Microsoft MD-101 Managing Modern Desktops Online Training
Microsoft MD-101 Online Training
The questions for MD-101 were last updated at Dec 20,2024.
- Exam Code: MD-101
- Exam Name: Managing Modern Desktops
- Certification Provider: Microsoft
- Latest update: Dec 20,2024
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain. The domain contains member computers that run Windows 8.1 and are enrolled in Microsoft Intune.
You need to identify which computers can be upgraded to Windows 10.
Solution: From the Microsoft Endpoint Manager admin center, you create a device compliance policy and assign the policy to the computers. After 24 hours, you view the Device compliance report in Intune.
Does this meet the goal?
- A . Yes
- B . No
Your company has a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com. All users have computers that run Windows 10. The computers are joined to Azure AD and managed by using Microsoft Intune.
You need to ensure that you can centrally monitor the computers by using Windows Analytics.
What should you create in Intune?
- A . a device configuration profile
- B . a conditional access policy
- C . a device compliance policy
- D . an update policy
A
Explanation:
References: https://www.scconfigmgr.com/2019/03/27/windows-analytics-onboarding-with-intune/
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your company uses Windows Update for Business.
The research department has several computers that have specialized hardware and software installed.
You need to prevent the video drivers from being updated automatically by using Windows Update.
Solution: From the Device Installation and Restrictions settings in a Group Policy object (GPO), you enable Prevent installation of devices using drivers that match these device setup classes, and then you enter the device GUID.
Does this meet the goal?
- A . Yes
- B . No
B
Explanation:
References: https://www.stigviewer.com/stig/microsoft_windows_server_2012_member_server/2013-07-25/finding/WN12-CC-000024
You have a computer named Computer1 that runs Windows 10. Computer is used by a user named User1.
You need to ensure that when User1 opens websites from untrusted locations by using Microsoft Edge, Microsoft Edge runs in isolated container.
What should you do first?
- A . From Windows Features, turn on Windows Defender Application Guard.
- B . From Windows Security, configure the Device security settings.
- C . From Windows Security, configure the Virus & threat protection settings.
- D . From Windows Features, turn on Hyper-V Platform.
A
Explanation:
Reference:
https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-guard/wd-app-guard-overview
https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-guard/install-wd-app-guard
You have a Microsoft 365 subscription that contains 100 devices enrolled in Microsoft Intune.
You need to review the startup processes and how often each device restarts.
What should you use?
- A . Endpoint analytics
- B . Intune Data Warehouse
- C . Azure Monitor
- D . Device Management
You have a Microsoft Deployment Toolkit (MDT) deployment share.
You plan to deploy Windows 10 by using the Standard Client Task Sequence template.
You need to modify the task sequence to perform the following actions:
✑ Format disks to support Unified Extensible Firmware Interface (UEFI).
✑ Create a recovery partition.
Which phase of the task sequence should you modify?
- A . Initialization
- B . Install
- C . Postlnstall
- D . Preinstall
D
Explanation:
Reference: https://www.prajwaldesai.com/create-extra-partition-in-mdt/
HOTSPOT
Your company has computers that run Windows 10 and are Microsoft Azure Active Directory (Azure AD)-joined.
The company purchases an Azure subscription.
You need to collect Windows events from the Windows 10 computers in Azure. The solution must enable you to create alerts based on the collected events.
What should you create in Azure and what should you configure on the computers? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
HOTSPOT
You have a Microsoft 365 subscription that contains the devices shown in the following table.
You plan to enroll the devices in Microsoft Intune.
How often will the compliance policy check-ins run after each device is enrolled in Intune? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Explanation:
Box 1: Every three minutes for 15 minutes, then every 15 minutes for two hours, and then around every eight hours
If devices recently enroll, then the compliance, non-compliance, and configuration check-in runs more frequently. The check-ins are estimated at:
Windows 10: Every 3 minutes for 15 minutes, then every 15 minutes for 2 hours, and then around every 8 hours
Graphical user interface, text, application, email
Description automatically generated
Box 2: Every 15 minutes for one hour, and then every eight hours
iOS/iPadOS: Every 15 minutes for 1 hour, and then around every 8 hours
You have a Microsoft 365 tenant that contains the devices shown in the following table.
The devices are managed by using Microsoft Intune.
You create a compliance policy named Policy1 and assign Policy1 to Group1. Policy1 is configured to mark a device as Compliant only if the device security settings match the settings specified in the policy.
You discover that devices that are not members of Group1 are shown as Compliant.
You need to ensure that only devices that are assigned a compliance policy can be shown as Compliant. All other devices must be shown as Not compliant.
What should you do?
- A . From Tenant administration, modify the Diagnostic settings.
- B . From Device compliance, configure the Compliance policy settings.
- C . From Endpoint security, configure the Conditional access
- D . From Policy1, modify the actions for noncompliance.
B
Explanation:
Reference: https://docs.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started
HOTSPOT
You have a Microsoft 365 E5 subscription that contains a user named User1.
You need to perform the following tasks for User1:
✑ Set the Usage location to Canada.
✑ Configure the Phone and Email authentication contact info for self-service password reset (SSPR).
Which two settings should you configure in the Azure Active Directory admin center? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.
Explanation:
Graphical user interface, application
Description automatically generated