exam questions

Exam MD-101 All Questions

View all questions & answers for the MD-101 exam

Exam MD-101 topic 5 question 14 discussion

Actual exam question from Microsoft's MD-101
Question #: 14
Topic #: 5
[All MD-101 Questions]

HOTSPOT -
You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com. All Windows 10 devices have apps named App1, App2 and App3 installed and are enrolled in Microsoft Intune.
You configure the following settings in Windows Information Protection (WIP):
✑ Protected apps: App1
✑ Exempt apps: App2
Windows Information Protection mode: Silent

App1, App2, and App3 use the same file format.
You create a file named File1 in App1.
You need to identify which apps can open File1.
Which apps should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune#exempt-apps-from-wip- restrictions

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Greysi
Highly Voted 2 years, 11 months ago
Same question as in MS-100 Q31 Topic 1. 1. Correct, all Apps have still access, because "Silent" 2. App3 only
upvoted 6 times
Morwen
1 year, 10 months ago
This is wrong, App3 doesn't have any policy, it's App1 that has Silent policy applied and it will have logging
upvoted 1 times
...
...
golijat
Most Recent 1 year, 8 months ago
The apps that can open File1 are as follows: - **App1**: As a protected app, App1 can open File1 because it adheres to the Windows Information Protection (WIP) policy¹. - **App2**: As an exempt app, App2 can also open File1. Exempt apps are exempt from the WIP policy and can access corporate data without restrictions². However, **App3** will not be able to open File1. This is because it is neither a protected app nor an exempt app under the WIP policy, and therefore it won't have access to files created in App1¹². Please note that in silent mode, Windows Information Protection (WIP) doesn't block inappropriate data sharing, it just logs it¹. So, any attempts to open File1 from App3 will be logged. Source: Conversation with Bing, 9/25/2023
upvoted 1 times
...
golijat
1 year, 8 months ago
The apps that can open File1 are App1 and App2. Here’s why: App1 is listed as a protected app in the Windows Information Protection (WIP) policy, which means it can access enterprise data and open protected files. App2 is listed as an exempt app in the WIP policy. Exempt apps ignore the WIP policy and can open both protected and unprotected files. App3 is not listed in the WIP policy, so it cannot open protected files. Please note that this applies when the WIP mode is set to Silent An action will be logged when you attempt to open File1 from **App3**. Here's why: - **App1** is a protected app, so it can open protected files without triggering an audit event. - **App2** is an exempt app, so it can also open protected files without triggering an audit event. - **App3** is not listed in the Windows Information Protection (WIP) policy, so if it attempts to open a protected file, it will trigger an audit event¹. This is because WIP creates audit events in situations such as when data is marked as Work but shared to a personal app.
upvoted 1 times
...
raduM
2 years, 7 months ago
now it says protected apps app1 wth? so it should be app1 in this case
upvoted 4 times
...
raduM
2 years, 7 months ago
wth??? shouldn't it be app2? it says protected apps app2 so basically an event will be logged only when you try to open the file from app2. the policy doesn't say anything about app3 so why would an event be logged there?
upvoted 2 times
...
AK4U_111
2 years, 7 months ago
Can someone please elaboprate as to why #2 is App 3 only?
upvoted 1 times
DashP
2 years, 6 months ago
App2 is Exempt
upvoted 2 times
...
...
DPivc
3 years, 11 months ago
Shouldn't the action be logged only from App3?
upvoted 3 times
...
Tomtom11
3 years, 11 months ago
WIP runs silently, logging inappropriate data sharing, without blocking anything that would have been prompted for employee interaction while in Allow Override mode. Unallowed actions, like apps inappropriately trying to access a network resource or WIP-protected data, are still stopped.
upvoted 2 times
...
Tomtom11
3 years, 11 months ago
https://docs.microsoft.com/en-us/mem/intune/apps/windows-information-protection-policy-create
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...