exam questions

Exam MD-101 All Questions

View all questions & answers for the MD-101 exam

Exam MD-101 topic 1 question 20 discussion

Actual exam question from Microsoft's MD-101
Question #: 20
Topic #: 1
[All MD-101 Questions]

Your company has a Microsoft 365 subscription.
You have enrolled all the company computers in Microsoft Intune.
You have been tasked with making sure that devices with a high Windows Defender Advanced Threat Protection (Windows Defender ATP) risk score are locked.
Which of the following actions should you take?

  • A. You should create a device configuration profile.
  • B. You should create a device compliance policy.
  • C. You should create a Windows AutoPilot deployment profile.
  • D. You should create a conditional access policy.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
honey919
2 months, 3 weeks ago
Selected Answer: B
In device compliance setting there is a option to select risk score. And on the status of compliance the actions are taken.
upvoted 1 times
...
NoursBear
1 year, 4 months ago
I think it's D, the blocking action is in conditional access policy not in the compliance policy. In the compliance policy I don't see if blah blah block
upvoted 1 times
...
Tati_Oliveira
1 year, 7 months ago
None of the answers are correct, the OS Version is configured under Device Restrictions.
upvoted 1 times
Tati_Oliveira
1 year, 7 months ago
Device Platform Restrictions
upvoted 1 times
...
...
Darkfire
1 year, 7 months ago
I also think correct answer should be B. Nevertheless, A and D are needed to successfully configure B. Main question is, which will be correct in the exam? Anybody knows?
upvoted 1 times
...
USRobotics
1 year, 8 months ago
I really don't understand why 3 options are marked as correct answer.
upvoted 2 times
...
devin19
1 year, 9 months ago
Selected Answer: B
Why all 3 selected when it doesn't say select all that apply
upvoted 4 times
...
xJoelinez
2 years, 1 month ago
Just to be clear, B alone will not be suffice. Yes you can block devices if they are not compliant, but this is only mobile devices running android and iOS. If you want to block devices that are running windows (Computers in the question) then you will need a conditional access policy too,
upvoted 1 times
dawnbringer69
2 years ago
I Have tested and can confirm that this is Valid. The answer is neverltheless B.
upvoted 1 times
...
...
okkies
2 years, 3 months ago
Selected Answer: B
Its surely B. https://docs.microsoft.com/en-us/mem/intune/protect/actions-for-noncompliance By default, each compliance policy includes the action for noncompliance of Mark device noncompliant with a schedule of zero days (0). The result of this default is when Intune detects a device isn't compliant, Intune immediately marks the device as noncompliant. After a device is marked as noncompliance, Azure Active Directory (AD) Conditional Access can block the device. just double checked it in a tenant
upvoted 2 times
...
Hatsapatsa
2 years, 3 months ago
Answer seems to be correct according to this Microsoft Documentation. https://docs.microsoft.com/en-us/intune/compliance-policy-create-android
upvoted 1 times
...
Meebler
2 years, 4 months ago
the correct answer to the multiple choice question is B: You should create a device compliance policy. This is because device compliance policies allow you to set rules for ensuring that devices meet certain compliance standards, including the level of Windows Defender ATP risk, and specify actions to take if a device is non-compliant, such as locking the device. Option A (creating a device configuration profile) is not directly related to locking devices with a high Windows Defender ATP risk score. Option C (creating a Windows AutoPilot deployment profile) is related to deploying and configuring devices, but it is not directly related to locking devices with a high Windows Defender ATP risk score. Option D (creating a conditional access policy) is related to controlling access to corporate resources based on various factors, but it is not directly related to locking devices with a high Windows Defender ATP risk score.
upvoted 1 times
...
raduM
2 years, 6 months ago
B is correct. Don't know why you put all the answers
upvoted 2 times
...
MR_Eliot
3 years ago
Selected Answer: B
I agree.
upvoted 2 times
...
PChi
3 years, 1 month ago
Answer B. Compliance and Conditional Policies are dependent on each other ("To use device compliance policies to block devices from corporate resources, Azure AD Conditional Access must be set up."- see link below) but you use compliance policy to retire noncompliant devices. https://docs.microsoft.com/en-us/mem/intune/protect/actions-for-noncompliance#:~:text=1%20Send%20email%20to%20end%20users%3A%20When%20the,device%20and%20remove%20the%20device%20from%20Intune%20management. CONTIDITONAL ACCESS: https://docs.microsoft.com/en-us/mem/intune/protect/conditional-access-intune-common-ways-use
upvoted 2 times
...
Anker
3 years, 3 months ago
Tested this, can confirm it is B. You create the compliance policy in the compliance settings you specify the risk level and in the next step (Actions for noncompliance) you can select remotely lock the noncompliant device.
upvoted 3 times
...
mikl
3 years, 4 months ago
Its surely B. https://docs.microsoft.com/en-us/mem/intune/protect/actions-for-noncompliance By default, each compliance policy includes the action for noncompliance of Mark device noncompliant with a schedule of zero days (0). The result of this default is when Intune detects a device isn't compliant, Intune immediately marks the device as noncompliant. After a device is marked as noncompliance, Azure Active Directory (AD) Conditional Access can block the device.
upvoted 2 times
...
mikl
3 years, 4 months ago
B. You should create a device compliance policy.
upvoted 1 times
...
velosiraptor
3 years, 4 months ago
B is the only close enough as an answer. Remote Lock option is only present in Device Compliance. Although W 10 do not support Remote lock if the question is not worded differently its the only option to fulfil the question requirement.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago