Courseiva

CCNA Protect Devices Questions

13 of 88 questions · Page 2/2 · Protect Devices topic · Answers revealed

76
MCQhard

You manage a fleet of Windows 10 devices with Microsoft Intune. You need to ensure that when a device is marked as noncompliant, it loses access to corporate email and Teams within 15 minutes. You have already configured a compliance policy and assigned it to all users. What should you do next to meet the requirement?

A.Configure a Conditional Access policy that requires compliant devices and set the grant control to require device compliance.
B.Configure a device compliance policy to automatically retire noncompliant devices after 15 minutes.
C.Configure an app protection policy that requires a PIN and blocks access to email and Teams on noncompliant devices.
D.Configure a Conditional Access policy that requires compliant devices and set the grant control to require multi-factor authentication.
AnswerA

A Conditional Access policy that requires compliant devices and uses the grant control 'Require device to be marked as compliant' will block access from devices that are not compliant. When a device becomes noncompliant, Intune marks it as such, and Conditional Access evaluates the device state. Access is typically blocked within minutes, meeting the 15-minute requirement. This is the correct approach to enforce compliance for access to corporate resources.

Why this answer

To block access to corporate resources like email and Teams when a device is noncompliant, you must use Conditional Access. A Conditional Access policy that requires the device to be marked as compliant will deny access if the device is not compliant. Intune updates the compliance status, and Conditional Access enforces it.

This typically takes effect within minutes, satisfying the 15-minute window. Other options do not provide the required enforcement.

Exam trap

The trap here is thinking that app protection policies or MFA can enforce device compliance; they cannot block access based on device compliance status.

77
MCQeasy

An administrator needs to ensure that only devices with a specific manufacturer are allowed to enroll in Intune. Which setting should the administrator configure?

A.Enrollment restrictions
B.Conditional Access policy
C.Device category
D.Device compliance policy
AnswerA

Enrollment restrictions can block devices by platform, manufacturer, etc.

Why this answer

Nrollment restrictions. Enrollment restrictions allow administrators to block devices based on manufacturer, OS version, or device platform. Conditional Access policies work after enrollment.

Device categories are for organizational grouping, not blocking enrollment. Device compliance policies evaluate device health after enrollment.

78
Multi-Selectmedium

Which THREE of the following are features of Microsoft Defender for Endpoint that help protect devices?

Select 3 answers
A.Attack surface reduction rules
B.Endpoint detection and response
C.Next-generation protection
D.Data loss prevention
E.Conditional access policies
AnswersA, B, C

Attack surface reduction rules block risky behaviours such as Office macros spawning child processes, script downloads and credential theft, satisfying the requirement for device protection features. They are enforced through Microsoft Defender for Endpoint policy and configuration profiles, hardening endpoints against common malware vectors without relying on signature detection alone.

Why this answer

Attack surface reduction rules (A) are a Defender for Endpoint feature that blocks risky behaviors such as Office macros spawning child processes or scripts launching executable content, thereby hardening the device against common attack vectors. Endpoint detection and response (B) provides behavioral monitoring, alert generation, investigation timelines, and automated remediation actions so security teams can detect and contain threats on endpoints. Next-generation protection (C) delivers cloud-delivered antivirus and antimalware capabilities, including real-time protection, behavior monitoring, and heuristics, to block malware at the device level.

Data loss prevention (D) is not a Defender for Endpoint device-protection feature; it is a separate Microsoft Purview/Compliance capability focused on preventing sensitive data exfiltration. Conditional access policies (E) are an identity and access control feature of Microsoft Entra ID, not a Defender for Endpoint device-protection capability.

Exam trap

The trap here is that candidates often confuse Data loss prevention (a compliance feature) with device protection features in Defender for Endpoint, or mistakenly think Conditional Access policies are part of Defender for Endpoint when they are actually an identity and access management feature in Microsoft Entra ID.

