Latest MD-101 Dumps Questions V16.02 Have Been Available For Candidates

No need to worry about MD-101 Managing Modern Desktops certification exam, latest MD-101 dumps questions V16.02 have been available for all candidates. The current MD-101 exam dumps are based on the new Managing Modern Desktops exam contents. Valid Microsoft MD-101 exam dumps are being verified by the specialist and these specialists created confident that the MD-101 questions and answers covering all of the subjects from the true Managing Modern Desktops exam.

Check Free Dumps OF MD-101 Dumps Questions V16.02 Below

1. Topic 1, Litware inc

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.

To start the case study

To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.

General Overview

Litware, Inc. is an international manufacturing company that has 3,000 employees. The company has sales, marketing, research, human resources (HR), development, and IT departments.

Litware has two main offices in New York and Los Angeles. Litware has five branch offices in Asia.

Existing Environment

Current Business Model

The Los Angeles office has 500 developers. The developers work flexible hours ranging from 11 AM to 10 PM.

Litware has a Microsoft System Center 2012 R2 Configuration Manager deployment.

During discovery, the company discovers a process where users are emailing bank account information of its customers to internal and external recipients.

Current Environment

The network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD). The functional level of the forest and the domain is Windows Server 2012 R2. All domain controllers run Windows Server 2012 R2.

Litware has the computers shown in the following table.

The development department uses projects in Azure DevOps to build applications.

Most of the employees in the sales department are contractors. Each contractor is assigned a computer that runs Windows 10. At the end of each contract, the computer is assigned to a different contractor. Currently, the computers are re-provisioned manually by the IT department.

Problem Statements

Litware identifies the following issues on the network:

- Employees in the Los Angeles office report slow Internet performance when updates are downloading. The employees also report that the updates frequently consume considerable resources when they are installed. The Update settings are configured as shown in the Updates exhibit. (Click the Updates button.)

- Management suspects that the source code for the proprietary applications in Azure DevOps in being shared externally.

- Re-provisioning the sales department computers is too time consuming.

Requirements

Business Goals

Litware plans to transition to co-management for all the company-owned Windows 10 computers.

Whenever possible, Litware wants to minimize hardware and software costs.

Device Management Requirements

Litware identifies the following device management requirements:

- Prevent the sales department employees from forwarding email that contains bank account information.

- Ensure that Microsoft Edge Favorites are accessible from all computers to which the developers sign in.

- Prevent employees in the research department from copying patented information from trusted applications to untrusted applications.

Technical Requirements

Litware identifies the following technical requirements for the planned deployment:

- Re-provision the sales department computers by using Windows AutoPilot.

- Ensure that the projects in Azure DevOps can be accessed from the corporate network only.

- Ensure that users can sign in to the Azure AD-joined computers by using a PIN. The PIN must expire every 30 days.

- Ensure that the company name and logo appears during the Out of Box Experience (OOBE) when using Windows AutoPilot.

Exhibits

Updates

What should you configure to meet the technical requirements for the Azure AD-joined computers?

2. What should you use to meet the technical requirements for Azure DevOps?

3. HOTSPOT

You need to meet the OOBE requirements for Windows AutoPilot.

Which two settings should you configure from the Azure Active Directory blade? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

4. You need to meet the device management requirements for the developers.

What should you implement?

5. HOTSPOT

You need to recommend a solution to meet the device management requirements.

What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

6. What should you upgrade before you can configure the environment to support co-management?

7. HOTSPOT

You need to resolve the performance issues in the Los Angeles office.

How should you configure the update settings? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

8. HOTSPOT

You need to meet the technical requirements for Windows AutoPilot.

Which two settings should you configure from the Azure Active Directory blade? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

9. You need to capture the required information for the sales department computers to meet the technical requirements.

Which Windows PowerShell command should you run first?

10. Topic 2, Contoso Ltd

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.

To start the case study

To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.

Overview

Contoso, Ltd, is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York.

Contoso has the users and computers shown in the following table.

The company has IT, human resources (HR), legal (LEG), marketing (MKG) and finance (FIN) departments.

Contoso uses Microsoft Store for Business and recently purchased a Microsoft 365 subscription.

