Pass the Microsoft Managing Modern Desktops (MD-101) Exam with Confidence: The Latest MD-101 Dumps

Are you preparing to take the Microsoft Managing Modern Desktops (MD-101) exam and achieve the Microsoft 365 Certified: Modern Desktop Administrator Associate certification? Come to DumpsBase today, our MD-101 exam dumps have been updated by our team to cover the latest exam objectives and skills measured, which include a comprehensive set of MD-101 exam questions and answers that cover all of the key concepts and areas of the exam, along with study tips to help you pass the Microsoft MD-101 exam with ease. Whether you’re new to managing modern desktops or looking to expand your knowledge, our MD-101 latest dumps should be the perfect resource to help you achieve your certification goals.

Try to read free MD-101 demo questions to check the latest MD-101 dumps:

1. Topic 1, Litware inc

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.

To start the case study

To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.

General Overview

Litware, Inc. is an international manufacturing company that has 3,000 employees. The company has sales, marketing, research, human resources (HR), development, and IT departments.

Litware has two main offices in New York and Los Angeles. Litware has five branch offices in Asia.

Existing Environment

Current Business Model

The Los Angeles office has 500 developers. The developers work flexible hours ranging from 11 AM to 10 PM.

Litware has a Microsoft System Center 2012 R2 Configuration Manager deployment.

During discovery, the company discovers a process where users are emailing bank account information of its customers to internal and external recipients.

Current Environment

The network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD). The functional level of the forest and the domain is Windows Server 2012 R2. All domain controllers run Windows Server 2012 R2.

Litware has the computers shown in the following table.

The development department uses projects in Azure DevOps to build applications.

Most of the employees in the sales department are contractors. Each contractor is assigned a computer that runs Windows 10. At the end of each contract, the computer is assigned to a different contractor. Currently, the computers are re-provisioned manually by the IT department.

Problem Statements

Litware identifies the following issues on the network:

- Employees in the Los Angeles office report slow Internet performance when updates are downloading. The employees also report that the updates frequently consume considerable resources when they are installed. The Update settings are configured as shown in the Updates exhibit. (Click the Updates button.)

- Management suspects that the source code for the proprietary applications in Azure DevOps in being shared externally.

- Re-provisioning the sales department computers is too time consuming.

Requirements

Business Goals

Litware plans to transition to co-management for all the company-owned Windows 10 computers.

Whenever possible, Litware wants to minimize hardware and software costs.

Device Management Requirements

Litware identifies the following device management requirements:

- Prevent the sales department employees from forwarding email that contains bank account information.

- Ensure that Microsoft Edge Favorites are accessible from all computers to which the developers sign in.

- Prevent employees in the research department from copying patented information from trusted applications to untrusted applications.

Technical Requirements

Litware identifies the following technical requirements for the planned deployment:

- Re-provision the sales department computers by using Windows AutoPilot.

- Ensure that the projects in Azure DevOps can be accessed from the corporate network only.

- Ensure that users can sign in to the Azure AD-joined computers by using a PIN. The PIN must expire every 30 days.

- Ensure that the company name and logo appears during the Out of Box Experience (OOBE) when using Windows AutoPilot.

Exhibits

Updates

HOTSPOT

You need to meet the OOBE requirements for Windows AutoPilot.

Which two settings should you configure from the Azure Active Directory blade? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

2. You need to capture the required information for the sales department computers to meet the technical

requirements.

Which Windows PowerShell command should you run first?

3. What should you configure to meet the technical requirements for the Azure AD-joined computers?

4. HOTSPOT

You need to resolve the performance issues in the Los Angeles office.

How should you configure the update settings? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

5. HOTSPOT

You need to meet the technical requirements for Windows AutoPilot.

Which two settings should you configure from the Azure Active Directory blade? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

6. HOTSPOT

You need to recommend a solution to meet the device management requirements.

What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

7. What should you use to meet the technical requirements for Azure DevOps?

8. You need to meet the device management requirements for the developers.

What should you implement?

9. What should you upgrade before you can configure the environment to support co-management?

10. Topic 2, Contoso Ltd

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.

To start the case study

To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.

Overview

Contoso, Ltd, is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York.

Contoso has the users and computers shown in the following table.

The company has IT, human resources (HR), legal (LEG), marketing (MKG) and finance (FIN) departments.

Contoso uses Microsoft Store for Business and recently purchased a Microsoft 365 subscription.

