Go Back on MD-102 Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99

MD-102 Practice Test


Page 8 out of 64 Pages

Topic 4: Mix Question

You have a Microsoft 365 E5 subscription that contains 150 hybrid Azure AD joined Windows devices. All the devices are enrolled in Microsoft Intune. You need to configure Delivery Optimization on the devices to meet the following requirements:
• Allow downloads from the internet and from other computers on the local network.
• Limit the percentage of used bandwidth to 50.
What should you use?


A.

a configuration profile


B.

a Windows Update for Business Group Policy setting


C.

a Microsoft Peer-to-Peer Networking Services Group Policy setting


D.

an Update ring for Windows 10 and later profile





A.
  

a configuration profile



Explanation: A configuration profile is the correct answer because it allows you to configure Delivery Optimization settings for Windows devices in Intune. You can specify the download mode, bandwidth limit, caching options, and more. A configuration profile is a template that contains one or more settings that you can apply to groups of devices.

References:
Windows 10 Delivery Optimization settings for Intune - Microsoft Intune | Microsoft Learn
Delivery Optimization settings in Microsoft Intune

You have a Microsoft 365 tenant that contains the objects shown in the following table.

In the Microsoft Intune admin center, you are creating a Microsoft 365 Apps app named App1. To which objects can you assign App1?


A.

Group3 and Group4 only


B.

Admin1, Group3, and Group4 only


C.

Group1, Group3, and Group4 only


D.

Group1, Group2, Group3, and Group4 only


E.

Admin1, Group1. Group2, Group3, and Group4





C.
  

Group1, Group3, and Group4 only



Explanation: In the Microsoft Intune admin center, you can assign apps to users or devices. Users can be assigned to apps by using user groups or individual user accounts. Devices can be assigned to apps by using device groups. In this scenario, the objects shown in the table are as follows:

Admin1 is an individual user account that belongs to the Global administrators role group.
Group1 is a user group that contains 100 users.
Group2 is a device group that contains 50 devices.
Group3 is a user group that contains 200 users.
Group4 is a device group that contains 150 devices.

Since App1 is a Microsoft 365 Apps app, it can only be assigned to users, not devices. Therefore, Group2 and Group4 are not valid objects for app assignment. Admin1 is also not a valid object for app assignment, because individual user accounts can only be used for testing purposes, not for production deployment. Therefore, the only valid objects for app assignment are Group1 and Group3, which are user groups.

You have a Microsoft 365 subscription that contains 1,000 Android devices enrolled in Microsoft Intune. You create an app configuration policy that contains the following settings:

• Device enrollment type: Managed devices
• Profile Type: All Profile Types
• Platform: Android Enterprise

Which two types of apps can be associated with the policy? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.


A.

Built-in Android app


B.

Managed Google Play store app


C.

Web link


D.

Android Enterprise system app


E.

Android store app





B.
  

Managed Google Play store app



D.
  

Android Enterprise system app



You have an Azure AD group named Group1. Group! contains two Windows 10 Enterprise devices named Device1 and Device2. You create a device configuration profile named Profile1. You assign Profile! to Group1. You need to ensure that Profile! applies to Device1 only. What should you modify in Profile 1?


A.

Assignments


B.

Settings


C.

Scope (Tags)


D.

Applicability Rules





D.
  

Applicability Rules



Explanation: To ensure that Profile1 applies to Device1 only, you need to modify the Applicability Rules in Profile1. You can use applicability rules to filter which devices receive a profile based on criteria such as device model, manufacturer, or operating system version. You can create an applicability rule that matches Device1’s properties and excludes Device2’s properties. 
References: https://docs.microsoft.com/enus/mem/intune/configuration/device-profile-assign#applicability-rules

You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.

You create a Conditional Access policy named CAPolicy1 that will block access to Microsoft Exchange Online from iOS devices. You assign CAPolicy1 to Group1.
You discover that User1 can still connect to Exchange Online from an iOS device.
You need to ensure that CAPolicy1 is enforced.
What should you do?


A.

Configure a new terms of use (TOU).


B.

Assign CAPolicy1 to Group2.


C.

Enable CAPolicy1


D.

Add a condition in CAPolicy1 to filter for devices.





B.
  

Assign CAPolicy1 to Group2.



Explanation:
Common signals that Conditional Access can take in to account when making a policy decision include the following signals:
* User or group membership
Policies can be targeted to specific users and groups giving administrators fine-grained control over access.
* Device
Users with devices of specific platforms or marked with a specific state can be used when enforcing Conditional Access policies.
Use filters for devices to target policies to specific devices like privileged access workstations.
* Etc.
Reference: https://learn.microsoft.com/en-us/azure/active-directory/conditionalaccess/overview


Page 8 out of 64 Pages
Previous