Jon cert test case study 3
Your network contains an Active Directory domain named contoso.com. The domain contains 500 computers that run Windows 7. Some of the computers are used by multiple users. You plan to refresh the operating system of the computers to Windows 10. You need to retain the personalization settings to applications before you refresh the computers. The solution must minimize network bandwidth and network storage space. Which command should you run on the computer? To answer, select the appropriate options in the answer area.
/i MigApp.xml: spanstate.exe /nocompress/ ui:Contoso\*:/genconfig:file1.xml
Your company has a Microsoft Azure Active Directory (Azure AD) tenant. All users in the company are licensed for Microsoft Intune. You need to ensure that the users enroll their iOS device in Intune. What should you configure first?
A. A Device Enrollment Program (DEP) token.
Your company has a Microsoft 365 subscription. All the users in the finance department own personal devices that run iOS or Android. All the devices are enrolled in Microsoft Intune. The finance department adds new users each month. The company develops a mobile application named App1 for the finance department users. You need to ensure that only the finance department users can download App1. What should you do first?
A. Add App1 to Intune.
Your network contains an Active Directory domain named contoso.com. The domain contains 200 computers that run Windows 10. The target is set to Server1. You plan to use known folder redirection in Microsoft OneDrive for Business. You need to ensure that the desktop content of users remains on their desktop when you implement known folder redirection. Which two actions should you perform? Each correct answer presents part of the solution.
A. Clear the Grant the user exclusive rights to Desktop check box. B. Change the Policy Removal setting.
You have the 64-bit computers shown in the following table. You plan to perform an in-place upgrade to the 64-bit version of Windows 10. Which computers can you upgrade to the 64-bit version of Windows 10 in their current state?
A. Computer2 and Computer4 only
You have 10 computers that run Windows 7 and have the following configurations: •A single MBR disk •A disabled TPM chip •Disabled hardware virtualization •UEFI firmware running in BIOS mode •Enabled Data Execution Prevention (DEP) You plan to upgrade the computers to Windows 10. You need to ensure that the computers can use Secure Boot. Which two actions should you perform? Each correct answer presents part of the solution.
A. Convert the MBR disk to a GPT disk E. Convert the firmware from BIOS to UEFI.
You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (AD) and enrolled in Microsoft Intune. You need to enable self-service password reset on the sign-in screen. Which settings should you configure from the Microsoft Intune blade?
A. Device configuration
You have devices enrolled in Microsoft Intune as shown in the following table. You create an app protection policy named Policy1 that has the following settings: •Platform: Windows 10 •Protected apps: App1 •Exempt apps: App2 •Network boundary: Cloud resources, IPv4 ranges You assign Policy1 to Group1 and Group2. You exclude Group3 from Policy1. Which devices will apply Policy1?
A. Device1, Device2, Device4, and Device5
You have a Microsoft Azure Log Analytics workplace that collects all the event logs from the computers at your company. You have a computer named Computer1 than runs Windows 10. You need to view the events collected from Computer1. Which query should you run in Log Analytics?
A. Event | where Computer = = "Computer1"
Your company has an infrastructure that has the following: A Microsoft 365 tenant An Active Directory forest Microsoft Store for Business A Key Management Service (KMS) server A Windows Deployment Services (WDS) server A Microsoft Azure Active Directory (Azure AD) Premium tenant The company purchases 100 new computers that run Windows 10. You need to ensure that the new computers are joined automatically to Azure AD by using Windows AutoPilot. What should you use? To answer, select the appropriate options in the answer area. What are two valid methods a user can use to sign in? Each correct answer presents part of the solution.
A. Facial recognition C. A pin
Your company uses Microsoft Intune to manage devices. You need to ensure that only Android devices that use Android work profiles can enroll in Intune. Which two configurations should you perform in the device enrollment restrictions? Each correct answer presents part of the solution.
A. From Select platforms, set Android work profile to Allow. D. From Select platforms, set Android to Block.
You have 100 devices that run Windows 10 and are joined to Microsoft Azure Active Directory (Azure AD). You need to prevent users from joining their home computer to Azure AD. What should you do?
A. From the Device enrollment blade in the Intune admin center, modify the Enrollment restriction settings.
You need to enable Windows Defender Credential Guard on computers that run Windows 10. What should you install on the computers?
A. Hyper-V
Your company plans to deploy tablets to 50 meeting rooms. The tablets run Windows 10 and are managed by using Microsoft Intune. The tablets have an application named App1. You need to configure the tablets so that any user can use App1 without having to sign in. Users must be prevented from using other applications on the tablets. Which device configuration profile type should you use?
A. Kiosk
You have a shared computer that runs Windows 10. The computer is infected with a virus. You discover that a malicious TTF font was used to compromise the computer. You need to prevent this type of threat from affecting the computer in the future. What should you use?
A. Windows Defender Exploit Guard
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You need to ensure that feature and quality updates install automatically during a maintenance window. Solution: From the Maintenance Scheduler settings, you configure Automatic Maintenance Random Delay. Does this meet the goal?
A. Yes
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your company uses Windows AutoPilot to configure the computer settings of computers issued to users. A user named User1 has a computer named Computer1 that runs Windows 10. User1 leaves the company. You plan to transfer the computer to a user named User2. You need to ensure that when User2 first starts the computer, User2 is prompted to select the language setting and to agree to the license agreement. Solution: You create a new Windows AutoPilot user-driven deployment profile. Does this meet the goal?
A. Yes
Your company has a Microsoft Azure Active Directory (Azure AD) tenant. The company has a Volume Licensing Agreement and uses a product key to activate Windows 10. You plan to deploy Windows 10 Pro to 200 new computers by using the Microsoft Deployment Toolkit (MDT) and Windows Deployment Services (WDS). You need to ensure that the new computers will be configured to have the correct product key during the installation. What should you configure?
A. a WDS boot image
Your company has 200 computers that run Windows 10. The computers are managed by using Microsoft Intune. Currently, Windows updates are downloaded without using Delivery Optimization. You need to configure the computers to use Delivery Optimization. What should you create in Intune?
A. a device configuration profile
Your company has a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com. All users have computers that run Windows 10. The computers are joined to Azure AD and managed by using Microsoft Intune. You need to ensure that you can centrally monitor the computers by using Windows Analytics. What should you create in Intune?
A. a device configuration profile
Your network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD). The domain contains 500 laptops that run Windows 8.1 Professional. The users of the laptops work from home. Your company uses Microsoft Intune, the Microsoft Deployment Toolkit (MDT), and Windows Configuration Designer to manage client computers. The company purchases 500 licenses for Windows 10 Enterprise. You verify that the hardware and applications on the laptops are compatible with Windows 10. The users will bring their laptop to the office, where the IT department will deploy Windows 10 to the laptops while the users wait. You need to recommend a deployment method for the laptops that will retain their installed applications. The solution must minimize how long it takes to perform the deployment. What should you include in the recommendation?
A. an in-place upgrade
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 subscription. You have 20 computers that run Windows 10 and are joined to Microsoft Azure Active Directory (Azure AD). You plan to replace the computers with new computers that run Windows 10. The new computers will be joined to Azure AD. You need to ensure that the desktop background, the favorites, and the browsing history are available on the new computers. Solution: You configure Enterprise State Roaming. Does this meet the goal?
A: Yes
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your company uses Windows Update for Business. The research department has several computers that have specialized hardware and software installed. You need to prevent the video drivers from being updated automatically by using Windows Update. Solution: From the Device Installation settings in a Group Policy object (GPO), you enable Specify search order for device driver source locations, and then you select Do not search Windows Update. Does this meet the goal?
A: Yes
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your company uses Windows Update for Business. The research department has several computers that have specialized hardware and software installed. You need to prevent the video drivers from being updated automatically by using Windows Update. Solution: From the Windows Update settings in a Group Policy object (GPO), you enable Do not include drivers with Windows Updates. Does this meet the goal?
A: Yes
Your company has a Microsoft Azure Active Directory (Azure AD) tenant. The company uses Microsoft Intune to manage iOS, Android, and Windows 10 devices. The company plans to purchase 1,000 iOS devices. Each device will be assigned to a specific user. You need to ensure that the new iOS devices are enrolled automatically in Intune when the assigned user signs in for the first time. Which three actions should you perform in sequence?