The company is opening a new branch office in Phoenix. Most of the users in the Phoenix office will work from home.

Existing Environment

The network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).

All member servers run Windows Server 2016. All laptops and desktop computers run Windows 10 Enterprise.

The computers are managed by using Microsoft Endpoint Configuration Manager. The mobile devices are managed by using Microsoft Intune.

The naming convention for the computers is the department acronym, followed by a hyphen, and then four numbers, for example, FIN-6785. All the computers are joined to the on-premises Active Directory domain.

Each department has an organizational unit (OU) that contains a child OU named Computers. Each computer account is in the Computers OU of its respective department.

Intune Configuration

The domain has the users shown in the following table.

User2 is a device enrollment manager (DEM) in Intune.

The devices enrolled in Intune are shown in the following table.

The device compliance policies in Intune are configured as shown in the following table.

The device compliance policies have the assignments shown in the following table.

The device limit restrictions in Intune are configured as shown in the following table.

Requirements

Planned Changes

Contoso plans to implement the following changes:

- Provide new computers to the Phoenix office users. The new computers have Windows 10 Pro preinstalled and were purchased already.

- Start using a free Microsoft Store for Business app named App1.

- Implement co-management for the computers.

Technical Requirements :

Contoso must meet the following technical requirements:

- Ensure that the users in a group named Group4 can only access Microsoft Exchange Online from devices that are enrolled in Intune.

- Deploy Windows 10 Enterprise to the computers of the Phoenix office users by using Windows Autopilot.

- Monitor the computers in the LEG department by using Windows Analytics.

- Create a provisioning package for new computers in the HR department.

- Block iOS devices from sending diagnostic and usage telemetry data.

- Use the principle of least privilege whenever possible.

- Enable the users in the MKG department to use App1.

- Pilot co-management for the IT department.

You need to meet the requirements for the MKG department users.

What should you do?

11. You need to prepare for the deployment of the Phoenix office computers.

What should you do first?

12. You need to meet the technical requirements for the iOS devices.

Which object should you create in Intune?

13. HOTSPOT

You need to meet the technical requirements for the new HR department computers.

How should you configure the provisioning package? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

14. DRAG DROP

You need to meet the technical requirements for the LEG department computers.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

15. HOTSPOT

What is the maximum number of devices that User1 and User2 can enroll in Intune? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

16. HOTSPOT

To which devices do Policy1 and Policy2 apply? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

17. HOTSPOT

You are evaluating which devices are compliant.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

18. HOTSPOT

You need a new conditional access policy that has an assignment for Office 365 Exchange Online.

You need to configure the policy to meet the technical requirements for Group4.

Which two settings should you configure in the policy? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

19. You need to prepare for the deployment of the Phoenix office computers.

What should you do first?

20. You need to meet the technical requirements for the IT department.

What should you do first?

21. Topic 3, Contoso, Ltd. (NEW)

Case Study

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.

To start the case study

To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.

Overview

Contoso, Ltd. is a consulting company that has a main office in Montreal and branch offices in Seattle and New York.

Contoso has a Microsoft 365 E5 subscription.

Network Environment

The network contains an on-premises Active domain named Contoso.com.

The domain contains the servers shown in the following table.

Contoso has a hybrid Azure Active Directory (Azure AD) tenant named Contoso.com.

Contoso has a Microsoft Store for Business instance.

Users and Groups

The Contoso.com tenant contains the users shown in the following table.

All users are assigned a Microsoft Office 365 license and an Enterprise Mobility + Security E3 license.

Enterprise State Roaming is enabled for Group1 and GroupA.

Group and Group have a Membership type of Assign

Devices

Contoso has the Windows 10 devices shown in the following table.

The Windows 10 devices are joined to Azure AD and enrolled in Microsoft intune.

The Windows 10 devices are configured as shown in the following table.

All the Azure AD joined devices have an executable file named C:AppA.exe and a folder named D:Folder 1.

Microsoft Endpoint Manager Configuration

Microsoft Endpoint Manager has the compliance policies shown in the following table.

The Compliance policy settings are shown in the following exhibit.

The Automatic Enrolment settings have the following configurations:

• MDM user scope GroupA

• MAM user scope: GroupB

You have an Endpoint protection configuration profile that has the following Controlled folder access settings:

• Name: Protection1

• Folder protection: Enable

• List of apps that have access to protected folders: CVAppA.exe

• List of additional folders that need to be protected: D:Folderi1

• Assignments

Windows Autopilot Configuration

Currently, there are no devices deployed by using Window Autopilot

The Intune connector tor Active Directory is installed on Server 1.

Planned Changes

Contoso plans to implement the following changes:

• Purchase a new Windows 10 device named Device6 and enroll the device in Intune.

• New computers will be deployed by using Windows Autopilot and will be hybrid Azure AO joined.

• Deploy a network boundary configuration profile that will have the following settings:

• Name Boundary 1

• Network boundary 192.168.1.0/24

• Scope tags: Tag 1

• Assignments;

• included groups: Group 1. Group2

• Deploy two VPN configuration profiles named Connection! and Connection that will have the following settings:

• Name: Connection 1

• Connection name: VPNI

• Connection type: L2TP

• Assignments:

• Included groups: Group1. Group2, GroupA

• Excluded groups: ―

• Name: Connection

• Connection name: VPN2

• Connection type: IKEv2 i Assignments:

• included groups: GroupA

• Excluded groups: GroupB

• Purchase an app named App1 that is available in Microsoft Store for Business and to assign the app to all the users.

Technical Requirements

Contoso must meet the following technical requirements:

• Users in GroupA must be able to deploy new computers.

• Administrative effort must be minimized.

You implement Boundary1 based on the planned changes.

Which devices have a network boundary of 192.168.1.0/24 applied?

22. HOTSPOT

User1 and User2 plan to use Sync your settings.

On which devices can the users use Sync your settings? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

23. HOTSPOT

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

24. HOTSPOT

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

25. Which user can enroll Device6 in Intune?

26. You need to ensure that computer objects can be created as part of the Windows Autopilot deployment. The solution must meet the technical requirements.

To what should you grant the right to create the computer objects?

27. Which users can purchase and assign App1?

28. HOTSPOT

You implement the planned changes for Connection1 and Connection2

How many VPN connections will there be for User1 when the user signs in to Device 1 and Devke2? To answer select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

29. HOTSPOT

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

30. You have an Azure Active Directory (Azure AD) tenant named contoso.com.

You create a terms of use (ToU) named Terms1 in contoso.com.

You are creating a conditional access policy named Policy1 to assign a cloud app named App1 to the users in contoso.com.

You need to configure Policy1 to require the users to accept Terms1.

What should you configure in Policy1?

31. You have a Microsoft 365 subscription. All devices run Windows 10.

You need to prevent users from enrolling the devices in the Windows Insider Program.

What two configurations should you perform from Microsoft 365 Device Management? Each correct answer is a complete solution. NOTE: Each correct selection is worth one point.

32. Your network contains an on-premises Active Directory domain named contoso.com that syncs to Azure Active Directory (Azure AD).

You have the Windows 10 devices shown in the following table.

You need to ensure that you can use co-management to manage all the Windows 10 devices.

Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

33. You have 500 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune.

You plan to distribute certificates to the computers by using Simple Certificate Enrollment Protocol (SCEP).

You have the servers shown in the following table.

NDES issues certificates from the subordinate CA.

You are configuring a device profile as shown in the exhibit. (Click the Exhibit tab.)

You need to complete the SCEP profile.

34. HOTSPOT

Your network contains an Active Directory domain. Active Directory is synced with Microsoft Azure Active Directory (Azure AD).

There are 500 domain-joined computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune.

You plan to implement Windows Defender Exploit Guard.

You need to create a custom Windows Defender Exploit Guard policy, and then distribute the policy to all the computers.

What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

35. HOTSPOT

You have 200 computers that run Windows 10.

You need to create a provisioning package to configure the following tasks:

✑ Remove the Microsoft News and the Xbox Microsoft Store apps.

✑ Add a VPN connection to the corporate network.

Which two customizations should you configure? To answer, select the appropriate customizations in the answer area. NOTE: Each correct selection is worth one point.

36. You have 100 computers that run Windows 8.1.

You need to create a report that will assess the Windows 10 readiness of the computers.

What should you use?

37. HOTSPOT

You have a Microsoft Intune subscription.

You are creating a Windows Autopilot deployment profile named Profile1 as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.

38. Your company implements Microsoft Azure Active Directory (Azure AD), Microsoft 365, Microsoft Intune, and Azure Information Protection.

The company’s security policy states the following:

✑ Personal devices do not need to be enrolled in Intune.

✑ Users must authenticate by using a PIN before they can access corporate email data.

✑ Users can use their personal iOS and Android devices to access corporate cloud services.

✑ Users must be prevented from copying corporate email data to a cloud storage service other than Microsoft OneDrive for Business.

You need to configure a solution to enforce the security policy.

What should you create?

39. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory domain. The domain contains member computers that run Windows 8.1 and are enrolled in Microsoft Intune.

You need to identify which computers can be upgraded to Windows 10.

Solution: You install the Microsoft Assessment and Planning Toolkit. From the Microsoft Assessment and Planning Toolkit, you collect inventory data and run the Windows 10 Readiness scenario.

Does this meet the goal?

40. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your company has an Azure Active Directory (Azure AD) tenant named contoso.com that contains several Windows 10 devices.

When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin.

You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.

Solution: From the Azure Active Directory admin center, you configure the Authentication methods.

Does this meet the goal?

41. You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (AD) and enrolled in Microsoft Intune.

You need to enable self-service password reset on the sign-in screen.

Which settings should you configure from the Microsoft Intune blade?

42. You have a shared computer that runs Windows 10.

The computer is infected with a virus.

You discover that a malicious TTF font was used to compromise the computer.

You need to prevent this type of threat from affecting the computer in the future.

What should you use?

43. HOTSPOT

You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com. All Windows 10 devices are enrolled in Microsoft Intune.

You configure the following settings in Windows Information Protection (WIP):

✑ Protected apps: App1

✑ Exempt apps: App2

✑ Windows Information Protection mode: Silent

App1, App2, and App3 use the same file format.

You create a file named File1 in App1.

You need to identify which apps can open File1.

What apps should you identify? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

44. You enable controlled folder access in audit mode for several computers that run Windows 10. You need to review the events audited by controlled folder access.

Which Event Viewer log should you view?

45. HOTSPOT

You have 100 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune.

You need to configure the following device restrictions:

✑ Block users from browsing to suspicious websites.

✑ Scan all scripts loaded into Microsoft Edge.

Which two settings should you configure in Device restrictions? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

46. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory domain. The domain contains member computers that run Windows 8.1 and are enrolled in Microsoft Intune.

You need to identify which computers can be upgraded to Windows 10.

Solution: From Windows on the Devices blade of the Microsoft Endpoint Manager admin center, you create a filter and export the results as a CSV file.

Does this meet the goal?

47. HOTSPOT

Your network contains an Active Directory domain.

The domain contains the computers shown in the following table.

Microsoft Defender Application Guard is installed on the computers.

Application Guard Group Policy settings are applied to the computers as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

48. You have a Microsoft 365 subscription.

You need to deploy Microsoft Office 365 ProPlus applications to Windows 10 devices.

What should you do first?

49. You have a Microsoft 365 tenant that contains the objects shown in the following table.

You are creating a compliance policy named Compliance1.

Which objects can you specify in Compliance1 as additional recipients of noncompliance notifications?

50. HOTSPOT

You have a Microsoft 365 subscription.

You plan to enroll devices in Microsoft Endpoint Manager that have the platforms and versions shown in the following table.

You need to configure device enrollment to meet the following requirements:

✑ Ensure that only devices that have approved platforms and versions can enroll in Endpoint Manager.

✑ Ensure that devices are added to Microsoft Azure Active Directory (Azure AD) groups based on a selection made by users during the enrollment.

Which device enrollment setting should you configure for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

51. You have a Microsoft 365 tenant that contains the devices shown in the following table.

The devices are managed by using Microsoft Intune.

You create a compliance policy named Policy1 and assign Policy1 to Group1. Policy1 is configured to mark a device as Compliant only if the device security settings match the settings specified in the policy.

You discover that devices that are not members of Group1 are shown as Compliant.

You need to ensure that only devices that are assigned a compliance policy can be shown as Compliant. All other devices must be shown as Not compliant.

What should you do?

52. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a computer named Computer1 that runs Windows 10.

You save a provisioning package named Package1 to a folder named C:Folder1.

You need to apply Package1 to Computer1.

Solution: From File Explorer, you go to C:Folder1, and then you double-click the Package1.ppkg file.

Does this meet the goal?

53. You have a Microsoft 365 subscription.

You have a conditional access policy that requires multi-factor authentication (MFA) for users in a group name Sales when the users sign in from a trusted location.

The policy is configured as shown in the exhibit. (Click the Exhibit tab.)

You create a compliance policy.

You need to ensure that the users are authenticated only if they are using a compliant device.

What should you configure in the conditional access policy?

54. Your company plans to deploy Windows 10 to device that will be configured for Englis use and other devices that will be configured for Korean use.

You need to create a single multivariate provisioning for the planned for the planned devices.

You create the provisioning package.

What should do you next to add the language settings to the package?

55. HOTSPOT

You are licensed for Microsoft Endpoint Manager.

You use Microsoft Endpoint Configuration Manager and Microsoft Intune.

You have devices enrolled in Configuration Manager as shown in the following table.

In Configuration Manager, you enable co-management and configure the following settings:

✑ Automatic enrolment in Intune: Pilot

✑ Intune Auto Enrollment: Collection1

In Configuration Manager, you configure co-management staging to have the following settings:

✑ Compliance policies: Collection2

✑ Device Configuration: Collection1

In Configuration Manager, you configure co-management workloads as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

56. HOTSPOT

Your network contains an Active Directory domain. The domain contains 1,200 computers that run Windows 8.1.

You deploy an Upgrade Readiness solution in Microsoft Azure and configure the computers to report to Upgrade Readiness.

From Upgrade Readiness, you open a table view of the applications.

You need to filter the view to show only applications that can run successfully on Windows 10.

How should you configure the filter in Upgrade Readiness? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

57. HOTSPOT

Your network contains an on-premises Active Directory forest named contoso.com. The forest contains a user named User1 and two computers named Computer1 and Computer2 that run Windows 10.

User1 is configured as shown in the following exhibit.

You rename file \Server1ProfilesUser1.V6NTUSER.DAT as NTUSER.MAN.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

58. Your network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD). The domain contains computers that run Windows 10. The computers are enrolled in Microsoft Intune and Windows Analytics.

Your company protects documents by using Windows Information Protection (WIP).

You need to identify non-approved apps that attempt to open corporate documents.

What should you use?

59. You have a computer named Computer1 that runs Windows 8.1.

You plan to perform an in-place upgrade of Computer1 to Windows 10 by using an answer file.

You need to identify which tool to use to create the answer file.

What should you identify?

60. DRAG DROP

You have a Microsoft Deployment Toolkit (MDT) deployment share named DS1.

You import a Windows 10 image to DS1.

You have an executable installer for an application named App1.

You need to ensure that App1 will be installed for all the task sequences that deploy the image.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

61. HOTSPOT

Your network contains an on-premises Active Directory forest named contoso.com that syncs to Azure Active Directory (Azure AD).

Azure AD contains the users shown in the following table.

You assign Windows 10 Enterprise E5 licenses to Group1 and User2.

You add computers to the network as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

62. You have computers that run Windows 10 and are joined to Azure Active Directory (Azure AD).

All users sign in to the computers by using their Azure AD account.

Enterprise State Roaming is enabled.

From the Settings app, a user named User1 adds a Microsoft account.

Which account will be used for the Synchronizing Windows setting?

63. You have 10 computers that run Windows 7 and have the following configurations:

✑ A single MBR disk

✑ A disabled TPM chip

✑ Disabled hardware virtualization

✑ UEFI firmware running in BIOS mode

✑ Enabled Data Execution Prevention (DEP) You plan to upgrade the computers to Windows 10.

You need to ensure that the computers can use Secure Boot.

Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

64. You have 100 devices that run Windows 10 and are joined to Microsoft Azure Active Directory (Azure AD).

You need to prevent users from joining their home computer to Azure AD.

What should you do?

65. Your network contains an Active Directory domain named contoso.com. The domain contains 200 computers that run Windows 10.

Folder Redirection for the Desktop folder is configured as shown in the following exhibit.

The target is set to Server1.

You plan to use known folder redirection in Microsoft OneDrive for Business.

You need to ensure that the desktop content of users remains on their desktop when you implement known folder redirection.

Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

66. HOTSPOT

Your network contains an Active Directory domain named constoso.com that is synced to Microsoft Azure Active Directory (Azure AD). All computers are enrolled in Microsoft Intune.

The domain contains the computers shown in the following table.

You are evaluating which Intune actions you can use to reset the computers to run Windows 10 Enterprise with the latest update.

Which computers can you reset by using each action? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

67. You have a Microsoft 365 E5 subscription and 25 Apple iPads.

You need to enroll the iPads in Microsoft Intune by using the Apple Configurator enrollment method.

