MD-102 Protecting Endpoints with Security Policies 2 — Questions and Answers
Question 1: Which Intune endpoint security policy configures Windows Firewall rules on managed devices?
- Endpoint security – Antivirus
- Endpoint security – Firewall (Correct answer)
- Device configuration – Endpoint protection
- Device compliance – Windows
Correct answer: Endpoint security – Firewall
The Endpoint security Firewall policy in Intune is specifically designed to configure Windows Firewall settings and rules on managed Windows devices.
Question 2: An administrator wants to ensure that a device's TPM chip is enabled and functioning before allowing access to corporate resources. Which Intune policy type is used?
- Device configuration profile
- Device compliance policy (Correct answer)
- Endpoint security – Account protection
- Endpoint security baseline
Correct answer: Device compliance policy
Device compliance policies in Intune can require that the TPM is enabled and functioning as a compliance requirement before granting conditional access to resources.
Question 3: Which feature in Microsoft Defender for Endpoint provides behavioral monitoring to detect and stop attacks in real time?
- Attack surface reduction rules
- Endpoint detection and response (EDR) (Correct answer)
- Cloud-delivered protection
- Tamper protection
Correct answer: Endpoint detection and response (EDR)
Endpoint detection and response (EDR) in Microsoft Defender for Endpoint provides behavioral monitoring, detecting suspicious activity and enabling security teams to investigate and respond to threats.
Question 4: A user is trying to access a phishing website. Which Microsoft Defender for Endpoint feature blocks access to the malicious URL?
- Attack surface reduction rules
- Network protection (Correct answer)
- Controlled folder access
- Application Guard
Correct answer: Network protection
Network protection in Microsoft Defender for Endpoint prevents users from accessing malicious websites and IP addresses by blocking network connections to known bad destinations.
Question 5: Which Intune policy can prevent users from modifying Microsoft Defender Antivirus settings on their Windows 10 devices?
- Endpoint security baseline
- Tamper protection setting in Antivirus policy (Correct answer)
- Device restriction configuration profile
- App protection policy
Correct answer: Tamper protection setting in Antivirus policy
Tamper protection, configured through the Intune Antivirus policy, prevents users and malware from modifying Microsoft Defender Antivirus security settings.
Question 6: An administrator wants to block USB drives on corporate Windows 10 devices using Intune. Which policy type should be used?
- Endpoint security – Attack surface reduction (Correct answer)
- Device configuration – Device restrictions
- Endpoint security – Firewall
- Device compliance policy
Correct answer: Endpoint security – Attack surface reduction
Attack surface reduction policies in Intune include removable storage device controls that can block USB drives and other removable media on managed Windows devices.
Which Intune endpoint security policy configures Windows Firewall rules on managed devices?