Add a Device Enrollment Program (DEP) token. Create an enrollment profile Assign an enrollment profile
Your company uses Microsoft Intune to manage Windows 10, Android, and iOS devices. Several users purchase new iPads and Android devices. You need to tell the users how to enroll their device in Intune. What should you instruct the users to use for each device? To answer, select the appropriate options in the answer area.
Android device: The Intune Company Portal app iPad: The Intune Company Portal app
You have 1,000 computers that run Windows 10 and are members of an Active Directory domain. You create a workspace in Microsoft Azure Log Analytics. You need to capture the event logs from the computers to Azure. What should you do? To answer, select the appropriate options in the answer area.
Azure service to provision: Log Analytics Action to perform on the computers: Install the Microsoft Monitoring Agent
Your network contains an Active Directory domain. The domain contains 2,000 computers that run Windows 10. You implement hybrid Microsoft Azure Active Directory (Azure AD) and Microsoft Intune. You need to automatically register all the existing computers to Azure AD and enroll the computers in Intune. The solution must minimize administrative effort. What should you use?
B. A Windows AutoPilot deployment profile.
You need to assign the same deployment profile to all the computers that are configured by using Windows Autopilot. Which two actions should you perform? Each correct answer presents part of the solution.
B. Assign a Windows AutoPilot deployment profile to a group F. Create a Microsoft Azure Active Directory (Azure AD) group that has dynamic membership rules and uses the ZTDID tag
Your company has a System Center Configuration Manager deployment that uses hybrid mobile device management (MDM). All Windows 10 devices are Active Directory domain-joined. You plan to migrate from hybrid MDM to Microsoft Intune standalone. You successfully run the Intune Data Importer tool. You need to complete the migration. Which two actions should you perform? Each correct answer presents part of the solution
B. Change the tenant MDM authority to Intune. C. Assign all users Intune licenses.
You are creating a device configuration profile in Microsoft Intune. You need to implement an ADMX-backed policy. Which profile type should you use?
B. Custom
You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune. You redirect Windows known folders to Microsoft OneDrive for Business. Which folder will be included in the redirection?
B. Desktop
Your company uses Microsoft Intune. More than 500 Android and iOS devices are enrolled in the Intune tenant. You plan to deploy new Intune policies. Different policies will apply depending on the version of Android or iOS installed on the device. You need to ensure that the policies can target the devices based on their version of Android or iOS. What should you configure first?
B. Device settings in Microsoft Azure Active Directory (Azure AD)
You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune. You redirect Windows known folders to Microsoft OneDrive for Business. Which folder will be included in the redirection?
B. Documents
Your network contains an Active Directory named contoso.com. The domain contains two computers named Computer1 and Computer2 that run Windows 10. Folder Redirection is configured for a domain user named User1. The AppData\Roaming folder and the Desktop folder are redirected to a network share. User1 signs in to Computer1 and performs the following tasks: •Configures screen saver to start after five minutes of inactivity •Modifies the default save location for Microsoft Word •Creates a file named File1.docx on the desktop •Modifies the desktop background You need to identify what will be retained when User1 signs in to Computer2. What should you identify?
B. File1.docx, the screen saver settings, the desktop background, and the default save location for Word
Your company has a Microsoft 365 subscription. A new user named Admin1 is responsible for deploying Windows 10 to computers and joining the computers to Microsoft Azure Active Directory (Azure AD). Admin1 successfully joins computers to Azure AD. Several days later, Admin1 receives the following error message: "This user is not authorized to enroll. You can try to do this again or contact your system administrator with the error code (0x801c0003)." You need to ensure that Admin1 can join computers to Azure AD and follow the principle of least privilege.
B. Modify the Device settings in Azure AD.
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You need to ensure that feature and quality updates install automatically during a maintenance window. Solution: From the Maintenance Scheduler settings, you configure Automatic Maintenance Activation Boundary. Does this meet the goal?
B. No
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You need to ensure that feature and quality updates install automatically during a maintenance window. Solution: From the Windows Update settings, you enable Configure Automatic Updates, select 4- Auto download and schedule the install, and then enter a time. Does this meet the goal?
B. No
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your company uses Windows AutoPilot to configure the computer settings of computers issued to users. A user named User1 has a computer named Computer1 that runs Windows 10. User1 leaves the company. You plan to transfer the computer to a user named User2. You need to ensure that when User2 first starts the computer, User2 is prompted to select the language setting and to agree to the license agreement. Solution: You perform a remote Windows AutoPilot Reset. Does this meet the goal?
B. No
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your company uses Windows AutoPilot to configure the computer settings of computers issued to users. A user named User1 has a computer named Computer1 that runs Windows 10. User1 leaves the company. You plan to transfer the computer to a user named User2. You need to ensure that when User2 first starts the computer, User2 is prompted to select the language setting and to agree to the license agreement. Solution: You create a new Windows AutoPilot self-deploying deployment profile. Does this meet the goal?
B. No
You install a feature update on a computer that runs Windows 10. How many days do you have to roll back the update?
B: 10
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 subscription. You have 20 computers that run Windows 10 and are joined to Microsoft Azure Active Directory (Azure AD). You plan to replace the computers with new computers that run Windows 10. The new computers will be joined to Azure AD. You need to ensure that the desktop background, the favorites, and the browsing history are available on the new computers. Solution: You configure roaming user profiles. Does this meet the goal?
B: No
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You need to ensure that feature and quality updates install automatically during a maintenance window. Solution: From the Windows Update settings, you enable Configure Automatic Updates, select 3 - Auto download and notify for Install, and then enter a time. Does this meet the goal?
B: No
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your company uses Windows Update for Business. The research department has several computers that have specialized hardware and software installed. You need to prevent the video drivers from being updated automatically by using Windows Update. Solution: From the Device Installation and Restrictions settings in a Group Policy object (GPO), you enable Prevent installation of devices using drivers that match these device setup classes, and then you enter the device GUID. Does this meet the goal?
B: No
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your company uses Windows Update for Business. The research department has several computers that have specialized hardware and software installed. You need to prevent the video drivers from being updated automatically by using Windows Update. Solution: From the Settings app, you clear the Give me updates for other Microsoft products when I update Windows check box. Does this meet the goal?
B:No
Your network contains an Active Directory domain named contoso.com. The domain contains computers that run Windows 10 and are joined to the domain. The domain is synced to Microsoft Azure Active Directory (Azure AD). You create an Azure Log Analytics workspace and deploy the Device Health solution. You need to enroll the computers in Windows Analytics. Which Group Policy setting should you configure?
C. Configure the Commercial ID
You manage a Microsoft 365 environment that has co-management enabled. All computers run Windows 10 and are deployed by using the Microsoft Deployment Toolkit (MDT). You need to recommend a solution to deploy Microsoft Office 365 ProPlus to new computers. The latest version must always be installed. The solution must minimize administrative effort. What is the best tool to use for the deployment? More than one answer choice may achieve the goal. Select the BEST answer.
C. Office Deployment Toolkit (ODT)
You have a computer named Computer5 that has Windows 10 installed. You create a Windows PowerShell script named config.ps1. You need to ensure that config.ps1 runs after feature updates are installed on Computer5. Which file should you modify on Computer5?
C. SetupConfig.ini
You have a Microsoft Azure Active Directory (Azure AD) tenant. All corporate devices are enrolled in Microsoft Intune. You have a web-based application named App1 that uses Azure AD to authenticate. You need to prompt all users of App1 to agree to the protection of corporate data when they access App1 from both corporate and non-corporate devices. What should you configure?
C. Terms of use in Conditional access
Your company has a Microsoft 365 subscription. The company uses Microsoft Intune to manage all devices. The company uses conditional access to restrict access to Microsoft 365 services for devices that do not comply with the company's security policies. You need to identify which devices will be prevented from accessing Microsoft 365 services. What should you use?
C. The Device compliance blade in the Intune admin center.
Your network contains an Active Directory domain. The functional level of the forest and the domain is Windows Server 2012 R2. The domain contains 500 computers that run Windows 10. All the computers are managed by using Microsoft System Center 2012 R2 Configuration Manager. You need to enable co-management. What should you do first?
C. Upgrade Configuration Manager to Current Branch.
You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune. You need to ensure that only applications that you explicitly allow can run on the computers. What should you use?
C. Windows Defender Application Guard
Your company standardizes on Windows 10 Enterprise for all users. Some users purchase their own computer from a retail store. The computers run Windows 10 Pro. You need to recommend a solution to upgrade the computers to Windows 10 Enterprise, join the computers to Microsoft Azure Active Directory (Azure AD), and install several Microsoft Store apps. The solution must meet the following requirements: •Ensure that any applications installed by the users are retained. •Minimize user intervention. What is the best recommendation to achieve the goal? More than one answer choice may achieve the goal. Select the BEST answer.
C. a Windows Configuration Designer provisioning package
Your company implements Microsoft Azure Active Directory (Azure AD), Microsoft 365, Microsoft Intune, and Azure Information Protection. The company's security policy states the following: •Personal devices do not need to be enrolled in Intune. •Users must authenticate by using a PIN before they can access corporate email data. •Users can use their personal iOS and Android devices to access corporate cloud services. •Users must be prevented from copying corporate email data to a cloud storage service other than Microsoft OneDrive for Business. You need to configure a solution to enforce the security policy. What should you create?
C. an app protection policy from the Intune admin center
Your network contains an Active Directory forest. The forest contains a single domain and three sites named Site1, Site2, and Site3. Each site is associated to two subnets. Site1 contains two subnets named SubnetA and SubnetB. All the client computers in the forest run Windows 10. Delivery Optimization is enabled. You have a computer named Computer1 that is in SubnetA. From which hosts will Computer1 download updates?
C. the computers in SubnetA only
You have a Microsoft 365 subscription. You need to configure access to Microsoft Office 365 for unmanaged devices. The solution must meet the following requirements: •Allow only the Microsoft Intune Managed Browser to access Office 365 web interfaces. •Ensure that when users use the Intune Managed Browser to access Office 365 web interfaces, they can only copy data to applications that are managed by the company. Which two settings should you configure from the Microsoft Intune blade? To answer, select the appropriate settings in the answer area.
Client apps Conditional access
You have computers that run Windows 10 as shown in the following table. Computer2 and Computer3 are enrolled in Microsoft Intune. In a Group Policy object (GPO) linked to the domain, you enable the Computer Configuration/Administrative Templates/Windows Components/Search/Allow Cortana setting. In an Intune device configuration profile, you configure the following: Device/Vendor/MSFT/Policy/Config/ControlPolicyConflict/MDMWinsOverGP to a value of 1 Experience/AllowCortana to a value of 0. Each of the following statement, select Yes if the statement is true. Otherwise, select No.
Computer1 can use Cortana for each: Yes Computer2 can use Cortana for search: No Computer3 can use Cortana for search: No
Your company uses Windows Defender Advanced Threat Protection (Windows Defender ATP). What is the effect of the Windows Defender ATP configuration? To answer, select the appropriate options in the answer area.
Computer1 will be a member of: Group3, Group4, and Group5 only If you add the tag demo to Computer1, Computer1 will be a member of: Group1, Group2, Group3, Group4, and Group5
You use the Antimalware Assessment solution in Microsoft Azure Log Analytics. From the Protection Status dashboard, you discover the computers shown in the following table. Computer1: No real time protection Computer2: Not reporting You verify that both computers are connected to the network and running. What is a possible cause of the issue on each computer? To answer, drag the appropriate causes to the correct computers. Each cause may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Computer1: Windows Defender is disabled Computer2: Windows Defender Application Gaurd is misconfigured
You have 200 computers that run Windows 10. You need to create a provisioning package to configure the following tasks: •Remove the Microsoft News and the Xbox Microsoft Store apps. •Add a VPN connection to the corporate network. Which two customizations should you configure? To answer, select the appropriate customizations in the answer area.
Connectivity profiles Policies
You have computers that run Windows 10 Pro. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune. You need to upgrade the computers to Windows 10 Enterprise. What should you configure in Intune?
D. A device configuration profile
Your network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD). You have a Microsoft 365 subscription. You create a conditional access policy for Microsoft Exchange Online. You need to configure the policy to prevent access to Exchange Online unless is connecting from a device that is hybrid Azure AD-joined. Which settings should you configure?
