Free Managing Modern Desktops (MD-101) v1.0 Questions and Answers — Questions and Answers
Question 1: Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations. These workstations have been enrolled in Microsoft Intune. <br> You are responsible for ensuring that the workstations can only execute programs that you have specifically authorized. <br> Solution: You make use of Windows Defender Application Guard. <br> Does the solution meet the goal?
- Yes
- No (Correct answer)
Correct answer: No
Use Windows Defender Application Control instead (WDAC). Windows Defender Application Control and code integrity protection based on virtualization.
Question 2: You are presently using Microsoft Azure Log Analytics' Antimalware Assessment product. <br> You have discovered a device without real-time protection after accessing the Protection Status dashboard. <br> Which of the following may be the cause of this?
- Windows Defender System Guard is incorrectly configured
- Windows Defender has been disabled (Correct answer)
- You need to install the Azure Diagnostic extension
- Windows Defender Credential Guard is incorrectly configured
Correct answer: Windows Defender has been disabled
On most devices, Microsoft Defender Antivirus serves as the primary antivirus and antimalware program.
Question 3: You are presently using Microsoft Azure Log Analytics' Antimalware Assessment product. <br> You discover a device that is not reporting when you enter the Protection Status dashboard. <br> Which of the following may be the cause of this?
- The Microsoft Malicious Software Removal tool is installed
- Windows Defender System Guard is incorrectly configured
- You need to install the Azure Diagnostic extension (Correct answer)
- Windows Defender Application Guard is incorrectly configured
Correct answer: You need to install the Azure Diagnostic extension
An agent in Azure Monitor called Azure Diagnostics extension gathers monitoring information from the guest operating system of Azure computing resources, including virtual machines.
Question 4: To determine if it is correct, you must take into account the underlined portion. <br> Hyper-V must be installed on Windows 10 machines in order to activate Windows Defender Credential Guard. <br> In the event that the underlined part is accurate, choose "No adjustment necessary." Choose the accurate answer if the underlined portion is accurate. <br> What should you put on the machines to install?
- A container cluster
- No adjustment required (Correct answer)
- Windows Defender Smart screen
- A virtual machine
Correct answer: No adjustment required
No adjustment is required — Windows Defender Credential Guard depends on virtualization-based security, which requires the Hyper-V platform to be installed. The statement as underlined is already accurate, so no other component needs to be added.
Question 5: One hundred Windows 10 devices linked to Microsoft Azure Active Directory (Azure AD) are under your management. <br> Make sure users cannot connect their own computers to Azure AD. <br> Which of the below activities ought you to perform?
- You should configure the Enrollment restriction settings via the Windows Defender Security Center
- You should configure the Enrollment restriction settings via the Device enrollment blade in the Intune admin center
- You should configure the Enrollment restriction settings via the Security & Compliance admin center
- You should configure the Enrollment restriction settings via the Azure Active Directory admin center (Correct answer)
Correct answer: You should configure the Enrollment restriction settings via the Azure Active Directory admin center
A central location for managing device IDs and keeping track of associated event data is provided by Azure Active Directory (Azure AD).
Question 6: To determine if it is correct, you must take into account the underlined portion. <br> You must access the For Developers setting in the Windows 10 Settings app under Update & Security to enable sideloading. <br> In the event that the underlined part is accurate, choose "No adjustment necessary." Choose the accurate answer if the underlined portion is accurate.
- Widows Insider
- No adjustment required (Correct answer)
- Activation
- Delivery Optimization
Correct answer: No adjustment required
How to allow Windows 10 to sideload apps on your computer <br> 1. Open Settings <br> 2. Click on Update & Security <br> 3. Click on For developers <br> 4. Under "Use developer features," select the Sideload apps option.
Question 7: To determine if it is correct, you must take into account the underlined portion. <br> Run the Install-Package cmdlet in Windows 10 to allow sideloading of a LOB application. <br> In the event that the underlined part is accurate, choose "No adjustment necessary." Choose the accurate answer if the underlined portion is accurate.
- Add-AppxPackage (Correct answer)
- No adjustment required
- Install-PackageProvider
- Save-Package
Correct answer: Add-AppxPackage
Add-AppxPackage is the correct PowerShell cmdlet for sideloading a line-of-business AppX application onto Windows 10. Install-Package, Install-PackageProvider, and Save-Package manage general software packages or providers, not the installation of AppX app packages.
Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations.
These workstations have been enrolled in Microsoft Intune.
You are responsible for ensuring that the workstations can only execute programs that you have specifically authorized.
Solution: You make use of Windows Defender Application Guard.
Does the solution meet the goal?