microsoft md-101 practice test

Managing Modern Desktops (beta)

Note: This exam has case studies

Question 1 Topic 7, Mixed Questions

You have a Microsoft 365 E5 subscription.
You need to download a report that lists all the devices that are NOT enrolled in Microsoft Intune and are assigned an app
protection policy.
What should you select in the Microsoft Endpoint Manager admin center?

  • A. Apps, and then App protection policies
  • B. Apps, and then Monitor
  • C. Devices, and then Monitor
  • D. Reports, and the Device compliance
Answer:

A

Explanation:
App report: You can search by platform and app, and then this report will provide two different app protection statuses that
you can select before generating the report. The statuses can be Protected or Unprotected.
Reference: https://docs.microsoft.com/en-us/mem/intune/apps/app-protection-policies-monitor

Discussions

Question 2 Topic 7, Mixed Questions

HOTSPOT
You have a Microsoft 365 subscription.
Users have iOS devices that are not enrolled in Microsoft 365 Device Management.
You create an app protection policy for the Microsoft Outlook app as shown in the exhibit. (Click the Exhibit tab.)

You need to configure the policy to meet the following requirements:
Prevent the users from using the Outlook app if the operating system version is less than 12.0.0. Require the users to


use an alphanumeric passcode to access the Outlook app.
What should you configure in an app protection policy for each requirement? To answer, select the appropriate options in the
answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Answer:

Explanation:
Reference: https://docs.microsoft.com/en-us/intune/app-protection-policy-settings-ios

Discussions

Question 3 Topic 7, Mixed Questions

HOTSPOT
Your network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD).
You have a Microsoft Office 365 subscription. All computers are joined to the domain and have the latest Microsoft OneDrive
sync client (OneDrive.exe) installed.
On all the computers, you configure the OneDrive settings as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in
the graphic.
NOTE: Each correct selection is worth one point.
Hot Area:

Answer:

Explanation:
Box 1:
Silently move known folders to OneDrive is enabled. Known folder include: Desktop, Documents, Pictures, Screenshots, and
Camera Roll
Box 2:
OneDrive Files On-Demand enables users to view, search for, and interact with files stored in OneDrive from within File
Explorer without downloading them and taking up space on the local hard drive.
Reference: https://docs.microsoft.com/en-us/onedrive/redirect-known-folders https://docs.microsoft.com/en-us/onedrive/plan-
onedrive-enterprise

Discussions

Question 4 Topic 7, Mixed Questions

You have devices enrolled in Microsoft Intune as shown in the following table.

You create an app protection policy named Policy1 that has the following settings:
Platform: Windows 10

Protected apps: App1

Exempt apps: App2

Network boundary: Cloud resources, IPv4 ranges

You assign Policy1 to Group1 and Group2. You exclude Group3 from Policy1.
Which devices will apply Policy1?

  • A. Device1, Device2, Device4, and Device5
  • B. Device1, Device4, and Device5 only
  • C. Device4 and Device5 only
  • D. Device1, Device3, Device4 and Device5
Answer:

C

Explanation:
Intune device configuration profiles let you include and exclude groups from profile assignment. Exclusion takes precedence
over inclusion in same group types.
Policy1 excludes Group3 and Group3 includes Device1, Device2, and Device3.
Incorrect Answers:
A, B, D: Device1, Device2, and Device3 are members of Group3. Policy1 excludes Group3. Exclusion takes precedence
over inclusion.
Reference:
https://docs.microsoft.com/en-us/mem/intune/configuration/device-profile-assign#exclude-groups-from-a-profile-assignment
https://docs.microsoft.com/en-us/intune/app-protection-policies

Discussions

Question 5 Topic 7, Mixed Questions

You have a Microsoft 365 subscription.
You need to deploy Microsoft 365 Apps for enterprise applications to Windows 10 devices.
What should you do first?

  • A. From Microsoft Azure Active Directory (Azure AD), create an app registration.
  • B. From the Endpoint Manager admin center, create an app.
  • C. From the Endpoint Manager admin center, create an app configuration policy.
  • D. From the Endpoint Manager admin center, enable Microsoft Store for Business synchronization.
Answer:

B

Explanation:
Reference: https://docs.microsoft.com/en-us/mem/intune/apps/apps-add-office365

Discussions

Question 6 Topic 7, Mixed Questions

You have a Microsoft 365 subscription.
You have 10 computers that run Windows 10 and are enrolled in mobile device management (MDM).
You need to deploy the Microsoft 365 Apps for enterprise suite to all the computers.
What should you do?

  • A. From the Endpoint Manager admin center, add an app.
  • B. From Microsoft Azure Active Directory (Azure AD), add an app registration.
  • C. From Microsoft Azure Active Directory (Azure AD), add an enterprise application.
  • D. From the Endpoint Manager admin center, create a Windows 10 device profile.
Answer:

C

Explanation:
Reference: https://docs.microsoft.com/en-us/windows/client-management/mdm/enterprise-app-management#application-
management-goals

Discussions

Question 7 Topic 7, Mixed Questions

You manage a Microsoft 365 environment that has co-management enabled.
All computers run Windows 10 and are deployed by using the Microsoft Deployment Toolkit (MDT).
You need to recommend a solution to deploy Microsoft Office 365 ProPlus to new computers. The latest version must always
be installed. The solution must minimize administrative effort.
What is the best tool to use for the deployment? More than one answer choice may achieve the goal. Select the BEST
answer.

  • A. Microsoft Intune
  • B. Microsoft Deployment Toolkit
  • C. Office Deployment Tool (ODT)
  • D. a Group Policy object (GPO)
  • E. Microsoft System Center Configuration Manager
Answer:

C

Explanation:
Reference: https://docs.microsoft.com/en-us/deployoffice/overview-of-the-office-2016-deployment-tool

Discussions

Question 8 Topic 7, Mixed Questions

HOTSPOT
Your company has a computer named Computer1 that runs Windows 10 Pro.
The company develops a proprietary Universal Windows Platform (UWP) app named App1. App1 is signed with a certificate
from a trusted certification authority (CA).
You need to sideload App1 to Computer1.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Answer:

Explanation:
Reference: https://www.windowscentral.com/how-enable-windows-10-sideload-apps-outside-store
https://docs.microsoft.com/en-us/windows/application-management/sideload-apps-in-windows-10

Discussions

Question 9 Topic 7, Mixed Questions

Your company has a main office and six branch offices. The branch offices connect to the main office by using a WAN link.
All offices have a local Internet connection and a Hyper-V host cluster.
The company has a Microsoft Endpoint Configuration Manager deployment. The main office is the primary site. Each branch
office has a distribution point.
All computers that run Windows 10 are managed by using both Configuration Manager and Microsoft Intune.
You plan to deploy the latest build of Microsoft Office 365 ProPlus to all the computers.
You need to minimize the amount of network traffic on the companys Internet links for the planned deployment.
What should you include in the deployment plan?

  • A. From Intune, configure app assignments for the Office 365 ProPlus suite. In each office, copy the Office 365 distribution files to a Microsoft Deployment Toolkit (MDT) deployment share.
  • B. From Intune, configure app assignments for the Office 365 ProPlus suite. In each office, copy the Office 365 distribution files to a Configuration Manager distribution point.
  • C. From Endpoint Configuration Manager, create an application deployment. Copy the Office 365 distribution files to a Configuration Manager cloud distribution point.
  • D. From Endpoint Configuration Manager, create an application deployment. In each office, copy the Office 365 distribution files to a Configuration Manager distribution point.
Answer:

D

Explanation:
Reference: https://docs.microsoft.com/en-us/deployoffice/deploy-office-365-proplus-with-system-center-configuration-
manager-2012r2#distribute-the-office-365-proplus-application-to-distribution-points-inconfiguration-manager

Discussions

Question 10 Topic 7, Mixed Questions

HOTSPOT
You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com. All Windows 10 devices have apps
named App1, App2 and App3 installed and are enrolled in Microsoft Intune.
You configure the following settings in Windows Information Protection (WIP):
Protected apps: App1

Exempt apps: App2

Windows Information Protection mode: Silent

App1, App2, and App3 use the same file format.
You create a file named File1 in App1.
You need to identify which apps can open File1.
What apps should you identify? To answer, select the appropriate options in the answer area, NOTE: Each correct selection
is worth one point.
Hot Area:

Answer:

Explanation:
Reference: https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/create-
wip-policy-using-intune https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-
protection/create-wip-policy-using-intune#exempt-apps-from-wip-restrictions

Discussions
To page 2