Deploy Windows

Deploy Windows 10

• configure language packs

• migrate user data

• perform a clean installation

• perform an in-place upgrade (using tools such as MDT, WDS, ADK, etc.)

• select the appropriate windows edition

• troubleshoot activation issues

Perform post-installation configuration

• configure Edge and Internet Explorer

• configure mobility settings

• configure sign-in options

• customize the Windows desktop

Manage devices and data

Manage local users, local groups, and devices

• manage devices in directories

• manage local groups

• manage local users

Configure data access and protection

• configure NTFS permissions

• configure shared permissions

Configure devices by using local policies

• configure local registry

• implement local policy

• troubleshoot group policies on devices

Manage Windows security

• configure user account control (UAC)

• configure Windows Defender Firewall

• implement encryption

Configure connectivity

Configure networking

• configure client IP settings

• configure mobile networking

• configure VPN client

• troubleshoot networking

• configure Wi-Fi profiles

Configure remote connectivity

• configure remote management

• enable PowerShell Remoting

• configure remote desktop access

Maintain Windows

Configure system and data recovery

• perform file recovery (including OneDrive)

• recover Windows 10

• troubleshoot startup/boot process

Manage updates

• check for updates

• troubleshoot updates

• validate and test updates

• select the appropriate servicing channel

• configure Windows update options

Monitor and manage Windows

• configure and analyze event logs

• manage performance

• manage Windows 10 environment

Deploy and update operating systems

Plan and implement Windows 10 by using dynamic deployment

• evaluate and select an appropriate deployment options

• pilot deployment

• manage and troubleshoot provisioning packages

Plan and implement Windows 10 by using Windows Autopilot

• evaluate and select an appropriate deployment options

• pilot deployment

• create, validate, and assign deployment profile

• extract device HW information to CSV file

• import device HW information to cloud service

• troubleshoot deployment

Upgrade devices to Windows 10

• identify upgrade and downgrade paths

• manage in-place upgrades

• configure a Windows analytics environment

• perform Upgrade Readiness assessment

• migrate user profiles

Manage updates

• configure Windows 10 delivery optimization

• configure Windows Update for Business

• deploy Windows updates

• implement feature updates

• monitor Windows 10 updates

Manage device authentication

• manage authentication policies

• manage sign-on options

• perform Azure AD join

Manage policies and profiles

Plan and implement co-management

• implement co-management precedence

• migrate group policy to MDM policies

• recommend a co-management strategy

Implement conditional access and compliance policies for devices

• implement conditional access policies

• manage conditional access policies

• plan conditional access policies

• implement device compliance policies

• manage device compliance policies

• plan device compliance policies

Configure device profiles

• implement device profiles

• manage device profiles

• plan device profiles

Manage user profiles

• configure user profiles

• configure Enterprise State Roaming in Azure AD

• configure sync settings

• implement Folder Redirection, including OneDrive

Manage and protect devices

Manage Windows Defender

• implement and manage Windows Defender Application Guard

• implement and manage Windows Defender Credential Guard

• implement and manage Windows Defender Exploit Guard

• implement Microsoft Defender Advanced Threat Protection

• integrate Windows Defender Application Control

• manage Windows Defender Antivirus

Manage Intune device enrollment and inventory

• configure enrollment settings

• configure Intune automatic enrollment

• enable device enrollment

• enroll non-Windows devices

• enroll Windows devices

• generate custom device inventory reports Review device inventory

Monitor devices

• monitor device health (e.g., log analytics, Windows Analytics, or other cloud-based tools,


• monitor device security

Manage apps and data

Deploy and update applications

• assign apps to groups

• deploy apps by using Intune

• deploy apps by using Microsoft Store for Business

• deploy O365 ProPlus

• enable sideloading of apps into images

• gather Office readiness data

• configure and implement kiosk (assigned access) or public devices

Implement Mobile Application Management (MAM)

