MD-102 Protecting Endpoints with Security Policies 1 — Questions and Answers
Question 1: Which Microsoft Intune policy type is used to configure Microsoft Defender Antivirus settings on Windows 10 endpoints?
- Device compliance policy
- Endpoint security – Antivirus policy (Correct answer)
- Device configuration profile – Endpoint protection template
- App protection policy
Correct answer: Endpoint security – Antivirus policy
Endpoint security Antivirus policies in Intune are specifically designed to configure Microsoft Defender Antivirus settings on managed Windows endpoints.
Question 2: An administrator wants to enable BitLocker encryption on all managed Windows 10 devices. Which Intune policy type should be used?
- Endpoint security – Disk encryption policy (Correct answer)
- Device compliance policy
- Windows Information Protection policy
- App configuration policy
Correct answer: Endpoint security – Disk encryption policy
Endpoint security Disk encryption policies in Intune configure BitLocker settings and enforce drive encryption on Windows 10/11 managed devices.
Question 3: Which Intune feature integrates with Microsoft Defender for Endpoint to allow Intune compliance policies to use device risk scores?
- Tenant attach
- Microsoft Tunnel
- Mobile Threat Defense connector (Correct answer)
- Endpoint security baseline
Correct answer: Mobile Threat Defense connector
The Mobile Threat Defense (MTD) connector in Intune integrates with Defender for Endpoint to feed device risk scores into compliance policy evaluation.
Question 4: An organization wants to use a pre-configured set of security settings recommended by Microsoft for Windows 10. What should the admin deploy?
- Custom OMA-URI settings
- Windows 10 security baseline (Correct answer)
- Endpoint detection and response policy
- Windows Update for Business ring
Correct answer: Windows 10 security baseline
Windows 10 security baselines in Intune provide Microsoft-recommended security configuration settings that can be deployed to managed devices with minimal customization.
Question 5: Which Windows security feature prevents untrusted applications from running on a device by allowing only signed and trusted software?
- Windows Firewall
- Windows Defender Credential Guard
- Windows Defender Application Control (WDAC) (Correct answer)
- Secure Boot
Correct answer: Windows Defender Application Control (WDAC)
Windows Defender Application Control (WDAC) enforces code integrity policies that allow only trusted and signed applications to execute on Windows devices.
Question 6: A company wants to prevent users from copying corporate data from managed apps to personal apps on iOS. Which Intune feature should be configured?
- Device compliance policy
- App protection policy (MAM) (Correct answer)
- iOS device restriction profile
- Conditional Access policy
Correct answer: App protection policy (MAM)
App protection policies (MAM) in Intune control data transfer between managed and unmanaged apps, preventing corporate data from being pasted or saved to personal apps on iOS.
Which Microsoft Intune policy type is used to configure Microsoft Defender Antivirus settings on Windows 10 endpoints?