Updated MD-101 Dumps For Managing Modern Desktops Exam

Good news for all MD-101 Managing Modern Desktops exam candidates, we have updated MD-101 dumps questions to ensure that you can pass MD-101 exam successfully. New MD-101 updated dumps contain 195 practice exam questions. We have verified that all the answers have been verified. Administrators who deploy, configure, secure, manage, and monitor devices and client applications in an enterprise environment can choose DumpsBase MD-101 dumps to prepare for Managing Modern Desktops exam well.

Read DumpsBase Microsoft MD-101 Free Dumps First

1. Topic 1, Litware inc

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.

To start the case study

To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.

General Overview

Litware, Inc. is an international manufacturing company that has 3,000 employees. The company has sales, marketing, research, human resources (HR), development, and IT departments.

Litware has two main offices in New York and Los Angeles. Litware has five branch offices in Asia.

Existing Environment

Current Business Model

The Los Angeles office has 500 developers. The developers work flexible hours ranging from 11 AM to 10 PM.

Litware has a Microsoft System Center 2012 R2 Configuration Manager deployment.

During discovery, the company discovers a process where users are emailing bank account information of its customers to internal and external recipients.

Current Environment

The network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD). The functional level of the forest and the domain is Windows Server 2012 R2. All domain controllers run Windows Server 2012 R2.

Litware has the computers shown in the following table.

The development department uses projects in Azure DevOps to build applications.

Most of the employees in the sales department are contractors. Each contractor is assigned a computer that runs Windows 10. At the end of each contract, the computer is assigned to a different contractor. Currently, the computers are re-provisioned manually by the IT department.

Problem Statements

Litware identifies the following issues on the network:

- Employees in the Los Angeles office report slow Internet performance when updates are downloading. The employees also report that the updates frequently consume considerable resources when they are installed. The Update settings are configured as shown in the Updates exhibit. (Click the Updates button.)

- Management suspects that the source code for the proprietary applications in Azure DevOps in being shared externally.

- Re-provisioning the sales department computers is too time consuming.

Requirements

Business Goals

Litware plans to transition to co-management for all the company-owned Windows 10 computers.

Whenever possible, Litware wants to minimize hardware and software costs.

Device Management Requirements

Litware identifies the following device management requirements:

- Prevent the sales department employees from forwarding email that contains bank account information.

- Ensure that Microsoft Edge Favorites are accessible from all computers to which the developers sign in.

- Prevent employees in the research department from copying patented information from trusted applications to untrusted applications.

Technical Requirements

Litware identifies the following technical requirements for the planned deployment:

- Re-provision the sales department computers by using Windows AutoPilot.

- Ensure that the projects in Azure DevOps can be accessed from the corporate network only.

- Ensure that users can sign in to the Azure AD-joined computers by using a PIN. The PIN must expire every 30 days.

- Ensure that the company name and logo appears during the Out of Box Experience (OOBE) when using Windows AutoPilot.

Exhibits

Updates

HOTSPOT

You need to resolve the performance issues in the Los Angeles office.

How should you configure the update settings? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

2. HOTSPOT

You need to meet the technical requirements for Windows AutoPilot.

Which two settings should you configure from the Azure Active Directory blade? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

3. You need to capture the required information for the sales department computers to meet the technical

requirements.

Which Windows PowerShell command should you run first?

4. What should you use to meet the technical requirements for Azure DevOps?

5. HOTSPOT

You need to recommend a solution to meet the device management requirements.

What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

6. What should you configure to meet the technical requirements for the Azure AD-joined computers?

7. What should you upgrade before you can configure the environment to support co-management?

8. You need to meet the device management requirements for the developers.

What should you implement?

9. HOTSPOT

You need to meet the OOBE requirements for Windows AutoPilot.

Which two settings should you configure from the Azure Active Directory blade? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

10. Topic 2, Contoso Ltd

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.

To start the case study

To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.

Overview

Contoso, Ltd, is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York.

Contoso has the users and computers shown in the following table.

The company has IT, human resources (HR), legal (LEG), marketing (MKG) and finance (FIN) departments.

Contoso uses Microsoft Store for Business and recently purchased a Microsoft 365 subscription.

The company is opening a new branch office in Phoenix. Most of the users in the Phoenix office will work from home.

