MD-101 Q76-100

Réussis tes devoirs et examens dès maintenant avec Quizwiz!

You have a Microsoft 365 subscription. All computers are enrolled in Microsoft Intune. You have business requirements for securing your Windows 10 environment as shown in the following table. Requirement1: Ensure that Microsoft Exchange Online can be accessed from known locations only. Requirement2: Lock a device that has a high Microsoft Defender Advanced Threat Protection risk score. What should you implement to meet each requirement? Requirement1: 1. A conditional access policy 2. A device compliance policy 3. A device configuration policy Requirement2: 1. A conditional access policy 2. A device compliance policy 3. A device configuration policy

1. A conditional access policy 2. A device compliance policy

You have a computer named Computer1 that runs Windows 10. Computer1 has the users shown in the following table. User1 - Administrators User2 - Replicator User3 - Guests User1 signs in to Computer1, creates the following files, and then signs out: ✑ File1.docx in C:\Users\User1\Desktop✑ File2.docx in C:\Users\Public\Public Desktop ✑ File3.docx in C:\Users\Default\ DesktopUser3 then signs in to Computer1 and creates a file named File4.docx in C:\Users\User3\Desktop. User2 has never signed in to Computer1. How many DOCX files will appear on the desktop of each user the next time each user signs in? 1. Number of documents that appear for User1: 0-5 2. Number of documents that appear for User2: 0-5 3. Number of documents that appear for User3: 0-5

1. 2 2. 2 3. 2

You have a workgroup computer named Computer1 that runs Windows 10 and has the users shown in the following table. User1 - Group1 User2 - Group2 User3 - Group3 Group1 is a member of Group3.You are creating a file named Kiosk.xml that specifies a lockdown profile for a multi-app kiosk. Kiosk.xml contains the following section. <UserGroup Type="LocalGroup" Name="Group3" /> You apply Kiosk.xml to Computer1.For each of the following statements, select Yes if the statement is true. Otherwise, select No. Yes/No 1. The lockdown profile applies to user1 2. The lockdown profile applies to user2 3. The lockdown profile applies to user3

1. No 2. No 3. Yes

Your network contains an Active Directory domain named contoso.com that syncs to Azure Active Directory (Azure AD). The domain contains the users shown in the following table. User1 - Windows AD User2 - Azure AD Enterprise State Roaming is enabled for User2. You have the computers shown in the following table. Computer1 - Windows 10 - Azure AD tenant Computer2 - Windows 8.1 - On-premises AD domain Computer3 - Windows 10 - Azure AD tenant Yes/No 1. If user1 modifies his desktop icons on Computer1, the changes will be on Computer2 2. If user1 modifies his desktop icons on Computer1, the changes will be on Computer3 3. If user2 modifies his desktop icons on Computer1, the changes will be on Computer3

1. No 2. No 3. Yes Enterprise State Roaming only works on Azure AD tenant devices/users and only on Windows 10

You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains a user named User1. User1 has the devices shown in the following table. Device1 - Windows 10 - Registered in Contoso.com: No Device2 - Android - Registered in Contoso.com: Yes Device3 - iOS - Registered in Contoso.com: Yes On September 5, 2019, you create and enforce a terms of use (ToU) in contoso.com. The ToU has the following settings: ✑ Name: Terms1 ✑ Display name: Terms1 name ✑ Require users to expand the terms of use: Off ✑ Require users to consent on every device: On ✑ Expire consents: On ✑ Expire starting on: October 10, 2019 ✑ Frequency: Monthly Yes/No User1 will be prompted to accept Terms1 on Device1 User1 will be prompted to accept Terms1 on Device2 User1 will be prompted to accept Terms1 on Device3

1. Yes 2. Yes 3. Yes

You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table. User1 - Group1 User2 -Group2 Contoso.com contains the devices shown in the following table. Device1 - Windows 10 - GroupA - Intune Managed: Yes Device2 - Windows 10 - GroupB - Intune Managed: No In Intune, you create the app protection policies shown in the following table. Policy1 - Windows 10 - With enrollment - Group1 Policy2 - Windows 10 - Without enrollment - Group2 Policy3 - Windows 10 - With enrollment - GroupA Policy4 - Windows 10 - Without enrollment - Group2 Yes/No 1. When User1 signs into Device1, Policy1 applies. 2. When User2 signs into Device1, Policy2 applies. 3. When User2 signs into Device2, Policy2 applies.

1. Yes 2. Yes 3. Yes

You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the devices shown in the following table. Device1 - Windows 10 Device2 - Android 8.0 Device3 - Android 9 Device4 - iOS 11.0 Device5 - iOS 11.4.1 All devices contain an app named App1 and are enrolled in Microsoft Intune. You need to prevent users from copying data from App1 and pasting the data into other apps. Which type of policy and how many policies should you create in Intune? Policy type: 1. App configuration policy 2. App protection policy 3. Conditional access policy 4. Device compliance policy Minimum number of policies: 1. 1 policies 2. 2 policies 3. 3 policies 4. 4 policies 5. 5 policies

2. App protection policy 3. 3 policies

Your company has computers that run Windows 8.1, Windows 10, or macOS. The company uses Microsoft Intune to manage the computers. You need to create an Intune profile to configure Windows Hello for Business on the computers that support it. Which platform type and profile type should you use? Platform type: 1. macOS 2. Windows 10 and later 3. Windows 8.1 and later Profile type: 1. Device restrictions 2. Device restrictions (Windows 10 Team) 3. Endpoint protection 4. Identity Protection

2. Windows 10 and later 4. Identity Protection

https://www.examtopics.com/exams/microsoft/md-101/view/20/ Your network contains an Active Directory domain named contoso.com. The domain contains 200 computers that run Windows 10. Folder Redirection for the Desktop folder is configured as shown in the following exhibit.

A. Clear the Grant the user exclusive rights to Desktop check box. B. Change the Policy Removal setting.

Your network contains an Active Directory named contoso.com. The domain contains two computers named Computer1 and Computer2 that run Windows 10. Folder Redirection is configured for a domain user named User1. The AppData\Roaming folder and the Desktop folder are redirected to a network share. User1 signs in to Computer1 and performs the following tasks: ✑ Configures screen saver to start after five minutes of inactivity ✑ Modifies the default save location for Microsoft Word ✑ Creates a file named File1.docx on the desktop ✑ Modifies the desktop background What will be retained when User1 signs in to Computer2? A. File1.docx and the desktop background only B. File1.docx, the screen saver settings, the desktop background, and the default save location for Word C. File1.docx only D. File1.docx, the desktop background, and the default save location for Word only

A. File1.docx and the desktop background only

Your company plans to deploy Windows 10 to devices that will be configured for English use and other devices that will be configured for Korean use. You need to create a single multivariant provisioning package for the planned devices. You create the provisioning package. What should you do next to add the language settings to the package? A. Modify the Customizations.xml file. B. Create a file named Languages.xml that contains a header for Korean. C. Modify the .ppkg file. D. Create a file named Languages.xml that contains a header for English.

A. Modify the Customizations.xml file.

You have an Azure Directory group named Group1 that contains Windows 10 Enterprise devices and Windows 10 Pro devices. From Microsoft Intune, you create a device configuration profile named Profile1. You need to ensure that Profile1 applies to only the Windows 10 Enterprise devices in Group1. Solution: You create an Azure Active Directory group that contains only the Windows 10 Enterprise devices. You assign Profile1 to the new group. Does this meet the goal? A. Yes B. No

A. Yes

You have an Azure Directory group named Group1 that contains Windows 10 Enterprise devices and Windows 10 Pro devices. From Microsoft Intune, you create a device configuration profile named Profile1. You need to ensure that Profile1 applies to only the Windows 10 Enterprise devices in Group1. Solution: You configure an applicability rule for Profile1. You assign Profile1 to Group1. Does this meet the goal? A. Yes B. No

A. Yes Applicability rules allow administrators to target devices in a group that meet specific criteria.

https://www.examtopics.com/exams/microsoft/md-101/view/16/ You have a Microsoft 365 subscription. You have a conditional access policy that requires multi-factor authentication (MFA) for users in a group name Sales when the users sign in from a trusted location. The policy is configured as shown in the exhibit. (Click the Exhibit tab.)

A. a condition

https://www.examtopics.com/exams/microsoft/md-101/view/20/ Your company has computers that run Windows 10. The employees at the company use the computers. You plan to monitor the computers by using the Update Compliance solution. You create the required resources in Azure. You need to configure the computers to send enhanced Update Compliance data. Which two Group Policy settings should you configure?

