Microsoft MD-102 Antivirus BitLocker Firewall ASR And Security Baselines Practice Test
Skills 3.1 • 30 original questions
This Microsoft MD-102 Endpoint Administrator practice test focuses on antivirus bitlocker firewall asr and security baselines through original scenario-based questions aligned to the skills measured as of July 24, 2026. Use the full ExamSnap MD-102 collection for broader practice across all current skill areas. For broader exam preparation, review the Microsoft MD-102 Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
During a device refresh at Fabrikam Retail, the Microsoft 365 administrator must centrally configure Microsoft Defender Antivirus settings for managed endpoints. Which action most directly satisfies the requirement? The affected devices are in the production ring, rollout wave 1.
Correct answer: A
Why: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. This directly addresses the requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
Option review:
A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. This directly addresses the requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
B: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
C: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
D: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
E: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
Learning point: Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
Adventure Works is revising endpoint operations for a security hardening project. Administrators need to enforce disk encryption and maintain recoverable, auditable BitLocker recovery information. Which implementation should the endpoint administrator select for the executive-device cohort, rollout wave 1?
Correct answer: A
Why: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. This directly addresses the requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
Option review:
A: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. This directly addresses the requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
B: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
C: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
D: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
E: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
Learning point: Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
A ticket escalated to the service desk lead at Proseware Services states one non-negotiable goal: centrally enforce host firewall settings and rules on managed Windows devices. Which choice is the strongest fit for the remote-user cohort, rollout wave 1?
Correct answer: E
Why: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. This directly addresses the requirement: centrally enforce host firewall settings and rules on managed Windows devices.
Option review:
A: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
C: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
D: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
E: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. This directly addresses the requirement: centrally enforce host firewall settings and rules on managed Windows devices.
Learning point: Create and assign Microsoft Defender Firewall policy through Intune endpoint security
For the shared-device cohort, rollout wave 1 at Fourth Coffee, a branch migration can proceed only if the team can reduce exploitable endpoint behaviors rather than relying only on malware detection after execution. What should the endpoint administrator configure?
Correct answer: A
Why: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. This directly addresses the requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
Option review:
A: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. This directly addresses the requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
B: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
C: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
D: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
E: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
Learning point: Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
The endpoint architecture review at Fabrikam Retail focuses on this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point. Which Microsoft management action is most appropriate for the field-device cohort, rollout wave 1?
Correct answer: D
Why: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. This directly addresses the requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
Option review:
A: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
B: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
D: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. This directly addresses the requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
E: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
Learning point: Plan and assign an Intune security baseline, then review conflicts with other configuration sources
A change advisory board at Adventure Works asks how to centrally configure Microsoft Defender Antivirus settings for managed endpoints during a Windows 11 rollout. Which proposed action should the Intune administrator approve for the developer cohort, rollout wave 2?
Correct answer: A
Why: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. This directly addresses the requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
Option review:
A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. This directly addresses the requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
C: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
D: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
E: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
Learning point: Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
Proseware Services has already ruled out manual per-device administration. For the frontline-user cohort, rollout wave 2, the remaining requirement is to enforce disk encryption and maintain recoverable, auditable BitLocker recovery information. Which choice best addresses it?
Correct answer: B
Why: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. This directly addresses the requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
Option review:
A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. This directly addresses the requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
C: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
D: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
E: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
Learning point: Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
During post-pilot review at Fourth Coffee, the endpoint administrator identifies a gap: the organization still needs to centrally enforce host firewall settings and rules on managed Windows devices. Which action should be added before the kiosk cohort, rollout wave 2 moves to production?
Correct answer: E
Why: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. This directly addresses the requirement: centrally enforce host firewall settings and rules on managed Windows devices.
Option review:
A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
B: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
C: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
D: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
E: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. This directly addresses the requirement: centrally enforce host firewall settings and rules on managed Windows devices.
Learning point: Create and assign Microsoft Defender Firewall policy through Intune endpoint security
The service desk lead at Fabrikam Retail is comparing several cloud-management options for a device refresh. Which one directly enables the team to reduce exploitable endpoint behaviors rather than relying only on malware detection after execution for the new-hire cohort, rollout wave 2?
Correct answer: B
Why: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. This directly addresses the requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
Option review:
A: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
B: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. This directly addresses the requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
D: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
E: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
Learning point: Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
A security and operations workshop at Adventure Works defines the desired outcome as follows: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point. Which implementation should be chosen for the contractor cohort, rollout wave 2?
Correct answer: B
Why: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. This directly addresses the requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
Option review:
A: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
B: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. This directly addresses the requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
C: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
D: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
E: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
Learning point: Plan and assign an Intune security baseline, then review conflicts with other configuration sources
Which action best matches this technical purpose for the lab-device cohort, rollout wave 3: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings.
Correct answer: A
Why: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. This directly addresses the requirement: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings..
Option review:
A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. This directly addresses the requirement: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings..
B: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings..
C: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings..
D: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings..
E: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings..
Learning point: Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
An administrator at Fourth Coffee describes the needed capability this way: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. Which option should be associated with that requirement for the pilot ring, rollout wave 3?
Correct answer: E
Why: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. This directly addresses the requirement: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices..
Option review:
A: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices..
B: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices..
C: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices..
D: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices..
E: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. This directly addresses the requirement: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices..
Learning point: Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
During a design validation for the production ring, rollout wave 3, Fabrikam Retail documents the following behavior: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. Which endpoint-management feature or action is being described?
Correct answer: D
Why: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. This directly addresses the requirement: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints..
Option review:
A: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints..
B: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints..
C: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints..
D: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. This directly addresses the requirement: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints..
E: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints..
Learning point: Create and assign Microsoft Defender Firewall policy through Intune endpoint security
The endpoint administrator must identify the Microsoft endpoint-management capability that provides this function for the executive-device cohort, rollout wave 3: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. Which choice is correct?
Correct answer: A
Why: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. This directly addresses the requirement: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content..
Option review:
A: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. This directly addresses the requirement: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content..
B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content..
C: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content..
D: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content..
E: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content..
Learning point: Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
A runbook for the remote-user cohort, rollout wave 3 contains this description: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. Which implementation belongs in that runbook?
Correct answer: A
Why: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. This directly addresses the requirement: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review..
Option review:
A: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. This directly addresses the requirement: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review..
B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review..
C: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review..
D: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review..
E: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review..
Learning point: Plan and assign an Intune security baseline, then review conflicts with other configuration sources
Fourth Coffee is troubleshooting a security hardening project. Evidence shows that the decisive requirement is to centrally configure Microsoft Defender Antivirus settings for managed endpoints. Which action should the desktop engineer investigate first for the shared-device cohort, rollout wave 4?
Correct answer: C
Why: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. This directly addresses the requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
Option review:
A: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
B: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
C: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. This directly addresses the requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
D: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
E: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
Learning point: Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
After eliminating network and licensing causes, the security administrator at Fabrikam Retail determines that success depends on the ability to enforce disk encryption and maintain recoverable, auditable BitLocker recovery information. Which endpoint-management action should be checked next for the field-device cohort, rollout wave 4?
Correct answer: B
Why: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. This directly addresses the requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
Option review:
A: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. This directly addresses the requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
C: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
D: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
E: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
Learning point: Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
A service-desk escalation during a branch migration has been narrowed to one management requirement: centrally enforce host firewall settings and rules on managed Windows devices. Which configuration is the most relevant starting point for the developer cohort, rollout wave 4?
Correct answer: C
Why: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. This directly addresses the requirement: centrally enforce host firewall settings and rules on managed Windows devices.
Option review:
A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
C: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. This directly addresses the requirement: centrally enforce host firewall settings and rules on managed Windows devices.
D: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
E: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
Learning point: Create and assign Microsoft Defender Firewall policy through Intune endpoint security
The failure pattern at Proseware Services affects the frontline-user cohort, rollout wave 4. Before making unrelated policy changes, the Microsoft 365 administrator needs a solution that will reduce exploitable endpoint behaviors rather than relying only on malware detection after execution. Which action is most directly relevant?
Correct answer: E
Why: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. This directly addresses the requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
Option review:
A: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
B: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
C: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
D: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
E: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. This directly addresses the requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
Learning point: Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
While investigating a operations review, Fourth Coffee confirms the environment must apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point. Which Microsoft endpoint-management capability should be validated for the kiosk cohort, rollout wave 4?
Correct answer: E
Why: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. This directly addresses the requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
Option review:
A: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
B: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
C: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
D: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
E: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. This directly addresses the requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
Learning point: Plan and assign an Intune security baseline, then review conflicts with other configuration sources
Two teams at Fabrikam Retail propose different approaches for the new-hire cohort, rollout wave 5. The selection criterion is simple: the chosen approach must centrally configure Microsoft Defender Antivirus settings for managed endpoints. Which option should win the technical comparison?
Correct answer: A
Why: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. This directly addresses the requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
Option review:
A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. This directly addresses the requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
C: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
D: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
E: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
Learning point: Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
For the contractor cohort, rollout wave 5, Adventure Works wants the least indirect solution to this goal: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information. Which action aligns most closely with that requirement?
Correct answer: E
Why: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. This directly addresses the requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
Option review:
A: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
B: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
C: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
D: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
E: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. This directly addresses the requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
Learning point: Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
A modernization plan at Proseware Services includes a device refresh. The security administrator is asked to choose the control that specifically helps the organization centrally enforce host firewall settings and rules on managed Windows devices. Which choice fits best for the lab-device cohort, rollout wave 5?
