[2026年02月23日] MD-102のPDFで最近更新された問題です集試験点数を伸ばそう [Q108-Q133]

Share

[2026年02月23日] MD-102のPDFで最近更新された問題です集試験点数を伸ばそう

MD-102完全版問題集には無料PDF問題で合格させる


Microsoft MD-102 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • Prepare infrastructure for devices: This topic focuses on adding devices to Microsoft Entra ID and enrolling devices to Microsoft Intune.
トピック 2
  • Manage and maintain devices: This section deals with managing, troubleshooting, and safeguarding various devices. It also covers methods to ensure that they meet organizational policies and security standards.
トピック 3
  • Protect devices: In this topic, aspiring administrators get knowledge about configuration of endpoint security and management of device updates by using Intune.
トピック 4
  • Manage applications: This section covers skills to manage application implementation, manage updates, and manage performance to support the performance of users to meet the needs of business organizations.

 

質問 # 108
In Microsoft Intune, you have the device compliance policies shown in the following table.

The Intune compliance policy settings are configured as shown in the following exhibit.

On June 1, you enroll Windows 10 devices in Intune as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

正解:

解説:

Device 1 is Windows 10 - and policy 1 is for Windows 8. Default compliance for devices without a policy is not compliant so first 2 questions are NO.
Then the third device has 2 policies, the first one is compliant and the second policy is not compliant but the device is not marked as non-compliant due to the fact that mark device as non-compliant is set to 10 days. This means that the machine will be compliant until june 10th.
Source:
Mark device non-compliant: By default, this action is set for each compliance policy and has a schedule of zero (0) days, marking devices as noncompliant immediately.
When you change the default schedule, you provide a grace period in which a user can remediate issues or become compliant without being marked as non-compliant.
This action is supported on all platforms supported by Intune.
https://docs.microsoft.com/en-us/mem/intune/protect/actions-for-noncompliance


質問 # 109
You have a Microsoft 365 subscription that uses Microsoft Intune Suite.
You use Microsoft Intune to manage Windows 11 devices.
You need to implement passwordless authentication that requires users to use number matching Which authentication method should you use?

  • A. text messages
  • B. FI002 security keys
  • C. voice calls
  • D. Microsoft Authenticator

正解:D


質問 # 110
You have a Microsoft 365 E5 subscription.
You have a Microsoft Intune enrollment profile for Android Enterprise devices that has the following settings:
* Name: Profile1
* Token type: Corporate-owned, fully managed
You need to enroll a new Android device in Intune by using Profile1. What should you use to enroll the device?

  • A. the Intune app
  • B. aQRcode
  • C. the Company Portal app
  • D. the Microsoft Authenticate app

正解:D


質問 # 111
You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains a user named User1. User1 has a user principal name (UPN) of user1 @contoso.com.
You join a Windows 10 device named Client1 to contoso.com.
You need to add User1 to the local Administrators group of Client1.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:


質問 # 112
You have a Microsoft 365 subscription that contains the devices shown in the following table.

You need to ensure that only devices running trusted firmware or operating system build can access network resources.
Which compliance policy setting should you configure for each device? To answer, drag the appropriate settings to the correct devices. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

正解:

解説:


質問 # 113
You have a Microsoft 365 tenant that contains the objects shown in the following table.

In the Microsoft Intune admin center, you are creating a Microsoft 365 Apps app named App1. To which objects can you assign App1?

  • A. Admin1, Group1. Group2, Group3, andGroup4
  • B. Group1, Group3, and Group4 only
  • C. Group1, Group2, Group3, and Group4 only
  • D. Group3 and Group4 only
  • E. Admin1, Group3, and Group4 only

正解:B

解説:
In the Microsoft Intune admin center, you can assign apps to users or devices. Users can be assigned to apps by using user groups or individual user accounts. Devices can be assigned to apps by using device groups. In this scenario, the objects shown in the table are as follows:
Admin1 is an individual user account that belongs to the Global administrators role group.
Group1 is a user group that contains 100 users.
Group2 is a device group that contains 50 devices.
Group3 is a user group that contains 200 users.
Group4 is a device group that contains 150 devices.
Since App1 is a Microsoft 365 Apps app, it can only be assigned to users, not devices. Therefore, Group2 and Group4 are not valid objects for app assignment. Admin1 is also not a valid object for app assignment, because individual user accounts can only be used for testing purposes, not for production deployment. Therefore, the only valid objects for app assignment are Group1 and Group3, which are user groups.


質問 # 114
-
You have a Microsoft 365 subscription that contains devices enrolled in Microsoft Intune.
You need to create Endpoint security policies to enforce the following requirements:
* Computers that run macOS must have FileVault enabled.
* Computers that run Windows 10 must have Microsoft Defender Credential Guard enabled.
* Computers that run Windows 10 must have Microsoft Defender Application Control enabled.
Which Endpoint security feature should you use for each requirement? To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

正解:

解説:

Explanation:

Disk Encryption
ASR - Ref
https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-asr-policy#:~:text=Application%20contr Account Protection - Ref
https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/configure?tabs=intune#:


質問 # 115
You have a Microsoft 365 E5 subscription that contains a user named User1.
You need to perform the following tasks for User1:
* Set the Usage location to Canada.
* Configure the Phone and Email authentication contact info for self-service password reset (SSPR).
Which two settings should you configure in the Azure Active Directory admin center? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:

Explanation:


質問 # 116
You have a Microsoft 365 E5 subscription that uses Microsoft Intune. The subscription contains the users shown in the following table.

Group2 and Group3 are members of Group1.
All the users use Microsoft Excel.
From the Microsoft Endpoint Manager admin center, you create the policies shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

正解:

解説:


質問 # 117
You have the MDM Security Baseline profile shown in the MDM exhibit. (Click the MDM tab.) You have the ASR Endpoint Security profile shown in the ASR exhibit. (Click the ASR tab.)


You plan to deploy both profiles to devices enrolled in Microsoft Intune. You need to identify how the following settings will be configured on the devices:
* Block Office applications from creating executable content
* Block Win32 API calls from Office macro
Currently, the settings are disabled locally on each device.
What are the effective settings on the devices? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:

Explanation:
lock Office App from creating executable content: Audit Mode
Both are set to Audit so that's what it will do.
Block Win32 API calls from the Office Macro: Audit
If you set the Baseline policy as Disable or Not Configured (same thing), and you have any other setting in the ASR, the ASR configuration will take over. That's how enterprise environments enforce granular controls of policies that are enforced for a smaller subset of the employee population. The article below (Jan 27, 2024) outlines the scenario and provides comments about this. In theory this also makes sense. If the baseline policy is configured to do nothing, and the ASR policy is configured to Audit, Block or Warn, I should think the ASR policy setting will take over the configuration.


質問 # 118
Hotspot Question
Your company has an infrastructure that has the following:
- A Microsoft 365 tenant
- An Active Directory forest
- Microsoft Intune
- A Key Management Service (KMS) server
- A Windows Deployment Services (WDS) server
- An Azure AD Premium tenant
The company purchases 100 new client computers that run Windows.
You need to ensure that the new computers are joined automatically to Azure AD by using Windows Autopilot.
What should you use? To answer, select the appropriate options in the answer area, NOTE: Each correct selection is worth one point.

正解:

解説:

Explanation:
Box 1: Microsoft Intune admin center
Box 2: Device serial number and hardware hash
Ensure that the CSV file meets requirements.
Device information in the CSV file where you capture hardware hashes should include:
Serial number
Windows product ID
Hardware hash
Optional group tag
Optional assigned user
Reference:
https://docs.microsoft.com/en-us/intune/enrollment-autopilot
https://docs.microsoft.com/en-us/mem/autopilot/add-devices


質問 # 119
You have a Microsoft Intune subscription.
You have devices enrolled in intune as shown in the following table.

An app named App1 is installed on each device.
What is the minimum number of app configuration policies required to manage Appl ?

  • A. 0
  • B. 1
  • C. 2
  • D. 3
  • E. 4

正解:A

解説:
Explanation
The correct answer is B because you need to create two app configuration policies for managed devices, one for iOS/iPadOS devices and one for Android devices . App configuration policies let you customize the settings of apps for iOS/iPadOS or Android devices . The settings are assigned to user groups and applied when the app runs1. The app developer or supplier provides the configuration settings (keys and values) that are exposed to Intune1. You can't use a single app configuration policy for both iOS/iPadOS and Android devices because they have different configuration settings : App configuration policies for Microsoft Intune | Microsoft Learn
https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-policies-overview 2: Add app configuration policies for managed iOS/iPadOS devices | Microsoft Learn
https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-policies-use-ios


質問 # 120
You need to recommend a solution to meet the device management requirements.
What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:

Reference:
https://github.com/MicrosoftDocs/IntuneDocs/blob/master/intune/app-protection-policy.md
https://docs.microsoft.com/en-us/azure/information-protection/configure-usage-rights#do-not-forward-option-for-emails


質問 # 121
You have a Microsoft 365 subscription that contains 1,000 Windows 11 devices enrolled in Microsoft Intune.
You plan to create and monitor the results of a compliance policy used to validate the BIOS version of the devices.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

正解:

解説:

Explanation


質問 # 122
You have a Microsoft 365 E5 subscription that contains 500 macOS devices enrolled in Microsoft Intune.
You need to ensure that you can apply Microsoft Defender for Endpoint antivirus policies to the macOS devices. The solution must minimize administrative effort.
What should you do?

  • A. Onboard the macOS devices to the Microsoft 365 compliance center.
  • B. From the Microsoft Endpoint Manager admin center, create a security baseline.
  • C. Install Defender for Endpoint on the macOS devices.
  • D. From the Microsoft Endpoint Manager admin center, create a configuration profile.

正解:C

解説:
Just install, and use Defender for Endpoint on Mac.
Reference:https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/microsoft-defender-endpo


質問 # 123
You have a Microsoft 365 E5 subscription. The subscription contains 25 computers that run Windows 11 and are enrolled in Microsoft Intune. You need to onboard the devices to Microsoft Defender for Endpoint. What should you create in the Microsoft Intune admin center?

  • A. an account protection policy
  • B. an antivirus policy
  • C. a security baseline
  • D. an endpoint detection and response (EDR) policy
  • E. an attack surface reduction (ASR) policy

正解:D

解説:
To onboard the devices to Microsoft Defender for Endpoint, you need to create an endpoint detection and response (EDR) policy in the Microsoft Intune admin center. This policy enables EDR capabilities on devices that are enrolled in Intune and allows you to configure various settings for EDR functionality. You can then assign the policy to groups of users or devices. References: https://docs.microsoft.com/en-us/mem/intune
/protect/edr-windows


質問 # 124
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.
You have devices enrolled in Microsoft Intune as shown in the following table.
From Intune, you create and send a custom notification named Notification1 to Group1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

正解:

解説:

Reference:
https://docs.microsoft.com/en-us/mem/intune/remote-actions/custom-notifications


質問 # 125
You have an Azure AD tenant named contoso.com.
You plan to use Windows Autopilot to configure the Windows 10 devices shown in the following table.

Which devices can be configured by using Windows Autopilot self-deploying mode?

  • A. Device3 only
  • B. Device2 and Devnce3 only
  • C. Device2 only
  • D. Device 1, Device2, and Device3

正解:B

解説:
Windows Autopilot self-deploying mode requires devices that have a firmware-embedded activation key for Windows 10 Pro or Windows 11 Pro. This feature allows devices to automatically activate Windows Enterprise edition using the subscription license assigned to the user. Device1 does not have a firmware-embedded activation key, so it cannot use self-deploying mode. Device2 and Device3 have firmware-embedded activation keys for Windows 10 Pro, so they can use self-deploying mode. Reference: Windows Autopilot self-deploying mode (Public Preview), Deploy Windows Enterprise licenses


質問 # 126
Your company has an internal portal that uses a URL of http://contoso.com.
The network contains computers that run Windows 10. The default browser on all the computers is Microsoft Edge.
You need to ensure that all users only use Internet Explorer to connect to the internal portal. The solution must ensure that Microsoft Edge can be used to connect to all other websites.
What should you do from each computer?

