Which Windows deployment option is: • where Microsoft Windows 10 is installed over the top of your current older Windows operating system. • Microsoft's recommended method when upgrading to Windows 10. • is quick and any user settings, apps and drivers are retained.
Autopilot
Wipe
Dynamic
In-place
Which Microsoft Windows 10 deployment option is: • is new, and it's been developed to: ○ allow administrators to quickly deploy new Windows 10 devices. ○ The organization no longer needs to reimage a device with a custom Windows image. ○ They can simply take the device out of the box, and then apply the necessary configuration changes to transform the device to be enterprise ready.
Which Microsoft Windows 10 deployment option is where: ○ a backup of the user and application settings is made ○ the old operating system is completely wiped ○ Windows 10 operating system is then installed then the backup of the user state is applied.
Which Microsoft Windows 10 deployment option is: • the latest deployment method introduced with Windows 10. • New devices are supplied with Windows 10 already pre-installed and, therefore, there is no need to re-image or manually prepare devices. • Administrators simply pre-configure settings and these are applied to the device. • When a new device is switched on by the end-user, settings and apps are auto-deployed to devices using Azure AD and Intune. • At the end of the setup process, the device is fully configured, secured, and ready for use.
A is a file that contains Windows 10 settings and configuration information that you may want the device to have.
★Methods for Deploying and Configuring Windows 10★
↓Definition↓ Transform an existing Windows 10 installation, join the device to Azure AD, and enroll it into a Mobile Device Management solution to complete configuration. Deploy Windows 10 on an existing Windows 7 or 8.1 device.
Windows Autopilot
Windows 10 Subscription Activation
Azure AD / MDM
Provisioning Packages
In-place Upgrade
Bare-metal
Refresh (wipe and load)
Replace
↓Definition↓ Upgrade the Windows edition seamlessly without requiring intervention or rebooting of the device.
↓Definition↓ Cloud-based identity and management solution offering device, app, and security configuration.
↓Definition↓ Small distributable .appx files that securely transform devices to meet organizational requirements.
↓Definition↓ Upgrade an earlier version of Windows to Windows 10 while retaining all apps, user data, and settings.
↓Definition↓ Deploy Windows 10 to newly built devices or wipe existing devices and deploy fresh Windows 10 images to them.
↓Definition↓ Re-use existing devices. Retain user state (user data, Windows, and app settings). Erase devices, deploy Windows 10 images to them, and finally, restore the user state.
↓Definition↓ Purchase new devices. Back up the user state from the current device. Transform or wipe a pre-installed Windows 10 installation and restore the user state.
Windows 10 is released using a continuous delivery model known as as a Service, with a new version of Windows 10 available every months.
It is recommended that administrators choose a group of users and deploy Windows 10 into focused pilot projects to test each version of Windows 10 within their organizations prior to rolling out the operating system to larger cohorts of users.
If internet access is not available for the Windows deployment, then you will need to select an alternative deployment method.
Each user profile contains a .dat file. When a user signs in to Windows, the system loads this file into the registry and maps it to the HKEY_CURRENT_ USER registry subtree. The user part of the registry contains user settings, such as desktop background and screen saver.
If a device has two policies applied and one is compliant and the other non-compliant, the resulting status for the device will be _________________.
compliant
non-compliant
provisioning methods include using Azure AD, Mobile Device Management, provisioning packages, subscription Activation, and Windows Autopilot.
Provisioning packages are created using the ___________________, which is part of the Windows ADK or as an app from the Microsoft Store.
Windows Configuration Designer
Delivery Optimization
Windows Analytics Designer
Windows Analytics is a cloud-based, free solution that includes:
Device Health
Upgrade Readiness
Progress Status
Update Compliance
Windows Autopilot allows you to automate the customization of the Out-Of-Box Experience and seamlessly enroll devices into .
Which Windows 10 editions are licensed to use Windows Autopilot and require Azure AD and an MDM solution?
Enterprise
Professional
Educational
All, Version 1703 and newer
The Windows Autopilot Enrollment Status Page allows only System Administrators to see the progress status page during the device setup.
Device vendors can extract and register devices with the Windows Autopilot service, or you can use the ______________.ps1 PowerShell cmdlet to extract the hardware ID for your existing devices.
Get-WindowsAutoPilot
Get-MSWindowsAutoPilotInfo
Get-WindowsAutoPilotInfo
Import-WindowsAutoPilotInfo
You can downgrade from any edition of Windows 10 to Windows 7, 8, or 8.1.
Windows 10 in S Mode is permanent and cannot be switched to another valid edition of Windows 10.
Upgrade Windows System Device( Upgrade, Windows, System, Device ) Readiness, which is part of Windows Analytics, offers free tools for enterprises to plan and manage the upgrade process, end to end.
When configuring devices to report telemetry to your Windows Analytics environment, you need to add the commercial product device private( commercial, product, device, private ) ID to your devices so that they know where to send their telemetry data.
You will need to wait for between ________ after configuring the Windows Analytics requirements before the first data will appear in the solution.
15 - 45 minutes
5 - 10 hours
12 - 24 hours
48 - 72 hours
Enterprises can securely extract, store, and restore user state using the User State Migration Tool.
Windows Folder Move for OneDrive automatically redirects users’ folders and important files to their OneDrive for Business account.
Cloud-based accounts can have their settings synced using ______________.
Folder redirection
Enterprise State Roaming
Roaming profiles
Windows 10 uses _____________ to increase the delivery speed of updates and reduce external bandwidth usage.
Virtual RAM
ReadyBoost
Windows Prime Time
Businesses can defer Quality Updates for up to __ days, and they can defer Feature Updates for up to a maximum of __ days.
15, 365
30, 365
45, 180
60, 180
Windows 10 Enterprise and Education edition updates that are targeted for release in September are supported for up to months from release.
You can use the app or Update Compliance to monitor Windows 10 updates within an enterprise.
Windows Hello allows you to use retinal or iris scanning to authenticate users.
Azure AD Password Protection allows you to enforce a list of up to 1,000 1,500 2,000 2,500( 1,000, 1,500, 2,000, 2,500 ) banned passwords that cannot be used by your users.
Multifactor authentication requires that users must have three two one( three, two, one ) (or more) things with which to identify themselves.
Windows Hello for Business is the enterprise implementation of Windows Hello and allows users to: authenticate to Active Directory or Azure AD, and it enables them to access network resources.
authenticate to Active Directory
authenticate to Azure Active Directory
access network resources
Dynamic Active Static Windows Kinetic( Dynamic, Active, Static, Windows, Kinetic ) Lock allows users with smartphones to automatically lock their devices whenever they step away from them.
Co-management is when you manage devices using:
System Center Configuration Manager (SCCM)
Azure Active Directory
Microsoft Intune
Starting with Windows 10 Version 1803 and later, can take precedence over policy when both Group Policy and its equivalent policy are set on the device.
The __________________ Tool is used to evaluate which Group Policies have been set for a target user/device and cross-reference against its built-in list of supported MDM policies.
Windows Delivery
System Center Configuration Manager
MDM Migration Analysis
___________________ policies provide administrators with a tool that allows Azure AD to check whether conditions have been met before access to corporate resources, such as controlled apps, will be granted.
Conditional access
Device access
Limited access
Default access
The benefits of deploying Conditional Access are:
Manage time.
Manage risk.
Address compliance and governance.
Manage cost.
Increase productivity.
Compliance policies are used to ensure devices meet compliance requirements, such as:
being encrypted
number of devices owned
not being jailbroken
using a password for device access
Non-compliant devices can be blocked from accessing resources or...
can be remotely wiped.
be placed on a registered offender list.
can be offered help to become compliant.
taken from user while under investigation.
When multiple device compliance policies are assigned to a device, Intune calculates a compliance status based on the highest lowest weakest strongest( highest, lowest, weakest, strongest ) severity level of all the policies assigned to the device.
Devices will periodically check with Intune to determine the compliance status of the device; this will be every ___ hours for Apple devices and every ___ hours for Android and Windows devices.
2; 6
3; 5
4; 6
6; 8
Intune device configuration policies are used to configure device settings using MDM.
Intune can deploy PowerShell scripts Java scripts Cmdlet scripts( PowerShell scripts, Java scripts, Cmdlet scripts ) to Windows devices using an MDM extension. This allows administrators to deploy Win32 apps if required.
MDM Meta AD Scope( MDM, Meta, AD, Scope ) tags are used to assign and filter Intune policies to specific Azure AD groups.
A user profile contains the user state which includes application settings and other system components settings, and per-user data, such as the:
user’s Desktop
Start menu
Documents folder
Music folder
Photos folder
User profiles can be:
Local
Regional
Roaming
Mandatory
Super Mandatory
Extremely Mandatory
Temporary User
If roaming user profiles grow too large, there will be little effect such as slowing down log in times for users.
Administrators can enable Temporary User type profiles so to store the individual profile folders to a location stored on the network.
Administrators can enable Enterprise State Roaming Folder Redirection Roaming Mandatory Roaming( Enterprise State Roaming, Folder Redirection, Roaming, Mandatory Roaming ) to allow Azure AD to securely synchronize users’ Windows settings and Universal Windows Platform (UWP) app settings data across their Windows devices.
Windows Defender Application Guard Windows Defender Exploit Guard Windows Defender Credential Guard Windows Defender Application Control( Windows Defender Application Guard, Windows Defender Exploit Guard, Windows Defender Credential Guard, Windows Defender Application Control ) requires a TPM and virtualization features to be enabled in a 64-bit edition of either Windows 10 Enterprise or Windows 10 Education.
Windows Defender Credential Guard Windows Defender Exploit Guard Windows Defender Application Guard Windows Defender Application Control( Windows Defender Credential Guard, Windows Defender Exploit Guard, Windows Defender Application Guard, Windows Defender Application Control ) consists of four components: Exploit Protection, Attack Surface Reduction Rules, Network Protection, and Controlled Folder Access.
Windows Defender Application Guard Windows Defender Application Control Windows Defender Exploit Guard Windows Defender Credential Control( Windows Defender Application Guard, Windows Defender Application Control, Windows Defender Exploit Guard, Windows Defender Credential Control ) has similar requirements to Credential Guard and enables you to open new browser windows in a virtualized environment.
Windows Defender Application Control Windows Defender Credential Guard Windows Defender Exploit Guard Windows Defender Application Guard( Windows Defender Application Control, Windows Defender Credential Guard, Windows Defender Exploit Guard, Windows Defender Application Guard ) enables you to determine which apps are safe to run in your organization.
Most Windows Defender features are managed through:
MDM
Windows PowerShell
Group Policy
Local Policy
The Quick Start Device Management MDM Best Start( Quick Start, Device, Management, MDM, Best Start ) node in the Device Enrollment blade of the Microsoft 365 Device Management portal enables you to view the completed steps to enable enrollment for different device types.
Automatic enrollment enables you to enroll Windows devices when they with or join Azure AD.
Device Enrollment Manager Accounts enable a specified account to enroll up to 500 1,000 1,500 2,500( 500, 1,000, 1,500, 2,500 ) devices.
Which of the below are not a way to enroll Windows devices?
Add a Work Or School account
Enroll In MDM Only (user-driven)
Azure AD Join during OOBE
Purchasing Product ID code via the Microsoft Store
Azure AD Join using Windows Autopilot
Enroll In MDM only (using a Device Enrollment Manager)
Azure AD Join using bulk enrollment
Windows can be configured to be user-driven or self-deploying, depending on how much user interaction you want.
To enroll Android and iOS devices, you can download the Company Portal app from the relevant device store, and then sign in to the app using an organizational or school account.
Windows Analytics and Log Analytics do not require an Azure subscription.
Threat Agent Status monitoring enables you to verify the status of Windows Defender on any device.
The Windows Imaging and Configuration Designer is a sub-component of which application suite?
Windows Assessment and Deployment Toolkit
Application Compatibility Toolkit
Microsoft Deployment Toolkit
User State Migration Tool
Office 365
A virtual machine that obtains its activation status from the host machine on which it is running is referred to as which type of activation?
Inherited
Subscription
Hosted
Virtual
Secondary
Which tool would you expect to see in an environment that is entirely using dynamic provisioning as their deployment method?
Windows Imaging and Configuration Designer
Windows Deployment Services
Which traditional deployment tool can deliver the highest level of automation and least level of user interaction when deploying an operating system?
Which scenario refers to the use of a device that is personally owned, but still recognized and managed by a corporate environment?
BYOD
AAD
UE-V
CYOD
Which statement would not represent a benefit of using provisioning packages to deploy Windows 10?
A new operating system must be re-installed
No dependence on a new or custom image
Multiple configurations within a single package
No dependence on a Mobile Device Management platform
No dependence on network connectivity
A provisioning package is applied to a target system by using which method?
Automatic distribution through Azure Active Directory and Mobile Device Management
Performing a wipe and load operation on the device
Distribution through Windows Deployment services
Local installation on the device
Distributing the package with Active Directory group policies
Which device configuration option is not available when using the user-driven mode of Windows Autopilot?
Azure Active Directory join
On-premises Active Directory join
Language choice
Locale and keyboard
Hybrid Active Directory join
Which statement correctly distinguishes a User Environment (UE-V) profile from a traditional roaming profile?
A roaming profile can include application settings, a UE-V profile cannot
A roaming profile allows targeted settings synchronization, a UE-V profile does not
A UE-V profile can include application settings, a roaming profile cannot
A roaming profile can follow you from computer to computer, a UE-V profile cannot
A UE-V profile allows targeted settings synchronization, a roaming profile does not
A previously applied provisioning package can be removed in which interface of Windows 10?
Settings App – Accounts – Access Work or School
Settings App – Accounts – Email & Accounts
Settings App – Apps – Apps and Features
Settings App – Update & Security – Delivery Optimization
Settings App – Accounts – Sync Your Settings