has the following settings:
* Assignments
o Users or workload identities: User 1. User1
o Cloud apps or actions: Office 365 Exchange Online
o Conditions: Device platforms: Windows, iOS
* Access controls
o Grant Require multi-factor authentication
You have a Conditional Access policy named CAPolicy2 that has the following settings:
Assignments
o Users or workload identities: Used, User2
o Cloud apps or actions: Office 365 Exch
o Conditions
* Device platforms: Android, iOS
* Filter for devices
* Device matching the rule: Exclude filtered devices from policy
* Rule syntax: device. displayName- contains "1"
* Access controls
* Grant Block access
For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Answer:

Explanation:


NEW QUESTION # 115
You use Windows Admin Center to remotely administer computers that run Windows 10.
When connecting to Windows Admin Center, you receive the message shown in the following exhibit.

You need to prevent the message from appearing when you connect to Windows Admin Center.
To which certificate store should you import the certificate?

  • A. Client Authentication Issuers
  • B. Trusted Root Certification Authorities
  • C. Personal

Answer: B


NEW QUESTION # 116
You have a Microsoft 365 subscription that uses Microsoft Intune and contains 100 Windows 10 devices. You need to create Intune configuration profiles to perform the following actions on the devices:
* Deploy a custom Start layout.
* Rename the local Administrator account.
Which profile type template should you use for each action? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation


NEW QUESTION # 117
You have a Microsoft 365 E5 subscription that contains a user named User! and a web app named Appl.
App1 must only accept modern authentication requests.
You plan to create a Conditional Access policy named CAPolicy1 that will have the following settings:
* Assignments
* Users or workload identities: User1
* Cloud apps or actions: App1
* Access controls
* Grant: Block access
You need to block only legacy authentication requests to Appl. Which condition should you add to CAPolicy1?

  • A. Sign-in risk
  • B. User risk
  • C. Client apps
  • D. Device platforms
  • E. Filter for devices

Answer: C

Explanation:
Explanation
you can use the client apps condition to block legacy authentication requests to App11. Legacy authentication is a term that refers to authentication protocols that do not support modern authentication features such as multi-factor authentication or conditional access . Examples of legacy authentication protocols include Basic Authentication, Digest Authentication, NTLM, and Kerberos . To block legacy authentication requests, you need to configure the client apps condition to include Other clients, which covers any client that uses legacy authentication protocols13. References: : Conditional Access: Block legacy authentication | Microsoft Learn
https://learn.microsoft.com/en-us/mem/identity-protection/conditional-access/block-legacy-authentication 2:
What is legacy authentication? | Microsoft Learn
https://learn.microsoft.com/en-us/mem/identity-protection/conditional-access/legacy-authentication 3: Client apps condition in Azure Active Directory Conditional Access | Microsoft Learn
https://learn.microsoft.com/en-us/mem/identity-protection/conditional-access/client-apps-condition


NEW QUESTION # 118
You have a Microsoft 365 subscription that uses Microsoft Intune.
You plan to use Windows Autopilot to provision 25 Windows 11 devices.
You need to meet the following requirements during device provisioning:
* Display the progress of app and profile deployments.
* Join the devices to Azure AD.
What should you configure to meet each requirement? To answer drag the appropriate settings to the correct requirements. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation


NEW QUESTION # 119
You have a Microsoft 365 E5 subscription that contains the devices shown in the following table.
All devices have Microsoft Edge installed.
From the Microsoft Intune admin center, you create a Microsoft
You need to apply Edge1 to all the supported devices.
To which devices should you apply Edge1?

  • A. Device1, Device2, and Device4 only
  • B. Device1, Device2, and Device3 only
  • C. Device1 only
  • D. Device1, Device2, Device3, and Device4
  • E. Device1 and Device2 only

Answer: D


NEW QUESTION # 120
You have a Microsoft 365 subscription that uses Microsoft Intune Suite. You use Microsoft Intune to manage devices.
You need to review the startup times and restart frequencies of the devices. What should you use?

  • A. Microsoft Defender for Endpoint
  • B. Endpoint analytics
  • C. intune Data Warehouse
  • D. Azure Monitor

Answer: B

Explanation:
Explanation
Endpoint analytics is a feature of Microsoft Intune that provides insights into the performance and health of devices. You can use endpoint analytics to review the startup times and restart frequencies of the devices, as well as other metrics such as sign-in times, battery life, app reliability, and software inventory. References:
https://docs.microsoft.com/en-us/mem/analytics/overview


NEW QUESTION # 121
You have a Microsoft 365 subscription that contains two users named User1 and User2. You need to ensure that the users can perform the following tasks:
* User1 must be able to create groups and manage users.
* User2 must be able to reset passwords for no administrative users.
The solution must use the principle of least privilege.
Which role should you assign to each user? To answer, drag the appropriate roles to the correct users. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 122
......


Microsoft MD-102 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Implement the Intune Connector for Active Directory
  • Implement Conditional Access policies that require a compliance status
Topic 2
  • Manage device configuration for all supported device platforms by using Intune
  • Monitor and troubleshoot configuration profiles
Topic 3
  • Plan and implement an MDT deployment infrastructure
  • Plan and implement a Windows client deployment by using Windows Autopilot
Topic 4
  • Manage device updates for all supported device platforms by using Intune
  • Implement automated response capabilities in Defender for Endpoint
Topic 5
  • Manage Android updates by using configuration profiles
  • Configure Windows client delivery optimization by using Intune
Topic 6
  • Deploy Windows devices by using Autopilot
  • Configure device registration for Autopilot
Topic 7
  • Implement and manage security baselines in Intune
  • Plan and implement app protection and app configuration policies
Topic 8
  • Manage notifications for compliance policies
  • Plan and implement app protection policies for iOS and Android
Topic 9
  • Implement Conditional Access policies for app protection policies
  • Configure policies for Office apps by using Group Policy or Intune
Topic 10
  • Specify configuration profiles to meet requirements
  • Implement compliance policies for all supported device platforms by using Intune
Topic 11
  • Implement endpoint protection for all supported device platforms
  • Manage Microsoft 365 Apps by using the Microsoft 365 Apps admin center
Topic 12
  • Implement and manage Local Administrative Passwords Solution (LAPS) for Azure AD
  • Manage role-based access control (RBAC) for Intune
Topic 13
  • Configure Remote Desktop on a Windows client
  • Configure PowerShell remoting and Windows Remote Management (WinRM)

 

Prepare For Realistic MD-102 Dumps PDF - 100% Passing Guarantee: https://www.exam4pdf.com/MD-102-dumps-torrent.html

Check the Available MD-102 Exam Dumps with 235 QA's: https://drive.google.com/open?id=1FCPY5AKdS5HBipcJV3KzfPLDZEESKfwR