What should you configure to meet the technical requirements for the Azure AD-joined computers?
a) Windows Hello for Business from the Microsoft Intune blade in the Azure portal
b) The Accounts options in an endpoint protection profile
c) The Password Policy settings in a Group Policy object (GPO)
d) A password policy from the Microsoft Office 365 portal
02. You manage 1,000 computers that run Windows 10. All the computers are enrolled in Microsoft Intune. You manage the servicing channel settings of the computers by using Intune.
You need to review the servicing status of a computer. What should you do?
a) From Device configuration- Profiles, view the device status.
b) From Device compliance, view the device compliance.
c) From Software updates, view the audit logs.
d) From Software updates, view the Per update ring deployment state.
03. What should you use to meet the technical requirements for Azure DevOps?
a) An app protection policy
b) Windows Information Protection (WIP)
c) Conditional access
d) A device configuration profile
04. You want to change an Azure Active Directory policy for your users. What PowerShell command would you use to accomplish this task?
a) New-AzureADPolicy
b) Edit-AzureADPolicy
c) New-AzurePolicy
d) Set-AzureADPolicy
05. You are creating a device configuration profile in Microsoft Intune. You need to implement an ADMX-backed policy. Which profile type should you use?
a) Identity protection
b) Custom
c) Device restrictions
d) Device restrictions (Windows 10 Team)
06. You have a Microsoft 365 subscription. All devices run Windows 10. You need to prevent users from enrolling the devices in the Windows Insider Program.
What should you configure from Microsoft 365 Device Management?
Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
a) a custom device configuration profile
b) a device restrictions device configuration profile
c) an app configuration policy
d) a Windows 10 update ring
e) a Windows 10 security baseline
07. CompanyA has 10,000 devices running Windows 10. You plan to implement Microsoft Intune for Mobile Device Management (MDM). You need to configure Microsoft Intune to support automatic device enrollment for all Windows 10 devices.
Which two actions should you perform?
Each correct answer presents part of the solution.
a) Assign a deployment profile to all devices.
b) Set the MDM user scope to all users.
c) Import the hardware IDs for all devices.
d) Assign an Intune license to all users.
e) Assign a device profile to all users.
08. You are the mobile device administrator for CompanyA. CompanyA has 3,500 devices running Windows 10, version 1709.
CompanyA has a System Center Configuration Manager site. This site has a single primary site server running version 1806. You are planning to implement co-management with Microsoft Intune.
You need to deploy co-management. What should you do first?
a) Upgrade to the latest version of Windows 10.
b) Deploy a Cloud Management Gateway.
c) Add a Microsoft Intune subscription in the Configuration Manager Console.
d) Assign a Microsoft Intune license to all users.
e) Upgrade to the latest version of System Center Configuration Manager (SCCM).
09. What should you upgrade before you can configure the environment to support co-management?
a) the domain functional level
b) Configuration Manager
c) the domain controllers
d) Windows Server Update Services (WSUS)
10. You have a Microsoft Azure Log Analytics workplace that collects all the event logs from the computers at your company.
You have a computer named Computer1 than runs Windows 10. You need to view the events collected from Computer1.
Which query should you run in Log Analytics?
a) Event | where Computer = = "Computer1"
b) ETWEvent | where SourceSystem = = "Computer1"
c) ETWEvent | where Computer = = "Computer1"
d) Event | where SourceSystem = = "Computer1"