Courseiva

CCNA Protect Devices Questions

75 of 88 questions · Page 1/2 · Protect Devices topic · Answers revealed

1
MCQeasy

You need to deploy a Microsoft 365 Apps for enterprise configuration to devices managed by Intune. Which policy type should you use?

A.Device configuration profile (settings catalog)
B.Managed apps policy
C.Windows update ring policy
D.Microsoft 365 Apps (Windows) configuration policy
AnswerD

Microsoft 365 Apps (Windows) configuration policies in Intune deploy and configure Office on Windows devices, letting you set update channels, remove previous installations, and choose specific apps. This directly satisfies the stem's requirement to deploy a Microsoft 365 Apps for enterprise configuration to Intune-managed devices, unlike settings catalog or compliance policies.

Why this answer

The Microsoft 365 Apps (Windows) configuration policy is the correct choice because it is specifically designed to manage the deployment, update settings, and configuration of Microsoft 365 Apps for enterprise on Intune-managed Windows devices. This policy type provides granular control over installation parameters, update channels, and app settings, directly aligning with the requirement to deploy a Microsoft 365 Apps configuration.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 Apps configuration policy with a device configuration profile or a managed apps policy, mistakenly thinking that general device policies can handle Office-specific deployment tasks, when in fact only the dedicated Microsoft 365 Apps policy provides the necessary ODT integration and update channel management.

How to eliminate wrong answers

Option A is wrong because a Device configuration profile (settings catalog) is used to configure device-level settings (e.g., security policies, registry keys) and cannot directly manage the installation or update configuration of Microsoft 365 Apps. Option B is wrong because a Managed apps policy applies to mobile application management (MAM) for protecting app data on devices not necessarily managed by Intune, and it does not handle deployment or configuration of Microsoft 365 Apps. Option C is wrong because a Windows update ring policy controls Windows OS update settings (e.g., deferral periods, feature updates) and has no capability to deploy or configure Microsoft 365 Apps for enterprise.

2
MCQmedium

Your organization uses Microsoft Entra ID joined devices and Microsoft Intune for mobile device management. A user reports that their device is not receiving compliance policies. The device shows as 'Compliant' in Intune but the Conditional Access policy still blocks access. What should you verify first?

A.Check if the compliance policy is assigned to the device's group.
B.Review the Conditional Access policy to ensure it requires compliant device.
C.Confirm the device is enrolled in Intune.
D.Verify the user is in the correct Azure AD group for Conditional Access.
AnswerB

Correct. The device shows as compliant but Conditional Access still blocks, suggesting the policy may not require compliant device. Reviewing the policy's conditions is the logical first step.

Why this answer

The device shows as 'Compliant' in Intune, indicating enrollment and policy assignment are not the issue. The Conditional Access policy may be misconfigured to require a different condition (e.g., hybrid Azure AD join) or may not be set to require compliant device. Reviewing the policy ensures it enforces the correct requirement.

Option A is incorrect because the device is already compliant, implying the policy is assigned. Option C is incorrect since the device is already enrolled (shown by compliance status). Option D is incorrect because group membership is irrelevant if the policy itself doesn't require a compliant device.

Exam trap

A common trap is assuming compliance status is sufficient for access, but Conditional Access policies have additional conditions (e.g., require compliant device, require hybrid join) that must be explicitly configured.

3
MCQmedium

Your organization uses Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy that automatically marks a device as noncompliant if it has not checked in with Intune for more than 30 days. Which compliance setting should you configure?

A.In the compliance policy, configure 'System Security' and set 'Require a password to unlock mobile devices' to 'Require'.
B.In the compliance policy, configure 'Device Health' and set 'Require BitLocker' to 'Require'.
C.In the compliance policy, set 'Compliance status validity period (days)' to 30.
D.In the compliance policy, set 'Mark devices with no compliance policy assigned as' to 'Not compliant'.
AnswerC

The compliance status validity period defines how long a device's last reported compliance state remains valid. When the device fails to check in within this period, Intune marks it noncompliant. Setting it to 30 days directly fulfills the requirement to flag devices that have not checked in for more than 30 days.

Why this answer

The compliance status validity period is the exact setting that determines how long a device's reported compliance state is trusted. When a device does not check in within that period, Intune automatically marks it noncompliant. Setting the validity period to 30 days ensures that any device silent for more than 30 days is flagged, matching the requirement precisely.

Exam trap

The trap here is confusing the setting that marks unassigned devices as noncompliant with the setting that expires stale compliance data.

4
MCQeasy

A company wants to prevent users from copying corporate data from managed Microsoft 365 apps to personal apps on iOS devices. What should they configure?

A.Intune app protection policy
B.Device compliance policy
C.Microsoft Defender for Cloud Apps session policy
D.Conditional Access policy
AnswerA

An Intune app protection policy applies MAM restrictions to managed Microsoft 365 apps, blocking cut, copy and paste of corporate content into personal apps on iOS without requiring device enrolment. This satisfies the requirement to prevent copying corporate data to personal apps.

Why this answer

Intune app protection policies (APP) are designed to manage and protect corporate data within applications, regardless of the device management state. By configuring data protection settings such as 'Allow app to transfer data to other apps' set to 'Policy managed apps only' and 'Save copies of org data' set to 'Block', you can prevent users from copying corporate data from managed Microsoft 365 apps to personal apps on iOS devices. This policy applies at the app layer, using the Intune App SDK or MAM (Mobile Application Management) channel, and does not require device enrollment.

Exam trap

The trap here is that candidates often confuse app protection policies (MAM) with device compliance or Conditional Access, mistakenly thinking that device-level controls can restrict app-to-app data transfer, when in fact only app-layer policies can enforce granular data protection like copy/paste restrictions.

How to eliminate wrong answers

Option B is wrong because device compliance policies evaluate device health and configuration (e.g., jailbreak detection, minimum OS version) but do not control data transfer between apps; they enforce compliance at the device level, not the app data layer. Option C is wrong because Microsoft Defender for Cloud Apps session policies control access and data exfiltration in real-time via reverse proxy for web apps (e.g., blocking downloads in a browser), but they do not apply to native mobile apps or control copy/paste between apps on iOS. Option D is wrong because Conditional Access policies enforce access controls (e.g., require compliant device, MFA) at sign-in, but they do not govern data movement or copy/paste behavior after authentication; they are an access gate, not a data protection mechanism.

5
MCQeasy

You need to wipe a lost corporate-owned iOS device that is enrolled in Intune. Which action should you perform?

A.Delete the device from Intune.
B.Retire the device.
C.Wipe the device.
D.Disable the device.
AnswerC

Wipe performs a full factory reset, removing all data and settings, which suits a lost corporate-owned device where data must not remain accessible. Retire would only remove corporate data, leaving personal content intact, so wipe is the appropriate action.

Why this answer

The correct action is to wipe the device because a corporate-owned iOS device that is lost requires a full factory reset to remove all data and prevent unauthorized access. In Microsoft Intune, the 'Wipe' action performs a factory reset, returning the device to its out-of-box state and removing all corporate and personal data, which is appropriate for a lost corporate-owned device.

Exam trap

The trap here is that candidates often confuse 'Retire' with 'Wipe', assuming both achieve the same result, but 'Retire' is designed for BYOD scenarios where personal data must be preserved, while 'Wipe' is required for corporate-owned devices that need complete data sanitization.

How to eliminate wrong answers

Option A is wrong because deleting the device from Intune only removes it from the management console without initiating any remote wipe or data removal, leaving the device fully functional with all data intact. Option B is wrong because retiring the device removes only managed apps and corporate data but preserves personal data, which is insufficient for a lost corporate-owned device that must be completely sanitized. Option D is wrong because disabling the device is not a supported Intune action for iOS devices; Intune offers 'Retire' and 'Wipe' actions, and 'Disable' is a generic term that does not correspond to any specific remote management command.

6
MCQmedium

Your organization uses Microsoft Intune to manage Windows 11 devices. The security team requires that BitLocker recovery keys be automatically escrowed to Microsoft Entra ID before a device is marked compliant. You need to configure a compliance policy setting that enforces this. Which setting should you configure?

A.Require Trusted Platform Module (TPM)
B.Require storage encryption
C.Require BitLocker recovery key backup
D.Require BitLocker
AnswerC

This setting explicitly verifies that the BitLocker recovery key has been backed up to Microsoft Entra ID. When enabled in a compliance policy, the device is marked non-compliant if the key is not escrowed. This directly enforces the security team's requirement that keys be escrowed before compliance is granted, ensuring recovery keys are available for administrative recovery.

Why this answer

The requirement is that BitLocker recovery keys are escrowed to Microsoft Entra ID before a device is compliant. The compliance policy setting 'Require BitLocker recovery key backup' specifically validates that the recovery key has been backed up to Microsoft Entra ID. Other BitLocker-related settings check for encryption or TPM presence but do not enforce escrow, so they would not satisfy the security team's condition.

Exam trap

The trap here is confusing general BitLocker enforcement with the specific recovery key escrow requirement, assuming that enabling 'Require BitLocker' automatically ensures key backup.

7
MCQmedium

You manage Windows 11 devices enrolled in Microsoft Intune. Security requires that devices with unsupported antivirus signatures be blocked from accessing Microsoft 365 resources. You create a compliance policy that sets the Microsoft Defender Antivirus requirement to 'Require' and the 'Antivirus signature age' to 3 days. A device reports an antivirus signature age of 5 days. What is the resulting device state?

A.The device is marked compliant but a remediation script is triggered.
B.The device is marked compliant because the signature age is not evaluated.
C.The device is marked noncompliant.
D.The device is marked noncompliant only if the user has not signed in for 30 days.
AnswerC

The compliance policy requires the antivirus signature age to be no more than 3 days. The device reports 5 days, which exceeds the threshold, so Intune evaluates the device as noncompliant. Conditional Access can then block access to Microsoft 365 resources. This is the expected behavior for a device that fails a compliance setting.

Why this answer

Compliance policies in Intune evaluate device settings such as antivirus signature age. When the signature age exceeds the configured value, the device is marked noncompliant. This status can be used by Conditional Access to block access to corporate resources.

The correct outcome is that the device is noncompliant because it fails the defined requirement.

Exam trap

The trap here is assuming that Intune only checks whether antivirus is enabled, not the signature age, leading to the incorrect belief that the device remains compliant.

8
MCQeasy

You need to ensure that only compliant devices can access Microsoft 365 resources. You create a Conditional Access policy in Microsoft Entra ID. Which condition should you use?

A.Locations condition set to trusted IPs.
B.Grant access with multi-factor authentication.
C.Require device to be marked as compliant.
D.Device platform condition set to all.
AnswerC

The grant control 'Require device to be marked as compliant' makes Microsoft Entra ID check Intune compliance state before issuing a token, blocking non-compliant devices from Microsoft 365. This directly enforces the stated constraint that only compliant devices gain access.

Why this answer

The question specifically asks to ensure that only compliant devices can access Microsoft 365 resources. In a Conditional Access policy, the 'Require device to be marked as compliant' grant control enforces that the device must be enrolled in Microsoft Intune and meet all compliance policies (e.g., encryption, OS version, threat level) before access is granted. This directly ties device health to resource access, which is the core requirement.

Exam trap

The trap here is that candidates often confuse 'device compliance' with 'device platform' or 'MFA', thinking that restricting by platform or adding MFA is sufficient to ensure device health, but neither checks the actual security posture of the device.

How to eliminate wrong answers

Option A is wrong because the 'Locations condition set to trusted IPs' controls access based on network location (e.g., corporate office), not device compliance; a non-compliant device from a trusted IP would still be allowed. Option B is wrong because 'Grant access with multi-factor authentication' verifies user identity via a second factor, but does not evaluate the device's compliance status; a compromised but MFA-authenticated device could still access resources. Option D is wrong because 'Device platform condition set to all' simply includes all operating systems (Windows, iOS, Android, etc.) in the policy scope, but does not enforce any compliance check; it is a condition, not a grant control.

9
MCQmedium

You are configuring a Microsoft Intune compliance policy for Windows 11 devices. You need to ensure that devices with BitLocker not enabled are marked noncompliant. Which setting should you configure in the compliance policy?

A.Require BitLocker
B.Require code integrity
C.Require Trusted Platform Module (TPM)
D.Require Secure Boot
AnswerA

The 'Require BitLocker' setting in a Windows compliance policy directly checks whether BitLocker Drive Encryption is enabled on the device. If BitLocker is not enabled, the device is marked noncompliant. This setting is specifically designed to enforce encryption at the device level, aligning with security requirements for data protection.

Why this answer

To enforce BitLocker encryption, the compliance policy must include the 'Require BitLocker' setting. This setting directly evaluates whether BitLocker is enabled on the device. Other security settings like Secure Boot or TPM presence do not confirm BitLocker status.

Therefore, configuring 'Require BitLocker' ensures devices without encryption are marked noncompliant.

Exam trap

The trap here is confusing BitLocker enforcement with other security settings like Secure Boot or TPM, which are related but do not directly check for BitLocker encryption.

10
MCQeasy

An IT administrator needs to ensure that iOS devices enrolled in Intune require a PIN of at least 6 digits. Where should the administrator configure this setting?

A.App protection policy
B.Device compliance policy for iOS
C.Conditional Access policy
D.Enrollment restrictions
AnswerB

A device compliance policy for iOS defines the minimum PIN length requirement, enforcing a six-digit passcode as a condition of compliance. Device restrictions profiles control features, not passcode length, so compliance is the correct location.

Why this answer

Device compliance policies in Intune define the rules and settings that devices must meet to be considered compliant, including password requirements such as minimum PIN length. For iOS devices, the compliance policy includes settings for passcode complexity and length. App protection policies apply to apps, not device-wide settings; Conditional Access policies enforce access based on compliance but do not define the PIN requirement; Enrollment restrictions control which devices can enroll, not security settings.

Exam trap

MD-102 often tests the difference between device compliance policies (device-wide settings) and app protection policies (app-level settings), so candidates may incorrectly choose app protection policy for device PIN requirements.

How to eliminate wrong answers

Option A is wrong because app protection policies apply to specific apps (e.g., Outlook) and can enforce PIN for app access, but they do not enforce a device-wide PIN requirement for iOS devices. Option C is wrong because Conditional Access policies use compliance status to grant or deny access, but they do not configure the PIN requirement itself. Option D is wrong because enrollment restrictions determine which devices are allowed to enroll (e.g., by platform or OS version), not security settings like PIN length.

11
MCQhard

Your organization uses Microsoft Defender for Cloud Apps. You need to configure a policy that automatically blocks downloads of sensitive data from SharePoint Online to unmanaged devices. Which policy type should you use?

A.Activity policy
B.App discovery policy
C.Access policy
D.Session policy
AnswerD

A session policy in Defender for Cloud Apps applies Conditional Access App Control, proxying the SharePoint Online session so downloads to unmanaged devices can be blocked in real time. Access policies only evaluate sign-in conditions, so they cannot intercept an in-session download action.

Why this answer

Session policies in Microsoft Defender for Cloud Apps allow real-time monitoring and control of user activities based on app and device context. By configuring a session policy with the condition 'Device tag equals Unmanaged' and the control 'Block download', you can automatically block downloads of sensitive data from SharePoint Online to unmanaged devices, leveraging reverse proxy architecture to inspect and intercept traffic.

Exam trap

The trap here is confusing Access policies (which control sign-in and token issuance) with Session policies (which control in-session actions like downloads), leading candidates to incorrectly choose Access policy when the question explicitly requires blocking a specific file operation on unmanaged devices.

How to eliminate wrong answers

Option A is wrong because Activity policies are used for post-event detection and alerting on specific user activities (e.g., multiple failed logins), not for real-time blocking of downloads based on device compliance. Option B is wrong because App discovery policies analyze cloud app usage and shadow IT, not control data exfiltration from managed apps like SharePoint Online. Option C is wrong because Access policies control authentication and access (e.g., requiring MFA or blocking sign-in) but do not provide granular, session-level controls like blocking file downloads within an already authenticated session.

12
MCQhard

You have a Microsoft 365 subscription that includes Microsoft Intune. You have 100 Windows 11 devices enrolled in Intune. You need to ensure that BitLocker recovery keys are automatically escrowed to Microsoft Entra ID when BitLocker is enabled. What should you configure?

A.An Endpoint protection profile with 'BitLocker' settings configured to save recovery information to Microsoft Entra ID
B.A device configuration profile with the 'Encrypt devices' setting set to 'Require'
C.A compliance policy that requires BitLocker and marks devices without escrowed keys as non-compliant
D.A PowerShell script deployed via Intune that runs 'manage-bde -protectors -adbackup'
AnswerA

In Intune, the Endpoint protection profile includes BitLocker settings where you can specify 'Save BitLocker recovery information to Microsoft Entra ID' and choose to store recovery keys. This directly ensures automatic escrow of recovery keys to Microsoft Entra ID, meeting the requirement without additional scripts.

Why this answer

The Endpoint protection profile in Intune provides native BitLocker settings, including the option to save recovery information to Microsoft Entra ID. Enabling this setting ensures that when BitLocker is activated, the recovery key is automatically escrowed to Entra ID, allowing administrators to retrieve it if needed. This is the most direct and supported method.

Exam trap

The trap here is assuming that a compliance policy or a simple encryption requirement will automatically escrow keys, when escrow requires explicit configuration in the BitLocker settings.

13
Multi-Selectmedium

An Intune administrator needs to ensure that Windows 10 devices are compliant with security requirements. Which TWO options are valid compliance settings for Windows 10?

Select 2 answers
A.Device category must be 'Corporate'
B.Device enrollment type must be 'Corporate'
C.Require BitLocker
D.Minimum OS version
E.Require app protection policy
AnswersC, D

Requiring BitLocker is a valid Windows 10 compliance setting in Intune, enforcing full-disk encryption via the device encryption policy. It directly satisfies the stem's security requirement by verifying drive encryption status, and is configurable under Device Compliance > Windows 10/11 compliance policy alongside firewall and antivirus settings.

Why this answer

Option C (Require BitLocker) is correct because BitLocker drive encryption is a native Windows 10 compliance setting in Intune under Device Health, allowing the admin to require that encryption is enabled on the device. Option D (Minimum OS version) is correct because Intune's Device Properties compliance settings for Windows 10 let you specify a minimum OS version (for example, 10.0.19041.0) that devices must meet to be marked compliant. Option A is not a compliance setting; device category is an attribute used for grouping and reporting, not a compliance rule.

Option B is not valid because enrollment type is not a configurable compliance condition in Intune. Option E is not a Windows 10 device compliance setting; app protection policies are separate MAM policies applied to apps, not device compliance rules.

Exam trap

The trap here is that candidates confuse device-level compliance settings (like OS version and BitLocker) with enrollment properties (device category, enrollment type) or app-level policies (app protection policy), which are managed in different policy types within Intune.

14
MCQhard

Your organization uses Windows Autopilot for device deployment. After a device completes the user-driven deployment, it appears in Microsoft Entra ID as 'Azure AD registered' instead of 'Azure AD joined'. What should you modify to ensure the device is joined?

A.Modify the Autopilot deployment profile to set 'Join to Azure AD as' to 'Azure AD joined'.
B.Add the device to a hybrid Azure AD join profile.
C.Modify the Autopilot deployment profile to set 'Join to Azure AD as' to 'Azure AD registered'.
D.Modify the enrollment restrictions to block personally owned devices.
AnswerA

The Autopilot deployment profile's 'Join to Azure AD as' setting controls whether the device performs a Microsoft Entra join or a work account registration; setting it to 'Azure AD joined' produces the required join type.

Why this answer

The Autopilot deployment profile includes a setting called 'Join to Azure AD as' that determines whether the device performs an Azure AD join or an Azure AD registration. By default, this setting may be configured as 'Azure AD registered', which results in a device that is only registered (workplace-joined) rather than fully joined. Changing this setting to 'Azure AD joined' ensures the device completes a full Azure AD join during the user-driven deployment, making it a managed device in Microsoft Entra ID.

Exam trap

The trap here is that candidates often confuse 'Azure AD registered' with 'Azure AD joined' because both involve Azure AD, but they fail to recognize that the Autopilot profile's join type setting directly controls this distinction, and that enrollment restrictions or hybrid join profiles are unrelated to changing the join type for a cloud-native Autopilot deployment.

How to eliminate wrong answers

Option B is wrong because a hybrid Azure AD join profile is used for devices that need to be joined to both on-premises Active Directory and Azure AD, typically requiring connectivity to a domain controller and synchronization via Azure AD Connect; this does not apply to a pure cloud-native Autopilot scenario where the device should be directly Azure AD joined. Option C is wrong because setting 'Join to Azure AD as' to 'Azure AD registered' would explicitly configure the device to be registered (workplace-joined) rather than joined, which is the opposite of what is needed to fix the issue. Option D is wrong because enrollment restrictions control which devices are allowed to enroll based on platform or ownership type (e.g., blocking personally owned devices), but they do not change the join type from registered to joined; the device would still be registered if the profile specifies registration.

15
MCQhard

You are troubleshooting a Windows 10 device that is showing as non-compliant in Intune. The exhibit shows the PowerShell output from the Microsoft Graph API. Based on the output, what is the most likely reason for the non-compliance?

A.The device does not have a compliant operating system version
B.BitLocker drive encryption is not enabled on the device
C.The device is not running a supported version of Windows 10
D.The device has a third-party antivirus installed
AnswerB

The Graph API output lists the compliance setting storageRequireEncryption as failing, which maps directly to BitLocker. Since the device reports non-compliant and this is the only failing rule shown, BitLocker encryption is not enabled, so Intune flags the device.

Why this answer

The output shows the non-compliance reason is 'RequireEncryption', indicating BitLocker is not enabled. Option A is incorrect because the reason is about encryption, not operating system version. Option C is incorrect because the reason is about encryption, not the Windows version.

Option D is incorrect because the reason is about encryption, not antivirus.

16
MCQeasy

You manage devices with Microsoft Intune. You need to deploy a Windows 10 feature update to a pilot group of devices. Which profile type should you use?

A.Windows 10 configuration profile
B.Windows 10 compliance policy
C.Windows 10 update ring profile
D.Windows 10 feature update profile
AnswerD

A Windows 10 feature update profile in Intune deploys a specific Windows feature update version to targeted devices, letting you scope it to the pilot group. Other profile types handle configuration, compliance, or quality updates, not feature-version upgrades.

Why this answer

A Windows 10 feature update profile is the correct choice because it is specifically designed to deploy feature updates (e.g., Windows 10 version 22H2) to targeted groups in Intune. Unlike update rings, which control the timing and deferral of updates, a feature update profile pins devices to a specific Windows version and orchestrates the upgrade process for pilot or broad deployments.

Exam trap

The trap here is that candidates often confuse update ring profiles (which manage update timing) with feature update profiles (which deploy a specific version), leading them to incorrectly select option C.

How to eliminate wrong answers

Option A is wrong because a Windows 10 configuration profile is used to configure device settings (e.g., security policies, browser settings) and cannot deploy feature updates. Option B is wrong because a Windows 10 compliance policy evaluates device compliance against rules (e.g., required OS version) but does not initiate or manage the deployment of feature updates. Option C is wrong because a Windows 10 update ring profile controls the deferral, pause, and rollout of quality updates and feature updates via Windows Update for Business, but it does not pin devices to a specific feature update version; it only manages update behavior and timing.

17
MCQhard

You use Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy that automatically marks devices as noncompliant if they do not have a specific antivirus signature version installed. The signature version is updated daily. Which compliance setting should you configure?

A.Require the device to have an active firewall.
B.Require the device to be at or under the machine risk score.
C.Require the device to have a minimum OS version.
D.Require the device to have up-to-date security intelligence.
AnswerD

The 'Require the device to have up-to-date security intelligence' setting in a Windows compliance policy checks whether the Microsoft Defender antivirus security intelligence (signature) version is current. You can configure the maximum number of days allowed since the last update. This directly enforces that devices have recent signatures, aligning with the daily update requirement.

Why this answer

The compliance setting 'Require the device to have up-to-date security intelligence' allows you to specify how many days old the antivirus signatures can be. By setting this to one day, you ensure that devices with signatures older than one day are marked noncompliant. This is the only setting among the options that directly evaluates the security intelligence version, making it the correct choice.

Exam trap

The trap here is confusing machine risk score with signature version; machine risk score uses threat intelligence from Defender for Endpoint, not the age of antivirus definitions.

18
MCQeasy

A user reports that their Windows 11 device is not receiving compliance policies from Microsoft Intune. The device shows as 'Not evaluated' in the Microsoft Intune admin center. Which step should you take first to resolve the issue?

A.Disconnect the device from Microsoft Entra ID and rejoin.
B.On the device, go to Settings > Accounts > Access work or school, select the account, and click Sync.
C.Delete and recreate the compliance policy in Microsoft Intune.
D.Re-enroll the device in Microsoft Intune.
AnswerB

A 'Not evaluated' status typically means the device has not checked in with the Intune service. Manually triggering a sync from Settings > Accounts > Access work or school forces the MDM enrolment to contact Intune, prompting policy evaluation before investigating deeper causes.

Why this answer

When a Windows 11 device shows 'Not evaluated' in Intune, it usually means the MDM enrollment is intact but the device hasn't checked in with the Intune service recently. Manually triggering a sync from Settings > Accounts > Access work or school forces the MDM client to pull the latest compliance policies immediately, which is the least disruptive first step.

Exam trap

MD-102 often tests the instinct to jump to re-enrollment or policy recreation when the real fix is a simple device sync — candidates overlook the manual sync option under Access work or school.

How to eliminate wrong answers

Option A is wrong because disconnecting from Entra ID and rejoining is a drastic action that would break the existing enrollment and require re-registration, not a first troubleshooting step. Option C is wrong because recreating the compliance policy does nothing if the device simply hasn't synced — the policy itself is likely fine. Option D is wrong because re-enrolling the device is a last-resort action that wipes the MDM state and is unnecessary when a simple sync may resolve the issue.

19
MCQmedium

You manage 500 Windows 11 devices with Microsoft Intune. A security policy requires that all devices run Microsoft Defender Antivirus with real-time protection enabled. You configure a Windows 10 and later antivirus policy in Intune and assign it to all devices. Several devices report that real-time protection is disabled. You need to ensure that real-time protection cannot be disabled by local administrators. What should you do?

A.Enable tamper protection in the Microsoft Defender for Endpoint security baseline or via a configuration profile.
B.Deploy a PowerShell script that runs at startup to enable real-time protection.
C.Create a compliance policy that requires real-time protection to be enabled.
D.Configure the 'Allow real-time protection' setting to 'Enabled' in the antivirus policy.
AnswerA

Tamper protection prevents users, including local administrators, from disabling real-time protection and other Defender Antivirus features. In Intune, you can enable tamper protection through the Defender for Endpoint security baseline or a custom configuration profile. Once enabled, the setting cannot be turned off locally, ensuring real-time protection remains active.

Why this answer

Tamper protection is the only feature that prevents local administrators from disabling real-time protection and other Defender Antivirus settings. While other methods can enable the setting, they cannot lock it. Enabling tamper protection via the Defender for Endpoint baseline or a configuration profile ensures the setting remains enforced and cannot be overridden on the device.

Exam trap

The trap here is assuming that setting 'Allow real-time protection' to Enabled will prevent users from turning it off, when it only makes the feature available.

20
MCQeasy

You need to ensure that devices enrolled in Microsoft Intune automatically receive Windows quality updates as soon as they are released. Which update ring setting should you configure?

A.Set 'Driver update deferral period (days)' to 0
B.Set 'Quality update deferral period (days)' to 0
C.Set 'Feature update deferral period (days)' to 0
D.Set 'Microsoft product updates' to 'Allow'
AnswerB

A quality update deferral of 0 days means devices receive quality updates immediately upon release, with no postponement. This directly satisfies the requirement for automatic, as-soon-as-released delivery through the Windows update ring in Microsoft Intune.

Why this answer

In Intune Windows update rings, the 'Quality update deferral period (days)' setting controls how long quality updates (security and reliability fixes) are deferred after release. Setting it to 0 means devices receive quality updates as soon as they are released, satisfying the requirement.

Exam trap

The trap is confusing quality updates with feature updates or driver updates — candidates often pick feature update deferral when the question asks about monthly security patches.

How to eliminate wrong answers

Option A is wrong because driver update deferral only affects driver updates, not Windows quality updates. Option C is wrong because feature update deferral controls Windows version upgrades (e.g., 21H2 to 22H2), not monthly quality updates. Option D is wrong because 'Microsoft product updates' allows updates for other Microsoft products (like Office), not Windows quality updates.

21
MCQeasy

You are reviewing a custom device configuration profile in Intune. The exhibit shows an OMA-URI setting. What is the purpose of this setting?

A.Enables the camera on the lock screen
B.Disables the camera on the device entirely
C.Disables the microphone on the lock screen
D.Disables the camera on the lock screen
AnswerD

This OMA-URI policy configures the AllowCamera policy under the Personalisation CSP, setting it to block camera access specifically from the lock screen. It satisfies the requirement to restrict lock-screen camera use without disabling the camera entirely elsewhere on the device.

Why this answer

The OMA-URI setting ./Vendor/MSFT/Policy/Config/DeviceLock/PreventLockScreenCamera is used to disable the camera on the Windows lock screen. This policy prevents users from accessing the camera while the device is locked, enhancing security by mitigating privacy risks such as unauthorized camera use. It does not affect camera functionality once the user logs in.

Exam trap

The trap here is that candidates often confuse 'disable camera on lock screen' with 'disable camera entirely' (Option B), but the OMA-URI explicitly targets the lock screen only, not the full device camera functionality.

How to eliminate wrong answers

Option A is wrong because the setting specifically disables the camera on the lock screen, not enables it; enabling would require a different policy value or OMA-URI path. Option B is wrong because this policy only restricts camera access on the lock screen, not the entire device; to disable the camera entirely, you would use a different policy such as AllowCamera under Device/Experience. Option C is wrong because this OMA-URI targets the camera, not the microphone; disabling the microphone on the lock screen would involve a separate policy like PreventLockScreenMicrophone.

22
MCQmedium

A company uses Intune to manage macOS devices. They need to deploy a custom configuration profile that enforces FileVault encryption. What is the recommended approach?

A.Create an endpoint security disk encryption policy in Intune and assign it to the devices
B.Use Apple Configurator to create the profile and import it into Intune
C.Ask users to manually enable FileVault
D.Use JAMF Pro to manage FileVault
AnswerA

The endpoint security disk encryption policy is the built-in Intune workload for FileVault, applying the required encryption settings to macOS devices without a custom profile. This satisfies the scenario's need to enforce FileVault through a supported policy type.

Why this answer

Intune provides a built-in endpoint security disk encryption policy for macOS that enforces FileVault encryption. This is the recommended approach because it integrates natively with Intune, allows assignment to device groups, and reports compliance status without requiring third-party tools or manual user action.

Exam trap

MD-102 often tests the preference for native Intune policies over third-party tools or manual methods — candidates may overcomplicate by choosing Apple Configurator or JAMF Pro when Intune has a built-in solution.

How to eliminate wrong answers

Option B is wrong because while Apple Configurator can create custom profiles, importing them into Intune is not the recommended approach for FileVault when a native Intune policy exists; it adds unnecessary complexity. Option C is wrong because asking users to manually enable FileVault is not a managed, enforceable solution and defeats the purpose of MDM. Option D is wrong because JAMF Pro is a third-party tool; while it can manage FileVault, the question specifies Intune as the management tool, so using JAMF Pro is out of scope.

23
MCQeasy

You need to enroll a Windows 11 device into Microsoft Intune using a work or school account. The device is already joined to Microsoft Entra ID. What is the simplest enrollment method?

A.Windows Autopilot
B.Group Policy to configure enrollment
C.Manual enrollment using the Company Portal
D.Automatic enrollment via Microsoft Entra join
AnswerD

Microsoft Entra join with automatic MDM enrolment configured in Intune silently enrols the device using the signed-in work or school account, requiring no user action. This is the simplest method for the already-joined Windows 11 device in the stem.

Why this answer

When a Windows 11 device is already Microsoft Entra joined, the simplest enrollment path is automatic MDM enrollment via the Entra join process. During the Entra join, if the user's license includes Intune and the MDM user scope is configured in the Entra ID Mobility settings, the device is automatically enrolled into Intune without any additional user action. This is the least-effort method because it requires no additional configuration on the device itself.

Exam trap

MD-102 often tests the distinction between Autopilot (provisioning new devices) and automatic enrollment (enrolling existing Entra-joined devices), causing candidates to pick Autopilot for any enrollment scenario.

How to eliminate wrong answers

Option A is wrong because Windows Autopilot is used for provisioning new or reset devices out-of-box, not for enrolling an already Entra-joined device. Option B is wrong because Group Policy-based enrollment is a legacy method for hybrid Azure AD joined devices and requires on-premises AD infrastructure, not the simplest path for a cloud-joined device. Option C is wrong because manual enrollment via Company Portal requires the user to install the app and sign in, which is more steps than automatic enrollment.

24
MCQhard

You review the compliance policy JSON for Windows 10 devices. A device running Windows 10 version 22H2 (build 22621.0) with a numeric-only password of 10 characters, BitLocker enabled, firewall enabled, and Microsoft Defender running reports as non-compliant. What is the most likely reason?

A.The password type is not alphanumeric.
B.The OS version is outside the allowed range.
C.Storage encryption is not enabled.
D.Microsoft Defender is not enabled.
AnswerA

A numeric-only password fails the alphanumeric password requirement, so the device reports non-compliant despite meeting the other conditions. Compliance policies in Microsoft Entra ID evaluate password complexity independently of length, meaning a 10-character PIN-style password satisfies length but not the required character-type constraint.

Why this answer

The compliance policy JSON for Windows 10 devices specifies a password type requirement of 'alphanumeric'. The device in question uses a numeric-only password (10 characters), which does not meet the alphanumeric requirement, causing it to be reported as non-compliant. All other conditions—BitLocker enabled, firewall enabled, and Microsoft Defender running—are satisfied, so the password type is the sole issue.

Exam trap

The trap here is that candidates often assume a long numeric password (10 characters) meets complexity requirements, but the policy explicitly requires alphanumeric characters, and the exam tests attention to the specific JSON setting rather than general password strength.

How to eliminate wrong answers

Option B is wrong because the OS version (Windows 10 version 22H2, build 22621.0) is within the allowed range; the compliance policy typically specifies a minimum OS version, and 22H2 is a supported build. Option C is wrong because storage encryption is enabled via BitLocker, which satisfies the encryption requirement. Option D is wrong because Microsoft Defender is explicitly stated as running, so it is enabled and compliant.

25
MCQeasy

You need to ensure that only authorized users can enroll devices in Microsoft Intune. Which setting should you configure?

A.Enrollment restrictions
B.Device categories
C.Device compliance policies
D.Conditional access policies
AnswerA

Enrollment restrictions control which users may enrol devices and which platforms or device types they can register, directly satisfying the requirement that only authorised users enrol in Microsoft Intune. Configuring a device-type or platform restriction, plus assigning it to a group, blocks unauthorised accounts at enrolment rather than relying on post-enrolment compliance.

Why this answer

Enrollment restrictions in Microsoft Intune let administrators control which users and devices are permitted to enroll, including platform, OS version, device type, and user/group targeting. By scoping enrollment to authorized groups or blocking personal devices, only approved users can complete MDM enrollment. This is the native control designed specifically to gate Intune enrollment.

Exam trap

MD-102 often tests the distinction between controls that gate enrollment (enrollment restrictions) versus controls that evaluate enrolled devices (compliance policies) or gate resource access (conditional access), so candidates pick a policy that sounds security-related but does not actually block enrollment.

How to eliminate wrong answers

Option B is wrong because device categories are metadata tags assigned to enrolled devices for reporting and policy targeting, not an enrollment gate. Option C is wrong because compliance policies evaluate already-enrolled devices against security baselines and mark them compliant/non-compliant; they do not prevent enrollment. Option D is wrong because conditional access policies control access to cloud resources based on device state, not whether a device can enroll in Intune.

26
MCQmedium

You have a hybrid Microsoft Entra ID joined Windows 10 device that is co-managed with Configuration Manager and Intune. You want Intune to manage Windows Update for Business settings. Which slider setting should you configure in Configuration Manager?

A.Move the slider for 'Windows Update policies' to 'Intune'
B.Move the slider for 'Endpoint protection' to 'Intune'
C.Move the slider for 'Resource access' to 'Intune'
D.Move the slider for 'Device configuration' to 'Intune'
AnswerA

Shifting the Windows Update policies workload slider to Intune transfers authority for Windows Update for Business settings to Microsoft Entra ID-based MDM, satisfying the requirement that Intune manage them. Configuration Manager retains the remaining co-management workloads, so update policy delivery no longer depends on the Configuration Manager client.

Why this answer

In a co-management scenario, workload sliders in Configuration Manager determine which authority manages specific workloads. To have Intune manage Windows Update for Business settings, you must move the slider for 'Windows Update policies' to Intune. This shifts the policy authority from Configuration Manager to Intune, allowing Intune's Update Rings and feature update policies to control Windows Update behavior on the device.

Exam trap

The trap here is that candidates often confuse 'Windows Update policies' with 'Device configuration' or 'Endpoint protection', assuming that update settings fall under a broader configuration or security category, but Microsoft specifically separates update management into its own workload slider.

How to eliminate wrong answers

Option B is wrong because 'Endpoint protection' controls antivirus, firewall, and Defender policies, not Windows Update settings. Option C is wrong because 'Resource access' manages VPN, Wi-Fi, email, and certificate profiles, which are unrelated to update policies. Option D is wrong because 'Device configuration' handles device restriction and configuration profiles, not Windows Update for Business policies.

27
MCQeasy

You are deploying Microsoft Defender for Endpoint to 200 Windows 10 devices managed by Microsoft Intune. You want to onboard the devices to Defender for Endpoint using the least administrative effort. What should you do?

A.Create a configuration profile with the Defender for Endpoint onboarding blob and assign it to the devices.
B.Deploy a PowerShell script that runs the onboarding script on each device.
C.Use the Microsoft Defender for Endpoint connector in Intune to onboard the devices.
D.Manually install the Defender for Endpoint agent on each device.
AnswerC

The Microsoft Defender for Endpoint connector in Intune allows you to onboard devices with minimal effort. You simply enable the connector, and Intune automatically deploys the onboarding configuration to all targeted devices. This method is the most efficient and reduces manual steps, making it ideal for large-scale deployments.

Why this answer

The Microsoft Defender for Endpoint connector in Intune is designed to simplify onboarding. When enabled, it automatically deploys the onboarding package to all Intune-managed Windows devices. This eliminates the need for manual configuration or scripting, providing the least administrative effort and ensuring consistent deployment across the organization.

Exam trap

The trap here is overlooking the built-in connector and instead opting for manual or script-based methods, which require more effort and do not leverage Intune's automation.

28
MCQmedium

Your organization, Fabrikam, uses Microsoft Intune to manage iOS/iPadOS and Android devices. You need to implement a solution that ensures company email can only be accessed from the Outlook mobile app, and that data from the Outlook app cannot be copied to personal apps. You also need to ensure that when a user leaves the company, the corporate data in Outlook is removed without affecting personal data. You plan to use app protection policies (MAM). The devices are not enrolled in Intune (unmanaged). You configure the app protection policies for Outlook on iOS and Android. However, users report that they can still copy email content to personal apps. What should you check?

A.Ensure that the devices are enrolled in Intune.
B.Check that the device compliance policy is assigned.
C.Verify that the 'Cut, copy, and paste' setting in the app protection policy is set to 'No' or 'Policy managed apps'.
D.Confirm that the Outlook app is a managed app in Intune.
AnswerC

Data transfer between apps is governed by the 'Cut, copy, and paste' restriction, which must be set to 'No' or 'Policy managed apps' to block copying into personal apps. Verifying this setting addresses the reported leak.

Why this answer

The 'Cut, copy, and paste' setting in the app protection policy controls data transfer between apps. To prevent copying email content to personal apps, this setting must be set to 'No' or 'Policy managed apps'. Option A is incorrect because device enrollment is not required for MAM policies on unmanaged devices.

Option B is incorrect because device compliance policies are not applicable without enrollment. Option D is incorrect because Outlook is already a managed app; the issue is the policy setting.

29
MCQmedium

Refer to the exhibit. You run a PowerShell command to check the assignment status of device configuration profiles. The 'BitLocker Policy' shows 'Pending'. What does 'Pending' indicate?

A.The policy is waiting for user approval
B.The policy assignment failed due to a conflict
C.The policy has been successfully applied
D.The policy has been assigned to the device but not yet applied
AnswerD

A pending status means the configuration profile is targeted at the device through its Microsoft Entra ID group assignment, but the device has not yet downloaded and processed it. This satisfies the scenario's requirement to interpret assignment status, distinguishing delivery from actual application of the BitLocker settings.

Why this answer

In Microsoft Intune, when a device configuration profile shows a status of 'Pending', it means the policy has been successfully assigned to the device in the cloud but has not yet been applied or reported back as compliant. This is a normal transitional state that occurs while the device checks in with the Intune service, downloads the policy, and applies it during the next sync cycle. The 'Pending' status does not indicate failure, conflict, or user approval requirements.

Exam trap

The trap here is that candidates often confuse 'Pending' with a failure or conflict, when in fact it is a normal intermediate state that resolves automatically after the device syncs with Intune.

How to eliminate wrong answers

Option A is wrong because 'Pending' does not require user approval; user approval is only relevant for specific scenarios like enrollment or app installation prompts, not for device configuration profiles. Option B is wrong because a policy conflict would typically result in a 'Conflict' or 'Error' status, not 'Pending'. Option C is wrong because 'Pending' explicitly means the policy has not yet been applied; a successfully applied policy would show a status of 'Succeeded' or 'Compliant'.

30
MCQhard

A company uses Microsoft Defender for Endpoint to manage endpoint security. They observe that some devices are not reporting vulnerability data to Microsoft Defender XDR. Which component is most likely misconfigured?

A.Microsoft Sentinel workspace
B.Microsoft Defender for Endpoint sensor on the devices
C.Intune MDM authority
D.Microsoft Purview compliance portal
AnswerB

Vulnerability data reaches Microsoft Defender XDR only through the Defender for Endpoint sensor, which collects and uploads device telemetry. A misconfigured or unhealthy sensor means devices stop reporting, so threat and vulnerability information never surfaces in the portal.

Why this answer

(Microsoft Defender for Endpoint sensor) is correct. The sensor is the agent installed on devices that collects and reports vulnerability information to Microsoft Defender XDR. If the sensor is misconfigured, missing, or not running, devices will not report vulnerability data.

Option A (Microsoft Sentinel workspace) is a SIEM that ingests security data but is not the source of vulnerability data. Option C (Intune MDM authority) manages device compliance and configuration but does not directly collect vulnerability data. Option D (Microsoft Purview compliance portal) handles data governance and compliance, not vulnerability reporting.

31
MCQmedium

You have a Windows 10 device that is managed by Intune and enrolled in Microsoft Defender for Endpoint. The device is reporting a high number of false positive detections from Microsoft Defender Antivirus. You need to configure an exclusion for a specific folder path to reduce false positives. Where should you configure the exclusion?

A.In a device compliance policy
B.In Group Policy
C.In the endpoint protection profile for Microsoft Defender Antivirus in Intune
D.In Microsoft Defender Security Center
AnswerC

Antivirus exclusions for folder paths are delivered through the Microsoft Defender Antivirus endpoint protection profile in Intune, which configures the Defender AV policy on managed devices. This applies the exclusion centrally without touching local device settings.

Why this answer

In an Intune-managed environment, antivirus exclusions for Microsoft Defender Antivirus are configured within the endpoint protection profile, specifically under the Microsoft Defender Antivirus settings. This profile is assigned to devices via Intune policies, allowing centralized management of exclusions without requiring on-premises Group Policy or direct interaction with the Microsoft Defender Security Center portal.

Exam trap

The trap here is that candidates often confuse the Microsoft Defender Security Center (a cloud-based security analytics portal) with the Intune endpoint protection profile, mistakenly thinking exclusions are configured in the security center rather than in the device management policy.

How to eliminate wrong answers

Option A is wrong because device compliance policies are used to enforce security requirements (e.g., encryption, OS version) and do not contain settings for antivirus exclusions. Option B is wrong because Group Policy is a traditional on-premises management tool; while it can configure Defender exclusions, it is not applicable when the device is solely managed by Intune and not domain-joined or using Group Policy. Option D is wrong because Microsoft Defender Security Center (now part of Microsoft 365 Defender) is a security operations portal for threat investigation and response, not a configuration interface for local antivirus exclusions on individual devices.

32
Multi-Selecteasy

You are configuring Microsoft Intune for Windows 10 devices. Which two settings can you enforce using a device restrictions profile? (Select TWO.)

Select 2 answers
A.Disable the camera
B.Set default web browser
C.Set battery saver threshold
D.Configure Windows Update for Business settings
E.Require a password for device unlock
AnswersA, E

Device restrictions include hardware disabling.

Why this answer

A is correct because the device restrictions profile in Microsoft Intune includes a 'Camera' setting under the 'General' category, which allows you to disable the camera on Windows 10 devices by setting it to 'Block'. This enforces a policy that prevents camera access across all apps and the OS, leveraging the CSP (Policy CSP) `Camera/AllowCamera`.

Exam trap

The trap here is that candidates often confuse device restrictions profiles with other policy types, such as Administrative Templates or Windows Update for Business profiles, leading them to select settings like default browser or Windows Update configuration that belong to different policy categories.

33
Multi-Selectmedium

Which TWO actions can you perform using Microsoft Intune to protect devices from malware?

Select 2 answers
A.Create network segmentation rules
B.Enable email attachment scanning
C.Deploy third-party antivirus software
D.Enforce Windows Defender Antivirus real-time protection
E.Configure Windows Defender Firewall rules
AnswersD, E

Enforcing Windows Defender Antivirus real-time protection through Intune endpoint security policies continuously scans files and processes, blocking malware before execution. This directly satisfies the stem's malware-protection requirement by configuring the antivirus engine on managed Windows devices via the Microsoft Intune security baseline or antivirus policy profile.

Why this answer

Option D is correct because Intune can enforce Windows Defender Antivirus settings through endpoint security antivirus policies, including turning on real-time protection, which actively detects and blocks malware on managed Windows devices. Option E is correct because Intune endpoint security firewall policies let you configure Windows Defender Firewall rules (such as blocking inbound/outbound traffic on specific ports or profiles), which helps prevent malware from communicating or spreading across the network. Option A is not provided by Intune itself; network segmentation is typically handled by network security appliances, VLANs, or Azure NSGs rather than Intune device configuration.

Option B is not an Intune malware-protection action; email attachment scanning is performed by Exchange Online Protection or Microsoft Defender for Office 365, not by Intune. Option C is not a native Intune malware-protection action in the sense described; while Intune can deploy apps, it does not itself provide antivirus protection, and the built-in Defender controls in D and E are the direct Intune mechanisms for malware protection.

Exam trap

Candidates often think only antivirus settings (like real-time protection) protect against malware, overlooking that firewall rules also play a crucial role by blocking malicious network traffic. The correct answers are D and E; a common mistake is selecting C (deploying third-party antivirus) or omitting E.

34
MCQhard

An organization uses Microsoft Defender for Cloud Apps to monitor cloud app usage. The security team wants to automatically apply an Intune app protection policy (APP) when a user accesses a risky app from an unmanaged device. What should the administrator use?

A.Conditional Access App Control with session control
B.Device configuration policy
C.App protection policy assignment to users
D.Device compliance policy
AnswerA

Conditional Access App Control with session control proxies app sessions in real time, letting Defender for Cloud Apps enforce Intune app protection policies when a risky app is accessed from an unmanaged device. This satisfies the stem's requirement for automatic, session-level policy application based on device management state and app risk.

Why this answer

Conditional Access App Control with session control is the correct solution because it allows the administrator to monitor and control app sessions in real time, applying Intune app protection policies (APP) when a user accesses a risky app from an unmanaged device. This integration uses reverse proxy architecture to intercept traffic and enforce data protection policies, such as blocking downloads or requiring managed apps, directly within the cloud app session.

Exam trap

The trap here is that candidates often confuse 'app protection policy assignment to users' (Option C) as the direct method, but the question requires dynamic, risk-based triggering via Conditional Access and Defender for Cloud Apps, not static user assignment.

How to eliminate wrong answers

Option B (Device configuration policy) is wrong because it manages device settings (e.g., Wi-Fi, VPN) and does not enforce app-level protection based on risk or device management status. Option C (App protection policy assignment to users) is wrong because it assigns APP directly to users without session-level conditional access; it cannot dynamically trigger based on real-time risk detection from Defender for Cloud Apps. Option D (Device compliance policy) is wrong because it evaluates device compliance (e.g., jailbreak detection, OS version) and blocks access at the device level, but it does not apply app protection policies within a cloud app session from an unmanaged device.

35
MCQhard

Refer to the exhibit. You are deploying a custom OMA-URI policy to Windows 10 devices. What is the effect of this policy?

A.Windows Update is configured to defer updates.
B.Device telemetry is set to enhanced.
C.Windows Defender is disabled.
D.Cortana is enabled.
AnswerB

The OMA-URI targets the System/AllowTelemetry policy CSP node, setting the value that maps to Enhanced (level 2). This restricts diagnostic data collection to enhanced level rather than Full or Basic, applying directly to Windows 10 devices.

Why this answer

The OMA-URI policy configured in the exhibit sets the 'System/AllowTelemetry' value to '2', which corresponds to the 'Enhanced' telemetry level in Windows 10. This policy enables Microsoft to collect additional diagnostic data, including how Windows and apps are used, to improve the user experience and device performance. It does not affect Windows Update deferral, Defender state, or Cortana.

Exam trap

The trap here is that candidates may confuse the telemetry policy with other common MDM policies, such as Windows Update deferral or Defender settings, because the exam often tests the specific numeric values and their corresponding telemetry levels rather than the broader functionality.

How to eliminate wrong answers

Option A is wrong because deferring Windows updates is configured via the 'Update/DeferUpdatePeriod' or 'Update/DeferFeatureUpdatesPeriod' OMA-URI, not through telemetry settings. Option C is wrong because disabling Windows Defender is controlled by policies such as 'Defender/DisableRealtimeMonitoring' or 'Defender/AllowUserUIAccess', not by the telemetry level. Option D is wrong because enabling Cortana is managed by policies like 'Experience/AllowCortana' or 'System/AllowCortana', not by the telemetry URI.

36
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that devices are compliant with a new security policy that requires Windows Defender Antivirus to be enabled and up-to-date. You create a device compliance policy with the setting 'Require' for Windows Defender Antivirus. After assigning the policy, you see that 90% of devices are compliant. The remaining 10% show 'Not evaluated'. You check the devices and find that they are online, enrolled, and have Windows Defender Antivirus enabled. What is the most likely reason for the 'Not evaluated' status?

A.The devices have not checked in with Intune since the policy was assigned
B.The devices are offline
C.The policy is not assigned to the devices
D.Windows Defender Antivirus is disabled
AnswerA

Compliance status is calculated when a device checks in and evaluates the assigned policy. Devices that have not synced since assignment remain 'Not evaluated' despite being online and enrolled, so a manual or scheduled Intune sync triggers evaluation and resolves the status.

Why this answer

A 'Not evaluated' compliance status in Intune means the device has not yet processed the assigned compliance policy — typically because it has not performed a device check-in (MDM sync) since the policy was assigned. Even though the device is online and enrolled, compliance evaluation only occurs during a scheduled or triggered check-in cycle, which can take up to 8 hours by default. Forcing a sync from the Company Portal or Intune console resolves this.

Exam trap

MD-102 often tests the distinction between 'Not evaluated' (policy not yet processed) and 'Not compliant' (policy processed and failed), tricking candidates into troubleshooting device configuration when the real issue is simply check-in timing.

How to eliminate wrong answers

Option B is wrong because the question explicitly states the devices are online, so offline status cannot explain the 'Not evaluated' state. Option C is wrong because if the policy were unassigned, the devices would show 'Not applicable' rather than 'Not evaluated', and the question implies the policy was assigned. Option D is wrong because the question confirms Windows Defender Antivirus is enabled on the devices, so the underlying setting is satisfied — the issue is evaluation timing, not configuration.

37
MCQhard

Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to implement a policy that requires devices to meet specific hardware and software conditions before they can access corporate email. The policy must evaluate the device's encryption status, OS version, and whether it has a firewall enabled. What should you create?

A.A Conditional Access policy that requires a compliant device.
B.An app protection policy that requires a PIN and blocks jailbroken devices.
C.A device configuration profile that enforces encryption, OS version, and firewall settings.
D.A device compliance policy that includes the required conditions, and then a Conditional Access policy that requires a compliant device.
AnswerD

A device compliance policy in Intune evaluates settings like BitLocker status, OS version, and firewall. Once the device is marked compliant, a Conditional Access policy can require a compliant device to grant access to email. This combination ensures devices meet the specified conditions before access is allowed.

Why this answer

To evaluate specific device conditions and control access, you must use a device compliance policy to assess the settings and a Conditional Access policy to enforce the requirement. The compliance policy checks encryption, OS version, and firewall; Conditional Access then blocks non-compliant devices from accessing email. This is the standard Intune and Microsoft Entra ID integration.

Exam trap

The trap here is assuming that Conditional Access alone can evaluate device settings; it only enforces compliance based on policies.

38
MCQhard

You configure a Windows 10 device compliance policy in Intune that requires 'Firewall' to be enabled. The device has Windows Defender Firewall enabled, but the device reports as non-compliant. You verify that the firewall is active. What is the most likely cause?

A.The firewall is configured to allow all inbound connections
B.The device uses a third-party firewall that Intune does not recognize
C.The firewall is enabled only on the Domain profile but not on Public or Private profiles
D.The device has multiple network adapters and the firewall is disabled on one
AnswerC

Intune's Firewall compliance rule evaluates all three Windows Defender Firewall profiles. Enabling the firewall only on the Domain profile leaves Public and Private profiles off, so the device reports non-compliant despite the firewall appearing active.

Why this answer

Intune's Firewall compliance setting evaluates Windows Defender Firewall across all three network profiles: Domain, Private, and Public. If the firewall is enabled only on the Domain profile but disabled on Private or Public, the device is reported as non-compliant even though the firewall appears active in some contexts. This is the most common cause of a false non-compliant report when the firewall is 'on'.

Exam trap

MD-102 often tests the misconception that 'firewall enabled' means a single toggle — candidates forget that Intune evaluates Domain, Private, and Public profiles independently and requires all three to be enabled.

How to eliminate wrong answers

Option A is wrong because allowing all inbound connections does not affect the compliance check — Intune only verifies that the firewall is enabled, not its rule configuration. Option B is wrong because Intune's built-in firewall compliance rule specifically checks Windows Defender Firewall status; a third-party firewall would cause non-compliance only if Defender Firewall itself is disabled, but the scenario states Defender Firewall is enabled. Option D is wrong because the compliance rule checks the firewall's overall state per profile, not per network adapter; a disabled firewall on one adapter would still be reflected in the profile state, but the more precise and common cause is a profile mismatch.

39
MCQhard

Refer to the exhibit. The JSON shows a compliance policy for Windows 10 devices. Devices that do not meet the policy are marked as non-compliant. Which diagnostic step would you take to identify why a specific device is non-compliant despite having BitLocker enabled?

A.Verify the compliance policy is assigned to the device's group.
B.Check the device's compliance status in Intune for details.
C.Review the device's hardware security features: Secure Boot and Code Integrity.
D.Modify the policy to remove the requireSecureBoot and requireCodeIntegrity settings.
AnswerC

Secure Boot and Code Integrity are separate device health attestation signals from BitLocker encryption status, so a device can have BitLocker enabled yet still fail the compliance policy if either is disabled or misconfigured. Reviewing these hardware security features identifies the specific setting causing non-compliance, satisfying the stem's requirement to diagnose why the device fails despite BitLocker.

Why this answer

The compliance policy JSON requires Secure Boot and Code Integrity in addition to BitLocker. Even if BitLocker is enabled, a device will be marked non-compliant if Secure Boot or Code Integrity is disabled or unsupported. Therefore, the correct diagnostic step is to review the device's hardware security features — Secure Boot and Code Integrity — to confirm they meet the policy requirements.

Exam trap

MD-102 often tests the assumption that BitLocker alone satisfies compliance — candidates forget that policies can require multiple settings, and a device fails if any single setting (like Secure Boot or Code Integrity) is not met.

How to eliminate wrong answers

Option A is wrong because if the policy were not assigned to the device's group, the device would not be evaluated against the policy at all and would not appear as non-compliant due to this policy — assignment issues produce a different symptom. Option B is wrong because checking compliance status in Intune shows the result but not the root cause; the question asks for the diagnostic step to identify why, and the status alone does not reveal that Secure Boot or Code Integrity is the failing setting. Option D is wrong because modifying the policy to remove the requirements is a remediation that weakens security, not a diagnostic step, and it does not identify why the device is non-compliant.

40
MCQhard

Your organization uses Microsoft Intune to manage devices. You have a Windows 10 device that is co-managed with Configuration Manager. You need to configure a policy that requires BitLocker encryption. You create a BitLocker policy in Intune and assign it to the device. After 24 hours, BitLocker is not enabled on the device. You verify that the device is online and the policy is assigned. What is the most likely cause?

A.The device is not online.
B.The encryption workload is set to Configuration Manager.
C.The device is not enrolled in Intune.
D.The BitLocker policy is not assigned to the correct group.
AnswerB

BitLocker falls under the Endpoint Protection workload in co-management. If that workload's authority remains with Configuration Manager, Intune's BitLocker policy is ignored on the device, so encryption never applies. Shifting the Endpoint Protection workload slider to Intune (or Pilot) resolves this.

Why this answer

In a co-managed environment, workload control determines which management authority (Configuration Manager or Intune) handles specific policies. If the encryption workload is set to Configuration Manager, Intune's BitLocker policy will be ignored, even if assigned and the device is online. This is the most likely reason the policy did not take effect after 24 hours.

Exam trap

The trap here is that candidates assume Intune policy always applies to enrolled devices, overlooking the co-management workload slider that can block Intune from managing specific workloads like encryption.

How to eliminate wrong answers

Option A is wrong because the device is verified as online, so connectivity is not the issue. Option C is wrong because the device is co-managed, meaning it is enrolled in both Configuration Manager and Intune; the policy assignment confirms enrollment. Option D is wrong because the policy is assigned to the device and verified, so group assignment is not the problem; the issue is workload control overriding Intune's authority.

41
MCQeasy

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that corporate data is separated from personal data on the device. Which management approach should you use?

A.Android Enterprise kiosk mode
B.Android Enterprise fully managed
C.Android Enterprise work profile
D.Android device administrator
AnswerC

A work profile creates a separate, managed container on the device, keeping corporate apps and data isolated from the personal profile. This directly satisfies the requirement to separate corporate from personal data on Android Enterprise devices.

Why this answer

Android Enterprise work profile creates a separate container for corporate data, keeping it isolated from personal data on the same device. Android Enterprise fully managed devices are for corporate-owned devices and do not have a personal space. Android Enterprise kiosk mode locks the device to a single app or set of apps, not designed for data separation.

Android device administrator is a legacy management method that does not provide data separation.

42
MCQhard

Refer to the exhibit. You deploy this compliance policy to Windows 10 devices. A device reports as compliant, but you suspect it may have a weak password policy because the password type is 'deviceDefault'. What is the effect of 'deviceDefault' on the password requirement?

A.It requires a password that meets the minimum length but no complexity
B.It uses the password type configured in the device's local policy
C.It does not require a password at all
D.It requires a password that contains at least one number and one letter
AnswerB

Selecting deviceDefault for password type defers enforcement to whatever password policy already exists locally on the device, rather than imposing an Intune-defined complexity or length requirement. Compliance therefore reflects the local configuration, which may be weaker than intended.

Why this answer

When the password type is set to 'deviceDefault' in a Microsoft Intune compliance policy for Windows 10, the policy does not enforce a specific password type (e.g., alphanumeric or numeric). Instead, it defers to the password type already configured in the device's local security policy (via Local Group Policy or the SAM registry). This means the device can still be compliant even if the local policy requires only a simple PIN or no complexity, as long as the local password type meets the minimum length and other requirements defined in the compliance policy.

Exam trap

The trap here is that candidates assume 'deviceDefault' means the Intune policy enforces a default Microsoft-defined password type (like alphanumeric), when in fact it simply passes control to the device's local policy, which may be weaker or stronger.

How to eliminate wrong answers

Option A is wrong because 'deviceDefault' does not inherently require a password that meets minimum length without complexity; it simply inherits whatever password type is set locally, which could include complexity requirements or none at all. Option C is wrong because 'deviceDefault' does not mean no password is required; the device still must have a password configured locally, and the compliance policy will enforce other settings like minimum length and expiration. Option D is wrong because requiring at least one number and one letter corresponds to the 'alphanumeric' password type, not 'deviceDefault'; 'deviceDefault' does not mandate any specific character composition.

43
MCQhard

Your organization uses Windows Defender Application Control (WDAC) to allow only approved apps. After deploying a WDAC policy via Intune, some users report that a critical line-of-business app is blocked. How should you troubleshoot?

A.Review CodeIntegrity/Operational logs in Event Viewer
B.Check AppLocker logs in Event Viewer
C.Review Intune device management events for policy errors
D.Check Microsoft 365 Defender portal for WDAC alerts
AnswerA

Reviewing CodeIntegrity/Operational logs reveals the exact WDAC block event, including the file hash, publisher and policy GUID that denied execution. This directly satisfies the troubleshooting constraint: identifying why the line-of-business app was blocked, so you can add a supplemental policy or managed installer rule in Intune.

Why this answer

WDAC blocks or allows applications based on code integrity rules, and when a policy is enforced, blocked execution events are logged in the CodeIntegrity/Operational event log under Event Viewer. Reviewing this log provides specific block events with file details and rule identifiers, enabling you to identify why the LOB app was blocked and adjust the policy accordingly.

Exam trap

The trap here is that candidates confuse WDAC with AppLocker and assume AppLocker logs are relevant, but WDAC uses its own dedicated CodeIntegrity logs for all block events.

How to eliminate wrong answers

Option B is wrong because AppLocker logs are used for AppLocker policies, not WDAC; WDAC uses its own CodeIntegrity logs. Option C is wrong because Intune device management events show policy deployment status (e.g., sync errors) but do not capture runtime block events from the WDAC driver on the client. Option D is wrong because the Microsoft 365 Defender portal aggregates WDAC alerts from devices that report to Defender for Endpoint, but it may not show granular block details for every locally blocked app, and the primary troubleshooting source is the local CodeIntegrity log.

44
MCQmedium

Your company uses Microsoft Defender for Endpoint (Defender XDR). You need to configure an automated investigation and remediation (AIR) rule that automatically quarantines a file when a specific alert is triggered. Which action should you take?

A.Add an indicator of compromise for the file.
B.Configure a device control policy.
C.Create a new automation rule in the Microsoft 365 Defender portal.
D.Create an attack surface reduction rule.
AnswerC

Creating an automation rule in the Microsoft 365 Defender portal directly satisfies the requirement to quarantine a file when a specific alert triggers. Automation rules evaluate alerts and execute response actions such as quarantine, unlike custom detections, which only generate alerts, or device groups, which merely scope remediation levels.

Why this answer

Automated investigation and remediation (AIR) rules in Microsoft 365 Defender allow you to define automated actions—such as quarantining a file—when a specific alert is triggered. This is the native mechanism for orchestrating response actions based on alert conditions, directly supporting the requirement to automatically quarantine a file upon alert generation.

Exam trap

The trap here is that candidates often confuse indicators of compromise (IoC) with automated response rules, mistakenly thinking that adding an IoC for a file will automatically trigger a quarantine action when the file is detected, whereas IoCs only define detection or blocking logic, not conditional alert-triggered remediation workflows.

How to eliminate wrong answers

Option A is wrong because adding an indicator of compromise (IoC) for the file creates a custom threat intelligence indicator that can block or alert on the file, but it does not create an automated investigation and remediation rule that triggers a quarantine action based on a specific alert. Option B is wrong because a device control policy governs removable storage and peripheral device access (e.g., USB drives), not file-level quarantine actions in response to alerts. Option D is wrong because an attack surface reduction (ASR) rule is a set of behavioral-based rules that prevent common attack techniques (e.g., blocking Office apps from creating child processes), but it does not provide the ability to define automated quarantine actions triggered by a specific alert.

45
MCQhard

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a managed Google Play app to work profile devices. After deploying, users report that the app is not available in the work profile. What is the most likely cause?

A.The app has not been approved in the managed Google Play store.
B.The app is only available for corporate-owned devices.
C.Android Enterprise enrollment is not enabled in Intune.
D.The device does not have a work profile configured.
AnswerA

Managed Google Play apps must be approved by an Intune administrator before they become assignable to Android Enterprise work profile devices. Until approval occurs, the app remains unavailable in the managed store, so it never installs into the work profile despite the deployment.

Why this answer

Managed Google Play apps must be approved before they can be deployed to work profile devices. Without approval, the app will not appear in the work profile's Play Store.

Exam trap

Candidates often assume that deployment failure is due to device ownership type (corporate vs personal), but the key prerequisite is app approval in Managed Google Play.

46
MCQhard

Your organization uses Microsoft Defender for Cloud Apps (part of Microsoft Defender XDR). You need to detect when users access cloud apps from unauthorized locations. Which log source should you integrate to get location information?

A.Microsoft Entra ID sign-in logs
B.Microsoft Intune device enrollment logs
C.Microsoft Purview audit logs
D.Microsoft Sentinel
AnswerA

Microsoft Entra ID sign-in logs record each authentication with the originating IP address, which Defender for Cloud Apps resolves into country, city and coordinates for its impossible travel and anomalous location detections. This directly satisfies the requirement to identify access from unauthorised locations, since the sign-in event carries the geo-location data the policy evaluates.

Why this answer

Microsoft Entra ID sign-in logs contain location information (IP address, country, city) for user sign-ins to cloud apps. Integrating these logs with Defender for Cloud Apps enables detection of access from unauthorized locations. Other log sources do not provide the necessary location context for cloud app access.

Exam trap

MD-102 often tests the confusion between different log sources; candidates may choose Microsoft Sentinel or Purview audit logs, but the specific location data for cloud app access comes from Entra ID sign-in logs.

How to eliminate wrong answers

Option B is wrong because Intune device enrollment logs pertain to device management, not user access to cloud apps, and lack location data. Option C is wrong because Microsoft Purview audit logs focus on compliance and data governance activities, not real-time sign-in locations. Option D is wrong because Microsoft Sentinel is a SIEM that can ingest logs, but it is not a log source itself; the question asks for the log source to integrate.

47
MCQeasy

Your organization wants to deploy Windows Update for Business policies using Microsoft Intune to Windows 10 devices. Which policy type should you use?

A.App protection policy
B.Device configuration profile for Windows Update for Business
C.Device compliance policy
D.Endpoint security policy for antivirus
AnswerB

A device configuration profile containing the Windows Update for Business settings delivers deferral, deadline and restart controls directly to Windows 10 devices. This is the correct policy type for applying WUfB settings through Intune, rather than update rings or scripts.

Why this answer

Windows Update for Business (WUfB) policies are configured using a device configuration profile in Microsoft Intune, specifically under the 'Windows Update for Business' template. This profile type allows you to manage update settings such as deferral periods, pause updates, and feature update targeting directly from Intune without requiring on-premises WSUS or additional infrastructure.

Exam trap

The trap here is that candidates often confuse Device compliance policies (which can report update status) with the actual policy type that configures update behavior, leading them to select Option C instead of the correct Device configuration profile for Windows Update for Business.

How to eliminate wrong answers

Option A is wrong because App protection policies (APP) are designed to protect corporate data in mobile apps (e.g., Outlook, OneDrive) on iOS/iPadOS and Android devices, not to manage Windows Update settings. Option C is wrong because Device compliance policies evaluate device health (e.g., BitLocker status, antivirus state, OS version) and trigger conditional access, but they do not configure update deployment behavior or deferral policies. Option D is wrong because Endpoint security policies for antivirus manage Microsoft Defender Antivirus configurations (e.g., real-time protection, cloud-delivered protection), not Windows Update for Business settings.

48
MCQmedium

Your company uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that work apps are sandboxed from personal apps. Which enrollment type should you use?

A.Fully managed
B.Work profile
C.Device administrator
D.Corporate-owned personally enabled (COPE)
AnswerB

Android Enterprise work profile creates a separate managed profile on the device, isolating corporate apps and data from personal apps. This satisfies the sandboxing requirement by enforcing containerisation between work and personal contexts on the same device.

Why this answer

The Work profile enrollment type is correct because it creates a separate, managed container on Android Enterprise devices that isolates work apps and data from personal apps and data. This sandboxing is enforced by the Android Enterprise framework, ensuring that work apps cannot access personal data and vice versa, which meets the requirement for separation without requiring full device management.

Exam trap

The trap here is that candidates often confuse COPE with Work profile, assuming COPE is required for sandboxing on corporate-owned devices, but the question focuses on the enrollment type that ensures sandboxing regardless of ownership, making Work profile the correct choice.

How to eliminate wrong answers

Option A is wrong because Fully managed enrollment gives the organization complete control over the entire device, which does not provide sandboxing between work and personal apps—it manages the whole device as a corporate asset. Option C is wrong because Device administrator is a legacy Android management mode that does not support work profile sandboxing; it applies policies to the entire device and lacks the containerization capabilities of Android Enterprise. Option D is wrong because Corporate-owned personally enabled (COPE) uses a work profile for separation but is designed for corporate-owned devices that also allow personal use, whereas the question does not specify device ownership and Work profile is the standard enrollment type for sandboxing on personally owned devices.

49
MCQmedium

You manage Windows 10 devices with Microsoft Intune. A user reports that a device has a red shield icon in the Windows Security Center, indicating tamper protection is off. You need to re-enable tamper protection on the device using Intune. Which profile type should you configure?

A.Device configuration profile (settings catalog)
B.Endpoint protection profile (Microsoft Defender Antivirus)
C.Security baseline (Windows 10/11)
D.Compliance policy
AnswerB

Endpoint protection profiles for Microsoft Defender Antivirus expose the tamper protection toggle directly, letting Intune push the setting to the device without a script. This satisfies the requirement to re-enable tamper protection remotely, since Defender Antivirus configuration is the only Intune profile type that carries that specific setting.

Why this answer

Tamper protection is a Microsoft Defender Antivirus setting that prevents unauthorized changes to security features. In Intune, this setting is configured under the 'Endpoint protection profile' using the 'Microsoft Defender Antivirus' template, specifically via the 'Enable tamper protection to prevent Microsoft Defender being disabled' toggle. This profile type directly manages Defender settings, including tamper protection, and applies them to enrolled Windows 10 devices.

Exam trap

The trap here is that candidates confuse the 'Security baseline' (which applies many security settings but not tamper protection) with the 'Endpoint protection profile' (which specifically manages Defender features like tamper protection), leading them to select Option C incorrectly.

How to eliminate wrong answers

Option A is wrong because a Device configuration profile (settings catalog) can configure many Windows settings but does not include the specific tamper protection setting for Microsoft Defender Antivirus; tamper protection is only exposed through the Endpoint protection profile. Option C is wrong because a Security baseline (Windows 10/11) applies a predefined set of security policies, but tamper protection is not a setting within the baseline; it must be configured separately via an Endpoint protection profile. Option D is wrong because a Compliance policy evaluates device compliance against rules (e.g., requiring tamper protection to be on) but cannot enforce or enable tamper protection; it only reports non-compliance and can trigger remediation actions via other profiles.

50
MCQeasy

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to deploy a security baseline that enforces BitLocker encryption and Windows Defender Antivirus settings. What is the recommended approach?

A.Create a custom configuration profile using Configuration Manager.
B.Deploy a PowerShell script via Intune to configure the settings.
C.Use the built-in Windows 10 security baseline in Intune.
D.Apply Group Policy Objects from on-premises Active Directory.
AnswerC

The built-in Windows 10 security baseline in Intune delivers preconfigured Microsoft-recommended settings for exactly these areas, including BitLocker drive encryption and Windows Defender Antivirus. It satisfies the requirement to enforce both without manually authoring each setting, and supports version upgrades as new baseline releases appear.

Why this answer

The recommended approach is to use the built-in Windows 10 security baseline in Intune (Option C). Intune provides pre-configured security baselines that include settings for BitLocker encryption and Windows Defender Antivirus, which can be customized as needed. Option A is incorrect because custom configuration profiles do not provide the pre-built baseline and are more manual.

Option B is incorrect because PowerShell scripts are not a baseline and are less manageable at scale. Option D is incorrect because Group Policy from on-premises AD is not integrated with Intune and requires hybrid infrastructure.

51
MCQeasy

An organization wants to enforce encryption on all Windows 10/11 devices using Intune. Which policy type should they use?

A.Device compliance policy
B.App protection policy
C.Device configuration profile (settings catalog)
D.Endpoint security disk encryption policy
AnswerD

Endpoint security disk encryption policies in Intune configure BitLocker settings and silently enable encryption across Windows 10 and 11 devices, including escrowing recovery keys to Microsoft Entra ID. This is the purpose-built policy type for enforcing encryption at scale.

Why this answer

The Endpoint security disk encryption policy in Intune is specifically designed to enforce encryption (e.g., BitLocker) on Windows 10/11 devices. It provides a dedicated, streamlined interface for configuring encryption settings and monitoring compliance, unlike general device configuration profiles which require manual setup via the settings catalog. This policy type is the correct choice because it directly targets disk encryption as a security baseline, aligning with the organization's goal to enforce encryption across all managed devices.

Exam trap

The trap here is that candidates often confuse Device compliance policy (which only checks encryption status) with a policy that actually enforces encryption, or they assume the settings catalog is the only way to configure BitLocker, missing the purpose-built Endpoint security disk encryption policy.

How to eliminate wrong answers

Option A is wrong because Device compliance policy evaluates whether devices meet compliance rules (e.g., encryption status) but does not enforce or configure encryption settings; it only reports non-compliance. Option B is wrong because App protection policy applies to mobile apps and data at the app level (e.g., MAM), not to the operating system or disk encryption on Windows devices. Option C is wrong because Device configuration profile (settings catalog) can configure BitLocker settings, but it is a general-purpose tool that requires manual selection of individual settings, whereas Endpoint security disk encryption policy provides a purpose-built, policy-driven approach with built-in monitoring and reporting for encryption enforcement.

52
MCQeasy

Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that corporate data in Microsoft Outlook is protected even if the device is not enrolled in MDM. Which policy should you deploy?

A.Device compliance policy
B.Device configuration profile
C.Conditional Access policy
D.App protection policy (MAM)
AnswerD

App protection policies apply at the app layer via Microsoft Intune, enforcing encryption, PIN and selective wipe on Outlook data without requiring device enrolment. This satisfies the constraint that corporate data must be protected on unenrolled iOS devices.

Why this answer

App protection policies (MAM) protect corporate data in apps like Outlook without requiring device enrollment in MDM. Option A (Device compliance policy) requires MDM enrollment. Option B (Device configuration profile) is for device settings, not data protection.

Option C (Conditional Access policy) controls access but does not directly protect data within apps.

53
MCQeasy

You use Microsoft Intune to manage Windows 10 devices. You need to create a compliance policy that requires devices to have a minimum OS version of 10.0.19044. You configure the setting 'Minimum OS version' to '10.0.19044'. Which additional setting must you configure to ensure that devices running a higher version, such as 10.0.19045, are also considered compliant?

A.Set 'Maximum OS version' to the highest supported build.
B.Configure a device configuration profile to set the OS version.
C.Set 'Valid operating system builds' to include all builds greater than 10.0.19044.
D.No additional setting is required; the minimum OS version setting allows higher versions by default.
AnswerD

The 'Minimum OS version' setting in Intune compliance policies checks that the device's OS version is greater than or equal to the specified value. Devices running a higher version, such as 10.0.19045, automatically satisfy the requirement. Therefore, no additional configuration is needed to include higher versions; they are inherently compliant.

Why this answer

The 'Minimum OS version' setting in a Windows compliance policy specifies the lowest acceptable OS build. Any device with an OS version equal to or higher than the specified value is considered compliant. Therefore, devices running 10.0.19045 or later automatically meet the requirement.

No additional setting is needed to include higher versions, as the comparison is inclusive and allows any newer build.

Exam trap

The trap here is thinking you need to specify a range or maximum to include newer versions, when in fact the minimum setting already permits all higher versions.

54
MCQeasy

A user reports that their iOS device is not receiving email on their work account. The device is enrolled in Intune. You verify that the Exchange ActiveSync profile is assigned correctly. What should you check next?

A.Ensure the MDM authority is set to Intune.
B.Check if an app protection policy is assigned to the user.
C.Verify that the device is enrolled in device enrollment manager mode.
D.Check the device's compliance status in Intune.
AnswerD

Conditional access in Microsoft Entra ID blocks Exchange ActiveSync when a device falls out of compliance, so a non-compliant status directly halts mail synchronisation despite correct profile assignment. Verifying compliance confirms whether access policy, not configuration, is preventing the iOS device from receiving email.

Why this answer

When an iOS device enrolled in Intune is not receiving email despite a correctly assigned Exchange ActiveSync profile, the next logical check is the device's compliance status. Conditional Access policies often require compliant devices to access Exchange Online, so a non-compliant device will be blocked from syncing email even if the profile is assigned.

Exam trap

The trap is focusing on the EAS profile itself — candidates assume the profile is the issue, but Conditional Access and compliance status are common blockers for email sync on enrolled devices.

How to eliminate wrong answers

Option A is wrong because the MDM authority is a tenant-wide setting; if it were not set to Intune, no devices would enroll, but the device is already enrolled. Option B is wrong because app protection policies (MAM) apply to apps and do not block native iOS Mail from syncing Exchange ActiveSync. Option C is wrong because device enrollment manager mode is for enrolling multiple devices with a single account and is not relevant to a single user's email issue.

55
Multi-Selectmedium

Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to configure a compliance policy that enforces encryption and firewall settings. Which two settings should you configure in the compliance policy? (Choose two.)

Select 2 answers
A.Require the device to be marked as compliant by a third-party MDM
B.Require Windows Defender Antivirus
C.Require Secure Boot to be enabled on the device
D.Require a firewall
E.Require BitLocker
AnswersD, E

Require a firewall is a compliance setting under System Security that verifies Microsoft Defender Firewall is enabled on the device. If the firewall is off, the device is marked noncompliant. This directly fulfills the requirement to enforce firewall settings in the compliance policy.

Why this answer

To enforce encryption and firewall settings in a Windows compliance policy, you configure 'Require BitLocker' under Device Health and 'Require a firewall' under System Security. These settings directly validate that encryption is active and the firewall is enabled, marking devices noncompliant if either condition fails.

Exam trap

The trap here is selecting other security-related settings like Secure Boot or antivirus, which are valuable but do not fulfill the specific encryption and firewall requirements.

56
MCQmedium

You are an endpoint administrator for a company that uses Microsoft Intune to manage Windows 11 devices. You have a device compliance policy that requires BitLocker Drive Encryption to be enabled on the OS drive. A user reports that their device is marked as non-compliant, even though they have BitLocker enabled and the drive is encrypted. You check the device and see that the BitLocker protection status is 'Protection Off' in the BitLocker control panel. The user has not set up a PIN. You need to ensure the device is compliant. What should you do?

A.Instruct the user to open BitLocker Drive Encryption and click 'Resume protection'.
B.In Intune, create a new configuration profile to enforce BitLocker with a startup PIN.
C.In the compliance policy, change the BitLocker requirement to 'Not required'.
D.In the compliance policy, set the BitLocker requirement to 'Require' and enable 'Require device encryption'.
AnswerA

BitLocker protection can be suspended, which leaves the drive encrypted but not actively protected. The compliance policy checks the protection status, not just encryption. Resuming protection re-enables BitLocker and will make the device compliant. This is the correct action because it addresses the actual state of BitLocker without weakening security.

Why this answer

The device is non-compliant because BitLocker protection is suspended, even though the drive is encrypted. The compliance policy checks the protection status, so the user must resume protection to become compliant. Resuming protection re-enables BitLocker and ensures the drive is actively protected, satisfying the policy requirement without compromising security.

Exam trap

The trap here is assuming that encryption alone satisfies BitLocker compliance, when the policy actually checks the active protection status, which can be suspended independently.

57
MCQmedium

Your organization uses Windows Autopilot and Microsoft Intune. You need to ensure that during the Autopilot deployment, the device automatically installs a set of required applications (Microsoft 365 Apps, company portal, and a line-of-business app) before the user can access the desktop. Which configuration should you use?

A.Configure the Enrollment Status Page (ESP) to block device use until required apps are installed
B.Set a device compliance policy to require all apps to be installed
C.Use a PowerShell script that runs during Autopilot to install apps
D.Configure an Autopilot deployment profile with the 'Skip EULA' option
AnswerA

The Enrollment Status Page hooks into Autopilot's device ESP phase, tracking Win32 and Microsoft Store app installation via Intune management extension before allowing desktop access. This directly satisfies the stem's constraint that required apps — Microsoft 365 Apps, Company Portal, and the LOB app — must install before the user reaches the desktop.

Why this answer

The Enrollment Status Page (ESP) in Windows Autopilot can be configured to block device use until specified required apps are installed. This ensures that Microsoft 365 Apps, Company Portal, and line-of-business apps are fully deployed before the user reaches the desktop, meeting the requirement of a controlled, app-ready deployment.

Exam trap

The trap here is that candidates often confuse the ESP's ability to block desktop access with compliance policies or scripts, not realizing that only the ESP provides the specific 'block until installed' functionality during Autopilot.

How to eliminate wrong answers

Option B is wrong because a device compliance policy checks the state of devices after enrollment (e.g., requiring apps to be installed for compliance), but it does not block the user from accessing the desktop during Autopilot deployment; it only flags non-compliance later. Option C is wrong because a PowerShell script running during Autopilot can install apps, but it cannot reliably block the user from accessing the desktop until all apps are installed; the ESP provides that blocking mechanism. Option D is wrong because the 'Skip EULA' option in an Autopilot deployment profile only skips the End-User License Agreement pages during OOBE, which has no effect on app installation or blocking desktop access.

58
MCQhard

Your organization uses Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy that requires devices to run Windows version 22H2 or later. When you create the policy, which option must you select for the OS version requirement?

A.Require OS version
B.Maximum OS version
C.Minimum OS version
D.Exact OS version
AnswerC

Minimum OS version sets a floor that devices must meet or exceed, so specifying Windows 11 22H2 enforces that devices run 22H2 or later. This directly satisfies the stem's requirement for a compliance policy mandating version 22H2 or above.

Why this answer

The requirement for devices to run Windows version 22H2 or later is a minimum version constraint. In Microsoft Intune compliance policies, the 'Minimum OS version' setting enforces that the device's OS version must be equal to or greater than the specified version, which directly matches the '22H2 or later' condition.

Exam trap

The trap here is that candidates confuse 'Minimum OS version' with 'Exact OS version' or 'Require OS version', mistakenly thinking Intune can enforce a single specific build rather than a minimum threshold.

How to eliminate wrong answers

Option A is wrong because 'Require OS version' is not a valid setting in Intune compliance policies; the actual settings are 'Minimum OS version' and 'Maximum OS version'. Option B is wrong because 'Maximum OS version' would restrict devices to a version no higher than the specified one, which is the opposite of the 'or later' requirement. Option D is wrong because 'Exact OS version' is not a supported option in Intune; compliance policies do not allow pinning to a single specific build, only range-based constraints.

59
MCQmedium

Your company deploys Microsoft Defender for Endpoint (Defender XDR) to all Windows devices. You need to create a custom detection rule that triggers an alert when a specific PowerShell script is executed on any device. Which action should you take in the Microsoft 365 Defender portal?

A.Create a new custom detection rule based on an Advanced hunting query.
B.Configure a Device control policy to block PowerShell.
C.Add an Indicator of compromise for the script hash.
D.Create a new attack simulation training campaign.
AnswerA

Custom detection rules run Advanced hunting KQL queries on a schedule and raise alerts when results match, so a query targeting PowerShell script execution events detects the script across all onboarded devices. This is the only mechanism in the Defender portal for query-based custom detections.

Why this answer

A is correct because custom detection rules in Microsoft 365 Defender are built from Advanced hunting queries (Kusto Query Language) that can detect specific script execution patterns, such as a PowerShell script with a known command line or hash. This allows you to trigger an alert when the exact script runs, meeting the requirement for a custom detection rule.

Exam trap

The trap here is that candidates often confuse Indicators of compromise (IoC) with custom detection rules, thinking a hash-based IoC can create a detection rule, but IoCs are for blocking or alerting on known files, not for writing custom KQL-based detection logic.

How to eliminate wrong answers

Option B is wrong because configuring a Device control policy to block PowerShell would prevent all PowerShell execution, not create a detection rule for a specific script; it is a restrictive control, not a detection mechanism. Option C is wrong because adding an Indicator of compromise (IoC) for the script hash would block or alert on the file based on its hash, but it does not create a custom detection rule with an Advanced hunting query; IoCs are for known threats, not custom detection logic. Option D is wrong because creating an attack simulation training campaign is for phishing simulations and user awareness, not for detecting PowerShell script execution on devices.

60
MCQmedium

You manage Windows 10 devices with Intune. You need to ensure that only approved apps can run on corporate devices. You configure AppLocker via a custom OMA-URI. However, users can still run unapproved apps. What is the most likely reason?

A.The device must be running Windows 10 Pro edition.
B.AppLocker rules can only be configured via Group Policy, not OMA-URI.
C.The AppLocker policy is set to 'Audit only' mode.
D.The policy is assigned to a device group instead of a user group.
AnswerC

Audit-only mode logs AppLocker events without blocking execution, so unapproved apps still launch despite the deployed policy. Switching the enforcement setting to Enforce makes the rules actively prevent unapproved applications from running on the managed devices.

Why this answer

When AppLocker is configured via custom OMA-URI in Intune, the policy is device-based and can be assigned to device groups. However, if the policy is set to 'Audit only' mode, it only logs events without actually blocking applications. This allows users to still run unapproved apps.

Option D is incorrect because assigning the policy to a device group does enforce AppLocker rules; the issue here is mode enforcement, not assignment type.

Exam trap

The trap is that candidates may overlook the enforcement mode of AppLocker policies, assuming they block by default, when 'Audit only' mode is a common configuration that logs but does not prevent execution.

How to eliminate wrong answers

Option A is wrong because AppLocker is supported on Windows 10 Enterprise and Education editions, not Pro; Pro edition lacks the AppLocker service and rule enforcement. Option B is wrong because AppLocker rules can be configured via OMA-URI using the ./Vendor/MSFT/AppLocker CSP, which is a supported method in Intune for Windows 10/11 devices. Option C is wrong because if the policy were in 'Audit only' mode, unapproved apps would still be allowed to run but events would be logged; the question states users can run unapproved apps, which could also happen in audit mode, but the most likely reason given the scenario is the assignment target mismatch.

61
MCQmedium

Refer to the exhibit. You configure this Enrollment Status Page (ESP) policy for Windows Autopilot deployments. During a deployment, a device fails to install a required app. What happens?

A.The device will be blocked from use until the app is installed or the device is reset.
B.The user can retry the installation manually.
C.The timeout will extend by 60 minutes.
D.The device will automatically retry the installation.
AnswerA

With the Enrollment Status Page blocking device use until all targeted apps install, a failed required app leaves the device locked on the ESP. The user cannot reach the desktop; only successful installation or a device reset clears the block.

Why this answer

The Enrollment Status Page (ESP) policy in Windows Autopilot can be configured to block device use until all required apps are installed. When a required app fails to install, the ESP enters a blocking state, preventing the user from accessing the desktop until the installation succeeds or the device is reset. This behavior is controlled by the 'Block device use until required apps are installed' setting in the ESP profile.

Exam trap

The trap here is that candidates often assume the ESP will automatically retry or extend the timeout, but the correct behavior is that the device is blocked indefinitely until the required app installs or the device is reset.

How to eliminate wrong answers

Option B is wrong because the ESP blocking state does not allow the user to manually retry the installation; the device remains blocked until the app installs or is reset. Option C is wrong because the ESP timeout extension (e.g., 60 minutes) applies only to the overall ESP timeout, not to a failed app installation; the blocking state persists indefinitely until resolved. Option D is wrong because the device does not automatically retry the installation; the ESP waits for the app to be installed via Intune management, but no automatic retry mechanism is triggered by the ESP itself.

62
MCQeasy

A company wants to prevent corporate data from being copied from managed apps to personal apps on iOS devices. Which Intune policy should the administrator configure?

A.Device configuration profile
B.Device compliance policy
C.App protection policy
D.Enrollment restrictions
AnswerC

App protection policies enforce data-transfer restrictions at the app layer, blocking cut, copy, and paste from managed apps to unmanaged personal apps on iOS. This directly satisfies the stem's requirement to prevent corporate data leakage between managed and personal apps, without needing device enrolment or MDM-level control.

Why this answer

App Protection Policies (APP) in Microsoft Intune are specifically designed to manage and protect corporate data within applications, regardless of the device enrollment state. On iOS, you can configure data transfer settings such as 'Allow app to transfer data to other apps' to restrict copying corporate data from managed apps to personal apps, using the iOS native inter-app control mechanisms like the Open-In management feature.

Exam trap

The trap here is that candidates often confuse App Protection Policies (which control data at the app layer) with Device Compliance Policies (which control device access), leading them to select the wrong option when the question focuses on data leakage prevention between apps.

How to eliminate wrong answers

Option A is wrong because Device Configuration Profiles are used to configure device settings (e.g., Wi-Fi, VPN, email) and enforce device-level restrictions, not to control data flow between apps at the application layer. Option B is wrong because Device Compliance Policies evaluate device health and security posture (e.g., jailbreak detection, minimum OS version) but do not govern inter-app data transfer policies. Option D is wrong because Enrollment Restrictions control which devices or users can enroll in Intune (e.g., platform allow/block, device type limits) and have no impact on data sharing behavior between apps after enrollment.

63
MCQeasy

You are investigating a malware incident on a Windows 10 device managed by Microsoft Intune and protected by Microsoft Defender for Endpoint. Which log should you analyze to determine the initial infection vector?

A.Microsoft Sysinternals Process Monitor logs.
B.Microsoft Intune compliance reports.
C.Windows Event Viewer logs on the device.
D.Microsoft Defender XDR incident investigation timeline.
AnswerD

Microsoft Defender XDR's incident investigation timeline correlates alerts, process trees and file events across endpoints, exposing the parent process and originating artefact that triggered the malware. This directly satisfies the stem's requirement to determine the initial infection vector, which raw Defender for Endpoint device timelines alone present without cross-signal correlation.

Why this answer

The Microsoft Defender XDR incident investigation timeline aggregates alerts, events, and forensic data from all Defender for Endpoint sensors across devices, providing a unified view of the attack chain. This timeline specifically surfaces the initial infection vector (e.g., malicious file, phishing link, or exploit) by correlating process creation, network connections, and file events at the moment of compromise, which is exactly what you need for malware incident analysis.

Exam trap

The trap here is that candidates often choose Windows Event Viewer (Option C) because they associate it with security auditing, but they fail to realize that the Defender XDR incident timeline is the centralized, cloud-native tool designed specifically for cross-device attack chain analysis in a managed environment.

How to eliminate wrong answers

Option A is wrong because Sysinternals Process Monitor logs are a local, real-time monitoring tool that captures file system, registry, and process/thread activity, but they are not centrally collected or retained by Intune or Defender for Endpoint for historical incident investigation; they require manual setup and are not part of the managed security solution. Option B is wrong because Intune compliance reports focus on device configuration compliance (e.g., OS version, encryption status, required apps) and do not contain security event logs or forensic data needed to trace an infection vector. Option C is wrong because Windows Event Viewer logs on the device (e.g., Security, System, or Microsoft-Windows-Windows Defender/Operational) are local and can be useful, but they lack the cross-device correlation, cloud-based retention, and automated attack chain reconstruction that the Defender XDR incident timeline provides; relying solely on Event Viewer would miss telemetry from other endpoints and cloud signals.

64
MCQmedium

A hospital uses Intune to manage Windows 10 devices used by doctors. The devices should automatically install critical updates from Windows Update for Business. Which type of policy should the administrator create?

A.Device compliance policy
B.App protection policy
C.Update rings for Windows 10
D.Device configuration profile (Update settings)
AnswerC

Update rings for Windows 10 define deferral, deadline and active-hours settings that control how Windows Update for Business delivers quality and feature updates. This is the Intune policy type that automates installation of critical updates on managed Windows 10 devices.

Why this answer

Update rings for Windows 10 are the correct policy type in Intune to manage when and how Windows 10 devices receive updates from Windows Update for Business. This policy allows you to configure deferral periods, pause updates, and set the update behavior (e.g., automatic installation of critical updates) without requiring on-premises WSUS or manual approval.

Exam trap

The trap here is that candidates confuse 'Device configuration profile (Update settings)' with the correct answer, because both can manage update behavior, but Update rings are the modern, recommended method in Intune for Windows 10 update management, while the legacy Update settings profile is deprecated and lacks features like pause and deferral granularity.

How to eliminate wrong answers

Option A is wrong because device compliance policies evaluate whether devices meet security requirements (e.g., encryption, antivirus) and trigger conditional access, but they do not control the installation of Windows updates. Option B is wrong because app protection policies manage how data is accessed and shared within mobile applications (e.g., Outlook, OneDrive) and do not affect operating system updates. Option D is wrong because while Device configuration profiles include update settings (e.g., 'Update settings' category), these are legacy settings that are less flexible and are superseded by Update rings for Windows 10, which provide granular control over Windows Update for Business policies.

65
MCQeasy

Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to ensure that BitLocker Drive Encryption is enabled on all devices and that the recovery keys are escrowed to Azure Active Directory (Azure AD). Which policy type should you use?

A.App protection policy
B.Security baseline
C.Device configuration profile for endpoint protection
D.Device compliance policy
AnswerC

A device configuration profile with the endpoint protection workload includes BitLocker settings. You can configure BitLocker to silently enable encryption and escrow recovery keys to Azure AD. This policy actively enforces the settings on the device. It is the correct choice to both enable BitLocker and ensure key escrow.

Why this answer

To enable BitLocker and escrow recovery keys to Azure AD, you should use a device configuration profile with the endpoint protection settings. This profile allows you to configure BitLocker to silently enable encryption and back up recovery keys to Azure AD. Compliance policies only check for encryption, and security baselines may not handle key escrow as directly.

App protection policies are unrelated.

Exam trap

The trap here is confusing compliance policies that check for BitLocker with configuration policies that actually enable and escrow keys.

66
MCQeasy

Your organization uses Microsoft Entra ID joined devices with Windows 10. You need to ensure that only compliant devices can access corporate email in Microsoft Outlook for Windows. Which integration should you enable?

A.Create a Conditional Access policy in Microsoft Entra ID requiring compliant devices for Exchange Online.
B.Enable App Protection Policies for Outlook for Windows.
C.Require all devices to be enrolled in Intune before accessing email.
D.Configure a compliance policy in Intune to mark devices as non-compliant if not updated.
AnswerA

Conditional Access enforces compliance at authentication, querying Intune device state before issuing tokens to Exchange Online. This satisfies the stem's requirement that only compliant devices reach corporate email, since Outlook for Windows authenticates against Microsoft Entra ID and the policy blocks non-compliant devices regardless of network location.

Why this answer

Creating a Conditional Access policy in Microsoft Entra ID that requires compliant devices for Exchange Online is the correct integration because it directly enforces device compliance as a condition for accessing corporate email. This policy evaluates the device's compliance status reported by Intune before granting access to Exchange Online, ensuring only compliant devices can use Outlook for Windows.

Exam trap

The trap here is that candidates confuse App Protection Policies (which protect data at the app level) with device compliance enforcement, or assume that Intune compliance policies alone block access without a Conditional Access policy to enforce them.

How to eliminate wrong answers

Option B is wrong because App Protection Policies (APP) for Outlook for Windows manage data protection at the app level (e.g., preventing copy/paste) but do not enforce device compliance; they are designed for unmanaged or BYOD scenarios. Option C is wrong because requiring all devices to be enrolled in Intune before accessing email is a prerequisite, not an integration that enforces compliance; it does not block non-compliant enrolled devices. Option D is wrong because configuring a compliance policy in Intune to mark devices as non-compliant if not updated is a compliance rule, but it does not integrate with access control; it requires a Conditional Access policy to enforce the block.

67
MCQhard

You manage Windows 11 devices with Microsoft Intune. You need to configure a policy that will automatically lock the screen after 5 minutes of inactivity and require a password to unlock. Which policy type should you use?

A.Endpoint protection profile with 'Local device security options'
B.Group Policy analytics profile
C.Device restrictions configuration profile
D.Compliance policy with 'Require a password to unlock mobile devices'
AnswerA

The Endpoint protection profile includes 'Local device security options' where you can configure interactive logon: Machine inactivity limit to 300 seconds (5 minutes) and require password on wakeup. This directly meets the requirement with precise control over screen lock timeout and password enforcement.

Why this answer

The Endpoint protection profile in Intune includes 'Local device security options' which allow you to configure the machine inactivity limit (screen lock timeout) and require a password on wakeup. Setting the inactivity limit to 300 seconds enforces a 5-minute lock, and the password requirement ensures unlock security. This is the most direct and supported method.

Exam trap

The trap here is assuming that a compliance policy can enforce settings; compliance policies only assess, while configuration profiles like Endpoint protection enforce.

68
Multi-Selecteasy

You need to configure Microsoft Defender for Endpoint on macOS devices. Which THREE components must be installed?

Select 3 answers
A.Microsoft Defender for Endpoint daemon
B.Microsoft Intune management extension
C.Configuration Manager client
D.Microsoft Defender for Endpoint kernel extension (or system extension)
E.Microsoft Defender for Endpoint user interface agent
AnswersA, D, E

The Microsoft Defender for Endpoint daemon provides the background scanning and protection service that macOS requires, satisfying the stem's demand for a mandatory component. Without this persistent service, real-time threat detection cannot run on the device, so it must be installed alongside the network extension and the application itself.

Why this answer

Microsoft Defender for Endpoint on macOS requires three core components: the Microsoft Defender for Endpoint daemon (wdavdaemon) (option A), which runs as a background service handling real-time protection, scanning, and communication with the cloud service; the Microsoft Defender for Endpoint kernel extension or system extension (option D), which provides the low-level hooks needed for file system monitoring and network protection on macOS; and the Microsoft Defender for Endpoint user interface agent (option E), which presents the menu bar app and notifications to the user. The Intune management extension (option B) is a Windows component used for PowerShell scripts and Win32 apps, not a Defender for Endpoint macOS requirement, and the Configuration Manager client (option C) is a Windows management agent that is not installed on macOS for this purpose.

Exam trap

The trap here is that candidates often confuse the macOS Defender components with Windows Defender components, mistakenly including Intune or ConfigMgr agents that are irrelevant to macOS deployments.

69
MCQeasy

Your organization uses Microsoft Intune to manage Android devices. You need to ensure that corporate data on these devices is protected in case the device is lost or stolen. You configure a compliance policy that requires device encryption and a device lock screen. However, you also want to be able to selectively wipe corporate data without wiping personal data. What should you do?

A.Enable remote lock on the device.
B.Configure a device compliance policy to wipe the device if non-compliant.
C.Use a device configuration profile to enable selective wipe.
D.Assign an app protection policy to the user for the corporate apps.
AnswerD

App protection policies apply at the application layer, enforcing encryption and access controls on corporate data within managed apps. This enables selective wipe of corporate data from those apps while leaving personal data on the device untouched, which device-level compliance policies cannot achieve.

Why this answer

App protection policies (APP) in Microsoft Intune provide the ability to selectively wipe corporate data from managed apps without affecting personal data on Android devices. This is achieved through the selective wipe action, which removes only the organization's data from apps that have the policy applied, leaving personal data intact. Compliance policies, as described in the scenario, enforce device-level settings like encryption and lock screen but do not offer granular data separation for selective wipe.

Exam trap

The trap here is that candidates often confuse device compliance policies (which enforce device-level security and can trigger full wipe) with app protection policies (which enable selective wipe of corporate data), leading them to choose option B or C instead of D.

How to eliminate wrong answers

Option A is wrong because remote lock only locks the device remotely, preventing unauthorized access but does not wipe any data, corporate or personal. Option B is wrong because configuring a device compliance policy to wipe the device if non-compliant performs a full device wipe, removing all data including personal data, which contradicts the requirement to selectively wipe only corporate data. Option C is wrong because device configuration profiles in Intune manage device settings (e.g., Wi-Fi, VPN, restrictions) and do not include a selective wipe capability; selective wipe is a feature of app protection policies, not configuration profiles.

70
MCQmedium

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that devices cannot access corporate email if they are rooted. What should you configure?

A.A device compliance policy with the 'Rooted devices' setting set to 'Block'.
B.An app protection policy that blocks jailbroken devices.
C.A Conditional Access policy that requires a compliant device.
D.A device configuration profile that disables USB debugging.
AnswerA

In an Intune compliance policy for Android Enterprise, the 'Rooted devices' setting can be set to 'Block'. When a device is detected as rooted, it is marked non-compliant. You can then use Conditional Access to block access to corporate email and other resources. This directly enforces the requirement.

Why this answer

To block rooted Android devices from accessing corporate email, you need a compliance policy that marks rooted devices as non-compliant. Then, a Conditional Access policy can enforce compliance for email access. The compliance policy setting 'Rooted devices' set to 'Block' is the key configuration.

Exam trap

The trap here is thinking that Conditional Access alone can detect rooted devices; it relies on compliance signals.

71
MCQmedium

You are reviewing an Intune endpoint protection profile for Windows 10. The exhibit shows a JSON snippet of the configuration. A user reports that a device detected malware with moderate severity, but the action taken was 'quarantine'. However, the desired action is 'clean'. Which setting should you modify?

A.defenderScheduleScanDay and defenderScheduleScanTime
B.A global setting to override all actions
C.defenderScanType
D.defenderDetectedMalwareActions for moderateSeverity
AnswerD

Modifying defenderDetectedMalwareActions for moderateSeverity directly controls the remediation action applied when Windows Defender Antivirus detects moderate-severity malware. The stem's constraint is that quarantine was applied instead of clean, so aligning this severity-specific action with the desired clean behaviour resolves the mismatch without affecting low, high, or severe thresholds.

Why this answer

The `defenderDetectedMalwareActions` setting in Intune endpoint protection profiles allows you to specify the remediation action for each threat severity level, including moderate. Since the user wants 'clean' instead of 'quarantine' for moderate severity threats, you must modify the `moderateSeverity` value within this setting. This is the only setting that controls per-severity remediation actions for Microsoft Defender Antivirus.

Exam trap

The trap here is that candidates confuse scan scheduling or scan type settings with remediation actions, or assume a single global action exists, when Microsoft Intune requires per-severity configuration via `defenderDetectedMalwareActions`.

How to eliminate wrong answers

Option A is wrong because `defenderScheduleScanDay` and `defenderScheduleScanTime` control when scheduled scans run, not the action taken on detected malware. Option B is wrong because there is no global override setting in Intune endpoint protection profiles that applies a single action to all threat severities; remediation actions are configured per severity level. Option C is wrong because `defenderScanType` defines the type of scan (e.g., quick, full) to perform, not the remediation action after detection.

72
Multi-Selectmedium

Which TWO actions should you take to ensure that only healthy Windows 10/11 devices can access Microsoft 365 services? (Choose two.)

Select 2 answers
A.Create a device compliance policy that includes health attestation checks
B.Configure Intune enrollment
C.Use Windows Autopilot to pre-provision devices
D.Deploy an app protection policy to M365 apps
E.Create a Conditional Access policy that requires compliant device
AnswersA, E

Health attestation in a Microsoft Entra ID compliance policy reports TPM-measured boot state, verifying Secure Boot, BitLocker and code integrity before granting access. This satisfies the stem's requirement that only healthy devices reach Microsoft 365 services, since non-compliant devices are blocked by Conditional Access.

Why this answer

Option A is correct because a device compliance policy in Microsoft Intune can include health attestation checks (e.g., BitLocker, Secure Boot, TPM, and code integrity via the Health Attestation Service), which determine whether a Windows 10/11 device meets the health and security baseline required to be marked compliant. Option E is correct because a Conditional Access policy that requires a compliant device enforces the compliance state at authentication time, blocking access to Microsoft 365 services from devices that are not marked compliant by Intune. Together, A defines what 'healthy' means and E enforces it for M365 access.

Option B is not correct on its own because Intune enrollment is a prerequisite for compliance evaluation but does not itself ensure only healthy devices can access M365 services. Option C is not correct because Windows Autopilot only pre-provisions and configures devices; it does not gate access based on device health. Option D is not correct because app protection policies (MAM) protect app data on unmanaged or managed devices but do not enforce device health attestation for M365 service access.

Exam trap

The trap here is that candidates confuse device enrollment (Option B) or provisioning (Option C) with ongoing health verification, but neither ensures the device remains healthy at the time of access; only the combination of a compliance policy with attestation checks and a Conditional Access policy that requires compliant device enforces this at authentication time.

73
MCQhard

You manage a set of Windows 11 devices with Microsoft Intune. You need to configure attack surface reduction (ASR) rules to block Office applications from creating child processes. You want to ensure the rules are enforced and cannot be bypassed by users. Which Intune profile type should you use?

A.Devices > Compliance policies
B.Endpoint security > Attack surface reduction policy
C.Devices > Configuration profiles > Templates > Endpoint protection
D.Devices > Configuration profiles > Templates > Custom
AnswerB

The Attack surface reduction policy under Endpoint security in Intune is specifically designed to configure and enforce ASR rules. It provides a streamlined interface to set rules to Block, Audit, or Warn. When set to Block, the rules are enforced by Defender Antivirus and cannot be disabled by users, meeting the requirement.

Why this answer

The Attack surface reduction policy in Intune is the correct choice for configuring ASR rules. It provides a dedicated, user-friendly interface to set rules to Block, Audit, or Warn. When set to Block, the rules are enforced by Defender Antivirus and cannot be overridden by users, ensuring the desired protection.

Exam trap

The trap here is assuming that any configuration profile that mentions ASR or endpoint protection will suffice, but the dedicated Attack surface reduction policy is the only one that provides full enforcement and management.

74
MCQeasy

Refer to the exhibit. You deploy this custom OMA-URI policy to Windows 10 devices. What is the expected outcome?

A.Telemetry is set to 1 - Basic
B.The policy applies to users, not devices
C.The policy fails because value 0 is not allowed
D.Telemetry is set to 0 - Security (Enterprise only)
AnswerD

The OMA-URI value 0 maps to the Security telemetry level, the minimum setting that sends only security-related data. This level is restricted to Enterprise editions, so Windows Pro devices would not apply it, matching the stated Enterprise-only constraint.

Why this answer

The OMA-URI policy sets the 'AllowTelemetry' value to 0, which in Windows 10 corresponds to the 'Security (Enterprise only)' telemetry level. This level sends only essential security data, such as the Malicious Software Removal Tool (MSRT) and Windows Defender information, and is only available in Enterprise editions. Therefore, the expected outcome is that telemetry is set to 0 - Security (Enterprise only).

Exam trap

A common misconception is that setting telemetry to 0 causes policy failure on non-Enterprise editions. However, the policy applies successfully; the setting is simply ignored on editions that do not support it.

How to eliminate wrong answers

Option A is wrong because the policy explicitly sets the value to 0, not 1; value 1 corresponds to 'Basic' telemetry, which includes limited diagnostic data. Option B is wrong because OMA-URI policies for Windows 10 device configuration are applied at the device level via MDM, not per user; the policy targets the device CSP (Policy/Config/System/AllowTelemetry). Option C is wrong because value 0 is a valid and allowed integer for the AllowTelemetry policy in Windows 10 Enterprise editions; it is not a failure condition, though it may be ignored on non-Enterprise editions.

75
MCQeasy

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to create a compliance policy that requires devices to have a firewall enabled. Which setting should you configure?

B.Antivirus
C.Require a password to unlock mobile devices
D.Require BitLocker
AnswerA

The Firewall setting in a Windows compliance policy checks whether the Windows Firewall is enabled on the device. Configuring this setting to 'Require' ensures devices with the firewall disabled are marked non-compliant, directly fulfilling the requirement.

Why this answer

The Firewall setting in a Windows compliance policy specifically evaluates whether Windows Firewall is enabled. Setting it to 'Require' ensures devices without an active firewall are non-compliant, directly satisfying the scenario's requirement.

Exam trap

The trap here is confusing firewall with other security settings like antivirus or BitLocker, which are related but do not enforce firewall enablement.

Page 1 of 2 · 88 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Protect Devices questions.