MD-101 Managing Modern Desktops (MD-101) Microsoft 5 — Questions and Answers
Question 1: An administrator configures a Windows Information Protection (WIP) policy in Intune. A user tries to copy corporate data from a protected app to a personal app. What happens?
- The copy is allowed but the data is encrypted
- The copy is blocked or the user is warned depending on WIP mode (Correct answer)
- The user's device is automatically marked non-compliant
- The copy is silently allowed with an audit log entry
Correct answer: The copy is blocked or the user is warned depending on WIP mode
WIP can be set to Silent (logs but allows), Override (warns user), or Block mode, and behavior depends on which mode is configured.
Question 2: Which Intune report type provides data about which devices have successfully received and applied a specific configuration profile?
- Device compliance report
- Device configuration assignment status report (Correct answer)
- Audit logs
- Endpoint analytics baseline report
Correct answer: Device configuration assignment status report
The device configuration assignment status report shows per-device success, failure, or pending status for configuration profile deployments.
Question 3: A Windows 10 device is enrolled in Intune via a bulk enrollment package. Which enrollment method is being used?
- Windows Autopilot user-driven mode
- Device enrollment manager (DEM) account
- Provisioning package (PPKG) via Windows Configuration Designer (Correct answer)
- Azure AD automatic MDM enrollment
Correct answer: Provisioning package (PPKG) via Windows Configuration Designer
Bulk enrollment using a provisioning package created with Windows Configuration Designer (PPKG) enrolls multiple devices without requiring individual user credentials.
Question 4: An administrator needs to deploy a mandatory language pack to all Windows 11 devices in Intune. Which feature is best suited for this task?
- Win32 app deployment
- PowerShell script (Correct answer)
- Feature update policy
- Windows quality update policy
Correct answer: PowerShell script
A PowerShell script in Intune can use DISM or Add-WindowsCapability to silently install language packs on managed devices.
Question 5: Which Endpoint analytics metric measures the time from power-on to a user being able to sign in on a Windows device?
- Time to responsive desktop
- Boot score
- Startup performance score (Correct answer)
- Sign-in time
Correct answer: Startup performance score
Startup performance in Endpoint analytics measures how long the boot process takes, from power-on to the user being able to sign in.
Question 6: A company wants to use Intune to enforce that Windows 10 devices have a minimum OS version of 10.0.19041. Where is this configured?
- Device configuration profile > Device restrictions
- Device compliance policy > Device health
- Device compliance policy > Device properties (Correct answer)
- Enrollment restriction profile
Correct answer: Device compliance policy > Device properties
Minimum OS version requirements are configured under Device properties within a device compliance policy in Intune.
Question 7: An administrator uses Microsoft Intune to manage update deployments and needs devices to install security updates within 7 days of release. Which policy type should be configured?
- Windows Update ring with a 7-day quality update deferral
- Feature update policy with 7-day deferral
- Windows Update ring with a 7-day deadline for quality updates (Correct answer)
- Endpoint security > Antivirus update policy
Correct answer: Windows Update ring with a 7-day deadline for quality updates
Setting a 7-day deadline for quality updates in a Windows Update ring policy forces devices to install security updates within 7 days of availability.
An administrator configures a Windows Information Protection (WIP) policy in Intune.
A user tries to copy corporate data from a protected app to a personal app.
What happens?