MD-101 Exam Question 21

Your network contains an Active Directory domain. Active Directory is synced with Microsoft Azure Active Directory (Azure AD).
There are 500 Active Directory domain-joined computers that run Windows 10 and are enrolled in Microsoft Intune.
You plan to implement Microsoft Defender Exploit Guard.
You need to create a custom Microsoft Defender Exploit Guard policy, and then distribute the policy to all the computers.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

MD-101 Exam Question 22

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a computer named Computer1 that runs Windows 10.
You save a provisioning package named Package1 to a folder named C:\Folder1.
You need to apply Package1 to Computer1.
Solution: From File Explorer, you go to C:\Folder1, and then you double-click the Package1.ppkg file.
Does this meet the goal?
  • MD-101 Exam Question 23

    You have computers that run Windows 10 as shown in the following table.

    Computer2 and Computer3 are enrolled in Microsoft Intune.
    In a Group Policy object (GPO) linked to the domain, you enable the Computer Configuration/Administrative Templates/Windows Components/Search/Allow Cortana setting.
    In an Intune device configuration profile, you configure the following:
    * Device/Vendor/MSFT/Policy/Config/ControlPolicyConflict/MDMWinsOverGP to a value of 1
    * Experience/AllowCortana to a value of 0.
    Each of the following statement, select Yes if the statement is true. Otherwise, select No.
    NOTE: Each correct selection is worth one point.

    MD-101 Exam Question 24

    You have a Microsoft Intune subscription that has the following device compliance policy settings:
    Mark devices with no compliance policy assigned as: Compliant
    Compliance status validity period (days): 14
    On January 1, you enroll Windows 10 devices in Intune as shown in the following table.

    On January 4, you create the following two device compliance policies:
    * Name: Policy1
    * Platform: Windows 10 and later
    * Require BitLocker: Require
    * Mark device noncompliant: 5 days after noncompliance
    * Scope (Tags): Tag1
    * Name: Policy2
    * Platform: Windows 10 and later
    * Firewall: Require
    * Mark device noncompliant: Immediately
    * Scope (Tags): Tag2
    On January 5, you assign Policy1 and Policy2 to Group1.
    For each of the following statements, select Yes if the statement is true. Otherwise, select No.
    NOTE: Each correct selection is worth one point.

    MD-101 Exam Question 25

    You have the devices shown in the following table.

    You plan to implement Microsoft Defender for Endpoint.
    You need to identify which devices can be onboarded to Microsoft Defender for Endpoint.
    What should you identify?