Correct answer: A
Why: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. This directly addresses the requirement: centrally enforce host firewall settings and rules on managed Windows devices.
Option review:
A: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. This directly addresses the requirement: centrally enforce host firewall settings and rules on managed Windows devices.
B: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
C: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
D: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
E: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
Learning point: Create and assign Microsoft Defender Firewall policy through Intune endpoint security
The pilot ring, rollout wave 5 is moving into a controlled rollout at Fourth Coffee. Which action should be included when the stated management objective is to reduce exploitable endpoint behaviors rather than relying only on malware detection after execution?
Correct answer: B
Why: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. This directly addresses the requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
Option review:
A: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
B: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. This directly addresses the requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
D: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
E: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
Learning point: Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
Fabrikam Retail is replacing an ad hoc process during a tenant consolidation. The replacement must reliably apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point. Which endpoint-management approach should the Microsoft 365 administrator implement for the production ring, rollout wave 5?
Correct answer: B
Why: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. This directly addresses the requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
Option review:
A: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
B: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. This directly addresses the requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
C: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
D: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
E: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: apply a standardized Microsoft-recommended endpoint security configuration as a managed starting point.
Learning point: Plan and assign an Intune security baseline, then review conflicts with other configuration sources
An audit finding for the executive-device cohort, rollout wave 6 says the current process does not consistently centrally configure Microsoft Defender Antivirus settings for managed endpoints. Which Microsoft endpoint-management action most directly closes that gap?
Correct answer: C
Why: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. This directly addresses the requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
Option review:
A: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
B: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
C: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. This directly addresses the requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
D: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
E: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally configure Microsoft Defender Antivirus settings for managed endpoints.
Learning point: Create and assign Microsoft Defender Antivirus policy through Intune endpoint security
The service desk lead at Proseware Services needs a repeatable configuration for the remote-user cohort, rollout wave 6. It must enforce disk encryption and maintain recoverable, auditable BitLocker recovery information. Which choice should be implemented instead of relying on manual endpoint work?
Correct answer: B
Why: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. This directly addresses the requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
Option review:
A: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
B: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. This directly addresses the requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
C: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
D: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
E: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: enforce disk encryption and maintain recoverable, auditable BitLocker recovery information.
Learning point: Create Intune disk encryption policy for BitLocker and manage recovery-key escrow, self-service recovery, and encryption compliance
During readiness testing at Fourth Coffee, the shared-device cohort, rollout wave 6 fails a business requirement because administrators cannot yet centrally enforce host firewall settings and rules on managed Windows devices. Which action should be implemented before rollout continues?
Correct answer: E
Why: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. This directly addresses the requirement: centrally enforce host firewall settings and rules on managed Windows devices.
Option review:
A: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
B: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
C: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
D: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: centrally enforce host firewall settings and rules on managed Windows devices.
E: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. This directly addresses the requirement: centrally enforce host firewall settings and rules on managed Windows devices.
Learning point: Create and assign Microsoft Defender Firewall policy through Intune endpoint security
A governance review asks the security administrator to justify the control selected for the field-device cohort, rollout wave 6. The requirement is to reduce exploitable endpoint behaviors rather than relying only on malware detection after execution. Which action has the clearest technical alignment?
Correct answer: A
Why: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. This directly addresses the requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
Option review:
A: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. This directly addresses the requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
B: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
C: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
D: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
E: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: reduce exploitable endpoint behaviors rather than relying only on malware detection after execution.
Learning point: Configure attack surface reduction policy in Intune and apply Zero Trust principles by limiting risky behaviors and unnecessary privileges
For a remote-work deployment, Adventure Works needs an endpoint-management capability with this effect: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. Which option most accurately provides that capability for the developer cohort, rollout wave 6?
Correct answer: E
Why: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. This directly addresses the requirement: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review..
Option review:
A: Intune antivirus policy centrally configures supported Microsoft Defender Antivirus behavior such as cloud protection, scanning, exclusions, and remediation settings. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review..
B: Firewall policy centrally manages supported Windows firewall profiles and rules across managed endpoints. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review..
C: Disk encryption policy can enforce BitLocker settings and provide recovery-key lifecycle and compliance visibility for managed Windows devices. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review..
D: Attack surface reduction controls reduce common endpoint attack paths such as malicious scripts, Office child processes, credential theft, and untrusted content. It can be valid in another endpoint-management scenario, but it does not most directly address this requirement: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review..
E: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review. This directly addresses the requirement: Security baselines provide Microsoft-recommended groups of security settings but still require deliberate targeting and conflict review..
Learning point: Plan and assign an Intune security baseline, then review conflicts with other configuration sources
Popular posts
Recent Posts