79
MCQmedium

You are deploying a new line-of-business app to 500 Windows 11 devices using Microsoft Intune. The app requires a specific PowerShell script to run after installation to configure registry settings. You need to ensure the script runs only after the app is successfully installed and that it does not require user interaction. What should you do?

A.Package the app and script together as a Win32 app with a custom installation command that runs the script after the installer.
B.Use a platform script that runs during device enrollment.
C.Add the PowerShell script as a dependency to the app.
D.Deploy the script using a separate PowerShell script policy and set it to run after the app is installed.
AnswerA

Packaging the app and script as a Win32 app allows you to define a custom installation command that can execute the installer followed by the PowerShell script. Intune runs the command as SYSTEM, and you can ensure the script runs only after successful installation by chaining commands with conditional execution. This meets the requirement without user interaction.

Why this answer

To run a PowerShell script after app installation without user interaction, you should package both as a Win32 app. The Win32 app deployment in Intune allows you to specify a custom installation command that can run the installer and then execute the script. This ensures the script runs in the system context after the app is installed.

Other methods like dependencies or separate script policies do not provide the required sequencing.

Exam trap

The trap here is assuming that Intune PowerShell script policies can be triggered by app installation events or that dependencies can be scripts, leading to unreliable sequencing.

80
MCQmedium

You manage Windows 11 devices with Microsoft Intune. Security requires that when a device is marked as noncompliant, access to Microsoft 365 services is blocked within 5 minutes, even if the user is already signed in. You configure a Conditional Access policy that requires a compliant device. What else must you configure to achieve this near-real-time enforcement?

A.Configure the Conditional Access policy to use 'Require device to be marked as compliant' and enable continuous access evaluation (CAE).
B.Decrease the compliance policy's 'Compliance status validity period' to 5 minutes.
C.Set the device compliance policy's action for noncompliance to 'Retire the device' immediately.
D.Set the compliance policy's 'Mark devices with no compliance policy assigned as' setting to 'Not compliant'.
AnswerA

Continuous access evaluation (CAE) enables near-real-time enforcement of Conditional Access policies by allowing Microsoft Entra ID to revoke access tokens when a device's compliance state changes, rather than waiting for token expiry. Combined with a compliant device requirement, CAE ensures that a noncompliant device is blocked within minutes, meeting the 5-minute requirement without user reauthentication.

Why this answer

Continuous access evaluation (CAE) is the feature that enables near-real-time enforcement of Conditional Access policies. When a device becomes noncompliant, Intune updates the device compliance state, and CAE allows Microsoft Entra ID to revoke access tokens immediately. Without CAE, access remains until token expiry, which can be up to an hour.

Therefore, enabling CAE alongside the compliant device requirement achieves the 5-minute block.

Exam trap

The trap here is assuming that shortening the compliance validity period or marking unassigned devices as noncompliant will speed up enforcement, when actually only continuous access evaluation provides near-real-time token revocation.

81
MCQeasy

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to prevent users from installing apps from unknown sources on their personally-owned work profile devices. Which configuration profile type should you use?

A.Custom
B.Endpoint protection
C.Device restrictions
D.Identity protection
AnswerC

For Android Enterprise personally-owned work profile devices, device restrictions profiles include settings to block installation of apps from unknown sources. This directly prevents sideloading and meets the requirement. Device restrictions are used to control features like camera, Bluetooth, and app installation sources on managed devices.

Why this answer

To prevent installation of apps from unknown sources on Android Enterprise personally-owned work profile devices, you should use a device restrictions profile. This profile type includes a setting under 'Work Profile Settings' or 'Device Settings' to block unknown sources. It is the built-in, recommended method.

Other profile types either do not apply to Android or do not have the specific setting.

Exam trap

The trap here is selecting a custom profile thinking it's needed for granular control, but Intune provides a built-in device restrictions setting for this exact purpose.

82
MCQeasy

Your company has 500 Windows 10 devices that are Hybrid Azure AD joined and managed by Microsoft Intune. You need to deploy a new line-of-business (LOB) app to all devices. The app is packaged as a .msi file. You create a new app in Intune and assign it to a device group containing all devices. After 24 hours, some devices report the app as 'Installed' but others show 'Failed'. You verify that the devices are online and have network connectivity. What should you do next to resolve the installation failures?

A.Use a PowerShell script to install the app on failed devices.
B.Check the Intune management extension logs on a failed device.
C.Create a new device group and assign the app again.
D.Re-assign the app to the device group.
AnswerB

MSI apps deploy through the Intune management extension on Windows, so its logs record the actual installation failure reason. Devices showing 'Failed' have the agent present, making these logs the correct diagnostic source for the error code.

Why this answer

The Intune management extension logs on a failed device contain detailed information about why the app installation failed, including error codes, detection rule failures, and installation command output. Since some devices succeeded and others failed with the same app and assignment, the issue is device-specific — checking the logs on a failed device is the correct next step to identify the root cause (e.g., missing dependency, detection rule mismatch, or installer error). This is the standard troubleshooting approach for Win32/MSI app deployment failures in Intune.

Exam trap

MD-102 often tests the difference between assignment issues and device-specific issues — candidates may jump to re-assigning or re-creating groups, but when some devices succeed and others fail with the same assignment, the problem is device-specific and requires log analysis, not assignment changes.

How to eliminate wrong answers

Option A is wrong because using a PowerShell script to install the app bypasses Intune's management and does not address the root cause — it also doesn't scale to hundreds of devices and may violate the requirement to deploy via Intune. Option C is wrong because creating a new device group and re-assigning the app does not change the underlying cause of the failure — the same devices would likely fail again, and it adds unnecessary administrative overhead. Option D is wrong because re-assigning the app to the same group will not fix the failure — the assignment is already correct since some devices installed successfully, so the issue is device-specific, not assignment-related.

83
MCQmedium

Your organization uses Microsoft Intune to manage iOS and Android devices. You have a compliance policy that requires a minimum OS version: iOS 16.0 and Android 12.0. You also have a Conditional Access policy that requires compliant devices. Several users report that they cannot access corporate email on their personal Android devices. The devices are Android 11.0. You need to allow these users to access email while ensuring that corporate data is protected. What should you do?

A.Remove the Conditional Access policy for these users.
B.Update the compliance policy to accept Android 11.0.
C.Create a Conditional Access policy that grants access but requires app protection policies and session controls.
D.Ask users to upgrade their devices to Android 12.0.
AnswerC

App protection policies with session controls let Android 11.0 devices reach email without meeting the OS-version compliance bar, because Conditional Access evaluates Intune app protection as a separate grant control rather than device compliance. Corporate data stays contained through encryption, selective wipe and copy/paste restrictions, satisfying the requirement to protect data on non-compliant personal devices.

Why this answer

It allows access from non-compliant devices while enforcing data protection through app protection policies (MAM) and session controls, such as limiting access to the web or approved apps. This balances security and usability. Option A is incorrect because removing the Conditional Access policy entirely would allow all devices, including those that are non-compliant, without any data protection.

Option B is incorrect because lowering the minimum OS version in the compliance policy weakens the security baseline and may not align with organizational requirements. Option D is incorrect because upgrading devices may not be immediately possible for all users, and the organization needs a solution that works with existing devices.

84
MCQhard

Refer to the exhibit. You deploy this endpoint protection configuration to a Windows 10 device. A user reports that they cannot connect to the device via RDP. What is the most likely cause?

A.The firewall rule 'Allow RDP' is configured to block traffic.
B.The firewall rule is for outbound traffic, not inbound.
C.The malware actions are blocking RDP traffic.
D.The firewall rule 'Allow RDP' is configured to allow traffic.
AnswerA

The endpoint protection configuration includes a firewall rule named 'Allow RDP' whose action is set to Block rather than Allow. This blocks inbound TCP 3389 traffic, preventing RDP connections even though the rule's name suggests otherwise.

Why this answer

The exhibit shows that the 'Allow RDP' firewall rule has its 'Action' set to 'Block', which overrides any other configuration. Windows Defender Firewall processes rules in order of priority, and a block action explicitly denies inbound RDP traffic (TCP port 3389), preventing any RDP connection to the device. This is the most direct cause of the user's inability to connect via RDP.

Exam trap

The trap here is that candidates assume a rule named 'Allow RDP' must permit traffic, overlooking the 'Action: Block' setting, which is the critical detail that reverses the rule's effect.

How to eliminate wrong answers

Option B is wrong because the firewall rule 'Allow RDP' is configured for inbound traffic (as indicated by the 'Direction: In' setting), not outbound; RDP connections to the device require inbound rules. Option C is wrong because malware actions (e.g., from Windows Defender Antivirus or Attack Surface Reduction) do not block RDP traffic unless specifically configured to do so, and the exhibit shows no such configuration; they focus on malicious behavior, not network connectivity. Option D is wrong because the rule is explicitly set to 'Block', not 'Allow', so stating it allows traffic contradicts the exhibited configuration.

85
MCQeasy

A company uses Microsoft Intune to manage Windows 11 devices. They want to ensure that only devices with a TPM 2.0 and Secure Boot enabled can access corporate resources in Microsoft Entra ID. What should they configure?

A.Configure Windows Hello for Business in Intune
B.Deploy an attack surface reduction rule in Microsoft Defender XDR
C.Use Windows Autopilot to enforce TPM and Secure Boot during provisioning
D.Create a Conditional Access policy that requires device compliance and a device compliance policy that checks TPM 2.0 and Secure Boot
AnswerD

Conditional Access enforces the access decision in Microsoft Entra ID, while the compliance policy evaluates TPM 2.0 and Secure Boot via device health attestation. Combining both satisfies the requirement that only compliant devices reach corporate resources.

Why this answer

Conditional Access policies in Microsoft Entra ID can require devices to be marked as compliant before granting access to corporate resources. A device compliance policy in Intune can be configured to check for TPM 2.0 and Secure Boot status on Windows 11 devices. Only when both conditions are met will the device be considered compliant, and the Conditional Access policy will enforce that compliance requirement, effectively blocking non-compliant devices from accessing corporate resources.

Exam trap

The trap here is that candidates often confuse provisioning-time enforcement (Autopilot) with runtime compliance enforcement (Conditional Access + compliance policy), mistakenly thinking Autopilot can block access after the device is in use.

How to eliminate wrong answers

Option A is wrong because Windows Hello for Business is an authentication method that uses biometrics or PINs, not a mechanism to enforce TPM 2.0 or Secure Boot as a compliance check for resource access. Option B is wrong because attack surface reduction rules in Microsoft Defender XDR are designed to block malicious behaviors (e.g., script execution, Office macro abuse), not to enforce hardware security features like TPM or Secure Boot for device compliance. Option C is wrong because Windows Autopilot is a provisioning tool that can apply settings during initial setup, but it does not enforce ongoing compliance checks or block access to corporate resources after provisioning; it cannot replace a Conditional Access policy that dynamically evaluates device compliance.

86
MCQmedium

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that all devices have a passcode of at least 6 characters and that devices are updated to the latest iOS version. You create a compliance policy. After assigning the policy, some devices are marked as non-compliant even though they have a passcode. What is the most likely cause?

A.The devices have multiple compliance policies applied.
B.iOS devices do not support compliance policies.
C.The devices have not checked in with Intune since the policy was assigned.
D.The policy was assigned to a user group instead of a device group.
AnswerC

Compliance state only refreshes when a device checks in with the Intune service. Until the device syncs and evaluates the newly assigned policy, it retains its previous status, so passcode-compliant devices can still appear non-compliant.

Why this answer

Intune compliance policies are evaluated only when devices check in with the service. If a device has not performed a check-in since the policy was assigned, it will not have received or evaluated the new policy, and its compliance status will remain based on the previous state. The check-in interval for iOS/iPadOS devices is typically every 8 hours, but can be forced manually by the user.

Until the device checks in, it cannot be marked compliant even if it meets the passcode and OS version requirements.

Exam trap

The trap here is that candidates assume compliance policies are evaluated immediately upon assignment, but Intune requires a device check-in to apply and evaluate the policy, and devices that haven't checked in will show as non-compliant even if they meet the requirements.

How to eliminate wrong answers

Option A is wrong because having multiple compliance policies does not inherently cause a device to be marked non-compliant; Intune evaluates all assigned policies and the device is compliant only if it meets all of them. Option B is wrong because iOS/iPadOS devices fully support compliance policies in Intune, including passcode and OS version requirements. Option D is wrong because assigning a compliance policy to a user group is the standard and supported method; Intune applies the policy to all devices owned by users in that group, and this does not cause false non-compliance.

87
Multi-Selecthard

You manage a hybrid Azure AD joined Windows 11 device with Microsoft Intune. You need to configure a device compliance policy that requires BitLocker drive encryption and Secure Boot to be enabled. Which two settings must you configure in the compliance policy? (Choose two.)

Select 2 answers
A.Require BitLocker
B.Require antivirus
C.Require code integrity
D.Require Trusted Platform Module (TPM)
E.Require Secure Boot to be enabled on the device
AnswersA, E

The 'Require BitLocker' setting in a Windows compliance policy checks whether BitLocker Drive Encryption is enabled on the device. If BitLocker is not enabled, the device is marked noncompliant. This setting directly enforces the requirement for drive encryption and is essential for meeting the scenario's security requirement.

Why this answer

To enforce BitLocker and Secure Boot, you must enable the corresponding settings in a Windows compliance policy. 'Require BitLocker' checks encryption status, and 'Require Secure Boot to be enabled on the device' verifies Secure Boot. The other settings address different security aspects and do not satisfy the requirements.

Exam trap

The trap here is confusing related security features like TPM or code integrity with the specific settings that directly enforce BitLocker and Secure Boot in a compliance policy.

88
MCQmedium

Your organization uses Microsoft Intune to manage Windows 11 devices. You need to ensure that only devices with a Trusted Platform Module (TPM) version 2.0 and Secure Boot enabled can access corporate email. What should you configure?

A.Create a compliance policy with device health rules.
B.Configure Windows Hello for Business with TPM requirement.
C.Create a conditional access policy that requires compliant device.
D.Create a device configuration policy to enable Secure Boot.
AnswerA

A compliance policy with device health rules evaluates TPM version and Secure Boot status through the device health attestation service. Conditional Access can then require compliant devices before granting Exchange Online access, satisfying the requirement to restrict corporate email.

Why this answer

Intune compliance policies include device health rules that can require specific hardware attributes such as TPM version and Secure Boot status. By creating a compliance policy with these device health requirements and then pairing it with a conditional access policy requiring a compliant device, you enforce that only devices meeting the TPM 2.0 and Secure Boot criteria can access corporate email. The compliance policy is the correct configuration object for defining these hardware requirements.

Exam trap

MD-102 often tests the confusion between configuration policies (which set device settings) and compliance policies (which evaluate and enforce device state) — candidates pick the configuration option because it mentions Secure Boot, missing that enforcement requires a compliance policy plus conditional access.

How to eliminate wrong answers

Option B is wrong because Windows Hello for Business with a TPM requirement governs authentication credential storage, not device access to corporate email — it does not enforce Secure Boot or gate email access based on device health. Option C is wrong because a conditional access policy requiring a compliant device is necessary but insufficient on its own — without a compliance policy defining TPM 2.0 and Secure Boot as requirements, there is nothing for the device to be compliant with. Option D is wrong because a device configuration policy enabling Secure Boot configures the setting but does not enforce it as an access condition for email — configuration and compliance are separate concerns in Intune.

← PreviousPage 2 of 2 · 88 questions total

Ready to test yourself?

Try a timed practice session using only Protect Devices questions.