D. Device state
Your company has a main office and six branch offices. The branch offices connect to the main office by using a WAN link. All offices have a local Internet connection and a Hyper-V host cluster. The company has a Microsoft System Center Configuration Manager deployment. The main office is the primary site. Each branch has a distribution point. All computers that run Windows 10 are managed by using both Configuration Manager and Microsoft Intune. You plan to deploy the latest build of Microsoft Office 365 ProPlus to all the computers. You need to minimize the amount of network traffic on the company's Internet links for the planned deployment. What should you include in the deployment plan?
D. From Configuration Manager, create an application deployment. In each office, copy the Office 365 distribution files to a Configuration Manager distribution point.
You manage 1,000 computers that run Windows 10. All the computers are enrolled in Microsoft Intune. You manage the servicing channel settings of the computers by using Intune. You need to review the servicing status of a computer. What should you do?
D. From Software updates, view the Per update ring deployment state.
You have a Microsoft Azure subscription that contains an Azure Log Analytics workspace. You deploy a new computer named Computer1 that runs Windows 10. Computer1 is in a workgroup. You need to ensure that you can use Log Analytics to query events from Computer1. What should you do on Computer1?
D. Install the Microsoft Monitoring Agent
You use Windows Defender Advanced Threat Protection (Windows Defender ATP) to protect computers that run Windows 10. You need to assess the differences between the configuration of Windows Defender ATP and the Microsoft recommended configuration baseline. Which tool should you use?
D. Microsoft Secure Score
You have 500 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune. You plan to distribute certificates to the computers by using Simple Certificate Enrollment Protocol (SCEP). NDES issues certificates from the subordinate CA. You are configuring a device profile as shown in the exhibit. (Click the Exhibit tab.) You need to complete the SCEP profile.
D. Server4
Your network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD). The domain contains computers that run Windows 10. The computers are enrolled in Microsoft Intune and Windows Analytics. Your company protects documents by using Windows Information Protection (WIP). You need to identify non-approved apps that attempt to open corporate documents. What should you use?
D. the App protection status report in Intune
Your network contains an Active Directory domain named contoso.com. You create a provisioning package named Package1 as shown in the following exhibit. What is the maximum number of devices on which you can run Package1 successfully?
D. unlimited
You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune. You need to configure an Intune device configuration profile to meet the following requirements: •Prevent Microsoft Office applications from launching child processes. •Block users from transferring files over FTP. Which two settings should you configure in Endpoint protection? To answer, select the appropriate settings in the answer area.
Endpoint Protection: Windows Defender Application Gu- 11 settings available Windows Defender Exploit Guard- 20 settings available
Your network contains an Active Directory domain. The domain contains 1,200 computers that run Windows 8.1. You deploy an Upgrade Readiness solution in Microsoft Azure and configure the computers to report to Upgrade Readiness. From Upgrade Readiness, you open a table view of the applications. You need to filter the view to show only applications that can run successfully on Windows 10. How should you configure the filter in Upgrade Readiness? To answer, select the appropriate options in the answer area.
Filter column: UpgradeDecision Filter value: Ready to upgrade
Your network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD). All computers are joined to the domain and registered to Azure AD. The network contains a Microsoft System Center Configuration Manager (Current Batch) deployment that is configured for co-management with Microsoft Intune. All the computers in the finance department are managed by using Configuration Manager. All the computers in the marketing department are managed by using Intune. You install new computers for the users in the marketing department by using the Microsoft Deployment Toolkit (MDT). You purchase an application named App1 that uses an MSI package. You need to install App1 on the finance department computers and the marketing department computers. How should you deploy App1 to each department? To answer, drag the appropriate deployment methods to the correct departments. Each deployment method may be used once, more than once, or not at all. You may need to drag the split bat between panes or scroll to view content.
Finance department: From Configuration Manager, add an application Marketing department: From Intune, add a line of business app
Your network contains an Active Directory domain named constoso.com that is synced to Microsoft Azure Active Directory (Azure AD). All computers are enrolled in Microsoft Intune. The domain contains the computers shown in the following table. You are evaluating which Intune actions you can use to reset the computers to run Windows 10 Enterprise with the latest update. Which computers can you reset by using each action? To answer, select the appropriate options in the answer area.
