- (Exam Topic 4)
Your network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD). All computers are joined to the domain and registered to Azure AD.
The network contains a Microsoft System Center Configuration Manager (Current Batch) deployment that is configured for co-management with Microsoft Intune.
All the computers in the finance department are managed by using Configuration Manager. All the computers in the marketing department are managed by using Intune.
You install new computers for the users in the marketing department by using the Microsoft Deployment Toolkit (MDT).
You purchase an application named App1 that uses an MSI package.
You need to install App1 on the finance department computers and the marketing department computers.
How should you deploy App1 to each department? To answer, drag the appropriate deployment methods to the correct departments. Each deployment method may be used once, more than once, or not at all. You may need to drag the split bat between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Solution:
Reference:
https://docs.microsoft.com/en-us/intune/apps-add
https://docs.microsoft.com/en-us/sccm/apps/get-started/create-and-deploy-an-application
Does this meet the goal?
Correct Answer:
A
- (Exam Topic 4)
Your network contains an Active Directory domain that is synced to Microsoft Azure Active Directory (Azure AD). The domain contains computers that run Windows 10. The computers are enrolled in Microsoft Intune and Windows Analytics.
Your company protects documents by using Windows Information Protection (WIP). You need to identify non-approved apps that attempt to open corporate documents. What should you use?
Correct Answer:
D
References:
https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/wip
- (Exam Topic 4)
You create a Windows Autopilot deployment profile.
You need to configure the profile settings to meet the following requirements:
Include the hardware serial number in the computer name.
Which two settings should you configure? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.
Solution:
Graphical user interface, text, application Description automatically generated
Graphical user interface Description automatically generated
Reference:
https://docs.microsoft.com/en-us/mem/autopilot/profiles
Does this meet the goal?
Correct Answer:
A
- (Exam Topic 4)
You have a Microsoft 365 subscription that contains the computers shown in the following table.
You plan to use Windows Autopilot.
You need to ensure that the computers support automatic registration in Windows Autopilot.
What should you do for each computer? To answer, select the appropriate options in the answer area.
Solution:
Box 1: Join the computer to Azure AD.
You can deploy hybrid Azure AD-joined devices by using Intune and Windows Autopilot. Box 2: Upgrade the operating system to Windows 10 Enterprise
The device to be enrolled must follow these requirements:
Use Windows 11 or Windows 10 version 1809 or later.
Reference: https://docs.microsoft.com/en-us/mem/autopilot/windows-autopilot-hybrid
Does this meet the goal?
Correct Answer:
A
- (Exam Topic 4)
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.
MFA has a trusted IP address range of 123.30.20.0/24.
You have the Azure AD named locations shown in the following table.
You create a Conditional Access policy that has the following settings:
Name: CAPolicy1
Assignments
- Users or workload identities
- Include: Group1
- Cloud apps or actions: App1 Conditions
- Locations
- Include: All trusted locations
Access controls
- Grant access
- Require multi-factor authentication
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Solution:
Box 1: Yes
Location2 is not trusted.
Box 2: No
Location1 is trusted.
Box 3: No
MFA IP range is also trusted.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy-all
Does this meet the goal?
Correct Answer:
A