70-398 Premium Bundle

70-398 Premium Bundle

Planning for and Managing Devices in the Enterprise Certification Exam

4.5 
(44655 ratings)
0 QuestionsPractice Tests
0 PDFPrint version
November 23, 2024Last update

Microsoft 70-398 Free Practice Questions

We offers . "Planning for and Managing Devices in the Enterprise", also known as 70-398 exam, is a Microsoft Certification. This set of posts, Passing the 70-398 exam with , will help you answer those questions. The covers all the knowledge points of the real exam. 100% real and revised by experts!

Also have 70-398 free dumps questions for you:

NEW QUESTION 1
A company plans to deploy Outlook as a managed app to all users. You deploy Microsoft Intune.
You must deploy an internally developed iOS line of business (LOB) app to all users in the sales department. These users must only be able to share data between Outlook and the internally developed LOB app.
You need to configure the environment for sales department users. What should you do?

  • A. Configure a security policy that forces encryption.
  • B. Use the Intune App Wrapping Tool to repackage the internally developed LOB application.
  • C. Upload the internally developed LOB app to the Apple App Stor
  • D. Deploy the app to all users in the sales department.
  • E. Use the Intune App Wrapping Tool to repackage the Outlook applicatio
  • F. Set the value for the App ID to match to Application ID of the internally developed LOB application.

Answer: B

Explanation: References:
https://docs.microsoft.com/en-us/intune/app-wrapper-prepare-ios

NEW QUESTION 2
A Datum Corporation plans to implement Mobile Device Management (MDM). The company uses the domain name Adatum.com. The company plans to integrate Microsoft Intune with System Center 2012 R2 Configuration Manager. Configuration Manager uses the public IP address 102.157.31.12. Domain Name System (DNS) is not configured to support MDM.You need to create a DNS record for automatically enrolling the device.Which DNS record type should you create?

  • A. a CNAME record named EnterpriseEnrollment.adatum.com that points to manage.microsoft.com.
  • B. a CNAME record named MDMEnrollment.adatum.com that points to manage.microsoft.com.
  • C. a PTR record named 102.157.31.12 that points to EnterpriseEnrollment.Adatum.com
  • D. an A resource record named autoenroll.adatum.com that points to 102.157.31.12

Answer: A

Explanation: References:
https://docs.microsoft.com/en-us/intune/windows-enroll

NEW QUESTION 3
You have a Windows 10 Enterprise computer named Computer1. Computer1 has File History enabled.
You create a folder named Folder1 in the root of the C: drive. You need to ensure that Folder1 is protected by File History.
What are two possible ways to achieve the goal? Each correct answer presents a complete solution.

  • A. From File Explorer, include Folder1 in an existing library.
  • B. Modify the Advanced settings from the FileHistory Control Panel item.
  • C. From the Settings app, modify the Backup options.
  • D. From File Explorer, modify the system attribute of Folder1.

Answer: AC

Explanation: By default, File History backs up all libraries. We can therefore ensure that Folder1 is protected by File History by adding the folder to a library.
The second method of ensuring that Folder1 is protected by File History is to add the folder location to File History. You do this by modifying the Backup options, not the File History Control Panel item as you might expect. In the Settings app, select Update & Security then Backup. Under the Back up using File History heading, select the Add a drive option.

NEW QUESTION 4
A company deploys Enterprise Mobility + Security. The company plans to use Azure Active Directory (AD) Premium to join all new Windows 10 devices.
Users must not be allowed to change the PowerSleep option.
You need to automatically apply custom power policies to all Windows 10 Azure AD joined devices.
What should you do?

  • A. From the Azure AD Premium Configuration page, enable automatic device enrollment.
  • B. Create a custom Poweroption Group Policy in Active Directory Domain Services (AD DS). Set the value of the PowerSleep option to False.
  • C. Configure automatic enrollment into Microsoft Intun
  • D. Create and deploy a custom Compliance policy to all Windows 10 devices.
  • E. Configure automatic enrollment into Microsoft Intune for all Azure AD Premium joined device
  • F. Apply a custom set of Open Mobile Alliance Uniform Resource Identifier (OMA- URI) settings to configure custom power settings.

Answer: B

NEW QUESTION 5
A company implements offline files for all Windows 10 devices. A user reports that they are running low on free disk space.
You need to determine the amount of disk space being used by offline files on the user’s device.
What should you do?

