exam questions

Exam MS-101 All Questions

View all questions & answers for the MS-101 exam

Exam MS-101 topic 3 question 113 discussion

Actual exam question from Microsoft's MS-101
Question #: 113
Topic #: 3
[All MS-101 Questions]

HOTSPOT -
You have a Microsoft 365 tenant that contains the compliance policies shown in the following table.

The tenant contains the devices shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
allesglar
Highly Voted 3 years, 4 months ago
I would go for N,N,N. Device1: has a risk status of High and is required to be under Low risk score due to Policy3 so not compliant Device2: has a risk status of Medium and is required to be under Low risk score due to Policy3 so not compliant Device3: has a risk status of Low and is required to be under Medium risk score due to Policy2 but is not compliant because Policy1 requires Bitlocker which is not configured.
upvoted 43 times
jodtzz
3 years, 4 months ago
Agreed. NNN
upvoted 10 times
JT19760106
3 years, 3 months ago
I think NNN is right. If you have deployed multiple compliance policies, Intune uses the most secure of these policies. https://docs.microsoft.com/en-us/mem/intune/protect/compliance-policy-monitor#how-intune-resolves-policy-conflicts
upvoted 9 times
...
...
...
Goena
Highly Voted 3 years, 4 months ago
Without concerning the scores high, medium and low (not sure if that has any influence): - Device 1: Y - Device has bitlocker configured - Device 2: N - Policy 3 requires bitlocker - Device 3: N - Policy 1 requires bitlocker
upvoted 15 times
Durden871
2 years, 9 months ago
Device 1 is compliant; however, it has policy 3 also applied. The device end point risk requires the device to be at "low". The risk of device 1 is at "high". Therefore, if one policy isn't applicable, it's not compliant, even if the other policies applied are in the "compliant" status.
upvoted 3 times
...
...
RazielLycas
Most Recent 2 years, 9 months ago
I go with N-N-N
upvoted 6 times
...
LillyLiver
3 years, 2 months ago
I think it's N,N,N. Device compliance policies don't have a priority to determine which policy is applied, like you would see with group policy in A.D. Device compliance policies, when a device has more than one policy applied, has to be compliant on all policies in order for it to pass all the measured tests. When a policy is applied that the device isn't compliant with, then all the policies applied are moved to that level and the device is marked as non-compliant. Here is the policy ranking. The higher the severity, the less likely it is that the device is compliant. Status Severity ======================= Unknown 1 NotApplicable 2 Compliant 3 InGracePeriod 4 NonCompliant 5 Error 6 Reference: https://docs.microsoft.com/en-us/mem/intune/protect/create-compliance-policy
upvoted 4 times
bac0n
2 years, 4 months ago
This is bang on. The article provides the info you need. Referencing the above chart; "When a device has multiple compliance policies, then the highest severity level of all the policies is assigned to that device." Which is to say, if a device is NONCOMPLIANT WITH ANY POLICY ASSIGNED TO IT, which all 3 of these devices are, then it is NONCOMPLIANT OVERALL.
upvoted 2 times
...
...
chungerr
3 years, 3 months ago
The answer is correct, YYN. The wording of the machine risk score states "be at" or "under." I interpret this phrase as the Machine Risk Score as equal or lower than. Y - Policy1 takes precedence. Device 1 meets Bitlocker and Machine Risk Score requirements. Y - Policy2 takes precedence. Device 2 meets Bitlocker and Machine Risk score requirements. N - Policy1 takes precedence. Device3 fails on Bitlocker requirement.
upvoted 1 times
chungerr
3 years, 3 months ago
Incorrect, discovered that the most restrictive setting wins when multiple policies apply. N N N
upvoted 16 times
...
...
ZuluHulu
3 years, 4 months ago
Doesn't Device 2 fail policy 3? Hence, be marked as non-compliant. Therefore, NO should be the answer.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago