exam questions

Exam MD-101 All Questions

View all questions & answers for the MD-101 exam

Exam MD-101 topic 3 question 71 discussion

Actual exam question from Microsoft's MD-101
Question #: 71
Topic #: 3
[All MD-101 Questions]

HOTSPOT -
You have two Windows 10 devices enrolled in Microsoft Intune as shown in the following table.

The Compliance policy settings are configured as shown in the following exhibit.

On August 1, you create a compliance policy as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: No -
Device1 belongs to Group2. Group2 has not been assigned a compliance policy. Devices with no compliance policy assigned as Not Compliant. Device1 gets a 3 day grace period, but at August 4 is it marked as Non-compliant.

Box 2: Yes -
Device1 belongs to Group2. Group2 has not been assigned a compliance policy. Devices with no compliance policy assigned as Not Compliant. Device1 gets a 3 day grace period, so at August 2 it is compliant.

Box 3: No -
Device2 has BitLocker Disabled. The Windows 10 compliance policy applies to Group1 which includes Device1. At August 4 Device is marked noncompliant. 5 days later, at August 9th it is retired.
Note:
* Retire the noncompliant device: This action removes all company data off the device and removes the device from Intune management.
* By default, each compliance policy includes the action for noncompliance of Mark device noncompliant with a schedule of zero days (0). The result of this default is when Intune detects a device isn't compliant, Intune immediately marks the device as noncompliant.
By configuring Actions for noncompliance you gain flexibility to decide what to do about noncompliant devices, and when to do it. For example, you might choose to not block the device immediately, and give the user a grace period to become compliant.
Compliance status validity period (days):
Specify a period in which devices must successfully report on all their received compliance policies. If a device fails to report its compliance status for a policy before the validity period expires, the device is treated as noncompliant.
Reference:
https://docs.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started https://docs.microsoft.com/en-us/mem/intune/protect/actions-for-noncompliance

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ChrisC21
Highly Voted 2 years ago
I'm thinking No, No, Yes. Here's my reasoning: There is no policy applied to device 1, which means it is counted as not-compliant. There is no policy or setting that would shift Device 1 to be compliant that applies to Device 1. The "Compliance Status Validity Period" setting is meant to change the compliance status of a device from compliant, to not compliant based upon a defined waiting or grace period, not the other way around. So, Device 1 remains not compliant throughout this whole process, which is why the first two answers are a "no". The third statement is a "yes", because Device 2 has Bitlocker disabled, which makes it not compliant. After 5 days, August 6th, it will still be noncompliant and be retired according to the applied policies in the pick. So we have our answers being no, no, yes.
upvoted 6 times
3dk1
1 year, 11 months ago
I agree, With Group2 being excluded I assume that would mean that Device1 has not policy applied, thus making it non-compliant regardless of the date. Device2 (being in Group1) will have the policy applied to it, and since it does not have bitlocker enabled - it will be retired after 5 days.
upvoted 1 times
...
...
AliNadheer
Most Recent 2 years, 2 months ago
No for all, for device 2- it will be marked for retirement, see below : Retire the noncompliant device: This action removes all company data off the device and removes the device from Intune management. The following platforms support this action: Android device administrator Android (AOSP) Android Enterprise: Fully Managed Dedicated Corporate-Owned Work Profile Personally Owned Work Profile iOS/iPadOS macOS Windows 10/11 When this action applies to a device, that device is added to a list of devices in the Microsoft Intune admin center at Devices > Compliance policies > Retire Noncompliant Devices. The device isn't retired until an admin takes explicit action to retire the device. reference: https://learn.microsoft.com/en-us/mem/intune/protect/actions-for-noncompliance
upvoted 1 times
...
Graz
2 years, 4 months ago
There are 2 ways of looking at this and I'm not sure which is correct. 1. The given Answer is correct, despite mixing up the explanation in box 3 with device 1 and device 2. The rationale makes sense. 2. If Group 2 is excluded from the compliance policy all together(which it is), wouldn't that mean than the days/grace periods of noncompliance for device 1 are irrelevant. All Devices without a compliance policy are marked uncompliant. With this reasoning, if this question appears on the exam, I'd answer NNN and know that I'm at least getting 2/3 of the question correct. Only part I'm unsure is box 2. I'll take my chance with that.
upvoted 4 times
...
Seley
2 years, 5 months ago
The explanation is wrong, because device 2 belongs to group 1. The explanation says device 1 is in group 1, which is wrong. Since the compliancy policy is only for group 1, it only applies to device 2. This means device 1 has no profile assigned and will be marked as non-compliant in 10 days as I understand it. So for the time being it is compliant. 1. Yes. 2. Still yes. 3. No, because device 2 is part of group 1. And the policy applies to group 1. Since device 2 has no bitlocker enabled it is not compliant. There in 5 days it will be retired. So yes, device 2 will be retired on August 6th. This is my reasoning and what I will go with
upvoted 2 times
Seley
2 years, 5 months ago
I change my opinion on the last part. 3. Is indeed No. It isn’t retired on the day it is marked compliant, but 5 days after, which would put it past August 6.
upvoted 1 times
DashP
2 years, 5 months ago
If the device is not compliant, and passes the configured amount of days it will be added to a list of devices in the Admin console considered for retirement. The device isn’t retired until an admin takes explicit action to retire the device.
upvoted 1 times
...
...
...
raduM
2 years, 5 months ago
no no yes
upvoted 4 times
...
raduM
2 years, 6 months ago
device 1 is member of group 2 so it will not get the policy because group 2 is excluded. group 1 will get the policy so at the 6th of Auigust 5 days will have passed sice it got the policy so it will be retired.
upvoted 1 times
...
AK4U_111
2 years, 6 months ago
The explaination says "The Windows 10 compliance policy applies to <<Group1 which includes Device1>>" WTH??
upvoted 1 times
...
Feyenoord
2 years, 6 months ago
I think it is No, No Yes.
upvoted 1 times
Feyenoord
2 years, 6 months ago
Need to correct myself, No, No, No
upvoted 1 times
...
...
jenraed
2 years, 6 months ago
I think it's NNN. From the first link: Compliance status validity period (days) Specify a period in which devices must successfully report on all their received compliance policies. If a device fails to report its compliance status for a policy before the validity period expires, the device is treated as not compliant. So wouldn't Device1 be marked as compliant until August 11?
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago