Free MD-102 Exam Braindumps

Pass your Endpoint Administrator exam with these free Questions and Answers

Page 4 of 20
QUESTION 11

- (Exam Topic 3)
Your network contains an Active Directory domain named contoso.com. The domain contains a computer named Computer1 that runs Windows 10. You have the groups shown in the following table.
MD-102 dumps exhibit
Which groups can you add to Group4?

  1. A. Group2only
  2. B. Group1 and Group2 only
  3. C. Group2 and Group3 only
  4. D. Group1, Group2, and Group3

Correct Answer: C

QUESTION 12

- (Exam Topic 3)
You have an Azure AD tenant named contoso.com. You have the devices shown in the following table.
MD-102 dumps exhibit
Which devices can be Azure AD joined, and which devices can be registered in contoso.com? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
MD-102 dumps exhibit
Solution:
MD-102 dumps exhibit

Does this meet the goal?

  1. A. Yes
  2. B. No

Correct Answer: A

QUESTION 13

- (Exam Topic 3)
You have an Azure AD group named Group1. Group! contains two Windows 10 Enterprise devices named Device1 and Device2. You create a device configuration profile named Profile1. You assign Profile! to Group1. You need to ensure that Profile! applies to Device1 only. What should you modify in Profile 1?

  1. A. Assignments
  2. B. Settings
  3. C. Scope (Tags)
  4. D. Applicability Rules

Correct Answer: D
To ensure that Profile1 applies to Device1 only, you need to modify the Applicability Rules in Profile1. You can use applicability rules to filter which devices receive a profile based on criteria such as device model, manufacturer, or operating system version. You can create an applicability rule that matches Device1’s properties and excludes Device2’s properties. References:
https://docs.microsoft.com/en-us/mem/intune/configuration/device-profile-assign#applicability-rules

QUESTION 14

- (Exam Topic 3)
You have a Microsoft 365 E5 subscription.
You create an app protection policy for Android devices named Policy1 as shown in the following exhibit.
MD-102 dumps exhibit
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
MD-102 dumps exhibit
Solution:
Box 1: Install the Intune Company Portal app on the device
On Android, Android devices will prompt to install the Intune Company Portal app regardless of which Device type is chosen.
Bix 2: Devices only
For Android devices, unmanaged devices are devices where Intune MDM management has not been detected. This includes devices managed by third-party MDM vendors.
Reference:
https://docs.microsoft.com/en-us/mem/intune/apps/app-protection-policies#app-protection-policies-for-iosipado

Does this meet the goal?

  1. A. Yes
  2. B. No

Correct Answer: A

QUESTION 15

- (Exam Topic 3)
You have the on-premises servers shown in the following table.
MD-102 dumps exhibit
You have a Microsoft 365 E5 subscription that contains Android and iOS devices. All the devices are managed by using Microsoft Intune.
You need to implement Microsoft Tunnel for Intune. The solution must minimize the number of open firewall ports.
To which server can you deploy a Tunnel Gateway server, and which inbound ports should be allowed on the server to support Microsoft Tunnel connections? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
MD-102 dumps exhibit
Solution:
Box 1: Server4
Microsoft Tunnel is a VPN gateway solution for Microsoft Intune that runs in a container on Linux and allows access to on-premises resources from iOS/iPadOS and Android Enterprise devices using modern authentication and Conditional Access.
Box 2: TCP 443 and UDP 443 only
Some traffic goes to your public facing IP address for the Tunnel. The VPN channel will use TCP, TLS, UDP, and DTLS over port 443.
By default, port 443 is used for both TCP and UDP, but this can be customized via the Intune Saerver Configuration – Server port setting. If changing the default port (443) ensure your inbound firewall rules are adjusted to the custom port.
Incorrect:
TCP 1723 is not used.
Reference: https://docs.microsoft.com/en-us/mem/intune/protect/microsoft-tunnel-overview

Does this meet the goal?

  1. A. Yes
  2. B. No

Correct Answer: A

Page 4 of 20

Post your Comments and Discuss Microsoft MD-102 exam with other Community members: