Exam2pass
0 items Sign In or Register
  • Home
  • IT Exams
  • Guarantee
  • FAQs
  • Reviews
  • Contact Us
  • Demo
Exam2pass > Microsoft > Microsoft Certifications > MD-102 > MD-102 Online Practice Questions and Answers

MD-102 Online Practice Questions and Answers

Questions 4

You have a Microsoft 365 subscription that uses Microsoft Intune Suite.

You use Microsoft Intune to manage devices.

You plan to deploy two apps named App1 and App2 to all Windows devices. App1 must be installed before App2.

From the Intune admin center, you create and deploy two Windows app (Win32) apps.

You need to ensure that App1 is installed before App2 on every device.

What should you configure?

A. the App1 deployment configurations

B. a dynamic device group

C. a detection rule

D. the App2 deployment configurations

Buy Now

Correct Answer: D

Detection rules in Win32 apps are telling Intune how to tell if the application has been installed or not. Configure a dependency in the win32 app deployment screen even has this wording: "Software dependencies are applications that must be installed before this application can be installed"

Configure App1 first so that it'll be selectable in the dependencies section

Questions 5

You have a Microsoft Deployment Toolkit (MDT) deployment share named DS1.

In the Out-of-Box Drivers node, you create folders that contain drivers for different hardware models.

You need to configure the Inject Drivers MDT task to use PnP detection to install the drivers for one of the hardware models.

What should you do first?

A. Import an OS package.

B. Create a selection profile.

C. Add a Gather task to the task sequence.

D. Add a Validate task to the task sequence.

Buy Now

Correct Answer: B

By default, MDT adds any storage and network drivers that you import to the boot images. However, you should add only the drivers that are necessary to the boot image. You can control which drivers are added by using selection profiles.

Reference: https://docs.microsoft.com/en-us/windows/deployment/deploy-windows-mdt/deploy-a-windows-10-image-using-mdt

Questions 6

You have a Microsoft 365 subscription that contains 1,000 Windows 11 devices enrolled in Microsoft Intune.

You plan to use Intune to deploy an application named App1 that contains multiple installation files.

What should you do first?

A. Prepare the contents of App1 by using the Microsoft Win32 Content Prep Tool.

B. Create an Android application package (APK).

C. Upload the contents of App1 to Intune.

D. Install the Microsoft Deployment Toolkit (MDT).

Buy Now

Correct Answer: A

B. An Android application package (APK) is used to deploy Android apps, not Win32 apps.

C. You cannot upload the contents of App1 to Intune until you have prepared the app content by using the Microsoft Win32 Content Prep Tool.

D. The Microsoft Deployment Toolkit (MDT) is used to deploy Windows operating systems and other software to computers, not to manage mobile devices.

Questions 7

You have a Microsoft 365 subscription. All devices run Windows 10.

You need to prevent users from enrolling the devices in the Windows Insider Program.

What two configurations should you perform from the Microsoft Intune admin center? Each correct answer is a complete solution.

NOTE: Each correct selection is worth one point.

A. a device restrictions device configuration profile

B. an app configuration policy

C. a Windows 10 and later security baseline

D. a custom device configuration profile

E. a Windows 10 and later update ring

Buy Now

Correct Answer: DE

D: Microsoft Intune includes many built-in settings to control different features on a device. You can also create custom profiles, which are created similar to built-in profiles. Custom profiles are great when you want to use device settings and features that aren't built in to Intune. These profiles include features and settings for you to control on devices in your organization. For example, you can create a custom profile that sets the same feature for every Windows device.

E Set up Insider Preview builds using Intune

1.

Log in to the Azure portal and select Intune.

2.

Go to Software Updates > Windows 10 Update Rings and select + Create to make an Update Ring policy. Add a name and select the Settings section to configure its settings.

3.

Etc.

Reference: https://docs.microsoft.com/en-us/windows-insider/business/manage-builds

Questions 8

You have a Microsoft 365 tenant that uses Microsoft Intune.

You use the Company Portal app to access and install published apps to enrolled devices.

From the Microsoft Intune admin center, you add a Microsoft Store app.

Which two App information types are visible in the Company Portal?

NOTE: Each correct selection is worth one point.

A. Privacy URL

B. Information URL

C. Developer

D. Owner

Buy Now

Correct Answer: AB

In the Microsoft Store App information page available through Microsoft Endpoint Manager admin center, the app details include:

*

Privacy URL: Optionally, enter the URL of a website that contains privacy information for this app. The URL is displayed to users in the company portal.

*

Developer: Optionally, enter the name of the app developer.

Information URL or Owner are not included.

Reference:

https://docs.microsoft.com/en-us/mem/intune/apps/store-apps-windows

Questions 9

You have computers that run Windows 10 and are managed by using Microsoft Intune.

Users store their files in a folder named D:\Folder1.

You need to ensure that only a trusted list of applications is granted write access to D:\Folder1.

What should you configure in the device configuration profile?

A. Microsoft Defender Exploit Guard

B. Microsoft Defender Application Guard

C. Microsoft Defender SmartScreen

D. Microsoft Defender Application Control

Buy Now

Correct Answer: A

The four components of Windows Defender Exploit Guard are:

1.

Controlled folder access: Protects sensitive data from ransomware by blocking untrusted processes from accessing your protected folders

2.

Attack Surface Reduction (ASR)

3.

Exploit protection

4.

Network protection

Reference: https://www.microsoft.com/security/blog/2017/10/23/windows-defender-exploit-guard-reduce-the-attack-surface-against-next-generation-malware/

Questions 10

You manage 1,000 computers that run Windows 10. All the computers are enrolled in Microsoft Intune. You manage the servicing channel settings of the computers by using Intune.

You need to review the servicing status of a computer.

What should you do?

A. From Device configuration - Profiles, view the device status.

B. From Software updates, view the Per update ring deployment state.

C. From Software updates, view the audit logs.

D. From Device compliance, view the device compliance.

Buy Now

Correct Answer: B

Reports for Update rings for Windows 10 and later policy.

Intune offers integrated report views for the Windows update ring policies you deploy. These views display details about the update ring deployment and status:

1) Sign in to Microsoft Endpoint Manager admin center.

2) Select Devices > Monitor. Then under Software updates select Per update ring deployment state and choose the deployment ring to review.

Note: Windows 10 and later update rings - Use a built-in report that's ready by default when you deploy update rings to your devices.

Reference:

https://docs.microsoft.com/en-us/intune/windows-update-compliance-reports

Questions 11

HOTSPOT

You have a Microsoft 365 E5 subscription.

You create an app protection policy for Android device named Policy1 as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.

Hot Area:

Buy Now

Correct Answer:

Box 1: Install the Company Portal app on the device

On Android, Android devices will prompt to install the Intune Company Portal app regardless of which Device Management type is chosen. For example, if you select 'Android Enterprise' then users with unmanaged Android devices will still be

prompted.

Box 2: device only

App protection policies can apply to apps running on devices that may or may not be managed by Intune.

Important

It can take time for app protection policies to apply to existing devices. End users will see a notification on the device when the app protection policy is applied. Apply your app protection policies to devices before applying condidtional access

rules.

Reference:

https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policies#app-protection-policies-for-iosipados-and-android-apps

Questions 12

HOTSPOT

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant.

You have a Microsoft 365 subscription.

You plan to use Windows Autopilot to deploy new Windows devices.

You plan to create a deployment profile.

You need to ensure that the deployment meets the following requirements:

1.

Devices must be joined to AD DS regardless of their current working location.

2.

Users in the marketing department must have a line-of-business (LOB) app installed during the deployment.

The solution must minimize administrative effort.

What should you do for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

Buy Now

Correct Answer:

Box 1: Deploy Always on VPN.

Devices must be joined to AD DS regardless of their current working location.

Off-premises/Internet scenarios and VPN connectivity

Windows Autopilot user-driven hybrid Azure AD join supports off-premises/Internet scenarios where direct connectivity to Active directory and domain controllers isn't available. However, an off-premises/Internet scenario doesn't eliminate the

need for connectivity to Active Directory and a domain controller during the domain join. In an off-premises/Internet scenario, connectivity to Active Directory and a domain controller can be established via a VPN connection during the

Autopilot process.

For off-premises/Internet scenarios requiring VPN connectivity, the only change in the Autopilot profile would be in the setting Skip AD connectivity check. In the Create and assign user-driven hybrid Azure AD join Autopilot profile section, the

Skip AD connectivity check setting should be set to Yes instead of to No. Setting this option to Yes prevents the deployment from failing since there's no direct connectivity to Active Directory and domain controllers until the VPN connection is

established.

In addition to changing the Skip AD connectivity check setting to Yes in the Autopilot profile, VPN support also relies on the following prerequisites:

The VPN solution can be deployed and installed with Intune.

The VPN solution needs to support one of the following options:

Let's the user manually establish a VPN connection from the Windows sign-in screen.

Automatically establishes a VPN connection as needed.

The VPN solution would need to be installed and configured via Intune during the Autopilot process. Configuration would need to include deploying any required device certificates if needed by the VPN solution. Once the VPN solution is

installed and configured on the device, the VPN connection can be established, either automatically or manually by the user, at which point the domain join can occur.

Box 2: Create a Microsoft Intune app deployment

Users in the marketing department must have a line-of-business (LOB) app installed during the deployment.

Add a Windows line-of-business app to Microsoft Intune A line-of-business (LOB) app is one that you add from an app installation file. This kind of app is typically written in-house. The following steps provide guidance to help you add a

Windows LOB app to Microsoft Intune.

Step 1 - App information

Step 2 - Select scope tags (optional)

Step 3 - Assignments

Step 4 - Review + create

Select the app type

Sign in to the Microsoft Intune admin center.

Select Apps > All apps > Add.

In the Select app type pane, under the Other app types, select Line-of-business app.

Click Select. The Add app steps are displayed.

Step 1 - App information

Select the app package file

Etc.

Incorrect:

* Modify the Autopilot deployment profile

Reference: https://learn.microsoft.com/en-us/autopilot/tutorial/pre-provisioning/hybrid-azure-ad-join-autopilot-profile https://learn.microsoft.com/en-us/mem/intune/apps/lob-apps-windows

Questions 13

DRAG DROP

You have an on-premises Active Directory domain that syncs to Azure AD tenant.

The tenant contains computers that run Windows 10. The computers are hybrid Azure AD joined and enrolled in Microsoft Intune.

The Microsoft Office settings on the computers are configured by using a Group Policy Object (GPO).

You need to migrate the GPO to Intune.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Select and Place:

Buy Now

Correct Answer:

Step 1: Create a configuration profile

Create the template

1) Sign in to the Microsoft Endpoint Manager admin center.

2) Select Devices > Configuration profiles > Create profile.

3) Etc.

Step 2: Configure the Administrative Template settings.

Find some settings. There are thousands of settings available in these templates.

Step 3: Assign the profile.

The template is created, but may not be doing anything yet. Be sure to assign the template (also called a profile) and monitor its status.

Reference:

https://docs.microsoft.com/en-us/mem/intune/configuration/administrative-templates-windows

Exam Code: MD-102
Exam Name: Endpoint Administrator
Last Update: Jun 13, 2025
Questions: 351

PDF (Q&A)

$45.99
ADD TO CART

VCE

$49.99
ADD TO CART

PDF + VCE

$59.99
ADD TO CART

Exam2Pass----The Most Reliable Exam Preparation Assistance

There are tens of thousands of certification exam dumps provided on the internet. And how to choose the most reliable one among them is the first problem one certification candidate should face. Exam2Pass provide a shot cut to pass the exam and get the certification. If you need help on any questions or any Exam2Pass exam PDF and VCE simulators, customer support team is ready to help at any time when required.

Home | Guarantee & Policy |  Privacy & Policy |  Terms & Conditions |  How to buy |  FAQs |  About Us |  Contact Us |  Demo |  Reviews

2025 Copyright @ exam2pass.com All trademarks are the property of their respective vendors. We are not associated with any of them.