• implement MAM policies

• manage MAM policies

• plan MAM

• configure Windows Information Protection

• implement Azure Information Protection templates

• securing data by using Intune

Question: 60
You have 20 computers that run Windows 11.
You need to enable Windows Sandbox on the computers.
How should you complete the command? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is
worth one point.
Box 1: Enable-WindowsOptionalFeature
To Enable Windows 10 Sandbox with PowerShell,
Question: 61
You have a Microsoft Azure Active Directory (Azure AD) tenant.
Some users sign in to their computer by using Windows Hello for Business.
A user named User1 purchases a new computer and joins the computer to Azure AD.
User1 attempts to configure the sign-in options and receives the error message shown in the exhibit.
You open Device Manager and confirm that all the hardware works correctly.
You need to ensure that User1 can use Windows Hello for Business facial recognition to sign in to the computer.
What should you do first?
A. Purchase an infrared (IR) camera.
B. Upgrade the computer to Windows 10 Enterprise.
C. Enable UEFI Secure Boot.
D. Install a virtual TPM driver.
Answer: B
Question: 62
You have a public computer named Computer1 that runs Windows 10/ Computer1 contains a folder named Folder1.
You need to provide a user named User1 with the ability to modify the permissions of Folder1. The solution must use the principle of
least privilege.
Which NTFS permission should you assign to User1?
A. Full control
B. Modify
C. Write
D. Read & execute
Answer: A
Question: 63
You have a computer that runs Windows 10.
You need to configure a picture password.
What should you do?
A. From Control Panel, configure the User Accounts settings.
B. From the Settings app, configure the Sign-in options.
C. From the Local Group Policy Editor, configure the Account Policies settings.
D. From Windows PowerShell, run the Set-LocalUser cmdlet and specify the InputObject parameter.
Answer: B
Question: 64
You have computers that run Windows 10 Enterprise as shown in the following table.
Both computers have applications installed and contain user data.
You plan to configure both computers to run Windows 10 Enterprise LTSC 2019 and to retain all the existing applications and data.
You need to recommend a method to deploy Windows 10 Enterprise LTSC 2019 to the computers. The solution must minimize effort to
install and configure the applications.
What should you include in the recommendation for each computer? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Graphical user interface, text, application, chat or text message
Description automatically generated
Question: 65
Please wait while the virtual machine loads. Once loaded, you may proceed to the lab section. This may take a few minutes, and the wait
time will not be deducted from your overall test time.
When the Next button is available, click it to access the lab section. In this section, you will perform a set of tasks in a live environment.
While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability
to navigate to external websites) will not be possible by design.
Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesnt matter how you accomplish the task,
if you successfully perform it, you will earn credit for that task.
Labs are not timed separately, and this test may more than one lab that you must complete. You can use as much time as you would
like to complete each lab. But, you
should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the test in the time
Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
Username and password
Use the following login credentials as needed:
To enter your password, place your cursor in the Enter password box and click on the password below.
Username: Contoso/Administrator
Password: Passw0rd!
The following information is for technical support purposes only:
Lab Instance: 10921597
You need to create a user account named User5 on Client2.
The solution must meet the following requirements:
Prevent User5 from changing the password of the account.
Ensure that User5 can perform backups.
Use the principle of least privilege.
To complete this task, sign in to the required computer or computers.
Answer: On Client2, press the Win + X keys on your keyboard. Then, click or tap the Computer Management option from the menu.
Expand the Local Users and Groups from the left side of the window, and select Users.
Right-click somewhere on the blank space found in the middle section of the window, and click or tap on New User. This opens the
New User window, where you can enter all the details about the new user account.
Type the user name and, optionally, its full name and description.
Type the password to be used for that user and confirm it.
Select the User cannot change password check box.
Click Create and Windows immediately creates the user account. When you are done creating user accounts, click Close in the New
User window.
Press the Win + R keys to open Run, type secpol.msc into Run, and click/tap on OK to open Local Security Policy.
Expand open Local Policies in the left pane of Local Security Policy, click/tap on User Rights Assignment, and double click/tap on
the Back up files and directories policy in the right pane.
Click/tap on the Add User or Group button.
Click/tap on the Object Types button.
Check all the boxes for Object types, and click/tap on the OK.
Click/tap on the Advanced button.
Click/tap on the Find Now button, select the name of the user or group
Click/tap on OK.
Click/tap on OK.
When finished, you can close Local Users and Groups.
Question: 66
Your company has an on-premises network that contains an Active Directory domain. The domain is synced to Microsoft Azure Active
Directory (Azure AD). All computers in the domain run Windows 10 Enterprise.
You have a computer named Computer1 that has a folder named C:Folder1.
You want to use File History to protect C:Folder1.
Solution: You enable File History on Computer1. You then encrypt the contents of Folder1.
Does this meet the goal?
A. Yes
B. No
Answer: B
File History only backs up copies of files that are in Libraries, and Desktop folders and the OneDrive files available offline on your PC.
If you have files or folders elsewhere that you want backed up, you can add them to one of these folders.
Question: 67
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth
one point.
Graphical user interface, text, application, email
Description automatically generated
Question: 68
Your network an Active Directory domain named The domain contains 50 computers that runs Windows 8.1. The
computer has locally installed desktop application that are compatible with Windows 10.
You need to upgrade the computers to windows 10, The solution must preserver the locally installed desktop applications.
Solution: You use Microsoft Deployment Toolkit (MDT) and create a task sequence. One each compute, you run the task sequence.
Does the meet the goal?
A. Yes
B. No
Answer: B
Question: 69
You have a computer named Computer1 that runs Windows 10. Computer1 is in a workgroup.
Computer1 contains the local users shown in the following table.
The Users group has Modify permissions to a folder named D:Folder1.
User3 creates a file named File1.docx in Folder1.
Which users can take ownership of File1.docx?
A. Administrator and User1 only
B. Administrator only
C. Administrator, User1, and User2
D. Administrator and User2 only
Answer: B
Only a member of the Administrators group can take ownership of a file or folder.
Question: 70
You have a computer that runs Windows 10.
You view the domain services status as shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Device is Azure AD joined; not domain joined.
The MDM URLs in the exhibit indicate the device is enrolled in Intune.
Question: 71
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution
that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the
review screen.
You manage devices that run Windows 10.
Ten sales users will travel to a location that has limited bandwidth that is expensive. The sales users will be at the location for three
You need to prevent all Windows updates from downloading for the duration of the trip. The
solution must not prevent access to email and the Internet.
Solution: From Accounts in the Settings app, you turn off Sync settings.
Does this meet the goal?
A. Yes
B. No
Answer: B
Question: 72
You have two workgroup computers named Computer1 and Computer2 that run Windows 10.
The computers contain the local security principals shown in the following table.
Which security principals can be members of GroupA and GroupC? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Graphical user interface, text, application, chat or text message
Description automatically generated
Question: 73
You have a file named Reg1.reg that contains the following content.
What is the effect of importing the file?
A. A key named command will be renamed as notepad.exe.
B. In a key named Notepad, the command value will be set to @="notepad.exe".
C. In a key named command, the default value will be set to notepad.exe.
Answer: C
