Courseiva

CCNA Manage Maintain Devices Questions

33 of 183 questions · Page 3/3 · Manage Maintain Devices topic · Answers revealed

151
MCQhard

Refer to the exhibit. You are reviewing an Intune configuration profile JSON for Windows 10. The profile includes BitLocker settings. Which setting will prevent users from enabling BitLocker if another encryption method is already in use?

A.bitLockerEncryptionMethod set to aes256
B.passwordRequired set to true
C.bitLockerDisableWarningForOtherDiskEncryption set to false
D.bitLockerDisableWarningForOtherDiskEncryption set to true
AnswerC

When false, the warning is shown and BitLocker will not enable if other encryption exists.

Why this answer

Setting bitLockerDisableWarningForOtherDiskEncryption to false means that BitLocker will display a warning and block enabling BitLocker if another disk encryption method (such as third-party encryption) is detected on the drive. This setting enforces the requirement to prevent users from enabling BitLocker when another encryption solution is already active, ensuring compliance and avoiding conflicts.

Exam trap

The trap here is that candidates often confuse bitLockerDisableWarningForOtherDiskEncryption with a simple warning toggle, not realizing that setting it to false actively blocks BitLocker enablement when other encryption is detected, while setting it to true allows BitLocker to proceed without warning.

How to eliminate wrong answers

Option A is wrong because bitLockerEncryptionMethod set to aes256 only specifies the encryption algorithm to use (AES-256) when BitLocker is enabled; it does not control whether BitLocker can be enabled if another encryption method is already present. Option B is wrong because passwordRequired set to true mandates that a recovery password be configured for BitLocker, but it does not affect the detection or blocking of other disk encryption methods. Option D is wrong because setting bitLockerDisableWarningForOtherDiskEncryption to true would suppress the warning and allow BitLocker to be enabled even if another encryption method is in use, which is the opposite of the desired behavior.

152
MCQeasy

You manage devices in Microsoft Intune. You need to generate a report that shows which devices have not checked in with Intune for more than 30 days. What should you use?

A.Device compliance report
B.Windows Update report
C.Device configuration report
D.Devices without recent check-in report
AnswerD

Intune provides a built-in report called 'Devices without recent check-in' that lists devices that have not communicated with the service within a specified number of days. This report directly answers the requirement to find devices inactive for more than 30 days.

Why this answer

The 'Devices without recent check-in' report in Intune is designed to list devices that have not communicated with the service within a specified period. It allows you to filter by number of days, making it the correct tool to identify devices inactive for more than 30 days.

Exam trap

The trap here is assuming that any device report includes check-in data, or confusing compliance reports with check-in reports.

153
MCQmedium

Refer to the exhibit. You create a compliance policy for Windows 10 devices. A device is reported as non-compliant. Upon investigation, you find that the device has a password of 6 characters. Which setting is causing the non-compliance?

A.requireCodeIntegrity
B.passwordMinimumLength
C.requireDeviceEncryption
D.requireSecureBoot
AnswerB

The compliance policy's passwordMinimumLength setting enforces a minimum character count, and the device's six-character password falls below the configured threshold, triggering non-compliance. This directly matches the stem's reported condition, where the password length is the sole identified deviation from policy requirements.

Why this answer

The compliance policy requires a minimum password length, and the device's 6-character password does not meet that requirement, making it non-compliant. The passwordMinimumLength setting directly controls the minimum number of characters a password must have, so a password shorter than the configured value triggers non-compliance.

Exam trap

The trap here is that candidates often confuse passwordMinimumLength with password complexity or other security settings like requireCodeIntegrity or requireSecureBoot, assuming any security-related non-compliance must be due to a broader security feature rather than the specific password length.

How to eliminate wrong answers

Option A is wrong because requireCodeIntegrity enforces that code integrity features (like Windows Defender Application Control) are enabled, which is unrelated to password length. Option C is wrong because requireDeviceEncryption mandates BitLocker or device encryption, not password length. Option D is wrong because requireSecureBoot checks that Secure Boot is enabled in UEFI, which is a hardware security feature, not a password policy.

154
MCQmedium

You manage 500 Windows 11 devices with Microsoft Intune. Several devices are shared by multiple employees across shifts at a manufacturing plant. You need to configure a policy that automatically removes local user profiles that have not been used for 60 days to conserve disk space, while preserving profiles of users who sign in regularly. What should you configure?

A.A compliance policy that marks devices as noncompliant after 60 days of profile inactivity.
B.An Intune settings catalog policy or custom OMA-URI using the SharedPC CSP with 'InactiveThreshold' set to 60 days.
C.A device restrictions configuration profile with the 'Inactivity timeout' setting configured to 60 days.
D.A Windows 10/11 device restrictions profile with 'Delete inactive user profiles' set to 60 days.
AnswerB

The SharedPC CSP exposes InactiveThreshold, which deletes local profiles not used within the specified number of days. This is the supported Intune mechanism for reclaiming disk space on shared or shift-based devices. It is applied through a settings catalog entry or custom OMA-URI, and it targets the exact behaviour required without affecting active users' profiles.

Why this answer

Shared devices accumulate local profiles over time, and Intune addresses this through the SharedPC CSP, which supports an InactiveThreshold value expressed in days. Configuring this through the settings catalog or a custom OMA-URI deletes dormant profiles automatically while leaving frequently used profiles intact. General device restrictions, compliance policies, and session timeouts do not perform profile cleanup, so they fail to reclaim the disk space consumed by unused accounts.

Exam trap

The trap here is assuming that device restriction or compliance settings include a profile cleanup timer, when in fact only the SharedPC CSP exposes an inactivity threshold that deletes stale local profiles.

155
MCQhard

You are deploying a Windows 11 device using Windows Autopilot. The device is enrolled in Microsoft Intune and assigned a device group. You need to ensure that during the out-of-box experience (OOBE), the device automatically joins Microsoft Entra ID and enrolls in Intune without user interaction. Which Autopilot deployment mode should you configure?

A.Autopilot reset
B.Self-deploying mode
C.User-driven mode
D.Pre-provisioning mode (White glove)
AnswerB

Self-deploying mode is designed for devices that require no user interaction. During OOBE, the device automatically joins Microsoft Entra ID and enrolls in Intune using the device's hardware hash and an assigned Autopilot profile. This mode is ideal for kiosks, digital signage, or shared devices where no user credentials are available or desired.

Why this answer

Self-deploying mode in Windows Autopilot enables a device to join Microsoft Entra ID and enroll in Intune automatically during OOBE, without any user interaction. It is the correct choice when zero-touch provisioning is required and no user credentials are available.

Exam trap

The trap here is assuming that pre-provisioning mode provides fully automated enrollment, when it still requires a user to complete the final OOBE steps.

156
MCQeasy

You manage a group of iOS devices enrolled in Microsoft Intune. Users report that they are unable to receive email on their devices after you deployed a new configuration profile. You need to identify the cause quickly. What should you use?

A.Intune configuration profile assignment status
B.Intune device compliance report
C.Azure AD sign-in logs
D.Intune audit logs
AnswerA

The assignment status for a configuration profile shows which devices received the profile and any errors during deployment. This is the quickest way to see if the email profile was successfully applied or if there were conflicts or failures that could explain the email issue.

Why this answer

The configuration profile assignment status in Intune provides per-device deployment details, including success or failure and error messages. This helps quickly identify if the email profile was not applied correctly or if there was a conflict, directly addressing the user's inability to receive email.

Exam trap

The trap here is confusing compliance reports with configuration profile status, assuming compliance reports show deployment errors.

157
MCQeasy

Your organization uses Microsoft Intune to manage iOS and Android devices. You need to ensure that corporate data on these devices is protected. Specifically, you want to prevent users from copying corporate data from managed apps to personal apps. You also want to ensure that when a device is lost or stolen, the corporate data can be selectively wiped without affecting personal data. Which Intune feature should you use to achieve these requirements?

A.App Protection Policies (MAM).
B.Device Compliance Policies.
C.Conditional Access Policies.
D.Device Configuration Profiles.
AnswerA

App Protection Policies apply MAM controls at the app layer, blocking copy-paste and data transfer from managed apps to personal apps, and support selective wipe that removes only corporate data, leaving personal content intact on the enrolled device.

Why this answer

App Protection Policies (MAM) provide data protection settings such as preventing copy/paste between managed and unmanaged apps, and allow selective wipe of corporate data. Option B is incorrect because device compliance policies focus on device-level settings, not app-level data protection. Option C is incorrect because conditional access policies control access based on compliance, but do not directly prevent copy/paste or provide selective wipe at the app level.

Option D is incorrect because device configuration profiles configure device settings, not app data protection.

158
MCQeasy

You are an endpoint administrator for a company that uses Microsoft Intune. You need to create a report that shows which devices have not checked in to Intune for more than 30 days. What should you use?

A.Intune device inventory report
B.Microsoft Entra sign-in logs
C.Intune device compliance report
D.Intune devices with stale check-in report
AnswerD

Intune includes a built-in report called 'Devices with stale check-in' that lists devices that have not checked in for a specified number of days. This report can be filtered to show devices not checked in for more than 30 days, directly answering the requirement.

Why this answer

Intune provides a specific report called 'Devices with stale check-in' that identifies devices that have not communicated with the service for a defined period. This report can be filtered to show devices with check-in times older than 30 days, making it the correct tool for the task.

Exam trap

The trap here is assuming that compliance or inventory reports include check-in time filters, when in fact only the stale check-in report is designed for this purpose.

159
MCQmedium

Refer to the exhibit. You run this KQL query in Microsoft Sentinel. What is the result?

A.A list of all devices regardless of operating system.
B.A list of all Windows devices with their last activity.
C.A count of unique Windows devices per device name in the last 7 days.
D.A count of security alerts per device.
AnswerC

Correct. The query summarizes unique devices by name.

Why this answer

The KQL query uses `DeviceInfo` (a Microsoft Sentinel table for device inventory), filters with `where` to include only rows where `OperatingSystem` contains 'Windows', then uses `summarize` with `dcount(DeviceName)` to count distinct device names, and `bin(TimeGenerated, 7d)` to group by 7-day intervals. This produces a count of unique Windows devices per device name over the last 7 days, making option C correct.

Exam trap

The trap here is that candidates may misinterpret `dcount(DeviceName)` as a count of rows or a list of devices, rather than recognizing it as a distinct count aggregation, and may overlook that `DeviceInfo` is an inventory table, not an alert table.

How to eliminate wrong answers

Option A is wrong because the query explicitly filters for Windows devices (`where OperatingSystem contains 'Windows'`), so it does not return all devices regardless of OS. Option B is wrong because the query does not retrieve any 'last activity' data; it uses `dcount(DeviceName)` to count unique devices, not to list devices with their last activity timestamp. Option D is wrong because the query operates on `DeviceInfo`, which is a device inventory table, not a security alerts table; there is no alert data or alert count logic in the query.

160
MCQhard

Your company uses Microsoft Intune to manage Windows 11 devices. You need to ensure that when a device is marked as noncompliant, it loses access to Microsoft 365 services within 15 minutes, without affecting compliant devices. You have already created a compliance policy and assigned it to all users. What should you configure next?

A.A device compliance policy in Intune with an action for noncompliance that marks the device as noncompliant immediately.
B.A configuration profile in Intune that sets the device to block access to Microsoft 365 services when noncompliant.
C.A conditional access policy in Microsoft Entra ID that requires compliant devices and set the grant control to 'Require device to be marked as compliant'.
D.A Microsoft Defender for Endpoint device group in Intune with an automated task to restrict access.
AnswerC

Conditional access policies in Microsoft Entra ID evaluate device compliance state and can block access to cloud apps when a device is noncompliant. By requiring compliant devices, noncompliant devices are denied access to Microsoft 365 services. The timing depends on token lifetime and compliance re-evaluation, but this is the correct mechanism to enforce compliance-based access.

Why this answer

Conditional access in Microsoft Entra ID enforces access controls based on conditions such as device compliance. By creating a policy that requires compliant devices for Microsoft 365 apps, noncompliant devices are blocked from accessing those services. This integrates with Intune compliance policies, which evaluate and report device state.

The other options do not provide real-time access blocking based on compliance.

Exam trap

The trap here is confusing Intune compliance policy actions with conditional access enforcement, when only conditional access can block access to cloud apps based on compliance state.

161
MCQmedium

You manage Windows 11 devices with Microsoft Intune. After a Windows quality update is deployed to a pilot ring, several devices report installation failures in the Update reports. You need to identify the exact error code returned by the update installation on a specific device without accessing the device directly. What should you do?

A.From the Intune admin center, select the device and review the device compliance policy status.
B.In the Microsoft Intune admin center, open the device's Windows Update for Business reports and view the 'Update installation failures' report.
C.In Microsoft Intune, review the device's discovered apps report to identify the update failure.
D.Use Microsoft Endpoint Configuration Manager to create a device collection and run a hardware inventory cycle.
AnswerB

Windows Update for Business reports in Intune provide detailed error codes and failure reasons for quality and feature updates, including per-device data. This directly meets the requirement to see the error code without accessing the device, as the report aggregates telemetry from the device and surfaces the exact failure code.

Why this answer

Windows Update for Business reports in Microsoft Intune include detailed update installation data, including failure codes and reasons. These reports are accessible from the Intune admin center and provide per-device information without requiring direct device access. The other options either report unrelated data or require additional infrastructure that does not surface update error codes.

Exam trap

The trap here is confusing update failure reporting with compliance or inventory reporting, which do not expose Windows Update error codes.

162
MCQhard

You are troubleshooting a Windows 11 device that fails to install an Intune-managed update. The device has been offline for two weeks. After reconnecting, the update does not install. In the Intune console, the update shows 'Failed to install' with error code 0x800f0831. What is the most likely cause?

A.The device does not have internet connectivity.
B.The device's Windows component store is corrupted due to missing prerequisites.
C.The device does not have enough disk space.
D.The update is superseded and no longer applicable.
AnswerB

Error 0x800f0831 indicates a missing servicing-stack or prerequisite update, not a network fault. Two weeks offline left the component store without the required cumulative prerequisites, so servicing cannot stage the Intune update. Reconnecting alone does not repair it; DISM /RestoreHealth or installing the prerequisite servicing stack update is needed.

Why this answer

Error code 0x800f0831 indicates that the Windows component store (CBS) is corrupted because a required servicing stack or prerequisite update is missing. When a device has been offline for two weeks, it may lack the necessary baseline updates that the current update depends on, causing the installation to fail even after reconnecting to the network.

Exam trap

The trap here is that candidates often assume 'offline for two weeks' implies a connectivity issue (option A), but the specific error code 0x800f0831 points to a corrupted component store from missing prerequisites, not a network problem.

How to eliminate wrong answers

Option A is wrong because the device has reconnected to the network and the Intune console shows the update attempt with a specific error code, which implies internet connectivity is present; a lack of connectivity would typically result in a 'pending download' or 'not applicable' status, not a specific CBS error. Option C is wrong because insufficient disk space usually produces error codes like 0x80070070 or 0x80070008, not 0x800f0831, which is specific to component store corruption. Option D is wrong because a superseded update would show as 'not applicable' or 'superseded' in the Intune console, not 'Failed to install' with a CBS-related error code; superseded updates are simply no longer offered to the device.

163
Multi-Selecthard

Your organization uses Microsoft Intune to manage devices. You need to collect diagnostic logs from a remote Windows device without user interaction. Which THREE methods can you use?

Select 3 answers
A.MDM diagnostic log collection policy
B.Device configuration profile
C.Device diagnostics (Intune device action)
D.Microsoft Support and Recovery Assistant
E.Remote Windows PowerShell session
AnswersA, C, E

Policy can trigger log upload to Intune.

Why this answer

The MDM diagnostic log collection policy is a built-in Intune feature that allows administrators to configure and trigger the collection of device diagnostic logs from Windows devices remotely without any user interaction. This policy leverages the Windows MDM protocol to gather logs such as event viewer logs, registry keys, and network traces, and uploads them to an Azure storage container for analysis.

Exam trap

The trap here is that candidates often confuse Device configuration profiles (which manage settings) with diagnostic collection actions, or assume that SaRA can be triggered remotely via Intune, when in fact it requires local user initiation.

164
MCQeasy

You are a Microsoft 365 Endpoint Administrator. You need to remotely wipe a lost Windows 11 device that is enrolled in Microsoft Intune. The device is currently offline. What happens when you initiate a wipe action from the Intune admin center?

A.The wipe command is sent via push notification and will execute even if the device is offline.
B.The wipe fails immediately because the device is offline, and you must retry once it is online.
C.The device is marked as wiped in Intune immediately, but the actual wipe occurs only if the device comes online within 24 hours.
D.The wipe command is queued and will execute the next time the device checks in with Intune.
AnswerD

When you initiate a wipe action for an offline device, Intune queues the command. The device will receive and execute the wipe the next time it connects to the Intune service. This is standard behavior for remote actions on enrolled devices. The wipe will remove corporate data and, depending on the wipe type, may reset the device to factory settings. The command remains pending until the device checks in.

Why this answer

Intune queues remote actions for devices that are offline. When the device next connects to the Intune service, it receives the pending wipe command and executes it. This ensures that lost or stolen devices can be wiped even if they are currently disconnected.

The other options incorrectly suggest immediate failure, expiration, or push notification delivery to offline devices. The correct behavior is to queue the command until the device checks in.

Exam trap

The trap here is assuming that remote actions require the device to be online at the moment of initiation, or that they expire after a certain time.

165
MCQeasy

You need to wipe a lost corporate-owned Windows 10 device that is enrolled in Intune. Which action should you take?

