Topic 4: Mix Question
You have a Microsoft 365 subscription that contains 500 Android Enterprise devices.
All the devices are enrolled in Microsoft Intune.
You need to deliver bookmarks to the Chrome browser on the devices. What should you create?
A.
a compliance policy
B.
a configuration profile
C.
an app protection policy
D.
an app configuration policy
an app configuration policy
Your company uses Microsoft Intune to manage devices.
You need to ensure that only Android devices that use Android work profiles can enroll in intune.
Which two configurations should you perform in the device enrollment restrictions? Each correct answer presents part of the solution.
NOTE Each correct selection is worth one point.
A.
From Platform Settings, set Android device administrator Personally Owned to Block.
B.
From Platform Settings, set Android Enterprise (work profile) to Allow.
C.
From Platform Settings, set Android device administrator Personally Owned to Allow
D.
From Platform Settings, set Android device administrator to Block.
From Platform Settings, set Android device administrator Personally Owned to Block.
From Platform Settings, set Android Enterprise (work profile) to Allow.
Explanation: To ensure that only Android devices that use Android work profiles can enroll in Intune, you need to perform two configurations in the device enrollment restrictions. First, you need to set Android device administrator Personally Owned to Block. This prevents users from enrolling personal Android devices that use device administrator mode. Second, you need to set Android Enterprise (work profile) to Allow. This allows users to enroll corporate-owned or personal Android devices that use work profiles.
References:
https://docs.microsoft.com/en-us/mem/intune/enrollment/enrollment-restrictions-set
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain. The domain contains a computer named Computer1 that runs Windows 8.1.
Computer1 has apps that are compatible with Windows 10.
You need to perform a Windows 10 in-place upgrade on Computer1.
Solution: You copy the Windows 10 installation media to a Microsoft Deployment Toolkit (MDT) deployment share. You create a task sequence, and then you run the MDT deployment wizard on Computer1.
Does this meet the goal?
A.
Yes
B.
No
No
You have a Microsoft 365 subscription.
You plan to enroll devices in Microsoft Endpoint Manager that have the platforms and versions shown in the following table.
You have an Azure AD tenant named contoso.com that contains the users shown in the following table.
You install a feature update on a computer that runs Windows 10.
How many days do you have to roll back the update?
A.
5
B.
10
C.
14
D.
30
10
You manage 1.000 devices by using Microsoft Intune. You review the Device compliance trends report. For how long will the report display trend data?
A.
30 days
B.
60 days
C.
90 days
D.
365 days
60 days
Explanation: The Device compliance trends report shows the number of devices that are compliant, noncompliant, and not evaluated over time. The report displays trend data for the last 60 days by default, but you can change the time range to view data for the last 7, 14, or 30 days as well. The report does not show data for more than 60 days. References: [Device compliance trends report]
Your network contains an Active Directory domain named contoso.com. The domain contains a computer named Computer1 that runs Windows 10. You have the groups shown in the following table.
Which groups can you add to Group4?
A.
Group2only
B.
Group1 and Group2 only
C.
Group2 and Group3 only
D.
Group1, Group2, and Group3
Group2 and Group3 only
Your network contains an on-premises Active Directory Domain Services (AD DS) domain
that syncs with an Azure AD tenant.
You have a Microsoft 365 subscription
You plan to use Windows Autopilot to deploy new Windows devices.
You plan to create a deployment profile.
You need to ensure that The deployment meets the following requirements:
• Devices must be joined to AD DS regardless of their current working location.
• Users in the marketing department must have a Iine-of-business (LOB) app installed during the deployment.
The solution must minimize administrative effort.
What should you do for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
You have a Microsoft 365 subscription that includes Microsoft Intune.
You need to implement a Microsoft Defender for Endpoint solution that meets the following requirements:
• Enforces compliance for Defender for Endpoint by using Conditional Access
• Prevents suspicious scripts from running on devices
What should you configure? To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
You have a Microsoft 365 tenant that uses Microsoft Intune and contains the devices shown in the following table.
You have a Microsoft 365 subscription.
All computers are enrolled in Microsoft Intune.
You have business requirements for securing your Windows 11 environment as shown in the following table.
Page 8 out of 27 Pages |
Previous |