Fresh Start action: Computer2 and Computer 3 only Wipe action: Computer 1, Computer2, and Computer3
Your company uses Microsoft Intune. You have a Microsoft Store for Business account. You need to ensure that you can deploy Microsoft Store for Business apps by using Intune. Which three actions should you perform in sequence?
From Microsoft Store for Business, add a management tool. From Microsoft Store for Business, assign apps to people From Intune, sync Microsoft Store for Business
Your company has a computer named Computer1 that runs Windows 10. Computer1 was used by a user who left the company. You plan to repurpose Computer1 and assign the computer to a new user. You need to redeploy Computer1 by using Windows AutoPilot. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Generate a CSV file that contains the computer information Generate a JSON file that contains the computer information Reset the computer
You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune. You need to set a custom image as the wallpaper and sign-in screen. Which two settings should you configure in Device restrictions? To answer, select the appropriate settings in the answer area.
Locked Screen Experience- 6 settings available Personalization- 1 setting available
Your company has an infrastructure that has the following: A Microsoft 365 tenant An Active Directory forest Microsoft Store for Business A Key Management Service (KMS) server A Windows Deployment Services (WDS) server A Microsoft Azure Active Directory (Azure AD) Premium tenant The company purchases 100 new computers that run Windows 10. You need to ensure that the new computers are joined automatically to Azure AD by using Windows AutoPilot. What should you use? To answer, select the appropriate options in the answer area.
Management tool: Azure Active Directory admin center Required information from each computer: Device serial number and hardware hash
You have a computer named Computer1 that runs Windows 10. Computer1 has the users shown in the following table. User 1 is Admin, User2 is Replicator, User3 is Guests. User1 signs in to Computer1, creates the following files, and then signs out: docx in C:\Users\User1\Desktop docx in C:\Users\Public\Public Desktop docx in C:\Users\Default\ Desktop User3 signs in to Computer1 and creates a file named File4.docx in C:\Users\User3\Desktop. User2 has never signed in to Computer1. How many DOCX files will appear on the desktop of each user the nest time each user signs in? To answer, select the appropriate options in the answer area.
Number of documents that will appear for User1: 3 Number of documents that will appear for User2: 1 Number of documents that will appear for User3: 2
You use Microsoft Intune to manage Windows updates. You have computers that run Windows 10. The computers are in a workgroup and are enrolled in Intune. For each of the following statements, select Yes if the statement is true. Otherwise, select No.
On Computer1, quality updates will be deferred for two days: No On Computer2, quality updates will be deferred for seven days: Yes On Computer3, quality updates will be deferred for 14 days: No
Your company has computers that run Windows 8.1, Windows 10, or macOS. The company uses Microsoft Intune to manage the computers. You need to create an Intune profile to configure Windows Hello for Business on the computers that support it. Which platform type and profile type should you use? To answer, select the appropriate options in the answer area.
Platform type: Windows 10 and later Profile type: Endpoint protection
You have a Microsoft 365 subscription. Users have iOS devices that are not enrolled in Microsoft 365 Device Management. You need to configure the policy to meet the following requirements: Prevent the users from using the Outlook app if the operating system version is less than 12.0.0. Require the users to use an alphanumeric passcode to access the Outlook app. What should you configure in an app protection policy for each requirement? To answer, select the appropriate options in the answer area.
Prevent the users from using Outlook if the operating system version is less than 12.0.0.: Conditional launch Require the users to use alphanumeric passcode to access Outlook: Access requirements
You have two computers that run Windows 10. What is the effect of the configurations on Computer1 and Computer2? To answer, select the appropriate options in the answer area.
Quality deferral on Computer1: 3 days Quality deferral on Computer2: 3 days
You have a Microsoft 365 subscription. All computers are enrolled in Microsoft Intune. What should you implement to meet each requirement? To answer, select the appropriate options in the answer area.