A.Delete the device from Intune.
B.Select the device and choose Wipe.
C.Select the device and choose Retire.
D.Reset the device using the Company Portal.
AnswerB

Correct. Wipe resets the device to factory settings.

Why this answer

The Wipe action in Intune restores a Windows 10 device to its factory default settings, removing all data and corporate access. This is the appropriate action for a lost corporate-owned device because it ensures sensitive data is erased while retaining the device's enrollment record for potential recovery or re-provisioning.

Exam trap

The trap here is confusing the Retire action (which only removes management and corporate data) with the Wipe action (which performs a full factory reset), leading candidates to choose Retire when a complete data erasure is required.

How to eliminate wrong answers

Option A is wrong because deleting the device from Intune only removes the device object from the console; it does not send a wipe command to the device, so data remains intact. Option C is wrong because Retire removes managed apps and policies but preserves personal data and does not perform a full factory reset, leaving corporate data potentially accessible. Option D is wrong because the Company Portal reset is a user-initiated action that requires the device to be physically accessible and logged in, which is not possible for a lost device.

166
Multi-Selecthard

Which TWO Windows Update for Business policies can you configure using Microsoft Intune?

Select 2 answers
A.Feature update version targeting
B.Quality update deferral period
C.Driver update deferral period
D.Windows Defender definition update schedule
E.Microsoft 365 Apps update channel
AnswersA, B

Correct. Feature update version targeting is a Windows Update for Business policy in Intune that allows you to specify a feature update version for devices to stay on.

Why this answer

Microsoft Intune allows you to configure a 'Feature update version targeting' policy, which specifies a target feature update version (e.g., Windows 11 23H2) for devices. Option B is correct because you can configure a 'Quality update deferral period' within an update ring policy to delay quality updates. Option C is incorrect because, although a driver update deferral period can be configured in an update ring policy, it is not a separate Windows Update for Business policy type; the question expects the two distinct policy types: Feature update version targeting and Quality update deferral period.

Option D is incorrect because Windows Defender definition update schedule is not a Windows Update for Business policy; it is managed via Microsoft Defender for Endpoint or other settings. Option E is incorrect because Microsoft 365 Apps update channel is not a Windows Update for Business policy; it is configured separately for Office applications.

Exam trap

The trap is that candidates often think only quality and feature update deferrals are configurable in Intune, overlooking that driver update deferral periods are also part of Windows Update for Business policies. This leads them to select only A and B, missing C.

167
MCQeasy

You are a Microsoft 365 Endpoint Administrator for a medium-sized company that uses Microsoft Intune to manage its Windows 10 devices. The company recently experienced a ransomware attack that encrypted local files on several devices. To mitigate future attacks, management wants to ensure that all devices have real-time protection enabled in Microsoft Defender Antivirus and that Controlled Folder Access is turned on. You need to configure these settings via Intune. You decide to create a device configuration profile for Windows 10. What is the most efficient way to deploy these settings to all existing and future devices?

A.Create a device configuration profile and assign it to a device group that includes all devices.
B.Use PowerShell scripts deployed via Intune to enable the settings on each device.
C.Create a device configuration profile and assign it to a user group that includes all users.
D.Create a compliance policy that requires these settings and assign it to all devices.
AnswerA

Assigning the device configuration profile to a device group containing all devices delivers the Defender Antivirus real-time protection and Controlled Folder Access settings to every existing and future member. This satisfies the stem's efficiency constraint, since new devices joining the group inherit the settings automatically.

Why this answer

A device configuration profile in Intune can include Microsoft Defender Antivirus settings (such as real-time protection and Controlled Folder Access) and is assigned to a device group. This ensures that both existing and future devices that join the group automatically receive the settings, providing a scalable and efficient deployment method without requiring user interaction or additional scripts.

Exam trap

The trap here is that candidates often confuse compliance policies with configuration profiles, thinking that compliance policies can enforce settings, when in reality they only evaluate and report on settings, requiring a separate configuration profile to actually apply the desired state.

How to eliminate wrong answers

Option B is wrong because PowerShell scripts deployed via Intune are executed on a per-device or per-user basis and require manual assignment or targeting; they do not provide the same declarative, policy-driven enforcement as a device configuration profile, and they cannot be as easily applied to future devices without ongoing script management. Option C is wrong because assigning the profile to a user group applies settings based on user identity, not device identity; if a user logs into a different device, the settings may not apply, and devices without a signed-in user (e.g., kiosks) would be missed. Option D is wrong because a compliance policy is designed to report or mark devices as non-compliant, not to enforce settings; it cannot enable real-time protection or Controlled Folder Access—it only checks if those settings are present and can trigger remediation actions only if configured with a corresponding device configuration profile.

168
MCQeasy

You are the endpoint administrator for a company using Microsoft Intune. The IT director asks you to generate a report that shows which Windows devices have not installed the latest security update in the past 14 days. What should you use?

A.Microsoft Intune Reports > Windows updates > Feature updates report.
B.Microsoft Intune Devices > Monitor > Noncompliant devices report.
C.Microsoft Intune Endpoint security > Windows updates report.
D.Microsoft Intune Reports > Windows updates > Windows quality updates report.
AnswerD

The Windows quality updates report shows the status of monthly security and quality updates across managed devices. It includes data on which devices have installed or are pending specific quality updates, and you can filter by update name and time. This report directly provides the information needed to identify devices missing recent security updates.

Why this answer

The Windows quality updates report in Intune provides detailed per-device status for monthly security and quality updates. It allows administrators to see which devices have not installed specific updates within a given timeframe, making it the correct tool for identifying devices missing recent security patches.

Exam trap

The trap here is assuming that the feature updates report covers all Windows updates, when in fact it only tracks annual feature updates, not monthly security patches.

169
Multi-Selectmedium

You are managing devices with Microsoft Intune. You need to ensure that only compliant devices can access corporate email. Which TWO components should you configure?

Select 2 answers
A.Device configuration profile
B.Compliance policy for Microsoft Intune
C.Device compliance policy
D.Conditional Access policy in Microsoft Entra ID
E.App protection policy
AnswersB, D

Correct - defines compliance rules that devices must meet to be considered compliant.

Why this answer

To ensure only compliant devices can access corporate email, you need a compliance policy (Option B) that defines device health rules and a Conditional Access policy (Option D) that enforces access based on compliance status. Option C is essentially the same concept as Option B and should not be selected as an additional component. Option A (device configuration profile) sets device settings but does not define compliance.

Option E (app protection policy) protects app data but does not evaluate device compliance.

Exam trap

The trap is that candidates may mistakenly include additional components such as configuration profiles or app protection policies, not realizing that only two components are necessary: Compliance Policy and Conditional Access.

170
MCQhard

You manage Windows 11 devices with Microsoft Intune. A line-of-business application must be deployed to a specific group of devices. The application installer requires administrative privileges and must run in the system context. You need to ensure the app installs silently without user interaction. What should you create?

A.A Win32 app with the install command configured to run with system privileges and a detection rule based on a file version.
B.An Office app deployment using the Microsoft 365 Apps configuration.
C.A Microsoft Store app (new) assigned as required to the device group.
D.A PowerShell platform script that runs once per device and invokes the installer.
AnswerA

Win32 apps in Intune run as the SYSTEM account by default on Windows devices, which satisfies the requirement for administrative privileges and system context. Configuring a detection rule based on file version lets Intune verify installation success and avoid reinstalling. The installer runs silently when the install command includes appropriate silent switches, meeting the no-user-interaction requirement.

Why this answer

Win32 apps in Intune are the appropriate deployment type for custom line-of-business installers that require administrative rights and system context. The Intune Management Extension runs the install command as SYSTEM, and detection rules determine whether the app is present. This provides silent installation, verification, and uninstall support that a platform script would not deliver.

Exam trap

The trap here is assuming that any deployment method capable of running elevated commands, such as a platform script, is a suitable substitute for a Win32 app.

171
MCQhard

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a custom configuration profile that sets a specific firewall rule. However, the profile fails to apply on a subset of devices. The Intune console shows 'Conflict' status. What is the most likely cause?

A.The user does not have a macOS license
B.The macOS version is not supported by the profile
C.Another profile with overlapping settings is assigned
D.The device is not connected to the internet
AnswerC

Overlapping settings from a second assigned profile cause Intune to report 'Conflict', because macOS configuration profiles cannot merge contradictory payload values — one payload wins and the other is rejected. Removing the duplicate firewall setting from one profile, or consolidating both into a single profile, resolves the conflict status.

Why this answer

The 'Conflict' status in Microsoft Intune indicates that two or more configuration profiles are attempting to apply different values to the same setting on the device. Since the question specifies a custom firewall rule, the most likely cause is that another profile (e.g., a built-in or custom profile) is also configuring firewall settings, creating a conflict. Intune cannot resolve overlapping settings, so it marks the profile as 'Conflict' and does not apply it.

Exam trap

The trap here is that candidates confuse 'Conflict' with 'Error' or 'Not applicable' — Microsoft Intune exams often test the specific Intune status codes, where 'Conflict' uniquely points to overlapping settings, not version or connectivity issues.

How to eliminate wrong answers

Option A is wrong because a missing macOS license would prevent enrollment or management entirely, not cause a specific 'Conflict' status on a profile. Option B is wrong because an unsupported macOS version would result in an 'Error' or 'Not applicable' status, not a 'Conflict' — Intune validates version compatibility before attempting to apply the profile. Option D is wrong because a device not connected to the internet would show a 'Pending' or 'Not evaluated' status, as Intune cannot communicate with the device to report a conflict.

172
MCQhard

You are the Intune administrator for Contoso Ltd., a company with 5,000 Windows 11 devices and 1,000 iOS devices managed by Microsoft Intune. The company uses Microsoft Defender for Endpoint for threat detection. You need to implement a solution that ensures devices are compliant before they can access corporate resources. You have the following requirements: 1. Windows devices must have Defender for Endpoint running and report a threat level of 'low' or better. 2. iOS devices must have a PIN of at least 6 characters and be jailbreak-detected as 'not jailbroken'. 3. If a device becomes noncompliant, it should be blocked immediately with no grace period. 4. Noncompliant devices should receive a notification to the user. You create compliance policies for Windows and iOS. You also create a conditional access policy in Microsoft Entra ID to require compliant devices. After deploying, you find that some Windows devices that are missing Defender for Endpoint are still able to access email. What should you do to resolve this issue?

A.Configure a notification to users when their device is noncompliant.
B.Modify the conditional access policy to require a compliant device and a specific client app.
C.Enable the 'Require Defender for Endpoint' setting in the Windows compliance policy.
D.Set the required threat level to 'medium' in the Windows compliance policy.
AnswerC

The Windows compliance policy must itself evaluate Defender for Endpoint status; without that setting, devices missing Defender still report compliant, so conditional access grants email access. Enabling 'Require Defender for Endpoint' makes the missing-agent state noncompliant, satisfying the requirement that Defender running be enforced.

Why this answer

The Windows compliance policy must explicitly have the 'Require Defender for Endpoint' setting enabled to enforce that the Defender for Endpoint sensor is present and active on the device. Without this setting, the compliance policy only checks the threat level reported by Defender for Endpoint but does not require the sensor to be installed or running. Enabling this setting ensures that devices missing the Defender for Endpoint sensor are marked as noncompliant, which then triggers the conditional access policy to block access to corporate resources like email.

Exam trap

The trap here is that candidates often assume that setting the required threat level to 'low' automatically enforces the presence of Defender for Endpoint, but in reality, the threat level check only evaluates the last reported threat score, not the sensor's installation or running state.

How to eliminate wrong answers

Option A is wrong because configuring a notification to users when their device is noncompliant does not enforce compliance or block access; it only informs the user after the device is already noncompliant. Option B is wrong because modifying the conditional access policy to require a specific client app does not address the missing Defender for Endpoint sensor; the conditional access policy already requires a compliant device, and the issue is that the compliance policy is not correctly evaluating the Defender for Endpoint requirement. Option D is wrong because setting the required threat level to 'medium' would allow devices with a threat level of 'medium' to be compliant, which is less restrictive than 'low' and does not solve the problem of devices missing Defender for Endpoint entirely.

173
MCQhard

Your organization uses Microsoft Defender for Endpoint. You need to configure automatic investigation and response for devices. Which setting in the Microsoft Defender XDR portal should you adjust?

A.Automated investigation and response
B.Threat analytics
C.Device inventory
D.Alert queue
AnswerA

Automated investigation and response in the Microsoft Defender XDR portal governs whether alerts trigger automatic investigation and remediation actions on devices. Enabling it there satisfies the requirement to configure automatic investigation and response for onboarded endpoints.

Why this answer

The correct setting is 'Automated investigation and response' because it directly controls the configuration of automatic investigation and response (AIR) capabilities in Microsoft Defender for Endpoint. This setting allows administrators to enable or disable automated investigations, set the automation level (e.g., full, semi, or no automation), and define remediation actions for devices. Without adjusting this setting, the automatic investigation and response workflow cannot be tailored to the organization's security requirements.

Exam trap

The trap here is that candidates often confuse the 'Automated investigation and response' configuration with the 'Alert queue' or 'Threat analytics' because they all appear under the same XDR portal section, but only the AIR setting directly manages the automation behavior for device-level response actions.

How to eliminate wrong answers

Option B is wrong because Threat Analytics is a feature that provides threat intelligence, vulnerability reports, and mitigation recommendations, but it does not configure the automatic investigation and response behavior for devices. Option C is wrong because Device Inventory is a list of all managed devices with their security status and configuration details, not a setting to enable or adjust automated response actions. Option D is wrong because Alert Queue is a view of security alerts generated by Defender for Endpoint, and while it allows manual triage of alerts, it does not control the automation level or response configuration for investigations.

174
MCQmedium

Your organization uses Microsoft Intune to manage 1,000 Windows 10 devices and 500 iOS devices. You need to enforce device compliance policies. For Windows devices, you require BitLocker encryption and Windows Defender Antivirus enabled. For iOS devices, you require a passcode of at least 6 characters and device encryption. Devices that become noncompliant should be marked as such and users should receive a notification email. After 7 days of noncompliance, the device should be blocked from accessing corporate email. You also need to create a report that shows the compliance status of all devices. Which combination of actions should you take?

A.Create Windows and iOS compliance policies with the required settings. Configure actions for noncompliance: send email immediately and block access after 7 days. Use the built-in compliance report.
B.Create app protection policies to require encryption and passcode. Use conditional access to block noncompliant devices.
C.Create device configuration profiles for BitLocker and encryption. Use conditional access to block noncompliant devices. Manually generate reports using PowerShell.
D.Use Autopilot to enforce encryption and passcode. Use Intune reporting for compliance status.
AnswerA

Separate Windows and iOS compliance policies apply platform-specific settings, while noncompliance actions send email immediately and block corporate email access after seven days. The built-in Intune compliance report satisfies the reporting requirement without custom tooling.

Why this answer

Intune compliance policies directly enforce device-level settings like BitLocker and passcode length, and they include built-in actions for noncompliance (e.g., send email, block access after a specified number of days). The built-in compliance report in the Intune portal provides an immediate view of all devices' compliance status without requiring manual scripting or additional tools.

Exam trap

Microsoft often tests the distinction between compliance policies (device-level enforcement with built-in actions) and app protection policies (data-level controls), leading candidates to confuse which policies can enforce BitLocker or trigger time-based blocking.

How to eliminate wrong answers

Option B is wrong because app protection policies (MAM) manage data-level security within apps, not device-level settings like BitLocker or device encryption; they cannot enforce BitLocker or Windows Defender Antivirus. Option C is wrong because device configuration profiles apply settings but do not include built-in actions for noncompliance (like sending email or blocking access after a delay); conditional access alone cannot trigger time-based actions, and manually generating reports with PowerShell is unnecessary when Intune provides a built-in compliance report. Option D is wrong because Autopilot is a deployment tool, not a compliance enforcement mechanism; it cannot enforce passcode length or device encryption on iOS, and Intune reporting is not limited to Autopilot.

175
Multi-Selectmedium

A company uses Microsoft Intune to manage iOS devices. They need to enforce a policy that requires a passcode of at least 6 characters, allows Touch ID, and automatically wipes the device after 10 failed attempts. Which three settings should be configured in a device restrictions profile for iOS? (Choose three.)

Select 3 answers
A.Number of failed attempts before wipe.
B.Maximum passcode age (days).
C.Minimum passcode length.
D.Allow simple passcode.
E.Allow Touch ID.
AnswersA, C, E

This triggers a wipe after 10 failed attempts.

Why this answer

The 'Number of failed attempts before wipe' setting directly enforces the requirement to automatically wipe the device after 10 failed passcode attempts. This setting is part of the device restrictions profile for iOS and triggers a device wipe when the specified threshold of consecutive incorrect passcode entries is reached.

Exam trap

The trap here is that candidates often confuse 'Maximum passcode age' with the wipe-on-failed-attempts setting, or mistakenly think 'Allow simple passcode' is required to enable Touch ID, when in fact Touch ID is a separate toggle that does not depend on simple passcode being allowed.

176
MCQeasy

You are the endpoint administrator for Contoso Ltd. The company uses Microsoft Intune to manage Windows 11 devices. You need to deploy a critical security update to all devices within 24 hours. The update is a quality update (KB5001234). You have created an update ring policy named 'Critical Ring' assigned to all devices. The policy currently has a deferral period of 7 days. You need to ensure that the update is installed immediately. What should you do?

A.Change the update ring policy deadline to 7 days to ensure devices have enough time.
B.Create a new feature update policy for KB5001234 and assign it to all devices.
C.Modify the 'Critical Ring' update ring policy to set the quality update deferral period to 0 days and the deadline for updates to 1 day.
D.Use the Windows Server Update Services (WSUS) console to approve the update for immediate installation.
AnswerC

Setting the quality update deferral to 0 days removes the seven-day hold, and a one-day deadline forces installation within the required 24-hour window. Both settings must change together; deferral alone would not guarantee the deadline is enforced on every device.

Why this answer

The update ring policy controls deferral and deadline. To install immediately, set deferral to 0 and deadline to 1 day. Creating a feature update policy is for feature updates, not quality updates.

Manually approving in WSUS is not relevant as Intune manages updates. Changing the deadline to 7 days would not meet the 24-hour requirement.

177
MCQmedium

A company uses Microsoft Intune to manage Windows devices. They want to deploy a custom line-of-business (LOB) app as a Win32 app. The app requires .NET Framework 4.8 and must be installed silently. Which file type should you use for the app deployment in Intune?

A..msi
B..appx
C..intunewin
D..exe
AnswerC

The .intunewin format is the packaged container produced by the Microsoft Win32 Content Prep Tool, which Intune requires to upload Win32 apps. It carries the silent install and uninstall commands plus detection rules, and prerequisite checks such as .NET Framework 4.8 are configured alongside it.

Why this answer

The .intunewin file is required for Win32 app deployment in Intune because it packages the installation files and detection rules into a single format that Intune can process. For a custom LOB app that needs silent installation and has dependencies like .NET Framework 4.8, the .intunewin wrapper allows you to specify the installation command (e.g., msiexec /i app.msi /qn) and detection logic, which is not possible with raw .msi or .exe files in the Win32 app context.

Exam trap

The trap here is that candidates mistakenly think a raw .exe or .msi can be deployed as a Win32 app in Intune, but Intune requires the .intunewin wrapper to handle detection, dependencies, and installation behavior for non-Store apps.

How to eliminate wrong answers

Option A is wrong because .msi files can be deployed directly as line-of-business apps in Intune, but they do not support the Win32 app deployment method's advanced features like custom detection rules, dependencies, or requirement rules; for a Win32 app, you must wrap the .msi in an .intunewin file. Option B is wrong because .appx files are used for Universal Windows Platform (UWP) apps, not Win32 apps, and they require a different deployment pipeline (e.g., Store or LOB app type). Option D is wrong because .exe files cannot be deployed directly as Win32 apps in Intune without being wrapped in an .intunewin file; the .intunewin packaging tool is required to encapsulate the .exe and its installation parameters.

178
MCQeasy

Your organization uses Microsoft Intune to manage devices. You need to configure a policy that automatically retires a device if it does not check in for 30 days. Which policy type should you configure?

A.Device configuration policy
B.Compliance policy
C.Windows Update for Business policy
D.Device health attestation policy
AnswerB

Compliance policies can include a grace period and action for non-compliance, including retiring devices after a specified period of inactivity.

Why this answer

A compliance policy in Microsoft Intune can include a 'Maximum days since device last checked in' setting. When a device fails to check in for the specified period (e.g., 30 days), Intune marks it as noncompliant, and a conditional access policy or automated action (such as retiring the device) can be triggered. This directly meets the requirement to automatically retire a device after 30 days of inactivity.

Exam trap

The trap here is that candidates often confuse a device configuration policy (which controls settings) with a compliance policy (which enforces conditions and triggers actions like retirement), leading them to select Option A instead of B.

How to eliminate wrong answers

Option A is wrong because a device configuration policy manages settings like passwords, encryption, and restrictions, but it does not include a check-in timeout or retirement trigger. Option C is wrong because a Windows Update for Business policy controls update deferrals and delivery optimization, not device check-in monitoring or retirement. Option D is wrong because a device health attestation policy verifies boot integrity and security features (e.g., Secure Boot, BitLocker) via the TPM, but it does not enforce a check-in interval or automatic retirement.

179
MCQmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. You configure a Conditional Access policy in Microsoft Entra ID targeting Exchange Online. What else must you configure in Intune to enforce compliance?

A.Device compliance policies.
B.No additional configuration is needed.
C.Device configuration policies.
D.App protection policies.
AnswerA

Conditional Access grants or blocks access based on compliance state, but that state is produced by Intune device compliance policies. Without a compliance policy defining the rules, devices have no evaluated status for the Conditional Access policy to act on.

Why this answer

A is correct because Conditional Access policies in Microsoft Entra ID evaluate device compliance status, but they rely on Intune to report that status. Without a device compliance policy assigned to the device, Intune cannot mark the device as compliant, so the Conditional Access policy will block access or treat the device as non-compliant. You must create and assign a compliance policy in Intune that defines the required security baselines (e.g., encryption, OS version, jailbreak detection) for the device to be considered compliant.

Exam trap

The trap here is that candidates assume Conditional Access policies are self-sufficient for compliance enforcement, overlooking that Intune compliance policies are the required mechanism to generate the compliance state that Conditional Access evaluates.

How to eliminate wrong answers

Option B is wrong because Conditional Access alone cannot enforce compliance; it only checks the compliance status reported by Intune, so additional configuration in Intune is mandatory. Option C is wrong because device configuration policies manage settings like Wi-Fi or VPN profiles, not compliance evaluation; they do not mark a device as compliant or non-compliant for Conditional Access. Option D is wrong because app protection policies (MAM) manage data protection at the app level without requiring device enrollment, but they do not make a device compliant for device-based Conditional Access policies targeting Exchange Online.

180
Multi-Selecthard

Which THREE conditions must be met for a Windows 10 device to be co-managed with Microsoft Intune and Microsoft Configuration Manager? (Choose three.)

Select 3 answers
A.The device must be enrolled in Microsoft Intune.
B.The device must have the Configuration Manager client installed.
C.The device must be Azure AD joined or hybrid Azure AD joined.
D.The device must be hybrid Azure AD joined.
E.The device must have the Intune Management Extension installed.
AnswersA, B, C

Co-management requires the device to be enrolled in Microsoft Intune, establishing the MDM authority alongside Configuration Manager's client agent. Without Intune enrolment, workloads cannot be shifted between the two services, so this condition directly satisfies the stem's requirement for simultaneous management by both tools.

Why this answer

Option A is correct because co-management requires the device to be enrolled in Microsoft Intune, which provides the MDM channel and enables the Intune workload authority alongside Configuration Manager. Option B is correct because the Configuration Manager client must be installed on the device so that the Configuration Manager channel and its workloads can function. Option C is correct because the device must be Azure AD joined or hybrid Azure AD joined to establish the identity and authentication needed for Intune enrollment and co-management.

Option D is not required because hybrid Azure AD join is only one of the acceptable identity states; Azure AD join alone also satisfies the requirement. Option E is not required because the Intune Management Extension is only needed for specific workloads such as PowerShell scripts and Win32 apps, not as a baseline condition for co-management.

Exam trap

The trap here is that candidates often think hybrid Azure AD join is mandatory (Option D), but Microsoft actually allows either Azure AD join or hybrid Azure AD join, and they confuse the Intune Management Extension (Option E) as a prerequisite when it is automatically installed post-enrollment for specific app deployment scenarios.

181
MCQmedium

You are implementing Windows Autopilot for your organization. You need to ensure that during the first boot, the device automatically enrolls in Microsoft Intune and joins Microsoft Entra ID. What is the minimum requirement for the device?

A.The device must have a local administrator account.
B.The device must be joined to an on-premises Active Directory domain.
C.The device must have a TPM 2.0 chip.
D.The device must be registered in Autopilot with a valid profile.
AnswerD

Autopilot requires the device hardware hash registered as an Autopilot device and assigned a deployment profile; without this, the Out-of-Box Experience cannot pull the Microsoft Entra ID join and Intune enrolment configuration, so registration plus a valid profile is the minimum.

Why this answer

Windows Autopilot requires the device to be registered in the Autopilot service with a valid profile assigned. This profile contains the settings that dictate the out-of-box experience (OOBE), including automatic enrollment into Microsoft Intune and joining Microsoft Entra ID (formerly Azure AD). Without a registered Autopilot profile, the device will not trigger the automated enrollment and join process during first boot.

Exam trap

The trap here is that candidates often confuse hardware prerequisites (like TPM 2.0) with the mandatory requirement of a registered Autopilot profile, leading them to select Option C instead of D.

How to eliminate wrong answers

Option A is wrong because a local administrator account is not a prerequisite for Autopilot; the device can be a standard user device and still enroll via Autopilot. Option B is wrong because Autopilot devices are designed to join Microsoft Entra ID directly, not an on-premises Active Directory domain; hybrid join is an optional configuration, not a minimum requirement. Option C is wrong because while TPM 2.0 is recommended for self-deploying mode and Windows Hello for Business, it is not a minimum requirement for user-driven Autopilot enrollment and Entra ID join; devices without TPM 2.0 can still use user-driven mode with password-based authentication.

182
MCQhard

You have assigned the compliance policy shown in the exhibit to all Windows devices. A Windows 11 device running build 10.0.22621.1500 reports as noncompliant. Which setting is causing the noncompliance?

A.OS version is above the maximum allowed
B.Password minimum length is not met
C.Device threat protection level is below medium
D.TPM is not present
AnswerA

The minimum OS version requirement exceeds build 10.0.22621.1500, so the device falls below the compliance threshold. Microsoft Entra ID marks it noncompliant because the assigned policy's minimum version constraint is unmet, not because of any maximum-version ceiling.

Why this answer

The compliance policy in the exhibit specifies a maximum OS version of 10.0.22621.1000, but the Windows 11 device is running build 10.0.22621.1500, which is above that maximum. Intune compares the device's OS version against the configured maximum OS version setting; if the device's version exceeds the maximum, it is marked as noncompliant. This setting is used to prevent devices with newer, potentially untested builds from accessing corporate resources.

Exam trap

The trap here is that candidates often assume noncompliance is due to missing security features like TPM or password policies, but the exhibit clearly shows a maximum OS version setting that the device's build exceeds, making it the direct cause.

How to eliminate wrong answers

Option B is wrong because the compliance policy does not include a password minimum length requirement, so the device cannot be noncompliant due to that setting. Option C is wrong because the policy does not configure a device threat protection level; the device threat protection setting is not present in the exhibit, so it cannot cause noncompliance. Option D is wrong because the policy does not require TPM presence; the TPM setting is not configured in the exhibit, so a missing TPM would not trigger noncompliance.

183
Multi-Selecthard

You manage a hybrid Azure AD joined environment with Microsoft Intune. You need to configure a Windows 10 device to receive Windows updates from Intune instead of from on-premises WSUS. The device is currently configured to use WSUS via Group Policy. Which TWO actions should you perform? (Choose two.)

Select 2 answers
A.Deploy a PowerShell script to modify the registry key HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU to point to Intune.
B.Enable the 'Microsoft Update' option in the Windows Update settings on each device.
C.Remove the WSUS Group Policy settings from the device.
D.Configure a conditional access policy to block WSUS traffic.
E.Enroll the device in Microsoft Intune and assign a Windows Update ring.
AnswersC, E

For Intune to manage Windows updates, the device must not be configured to use WSUS via Group Policy. Removing the WSUS settings ensures that the Windows Update client does not point to an on-premises server, allowing Intune update rings to take effect. This is a necessary step.

Why this answer

To transition from WSUS to Intune update management, you must remove the WSUS Group Policy settings that direct the device to the on-premises server, and then enroll the device in Intune and assign a Windows Update ring. These two actions ensure that Intune policies take precedence and manage update delivery.

Exam trap

The trap here is thinking that Intune can override existing WSUS Group Policy settings automatically, when in fact WSUS GPOs must be removed first for Intune update rings to apply.

← PreviousPage 3 of 3 · 183 questions total

Ready to test yourself?

Try a timed practice session using only Manage Maintain Devices questions.