Endpoint Administrator Free Sample Questions

20 free sample questions177 in the full practice test Other versions: 70-697(214),98-349(50),MD-100(48),MD-101(50)

Try simulator

MD-102 Sample Questions

  1. Question 1

    A financial services company is implementing Microsoft Intune to manage its Windows 11 devices. The security team requires that all devices have BitLocker encryption enabled and that recovery keys are backed up to Microsoft Entra ID. However, a specific group of legacy accounting devices lacks a Trusted Platform Module (TPM) 2.0 chip. You need to create a compliance policy that enforces BitLocker but accommodates these legacy devices. Which configuration is required to achieve this?

    Answer and explanation

    Correct answer: B

    Intune compliance policies for BitLocker do not automatically adapt for devices without a TPM. The best practice for this scenario is to create two distinct policies and use dynamic device groups to target them appropriately. One group can be created with a rule like (device.deviceTrustType -eq "TPM") for TPM-enabled devices, and another for devices without a TPM or with an older version. This ensures that all devices are evaluated for compliance correctly based on their hardware capabilities.

  2. Question 2

    Your organization uses Microsoft Intune Suite and has implemented Endpoint Privilege Management (EPM). A new policy is created to allow users to run a specific legacy application, C:\Apps\LegacyApp.exe, with administrative privileges. After deploying the policy, users report they are still prompted for admin credentials. You verify the policy is assigned to the correct user group and the file path is correct. What is the most likely cause of this issue?

    Answer and explanation

    Correct answer: B

    Endpoint Privilege Management rules require more than just a file path for validation to prevent spoofing. A robust rule must include a file hash, a certificate signature, or both. If only the file path is defined, EPM will not trust the rule and will not elevate the application, resulting in the standard User Account Control (UAC) prompt. The most secure and reliable method is to include the file hash, which ensures the exact version of the executable is being elevated.

  3. Question 3

    Multiple answers

    You are deploying Windows 11 devices using Windows Autopilot user-driven mode for a hybrid work environment. You need to ensure that specific business-critical applications are installed and security policies are applied before users can access the desktop. However, you want to allow users to start working as soon as possible, even if non-essential applications are still installing in the background. Which two components of the Enrollment Status Page (ESP) should you configure? (Select TWO)

    Answer and explanation

    Correct answers: C, D

    This setting is the core of the ESP's function. By setting it to 'Yes', you ensure the user is held at the ESP screen until the specified configurations are complete.

    This allows you to define a subset of required applications that must be installed before the user can proceed. Other applications assigned as 'Required' but not on this blocking list will continue to install in the background after the user reaches the desktop.

  4. Question 4

    A university is deploying shared Windows 11 devices in a computer lab. The devices must be configured in kiosk mode to run only the Microsoft Edge browser. Additionally, after each user session, the device must automatically sign out the user and delete the local profile to ensure data privacy and a clean state for the next user. Which type of account should be configured for the kiosk profile to meet these requirements?

    Answer and explanation

    Correct answer: D

    The 'Guest account' option within the multi-app kiosk configuration is specifically designed for shared device scenarios. It creates a temporary local account for each session. When the user signs out or the session ends, this temporary account and all associated data are deleted, ensuring a clean and secure environment for the next user.

  5. Question 5

    True or False: When configuring an Intune app protection policy for iOS devices, setting the 'Save copies of org data' policy to 'Block' will prevent users from saving corporate files to any personal cloud storage app, but will still allow saving to the local device storage by default.

    Answer and explanation

    Correct answer: B

    The statement is false. The 'Save copies of org data' policy setting controls where users can save corporate data. When set to 'Block', it prevents saving to any non-policy managed location, which includes both personal cloud storage apps AND the local device storage. To allow saving to a specific corporate location like OneDrive, you must configure policy-managed locations.

  6. Question 6

    A company is migrating its local administrator password management to Microsoft Entra LAPS. An administrator needs to retrieve the password for a specific device, DESKTOP-ABC, to perform a maintenance task. The administrator has been assigned the 'Cloud Device Administrator' role in Microsoft Entra ID. Where can the administrator retrieve the LAPS password for DESKTOP-ABC?

    Answer and explanation

    Correct answer: B

    With the correct permissions (such as Cloud Device Administrator or Intune Administrator), the LAPS password for a Microsoft Entra joined device can be retrieved from both the Microsoft Entra admin center and the Microsoft Intune admin center. On the device's object page in either portal, there is a 'Local administrator password' blade or option to view the password. This is the primary location for administrative retrieval.

  7. Question 7

    You are creating a filter in Microsoft Intune to target a device configuration profile to only corporate-owned Windows devices that are part of the marketing department. The department information is stored in the department device property. Which rule syntax should you use for this filter?

    Answer and explanation

    Correct answer: A

    The correct syntax for an Intune filter rule uses the device or user prefix, followed by the property name. The -eq operator is used for equality checks, and the -and operator combines multiple conditions. Therefore, (device.deviceOwnership -eq "Corporate") -and (device.department -eq "Marketing") correctly targets devices that meet both criteria.

  8. Question 8

    A global organization wants to optimize the delivery of Windows quality updates to its branch offices, which have limited WAN bandwidth. The goal is to have devices in each office share update content with each other before downloading from the internet. The network is segmented by subnet. What is the most effective Delivery Optimization download mode to configure in Intune to achieve this?

    Answer and explanation

    Correct answer: C

    Download mode 2, 'Group', is the most effective choice. It restricts peer sharing to devices within the same group. When you configure the 'Select the source of group IDs' setting to use the AD Site or a DHCP option, devices in the same physical location (branch office) can form a peer group and share content efficiently over the LAN, significantly reducing WAN bandwidth consumption.

  9. Question 9

    A hospital is deploying dedicated Android Enterprise devices for patient check-in. These devices must be locked down to a single application and require a secure method of enrollment that can be easily performed by non-technical staff. The devices are new and will be unboxed on-site. Which enrollment method should be used?

    Answer and explanation

    Correct answer: C

    For dedicated devices (kiosk mode), enrollment using a QR code is ideal for on-site, bulk provisioning by non-technical staff. From the factory reset screen, tapping the screen multiple times initiates the QR code scanner. Scanning the QR code generated from the Intune enrollment profile automates the Wi-Fi connection, agent download, and enrollment process into dedicated device mode.

  10. Question 10

    You are packaging a complex Win32 application for deployment via Intune. The application has a dependency on the .NET Framework 4.8 runtime. You need to ensure the .NET Framework is installed before the main application attempts to install. How should you configure this in the Win32 app properties in Intune?

    Answer and explanation

    Correct answer: C

    The 'Dependencies' feature for Win32 apps in Intune is designed for this exact scenario. You must first package and upload the .NET Framework 4.8 as a separate Win32 app. Then, when configuring the main application, you can add the .NET Framework app as a dependency and configure it to automatically install. Intune will then process the dependency chain, ensuring the framework is installed before the main application.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 539 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon