1.
Your company uses Microsoft Intune to manage devices. You need to ensure that only Android devices that use Android work profiles can enroll in Intune. Which two configurations should you perform in the device enrollment restrictions? Each correct answer presents part of the solution. NOTE: each correct selection is worth one point.
2.
You have a Microsoft Azure Log Analytics workplace that collects all the event logs from the computers at your company. You have a computer named Computer1 than runs Windows 10. You need to view the events collected from Computer1. Which query should you run in Log Analytics?
3.
You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune. You need to ensure that only applications that you explicitly allow can run on the computers. What should you use?
4.
Your company has a Microsoft Azure Active Directory (Azure AD) tenant. All users in the company are licensed for Microsoft Intune. You need to ensure that the users enroll their iOS device in Intune. What should you configure first?
5.
You have a shared computer that runs Windows 10. The computer is infected with a virus. You discover that a malicious TTF font was used to compromise the computer. You need to prevent this type of threat from affecting the computer in the future. What should you use?
6.
Your network contains an Active Directory domain. The functional level of the forest and the domain is Windows Server 2012 R2. The domain contains 500 computers that run Windows 10. All the computers are managed by using Microsoft System Center 2012 R2 Configuration Manager. You need to enable co-management. What should you do first?
7.
Your network contains an Active Directory domain named contoso.com. The domain contains computers that run Windows 10 and are joined to the domain. The domain is synced to Microsoft Azure Active Directory (Azure AD). You create an Azure Log Analytics workspace and deploy the Device Health solution. You need to enroll the computers in Windows Analytics. Which Group Policy setting should you configure?
8.
You need to enable Windows Defender Credential Guard on computers that run Windows 10. What should you install on the computers?
9.
You have 100 devices that run Windows 10 and are joined to Microsoft Azure Active Directory (Azure AD). You need to prevent users from joining their home computer to Azure AD. What should you do?
10.
Your company has a Microsoft 365 subscription. A new user named Admin1 is responsible for deploying Windows 10 to computers and joining the computers to Microsoft Azure Active Directory (Azure AD). Admin1 successfully joins computers to Azure AD. Several days later, Admin1 receives the following error message: "This user is not authorized to enroll. You can try to do this again or contact your system administrator with the error code (0x801c0003)." You need to ensure that Admin1 can join computers to Azure AD and follow the principle of least privilege. What should you do?