  • A. On the device, run the following Windows PowerShell command:Get-Disk | Where- Object IsOffline- Eq $True | Set-Disk-IsOffline $False
  • B. Instruct the user to launch Resource Manager.
  • C. On the device, run the following Windows PowerShell command:Get-Disk | Where- Object IsOffline- Eq $False | Set-Disk-IsOffline $True
  • D. Instruct the user to launch Sync Center.

Answer: D

NEW QUESTION 6
DRAG DROP
You need to resolve the Security team service announcement.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
70-398 dumps exhibit

    Answer:

    Explanation: 1: In the Mandatory Updates list, filter by Needing additional approvals, and approve the update.
    2: Select the Windows 10 computer device group in the Approval wizard.
    3: Configure the approval settings to require install with a deadline as soon as possible.
    References:
    https://www.credera.com/blog/infrastructure/understanding-windows-updates-for-pcs-with-microsoft-intune/

    NEW QUESTION 7
    You are a system administrator for a department that has Windows 10 Enterprise computers in a domain configuration.
    You deploy an application to all computers in the domain.
    You need to use group policy to restrict certain groups from running the application. What should you do?

    • A. Set up DirectAccess.
    • B. Configure AppLocker.
    • C. Disable BitLocker.
    • D. Run the User State Management Tool.

    Answer: B

    Explanation: AppLocker is a feature in Windows Server 2012, Windows Server 2008 R2, Windows 8, and Windows 7 that advances the functionality of the Software Restriction Policies feature. AppLocker contains new capabilities and extensions that reduce administrative overhead and help administrators control how users can access and use files, such as executable files, scripts, Windows Installer files, and DLLs.
    AppLocker rules can be applied to security groups. We can use a group policy to apply AppLocker rules to the security groups to prevent them from running the application.

    NEW QUESTION 8
    DRAG DROP
    A company plans to upgrade all devices from Windows 7 to Windows 10. All Windows 10 devices belong to an organizational unit (OU) named Desktops. All devices for users in the sales department are enrolled in Azure Active Directory (AD). All users belong to an OU named Employees.
    Users in the finance department must not be able to modify the power policy settings. You need to apply the power policy.
    What should you do? To answer, drag the appropriate option to the correct item. Each option may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
    70-398 dumps exhibit

      Answer:

      Explanation: 70-398 dumps exhibit

      NEW QUESTION 9
      A company uses Office 365. The company has an on-premises Active Directory Domain Services (AD DS) domain and Azure Active Directory Connect. The company runs an on- premises installation of System Center Configuration Manager. All devices are joined to the domain. All users have AD DS accounts and use their AD DS credentials to access the Office 365 resources.
      You plan to use Cloud App Discovery. You need to deploy a solution.
      Which three will achieve the goal? Each correct answer presents a complete solution.

      • A. Install the agent by using System Center Operations Manager.
      • B. Install the agent by using SystemCenter Configuration Manager.
      • C. Install the agent by using Group Policy.
      • D. Install the agent manually.
      • E. Install the agent by using the Office 365 portal.

      Answer: BCD

      NEW QUESTION 10
      HOTSPOT
      A company runs Windows 10 Enterprise on all devices and has a single Active Directory Domain Services (AD DS) domain. The company uses Microsoft Intune to manage Windows Phones and iOS devices.
      Security updates must be installed as quickly as possible. The update management solution must be able to automatically uninstall updates. You must not deploy any additional development or custom tools.
      You need to implement a solution.
      In the table below, identify the feature that each solution supports.
      NOTE: Make only one selection in each column. Each correct answer is worth one point.
      70-398 dumps exhibit

        Answer:

        Explanation: 70-398 dumps exhibit

        NEW QUESTION 11
        A company deploys Office 365 in a federated identity model. The environment has two Active Directory Domain Services (AD DS) servers and two Web Application Proxy servers that are not joined to the domain.
        All externally published applications that use Windows Authentication and are hosted on- premises must use Active Directory Federation Services (AD FS) to log on.
        You need deploy pre-authentication on the Web Application Proxy (WAP) servers. What should you do first?

        • A. Enable Kerberos constrained delegation.
        • B. Join the WAP servers to the AD DS domain.
        • C. Remove and reinstall the AD FS role.
        • D. Remove and reinstall the WAP role.

        Answer: B

        NEW QUESTION 12
        DRAG DROP
        You receive the following error message when you attempt to open a Remote Desktop Protocol (RDP) file to make a connection: “The remote session was disconnected because there are no Remote Desktop License Servers available to provide a license. Please contact the server administrator.”
        You need to use the RDP file to sign into the virtual machine as administrator and then fix the issue.
        In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.
        70-398 dumps exhibit

          Answer:

          Explanation: 70-398 dumps exhibit

          NEW QUESTION 13
          DRAG DROP
          You have a computer that runs Windows 10 Enterprise that contains the following folders:
          70-398 dumps exhibit
          You have a local user named User1. User1 has read and execute permission to Folder1. You need to ensure that User1 can perform the following tasks:
          The solution must use the principle of least privilege.
          Which permissions should you assign to User1 on each folder? To answer, drag the appropriate permissions to the correct folders. Each permission may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
          70-398 dumps exhibit

            Answer:

            Explanation: Advanced permissions are detailed permissions that are grouped together to create the standard permissions. The permissions in this question are standard permissions.
            Folder2: To create new files in a folder, you need Write permission to the folder. The ‘Write’ standard permission includes the ‘Create files / write data’ advanced permission.
            Folder3: To edit existing files in a folder, you need Modify permission.
            Folder5: To change the permissions of files in a folder, you need the ‘Change Permissions’ advanced permission. The Change Permission advanced permission is in the ‘Full Control’ standard permission group. Therefore, the answer for Folder5 is Full Control.
            References: http://windows.microsoft.com/en-gb/windows/before-applying-permissions-file-folder#1TC=windows-7

            NEW QUESTION 14
            Your company runs Windows 10 Enterprise on all devices. You hire a new employee and provide a device for the employee.
            All drives must be encrypted.
            You need to determine whether volume C in the device is encrypted. At an elevated command prompt, which command should you run?

            • A. mange-bde –setidentifier C:
            • B. mange-bde –on C:
            • C. mange-bde –unlock C:
            • D. mange-bde –status C:

            Answer: D

            Explanation: References:
            https://technet.microsoft.com/en-us/library/jj647767(v=ws.11).aspx#BKMK_managebde

            NEW QUESTION 15
            DRAG DROP
            You need to test the ProseWare MyNotesPro app.
            Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
            70-398 dumps exhibit

              Answer:

              Explanation: 70-398 dumps exhibit

              Topic 3, Blue Yonder Airline
              Overview Background
              Blue Yonder Airlines provides regional commercial jet services in the continental United States. The company also designs, manufactures, and sells custom parts for jet aircraft. The custom parts business is growing rapidly. Blue Yonder airlines has developed a new part that will help airlines comply with new safety regulations. The company has a backlog of customers that would like to purchase the part.
              The Sales department has 500 users and the Engineering department has 200 users. All employees work eight hour shifts. The Sales and Engineering teams cannot effectively collaborate on projects. This has resulted in missed deadlines for releasing new products to manufacturing.
              Mobile device management
              Blue Yonder Airlines has a subscription to Microsoft Intune for Mobile Device Management (MDM). The subscription includes the MDM Authority and Terms and Conditions components. The company has deployed the Network Device Enrollment service, Enterprise Certification Authority, and the Intune Certificate Connector. Blue Yonder Airlines has an on-premises Microsoft Exchange environment.
              The company will use a combination of Intune and Azure RemoteApp for Mobile Application Management.
              Mobile devices for employees
              Blue Yonder Airlines plans to deploy mobile devices to the Sales and Engineering department employees for use while they are outside of the company network. The company plans to deploy the latest iOS devices for Sales department users and Windows 10 tablet devices for Engineering department users.
              You configure a Sales group for Sales department users and an Engineering group for Engineering department users. In Intune, you configure a computer device group for Windows 10 devices, and a mobile device group for iOS devices. You synchronize the Sales and Engineering groups with Azure Active Directory (AD).
              Network resources
              You have a network file share that is used by Engineering department users to collaborate on projects. The file share is configured with full control permissions. The company is concerned that users may be disrupted if they are suddenly denied access to the file share.
              Applications
              Inventory Management App
              Blue Yonder Airlines has developed a custom inventory management app. Sales department users must be able to access the app from enrolled mobile devices. The data that the app uses is considered confidential and must be encrypted.
              New product Sales App
              You procure a third-party app from a vendor to support new product sales. The data that the app uses is highly confidential. You must restrict access to the app and the app’s data to only Engineering department users. The app has been signed by using a Blue Airlines certificate. This certificate is not trusted by devices that run Windows 10.
              Product Request Program App
              The company has developed the Product Request Program app as a 32-bit Windows application. The application allows the company to manage the sales fulfillment process. It is also used to record customer requests for new parts and services. You plan to publish the Product Request Program app in Azure RemoteApp and configure access for users in the Engineering and Sales departments. This app is not compatible with the iOS platform and cannot by published by using Intune. You create a virtual machine in Azure that runs Windows Server 2012 R2. You install the Product Request Program app on the virtual machine.
              Business Requirements
              You must ensure that the Sales and Engineering teams can share documents and collaborate effectively. Any collaboration solution must be highly available and must be accessible from the internet. You must restrict access to any shared files to prevent access.
              You must restrict permissions to the Engineering file share. You must monitor access to the file share.
              You must provide users in the Sales and Engineering departments access to the following resources:
              *Corporate email
              *File Shares hosted in Microsoft SharePoint Online
              *The Product Request Program app
              Technical Requirements
              You have the following technical requirements:
              *Allow all Sales department users to enroll iOS devices for device management andenable encrypted notifications to the devices.
              *Employees must be able to access company resources without having to manually install certificates or using an out-of-band process.
              *Employees must only access corporate resources from devices that comply withthe company’s security policies.
              Mobile device protection policies
              *All devices must include a trusted build and must comply with Blue Yonder Airlines password complexity rules.
              *You must clear all corporate data from a mobile device when the number of repeated log on failures is more than 10.
              *All devices must be protected from data loss in the event that a device is lost or damaged.
              *Data that is considered confidential must be encrypted on devices.
              Additional technical requirements for Engineering department users and devices
              *Users must not be challenged for credentials after they initially enroll a device in Intune.
              *Users must be able to access corporate email on enrolled Windows 10 devices.
              *Devices must be automatically updated when an update is available. You must configure the Intune agent to prompt for restart no more than one time during normal business hours. System restarts to complete update installations must occur outside of normal business hours.
              Problem Statements
              Sales and Engineering teams
              Sales and Engineering department users report that it is difficult to share documents and collaborate on new projects. Blue Yonder Airlines has an urgent need to improve collaboration between the Sales department and Engineering department. Any collaboration solution must be highly available and accessible from the Internet.
              Engineering department users report that Intune prompts them to restart their Windows 10 devices every 30 minutes when an update is available for installation. The prompts are disruptive to users.
              Security issues
              The Blue Yonder Airlines Security team has detected a vulnerability in Windows 10 devices. Microsoft has released a patch to address the vulnerability. The Security department has issued a service announcement. They request that you deploy the patch to all Windows 10 devices managed by Microsoft Intune.

              NEW QUESTION 16
              HOTSPOT
              You administer Windows 10 Enterprise computers in your company network, including a computer named Wst1. Wst1 is configured with multiple shared printer queues.
              Wst1 indicates hardware errors. You decide to migrate the printer queues from Wst1 to a new computer named Client1.
              You export the printers on Wst1 to a file. You need to import printers from the file to Client1.
              From the Print Management console, which Print Management node should you select? To answer, select the appropriate node in the answer area.
              70-398 dumps exhibit

                Answer:

                Explanation: We have exported the printers on Wst1 to a file. To import printers from the file to Client1, we use the Printer Migration Wizard.
                Right-click Print Management, and then click Migrate Printers to open the Printer Migration Wizard. Select Import printer queues and printer drivers from a file, and select the export file. Then complete the wizard.
                References: http://blogs.technet.com/b/canitpro/archive/2013/06/17/step-by-step-install-use-and-remove-windows-server-migration-tools.aspx

                NEW QUESTION 17
                You need to import RemApp1 into the Azure RemoteApp Template Image Library. Which tool should you run first?

                • A. Disk2VHD
                • B. System Preparation Tool
                • C. Application Compatibility Toolkit
                • D. Azure Mobile Apps Software Development Kit installer.

                Answer: B

                P.S. Easily pass 70-398 Exam with 74 Q&As 2passeasy Dumps & pdf Version, Welcome to Download the Newest 2passeasy 70-398 Dumps: https://www.2passeasy.com/dumps/70-398/ (74 New Questions)


                START 70-398 EXAM