Free MD-101 Exam Study Guide for the NEW [Aug-2023] Dumps Test Engine [Q94-Q119]

Share

Free MD-101 Exam Study Guide for the NEW [Aug-2023] Dumps Test Engine

MD-101 PDF Dumps Extremely Quick Way Of Preparation

NEW QUESTION # 94
You have 100 devices that run Windows 10 and are joined to Microsoft Azure Active Directory (Azure AD).
You need to prevent users from joining their home computer to Azure AD.
What should you do?

  • A. From the Devices blade in the Azure Active Directory admin center, modify the Device settings.
  • B. From the Device enrollment blade in the Intune admin center, modify the Enrollment restriction settings.
  • C. From the Mobility (MDM and MAM) blade in the Azure Active Directory admin center, modify the Microsoft Intune enrollment settings.
  • D. From the Device enrollment blade in the Intune admin center, modify the Device enrollment manages settings.

Answer: A

Explanation:
References:
https://docs.microsoft.com/en-us/intune/enrollment-restrictions-set


NEW QUESTION # 95
Your company has a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com. All users have computers that run Windows 10. The computers are joined to Azure AD and managed by using Microsoft Intune.
You need to ensure that you can centrally monitor the computers by using the Update Compliance solution.
What should you create in Intune?

  • A. a device configuration profile
  • B. an update policy
  • C. a device compliance policy
  • D. a conditional access policy

Answer: A

Explanation:
Explanation
Explanation/Reference:
https://www.jeffgilb.com/update-compliance-with-intune/
Manage and Protect Devices
Question Set 1


NEW QUESTION # 96
You have a Microsoft 365 Business Standard subscription and 100 Windows 10 Pro devices.
You purchase a Microsoft 365 E5 subscription.
You need to upgrade the Windows 10 Pro devices to Windows 10 Enterprise. The solution must minimize
administrative effort.
Which upgrade method should you use?

  • A. Subscription Activation
  • B. an in-place upgrade by using Windows installation media
  • C. a Microsoft Deployment Toolkit (MDT) lite-touch deployment
  • D. Windows Autopilot

Answer: A

Explanation:
Explanation
Windows 10/11 Subscription Activation
Windows 10 Pro supports the Subscription Activation feature, enabling users to "step-up" from Windows 10
Pro or Windows 11 Pro to Windows 10 Enterprise or Windows 11 Enterprise, respectively, if they are
subscribed to Windows 10/11 Enterprise E3 or E5.
Reference: https://docs.microsoft.com/en-us/windows/deployment/windows-10-subscription-activation


NEW QUESTION # 97
You have a Microsoft Intune subscription associated to an Azure Active Directory (Azure AD) tenant named
contoso.com.
Users use one of the following three suffixes when they sign in to the tenant: us.contoso.com, eu.contoso.com,
or contoso.com.
You need to ensure that the users are NOT required to specify the mobile device management (MDM)
enrollment URL as part of the enrollment process. The solution must minimize the number of changes.
Which DNS records do you need?

  • A. one TXT record only
  • B. one CNAME record only
  • C. three CNAME records
  • D. three TXT records

Answer: C

Explanation:
Reference:
https://docs.microsoft.com/en-us/mem/intune/enrollment/windows-enroll#simplify-windows-enrollment-without


NEW QUESTION # 98
You have devices enrolled in Microsoft Intune as shown in the following table.

You create device configuration profiles in Intune as shown in the following table.

You assign the device configuration profiles to groups as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

If a compliance policy evaluates against the same setting in another compliance policy, then the most
restrictive compliance policy setting applies.
Reference:
https://docs.microsoft.com/en-us/mem/intune/configuration/device-profile-troubleshoot


NEW QUESTION # 99
Your company has computers that run Windows 8.1, Windows 10, or macOS.
The company uses Microsoft Intune to manage the computers.
You need to create an Intune profile to configure Windows Hello for Business on the computers that support
it.
Which platform type and profile type should you use? To answer, select the appropriate options in the answer
area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

Reference:
https://docs.microsoft.com/en-us/intune/endpoint-protection-configure


NEW QUESTION # 100
Your company has devices enrolled in Microsoft Intune as shown in the following table.

In Microsoft Endpoint Manager, you define the company's network as a location named Location1.
Which devices can use network location-based compliance policies?

  • A. Device1, Device2, and Device3
  • B. Device1 and Device2 only
  • C. Device2 and Device3 only
  • D. Device1 only
  • E. Device2 only

Answer: A

Explanation:
Explanation
Intune supported operating systems
Intune supports devices running the following operating systems (OS):
iOS
Android
Windows
macOS
Note: View the device compliance settings for the different device platforms:
Android device administrator
Android Enterprise
iOS
macOS
Windows Holographic for Business
Windows 8.1 and later
Windows 10/11
Reference: https://docs.microsoft.com/en-us/mem/intune/fundamentals/supported-devices-browsers
https://docs.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started


NEW QUESTION # 101
You have a Microsoft Azure Active Directory (Azure AD) tenant. All corporate devices are enrolled in Microsoft Intune.
You have a web-based application named App1 that uses Azure AD to authenticate.
You need to prompt all users of App1 to agree to the protection of corporate data when they access App1 from both corporate and non-corporate devices.
What should you configure?

  • A. Terms of use in Conditional access
  • B. an Endpoint protection profile in Device configuration
  • C. Notifications in Device compliance
  • D. Terms and Conditions in Device enrollment

Answer: A

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/terms-of-use


NEW QUESTION # 102
You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (AD) and enrolled in Microsoft Intune.
You need to enable self-service password reset on the sign-in screen.
Which settings should you configure from the Microsoft Intune blade?

  • A. Device configuration
  • B. Device enrollment
  • C. Conditional access
    References:
    https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-sspr-windows
  • D. Device compliance

Answer: A


NEW QUESTION # 103
You have an Azure Active Directory (Azure AD) tenant named Contoso.com contains the device shown in the following table.

All devices contains an app named App1 and are enrolled in Microsoft Intune.
You need to prevent users from copying data from App1 and pasting the data into other apps.
Which type of policy and how policies should you create in intune, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 104
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a computer named Computer1 that runs Windows 10.
You save a provisioning package named Package1 to a folder named C:\Folder1.
You need to apply Package1 to Computer1.
Solution: At a command prompt, you change the current folder to , and then you run the RegSvr32.exe Package1.ppkg command.
Does this meet the goal?

  • A. No
  • B. Yes

Answer: A

Explanation:
Explanation
To install a provisioning package, navigate to Settings > Accounts > Access work or school > Add or remove a provisioning package > Add a package, and select the package to install.
Reference:
https://docs.microsoft.com/en-us/windows/configuration/provisioning-packages/provisioning-apply-package


NEW QUESTION # 105
You have following types of devices enrolled in Microsoft Intune:
* Windows 10
* Android
* iOS
For which types of devices can you create VPN profiles in Microsoft Endpoint Manager?

  • A. Windows 10 and iOS only
  • B. Windows 10, Android, and iOS
  • C. Windows 10 only
  • D. Windows 10 and Android only
  • E. Android and iOS only

Answer: B

Explanation:
Reference:
https://docs.microsoft.com/en-us/mem/intune/configuration/vpn-settings-android


NEW QUESTION # 106
Your company has computers that run Windows 8.1, Windows 10, or macOS.
The company uses Microsoft Intune to manage the computers.
You need to create an Intune profile to configure Windows Hello for Business on the computers that support it.
Which platform type and profile type should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/intune/endpoint-protection-configure


NEW QUESTION # 107
Your network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD). The domain contains computers that run Windows 10. The computers are enrolled in Microsoft Intune and Windows Analytics.
Your company protects documents by using Windows Information Protection (WIP).
You need to identify non-approved apps that attempt to open corporate documents.
What should you use?

  • A. Intune Data Warehouse
  • B. Microsoft Cloud App Security
  • C. the Device Health solution in Windows Analytics
  • D. the App protection status report in Intune
    References:
    https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/wip-learning

Answer: D


NEW QUESTION # 108
Your company uses Microsoft Intune to manage Windows 10, Android, and iOS devices.
Several users purchase new iPads and Android devices.
You need to tell the users how to enroll their device in Intune.
What should you instruct the users to use for each device? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

The Intune Company Portal app is used to enroll Android, iOS, macOS, and Windows devices References:
https://docs.microsoft.com/en-us/intune-user-help/enroll-device-android-company-portal
https://docs.microsoft.com/en-us/intune-user-help/enroll-your-device-in-intune-ios
https://docs.microsoft.com/en-us/intune-user-help/enroll-your-device-in-intune-macos-cp


NEW QUESTION # 109
Your company has a Microsoft Azure Active Directory (Azure AD) tenant and computers that run Windows 10.
The company uses Microsoft Intune to manage the computers.
The Azure AD tenant has the users shown in the following table.

The device type restrictions in Intune are configured as shown in the following table:

User3 is a device enrollment manager (DEM) in Intune.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Policy 1 - Priority 1 (Andriod, IOS, Windows) Applied to None Policy 2 - Priority 2 (Windows) Applied to Group 2 Policy 3 - Priority 3 (Android) Applied to Group 1 User 1 is in G1, so they cannot enroll Windows devices. User 2 is in both G1 & G2, G2 has P2 with a Pri.2 which means, even though they are in G1, G1 has a pri.3, so P3 will not apply User 3 Is not a member of any group so the Default will apply. Policy 1 is assigned to NONE, default is assigned to All users, therefore they can NOT enroll iOS as default is only Android & Win.
References:
https://docs.microsoft.com/en-us/intune-user-help/enroll-your-device-in-intune-android


NEW QUESTION # 110
You need to prepare for the deployment of the Phoenix office computers.
What should you do first?

  • A. Generalize the computers and configure the Device settings from the Azure Active Directory blade in
    the Azure portal.
  • B. Generalize the computers and configure the Mobility (MDM and MAM) settings from the Azure Active
    Directory blade in the Azure portal.
  • C. Extract the hardware ID information of each computer to a CSV file and upload the file from the
    Devices settings in Microsoft Store for Business.
  • D. Extract the hardware ID information of each computer to an XLSX file and upload the file from the
    Devices settings in Microsoft Store for Business.

Answer: C

Explanation:
Explanation/Reference:
References:
https://docs.microsoft.com/en-us/microsoft-store/add-profile-to-devices#manage-autopilot-deployment-
profiles
Question Set 3


NEW QUESTION # 111
Case Study 2 - Contoso Ltd
Overview
Contoso, Ltd, is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York.
Contoso has the users and computers shown in the following table.

The company has IT, human resources (HR), legal (LEG), marketing (MKG) and finance (FIN) departments.
Contoso uses Microsoft Store for Business and recently purchased a Microsoft 365 subscription.
The company is opening a new branch office in Phoenix. Most of the users in the Phoenix office will work from home.
Existing Environment
The network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).
All member servers run Windows Server 2016. All laptops and desktop computers run Windows
10 Enterprise.
The computers are managed by using Microsoft System Center Configuration Manager. The mobile devices are managed by using Microsoft Intune.
The naming convention for the computers is the department acronym, followed by a hyphen, and then four numbers, for example, FIN-6785. All the computers are joined to the on-premises Active Directory domain.
Each department has an organization unit (OU) that contains a child OU named Computers. Each computer account is in the Computers OU of its respective department.
Intune Configuration

Requirements
Planned Changes
Contoso plans to implement the following changes:
- Provide new computers to the Phoenix office users. The new computers have Windows 10 Pro preinstalled and were purchased already.
- Start using a free Microsoft Store for Business app named App1.
- mplement co-management for the computers.
Technical Requirements
Contoso must meet the following technical requirements:
- Ensure that the users in a group named Group4 can only access Microsoft Exchange Online from devices that are enrolled in Intune.
- Deploy Windows 10 Enterprise to the computers of the Phoenix office users by using Windows Autopilot.
- Monitor the computers in the LEG department by using Windows Analytics.
- Create a provisioning package for new computers in the HR department.
- Block iOS devices from sending diagnostic and usage telemetry data.
- Use the principle of least privilege whenever possible.
- Enable the users in the MKG department to use App1.
- Pilot co-management for the IT department.
You need to meet the requirements for the MKG department users.
What should you do?

  • A. Assign the MKG department users the Basic Purchaser role in Microsoft Store for Business
  • B. Add App1 to the private store
  • C. Download the APPX file for App1 from Microsoft Store for Business
  • D. Acquire App1 from Microsoft Store for Business
  • E. Assign the MKG department users the Purchaser role in Microsoft Store for Business

Answer: D

Explanation:
https://docs.microsoft.com/en-us/microsoft-store/distribute-apps-from-your-private-store


NEW QUESTION # 112
What is the maximum number of devices that User1 and User2 can enroll in Intune? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 113
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.

You have devices enrolled in Microsoft Intune as shown in the following table.

From Intune, you create and send a custom notification named Notification1 to Group1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
A screenshot of a computer Description automatically generated with medium confidence

Reference:
https://docs.microsoft.com/en-us/mem/intune/remote-actions/custom-notifications


NEW QUESTION # 114
You have a Windows 10 device named Device1 that is joined to Active Directory and enrolled in Microsoft Intune.
Device 1 is managed by using Group Policy and Intune.
You need to ensure that the Intune settings override the Group Policy settings.
What should you configure?

  • A. a device configuration profile
  • B. a device compliance policy
  • C. an MDM Security Baseline profile
  • D. a Group Policy Object (GPO)

Answer: A

Explanation:
Reference:
https://uem4all.com/2018/04/02/windows-10-group-policy-vs-intune-mdm-policy-who-wins/


NEW QUESTION # 115
You create a Windows Autopilot deployment profile.
You need to configure the profile settings to meet the following requirements:
Automatically enroll new devices and provision system apps without requiring end-user authentication.
Include the hardware serial number in the computer name.
Which two settings should you configure? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/mem/autopilot/profiles


NEW QUESTION # 116
Your company uses Windows Defender Advanced Threat Protection (Windows Defender ATP). Windows Defender ATP includes the machine groups shown in the following table.

You onboard a computer to Windows Defender ATP as shown in the following exhibit.

What is the effect of the Windows Defender ATP configuration? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 117
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.

You have devices enrolled in Microsoft Intune as shown in the following table.

From Intune, you create and send a custom notification named Notification1 to Group1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
A screenshot of a computer Description automatically generated with medium confidence

Reference:
https://docs.microsoft.com/en-us/mem/intune/remote-actions/custom-notifications


NEW QUESTION # 118
You have 100 devices that run Windows 10 and are joined to Microsoft Azure Active Directory (Azure AD).
You need to prevent users from joining their home computer to Azure AD.
What should you do?

  • A. From the Devices blade in the Azure Active Directory admin center, modify the Device settings.
  • B. From the Device enrollment blade in the Intune admin center, modify the Enrollment restriction settings.
  • C. From the Mobility (MDM and MAM) blade in the Azure Active Directory admin center, modify the Microsoft Intune enrollment settings.
  • D. From the Device enrollment blade in the Intune admin center, modify the Device enrollment manages settings.

Answer: A

Explanation:
Explanation
References:
https://docs.microsoft.com/en-us/intune/enrollment-restrictions-set


NEW QUESTION # 119
......


Microsoft MD-101 Certification Exam covers a range of topics related to managing modern desktops, including configuring, deploying, and managing Windows 10 devices and applications, as well as implementing and managing security and compliance solutions for modern desktops. MD-101 exam also covers topics related to managing and deploying cloud services and mobility solutions, including Microsoft Intune and Azure Active Directory.

 

Enhance your career with MD-101 PDF Dumps - True Microsoft Exam Questions: https://www.passtorrent.com/MD-101-latest-torrent.html

Download MD-101 Dumps (2023) - Free PDF Exam Demo: https://drive.google.com/open?id=1dgybgVdPSC8DE3faf5KlNbWwrikRUsKB