exam questions

Exam MD-101 All Questions

View all questions & answers for the MD-101 exam

Exam MD-101 topic 3 question 18 discussion

Actual exam question from Microsoft's MD-101
Question #: 18
Topic #: 3
[All MD-101 Questions]

HOTSPOT -
You have a Microsoft 365 subscription.
You have 25 Microsoft Surface Hub devices that you plan to manage by using Microsoft Endpoint Manager.
You need to configure the devices to meet the following requirements:
✑ Enable Windows Hello for Business.
✑ Configure Microsoft Defender SmartScreen to block users from running unverified files.
Which profile types should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: Identity protection -
In the Windows Hello for Business settings you can configure in an Identity protection profile. Identity protection profiles are part of device configuration policy in
Microsoft Intune. With an Identity protection profile, you can configure settings on discrete groups of Windows 10/11 devices.

Box 2: Endpoint protection -
Microsoft Intune includes many settings to help protect your devices. These settings are created in an endpoint protection configuration profile in Intune to control security, including BitLocker and Microsoft Defender.
Reference:
https://docs.microsoft.com/en-us/mem/intune/protect/identity-protection-windows-settings?toc=/intune/configuration/toc.json&bc=/intune/configuration/breadcrumb/ toc.json https://docs.microsoft.com/en-us/mem/intune/protect/endpoint-protection-windows-10?toc=/intune/configuration/toc.json&bc=/intune/configuration/breadcrumb/ toc.json

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Perycles
Highly Voted 3 years, 10 months ago
answers are correct.
upvoted 11 times
...
MikeMatt2020
Highly Voted 3 years, 11 months ago
Windows Hello for Business can be configure within Identity Protection But it seems that this SmartScreen setting can be configured in BOTH Device Restrictions and Endpoint Protection. Literally the same exact setting.
upvoted 6 times
MikeMatt2020
3 years, 11 months ago
I suppose I'll go with Endpoint Protection. Still confusing. https://docs.microsoft.com/en-us/mem/intune/protect/endpoint-protection-windows-10
upvoted 4 times
...
RodrigoT
3 years, 1 month ago
They are NOT the same thing. Microsoft Defender SmartScreen under Device restrictions is only for Microsoft Edge. The right answer is indeed Endpoint protection > Microsoft Defender SmartScreen settings. https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-smartscreen#smartscreen-enablesmartscreeninshell
upvoted 8 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago