Skip to content

70-697 Configuring Windows Devices Practice Questions

Prepare for 70-697 with more than an answer.

214 questions in the full set20 sample questionsUpdated Jan 24, 2026

Unlock the full exam and previous versions

  • v1Version 1 177 questions Locked
  • 70-697Legacy Configuring Windows Devices 214 questions Current
  • 98-349Legacy Windows Operating System Fundamentals 50 questions Locked
  • MD-100Legacy Windows Client 48 questions Locked
  • MD-101Legacy Managing Modern Desktops 50 questions Locked
Exam fee
$165 USD
Time limit
120 minutes
Questions on the exam
40-60
Passing score
700 (scale 100-1000)
Level
MCSA
Valid for
N/A - Retired certification
Domains covered on the exam 7
  1. Manage identity15%
  2. Plan desktop and device deployment15%
  3. Plan and implement a Microsoft Intune device management solution25%
  4. Configure networking15%
  5. Configure storage10%
  6. Manage data access and protection10%
  7. Manage remote access10%
  1. 1

    A user with a Windows 10 laptop that is part of an Active Directory domain needs to encrypt a 64 GB USB 3.0 flash drive to transport sensitive project files. The company policy requires that the drive be accessible on both Windows 10 and Windows 7 computers, and that a recovery key be stored in Active Directory. The user's laptop has a TPM 1.2 chip. Which tool and configuration should be used?

    Show answer details

    Correct answer: C

    BitLocker To Go is the correct feature for encrypting removable drives. To ensure compatibility with Windows 7, a password is the appropriate unlock method. The TPM on the host laptop is irrelevant for BitLocker To Go. A correctly configured Group Policy Object (GPO) is required to ensure the recovery key is automatically backed up to Active Directory Domain Services (AD DS).

  2. 2

    A company is implementing a BYOD (Bring Your Own Device) policy for employees who use their personal iOS and Android devices to access corporate email and documents. The company uses Microsoft Intune for mobile device management. The security team wants to ensure that corporate data is protected without taking full control of the users' personal devices. Specifically, they want to prevent users from copying data from managed applications, like Outlook, to unmanaged personal applications, like a personal cloud storage app. They also want to enforce a PIN to access the managed apps.

    Which Intune feature must be configured and deployed to meet these requirements? (Select TWO)

    Show answer details

    Correct answer: B, D

    App Protection Policies (APP), also known as Mobile Application Management (MAM), are designed specifically for this BYOD scenario. They apply security controls at the application level without requiring the device to be fully enrolled (MDM). These policies can enforce data loss prevention (DLP) rules like preventing cut/copy/paste to unmanaged apps.

    Conditional Access Policies work in conjunction with App Protection Policies. A Conditional Access policy can be configured to grant access to corporate resources (like Exchange Online) only if the access request is coming from an app that is protected by an approved App Protection Policy. This ensures the data controls are in place before access is allowed.

  3. 3

    You are troubleshooting a network connectivity issue on a Windows 10 computer. The user reports that they can access internal network shares but cannot browse the internet. You run ipconfig /all and receive the following output:

    IPv4 Address. . . . . . . . . . . : 192.168.1.110(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Default Gateway . . . . . . . . . :
    DHCP Server . . . . . . . . . . . : 192.168.1.1
    DNS Servers . . . . . . . . . . . : 192.168.1.1

    Based on this output, what is the most likely cause of the problem?

    Show answer details

    Correct answer: C

    The Default Gateway is the IP address of the router that a computer uses to send traffic to other networks, including the internet. The ipconfig output shows that this field is blank. Without a Default Gateway, the computer can communicate with other devices on its local subnet (192.168.1.x) but does not know where to send traffic destined for the internet. This perfectly matches the user's reported symptoms.

  4. 4

    True or False: The User State Migration Tool (USMT) can be used to perform an in-place migration of user data and settings when upgrading a computer from a 32-bit version of Windows 7 to a 64-bit version of Windows 10.

    Show answer details

    Correct answer: A

    This is a key use case for USMT. A direct in-place upgrade from a 32-bit OS to a 64-bit OS is not possible; it requires a custom 'wipe-and-load' installation. USMT is designed to handle this scenario by capturing the user state from the 32-bit OS, allowing the technician to install the new 64-bit OS, and then restoring the user state onto the new installation. USMT fully supports cross-architecture migrations (32-bit to 64-bit).

  5. 5

    You are configuring Microsoft Intune to issue device certificates for Wi-Fi authentication. The solution requires an on-premises Certificate Authority (CA) and a Network Device Enrollment Service (NDES) server. You have created a SCEP certificate profile in Intune. Which component is responsible for forwarding the certificate request from the managed device to the NDES server?

    graph TD subgraph "Cloud (Intune)" Intune[Microsoft Intune] Device[Managed Device] end subgraph "On-Premises Network" NDES[NDES Server] CA[Certificate Authority] Connector[Intune Certificate Connector] end Device -- 1. SCEP Profile --> Intune Intune -- 2. Policy --> Device Device -- 3. Certificate Request --> NDES NDES -- 4. Validate Request --> Connector Connector -- 5. Issue Request --> CA CA -- 6. Certificate --> Connector Connector -- 7. Certificate --> NDES NDES -- 8. Certificate --> Device
    Show answer details

    Correct answer: B

    As shown in the diagram, after the device receives the SCEP profile from Intune, the device itself generates a Certificate Signing Request (CSR) and sends it directly to the public-facing URL of the NDES server. The Intune Certificate Connector's role is to validate this request with Intune and then pass it to the internal CA, but the initial request comes from the device.

  6. 6

    You support Windows 10 Enterprise computers that are members of an Active Directory domain. Your company policy defines the list of approved Windows Store apps that are allowed for download and installation.You have created a new AppLocker Packaged Apps policy to help enforce the company policy.You need to test the new AppLocker Packaged Apps policy before you implement it for the entire company.What should you do? A.From Group Policy, enforce the new AppLocker policy in Audit Only mode.B.From Group Policy, run the Group Policy Results Wizard.C.From Group Policy, run the Group Policy Modeling Wizard.D.From PowerShell, run the Get-AppLockerPolicy –Effective command to retrieve the AppLocker effective policy.

    Show answer details

    Correct answer: A

  7. 7

    You support Windows 10 Enterprise computers.Your company has started testing Application Virtualization (App-V) applications on several laptops. You discover that the App-V applications are available to users even when the laptops are offline.You need to ensure that the App-V applications are available to users only when they are connected to the company network.What should you do? A.Change user permissions to the App-V applications.B.Disable the Disconnected operation mode.C.Configure mandatory profiles for laptop users.D.Reset the App-V client FileSystem cache.

    Show answer details

    Correct answer: B

  8. 8

    Your network contains an Active Directory domain named contoso.com. The domain contains Windows 10 Enterprise client computers.Your company has a subscription to Microsoft Office 365. Each user has a mailbox that is stored in Office 365 and a user account in the contoso.com domain.Each mailbox has two email addresses.You need to add a third email address for each user.What should you do? A.From Active Directory Users and Computers, modify the E-mail attribute for each user.B.From Microsoft Azure Active Directory Module for Windows PowerShell, run the Set-Mailbox cmdlet.C.From Active Directory Domains and Trust, add a UPN suffix for each user.D.From the Office 365 portal, modify the Users settings of each user.

    Show answer details

    Correct answer: B

  9. 9

    Your Windows 10 Enterprise work computer is a member of an Active Directory domain. You use your domain account to log on to the computer. You use yourMicrosoft account to log on to a home laptop.You want to access Windows 10 Enterprise apps from your work computer by using your Microsoft account.You need to ensure that you are able to access the Windows 10 Enterprise apps on your work computer by logging on only once.What should you do? A.Add the Microsoft account as a user on your work computer.B.Enable Remote Assistance on your home laptop.C.Connect your Microsoft account to your domain account on your work computer.D.Install OneDrive for Windows on both your home laptop and your work computer.

    Show answer details

    Correct answer: C

  10. 10

    You administer a Windows 10 Enterprise computer that runs Hyper-V. The computer hosts a virtual machine with multiple snapshots. The virtual machine uses one virtual CPU and 512 MB of RAM.You discover that the virtual machine pauses automatically and displays the state as paused-critical.You need to identify the component that is causing the error.Which component should you identify? A.no virtual switch definedB.insufficient memoryC.insufficient hard disk spaceD.insufficient number of virtual processors

    Show answer details

    Correct answer: C

Create an account to continue.