DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Success Secrets: Microsoft MD-102 Exam Questions & Mock Tests, Microsoft Windows Endpoint Administrator | SPOTO

Unlock the secrets to acing the Microsoft MD-102 certification exam with SPOTO's comprehensive exam questions and mock tests. Our latest practice tests provide a realistic exam experience, featuring online exam questions, sample questions, and accurate exam dumps. Gain access to a wealth of exam materials, including free tests for exam practice, and exam questions and answers that cover all the essential topics. Whether you're looking to enhance your knowledge of data protection, endpoint threat protection, or Microsoft Defender solutions, our MD-102 Manage Endpoint Security resources ensure you're fully prepared for the real test environment. Confidently pursue the Microsoft 365 Certified: Endpoint Administrator Associate certification with SPOTO's top-notch exam preparation resources.
Take other online exams

Question #1
You have a Microsoft 365 E5 subscription that contains 500 macOS devices enrolled in Microsoft Intune. You need to ensure that you can apply Microsoft Defender for Endpoint antivirus policies to the macOS devices. The solution must minimize administrative effort. What should you do?
A. From the Microsoft Endpoint Manager admin center, create a configuration profile
B. From the Microsoft Endpoint Manager admin center, create a security baseline
C. Onboard the macOS devices to the Microsoft 365 compliance center
D. Install Defender for Endpoint on the macOS devices
View answer
Correct Answer: A
Question #2
You have a Microsoft 365 E5 subscription that uses Microsoft Intune. You add apps to Intune as shown in the following table. You need to create an app configuration policy named Policy1 for the Android Enterprise platform. Which apps can you manage by using Policyl1?
A. App2 only
B. App3 only
C. App1 and App3 only
D. App2 and App3 only
E. App1, App2, and App3
View answer
Correct Answer: D
Question #3
You have a Microsoft 365 Business Standard subscription and 100 Windows 10 Pro devices. You purchase a Microsoft 365 E5 subscription. You need to upgrade the Windows 10 Pro devices to Windows 10 Enterprise. The solution must minimize administrative effort. Which upgrade method should you use?
A. Windows Autopilot
B. a Microsoft Deployment Toolkit (MDT) lite-touch deployment
C. Subscription Activation
D. an in-place upgrade by using Windows installation media
View answer
Correct Answer: A
Question #4
You use Microsoft Endpoint Manager to manage Windows 10 devices. You are designing a reporting solution that will provide reports on the following: Compliance policy trends Trends in device and user enrolment App and operating system version breakdowns of mobile devices You need to recommend a data source and a data visualization tool for the design. What should you recommend? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
View answer
Correct Answer: C
Question #5
Your network contains an Active Directory domain. The domain contains a computer named Computer! that runs Windows 11. You need to enable the Windows Remote Management (WinRM) service on Computer1 and perform the following configurations: ? For the WinRM service, set Startup type to Automatic. ? Create a listener that accepts requests from any IP address. ? Enable a firewall exception for WS-Management communications. Which PowerShell cmdlet should you use?
A. Connect-WSMan
B. Enable-PSRemoting
C. Invoke-WSManAction
D. Enable-PSSessionConfiguration
View answer
Correct Answer: A
Question #6
You have a Microsoft 365 subscription that uses Microsoft Intune. You plan to manage Windows updates by using Intune. You create an update ring for Windows 10 and later and configure the User experience settings for the ring as shown in the following exhibit. Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
View answer
Correct Answer: A
Question #7
Your company uses Microsoft Intune to manage devices. You need to ensure that only Android devices that use Android work profiles can enroll in intune. Which two configurations should you perform in the device enrollment restrictions? Each correct answer presents part of the solution. NOTE Each correct selection is worth one point.
A. From Platform Settings, set Android device administrator Personally Owned to Block
B. From Platform Settings, set Android Enterprise (work profile) to Allow
C. From Platform Settings, set Android device administrator Personally Owned to Allow
D. From Platform Settings, set Android device administrator to Block
View answer
Correct Answer: A
Question #8
You have a Microsoft 365 tenant that contains the objects shown in the following table. You are creating a compliance policy named Compliance1. Which objects can you specify in Compliance1 as additional recipients of noncompliance notifications?
A. Group3 and Group4 only
B. Group3, Group4, and Admin1 only
C. Group1, Group2, and Group3 only
D. Group1, Group2, Group3, and Group4 only
E. Group1, Group2, Group3, Group4, and Admin1
View answer
Correct Answer: A
Question #9
Which devices are registered by using the Windows Autopilot deployment service?
A. Device1 only
B. Device3 only
C. Device1 and Device3 only
D. Device1, Device2, and Device3
View answer
Correct Answer: C
Question #10
You have a Microsoft 365 subscription that contains 100 devices enrolled in Microsoft Intune. You need to review the startup processes and how often each device restarts. What should you use?
A. Endpoint analytics
B. Intune Data Warehouse
C. Azure Monitor
D. Device Management
View answer
Correct Answer: A
Question #11
You have a Microsoft 365 E5 subscription that contains the groups shown in the following table. You create a Conditional Access policy named CAPolicy1 that will block access to Microsoft Exchange Online from iOS devices. You assign CAPolicy1 to Group1. You discover that User1 can still connect to Exchange Online from an iOS device. You need to ensure that CAPolicy1 is enforced. What should you do?
A. Configure a new terms of use (TOU)
B. Assign CAPolicy1 to Group2
C. Enable CAPolicy1
D. Add a condition in CAPolicy1 to filter for devices
View answer
Correct Answer: A
Question #12
You have a Microsoft 365 subscription that includes Microsoft Intune. You need to implement a Microsoft Defender for Endpoint solution that meets the following requirements: ? Enforces compliance for Defender for Endpoint by using Conditional Access ? Prevents suspicious scripts from running on devices What should you configure? To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes
A. Mastered
B. Not Mastered
View answer
Correct Answer: ACE
Question #13
You have a Microsoft 365 subscription. All users have Microsoft 365 apps deployed. You need to configure Microsoft 365 apps to meet the following requirements: ? Enable the automatic installation of WebView2 Runtime. ? Prevent users from submitting feedback. Which two settings should you configure in the Microsoft 365 Apps admin center? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
View answer
Correct Answer: A
Question #14
You have a Microsoft Intune subscription. You have devices enrolled in intune as shown in the following table. An app named App1 is installed on each device. What is the minimum number of app configuration policies required to manage Appl ?
A. 1
B. 2
C. 3
D. 4
E. 5
View answer
Correct Answer: B
Question #15
You have a server named Server1 and computers that run Windows 8.1. Server1 has the Microsoft Deployment Toolkit (MDT) installed. You plan to upgrade the Windows 8.1 computers to Windows 10 by using the MDT deployment wizard. You need to create a deployment share on Server1. What should you do on Server1, and what are the minimum components you should add to the MDT deployment share? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
View answer
Correct Answer: C
Question #16
You have a Microsoft 365 subscription that contains 1,000 Android devices enrolled in Microsoft Intune. You create an app configuration policy that contains the following settings: ? Device enrollment type: Managed devices ? Profile Type: All Profile Types ? Platform: Android Enterprise Which two types of apps can be associated with the policy? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
A. Built-in Android app
B. Managed Google Play store app
C. Web link
D. Android Enterprise system app
E. Android store app
View answer
Correct Answer: A
Question #17
You have a Microsoft 365 subscription that contains a user named User1 and uses Microsoft Intune Suite. You use Microsoft Intune to manage devices that run Windows 11. User1 provides remote support for 75 devices in the marketing department. You need to add User1 to the Remote Desktop Users group on each marketing department device. What should you configure?
A. an app configuration policy
B. a device compliance policy
C. an account protection policy
D. a device configuration profile
View answer
Correct Answer: A
Question #18
You use Windows Admin Center to remotely administer computers that run Windows 10. When connecting to Windows Admin Center, you receive the message shown in the following exhibit. You need to prevent the message from appearing when you connect to Windows Admin Center. To which certificate store should you import the certificate?
A. Personal
B. Trusted Root Certification Authorities
C. Client Authentication Issuers
View answer
Correct Answer: A
Question #19
You have 200 computers that run Windows 10. The computers are joined to Azure AD and enrolled in Microsoft Intune. You need to set a custom image as the wallpaper and sign-in screen. Which two settings should you configure in the Device restrictions configuration profile? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
View answer
Correct Answer: A
Question #20
You use Microsoft Defender for Endpoint to protect computers that run Windows 10. You need to assess the differences between the configuration of Microsoft Defender for Endpoint and the Microsoft-recommended configuration baseline. Which tool should you use?
A. Microsoft Defender for Endpoint Power 81 app
B. Microsoft Secure Score
C. Endpoint Analytics
D. Microsoft 365 Defender portal
View answer
Correct Answer: A
Question #21
You have computer that run Windows 10 and connect to an Azure Log Analytics workspace. The workspace is configured to collect all available events from Windows event logs. The computers have the logged events shown in the following table. Which events are collected in the Log Analytics workspace?
A. 1 only
B. 2 and 3 only
C. 1 and 3 only
D. 1, 2, and 4 on
E. 1, 2, 3, and 4
View answer
Correct Answer: A
Question #22
You have an Azure AD tenant named contoso.com. You have the devices shown in the following table. Which devices can be Azure AD joined, and which devices can be registered in contoso.com? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
View answer
Correct Answer: A
Question #23
You have a Microsoft 365 E5 subscription that contains 150 hybrid Azure AD joined Windows devices. All the devices are enrolled in Microsoft Intune. You need to configure Delivery Optimization on the devices to meet the following requirements: ? Allow downloads from the internet and from other computers on the local network. ? Limit the percentage of used bandwidth to 50. What should you use?
A. a configuration profile
B. a Windows Update for Business Group Policy setting
C. a Microsoft Peer-to-Peer Networking Services Group Policy setting
D. an Update ring for Windows 10 and later profile
View answer
Correct Answer: B
Question #24
You have a Hyper-V host that contains the virtual machines shown in the following table. On which virtual machines can you install Windows 11?
A. VM1 only
B. VM3only
C. VM1 and VM2 only
D. VM2 and VM3 only
E. VM1, VM2, and VM3
View answer
Correct Answer: AC
Question #25
You have a Microsoft 365 subscription. You have devices enrolled in Microsoft Intune as shown in the following table. To which devices can you deploy apps by using Intune?
A. Device1 only
B. Device1 and Device2 only
C. Device1 and Device3 only
D. Device1, Device2, and Device3 only
E. Device1, Device2, Device3, and Device4
View answer
Correct Answer: B
Question #26
You have SOO Windows 10 devices enrolled in Microsoft Intune. You plan to use Exploit protection in Microsoft Intune to enable the following system settings on the devices: ? Data Execution Prevention (DEP) ? Force randomization for images (Mandatory ASlR) You need to configure a Windows 10 device that will be used to create a template file. Which protection areas on the device should you configure in the Windows Security app before you create the template file? To answer, drag the appropriate protection ar
A. Mastered
B. Not Mastered
View answer
Correct Answer: A
Question #27
You have an Azure AD tenant and 100 Windows 10 devices that are Azure AD joined and managed by using Microsoft Intune. You need to configure Microsoft Defender Firewall and Microsoft Defender Antivirus on the devices. The solution must minimize administrative effort. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
A. To configure Microsoft Defender Antivirus, create a Group Policy Object (GPO) and configure the Windows Defender Antivirus settings
B. To configure Microsoft Defender Firewall, create a device configuration profile and configure the Device restrictions settings
C. To configure Microsoft Defender Antivirus, create a device configuration profile and configure the Endpoint protection settings
D. To configure Microsoft Defender Antivirus, create a device configuration profile and configure the Device restrictions settings
E. To configure Microsoft Defender Firewall, create a device configuration profile and configure the Endpoint protection settings
F. To configure Microsoft Defender Firewall, create a Group Policy Object (GPO) and configure Windows Defender Firewall with Advanced Security
View answer
Correct Answer: B
Question #28
You have a Microsoft 365 E5 subscription that contains a group named Group1. You create a Conditional Access policy named CAPolicy1 and assign CAPolicy1 to Group1. You need to configure CAPolicy1 to require the members of Group1 to reauthenticate every eight hours when they connect to Microsoft Exchange Online. What should you configure?
A. Session access controls
B. an assignment that uses a User risk condition
C. an assignment that uses a Sign-in risk condition
D. Grant access controls
View answer
Correct Answer: A
Question #29
What should you upgrade before you can configure the environment to support co-management?
A. the domain functional level
B. Configuration Manager
C. the domain controllers
D. Windows Server Update Services (WSUS)
View answer
Correct Answer: B
Question #30
You have 25 computers that run Windows 10 Pro. You have a Microsoft 365 E5 subscription that uses Microsoft Intune. You need to upgrade the computers to Windows 11 Enterprise by using an in-place upgrade. The solution must minimize administrative effort. What should you use?
A. Microsoft Deployment Toolkit (MDT) and a default image of Windows 11 Enterprise
B. Microsoft Configuration Manager and a custom image of Windows 11 Enterprise
C. Windows Autopilot
D. Subscription Activation
View answer
Correct Answer: B
Question #31
You have a Microsoft 365 subscription that uses Microsoft Intune. You have five new Windows 11 Pro devices. You need to prepare the devices for corporate use. The solution must meet the following requirements: ? Install Windows 11 Enterprise on each device. ? Install a Windows Installer (MSI) package named App1 on each device. ? Add a certificate named Certificate1 that is required by App1. ? Join each device to Azure AD. Which three provisioning options can you use? Each correct answer presents a complete
A. subscription activation
B. a custom Windows image
C. an in-place upgrade
D. Windows Autopilot
E. provisioning packages
View answer
Correct Answer: A
Question #32
You have a Microsoft 365 E5 subscription that contains the users shown in the following table. In the Microsoft 365 Apps admin center, you create a Microsoft Office customization. Which users can download the Office customization file from the admin center?
A. Admin1, Admin2, Admin3
B. Admin1, Admin2, and Admin3 only
C. Admin3 only
D. Admin3 and Admin4 only
E. Admin1 and Admin3 only
View answer
Correct Answer: D
Question #33
You have an Azure AD tenant named contoso.com that contains a user named Used. User! has a user principal name (UPN) of user1@contoso.com. You join a Windows 11 device named Client 1 to contoso.com. You need to add User1 to the local Administrators group of Client1. How should you complete the command? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
View answer
Correct Answer: D
Question #34
You have 100 Windows 10 devices enrolled in Microsoft Intune. You need to configure the devices to retrieve Windows updates from the internet and from other computers on a local network. Which Delivery Optimization setting should you configure, and which type of Intune object should you create? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
View answer
Correct Answer: C
Question #35
You have a Microsoft 365 subscription that uses Microsoft Intune Suite. You use Microsoft Intune to manage devices. You use Windows Autopilot to deploy Windows 11 to devices. A support engineer reports that when a deployment fails, they cannot collect deployment logs from failed device. You need to ensure that when a deployment fails, the deployment logs can be collected. What should you configure?
A. the automatic enrollment settings
B. the Windows Autopilot deployment profile
C. the enrollment status page (ESP) profile
D. the device configuration profile
View answer
Correct Answer: A
Question #36
You have 100 computers that run Windows 10 and connect to an Azure Log Analytics workspace. Which three types of data can you collect from the computers by using Log Analytics? Each correct answer a complete solution. NOTE: Each correct selection is worth one point.
A. error events from the System log
B. failure events from the Security log
C. third-party application logs stored as text files
D. the list of processes and their execution times
E. the average processor utilization
View answer
Correct Answer: A
Question #37
You have an on-premises server named Server! that hosts a Microsoft Deployment Toolkit (MDT) deployment share named MDT1. You need to ensure that MDT1 supports multicast deployments. What should you install on Server1?
A. Multipath I/O (MPIO)
B. Multipoint Connector
C. Windows Deployment Services (WDS)
D. Windows Server Update Services (WSUS)
View answer
Correct Answer: B
Question #38
You have a Microsoft 365 E5 subscription that uses Microsoft Intune. The subscription contains the users shown in the following table. Group2 and Group3 are members of Group1. All the users use Microsoft Excel. From the Microsoft Endpoint Manager admin center, you create the policies shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
View answer
Correct Answer: B

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number: