Brilliant MD-102 Exam Dumps Get MD-102 Dumps PDF [Q300-Q325]

Share

Brilliant MD-102 Exam Dumps Get MD-102 Dumps PDF

MD-102 Dumps PDF - MD-102 Real Exam Questions Answers

NEW QUESTION # 300
You have 100 computers that run Windows 10.
You plan to deploy Windows 11 to the computers by performing a wipe and load installation.
You need to recommend a method to retain the user settings and the user data.
Which three actions should you recommend be performed in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

1 - Create a system image backup.
2 - Deploy Windows 11.
3 - Restore a system image backup.


NEW QUESTION # 301
Hotspot Question
You have a Microsoft 365 subscription that uses Microsoft Intune and contains 100 Windows 10 devices.
You need to create Intune configuration profiles to perform the following actions on the devices:
- Deploy a custom Start layout.
- Rename the local Administrator account.
Which profile template should you use for each action? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Device restriction
Customize Start Menu Custom & Taskbar
Here is a quick step-by-step guide to help you to deploy the prepared XML file. This Intune policy helps to customize the start menu and taskbar for Windows 10 devices.
Logon to Microsoft Endpoint Manager Portal.
Navigate to Devices -> Windows -> Configuration Profiles.
Select Platform -> Windows 10 and later.
Select Profile Type -> Template.
Search with "device" and select Device Restrictions.
Click on Create button.
Box 2: Endpoint protection
Reference:
https://www.anoopcnair.com/start-menu-taskbar-custom-layout-intune-cloudpc/
https://docs.microsoft.com/en-us/mem/intune/protect/identity-protection-configure


NEW QUESTION # 302
You have a Microsoft Intune subscription.
You are creating a Windows Autopilot deployment profile named Profile1 as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 303
You need to meet the technical requirements for the iOS devices.
Which object should you create in Intune?

  • A. A Deployment profile
  • B. A compliance policy
  • C. An app protection policy
  • D. A device configuration profile

Answer: D

Explanation:
Explanation
References:
https://docs.microsoft.com/en-us/intune/device-restrictions-configure
https://docs.microsoft.com/en-us/intune/device-restrictions-ios


NEW QUESTION # 304
You have a Microsoft 365 Business Standard subscription and 100 Windows 10 Pro devices.
You purchase a Microsoft 365 E5 subscription.
You need to upgrade the Windows 10 Pro devices to Windows 10 Enterprise. The solution must minimize administrative effort.
Which upgrade method should you use?

  • A. an in-place upgrade by using Windows installation media
  • B. Windows Autopilot
  • C. a Microsoft Deployment Toolkit (MDT) lite-touch deployment
  • D. Subscription Activation

Answer: D

Explanation:
Explanation
Subscription Activation is a feature that allows you to upgrade from Windows 10 Pro or Windows 11 Pro to Windows 10 Enterprise or Windows 11 Enterprise without needing a product key or reinstallation. You just need to assign a subscription license (such as Microsoft 365 E5) to the user in Azure AD, and then sign in to the device with that user account. The device will automatically activate Windows Enterprise edition using the firmware-embedded activation key for Windows Pro edition. This method minimizes administrative effort and simplifies the upgrade process. References: Windows subscription activation, Deploy Windows Enterprise licenses


NEW QUESTION # 305
Hotspot Question
Your company has computers that run Windows 10. The employees at the company use the computers.
You plan to monitor the computers by using the Update Compliance solution.
You create the required resources in Azure.
You need to configure the computers to send enhanced Update Compliance data.
Which two Group Policy settings should you configure? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Configure the Commercial ID
All Group policies that need to be configured for Update Compliance are under Computer Configuration>Administrative Templates>Windows Components\Data Collection and Preview Builds. All of these policies must be in the Enabled state and set to the defined Value below.
* Configure the Commercial ID
Identifies the device as belonging to your organization.
Box 2: Allow device name to be sent in Windows diagnostic data
* Allow device name to be sent in Windows diagnostic data
Allows device name to be sent for Windows Diagnostic Data. If this policy is Not Configured or Disabled, Device Name will not be sent and will not be visible in Update Compliance, showing # instead.
Reference:
https://docs.microsoft.com/en-us/windows/deployment/update/update-compliance-configuration- manual


NEW QUESTION # 306
Your company has a Microsoft 365 E5 tenant.
All the devices of the company are enrolled in Microsoft Intune.
You need to create advanced reports by using custom queries and visualizations from raw Microsoft Intune data.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

Explanation:


NEW QUESTION # 307
Your network contains an Active Directory domain named contoso.com. The domain contains two computers named Computer! and Computer2 that run Windows 10. On Computer1, you need to run the Invoke-Command cmdlet to execute several PowerShell commands on Computed. What should you do first?

