exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 2 question 3 discussion

Actual exam question from Microsoft's MS-500
Question #: 3
Topic #: 2
[All MS-500 Questions]

HOTSPOT -
You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table.

You register devices in contoso.com as shown in the following table.

You create app protection policies in Intune as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
https://docs.microsoft.com/en-us/intune/apps/app-protection-policy

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DudleyYVR
Highly Voted 4 years, 2 months ago
Answer is right. Device 2 is not intune managed so policy does not apply to user 2
upvoted 29 times
...
kiketxu
Highly Voted 4 years, 3 months ago
I would say here: NO, YES, "YES". In the third, User2 w/Device2 matches with iOS Policy4 for GroupB.
upvoted 18 times
phatboi
3 years, 5 months ago
device 2 is not intune managed and the policy 4 is for intune app managed
upvoted 5 times
...
Jslei
4 years, 3 months ago
but Device2 is not intune managed?
upvoted 4 times
...
Sugar123
4 years, 3 months ago
I believe it is No, Yes, No. Device 2 is not managed by Microsoft Intuned.
upvoted 23 times
rkapoor8855
4 years, 3 months ago
Agreed
upvoted 5 times
kiketxu
4 years, 3 months ago
Ohh! You both right. Isn't intune managed. NO, YES, NO.
upvoted 11 times
cebularz
3 years, 11 months ago
No, https://docs.microsoft.com/en-us/mem/intune/apps/app-protection-policy#app-protection-policies-on-devices You have info that is not neccessery to be managed by Intune. So No, YES, YES
upvoted 1 times
Robert__Susin
3 years, 11 months ago
No, you are talking about MAM-WE for BYOD, the policy states that it needs to be intune managed to be applied, so they and the given answer are correct: N, Y, N
upvoted 3 times
...
...
...
...
...
...
Wigoth
Most Recent 2 years ago
I go for NYN but in different way: user1->> GRP1 : GRP1->> POL1 = POL3 is not applied user2->> GRP2 : GRP2->> POL2 = POL2 is applied user2->> GRP2 : GRP2->> POL2 = POL4 is not applied They don't ask if the devices are compliant or not but if the policies are applied or not
upvoted 1 times
...
Paul_white
2 years, 5 months ago
This question tests your understanding of app protection policies. App protection policies are applied to groups with users and not groups with devices. The device group is there as a distraction, you should only focus on the groups with users. This explains how app protection policies can protect organisation data on unmanaged/personal devices. The answer remains No Yes, No since the app protection policies are applied to the groups with the users and not groups with devices
upvoted 7 times
...
mcclane654
2 years, 5 months ago
answer is correct, the managed state bugged me: https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policies?WT.mc_id=Portal-fx#target-app-protection-policies-based-on-device-management-state
upvoted 1 times
...
NarenKA
2 years, 10 months ago
Answer is: N Y N Since Policy3 applies to iOS and Device1 is a Windows 10 device Policy3 does not apply. Since User2 is a member of Group2 and Policy2 apply to Windows 10 devices, Policy2 applies to User2 on Device1. User2 isn't a member of Group2 and since you need to have users as part of the protected group Policy4 does not apply to Device2 / User2.
upvoted 3 times
...
sliix
3 years, 2 months ago
Can anyone tell me what's the meaning of "Apps on intuned managed devices"?
upvoted 4 times
...
mkoprivnj
3 years, 6 months ago
N, Y, N
upvoted 6 times
...
Nail
3 years, 10 months ago
https://docs.microsoft.com/en-us/mem/intune/apps/quickstart-create-assign-app-policy "App protection policies can only be applied to groups that contains users, not groups that contain devices."
upvoted 4 times
...
theboywonder
3 years, 11 months ago
given answers are correct, a device needs to be intune managed to apply to an APP
upvoted 1 times
Robert__Susin
3 years, 11 months ago
A device dosent need to be intune managed to apply APP, that is why MAM-WE exists for BYOD devices, see: https://docs.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment-mamwe
upvoted 6 times
...
...
prats005
4 years, 2 months ago
which one is correct?
upvoted 1 times
...
w00t
4 years, 2 months ago
Answer is correct: Yes, No, Yes.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...