Pass Microsoft MD-101 Exam with Guarantee Updated 265 Questions
Latest MD-101 Pass Guaranteed Exam Dumps Certification Sample Questions
Microsoft MD-101: Potential candidates
Just like any other certification path from the Microsoft program, this one is ideal for a certain audience that can pursue it. Thus, you can go for this option if you are an Administrator who wants to verify skills in managing devices in an enterprise environment and monitoring client applications, or improve the existing knowledge. You should also know how to perform the processes associated with security, deployment, and configuration.
Microsoft MD-101: Exam topics and subtopics
The exam covers different domains and each of them has subtopics, which you need to master as well. Thus, it is important to know the content of the test in detail. The sections of the Microsoft MD-101 exam content include the following:
- Manage and Protect Devices (20-25%)
This topic covers the details of how to manage Intune device enrollment and inventory, monitor devices, and manage Windows Defender. These skills include the way of how you enroll non-Windows or Windows devices as well as your ability to integrate Windows Defender Application Control and your knowledge of how to work with Windows Defender extensions.
- Manage Profiles and Policies (25-30%)
In this area, you will be evaluated on the skills, including implementation of conditional access and compliance policies for devices, planning of co-management, management of user profiles, and configuration of device profiles. Therefore, you need to know how to perform the migration of group policy to MDM policies, configure Enterprise State Roaming in Azure AD, and implement device profiles. It is also important to understand the idea of recommending a co-management strategy, implementing Folder Redirection, and managing conditional access policies.
- Deploy and Update Operating Systems (35-40%)
This domain has the highest percentage of appearing in the Microsoft MD-101 exam. This means that most of the 40-60 questions will represent this section. It covers a wide range of skills, including the upgrade of devices to Windows 10, management of updates, implementation of Windows 10 by using Windows Autopilot, management of device authentication, as well as implementation of Windows 10 by using dynamic deployment. These tasks include your full understanding of how to pilot deployment, identify downgrade and upgrade paths, perform Azure AD join, migrate user profiles, and configure an environment of Desktop Analytics. You have to know the details of managing and troubleshooting provisioning packages as well. Your skills in managing sign-on options and implementing feature updates are also important.
- Manage Apps and Data (10-15%)
This objective has the smallest amount of questions that you will face with during the exam. It covers two main subtopics, which include deploying and updating apps as well as implementing Mobile Application Management. This means that you should have the relevant skills in deploying apps by using Intune or Microsoft Store for Business, deploying Microsoft 365 Apps for Enterprise, configuring kiosk and implementing it, and managing MAM policies.
NEW QUESTION 124
You have a workgroup computer named Computer1 that runs Windows 10 and has the users shown in the following table.
Group1 is a member of Group3.
You are creating a file named Kiosk.xml that specifies a lockdown profile for a multi-app kiosk.
Kiosk.xml contains the following section.
You apply Kiosk.xml to Computer1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/windows/configuration/lock-down-windows-10-to-specific-apps#config-for-gro
NEW QUESTION 125
You have a Microsoft 365 subscription.
You need to configure access to Microsoft Office 365 for unmanaged devices. The solution must meet the following requirements:
* Allow only the Microsoft Intune Managed Browser to access Office 365 web interfaces.
* Ensure that when users use the Intune Managed Browser to access Office 365 web interfaces, they can only copy data to applications that are managed by the company.
Which two settings should you configure from the Microsoft Intune blade? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
References:
https://docs.microsoft.com/en-us/intune/app-configuration-managed-browser#application-protection-policies-for
NEW QUESTION 126
You need to meet the technical requirements for the IT department.
What should you do first?
- A. From the Azure Active Directory blade in the Azure portal, enable Seamless single sign-on.
- B. From the Configuration Manager console, add an Intune subscription.
- C. From the Azure Active Directory blade in the Azure portal, configure the Mobility (MDM and MAM)
settings. - D. From the Microsoft Intune blade in the Azure portal, configure the Windows enrollment settings.
Answer: C
Explanation:
Explanation/Reference:
Reference:
https://docs.microsoft.com/en-us/sccm/comanage/tutorial-co-manage-clients
Question Set 3
NEW QUESTION 127
You use Microsoft Intune to manage Windows updates.
You have computers that run Windows 10. The computers are in a workgroup and are enrolled in Intune. The computers are configured as shown in the following table.
On each computer, the Select when Quality Updates are received Group Policy setting is configured as shown in the following table.
You have Windows 10 update rings in Intune as shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
NEW QUESTION 128
You use the Antimalware Assessment solution in Microsoft Azure Log Analytics.
From the Protection Status dashboard, you discover the computers shown in the following table.
You verify that both computers are connected to the network and running.
What is a possible cause of the issue on each computer? To answer, drag the appropriate causes to the correct computers. Each cause may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/ga-ie/azure/security-center/security-center-install-endpoint-protection
NEW QUESTION 129
You have a computer named Computer1 that runs Windows 10.
Computer1 has the users shown in the following table.
User1 signs in to Computer1, creates the following files, and then signs out User3 signs in to Computer1 and creates a file named File4.
User2 has never signed in to Computer1.
How many DOCX files will appear on the desktop of each user the nest time each user signs in? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
NEW QUESTION 130
You have a Microsoft 365 subscription.
You have 10 computers that run Windows 10 and are enrolled in mobile device management (MDM) You need to deploy the Microsoft Office 365 ProPlus suite to all the computers. What should you do?
- A. From Microsoft Azure Active Directory (Azure AD), add an enterprise application
- B. From Microsoft Azure Active Directory (Azure AD), add an app registration.
- C. From the Device Management admin center, create a Windows 10 device profile.
- D. From the Device Management admin center, add an app.
Answer: A
NEW QUESTION 131
You have 1,000 computers that run Windows 10 and are members of an Active Directory domain.
You create a workspace in Microsoft Azure Log Analytics.
You need to capture the event logs from the computers to Azure.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/azure-monitor/platform/agent-windows
NEW QUESTION 132
You have a Microsoft 365 subscription.
All computers are enrolled in Microsoft Intune.
You have business requirements for securing your Windows 10 environment as shown in the following table.
What should you implement to meet each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://github.com/MicrosoftDocs/IntuneDocs/blob/master/intune/advanced-threat-protection.md
NEW QUESTION 133
You have computers that run Windows 10 as shown in the following table.
Computer2 and Computer3 are enrolled in Microsoft Intune.
In a Group Policy object (GPO) linked to the domain, you enable the Computer Configuration/Administrative Templates/Windows Components/Search/Allow Cortana setting.
In an Intune device configuration profile, you configure the following:
* Device/Vendor/MSFT/Policy/Config/ControlPolicyConflict/MDMWinsOverGP to a value of 1
* Experience/AllowCortana to a value of 0.
Each of the following statement, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://blogs.technet.microsoft.com/cbernier/2018/04/02/windows-10-group-policy-vs-intune-mdm-policy-who-w
NEW QUESTION 134
What should you upgrade before you can configure the environment to support co-management?
- A. the domain functional level
- B. Windows Server Update Services (WSUS)
- C. the domain controllers
- D. Configuration Manager
Answer: D
Explanation:
References:
https://docs.microsoft.com/en-us/sccm/comanage/tutorial-co-manage-clients
Topic 2, Contoso Ltd
Existing Environment
The network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).
All member servers run Windows Server 2016. All laptops and desktop computers run Windows 10 Enterprise.
The computers are managed by using Microsoft System Center Configuration Manager. The mobile devices are managed by using Microsoft Intune.
The naming convention for the computers is the department acronym, followed by a hyphen, and then four numbers, for example, FIN-6785. All the computers are joined to the on-premises Active Directory domain.
Each department has an organization unit (OU) that contains a child OU named Computers. Each computer account is in the Computers OU of its respective department.
