Skip to Content

MS-101 Microsoft 365 Mobility and Security Exam Questions and Answers – Page 1

The latest MS-101 Microsoft 365 Mobility and Security certification actual real practice exam question and answer (Q&A) dumps are available free, which are helpful for you to pass the MS-101 Microsoft 365 Mobility and Security exam and earn MS-101 Microsoft 365 Mobility and Security certification.

MS-101 Microsoft 365 Mobility and Security Exam Questions and Answers

Exam Question 1

You are deploying Microsoft Endpoint Manager.
You successfully enroll Windows 10 devices in Endpoint Manager.
When you try to enroll an iOS device in Endpoint Manager, you get an error.
You need to ensure that you can enroll the iOS device in Endpoint Manager.
Solution: You add your user account as a device enrollment manager.
Does this meet the goal?

A. Yes
B. No
Correct Answer:
B. No

Exam Question 2

You are deploying Microsoft Endpoint Manager.
You successfully enroll Windows 10 devices in Endpoint Manager.
When you try to enroll an iOS device in Endpoint Manager, you get an error.
You need to ensure that you can enroll the iOS device in Endpoint Manager.
Solution: You configure the Apple MDM Push certificate.
Does this meet the goal?

A. Yes
B. No
Correct Answer:
A. Yes

Exam Question 3

You are deploying Microsoft Endpoint Manager.
You successfully enroll Windows 10 devices in Endpoint Manager.
When you try to enroll an iOS device in Endpoint Manager, you get an error.
You need to ensure that you can enroll the iOS device in Endpoint Manager.
Solution: You create an Apple Configurator enrollment profile.
Does this meet the goal?

A. Yes
B. No
Correct Answer:
B. No

Exam Question 4

Your network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).
You manage Windows 10 devices by using Microsoft System Center Configuration Manager (Current Branch). You configure pilot co-management.
You add a new device named Device1 to the domain. You install the Configuration Manager client on Device1.
You need to ensure that you can manage Device1 by using Microsoft Intune and Configuration Manager.
Solution: You create a device configuration profile from the Device Management admin center.
Does this meet the goal?

A. Yes
B. No
Correct Answer:
B. No

Exam Question 5

Your network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).
You manage Windows 10 devices by using Microsoft System Center Configuration Manager (Current Branch).
You configure pilot co-management.
You add a new device named Device1 to the domain. You install the Configuration Manager client on Device1.
You need to ensure that you can manage Device1 by using Microsoft Intune and Configuration Manager.
Solution: You add Device1 to an Active Directory group.
Does this meet the goal?

A. Yes
B. No
Correct Answer:
A. Yes

Exam Question 6

Your network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).
You manage Windows 10 devices by using Microsoft System Center Configuration Manager (Current Branch).
You configure pilot co-management.
You add a new device named Device1 to the domain. You install the Configuration Manager client on Device1.
You need to ensure that you can manage Device1 by using Microsoft Intune and Configuration Manager.
Solution: You unjoin Device1 from the Active Directory domain.
Does this meet the goal?

A. Yes
B. No
Correct Answer:
B. No

Exam Question 7

Your network contains an Active Directory forest named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).
You use Microsoft Endpoint Configuration Manager for device management.
You have the Windows 10 devices shown in the following table.

Name Collection
Device1 Collection1
Device2 Collection2

You configure Endpoint Configuration Manager co-management as follows:

  • Automatic enrollment in Intune: Pilot
  • Pilot collection for all workloads: Collection2

You configure co-management workloads as shown in the following exhibit.
You configure co-management workloads as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

  • Microsoft Intune manage the compliance policies for Device1.
  • Configuration Manager manages the Windows Update policies for Device1.
  • Micorosft Intune manages Endpoint Protection for Device2.

Correct Answer:

  • Microsoft Intune manage the compliance policies for Device1: No
  • Configuration Manager manages the Windows Update policies for Device1: No
  • Micorosft Intune manages Endpoint Protection for Device2: Yes

Exam Question 8

You have three devices enrolled in Microsoft Intune as shown in the following table.

Name Platform Member of
Device1 Windows 10 Group1
Device2 Android Group2, Group3
Device3 Windows 10 Group2, Group3

The device compliance policies in Intune are configured as shown in the following table.

Name Platform Assigned
Policy1 Windows 10 and later Yes
Policy2 Android No
Policy3 Windows 10 and later Yes

The device compliance policies have the assignments shown in the following table.

Name Include Exclude
Policy1 Group3 None
Policy2 Group2 Group3

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

  • Policy1 applies to Device3.
  • Policy2 applies to Device2.

Correct Answer:

  • Policy1 applies to Device3: Yes
  • Policy2 applies to Device2: Yes

Exam Question 9

You have Windows 10 Pro devices that are joined to an Active Directory domain.
You plan to create a Microsoft 365 tenant and to upgrade the devices to Windows 10 Enterprise.
You are evaluating whether to deploy Windows Hello for Business.
What are two prerequisites of the deployment? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

A. Microsoft Endpoint Manager enrollment
B. Microsoft Azure Active Directory (Azure AD)
C. smartcards
D. TPM-enabled devices
Correct Answer:
A. Microsoft Endpoint Manager enrollment
B. Microsoft Azure Active Directory (Azure AD)

Exam Question 10

You have a Microsoft 365 tenant.
All users are assigned the Enterprise Mobility + Security license.
You need to ensure that when users join their device to Microsoft Azure Active Directory (Azure AD), the device is enrolled in Microsoft Endpoint Manager automatically.
What should you configure?

A. Enrollment restrictions from the Endpoint Manager admin center
B. device enrollment managers from the Endpoint Manager admin center
C. MAM User scope from the Azure Active Directory admin center
D. MDM User scope from the Azure Active Directory admin center
Correct Answer:
D. MDM User scope from the Azure Active Directory admin center