MD-102 Practice Questions
Prepare for MD-102 with more than an answer.
Unlock the full exam and previous versions
- v1Version 1 177 questions Current
- 70-697Legacy Configuring Windows Devices 214 questions Locked
- 98-349Legacy Windows Operating System Fundamentals 50 questions Locked
- MD-100Legacy Windows Client 48 questions Locked
- MD-101Legacy Managing Modern Desktops 50 questions Locked
- Exam fee
- $165 USD
- Level
- Associate
- Valid for
- 1 year
Domains covered on the exam 4
- Prepare infrastructure for devices25%
- Manage and maintain devices32.5%
- Manage applications17.5%
- Protect devices17.5%
- 1
A new Attack Surface Reduction (ASR) rule, 'Block untrusted and unsigned processes that run from USB', is enabled in an Intune policy and set to 'Block' mode. After deployment, a critical line-of-business tool that runs from a specific, company-issued USB drive stops working. You need to allow this specific tool to run while keeping the ASR rule active for all other USB-based processes. What should you do?
Show answer details
Correct answer: B
Attack Surface Reduction policies in Intune allow for granular exclusions. To resolve this issue without weakening the overall security posture, you should add the full file path of the specific, trusted application (e.g.,
E:\LOBApp\tool.exe) to the exclusion list for that particular ASR rule. This allows only that application to bypass the rule, while the block action remains in effect for all other untrusted processes from USB drives. - 2
You are managing a fleet of macOS devices with Microsoft Intune. You need to deploy a custom
.pkginstaller for a line-of-business application. Which prerequisite tool must you use to prepare the.pkgfile before you can upload it to Intune?Show answer details
Correct answer: C
To deploy macOS LOB apps (as
.pkgfiles), you must first use the Microsoft Intune App Wrapping Tool for macOS. This command-line tool wraps the.pkgfile into an.intunemacformat, which is the file type that Intune requires for upload and deployment. This tool also extracts detection metadata from the package. - 3
True or False: A dynamic device group in Microsoft Entra ID can be created with a membership rule based on a device's Intune enrollment profile name.
Show answer details
Correct answer: A
The statement is true. The
enrollmentProfileNameis a valid device attribute that can be used in dynamic membership rules for device groups in Microsoft Entra ID. For example, a rule like(device.enrollmentProfileName -eq "Kiosk_Profile")can be used to automatically group all devices that were enrolled using a specific Autopilot or device enrollment profile. - 4
Your company uses Microsoft Tunnel for MAM to allow unmanaged personal iOS devices to securely access on-premises web applications. A user reports they can no longer access an internal web app from the Microsoft Edge browser on their personal iPhone. You have confirmed the Microsoft Tunnel Gateway is healthy. What is the first thing you should check on the user's device?
Show answer details
Correct answer: B
For Microsoft Tunnel for MAM on iOS and Android, the Microsoft Defender for Endpoint app acts as the tunnel client. If this app is not installed, not running, or the user has not signed into it, the tunnel connection cannot be established. Therefore, verifying the status of the Defender for Endpoint app is the first and most crucial troubleshooting step.
- 5
A user with a personally owned (BYOD) iOS device is unable to access SharePoint Online. An investigation shows that their device is marked as non-compliant in Intune. The user's Conditional Access policy requires a compliant device for access. The compliance policy requires the device OS to be version 16.0 or higher. The user's device is running iOS 15.7. The user insists they never received a notification to upgrade. What is the most likely reason the user was not notified about the non-compliance issue?
sequenceDiagram participant User as User's Device (iOS 15.7) participant Intune participant Entra as Microsoft Entra ID participant SPO as SharePoint Online User->>SPO: Request Access SPO->>Entra: Evaluate CA Policy Entra->>Intune: Check Compliance Status Intune-->>Entra: Non-Compliant (OS < 16.0) Entra-->>User: Access DeniedShow answer details
Correct answer: B
The device compliance policy itself must be configured with an 'Action for noncompliance', such as 'Send email to end user' or 'Send push notification'. If no action is configured, the device will be marked as non-compliant, and Conditional Access will block it, but the user will receive no proactive notification from Intune explaining why.
- 6
A financial services company is implementing Microsoft Intune to manage its Windows 11 devices. The security team requires that all devices have BitLocker encryption enabled and that recovery keys are backed up to Microsoft Entra ID. However, a specific group of legacy accounting devices lacks a Trusted Platform Module (TPM) 2.0 chip. You need to create a compliance policy that enforces BitLocker but accommodates these legacy devices. Which configuration is required to achieve this?
Show answer details
Correct answer: B
Intune compliance policies for BitLocker do not automatically adapt for devices without a TPM. The best practice for this scenario is to create two distinct policies and use dynamic device groups to target them appropriately. One group can be created with a rule like
(device.deviceTrustType -eq "TPM")for TPM-enabled devices, and another for devices without a TPM or with an older version. This ensures that all devices are evaluated for compliance correctly based on their hardware capabilities. - 7
Your organization uses Microsoft Intune Suite and has implemented Endpoint Privilege Management (EPM). A new policy is created to allow users to run a specific legacy application,
C:\Apps\LegacyApp.exe, with administrative privileges. After deploying the policy, users report they are still prompted for admin credentials. You verify the policy is assigned to the correct user group and the file path is correct. What is the most likely cause of this issue?Show answer details
Correct answer: B
Endpoint Privilege Management rules require more than just a file path for validation to prevent spoofing. A robust rule must include a file hash, a certificate signature, or both. If only the file path is defined, EPM will not trust the rule and will not elevate the application, resulting in the standard User Account Control (UAC) prompt. The most secure and reliable method is to include the file hash, which ensures the exact version of the executable is being elevated.
- 8
You are deploying Windows 11 devices using Windows Autopilot user-driven mode for a hybrid work environment. You need to ensure that specific business-critical applications are installed and security policies are applied before users can access the desktop. However, you want to allow users to start working as soon as possible, even if non-essential applications are still installing in the background. Which two components of the Enrollment Status Page (ESP) should you configure? (Select TWO)
Show answer details
Correct answer: C, D
This setting is the core of the ESP's function. By setting it to 'Yes', you ensure the user is held at the ESP screen until the specified configurations are complete.
This allows you to define a subset of required applications that must be installed before the user can proceed. Other applications assigned as 'Required' but not on this blocking list will continue to install in the background after the user reaches the desktop.
- 9
A university is deploying shared Windows 11 devices in a computer lab. The devices must be configured in kiosk mode to run only the Microsoft Edge browser. Additionally, after each user session, the device must automatically sign out the user and delete the local profile to ensure data privacy and a clean state for the next user. Which type of account should be configured for the kiosk profile to meet these requirements?
Show answer details
Correct answer: D
The 'Guest account' option within the multi-app kiosk configuration is specifically designed for shared device scenarios. It creates a temporary local account for each session. When the user signs out or the session ends, this temporary account and all associated data are deleted, ensuring a clean and secure environment for the next user.
- 10
True or False: When configuring an Intune app protection policy for iOS devices, setting the 'Save copies of org data' policy to 'Block' will prevent users from saving corporate files to any personal cloud storage app, but will still allow saving to the local device storage by default.
Show answer details
Correct answer: B
The statement is false. The 'Save copies of org data' policy setting controls where users can save corporate data. When set to 'Block', it prevents saving to any non-policy managed location, which includes both personal cloud storage apps AND the local device storage. To allow saving to a specific corporate location like OneDrive, you must configure policy-managed locations.