  • A. From Internet Explorer, configure the Compatibility View settings
  • B. From Microsoft Edge, configure the Advanced Site Settings
  • C. From the local policy, configure Enterprise Mode
  • D. From the Settings app, configure the default web browser settings

正解:C

解説:
For Windows 10 and Windows 10 Mobile, Microsoft Edge is the default browser experience.
However, Microsoft Edge lets you continue to use IE11 for sites that are on your corporate intranet or included on your Enterprise Mode Site List.
Using Enterprise Mode means that you can continue to use Microsoft Edge as your default browser, while also ensuring that your apps continue working on IE11.
https://docs.microsoft.com/en-us/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode


質問 # 127
You have two computers that run Windows 10. The computers are enrolled in Microsoft Intune as shown in the following table.

Windows 10 update rings are defined in Intune as shown in the following table.

You assign the update rings as shown in the following table.

What is the effect of the configurations on Computer1 and Computer2? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:

Explanation:

Computer1 and Computer2 are members of Group1. Ring1 is applied to Group1.
Note: The term "Exclude" is misleading. It means that the ring is not applied to that group, rather than that group being blocked.
References:
https://docs.microsoft.com/en-us/windows/deployment/update/waas-wufb-intune
https://allthingscloud.blog/configure-windows-update-business-using-microsoft-intune/


質問 # 128
You have a Microsoft 365 E5 subscription that contains a computer named Computer1 that runs Windows 11.
Computer1 is enrolled in Microsoft Intune.
You need to deploy an app named App1 to Computer1. The App1 installation will use multiple files.
What should you use to package App1, and which file format will be used? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:

Explanation:

"The Microsoft Win32 Content Prep Tool zips all files and subfolders when it creates the .intunewin file. Be sure to keep the Microsoft Win32 Content Prep Tool separate from the installer files and folders, so that you don't include the tool or other unnecessary files and folders in your .intunewin file."


質問 # 129
You use the Microsoft Deployment Toolkit (MDT) to manage Windows 11 deployments.
From Deployment Workbench, you modify the WinPE settings and add PowerShell support.
You need to generate a new set of WinPE boot image files that contain the updated settings.
What should you do?

  • A. From the Advanced Configuration node, create new media.
  • B. From the Packages node, import a new operating system package
  • C. From the Deployment Shares node, update the deployment share.
  • D. From the Operating Systems node, import a new operating system.

正解:C


質問 # 130
You have two computers that run Windows 10. The computers are enrolled in Microsoft Intune as shown in the following table.

Windows 10 update rings are defined in Intune as shown in the following table.

You assign the update rings as shown in the following table.

What is the effect of the configurations on Computer1 and Computer2? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:

Explanation:

Computer1 and Computer2 are members of Group1. Ring1 is applied to Group1.
Note: The term "Exclude" is misleading. It means that the ring is not applied to that group, rather than that group being blocked.
References:
https://docs.microsoft.com/en-us/windows/deployment/update/waas-wufb-intune
https://allthingscloud.blog/configure-windows-update-business-using-microsoft-intune/


質問 # 131
Your network contains an Active Directory domain named adatum.com, a workgroup, and computers that run Windows 10. The computers are configured as shown in the following table.

The local Administrator accounts on Computed, Computed, and Computed have the same user name and password.
On Computed. Windows Defender Firewall is configured as shown in the following exhibit.

正解:

解説:

Explanation:


質問 # 132
You have a Microsoft 365 E5 subscription that contains 10 Android Enterprise devices. Each device has a corporate-owned work profile and is enrolled in Microsoft Intune.
You need to configure the devices to run a single app in kiosk mode.
Which Configuration settings should you modify in the device restrictions profile?

  • A. Users and Accounts
  • B. General
  • C. System security
  • D. Device experience

正解:D

解説:
Explanation
To configure the devices to run a single app in kiosk mode, you need to modify the Device experience settings in the device restrictions profile. You can specify the app package name and activity name for the app that you want to run in kiosk mode. References:
https://docs.microsoft.com/en-us/mem/intune/configuration/device-restrictions-android-for-work#device-experie


質問 # 133
......

100%更新されたのはMicrosoft MD-102限定版PDF問題集:https://www.goshiken.com/Microsoft/MD-102-mondaishu.html

無料Microsoft 365 Certified MD-102公式認定ガイドPDFダウンロード:https://drive.google.com/open?id=1kcPlMcatsL7VNQbTn3TgoF-QzqMUAkV_