[Feb-2023] Microsoft MD-101 Actual Questions and Braindumps [Q163-Q186]

Share

[Feb-2023] Microsoft MD-101 Actual Questions and Braindumps

Pass MD-101 Exam with Updated MD-101 Exam Dumps PDF 2023

NEW QUESTION 163
What is the maximum number of devices that User1 and User2 can enroll in Intune? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

 

NEW QUESTION 164
Your network contains an Active Directory domain named contoso.com. The domain contains computers that run Windows 10 and are joined to the domain.
The domain is synced to Microsoft Azure Active Directory (Azure AD).
You create an Azure Log Analytics workspace and deploy the Device Health solution. You need to enroll the computers in Windows Analytics.
Which Group Policy setting should you configure?

  • A. Specify intranet Microsoft update service location
  • B. Configure the Commercial ID
  • C. Allow Telemetry
  • D. Connected User Experiences and Telemetry

Answer: B

Explanation:
Microsoft uses a unique commercial ID to map information from user computers to your Azure workspace.
Copy your commercial ID key from any of the Windows Analytics solutions you have added to your Windows Portal, and then deploy it to user computers.
https://docs.microsoft.com/en-us/windows/deployment/update/windows-analytics-get-started

 

NEW QUESTION 165
Your company has a Microsoft Azure Active Directory (Azure AD) tenant.
The company has a Volume Licensing Agreement and uses a product key to activate Windows 10.
You plan to deploy Windows 10 Pro to 200 new computers by using the Microsoft Deployment Toolkit (MDT) and Windows Deployment Services (WDS).
You need to ensure that the new computers will be configured to have the correct product key during the installation.
What should you configure?

  • A. the Device settings in Azure AD
  • B. a WDS boot image
  • C. a Windows AutoPilot deployment profile
  • D. an MDT task sequence

Answer: B

Explanation:
Explanation
References:
https://docs.microsoft.com/en-us/windows/deployment/deploy-windows-mdt/deploy-a-windows-10-imageusing-

 

NEW QUESTION 166
You have a workgroup computer named Computer1 that runs Windows 10 and has the users shown in the following table.

Group1 is a member of Group3.
You are creating a file named Kiosk.xml that specifies a lockdown profile for a multi-app kiosk.
Kiosk.xml contains the following section.

You apply Kiosk.xml to Computer1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/windows/configuration/lock-down-windows-10-to-specific-apps#config-for-group-accounts

 

NEW QUESTION 167
You have a Microsoft 365 subscription.
You plan to enroll devices in Microsoft Endpoint Manager that have the platforms and versions shown in the following table.

You need to configure device enrollment to meet the following requirements:
Ensure that only devices that have approved platforms and versions can enroll in Endpoint Manager.
Ensure that devices are added to Microsoft Azure Active Directory (Azure AD) groups based on a selection made by users during the enrollment.
Which device enrollment setting should you configure for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/mem/intune/enrollment/enrollment-restrictions-set
https://docs.microsoft.com/en-us/mem/intune/enrollment/device-group-mapping

 

NEW QUESTION 168
You have a workgroup computer named Computer1 that runs Windows 10 and has the users shown in the following table.

Group1 is a member of Group3.
You are creating a file named Kiosk.xml that specifies a lockdown profile for a multi-app kiosk.
Kiosk.xml contains the following section.

You apply Kiosk.xml to Computer1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

Reference:
https://docs.microsoft.com/en-us/windows/configuration/lock-down-windows-10-to-specific-apps#config-for-gro

 

NEW QUESTION 169
You have groups that use the Dynamic Device membership type as shown in the following table.

You are deploying Microsoft 365 apps.
You have devices enrolled in Microsoft Intune as shown in the following table.

