Free MD-102 Managing Device and Data Questions and Answers 1 — Questions and Answers
Question 1: The forest root domain contains objects that don’t exist in other domains in the forest.
- True (Correct answer)
- False
Correct answer: True
The forest root domain in Active Directory holds several unique objects and roles that are not replicated to other domains within the same forest. These include the Schema Master and Domain Naming Master FSMO roles, as well as enterprise-wide configurations and trust relationships that apply to the entire forest. Therefore, it contains objects specific to its role as the root.
Question 2: Global Infotech has appointed you as a Desktop Administrator who needs your help on setting up conditional access policies to provide granular access for accessing company data irrespective of the device and location due to work from home policy. Please select the most secure way of accessing the data from the following.
- Activate MFA for the employees to use the corporate application on their personal devices (Correct answer)
- Automatically update the device to the latest version for accessing the company’s data
- Ask the employees to visit any nearby office with a secured network
- User Exchange ActiveSync to enable access for the employees using their home network
Correct answer: Activate MFA for the employees to use the corporate application on their personal devices
Activating Multi-Factor Authentication (MFA) is the most secure option for accessing corporate data from personal devices. MFA adds an essential layer of security by requiring users to provide two or more verification factors, significantly reducing the risk of unauthorized access even if a password is compromised. This approach directly addresses the need for granular and secure access in a work-from-home scenario, especially when combined with conditional access policies.
Question 3: What are some of the more commonly used device compliance settings? Choose 2 Options
- Restrict internet service providers
- Perform factory reset including deleting personal data
- Maximum OS version allowed (Correct answer)
- Record the private conversation on any 3rd party messenger
- Whether the device is jail-broken or rooted (Correct answer)
Correct answer: Maximum OS version allowed
Device compliance policies in Intune are crucial for ensuring devices meet organizational security standards. Two commonly used settings are "Maximum OS version allowed," which prevents devices running outdated or unsupported operating systems from accessing corporate resources, and "Whether the device is jail-broken or rooted," which identifies and restricts access for devices that have had their security protections bypassed. These settings help maintain a secure and manageable endpoint environment.
Question 4: You are assigned a task to restrict access for Android Smartphones from accessing Organizational data. You should find and restrict the access for smartphones that don’t have the latest version of the security patch and can give a maximum 90 days of grace period for the users to update their smartphones. Which of the following can be used to achieve this task?
- Notify end users through email
- Google Play Protect
- Encryption of data
- Mark device non-compliant (Correct answer)
Correct answer: Mark device non-compliant
To restrict access for Android smartphones that lack the latest security patch and provide a grace period, you should configure a device compliance policy to "Mark device non-compliant." This policy allows you to define the required security patch level and then specify actions for non-compliant devices, including a grace period before access is blocked. Once marked non-compliant, conditional access policies can then prevent these devices from accessing organizational data.
Question 5: A restaurant named Pizzamania wants to digitize their orders so they decide to give new iPhones to their waiters. Which Apple option can deploy an enrollment profile “over the air” to bring devices into management?
- Company Portal
- Device Enrollment Program (DEP) (Correct answer)
- Enterprise work profile
- Configurator for iPhone
Correct answer: Device Enrollment Program (DEP)
Apple's Device Enrollment Program (DEP), now part of Apple Business Manager (ABM) or Apple School Manager (ASM), is specifically designed for "over the air" enrollment of corporate-owned Apple devices. It allows organizations to automatically enroll devices into MDM, apply initial configurations, and supervise them directly out of the box, streamlining the deployment process for new devices like the iPhones for Pizzamania's waiters.
The forest root domain contains objects that don’t exist in other domains in the forest.