Topic 4: Mix Question

You have a Microsoft 365 subscription that contains 100 devices enrolled in Microsoft Intune.

You need to review the startup processes and how often each device restarts.

What should you use?

A. Endpoint analytics

B. Intune Data Warehouse

C. Azure Monitor

D. Device Management

B.   Intune Data Warehouse

You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.



You create a Conditional Access policy named CAPolicy1 that will block access to Microsoft Exchange Online from iOS devices. You assign CAPolicy1 to Group1.

You discover that User1 can still connect to Exchange Online from an iOS device.

You need to ensure that CAPolicy1 is enforced.

What should you do?

A. Configure a new terms of use (TOU).

B. Assign CAPolicy1 to Group2.

C. Enable CAPolicy1

D. Add a condition in CAPolicy1 to filter for devices.

B.   Assign CAPolicy1 to Group2.

You manage 1,000 computers that run Windows 10. All the computers are enrolled in Microsoft Intune. You manage the servicing channel settings of the computers by using Intune.

You need to review the servicing status of a computer.

What should you do?

A. From Software updates, view the Per update ring deployment state.

B. From Software updates, view the audit logs.

C. From Device configuration - Profiles, view the device status.

D. From Device compliance, view the device compliance.

A.   From Software updates, view the Per update ring deployment state.

Your company has an Azure AD tenant named contoso.com that contains several Windows 10 devices.

When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin.

You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.

Solution: From the Microsoft Entra admin center, you modify the User settings and the Device settings.

Does this meet the goal?

A. Yes

B. No

B.   No

You have devices enrolled in Microsoft Intune as shown in the following table.



Intune includes the device compliance policies shown in the following table.



The device compliance policies have the assignments shown in the following table.



For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.


Your company has a Microsoft 365 E5 tenant.

All the devices of the company are enrolled in Microsoft Intune.

You need to create advanced reports by using custom queries and visualizations from raw Microsoft Intune data.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.


You have a Microsoft 365 subscription that contains 1,000 iOS devices. The devices are enrolled in Microsoft Intune as follows:

• Two hundred devices are enrolled by using the Intune Company Portal.

• Eight hundred devices are enrolled by using Apple Automated Device Enrollment (ADE).

You create an iOS/iPadOS software updates policy named Policy 1 that is configured to install iOS/iPadOS 15.5.

How many iOS devices will Policy1 update, and what should you configure to ensure that only iOS/iPadOS 15.5 is installed? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


You have a Microsoft 365 E5 subscription.

All devices are enrolled in Microsoft Intune.

You need to ensure that devices that have NOT checked in for 30 days are deleted from intune.

What should you configure from the Microsoft Intune admin center?

A. a device limit restriction

B. automatic enrollment

C. a device clean-up rule

D. a configuration profile

C.   a device clean-up rule

You use Windows Admin Center to remotely administer computers that run Windows 10.

When connecting to Windows Admin Center, you receive the message shown in the following exhibit.



You need to prevent the message from appearing when you connect to Windows Admin Center.

To which certificate store should you import the certificate?

A. Personal

B. Trusted Root Certification Authorities

C. Client Authentication Issuers

B.   Trusted Root Certification Authorities

You have a Microsoft 365 E5 subscription that contains a group named Group1.

You create a Conditional Access policy named CAPolicy1 and assign CAPolicy1 to Group1.

You need to configure CAPolicy1 to require the members of Group1 to reauthenticate every eight hours when they connect to Microsoft Exchange Online.

What should you configure?

A. Session access controls

B. an assignment that uses a User risk condition

C. an assignment that uses a Sign-in risk condition

D. Grant access controls

A.   Session access controls

Page 8 out of 32 Pages