Exam2pass
0 items Sign In or Register
  • Home
  • IT Exams
  • Guarantee
  • FAQs
  • Reviews
  • Contact Us
  • Demo
Exam2pass > Microsoft > Microsoft Certifications > MD-102 > MD-102 Online Practice Questions and Answers

MD-102 Online Practice Questions and Answers

Questions 4

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to deploy and manage Windows devices.

You have 100 devices from users that left your company.

You need to repurpose the devices for new users by removing all the data and applications installed by the previous users. The solution must minimize administrative effort.

What should you do?

A. Deploy a new configuration profile to the devices.

B. Perform a Windows Autopilot reset on the devices.

C. Perform an in-place upgrade on the devices.

D. Perform a clean installation of Windows 11 on the devices.

Buy Now

Correct Answer: B

Windows Autopilot Reset takes the device back to a business-ready state, allowing the next user to sign in and get productive quickly and simply. Specifically, Windows Autopilot Reset:

Removes personal files, apps, and settings.

Reapplies a device's original settings.

Sets the region, language, and keyboard to the original values.

Maintains the device's identity connection to Azure AD.

Maintains the device's management connection to Intune.

The Windows Autopilot Reset process automatically keeps information from the existing device:

Wi-Fi connection details.

Provisioning packages previously applied to the device.

A provisioning package present on a USB drive when the reset process is started.

Azure Active Directory device membership and MDM enrollment information.

SCEP certificates.

Windows Autopilot Reset blocks the user from accessing the desktop until this information is restored, including reapplying any provisioning packages. For devices enrolled in an MDM service, Windows Autopilot Reset also blocks until an

MDM sync is completed. When Autopilot reset is used on a device, the device's primary user is removed. The next user who signs in after the reset will be set as the primary user.

Reference:

https://learn.microsoft.com/en-us/mem/autopilot/windows-autopilot-reset

Questions 5

Your network contains an Active Directory domain. The domain contains 10 computers that run Windows 10. Users in the finance department use the computers.

You have a computer named Computer1 that runs Windows 10.

From Computer1, you plan to run a script that executes Windows PowerShell commands on the finance department computers.

You need to ensure that you can run the PowerShell commands on the finance department computers from Computer.

What should you do on the finance department computers?

A. From Windows PowerShell, run the Enable-MMAgent cmdlet.

B. From the local Group Policy, enable the Allow Remote Shell Access setting.

C. From Windows PowerShell, run the Enable-PSRemoting cmdlet.

D. From the local Group Policy, enable the Turn on Script Execution setting.

Buy Now

Correct Answer: C

https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/enable-psremoting?view=powershell-6

Questions 6

What should you use to meet the technical requirements for Azure DevOps?

A. An app protection policy

B. Windows Information Protection (WIP)

C. Conditional access

D. A device configuration profile

Buy Now

Correct Answer: C

https://docs.microsoft.com/en-us/azure/devops/organizations/accounts/manage- conditional-access?view=azure-devops

Questions 7

HOTSPOT

You have an Azure AD tenant named contoso.com that contains the devices shown in the following table.

All devices contain an app named App1 and are enrolled in Microsoft Intune.

You need to prevent users from copying data from App1 and pasting the data into other apps.

Which type of policy and how many policies should you create in Intune? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

Buy Now

Correct Answer:

Questions 8

HOTSPOT

You have 100 Windows 10 devices enrolled in Microsoft Intune.

You need to configure the devices to retrieve Windows updates from the internet and from other computers on a local network.

Which Delivery Optimization setting should you configure, and which type of Intune object should you create? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

Buy Now

Correct Answer:

Questions 9

HOTSPOT

Your network contains an Active Directory domain. The domain contains 1,000 computers that run Windows 11.

You need to configure the Remote Desktop settings of all the computers. The solution must meet the following requirements:

Prevent the sharing of clipboard contents.

Ensure that users authenticate by using Network Level Authentication (NLA).

Which two nodes of the Group Policy Management Editor should you use? To answer, select the appropriate nodes in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

Buy Now

Correct Answer:

Questions 10

HOTSPOT

Your network contains an on-premises Active Directory domain named contoso.com that syncs to Azure AD.

A user named User1 uses the domain-joined devices shown in the following table.

In the Microsoft Entra admin center, you assign a Windows 11 Enterprise E5 license to User1.

You need to identify what will occur when User1 next signs in to the devices.

What should you identify for each device? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

Buy Now

Correct Answer:

Box 1: Will perform an in-place upgrade to Windows 11 Enterprise Windows 10 Pro

Box 2: Will activate as Windows 11 Enterprise Windows 11 Pro

Windows 10 Pro supports the Subscription Activation feature, enabling users to “step-up” from Windows 10 Pro or Windows 11 Pro to Windows 10 Enterprise or Windows 11 Enterprise, respectively, if they are subscribed to Windows 10/11 Enterprise E3 or E5.

With Windows 10, version 1903 and later, the Subscription Activation feature also supports the ability to step-up from Windows 10 Pro Education or Windows 11 Pro Education to the Enterprise grade editions for educational institutions— Windows 10 Education or Windows 11 Education.

Reference: https://docs.microsoft.com/en-us/windows/deployment/windows-10-subscription-activation

Questions 11

HOTSPOT

You have a Microsoft 365 subscription that uses Microsoft Intune and contains 100 Windows 10 devices.

You need to create Intune configuration profiles to perform the following actions on the devices:

1.

Deploy a custom Start layout.

2.

Rename the local Administrator account.

Which profile type template should you use for each action? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

Buy Now

Correct Answer:

Box 1: Device restriction

Customize Start Menu Custom and Taskbar

Here is a quick step-by-step guide to help you to deploy the prepared XML file. This Intune policy helps to customize the start menu and taskbar for Windows 10 devices.

Logon to Microsoft Endpoint Manager Portal.

Navigate to Devices -> Windows -> Configuration Profiles.

Select Platform -> Windows 10 and later.

Select Profile Type -> Template.

Search with “device” and select Device Restrictions.

Click on Create button.

Box 2: Identity protection

Use an Identity protection profile to manage Windows Hello for Business on groups of devices in Microsoft Intune. Windows Hello for Business is a method for signing in to Windows devices by replacing passwords, smart cards, and virtual

smart cards. Intune includes built-in settings so Administrators can configure and use Windows Hello for Business.

Incorrect:

*

Delivery Optimization settings for your Windows devices to reduce bandwidth consumption when those devices download applications and updates. Configure Delivery Optimization as part of your device configuration profiles.

*

With Intune, you can use device configuration profiles to manage common Endpoint protection security features on devices, including:

Firewall BitLocker Allowing and blocking apps Microsoft Defender and encryption For example, you can create an Endpoint protection profile that only allows macOS users to install apps from the Mac App Store. Or, enable Windows SmartScreen when running apps on Windows 10/11 devices.

Reference: https://www.anoopcnair.com/start-menu-taskbar-custom-layout-intune-cloudpc/ https://docs.microsoft.com/en-us/mem/intune/protect/identity-protection-configure

Questions 12

HOTSPOT

You need a new conditional access policy that has an assignment for Office 365 Exchange Online.

You need to configure the policy to meet the technical requirements for Group4.

Which two settings should you configure in the policy? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

Buy Now

Correct Answer:

References: https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/overview https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/conditions https://docs.microsoft.com/en-us/intune/device-compliance-get-started

Questions 13

DRAG DROP

You have a Microsoft Deployment Toolkit (MDT) deployment share that has a path of D:\MDTShare.

You need to add a feature pack to the boot image.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Select and Place:

Buy Now

Correct Answer:

Step 1: Copy the feature pack to D:\MDTShare\Tools\x86

Add a feature pack, DaRT 10 (part of MDOP 2015), to the boot images.

1.

Copy the CAB files to the deployment share: MDTShare\Tools\x86

2.

In the Deployment Workbench, right-click the MDTShare deployment share and select Properties.

Step 2: Modify the Windows PE properties of the deployment share

3.

On the Windows PE tab, in the Platform drop-down list, make sure x86 is selected.

4.

On the Features sub tab, select the Microsoft Diagnostics and Recovery Toolkit (DaRT) checkbox.

Etc.

Step 3: Update the deployment share

Like the MDT Build Lab deployment share, the MDT Production deployment share needs to be updated after it has been configured. This is the process during which the Windows PE boot images are created.

Reference:

https://docs.microsoft.com/en-us/windows/deployment/deploy-windows-mdt/deploy-a-windows-10-image-using-mdt

Exam Code: MD-102
Exam Name: Endpoint Administrator
Last Update: May 27, 2026
Questions: 431

PDF (Q&A)

$45.99
ADD TO CART

VCE

$49.99
ADD TO CART

PDF + VCE

$59.99
ADD TO CART

Exam2Pass----The Most Reliable Exam Preparation Assistance

There are tens of thousands of certification exam dumps provided on the internet. And how to choose the most reliable one among them is the first problem one certification candidate should face. Exam2Pass provide a shot cut to pass the exam and get the certification. If you need help on any questions or any Exam2Pass exam PDF and VCE simulators, customer support team is ready to help at any time when required.

Home | Guarantee & Policy |  Privacy & Policy |  Terms & Conditions |  How to buy |  FAQs |  About Us |  Contact Us |  Demo |  Reviews

2026 Copyright @ exam2pass.com All trademarks are the property of their respective vendors. We are not associated with any of them.