exam questions

Exam MD-101 All Questions

View all questions & answers for the MD-101 exam

Exam MD-101 topic 3 question 46 discussion

Actual exam question from Microsoft's MD-101
Question #: 46
Topic #: 3
[All MD-101 Questions]

You have computers that run Windows 10, are joined to Azure Active Directory (Azure AD), and are enrolled in Microsoft Intune.
You have an Azure web app named App1. App1 only allows connections over HTTPS. App1 uses a certificate from an on-premises certification authority (CA).
You need to ensure that the computers can connect to App1 from Microsoft Edge.
Which type of device configuration profile should you create in Microsoft Endpoint Manager?

  • A. trusted certificate
  • B. Simple Certificate Enrollment Protocol (SCEP) certificate
  • C. imported public key pair (PKCS) certificate
  • D. public key pair (PKCS) certificate
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Goofer
Highly Voted 3 years, 5 months ago
SCEP is to onroll certificates to Intune Devices (not necessary) PKCS is to onroll certificates to Intune Devices (not necessary) To trust the (internal) certificate of app1 you need to import the internal root certificate to the 'trused root certification authorities' of the device. You must create a configuration Profile - Trusted certificate to deploy the root certificate to the intune devices Answer = trusted certificate
upvoted 11 times
MR_Eliot
2 years, 12 months ago
Agreed.
upvoted 1 times
...
...
Jana08
Highly Voted 3 years, 10 months ago
SCEP Appears to be correct: Intune supports use of the Simple Certificate Enrollment Protocol (SCEP) to authenticate connections to your apps and corporate resources. https://docs.microsoft.com/en-us/mem/intune/protect/certificates-scep-configure
upvoted 6 times
...
SR1991
Most Recent 1 year, 8 months ago
Selected Answer: B
To use a SCEP certificate profile, a device must have also received the trusted certificate profile that provisions it with your Trusted Root CA certificate. We recommend you deploy both the trusted root certificate profile and SCEP certificate profile to the same groups. Consider the following before you continue: When you assign SCEP certificate profiles to groups, the Trusted Root CA certificate file (as specified in the trusted certificate profile) is installed on the device. The device uses the SCEP certificate profile to create a certificate request for that Trusted Root CA certificate.
upvoted 1 times
...
Shalen
2 years, 2 months ago
Selected Answer: B
the keyword on this question is uses certificate from onprem root CA , i vote B
upvoted 1 times
...
AhmadMa
2 years, 4 months ago
Selected Answer: A
SCEP is not necesary here
upvoted 1 times
...
bitjos
2 years, 4 months ago
Selected Answer: A
A. "Create and deploy a trusted certificate profile before you create a SCEP, PKCS, or PKCS imported certificate profile" https://learn.microsoft.com/en-us/mem/intune/protect/certificates-trusted-root
upvoted 4 times
...
IykeP
3 years, 3 months ago
Selected Answer: B
B is the correct answer.
upvoted 4 times
...
jorlloen
3 years, 8 months ago
In my opion. MS Edge needs to trust with App1 certificate, if not a "can't connect securely to this page" message will be showed on Edge, so you need to deploy the Root CA certificate in Trusted root certification Authorities. A is my ssugested answer.
upvoted 4 times
forExamCert2023
3 years, 1 month ago
While that can be a solution, have this in mind that Microsoft wants us to see if we know the new way of doing the business. That is their goal.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago