MD-101 Managing Modern Desktops (MD-101) v1.0 4 — Questions and Answers
Question 1: Which Delivery Optimization download mode distributes Windows Update content among peers on the same local network without needing a local cache server?
- Mode 0 – HTTP only
- Mode 1 – LAN (Correct answer)
- Mode 2 – Group
- Mode 99 – Simple download
Correct answer: Mode 1 – LAN
Delivery Optimization Mode 1 (LAN) allows devices on the same local network to share update content directly with each other.
Question 2: An organization uses Microsoft Intune to manage Android Enterprise devices. Which enrollment mode fully manages corporate-owned devices while keeping a separate personal work profile optional?
- Android Enterprise – Personally owned with work profile
- Android Enterprise – Fully managed (Correct answer)
- Android Enterprise – Corporate-owned dedicated devices (Kiosk)
- Android device administrator
Correct answer: Android Enterprise – Fully managed
Android Enterprise Fully Managed mode gives IT full control over corporate-owned devices without separating personal and work data.
Question 3: A device enrolled in Intune shows 'Not evaluated' as its compliance state. What is the most likely reason?
- The device has no compliance policy assigned to it (Correct answer)
- The device failed a required check
- BitLocker is not enabled
- The device is running an unsupported OS version
Correct answer: The device has no compliance policy assigned to it
A 'Not evaluated' state means no compliance policy has been assigned to the device, so Intune has nothing to evaluate it against.
Question 4: You need to prevent users from copying data from a managed Office app to an unmanaged personal app on iOS. Which Intune feature addresses this?
- Device compliance policy
- App protection policy (MAM) (Correct answer)
- Conditional Access
- Enrollment restriction
Correct answer: App protection policy (MAM)
App protection policies (MAM) control data transfer between managed and unmanaged apps, including blocking cut/copy/paste to personal apps.
Question 5: Which command-line tool can reset a Windows 10 device back to Autopilot-ready state while keeping it enrolled in Azure AD and Intune?
- sysprep /generalize
- Autopilot Reset (via Intune or Settings) (Correct answer)
- DISM /apply-image
- wpeutil reboot
Correct answer: Autopilot Reset (via Intune or Settings)
Autopilot Reset restores the device to a business-ready state while maintaining its Azure AD enrollment and Intune management.
Question 6: A company wants to restrict which websites users can visit on managed Windows 11 devices using Microsoft Edge. Which Intune feature should they configure?
- Windows Defender Firewall outbound rules
- Microsoft Edge Administrative Templates (ADMX) in Intune (Correct answer)
- Network protection via Microsoft Defender for Endpoint
- Endpoint security – Attack surface reduction rules
Correct answer: Microsoft Edge Administrative Templates (ADMX) in Intune
Microsoft Edge ADMX policies in Intune allow administrators to configure allowed/blocked URLs and browsing restrictions directly in Edge.
Question 7: You are configuring Windows Update rings in Intune for a pilot group. Which setting controls the number of days before a quality update is automatically installed?
- Feature update deferral period
- Quality update deferral period (Correct answer)
- Deadline for quality updates
- Active hours end time
Correct answer: Quality update deferral period
The quality update deferral period delays security and cumulative updates by the specified number of days before devices download them.
Which Delivery Optimization download mode distributes Windows Update content among peers on the same local network without needing a local cache server?