  • A. On Computed, add Computer! to the Remote Management Users group.
  • B. On Computed, run the Enable-PSRemoting cmdlet.
  • C. From Active Directory, configure the Trusted for Delegation setting for the computer account of Computed.
  • D. On Computer1, run the HcK-PSSession cmdlet.

Answer: B


NEW QUESTION # 308
You have a Microsoft 365 subscription that contains 1,000 Windows 11 devices enrolled in Microsoft Intune.
You plan to create and monitor the results of a compliance policy used to validate the BIOS version of the devices.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

1 - Create a PowerSheel discovery script and a JSON file.
2 - Upload the PowerShell script to Intune.
3 - Upload the JSON file to Azure AD.
4 - Create and assign a custom compliance policy.


NEW QUESTION # 309
You have a Microsoft 365 E5 subscription that contains the devices shown in the following table.

All devices have Microsoft Edge installed.
From the Microsoft Intune admin center, you create a Microsoft Edge Baseline profile named Edge1.
You need to apply Edge1 to all the supported devices.
To which devices should you apply Edge1?

  • A. Device1, Device2, Device3, and Device4
  • B. Device1 and Device2 only
  • C. Device1 only
  • D. Device1, Device2, and Device4 only
  • E. Device1, Device2, and Device3 only

Answer: B


NEW QUESTION # 310
You have an Azure Active Directory group named Group1. Group1 contains two Windows 10 Enterprise devices named Device1 and Device2.
You create a device configuration profile named Profile1. You assign Profile1 to Group1.
You need to ensure that Profile1 applies to Device1 only.
What should you modify in Policy1?

  • A. Applicability Rules
  • B. Assignments
  • C. Scope (Tags)
  • D. Settings

Answer: B

Explanation:
You create a profile, and it includes all the settings you entered. The next step is to deploy or
"assign" the profile to your user or device groups. When it's assigned, the users and devices receive your profile, and the settings you entered are applied.
Reference:
https://docs.microsoft.com/en-us/mem/intune/configuration/device-profile-assign


NEW QUESTION # 311
You have a server named Server1 and computers that run Windows 8.1. Server1 has the Microsoft Deployment Toolkit (MDT) installed.
You plan to upgrade the Windows 8.1 computers to Windows 10 by using the MDT deployment wizard.
You need to create a deployment share on Server1.
What should you do on Server1, and what are the minimum components you should add to the MDT deployment share? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/windows/deployment/deploy-windows-mdt/create-a-windows-10-reference-image


NEW QUESTION # 312
Your network contains an Active Directory domain. The functional level of the forest and the domain is Windows Server 2012 R2.
The domain contains 500 computers that run Windows 10. All the computers are managed by using Microsoft System Center 2012 R2 Configuration Manager.
You need to enable co-management.
What should you do first?

  • A. Upgrade Configuration Manager to Current Branch.
  • B. Raise the forest functional level.
  • C. Raise the domain functional level.
  • D. Deploy the Microsoft Intune client.

Answer: A

Explanation:
Co-management enables you to concurrently manage Windows 10 devices by using both Configuration Manager and Microsoft Intune. It lets you cloud-attach your existing investment in Configuration Manager by adding new functionality.
Windows 10 device has the Configuration Manager client and is enrolled to Intune, you get the benefits of both services.
https://docs.microsoft.com/en-us/configmgr/comanage/overview#prerequisites


NEW QUESTION # 313
You have a Windows 10 device named Computer1 enrolled in Microsoft Intune.
You need to configure Computer1 as a public workstation that will run a single customer-facing, full-screen application.
Which template should you use to create a configuration profile for Computer1 in the Microsoft Endpoint Manager admin center?

  • A. Shared multi-user device
  • B. Kiosk
  • C. Device restrictions
  • D. Endpoint protection

Answer: B


NEW QUESTION # 314
You have a Microsoft 365 subscription that contains the devices shown in the following table.

You plan to enroll the devices in Microsoft Intune.
How often will the compliance policy check-ins run after each device is enrolled in Intune? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Box 1: Every three minutes for 15 minutes, then every 15 minutes for two hours, and then around every eight hours If devices recently enroll, then the compliance, non-compliance, and configuration check-in runs more frequently. The check-ins are estimated at:
Windows 10: Every 3 minutes for 15 minutes, then every 15 minutes for 2 hours, and then around every 8 hours Graphical user interface, text, application, email Description automatically generated

Box 2: Every 15 minutes for one hour, and then every eight hours
iOS/iPadOS: Every 15 minutes for 1 hour, and then around every 8 hours
Reference: https://docs.microsoft.com/en-us/mem/intune/configuration/device-profile-troubleshoot


NEW QUESTION # 315
Your network contains an Active Directory named contoso.com. The domain contains two computers named Computer1 and Computer2 that run Windows 10.
Folder Redirection is configured for a domain user named User1. The AppData\Roaming folder and the Desktop folder are redirected to a network share.
User1 signs in to Computer1 and performs the following tasks:
- Configures screen saver to start after five minutes of inactivity
- Modifies the default save location for Microsoft Word
- Creates a file named File1.docx on the desktop
- Modifies the desktop background
You need to identify what will be retained when User1 signs in to Computer2.
What should you identify?

  • A. File1.docx only
  • B. File1.docx and the desktop background only
  • C. File1.docx, the screen saver settings, the desktop background, and the default save location for Word
  • D. File1.docx, the desktop background, and the default save location for Word only

Answer: A

Explanation:
User selected Desktop background, user nominated default word save location and user screen saver settings are all stored in under the user based registry (ie NTuser.dat) NTUSER.DAT is not stored under the user APPDATA folder but under the users local profile.
Roaming profiles are not stated as being enabled in domain so must assume they are not active and therefore NTUser.dat will not roam to server and to other logged on computers. That means user registry settings will not move from one computer to another when user logs onto another computer.
As stated the desktop folder is being redirected and applied to domain user named user1 which must have been done using AD Group Policies. The Redirected Folder Group Policy will apply to both Computer1 and Computer2 at logon time.
https://docs.microsoft.com/en-us/windows-server/storage/folder-redirection/folder-redirection-rup- overview


NEW QUESTION # 316
You have a Microsoft 365 subscription.
All users have Microsoft 365 apps deployed.
You need to configure Microsoft 365 apps to meet the following requirements:
* Enable the automatic installation of WebView2 Runtime.
* Prevent users from submitting feedback.
Which two settings should you configure in the Microsoft 365 Apps admin center? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
D:\mudassar\Untitled.jpg

You can enable automatic installation in the same setting as where you prevent it from being installed automatically:
To prevent the automatic installation of WebView2 Runtime, sign in to the Microsoft 365 Apps admin center (https://config.office.com) with an admin account. Then, go to Customization > Device Configuration > Modern Apps Settings. Select Microsoft Edge WebView2 and then clear the Enable automatic installation of WebView2 Runtime check box.
https://learn.microsoft.com/en-us/deployoffice/webview2-install
Prevent users from submitting feedback:
https://learn.microsoft.com/en-us/microsoft-365/admin/manage/manage-feedback-ms-org?view=o365-worldwid


NEW QUESTION # 317
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain. The domain contains a computer named Computer1 that runs Windows 8.1.
Computer1 has apps that are compatible with Windows 10.
You need to perform a Windows 10 in-place upgrade on Computer1.
Solution: You copy the Windows 10 installation media to a Microsoft Deployment Toolkit (MDT) deployment share. You create a task sequence, and then you run the MDT deployment wizard on Computer1.
Does this meet the goal?

  • A. No
  • B. Yes

Answer: B

Explanation:
https://learn.microsoft.com/en-us/windows/deployment/deploy-windows-mdt/upgrade-to-windows-
10-with-the-microsoft-deployment-toolkit


NEW QUESTION # 318
You have a Microsoft 365 subscription that contains the devices shown in the following table.

You plan to enroll the devices in Microsoft Intune.
How often will the compliance policy check-ins run after each device is enrolled in Intune? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Every three minutes for 15 minutes, then every 15 minutes for two hours, and then around every eight hours If devices recently enroll, then the compliance, non-compliance, and configuration check-in runs more frequently. The check-ins are estimated at:
Windows 10: Every 3 minutes for 15 minutes, then every 15 minutes for 2 hours, and then around every 8 hours Graphical user interface, text, application, email Description automatically generated

Box 2: Every 15 minutes for one hour, and then every eight hours
iOS/iPadOS: Every 15 minutes for 1 hour, and then around every 8 hours
Reference: https://docs.microsoft.com/en-us/mem/intune/configuration/device-profile-troubleshoot


NEW QUESTION # 319
You have a Microsoft 365 subscription that contains 1,000 iOS devices and includes Microsoft Intune. You need to prevent the printing of corporate data from managed apps on the devices, should you configure?

  • A. an app configuration policy
  • B. an app protection policy
  • C. an iOS app provisioning profile
  • D. a security baseline

Answer: B

Explanation:
Explanation
An app protection policy is a set of rules that controls how data is accessed and handled by managed apps on mobile devices. App protection policies can prevent the printing of corporate data from managed apps on iOS devices by using the Restrict cut, copy, and paste with other apps setting. This setting can be configured to block printing from the iOS share menu. An app configuration policy is used to customize the behavior of a managed app, such as specifying a VPN profile or a web link. A security baseline is a collection of recommended security settings for Windows 10 devices that are managed by Intune. An iOS app provisioning profile is a file that contains information about the app's identity, entitlements, and distribution method


NEW QUESTION # 320
You have an Azure AD tenant that contains the users shown in the following table.

You have the devices shown in the following table.

You have a Conditional Access policy named CAPolicy1 that has the following settings:
* Assignments
o Users or workload identities: User 1. User1
o Cloud apps or actions: Office 365 Exchange Online
o Conditions: Device platforms: Windows, iOS
* Access controls
o Grant Require multi-factor authentication
You have a Conditional Access policy named CAPolicy2 that has the following settings:
Assignments
o Users or workload identities: Used, User2
o Cloud apps or actions: Office 365 Exch
o Conditions
* Device platforms: Android, iOS
* Filter for devices
* Device matching the rule: Exclude filtered devices from policy
* Rule syntax: device. displayName- contains "1"
* Access controls
* Grant Block access
For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Answer:

Explanation:


NEW QUESTION # 321
Drag and Drop Question
You have a Microsoft Intune subscription that is configured to use a PFX certificate connector to an on- premises Enterprise certification authority (CA).
You need to use Intune to configure autoenrollment for Android devices by using public key pair (PKCS) certificates.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

Explanation:
Step 1: Obtain the root certificate.
Export the root certificate from the Enterprise CA.
To authenticate a device with VPN, WiFi, or other resources, a device needs a root or intermediate CA certificate.
Step 2: From the Microsoft Endpoint Manager admin center, create a trusted certificate profile Create a trusted certificate profile
1. Sign in to the Microsoft Endpoint Manager admin center.
2. Select and go to Devices > Configuration profiles > Create profile.
3. Enter the following properties:
Platform:
Profile: Select Trusted certificate. Or, select Templates > Trusted certificate.
Select Create.
4. Etc.
Step 3: From the Microsoft Endpoint Manager admin center, create a PKCS certificate profile Create a PKCS certificate profile
1. Sign in to the Microsoft Endpoint Manager admin center.
2. Select and go to Devices > Configuration profiles > Create profile.
3. Enter the following properties:
Platform:
Profile: Select PKCS certificate. Or, select Templates > PKCS certificate.
Select Create.
4. Etc.
Reference:
https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure


NEW QUESTION # 322
You have a Microsoft 365 ES subscription that uses Microsoft Intune.
Devices are enrolled in Intune as shown in the following table.

The devices are the members of groups as shown in the following table.

You create an JOS/iPadOS update profile as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 323
Your on-premises network contains an Active Directory Domain Services (AD DS) domain.
You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains five virtual machines and is NOT connected to the on-premises network.
You have a Microsoft 365 subscription that uses Microsoft Intune Suite.
You purchase Windows 365 Enterprise licenses.
You need to deploy Cloud PC. The solution must meet the following requirements:
* All users must be able to access their Cloud PC at any time without any restrictions.
* The users must be able to connect to the virtual machines on VNet1.
How should you configure the provisioning policy for Windows 365? To answer, drag the appropriate options to the correct settings. Each option may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 324
Your network contains an Active Directory domain. The domain contains 10 computers that run Windows 10. Users in the finance department use the computers.
You have a computer named Computer1 that runs Windows 10.
From Computer1, you plan to run a script that executes Windows PowerShell commands on the finance department computers.
You need to ensure that you can run the PowerShell commands on the finance department computers from Computer.
What should you do on the finance department computers?

  • A. From the local Group Policy, enable the Allow Remote Shell Access setting.
  • B. From the local Group Policy, enable the Turn on Script Execution setting.
  • C. From Windows PowerShell, run the Enable-PSRemoting cmdlet.
  • D. From Windows PowerShell, run the Enable-MMAgent cmdlet.

Answer: C


NEW QUESTION # 325
......

Valid MD-102 Test Answers & Microsoft MD-102 Exam PDF: https://certtree.2pass4sure.com/Microsoft-365-Certified/MD-102-actual-exam-braindumps.html