The company is opening a new branch office in Phoenix. Most of the users in the Phoenix office will work from home.

Existing Environment

The network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).

All member servers run Windows Server 2016. All laptops and desktop computers run Windows 10 Enterprise.

The computers are managed by using Microsoft Endpoint Configuration Manager. The mobile devices are managed by using Microsoft Intune.

The naming convention for the computers is the department acronym, followed by a hyphen, and then four numbers, for example, FIN-6785. All the computers are joined to the on-premises Active Directory domain.

Each department has an organizational unit (OU) that contains a child OU named Computers. Each computer account is in the Computers OU of its respective department.

Intune Configuration

The domain has the users shown in the following table.

User2 is a device enrollment manager (DEM) in Intune.

The devices enrolled in Intune are shown in the following table.

The device compliance policies in Intune are configured as shown in the following table.

The device compliance policies have the assignments shown in the following table.

The device limit restrictions in Intune are configured as shown in the following table.

Requirements

Planned Changes

Contoso plans to implement the following changes:

- Provide new computers to the Phoenix office users. The new computers have Windows 10 Pro preinstalled and were purchased already.

- Start using a free Microsoft Store for Business app named App1.

- Implement co-management for the computers.

Technical Requirements :

Contoso must meet the following technical requirements:

- Ensure that the users in a group named Group4 can only access Microsoft Exchange Online from devices that are enrolled in Intune.

- Deploy Windows 10 Enterprise to the computers of the Phoenix office users by using Windows Autopilot.

- Monitor the computers in the LEG department by using Windows Analytics.

- Create a provisioning package for new computers in the HR department.

- Block iOS devices from sending diagnostic and usage telemetry data.

- Use the principle of least privilege whenever possible.

- Enable the users in the MKG department to use App1.

- Pilot co-management for the IT department.

HOTSPOT

You are evaluating which devices are compliant.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

11. HOTSPOT

You need to meet the technical requirements for the new HR department computers.

How should you configure the provisioning package? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

12. HOTSPOT

What is the maximum number of devices that User1 and User2 can enroll in Intune? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

13. HOTSPOT

You need a new conditional access policy that has an assignment for Office 365 Exchange Online.

You need to configure the policy to meet the technical requirements for Group4.

Which two settings should you configure in the policy? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

14. You need to prepare for the deployment of the Phoenix office computers.

What should you do first?

15. You need to prepare for the deployment of the Phoenix office computers.

What should you do first?

16. HOTSPOT

To which devices do Policy1 and Policy2 apply? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

17. You need to meet the requirements for the MKG department users.

What should you do?

18. You need to meet the technical requirements for the iOS devices.

Which object should you create in Intune?

19. DRAG DROP

You need to meet the technical requirements for the LEG department computers.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

20. You need to meet the technical requirements for the IT department.

What should you do first?

21. Topic 3, Contoso, Ltd. (NEW)

Case Study

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.

To start the case study

To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.

Overview

Contoso, Ltd. is a consulting company that has a main office in Montreal and branch offices in Seattle and New York.

Contoso has a Microsoft 365 E5 subscription.

Network Environment

The network contains an on-premises Active domain named Contoso.com.

The domain contains the servers shown in the following table.

Contoso has a hybrid Azure Active Directory (Azure AD) tenant named Contoso.com.

Contoso has a Microsoft Store for Business instance.

Users and Groups

The Contoso.com tenant contains the users shown in the following table.

All users are assigned a Microsoft Office 365 license and an Enterprise Mobility + Security E3 license.

Enterprise State Roaming is enabled for Group1 and GroupA.

Group and Group have a Membership type of Assign

Devices

Contoso has the Windows 10 devices shown in the following table.

The Windows 10 devices are joined to Azure AD and enrolled in Microsoft intune.

The Windows 10 devices are configured as shown in the following table.

All the Azure AD joined devices have an executable file named C:AppA.exe and a folder named D:Folder 1.

Microsoft Endpoint Manager Configuration

Microsoft Endpoint Manager has the compliance policies shown in the following table.

The Compliance policy settings are shown in the following exhibit.

The Automatic Enrolment settings have the following configurations:

• MDM user scope GroupA

• MAM user scope: GroupB

You have an Endpoint protection configuration profile that has the following Controlled folder access settings:

• Name: Protection1

• Folder protection: Enable

• List of apps that have access to protected folders: CVAppA.exe

• List of additional folders that need to be protected: D:Folderi1

• Assignments

Windows Autopilot Configuration

Currently, there are no devices deployed by using Window Autopilot

The Intune connector tor Active Directory is installed on Server 1.

Planned Changes

Contoso plans to implement the following changes:

• Purchase a new Windows 10 device named Device6 and enroll the device in Intune.

• New computers will be deployed by using Windows Autopilot and will be hybrid Azure AO joined.

• Deploy a network boundary configuration profile that will have the following settings:

• Name Boundary 1

• Network boundary 192.168.1.0/24

• Scope tags: Tag 1

• Assignments;

• included groups: Group 1. Group2

• Deploy two VPN configuration profiles named Connection! and Connection that will have the following settings:

• Name: Connection 1

• Connection name: VPNI

• Connection type: L2TP

• Assignments:

• Included groups: Group1. Group2, GroupA

• Excluded groups: ―

• Name: Connection

• Connection name: VPN2

• Connection type: IKEv2 i Assignments:

• included groups: GroupA

• Excluded groups: GroupB

• Purchase an app named App1 that is available in Microsoft Store for Business and to assign the app to all the users.

Technical Requirements

Contoso must meet the following technical requirements:

• Users in GroupA must be able to deploy new computers.

• Administrative effort must be minimized.

HOTSPOT

User1 and User2 plan to use Sync your settings.

On which devices can the users use Sync your settings? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

22. Which users can purchase and assign App1?

23. Which user can enroll Device6 in Intune?

24. HOTSPOT

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

25. HOTSPOT

You implement the planned changes for Connection1 and Connection2

How many VPN connections will there be for User1 when the user signs in to Device 1 and Devke2? To answer select the appropriate options in the answer area. NOTE; Each correct selection is worth one point.

26. Topic 4, Misc. Questions

HOTSPOT

You upgrade three computers from Windows 8.1 to Windows 10 as shown in the following table.

The in-place upgrade settings used to perform the upgrade are shown in the following table.

After the upgrade, you perform the following actions on each computer:

- Add a local user account named LocalAdmin1.

- Install Microsoft Office 2019.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

27. HOTSPOT

You use Microsoft Intune to manage Windows updates.

You have computers that run Windows 10. The computers are in a workgroup and are enrolled in Intune.

The computers are configured as shown in the following table.

On each computer, the Select when Quality Updates are received Group Policy setting is configured as shown in the following table.

You have Windows 10 update rings in Intune as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

28. You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune.

You redirect Windows known folders to Microsoft OneDrive for Business.

Which folder will be included in the redirection?

29. You have an Azure Active Directory (Azure AD) tenant named adatum.com that contains two computers named Computer1 and Computer2. The computers run Windows 10 and are members of a group named GroupA.

The tenant contains a user named User1 that is a member of a group named Group 1.

You need to ensure that if User1 changes the desktop background on Computer1, the new desktop background will appear when User1 signs in to Computer2.

What should you do?

30. You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune.

You redirect Windows known folders to Microsoft OneDrive for Business.

Which folder will be included in the redirection?

31. Your network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD). The domain contains computers that run Windows 10. The computers are enrolled in Microsoft Intune and Windows Analytics.

Your company protects documents by using Windows Information Protection (WIP).

You need to identify non-approved apps that attempt to open corporate documents.

What should you use?

32. You have a computer named Computer1 that runs Windows 10. Computer is used by a user named User1.

You need to ensure that when User1 opens websites from untrusted locations by using Microsoft Edge, Microsoft Edge runs in isolated container.

What should you do first?

33. HOTSPOT

Your network contains an Active Directory domain. The domain contains computers that run Windows 10 and are enrolled in Microsoft Intune. Updates are deployed by using Windows Update for Business.

Users in a group named Group1 must meet the following requirements:

✑ Update installations must occur any day only between 00:00 and 05:00.

✑ Updates must be downloaded from Microsoft and from other company computers that already downloaded the updates.

You need to configure the Windows 10 Update Rings in Intune to meet the requirements.

Which two settings should you modify? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

34. Your network contains an Active Directory domain. The domain contains 100 computers that run Windows 10.

You need to prevent users and apps from accessing dangerous websites.

What should you configure?

35. HOTSPOT

You have a Microsoft Intune subscription.

You are creating a Windows Autopilot deployment profile named Profile1 as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.

36. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these

questions will not appear in the review screen.

Your company uses Windows Update for Business.

The research department has several computers that have specialized hardware and software installed.

You need to prevent the video drivers from being updated automatically by using Windows Update.

Solution: From the Device Installation settings in a Group Policy object (GPO), you enable Specify search

order for device driver source locations, and then you select Do not search Windows Update.

Does this meet the goal?

37. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure Directory group named Group1 that contains Windows 10 Enterprise devices and Windows 10 Pro devices.

From Microsoft Intune, you create a device configuration profile named Profile1.

You need to ensure that Profile1 applies to only the Windows 10 Enterprise devices in Group1.

Solution: You configure an applicability rule for Profile1. You assign Profile1 to Group1.

Does this meet the goal?

38. Your network contains an Active Directory domain. The domain contains 2,000 computers that run Windows 10.

You implement hybrid Microsoft Azure Active Directory (Azure AD) and Microsoft Intune.

You need to automatically register all the existing computers to Azure AD and enroll the computers in Intune.

The solution must minimize administrative effort.

What should you use?

39. Your company uses Microsoft Intune to manage devices. You need to ensure that only Android devices that use Android work profiles can enroll in Intune.

Which two configurations should you perform in the device enrollment restrictions? Each correct answer

presents part of the solution. NOTE: each correct selection is worth one point.

40. Your company has a Microsoft 365 subscription.

The company uses Microsoft Intune to manage all devices.

The company uses conditional access to restrict access to Microsoft 365 services for devices that do not

comply with the company’s security policies.

You need to identify which devices will be prevented from accessing Microsoft 365 services.

What should you use?

41. Your company has a Microsoft 365 subscription.

A new user named Admin1 is responsible for deploying Windows 10 to computers and joining the computers to Microsoft Azure Active Directory (Azure AD).

Admin1 successfully joins computers to Azure AD.

Several days later, Admin1 receives the following error message: “This user is not authorized to enroll. You can try to do this again or contact your system administrator with the error code (0x801c0003).”

You need to ensure that Admin1 can join computers to Azure AD and follow the principle of least privilege.

42. You have a computer named Computer5 that has Windows 10 installed.

You create a Windows PowerShell script named config.ps1.

You need to ensure that config.ps1 runs after feature updates are installed on Computer5.

Which file should you modify on Computer5?

43. You have Windows 10 devices that are managed by using Microsoft Intune. Intune and the Microsoft Store for Business are integrated.

You need to deploy the Remote Desktop modern app as an automatic install to the Windows 10 devices without user interaction.

Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

44. HOTSPOT

Your network contains an Active Directory domain named contoso.com. The domain contains 500 computers that run Windows 7. Some of the computers are used by multiple users.

You plan to refresh the operating system of the computers to Windows 10.

You need to retain the personalization settings to applications before you refresh the computers. The solution must minimize network bandwidth and network storage space.

Which command should you run on the computer? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

45. You have a Microsoft 365 subscription.

You have 20 computers that run Windows 10 and are joined to Microsoft Azure Active Directory (Azure AD)

You plan to replace the computers with new computers that run Windows 10. The new computers will be joined to Azure AD.

You need 10 ensure that the desktop background, the favorites, and the browsing history are available on the new computer.

What should you use?

46. You have a Microsoft 365 tenant that contains the Windows 10 devices shown in the following table.

You enable Enterprise State Roaming

You need to ensure that User1 can sync Windows settings across the devices.

What should you do?

47. HOTSPOT

You use the Microsoft Deployment Toolkit (MDT) to deploy Windows 10.

You need to modify the deployment share to meet the following requirements:

✑ Ensure that the user who performs the installation is prompted to set the local Administrator password.

✑ Define a rule for how to name computers during the deployment.

The solution must NOT replace the existing WinPE image.

Which file should you modify for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

48. HOTSPOT

You have a Microsoft 365 tenant that uses Microsoft Intune to manage the devices shown in the following table.

You need to deploy a compliance solution that meets the following requirements:

✑ Marks the devices as Not Compliant if they do not meet compliance policies

✑ Remotely locks noncompliant devices

What is the minimum number of compliance policies required, and which devices support the remote lock action? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

49. HOTSPOT

You have groups that use the Dynamic Device membership type as shown in the following table.

You are deploying Microsoft 365 apps.

You have devices enrolled in Microsoft Intune as shown in the following table.

In the Microsoft Endpoint Manager admin center, you create a Microsoft 365 Apps app as shown in the exhibit. (Click the Exhibit tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

50. HOTSPOT

You have a Microsoft 365 tenant that uses Microsoft Intune to manage personal and corporate devices.

The tenant contains three Windows 10 devices as shown in the following exhibit.

How will Intune classify each device after the devices are enrolled in Intune automatically? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

51. You have a server that runs the Microsoft Deployment Toolkit (MDT). You have computers that run Windows 8.1 or Windows 10.

You have a Microsoft 365 tenant. Microsoft 365 Enterprise E5 licenses are assigned to all users.

You need to recommend a strategy to install Windows 10 on the Windows 8.1 computers. The installation must retain the user files, settings, and supported applications.

What should you recommend?

52. HOTSPOT

Your network contains an on-premises Active Directory forest named contoso.com. The

forest contains a user named User1 and two computers named Computer1 and Computer2 that run Windows 10.

User1 is configured as shown in the following exhibit.

You rename file \Server1ProfilesUser1.V6NTUSER.DAT as NTUSER.MAN.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

53. HOTSPOT

You have a Microsoft 365 subscription.

Users have iOS devices that are not enrolled in Microsoft 365 Device Management.

You create an app protection policy for the Microsoft Outlook app as shown in the exhibit. (Click the Exhibit tab.)

You need to configure the policy to meet the following requirements:

✑ Prevent the users from using the Outlook app if the operating system version is less than 12.0.0.

✑ Require the users to use an alphanumeric passcode to access the Outlook app.

What should you configure in an app protection policy for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

54. Your company plans to deploy tablets to 50 meeting rooms.

The tablets run Windows 10 and are managed by using Microsoft Intune. The tablets have an application

named App1.

You need to configure the tablets so that any user can use App1 without having to sign in. Users must be

prevented from using other applications on the tablets.

Which device configuration profile type should you use?

55. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your company uses Windows Update for Business.

The research department has several computers that have specialized hardware and software installed.

You need to prevent the video drivers from being updated automatically by using Windows Update.

Solution: From the Settings app, you clear the Give me updates for other Microsoft products when I update Windows check box.

Does this meet the goal?

56. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these

questions will not appear in the review screen.

Your company uses Windows AutoPilot to configure the computer settings of computers issued to users.

A user named User1 has a computer named Computer1 that runs Windows 10. User1 leaves the company.

You plan to transfer the computer to a user named User2.

You need to ensure that when User2 first starts the computer, User2 is prompted to select the language setting and to agree to the license agreement.

Solution: You perform a remote Windows AutoPilot Reset.

Does this meet the goal?

57. DRAG DROP

You have five computers that runs Windows 10.

You need to create a provisioning package to configure the computers to meet the following requirements:

✑ Run an interactive app.

✑ Automatically sign in by using a local user account.

✑ Prevent users from accessing the desktop and running other applications.

Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

58. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these

questions will not appear in the review screen.

You need to ensure that feature and quality updates install automatically during a maintenance window.

Solution: From the Maintenance Scheduler settings, you configure Automatic Maintenance Activation

Boundary.

Does this meet the goal?

59. You have 100 computers that run Windows 8.1.

You need to create a report that will assess the Windows 10 readiness of the computers.

What should you use?

60. HOTSPOT

You have a Microsoft 365 tenant named contoso.com that contains a group named ContosoUsers. All the users in contoso.com are members of ContosoUsers.

You have two Windows 10 devices as shown in the following table.

Both Computer1 and Computer2 contain two apps named App1 and App2.