Existing Environment

The network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).

All member servers run Windows Server 2016. All laptops and desktop computers run Windows 10 Enterprise.

The computers are managed by using Microsoft Endpoint Configuration Manager. The mobile devices are managed by using Microsoft Intune.

The naming convention for the computers is the department acronym, followed by a hyphen, and then four numbers, for example, FIN-6785. All the computers are joined to the on-premises Active Directory domain.

Each department has an organizational unit (OU) that contains a child OU named Computers. Each computer account is in the Computers OU of its respective department.

Intune Configuration

The domain has the users shown in the following table.

User2 is a device enrollment manager (DEM) in Intune.

The devices enrolled in Intune are shown in the following table.

The device compliance policies in Intune are configured as shown in the following table.

The device compliance policies have the assignments shown in the following table.

The device limit restrictions in Intune are configured as shown in the following table.

Requirements

Planned Changes

Contoso plans to implement the following changes:

- Provide new computers to the Phoenix office users. The new computers have Windows 10 Pro preinstalled and were purchased already.

- Start using a free Microsoft Store for Business app named App1.

- Implement co-management for the computers.

Technical Requirements :

Contoso must meet the following technical requirements:

- Ensure that the users in a group named Group4 can only access Microsoft Exchange Online from devices that are enrolled in Intune.

- Deploy Windows 10 Enterprise to the computers of the Phoenix office users by using Windows Autopilot.

- Monitor the computers in the LEG department by using Windows Analytics.

- Create a provisioning package for new computers in the HR department.

- Block iOS devices from sending diagnostic and usage telemetry data.

- Use the principle of least privilege whenever possible.

- Enable the users in the MKG department to use App1.

- Pilot co-management for the IT department.

You need to prepare for the deployment of the Phoenix office computers.

What should you do first?

11. HOTSPOT

You need a new conditional access policy that has an assignment for Office 365 Exchange Online.

You need to configure the policy to meet the technical requirements for Group4.

Which two settings should you configure in the policy? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

12. HOTSPOT

You are evaluating which devices are compliant.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

13. You need to meet the requirements for the MKG department users.

What should you do?

14. You need to prepare for the deployment of the Phoenix office computers.

What should you do first?

15. HOTSPOT

What is the maximum number of devices that User1 and User2 can enroll in Intune? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

16. You need to meet the technical requirements for the iOS devices.

Which object should you create in Intune?

17. DRAG DROP

You need to meet the technical requirements for the LEG department computers.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

18. You need to meet the technical requirements for the IT department.

What should you do first?

19. HOTSPOT

You need to meet the technical requirements for the new HR department computers.

How should you configure the provisioning package? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

20. HOTSPOT

To which devices do Policy1 and Policy2 apply? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

21. Topic 3, Misc. Questions

HOTSPOT

You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com. All Windows 10 devices are enrolled in Microsoft Intune.

You configure the following settings in Windows Information Protection (WIP):

- Protected apps: App1

- Exempt apps: App2

- Windows Information Protection mode: Silent

App1, App2, and App3 use the same file format.

You create a file named File1 in App1.

You need to identify which apps can open File1.

What apps should you identify? To answer, select the appropriate options in the answer area, NOTE: Each correct selection is worth one point.

22. You have an Azure Active Directory group named Group1. Group1 contains two Windows 10 Enterprise devices named Device1 and Device2.

You create a device configuration profile named Profile1. You assign Profile1 to Group1. You need to ensure that Profile1 applies to Device1 only.

What should you modify in Policy1?

23. HOTSPOT

Your network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD).

You have a Microsoft Office 365 subscription. All computers are joined to the domain and have the latest Microsoft OneDrive sync client (OneDrive.exe) installed.

On all the computers, you configure the OneDrive settings as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.

24. HOTSPOT

Your network contains an Active Directory domain. Active Directory is synced with Microsoft Azure Active Directory (Azure AD).

There are 500 domain-joined computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune.

You plan to implement Windows Defender Exploit Guard.

You need to create a custom Windows Defender Exploit Guard policy, and then distribute the policy to all the computers.

What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

25. HOTSPOT

You network contains an Active Directory domain. The domain contains 200 computers that run Windows 8.1. You have a Microsoft Azure subscription.

You plan to upgrade the computers to Windows 10.

You need to generate an Upgrade Readiness report for the computers.

What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

26. DRAG DROP

Your company uses Microsoft Intune. You have a Microsoft Store for Business account.

You need to ensure that you can deploy Microsoft Store for Business apps by using Intune.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

27. Your company has 200 computers that run Windows 10. The computers are managed by using Microsoft Intune.

Currently, Windows updates are downloaded without using Delivery Optimization.

You need to configure the computers to use Delivery Optimization.

What should you create in Intune?

28. You have computers that run Windows 10 and are managed by using Microsoft Intune.

Users store their files in a folder named D:Folder1.

You need to ensure that only a trusted list of applications is granted write access to D:Folder1.

What should you configure in the device configuration profile?

29. HOTSPOT

Your company has an infrastructure that has the following:

- A Microsoft 365 tenant

- An Active Directory forest

- Microsoft Store for Business

- A Key Management Service (KMS) server

- A Windows Deployment Services (WDS) server

- A Microsoft Azure Active Directory (Azure AD) Premium tenant

The company purchases 100 new computers that run Windows 10.

You need to ensure that the new computers are joined automatically to Azure AD by using Windows AutoPilot.

What should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

30. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your company has an Azure Active Directory (Azure AD) tenant named contoso.com that contains several Windows 10 devices.

When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin.

You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.

Solution: From the Azure Active Directory admin center, you configure the Authentication methods.

Does this meet the goal?

31. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these

questions will not appear in the review screen.

Your company uses Windows Update for Business.

The research department has several computers that have specialized hardware and software installed.

You need to prevent the video drivers from being updated automatically by using Windows Update.

Solution: From the Device Installation and Restrictions settings in a Group Policy object (GPO), you enable Prevent installation of devices using drivers that match these device setup classes, and then you enter the device GUID.

Does this meet the goal?

32. You have a Microsoft 365 subscription.

You have 20 computers that run Windows 10 and are joined to Microsoft Azure Active Directory (Azure AD)

You plan to replace the computers with new computers that run Windows 10. The new computers will be joined to Azure AD.

You need 10 ensure that the desktop background, the favorites, and the browsing history are available on the new computer.

What should you use?

33. HOTSPOT

You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune.

You need to configure an Intune device configuration profile to meet the following requirements:

- Prevent Microsoft Office applications from launching child processes.

- Block users from transferring files over FTP.

Which two settings should you configure in Endpoint protection? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

34. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure Directory group named Group1 that contains Windows 10 Enterprise devices and Windows 10 Pro devices.

From Microsoft Intune, you create a device configuration profile named Profile1.

You need to ensure that Profile1 applies to only the Windows 10 Enterprise devices in Group1.

Solution: You create an Azure Active Directory group that contains only the Windows 10 Enterprise devices. You assign Profile1 to the new group.

Does this meet the goal?

35. HOTSPOT

You have 1,000 computers that run Windows 10 and are members of an Active Directory domain.

You create a workspace in Microsoft Azure Log Analytics.

You need to capture the event logs from the computers to Azure.

What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

36. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a Microsoft 365 subscription.

You have 20 computers that run Windows 10 and are joined to Microsoft Azure Active Directory (Azure AD).

You plan to replace the computers with new computers that run Windows 10. The new computers will be joined to Azure AD.

You need to ensure that the desktop background, the favorites, and the browsing history are available on the new computers.

Solution: You configure Enterprise State Roaming.

Does this meet the goal?

37. HOTSPOT

You have a Microsoft 365 subscription.

Users have iOS devices that are not enrolled in Microsoft 365 Device Management.

You create an app protection policy for the Microsoft Outlook app as shown in the exhibit. (Click the Exhibit tab.)

You need to configure the policy to meet the following requirements:

- Prevent the users from using the Outlook app if the operating system version is less than 12.0.0.

- Require the users to use an alphanumeric passcode to access the Outlook app.

What should you configure in an app protection policy for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

38. HOTSPOT

You have computers that run Windows 10 and are configured by using Windows AutoPilot.

A user performs the following tasks on a computer named Computer1:

- Creates a VPN connection to the corporate network

- Installs a Microsoft Store app named App1

- Connects to a Wi-Fi network

You perform a Windows AutoPilot Reset on Computer1.

What will be the state of the computer when the user signs in? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

39. Your company has a main office and six branch offices. The branch offices connect to the main office by using a WAN link. All offices have a local Internet connection and a Hyper-V host cluster.

The company has a Microsoft System Center Configuration Manager deployment. The main office is the primary site. Each branch has a distribution point. All computers that run Windows 10 are managed by using both Configuration Manager and Microsoft Intune.

You plan to deploy the latest build of Microsoft Office 365 ProPlus to all the computers.

You need to minimize the amount of network traffic on the company’s Internet links for the planned deployment.

What should you include in the deployment plan?

40. HOTSPOT

You have a Microsoft 365 subscription.

You plan to enroll devices in Microsoft Endpoint Manager that have the platforms and versions shown in the following table.

You need to configure device enrollment to meet the following requirements:

- Ensure that only devices that have approved platforms and versions can enroll in Endpoint Manager.

- Ensure that devices are added to Microsoft Azure Active Directory (Azure AD) groups based on a selection made by users during the enrollment.

Which device enrollment setting should you configure for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

41. HOTSPOT

Your company has 1,000 Windows 10 devices that are enrolled in Windows Analytics.

You need to view the following information:

- The number of devices that are vulnerable to Spectre and Meltdown vulnerabilities

- The number of devices that have Windows Defender real-time protection turned off

Which Windows Analytics solutions should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

42. HOTSPOT

Your company uses Windows Defender Advanced Threat Protection (Windows Defender ATP).

Windows Defender ATP includes the machine groups shown in the following table.

You onboard a computer to Windows Defender ATP as shown in the following exhibit.

What is the effect of the Windows Defender ATP configuration? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

43. You enable controlled folder access in audit mode for several computers that run Windows 10. You need to review the events audited by controlled folder access.

Which Event Viewer log should you view?

44. Your company has a Microsoft Azure Active Directory (Azure AD) tenant.

The company has a Volume Licensing Agreement and uses a product key to activate Windows 10.

You plan to deploy Windows 10 Pro to 200 new computers by using the Microsoft Deployment Toolkit (MDT) and Windows Deployment Services (WDS).

You need to ensure that the new computers will be configured to have the correct product key during the installation.

What should you configure?

45. Your company has a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com. All users have computers that run Windows 10. The computers are joined to Azure AD and managed by using Microsoft Intune.

You need to ensure that you can centrally monitor the computers by using Windows Analytics.

What should you create in Intune ?

46. You have a Microsoft 365 subscription.

You have 20 computers that run Windows 10 and are joined to Microsoft Azure Active Directory (Azure AD).

You plan to replace the computers with new computers that run Windows 10. The new computers will be

joined to Azure AD.

You need to ensure that the desktop background, the favorites, and the browsing history are available on the new computers.

What should you use?

47. HOTSPOT

Your network contains an Active Directory domain. The domain contains 1,200 computers that run Windows 8.1.

You deploy an Upgrade Readiness solution in Microsoft Azure and configure the computers to report to Upgrade Readiness.

From Upgrade Readiness, you open a table view of the applications.

You need to filter the view to show only applications that can run successfully on Windows 10.

How should you configure the filter in Upgrade Readiness? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

48. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a computer that runs Windows 8.1.

Two days ago, you upgraded the computer to Windows 10.

You need to downgrade the computer to Windows 8.1.

Solution: You restart the computer to Windows Recovery Environment (Windows RE) and use the Advanced options.

Does this meet the goal?

49. Your company has a Microsoft 365 subscription.

The company uses Microsoft Intune to manage all devices.

The company uses conditional access to restrict access to Microsoft 365 services for devices that do not comply with the company’s security policies.

You need to identify which devices will be prevented from accessing Microsoft 365 services.

What should you use?

50. HOTSPOT

You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the devices shown in the following table.

All devices contain an app named App1 and are enrolled in Microsoft Intune.

You need to prevent users from copying data from App1 and pasting the data into other apps.

Which type of policy and how many policies should you create in Intune? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.


 

Microsoft 365 Security Administration Certification MS-500 Updated Dumps Questions
Microsoft Azure Security Technologies AZ-500 Updated Exam Dumps V15.02

Add a Comment

Your email address will not be published. Required fields are marked *