What should you do first?

68. You have a computer named Computer1 that runs Windows 10. Computer is used by a user named User1.

You need to ensure that when User1 opens websites from untrusted locations by using Microsoft Edge, Microsoft Edge runs in isolated container.

What should you do first?

69. HOTSPOT

You have a Microsoft 365 tenant that uses Microsoft Intune and contains the devices shown in the following table.

In Endpoint security, you need to configure a disk encryption policy for each device.

Which encryption type should you use for each device, and which role-based access control (RBAQ role in Intune should you use to manage the encryption keys? To answer, select the appropriate options m the answer area. NOTE: Each correct selection is worth one point.

70. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure Directory group named Group1 that contains Windows 10 Enterprise devices and Windows 10 Pro devices.

From Microsoft Intune, you create a device configuration profile named Profile1.

You need to ensure that Profile1 applies to only the Windows 10 Enterprise devices in Group1.

Solution: You configure an applicability rule for Profile1. You assign Profile1 to Group1.

Does this meet the goal?

71. You have a Windows 10 device named Device1 that is joined to Active Directory and enrolled in Microsoft Intune.

Device 1 is managed by using Group Policy and Intune.

You need to ensure that the Intune settings override the Group Policy settings.

What should you configure?

72. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a computer that runs Windows 8.1.

Two days ago, you upgraded the computer to Windows 10.

You need to downgrade the computer to Windows 8.1.

Solution: From the Settings app, you use the Recovery options.

Does this meet the goal?

73. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a computer that runs Windows 8.1.

Two days ago, you upgraded the computer to Windows 10.

You need to downgrade the computer to Windows 8.1.

Solution: From Windows Update in the Settings app, you use the Advanced options.

Does this meet the goal?

74. HOTSPOT

You have unrooted devices enrolled in Microsoft Intune as shown in the following table.

The devices are members of a group named Group1.

In Intune, you create a device compliance location that has the following configurations:

✑ Name: Network1

✑ IPv4 range: 192.168.0.0/16

In Intune, you create a device compliance policy for the Android platform.

The policy has following configurations:

✑ Name: Policy1

✑ Device health: Rooted devices: Block

✑ Locations: Location: Network1

✑ Mark device noncompliant: Immediately

✑ Assigned: Group1

In Intune device compliance policy has the following configurations:

✑ Mark devices with no compliance policy assigned as: Compliant

✑ Enhanced jailbreak detection: Enabled

✑ Compliance status validity period (days): 20

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

75. Your company has a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com. All users have computers that run Windows 10. The computers are joined to Azure AD and managed by using Microsoft Intune.

You need to ensure that you can centrally monitor the computers by using Windows Analytics.

What should you create in Intune?

76. You have a Microsoft Azure subscription that contains an Azure Log Analytics workspace.

You deploy a new computer named Computer1 that runs Windows 10. Computer1 is in a workgroup.

You need to ensure that you can use Log Analytics to query events from Computer1.

What should you do on Computer1?

77. You have a Microsoft 365 subscription.

You have 10 computers that run Windows 10 and are enrolled in mobile device management (MDM)

You need to deploy the Microsoft Office 365 ProPlus suite to all the computers.

What should you do?

78. You have a Microsoft Azure Log Analytics workplace that collects all the event logs from the computers at your company.

You have a computer named Computer1 than runs Windows 10. You need to view the events collected from Computer1.

Which query should you run in Log Analytics?

79. HOTSPOT

Your company has computers that run Windows 8.1, Windows 10, or macOS.

The company uses Microsoft Intune to manage the computers.

You need to create an Intune profile to configure Windows Hello for Business on the computers that support it.

Which platform type and profile type should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

80. HOTSPOT

You have computers that run Windows 10 and are configured by using Windows AutoPilot.

A user performs the following tasks on a computer named Computer1:

✑ Creates a VPN connection to the corporate network

✑ Installs a Microsoft Store app named App1

✑ Connects to a Wi-Fi network

You perform a Windows AutoPilot Reset on Computer1.

What will be the state of the computer when the user signs in? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.


 

Newly Updated AZ-204 Dumps (2023) To Ensure Your Success: DumpsBase's AZ-204 Dumps V19.02
AZ-700 Designing and Implementing Microsoft Azure Networking Solutions Exam Dumps - Updated for [2023]

Add a Comment

Your email address will not be published. Required fields are marked *