Allow device name to be sent in Windows diagnostic data Configure the Commercial ID

You are creating a device configuration profile in Microsoft Intune. You need to implement an ADMX-backed policy. Which profile type should you use? A. Identity protection B. Custom C. Device restrictions D. Device restrictions (Windows 10 Team)

B. Custom

You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune. You redirect Windows known folders to Microsoft OneDrive for Business. Which folder will be included in the redirection? A. Saved Games B. Documents C. Music D. Downloads E. Favorites F. AppData G. Videos

B. Documents

Your company has an internal portal that uses a URL of http://contoso.com.The network contains computers that run Windows 10. The default browser on all the computers is Microsoft Edge. You need to ensure that all users only use Internet Explorer to connect to the internal portal. The solution must ensure that Microsoft Edge can be used to connect to all other websites. What should you do from each computer? A. From Internet Explorer, configure the Compatibility View settings B. From the local policy, configure Enterprise Mode C. From Microsoft Edge, configure the Advanced Site Settings D. From the Settings app, configure the default web browser settings

B. From the local policy, configure Enterprise Mode

You have an Azure Directory group named Group1 that contains Windows 10 Enterprise devices and Windows 10 Pro devices. From Microsoft Intune, you create a device configuration profile named Profile1. You need to ensure that Profile1 applies to only the Windows 10 Enterprise devices in Group1. Solution: You create a scope tag, and then you add the scope tag to the Windows 10 Enterprise devices. You edit the settings of Profile1. Does this meet the goal? A. Yes B. No

B. No Use Intune scope tags to provide administrative users with a filtered a view to securable objects. Scope tags are filtering option provided in Intune to ease the admin jobs. So in this question the Scope tags are not used in the way that they are intended to be used. So again No

You have computers that run Windows 10 Pro. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune. You need to upgrade the computers to Windows 10 Enterprise. What should you configure in Intune? A. A device enrollment policy B. A device cleanup rule C. A device compliance policy D. A device configuration profile

D. A device configuration profile

You have an Azure Active Directory group named Group1. Group1 contains two Windows 10 Enterprise devices named Device1 and Device2.You create a device configuration profile named Profile1. You assign Profile1 to Group1.You need to ensure that Profile1 applies to Device1 only.What should you modify in Policy1? A. Scope (Tags) B. Settings C. Applicability Rules D. Assignments

D. Assignments

Your network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD). You have a Microsoft 365 subscription. You create a conditional access policy for Microsoft Exchange Online. You need to configure the policy to prevent access to Exchange Online unless a user is connecting from a device that is hybrid Azure AD-joined. Which settings should you configure? A. Locations B. Device platforms C. Sign-in risk D. Device state

D. Device state

Your company uses Microsoft Intune. More than 500 Android and iOS devices are enrolled in the Intune tenant. You plan to deploy new Intune policies. Different policies will apply depending on the version of Android or iOS installed on the device. You need to ensure that the policies can target the devices based on their version of Android or iOS.What should you configure first? A. Corporate device identifiers in Intune B. Device settings in Microsoft Azure Active Directory (Azure AD) C. Device categories in Intune D. Groups that have dynamic membership rules in Microsoft Azure Active Directory (Azure AD)

D. Groups that have dynamic membership rules in Microsoft Azure Active Directory (Azure AD)

You have an Azure Active Directory (Azure AD) tenant that contains a user named User1. User1 has the device shown in the following table. Device1 - Windows - 10.0.18362.0 - Azure AD Registered - None Device2 - Windows - 10.0.18362.30 - Azure AD Registered - Microsoft Intune Device3 - Windows - 10.0.18362.0 - Azure AD joined - None Device4 - Windows - 10.0.18362.30 - Azure AD joined - Microsoft Intune Enterprise State Roaming is configured for User1. User1 signs in to Device4 and changes the desktop. You need to identify on which devices User1 will have a changed desktop. Which devices should you identify? A. Device1, Device2, Device3, and Device4 B. Device4 only C. Device2, Device3, and Device4 only D. Device2 and Device4 only E. Device3 and Device4 only

E. Device3 and Device4 only

https://www.examtopics.com/exams/microsoft/md-101/view/20/ You are licensed for Microsoft Endpoint Manager. You use Microsoft Endpoint Configuration Manager and Microsoft Intune. You have devices enrolled in Configuration Manager as shown in the following table.

NO. Device1 is enrolled but not assigned. NO. Device2 is assigned but not enrolled. YES. Device3 is enrolled and assigned, because is included in both collections.


Ensembles d'études connexes

1Z0-144 Multiple Choice Questions

View Set

Voting and Political Participation

View Set

"A Good Man is Hard to Find" by Flannery O'Connor

View Set

NUR 307 - Chapter 25: Growth and Development of the Newborn and Infant

View Set

The Industrial Revolution: The Great Exhibition of 1851 at the Crystal Palace

View Set