You configure an app protection policy named AppPolicy1 that has the following settings:

✑ Protected apps: App1

✑ Assignments: ContosoUsers

✑ Enrollment state: Without enrollment

✑ Windows Information Protection mode: Block

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

61. You have a Microsoft 365 tenant that uses Microsoft Intune.

You use the Company Portal app to access and install published apps to enrolled devices. From the Microsoft Endpoint Manager admin center, you add a Microsoft Store app .

Which two App information types are visible in the Company Portal? Note: Each correct selection is worth one point.

62. Your company has a System Center Configuration Manager deployment that uses hybrid mobile device management (MDM). All Windows 10 devices are Active Directory domain-joined.

You plan to migrate from hybrid MDM to Microsoft Intune standalone.

You successfully run the Intune Data Importer tool.

You need to complete the migration.

Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

63. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these

questions will not appear in the review screen.

Your company uses Windows AutoPilot to configure the computer settings of computers issued to users.

A user named User1 has a computer named Computer1 that runs Windows 10. User1 leaves the company.

You plan to transfer the computer to a user named User2.

You need to ensure that when User2 first starts the computer, User2 is prompted to select the language setting and to agree to the license agreement.

Solution: You create a new Windows AutoPilot user-driven deployment profile.

Does this meet the goal?

64. HOTSPOT

Your network contains an on-premises Active Directory forest named contoso.com that syncs to Azure Active Directory (Azure AD).

Azure AD contains the users shown in the following table.

You assign Windows 10 Enterprise E5 licenses to Group1 and User2.

You add computers to the network as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

65. Your network contains an Active Directory domain. The domain contains 5,000 computers that run Windows 10. All users use Roaming User Profiles-Some users report that it takes a long hme to sign in to the computers. You discover that the users have user profiles that are larger than 1 GB. You need to reduce the amount of time it takes for the users to sign in .

What should you configure?

66. You have an Azure Active Directory (Azure AD) tenant and 100 Windows 10 devices that are Azure AD joined and managed by using Microsoft Intune.

You need to configure Microsoft Defender Firewall and Microsoft Defender Antivirus on the devices. The solution must minimize administrative effort.

Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

67. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your company has an Azure Active Directory (Azure AD) tenant named contoso.com that contains several Windows 10 devices.

When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin.

You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.

Solution: From the Azure Active Directory admin center, you modify the User settings and the Device settings.

Does this meet the goal?

68. HOTSPOT

Your company has computers that run Windows 10 and are Microsoft Azure Active Directory (Azure AD)-joined.

The company purchases an Azure subscription.

You need to collect Windows events from the Windows 10 computers in Azure. The solution must enable you to create alerts based on the collected events.

What should you create in Azure and what should you configure on the computers? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

69. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure Directory group named Group1 that contains Windows 10 Enterprise devices and Windows 10 Pro devices.

From Microsoft Intune, you create a device configuration profile named Profile1.

You need to ensure that Profile1 applies to only the Windows 10 Enterprise devices in Group1.

Solution: You create an Azure Active Directory group that contains only the Windows 10 Enterprise devices. You assign Profile1 to the new group.

Does this meet the goal?

70. Your network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD). The domain contains 500 laptops that run Windows 8.1 Professional. The users of the laptops work from home.

Your company uses Microsoft Intune, the Microsoft Deployment Toolkit (MDT), and Windows Configuration Designer to manage client computers.

The company purchases 500 licenses for Windows 10 Enterprise.

You verify that the hardware and applications on the laptops are compatible with Windows 10.

The users will bring their laptop to the office, where the IT department will deploy Windows 10 to the laptops while the users wait.

You need to recommend a deployment method for the laptops that will retain their installed applications. The solution must minimize how long it takes to perform the deployment.

What should you include in the recommendation?

71. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your company has an Azure Active Directory (Azure AD) tenant named contoso.com that

contains several Windows 10 devices.

When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin.

You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.

Solution: From the Azure Active Directory admin center, you configure automatic mobile device management (MDM) enrollment. From the Device Management admin center, you create and assign a device restrictions profile.

Does this meet the goal?

72. HOTSPOT

You have the devices shown in the following table.

You plan to implement Desktop Analytics.

You need to identify which devices support the following:

✑ Compatibility insights

✑ App usage insights

Which devices should you identify? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

73. You have 100 computers that run Windows 8.1.

You need to identify which computers can be upgraded to Windows 10.

