[Feb 03, 2026] Genuine MD-102 Exam Dumps New 2026 Microsoft Pratice Exam [Q121-Q139]

Share

[Feb 03, 2026] Genuine MD-102 Exam Dumps New 2026 Microsoft Pratice Exam

New 2026 Realistic MD-102 Dumps Test Engine Exam Questions in here

NEW QUESTION # 121
You have a Microsoft 365 subscription.
You use Microsoft Intune Suite to manage devices.
You have the iOS app protection policy shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point,

Answer:

Explanation:

Explanation:
Box 1 = PIN only
Box 2 = reset the PIN app
iOS/iPadOS app protection policy settings - Microsoft Intune | Microsoft Learn
https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy-settings-ios


NEW QUESTION # 122
You have following types of devices enrolled in Microsoft Intune:
- Windows 10
- Android
- iOS
For which types of devices can you create VPN profiles in Microsoft Endpoint Manager?

  • A. Android and iOS only
  • B. Windows 10, Android, and iOS
  • C. Windows 10 and iOS only
  • D. Windows 10 and Android only
  • E. Windows 10 only

Answer: B

Explanation:
You can create VPN profiles for Android, Android Enterprise, iOS/iPadOS, macOS, Windows 10 and later, and Windows 8.1 devices.
Reference:
https://docs.microsoft.com/en-us/mem/intune/configuration/vpn-settings-android


NEW QUESTION # 123
You have a Microsoft 365 tenant that uses Microsoft Intune to manage personal and corporate devices. The tenant contains three Windows 10 devices as shown in the following exhibit.

How will Intune classify each device after the devices are enrolled in Intune automatically? To answer, select the appropriate options in the answer area.
NOTE:Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Table Description automatically generated

Reference:
https://docs.microsoft.com/en-us/azure/active-directory/devices/concept-azure-ad-join
https://docs.microsoft.com/en-us/azure/active-directory/devices/concept-azure-ad-register


NEW QUESTION # 124
You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune.
You need to configure an Intune device configuration profile to meet the following requirements:
* Prevent Microsoft Office applications from launching child processes.
* Block users from transferring files over FTP.
Which two settings should you configure in Endpoint protection? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

References:
https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-protection-windows-10#global-settings
https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-protection-windows-10#microsoft-defender-expl


NEW QUESTION # 125
Your network contains an on-premises Active Directory domain and an Azure AD tenant.
The Default Domain Policy Group Policy Object (GPO) contains the settings shown in the following table.

Which device configuration profile type template should you use?

  • A. Device restrictions
  • B. Endpoint protection
  • C. Administrative Templates
  • D. Custom

Answer: C

Explanation:
To configure the settings shown in the table, you need to use the Administrative Templates device configuration profile type template. This template allows you to configure hundreds of settings that are also available in Group Policy. You can use this template to configure settings such as password policies, account lockout policies, and audit policies. References:
https://docs.microsoft.com/en-us/mem/intune/configuration/administrative-templates-windows


NEW QUESTION # 126
You have 100 computers that run Windows 10. You have no servers. All the computers are joined to Microsoft Azure Active Directory (Azure AD).
The computers have different update settings, and some computers are configured for manual updates.
You need to configure Windows Update. The solution must meet the following requirements:
The configuration must be managed from a central location.
Internet traffic must be minimized.
Costs must be minimized.
How should you configure Windows Update? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Box 1: Windows Server Update Services (WSUS)
Windows Server Update Services (WSUS) enables information technology administrators to deploy the latest Microsoft product updates. You can use WSUS to fully manage the distribution of updates that are released through Microsoft Update to computers on your network.
Windows Server Update Services is a built-in server role that includes the following enhancements:
Can be added and removed by using the Server Manager
Includes Windows PowerShell cmdlets to manage the most important administrative tasks in WSUS Etc.
Box 2: A Group Policy object
In an Active Directory environment, you can use Group Policy to define how computers and users can interact with Windows Update to obtain automatic updates from Windows Server Update Services (WSUS).
Box 3: BranchCache
BranchCache is a bandwidth-optimization feature that has been available since the Windows Server 2008 R2 and Windows 7 operating systems. Each client has a cache and acts as an alternate source for content that devices on its own network request. Windows Server Update Services (WSUS) and Microsoft Endpoint Manager can use BranchCache to optimize network bandwidth during update deployment, and it's easy to configure for either of them. BranchCache has two operating modes: Distributed Cache mode and Hosted Cache mode.
Reference: https://docs.microsoft.com/en-us/windows/deployment/update/waas-branchcache
https://docs.microsoft.com/en-us/windows-server/administration/windows-server-update-services/deploy/4-confi


NEW QUESTION # 127
You have 100 Windows 10 devices enrolled in Microsoft Intune.
You need to configure the devices to retrieve Windows updates from the internet and from other computers on a local network.
Which Delivery Optimization setting should you configure, and which type of Intune object should you create? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Delivery Optimization setting: B. Download mode Intune object: A configuration profile To configure the devices to retrieve Windows updates from the internet and from other computers on a local network, you need to configure the Download mode setting in a Delivery Optimization device configuration profile. This setting specifies how the devices use Delivery Optimization to download updates. You can choose from several options, such as HTTP only, LAN only, or Group. For example, you can set the Download mode to Group and specify a group ID for the devices to share updates among themselves and with other devices that have the same group ID. You can also set the Download mode to Internet to allow the devices to download updates from Microsoft or other devices on the internet that use Delivery Optimization.
References: https://docs.microsoft.com/en-us/mem/intune/configuration/delivery-optimization-windows


NEW QUESTION # 128
Hotspot Question
You have 100 computers that run Windows 10.
The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune.
You need to configure the following device restrictions:
- Block users from browsing to suspicious websites.
- Scan all scripts loaded into Microsoft Edge.
Which two settings should you configure in Device restrictions? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Windows Defender SmartScreen
Block users from browsing to suspicious websites.
Microsoft Defender SmartScreen protects against phishing or malware websites and applications, and the downloading of potentially malicious files.
Microsoft Defender SmartScreen determines whether a site is potentially malicious Box 2: Windows Defender Antivirus Scan all scripts loaded into Microsoft Edge.
Reference:
https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender- smartscreen/windows-defender-smartscreen-overview


NEW QUESTION # 129
Your network contains an Active Directory domain named contoso.com. The domain contains two computers named Computer1 and Computer2 that run Windows 10.
On Computer1, you need to run the Invoke-Command cmdlet to execute several PowerShell commands on Computer2.
What should you do first?

  • A. On Computer1, run the New-PSSession cmdlet.
  • B. From Active Directory, configure the Trusted for Delegation setting for the computer account of Computer2.
  • C. On Computer2, run the Enable-PSRemoting cmdlet.
  • D. On Computer2, add Computer1 to the Remote Management Users group.

Answer: C

Explanation:
"PowerShell remoting is enabled by default on Windows Server platforms. You can use Enable- PSRemoting to enable PowerShell remoting on other supported versions of Windows and to re- enable remoting if it becomes disabled."
https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/enable- psremoting?view=powershell-6


NEW QUESTION # 130
You have groups that use the Dynamic Device membership type as shown in the following table.

You are deploying Microsoft 365 apps.
You have devices enrolled in Microsoft Intune as shown in the following table.

In the Microsoft Endpoint Manager admin center, you create a Microsoft 365 Apps app as shown in the exhibit. (Click the Exhibit tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

Reference:
https://docs.microsoft.com/en-us/mem/intune/apps/apps-add-office365
https://docs.microsoft.com/en-us/mem/intune/apps/apps-deploy
https://docs.microsoft.com/en-us/mem/intune/apps/apps-add


NEW QUESTION # 131
Your network contains an Active Directory domain named contoso.com that syncs to Azure Active Directory (Azure AD).
Existing on-premises computers are managed by using Microsoft System Center Configuration Manager (Current Branch).
You configure contoso.com for co-management.
You deploy 100 new devices that run Windows 10. The devices are joined to Azure AD and enrolled in Microsoft Intune.
You need to ensure that the devices are co-managed.
What should you create in Intune first?

  • A. a device compliance policy
  • B. a conditional access policy
  • C. an app for the Endpoint Configuration Manager client
  • D. a device configuration profile
    E an app configuration policy

Answer: C

Explanation:
For new internet-based devices, you need to create an app in Intune. Deploy this app to Windows
10 devices that aren't already Configuration Manager clients. This scenario is when you have new Windows 10 devices that join Azure AD and automatically enroll to Intune. You install the Configuration Manager client to reach a co-management state.
https://docs.microsoft.com/en-us/configmgr/comanage/how-to-prepare-win10


NEW QUESTION # 132
You manage 1,000 computers that run Windows 10. All the computers are enrolled in Microsoft Intune. You manage the servicing channel settings of the computers by using Intune.
You need to review the servicing status of a computer.
What should you do?

  • A. From Device configuration - Profiles, view the device status.
  • B. From Device compliance, view the device compliance.
  • C. From Software updates, view the Per update ring deployment state.
  • D. From Software updates, view the audit logs.

Answer: C

Explanation:
https://learn.microsoft.com/en-us/mem/intune/protect/windows-update-reports#reports-for-update-rings-for- windows-10-and-later-policy:~:text=IncompatibleServicingChannel


NEW QUESTION # 133
-
You have a Microsoft 365 subscription that contains the devices shown in the following table.

All the devices will be reimaged and licensed by using subscription activation.
The devices are assigned to the users shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
A screenshot of a computer error Description automatically generated


NEW QUESTION # 134
Your network contains an Active Directory domain.
You install the Microsoft Deployment Toolkit (MDT) on a server.
You have a custom image of Windows 11.
You need to deploy the image to 100 devices by using MDT.
Which three actions should you perform in sequence? To answer, move answer area and arrange them in the correct order.

Answer:

Explanation:

Explanation:
To deploy the Windows 11 image to 100 devices by using MDT, you should perform the following three actions in sequence:
* Install Windows Deployment Services (WDS) on the server. WDS is a role that enables you to deploy Windows operating systems over the network by using PXE boot and multicast technologies. You need to install WDS before you can enable multicast and configure the boot images for MDT. You can install WDS by using the Server Manager or PowerShell1.
* Create a deployment share on the server. A deployment share is a folder that contains the MDT files, scripts, applications, drivers, operating systems, and task sequences that you use to deploy Windows. You need to create a deployment share by using the MDT Deployment Workbench2.
* Add the Windows 11 image and create a task sequence in the deployment share. An image is a file that contains a snapshot of a Windows installation. A task sequence is a set of steps that MDT executes to install Windows and configure the settings. You need to add the Windows 11 image by importing it from a source folder or a WIM file, and create a task sequence by using a template or customizing your own3.
These are the basic steps to prepare for deploying Windows 11 with MDT. For more details and guidance, you can refer to the web search results I found for you by using search_web("deploy Windows 11 image with MDT").


NEW QUESTION # 135
You have a Microsoft 365 subscription that contains two security groups named Group1 and Group2.
Microsoft 365 uses Microsoft Intune Suite.
You use Microsoft Intune to manage devices.
You need to assign roles in Intune to meet the following requirements:
* The members of Group1 must manage Intune roles and assignments.
* The members of Group2 must assign existing apps and policies to users and devices.
The solution must follow the principle of least privilege.
Which role should you assign to each group? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
To assign roles in Intune to meet the requirements, you should assign the following roles to each group:
Group1: Intune Role Administrator Group2: Help Desk Operator
The Intune Role Administrator role is the only Intune role that can manage custom Intune roles and add assignments for built-in Intune roles1. This role meets the requirement for Group1 to manage Intune roles and assignments.
The Help Desk Operator role can perform remote tasks on users and devices, and can assign applications or policies to users or devices1. This role meets the requirement for Group2 to assign existing apps and policies to users and devices.


NEW QUESTION # 136
You have a Microsoft 365 E5 subscription.
You create an app protection policy for Android device named Policy1 as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Install the Company portal
Box 2: Users Only
https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policies#target-app-protection-policies- based-on-device-management-state:~:text=Because%20Intune%20app%20protection%20policies%20target%
20a%20user%27s%20identity%2C%20the%20protection%20settings%20for%20a%20user%20can%
20apply%20to%20both%20enrolled%20(MDM%20managed)%20and%20nonenrolled%20devices%20(no%
20MDM).


NEW QUESTION # 137
What should you use to meet the technical requirements for Azure DevOps?

  • A. Windows Information Protection (WIP)
  • B. Conditional access
  • C. A device configuration profile
  • D. An app protection policy

Answer: B

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/devops/organizations/accounts/manage-conditional-access?
view=azure-devops


NEW QUESTION # 138
Your company has a System Center Configuration Manager deployment that uses hybrid mobile device management (MDM). All Windows 10 devices are Active Directory domain-joined.
You plan to migrate from hybrid MDM to Microsoft Intune standalone.
You successfully run the Intune Data Importer tool.
You need to complete the migration.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Create a new Intune tenant.
  • B. In Intune, add a device enrollment manager (DEM).
  • C. Assign all users Intune licenses.
  • D. Change the tenant MDM authority to Intune.

Answer: C,D

Explanation:
https://docs.microsoft.com/en-us/sccm/mdm/deploy-use/migrate-hybridmdm-to-intunesa
https://docs.microsoft.com/en-us/sccm/mdm/deploy-use/migrate-prepare-intune
https://docs.microsoft.com/en-us/sccm/mdm/deploy-use/change-mdm-authority


NEW QUESTION # 139
......

Grab latest Amazon MD-102 Dumps as PDF Updated: https://selftestengine.testkingit.com/Microsoft/latest-MD-102-exam-dumps.html