In the Microsoft Endpoint Manager admin center, you create a Microsoft 365 Apps app as shown in the exhibit. (Click the Exhibit tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/mem/intune/apps/apps-add-office365
https://docs.microsoft.com/en-us/mem/intune/apps/apps-deploy
https://docs.microsoft.com/en-us/mem/intune/apps/apps-add

 

NEW QUESTION 170
Your company uses Microsoft Intune to manage devices. You need to ensure that only Android devices that use Android work profiles can enroll in Intune.
Which two configurations should you perform in the device enrollment restrictions? Each correct answer presents part of the solution.
NOTE: each correct selection is worth one point.

  • A. From Select platforms, set Android to
  • B. From Configure platforms, set Android Personally Owned to
  • C. From Configure platforms, set Android Personally Owned to
  • D. From Select platforms, set Android work profile to

Answer: A,D

Explanation:
Explanation
https://docs.microsoft.com/en-us/InTune/enrollment-restrictions-set

 

NEW QUESTION 171
In Microsoft Intune, you have the device compliance policies shown in the following table.

The Intune compliance policy settings are configured as shown in the following exhibit.

On June 1, you enroll Windows 10 devices in Intune as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/mem/intune/protect/actions-for-noncompliance

 

NEW QUESTION 172
Your company has computers that run Windows 10 and are Microsoft Azure Active Directory (Azure AD)-joined.
The company purchases an Azure subscription.
You need to collect Windows events from the Windows 10 computers in Azure. The solution must enable you to create alerts based on the collected events.
What should you create in Azure and what should you configure on the computers? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/azure-monitor/platform/log-analytics-agent

 

NEW QUESTION 173
Your company implements Microsoft Azure Active Directory (Azure AD), Microsoft 365, Microsoft Intune, and Azure Information Protection.
The company's security policy states the following:
Personal devices do not need to be enrolled in Intune.
Users must authenticate by using a PIN before they can access corporate email data.
Users can use their personal iOS and Android devices to access corporate cloud services.
Users must be prevented from copying corporate email data to a cloud storage service other than Microsoft OneDrive for Business.
You need to configure a solution to enforce the security policy.
What should you create?

  • A. a supervision policy from the Security & Compliance admin center
  • B. a data loss prevention (DLP) policy from the Security & Compliance admin center
  • C. a device configuration profile from the Intune admin center
  • D. an app protection policy from the Intune admin center

Answer: D

Explanation:
Reference:
https://docs.microsoft.com/en-us/intune/app-protection-policy

 

NEW QUESTION 174
You have a Microsoft 365 subscription that contains devices enrolled in Microsoft Intune.
You need to create Endpoint security policies to enforce the following requirements:
Computers that run macOS must have FileVault enabled.
Computers that run Windows 10 must have Microsoft Defender Credential Guard enabled.
Computers that run Windows 10 must have Microsoft Defender Application Control enabled.
Which Endpoint security feature should you use for each requirement? To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-account-protection-policy
https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-asr-policy

 

NEW QUESTION 175
You have a Microsoft Azure Active Directory (Azure AD) tenant. All corporate devices are enrolled in Microsoft Intune.
You have a web-based application named App1 that uses Azure AD to authenticate.
You need to prompt all users of App1 to agree to the protection of corporate data when they access App1 from both corporate and non-corporate devices.
What should you configure?

  • A. Terms and Conditions in Device enrollment
  • B. Notifications in Device compliance
  • C. an Endpoint protection profile in Device configuration
  • D. Terms of use in Conditional access

Answer: D

Explanation:
References:
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/terms-of-use

 

NEW QUESTION 176
You need to recommend a solution to meet the device management requirements.
What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://github.com/MicrosoftDocs/IntuneDocs/blob/master/intune/app-protection-policy.md
https://docs.microsoft.com/en-us/azure/information-protection/configure-usage-rights#do-not-forward-option-for-emails

 

NEW QUESTION 177
Your network contains an Active Directory domain named constoso.com that is synced to Microsoft Azure Active Directory (Azure AD). All computers are enrolled in Microsoft Intune.
The domain contains the computers shown in the following table.

You are evaluating which Intune actions you can use to reset the computers to run Windows 10 Enterprise with the latest update.
Which computers can you reset by using each action? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

Reference:
https://docs.microsoft.com/en-us/intune/device-fresh-start
https://docs.microsoft.com/en-us/intune/devices-wipe

 

NEW QUESTION 178
Your company has computers that run Windows 10. The employees at the company use the computers.
You plan to monitor the computers by using the Update Compliance solution.
You create the required resources in Azure.
You need to configure the computers to send enhanced Update Compliance data.
Which two Group Policy settings should you configure? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/windows/deployment/update/update-compliance-configuration-manual

 

NEW QUESTION 179
You have 200 computers that run Windows 10.
You need to create a provisioning package to configure the following tasks:
Remove the Microsoft News and the Xbox Microsoft Store apps.
Add a VPN connection to the corporate network.
Which two customizations should you configure? To answer, select the appropriate customizations in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/windows/configuration/wcd/wcd-connectivityprofiles
https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-configuration-service-provider#applicationmanagement-applicationrestrictions
https://docs.microsoft.com/en-us/windows/configuration/wcd/wcd-policies

 

NEW QUESTION 180
Your network contains an Active Directory domain. The domain contains 1,200 computers that run Windows 8.1.
You deploy an Upgrade Readiness solution in Microsoft Azure and configure the computers to report to Upgrade Readiness.
From Upgrade Readiness, you open a table view of the applications.
You need to filter the view to show only applications that can run successfully on Windows 10.
How should you configure the filter in Upgrade Readiness? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
References:
https://docs.microsoft.com/en-us/windows/deployment/upgrade/upgrade-readiness-resolve-issues

 

NEW QUESTION 181
You have a Microsoft 365 subscription. All devices run Windows 10.
You need to prevent users from enrolling the devices in the Windows Insider Program.
What two configurations should you perform from Microsoft 365 Device Management? Each correct answer is a complete solution.
NOTE: Each correct selection is worth one point.

  • A. a custom device configuration profile
  • B. an app configuration policy
  • C. a device restrictions device configuration profile
  • D. a Windows 10 update ring
  • E. a Windows 10 security baseline

Answer: B,D

 

NEW QUESTION 182
What should you configure to meet the technical requirements for the Azure AD-joined computers?

  • A. A password policy from the Microsoft Office 365 portal.
  • B. The Password Policy settings in a Group Policy object (GPO).
  • C. The Accounts options in an endpoint protection profile.
  • D. Windows Hello for Business from the Microsoft Intune blade in the Azure portal.

Answer: D

Explanation:
Explanation
References:
https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-manage-inorgani

 

NEW QUESTION 183
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You need to ensure that feature and quality updates install automatically during a maintenance window.
Solution: From the Windows Update settings, you enable Configure Automatic Updates, select 3 - Auto download and notify for Install, and then enter a time.
Does this meet the goal?

  • A. No
  • B. Yes

Answer: A

Explanation:
Explanation/Reference:
References:
https://docs.microsoft.com/en-us/sccm/sum/deploy-use/automatically-deploy-software-updates

 

NEW QUESTION 184
You need to meet the technical requirements for the iOS devices.
Which object should you create in Intune?

  • A. A compliance policy
  • B. A Deployment profile
  • C. A device profile
  • D. An app protection policy

Answer: C

Explanation:
Explanation/Reference:
References:
https://docs.microsoft.com/en-us/intune/device-restrictions-configure
https://docs.microsoft.com/en-us/intune/device-restrictions-ios

 

NEW QUESTION 185
You use the Antimalware Assessment solution in Microsoft Azure Log Analytics.
From the Protection Status dashboard, you discover the computers shown in the following table.

You verify that both computers are connected to the network and running.
What is a possible cause of the issue on each computer? To answer, drag the appropriate causes to the correct computers. Each cause may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/ga-ie/azure/security-center/security-center-install-endpoint-protection

 

NEW QUESTION 186
......

Latest MD-101 Pass Guaranteed Exam Dumps with Accurate & Updated Questions: https://dumpstorrent.actualpdf.com/MD-101-real-questions.html