What should you use?

74. HOTSPOT

Your company has an infrastructure that has the following:

✑ A Microsoft 365 tenant

✑ An Active Directory forest

✑ Microsoft Store for Business

✑ A Key Management Service (KMS) server

✑ A Windows Deployment Services (WDS) server

✑ A Microsoft Azure Active Directory (Azure AD) Premium tenant

The company purchases 100 new computers that run Windows 10.

You need to ensure that the new computers are joined automatically to Azure AD by using Windows AutoPilot.

What should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

75. Your company purchases new computers that run Windows 10. The computers have cameras that support Windows Hello for Business.

You configure the Windows Hello for Business Group Policy settings as shown in the following exhibit.

What are two valid methods a user can use to sign in? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

76. You have a Microsoft 365 subscription.

You have a conditional access policy that requires multi-factor authentication (MFA) for users in a group name Sales when the users sign in from a trusted location.

The policy is configured as shown in the exhibit. (Click the Exhibit tab.)

You create a compliance policy.

You need to ensure that the users are authenticated only if they are using a compliant device.

What should you configure in the conditional access policy?

77. You use Windows Defender Advanced Threat Protection (Windows Defender ATP) to protect computers that run Windows 10.

You need to assess the differences between the configuration of Windows Defender ATP and the Microsoft recommended configuration baseline.

Which tool should you use?

78. You have a Microsoft 365 subscription. All devices run Windows 10.

You need to prevent users from enrolling the devices in the Windows Insider Program.

What should you configure from Microsoft 365 Device Management? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

79. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory domain. The domain contains member computers that run Windows 8.1 and are enrolled in Microsoft Intune.

You need to identify which computers can be upgraded to Windows 10.

Solution: You install the Microsoft Assessment and Planning Toolkit. From the Microsoft Assessment and Planning Toolkit, you collect inventory data and run the Windows 10 Readiness scenario.

Does this meet the goal?

80. HOTSPOT

You have a Microsoft 365 subscription.

You need to configure access to Microsoft Office 365 for unmanaged devices.

The solution must meet the following requirements:

✑ Allow only the Microsoft Intune Managed Browser to access Office 365 web interfaces.

✑ Ensure that when users use the Intune Managed Browser to access Office 365 web interfaces, they can only copy data to applications that are managed by the company.

Which two settings should you configure from the Microsoft Intune blade? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

81. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory domain. The domain contains member computers that run Windows 8.1 and are enrolled in Microsoft Intune.

You need to identify which computers can be upgraded to Windows 10.

Solution: From Windows on the Devices blade of the Microsoft Endpoint Manager admin center, you create a filter and export the results as a CSV file.

Does this meet the goal?

82. You have an Azure Active Directory (Azure AD) tenant named contoso.com.

You plan to use Windows Autopilot to configure the Windows 10 devices shown in the following table.

Which devices can be configured by using Windows Autopilot self-deploying mode?

83. You need to assign the same deployment profile to all the computers that are configured by using Windows Autopilot.

Which two actions should you perform? Each correct answer presents part of the solution. NOTE: each correct selection is worth one point.

84. Your network contains an Active Directory domain named contoso.com.

You create a provisioning package named Package1 as shown in the following exhibit.

What is the maximum number of devices on which you can run Package1 successfully?

85. HOTSPOT

Your network contains an Active Directory domain. The domain contains 1,200 computers that run Windows 8.1.

You deploy an Upgrade Readiness solution in Microsoft Azure and configure the computers to report to Upgrade Readiness.

From Upgrade Readiness, you open a table view of the applications.

You need to filter the view to show only applications that can run successfully on Windows 10.

How should you configure the filter in Upgrade Readiness? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

86. You have 500 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune.

You plan to distribute certificates to the computers by using Simple Certificate Enrollment Protocol (SCEP).

You have the servers shown in the following table.

NDES issues certificates from the subordinate CA.

You are configuring a device profile as shown in the exhibit. (Click the Exhibit tab.)

You need to complete the SCEP profile.

87. You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune.

You need to ensure that only applications that you explicitly allow can run on the computers.

What should you use?