Intune Configuration
Requirements
Planned Changes
Contoso plans to implement the following changes:
Provide new computers to the Phoenix office users. The new computers have Windows 10 Pro preinstalled and were purchased already.
Start using a free Microsoft Store for Business app named App1.
Implement co-management for the computers.
Technical Requirements:
Contoso must meet the following technical requirements:
Ensure that the users in a group named Group4 can only access Microsoft Exchange Online from devices that are enrolled in Intune.
Deploy Windows 10 Enterprise to the computers of the Phoenix office users by using Windows Autopilot.
Monitor the computers in the LEG department by using Windows Analytics.
Create a provisioning package for new computers in the HR department.
Block iOS devices from sending diagnostic and usage telemetry data.
Use the principle of least privilege whenever possible.
Enable the users in the MKG department to use App1.
Pilot co-management for the IT department.
NEW QUESTION 135
You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com. All Windows 10 devices are enrolled in Microsoft Intune.
You configure the following settings in Windows Information Protection (WIP):
* Protected apps: App1
* Exempt apps: App2
* Windows Information Protection mode: Silent
App1, App2, and App3 use the same file format.
You create a file named File1 in App1.
You need to identify which apps can open File1.
What apps should you identify? To answer, select the appropriate options in the answer area, NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune
https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune#exempt-apps-from-wip-restrictions
NEW QUESTION 136
Your company has an infrastructure that has the following:
* A Microsoft 365 tenant
* An Active Directory forest
* Microsoft Store for Business
* A Key Management Service (KMS) server
* A Windows Deployment Services (WDS) server
* A Microsoft Azure Active Directory (Azure AD) Premium tenant
The company purchases 100 new computers that run Windows 10.
You need to ensure that the new computers are joined automatically to Azure AD by using Windows AutoPilot.
What should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/intune/enrollment-autopilot
Topic 1, Litware inc
Case Study
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.
Existing Environment
Current Business Model
The Los Angeles office has 500 developers. The developers work flexible hours ranging from 11:00 to 22:00. Litware has a Microsoft System Center 2012 R2 Configuration Manager deployment. During discovery, the company discovers a process where users are emailing bank account information of its customers to internal and external recipients.
Current Environment
The network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD). The functional level of the forest and the domain is Windows Server 2012 R2. All domain controllers run Windows Server 2012 R2.
Litware has the computers shown in the following table.
The development department uses projects in Azure DevOps to build applications.
Most of the employees in the sales department are contractors. Each contractor is assigned a computer that runs Windows 10. At the end of each contract, the computer is assigned to different contractor. Currently, the computers are re-provisioned manually by the IT department.
Problem Statements
Litware identifies the following issues on the network:
* Employees in the Los Angeles office report slow Internet performance when updates are downloading. The employees also report that the updates frequently consume considerable resources when they are installed. The Update settings are configured as shown in the Updates exhibit. (Click the Updates button.)
* Management suspects that the source code for the proprietary applications in Azure DevOps in being shared externally.
* Re-provisioning the sales department computers is too time consuming.
Requirements
Business Goals
Litware plans to transition to co-management for all the company-owned Windows 10 computers. Whenever possible, Litware wants to minimize hardware and software costs.
Device Management Requirements
Litware identifies the following device management requirements:
* Prevent the sales department employees from forwarding email that contains bank account information.
* Ensure that Microsoft Edge Favorites are accessible from all computers to which the developers sign in.
* Prevent employees in the research department from copying patented information from trusted applications to untrusted applications.
Technical Requirements
Litware identifies the following technical requirements for the planned deployment:
* Re-provision the sales department computers by using Windows AutoPilot.
* Ensure that the projects in Azure DevOps can be accessed from the corporate network only.
* Ensure that users can sign in to the Azure AD-joined computers by using a PIN. The PIN must expire every 30 days.
* Ensure that the company name and logo appears during the Out of Box Experience (OOBE) when using Windows AutoPilot.
Exhibits
NEW QUESTION 137
Your company has an infrastructure that has the following:
A Microsoft 365 tenant
An Active Directory forest
Microsoft Store for Business
A Key Management Service (KMS) server
A Windows Deployment Services (WDS) server
A Microsoft Azure Active Directory (Azure AD) Premium tenant
The company purchases 100 new computers that run Windows 10.
You need to ensure that the new computers are joined automatically to Azure AD by using Windows AutoPilot.
What should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/intune/enrollment-autopilot
NEW QUESTION 138
You have a Microsoft 365 tenant that contains the users shown in the following table.
You have Windows 10 devices enrolled in Microsoft Intune as shown in the following table.
You create a Windows 10 update ring that has the following settings:
Basics:
- Name: Ring1
Update ring settings:
- Active hours start: 8 AM
- Active hours end: 8 PM
Assignments:
- Included Groups: All devices
- Excluded Groups: Group1
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/mem/intune/protect/windows-10-update-rings
NEW QUESTION 139
You have 500 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune.
You plan to distribute certificates to the computers by using Simple Certificate Enrollment Protocol (SCEP).
You have the servers shown in the following table.
NDES issues certificates from the subordinate CA.
You are configuring a device profile as shown in the exhibit. (Click the tab.) You need to complete the SCEP profile.
- A. Server1
- B. Server2
- C. Server3
- D. Server4
Answer: D
NEW QUESTION 140
Your company has an infrastructure that has the following:
A Microsoft 365 tenant
An Active Directory forest
Microsoft Store for Business
A Key Management Service (KMS) server
A Windows Deployment Services (WDS) server
A Microsoft Azure Active Directory (Azure AD) Premium tenant
The company purchases 100 new computers that run Windows 10.
You need to ensure that the new computers are joined automatically to Azure AD by using Windows AutoPilot.
What should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/intune/enrollment-autopilot
NEW QUESTION 141
Your company has a computer named Computer1 that runs Windows 10 Pro.
The company develops a proprietary Universal Windows Platform (UWP) app named App1. App1 is signed with a certificate from a trusted certification authority (CA).
You need to sideload App1 to Computer1.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://www.windowscentral.com/how-enable-windows-10-sideload-apps-outside-store
https://docs.microsoft.com/en-us/windows/application-management/sideload-apps-in-windows-10
NEW QUESTION 142
You have a hybrid Microsoft Azure Active Directory (Azure AD) tenant.
You configure a Windows Autopilot deployment profile as shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
References:
https://docs.microsoft.com/en-us/intune/enrollment-autopilot
NEW QUESTION 143
You have a hybrid Microsoft Azure Active Directory (Azure AD) tenant, a Microsoft System Center Configuration Manager (Current Branch) environment, and a Microsoft 365 subscription.
You have computers that run Windows 10 as shown in the following table.
You plan to use Microsoft 365 Device Management.
Which computers support co-management by Configuration Manager and Device Management?
- A. Computer1, Computer2, and Computer3
- B. Computer1 and Computer2 only
- C. Computer2 only
- D. Computer3 only
Answer: C
NEW QUESTION 144
You have unrooted devices enrolled in Microsoft Intune as shown in the following table.
The devices are members of a group named Group1.
In Intune, you create a device compliance location that has the following configurations:
* Name: Network1
* IPv4 range: 192.168.0.0/16
In Intune, you create a device compliance policy for the Android platform. The policy has following configurations:
* Name: Policy1
* Device health: Rooted devices: Block
* Locations: Location: Network1
* Mark device noncompliant: Immediately
* Assigned: Group1
In Intune device compliance policy has the following configurations:
* Mark devices with no compliance policy assigned as: Compliant
* Enhanced jailbreak detection: Enabled
* Compliance status validity period (days): 20
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/intune/device-compliance-get-started
NEW QUESTION 145
......
New MD-101 Test Materials & Valid MD-101 Test Engine: https://pass4sure.practicedump.com/MD-101-exam-questions.html