Requirement 1: A conditional access policy Requirement2: A device compliance policy
You have 100 computers that run Windows 8.1. You plan to deploy Windows 10 to the computers by performing a wipe and load installation. You need to recommend a method to retain the user settings and the user data. Which three actions should you recommend be performed in sequence?
Run scan state. exe. Deploy Windows 10 Run loadstone. exe.
You have computers that run Windows 10 and are configured by using Windows AutoPilot. A user performs the following tasks on a computer named Computer1: Creates a VPN connection to the corporate network Installs a Microsoft Store app named App1 Connects to a Wi-Fi network You perform a Windows AutoPilot Reset on Computer1. What will be the state of the computer when the user signs in? To answer, select the appropriate options in the answer area.
The Wi-Fi connection will be: Retained and the passphrase will be retained App1 will be: Removed The VPN connection will be: Removed
You have a hybrid Microsoft Azure Active Directory (Azure AD) tenant. Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
To apply the profile to a new computer, you must first: import a CSV file into Windows Autopilot When the Windows Autopilot profile is applied to a computer, the computer will be: registered in Azure AD only
Your company has a computer named Computer1 that runs Windows 10 Pro. The company develops a proprietary Universal Windows Platform (UWP) app named App1. App1 is signed with a certificate from a trusted certification authority (CA). You need to sideload App1 to Computer1. What should you do? To answer, select the appropriate options in the answer area.
To enable sideloading: Configure the For developers settings in the Settings app To side load App1: Run the Add-AppxPackage cmdlet
Your network contains an Active Directory domain. Active Directory is synced with Microsoft Azure Active Directory (Azure AD). There are 500 domain-joined computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune. You plan to implement Windows Defender Exploit Guard. You need to create a custom Windows Defender Exploit Guard policy, and then distribute the policy to all the computers. What should you do? To answer, select the appropriate options in the answer area.
Tool to use to configure the settings: Security & Compliance in Microsoft 365 Distribution method: A Group Policy object (GPO)
Your network contains an Active Directory domain. The domain contains computers that run Windows 10 and are enrolled in Microsoft Intune. Updates are deployed by using Windows Update for Business. Users in a group named Group1 must meet the following requirements: Update installations must occur any day only between 00:00 and 05:00. Updates must be downloaded from Microsoft and from other company computers that already downloaded the updates. You need to configure the Windows 10 Update Rings in Intune to meet the requirements. Which two settings should you modify? To answer, select the appropriate settings in the answer area.
User experience settings: Notify download delivery optimization download mode: Not configured
Your company has a Microsoft Azure Active Directory (Azure AD) tenant and computers that run Windows 10. The company uses Microsoft Intune to manage the computers. User3 is a device enrollment manager (DEM) in Intune. For each of the following statements, select Yes if the statement is true. Otherwise, select No.
User1 can enroll a Windows device in Intune: No User2 can enroll a Windows device in Intune: No User3 can enroll an iOS device in Intune: Yes
You have a Microsoft Intune subscription. Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
Users who deploy by using Profile1: can modify the desktop settings only for themselves Users can configure the [answer] during the deployment: keyboard layout
You have 100 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune. You need to configure the following device restrictions: Block users from browsing to suspicious websites. Scan all scripts loaded into Microsoft Edge. Which two settings should you configure in Device restrictions? To answer, select the appropriate settings in the answer area.
Windows Defender SmartScreen 3 settings available Windows Defender Antivirus 34 settings available
You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com. All Windows 10 devices are enrolled in Microsoft Intune. You configure the following settings in Windows Information Protection (WIP): Protected apps: App1 Exempt apps: App2 Windows Information Protection mode: Silent App1, App2, and App3 use the same file format. You create a file named File1 in App1. You need to identify which apps can open File1. What apps should you identify?
You can open File1 from: App1, and App2 only An action will be logged when you attempt to open File1 from: App2 and App3 only
Your network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD). You have a Microsoft Office 365 subscription. All computers are joined to the domain and have the latest Microsoft OneDrive sync client (OneDrive.exe) installed. On all the computers, you configure the OneDrive settings as shown in the following exhibit. Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
[ANSWER] will sync automatically by using OneDrive: The Documents folder To reduce the disk space used by a user profile, you must [answer]: enable OneDrive Files On-Demand