88. You use the Microsoft Deployment Toolkit (MDT) to deploy Windows 10.

You create a new task sequence by using the Standard Client Task Sequence template to deploy Windows 10 Enterprise to new computers. The computers have a single hard disk.

You need to modify the task sequence to create a system volume and a data volume.

Which phase should you modify in the task sequence?

89. HOTSPOT

Your company has computers that run Windows 8.1, Windows 10, or macOS.

The company uses Microsoft Intune to manage the computers.

You need to create an Intune profile to configure Windows Hello for Business on the computers that support it.

Which platform type and profile type should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

90. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You need to ensure that feature and quality updates install automatically during a maintenance window.

Solution: From the Maintenance Scheduler settings, you configure Automatic Maintenance Random Delay.

Does this meet the goal?

91. You have an Azure Active Directory group named Group1. Group1 contains two Windows 10 Enterprise devices named Device1 and Device2.

You create a device configuration profile named Profile1. You assign Profile1 to Group1. You need to ensure that Profile1 applies to Device1 only .

What should you modify in Policy1?

92. Your network contains an on-premises Active Directory domain named contoso.com that syncs to Azure Active Directory (Azure AD).

You have the Windows 10 devices shown in the following table.

You need to ensure that you can use co-management to manage all the Windows 10 devices.

Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

93. You have an Azure Active Directory (Azure AD) tenant named adatum.com The tenant contains Windows 10 devices that are enrolled in Microsoft Intune.

You create an Azure Log Analytics workspace and add the Device Health solution to the workspace.

You need to create a custom device configuration profile that will enroll the Windows 10 devices in Device Health.

Which OMA-URI should you add to the profile?

94. You have a hybrid deployment of Azure Active Directory (Azure AD) that contains 50 Windows 10 devices. All the devices are enrolled in Microsoft Endpoint Manager.

You discover that Group Policy settings override the settings configured in Microsoft Endpoint Manager policies.

You need to ensure that the settings configured in Microsoft Endpoint Manager override the Group Policy

settings.

What should you do?

95. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your company has an Azure Active Directory (Azure AD) tenant named contoso.com and a Microsoft Intune subscription.

Contoso.com contains a user named [email protected]

You have a computer named Computer1 that runs Windows 8.1.

You need to perform an in-place upgrade of Computer1 to Windows 10.

Solution: You start Computer1 from the Windows 10 installation media and use the Install option.

Does this meet the goal?

96. HOTSPOT

Your network contains an Active Directory domain. The domain contains computers that are managed by using Microsoft Endpoint Configuration Manager.

You plan to integrate Configuration Manager and Azure as part of a Desktop Analytics implementation.

You create a new organizational unit (OU) and place several test computers that run Windows 10 into the OU.

You need to collect diagnostic data from the test computers to Desktop Analytics.

• App usage and insights data

• Health monitoring data

• Deployment status data

The solution must minimize the data collected.

Which two Group Policy settings should you configure? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

97. You have an Azure Active Directory (Azure AD) tenant named contoso.com.

You create a terms of use (ToU) named Terms1 in contoso.com.

You are creating a conditional access policy named Policy1 to assign a cloud app named App1 to the users in contoso.com.

You need to configure Policy1 to require the users to accept Terms1.

What should you configure in Policy1?

98. HOTSPOT

You have a Microsoft Intune subscription.

You create the Windows Autopilot deployment profile-shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.

99. You are configuring an SSTP VPN.

When you attempt to connect to the VPN, you receive the message shown in the exhibit. (Click the Exhibit tab.)

What should you do to ensure that you can connect to the VPN?

100. HOTSPOT

You have a Microsoft 365 tenant that uses Microsoft Intune and contains the devices shown in the following table.

In Endpoint security, you need to configure a disk encryption policy for each device.

Which encryption type should you use for each device, and which role-based access control (RBAQ role in Intune should you use to manage the encryption keys? To answer, select the appropriate options m the answer area. NOTE: Each correct selection is worth one point.


 

Microsoft Power Platform Fundamentals PL-900 Dumps Updated With Actual Q&As
Improved SC-900 Exam Dumps Questions For Microsoft Security Compliance and Identity Fundamentals Exam

Add a Comment

Your email address will not be published. Required fields are marked *