70-697 Sample Questions & Answers
Managing mobile devices and apps through Intune takes the biggest share, ahead of Active Directory identity and user accounts, migrating user data and deploying Hyper-V, network and storage configuration, file permissions, and remote access.
Launch the full 70-697 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
You deploy several tablet PCs that run Windows 10 Enterprise.You need to minimize power usage when the user presses the sleep button.What should you do? A.In Power Options, configure the sleep button setting to Sleep.B.In Power Options, configure the sleep button setting to Hibernate.C.Configure the active power plan to set the system cooling policy to passive.D.Disable the C-State control in the computer’s BIOS.
Show answer & explanation
Correct answer: B
- Question 2IntermediateSelect 2
You are the desktop administrator for a small company.Your workgroup environment consists of Windows 10 Enterprise computers. You want to prevent 10 help desk computers from sleeping. However, you want the screens to shut off after a certain period of time if the computers are not being used.You need to configure and apply a standard power configuration scheme for the 10 help desk computers on your network.Which two actions should you perform? Each correct answer presents part of the solution. A.Import the power scheme by using POWERCFG /IMPORT on each of the remaining help desk computers. Set the power scheme to Active by using POWERCFG /S.B.Use POWERCFG /X on one help desk computer to modify the power scheme to meet the requirements. Export the power scheme by using POWERCFG / EXPORT.C.Use POWERCFG /S on one help desk computer to modify the power scheme to meet the requirements. Export the power scheme by using POWERCFG / EXPORT.D.Import the power scheme by using POWERCFG /IMPORT on each of the remaining help desk computers. Set the power scheme to Active by using POWERCFG /X.
Show answer & explanation
Correct answers: A, B
- Question 3IntermediateSelect 2
A company has an Active Directory Domain Services (AD DS) domain. All client computers run Windows 10 Enterprise. Some computers have a Trusted PlatformModule (TPM) chip.You need to configure a single Group Policy object (GPO) that will allow Windows BitLocker Drive Encryption on all client computers.Which two actions should you perform? Each correct answer presents part of the solution. A.Enable the Require additional authentication at startup policy setting.B.Enable the Enforce drive encryption type on operating system drives policy setting.C.Enable the option to allow BitLocker without a compatible TPM.D.Configure the TPM validation profile to enable Platform Configuration Register indices (PCRs) 0, 2, 4, and 11.
Show answer & explanation
Correct answers: A, C
- Question 4IntermediateSelect 2
Employees are permitted to bring personally owned portable Windows 10 Enterprise computers to the office. They are permitted to install corporate applications by using the management infrastructure agent and access corporate email by using the Mail app.An employees personally owned portable computer is stolen.You need to protect the corporate applications and email messages on the computer.Which two actions should you perform? Each correct answer presents part of the solution. A.Prevent the computer from connecting to the corporate wireless network.B.Change the user’s password.C.Disconnect the computer from the management infrastructure.D.Initiate a remote wipe.
Show answer & explanation
Correct answers: B, D
- Question 5Intermediate
You are an IT consultant for small and mid-sized business.One of your clients wants to start using Virtual Smart Cards on its Windows 10 Enterprise laptops and tablets. Before implementing any changes, the client wants to ensure that the laptops and tablets support Virtual Smart Cards.You need to verify that the client laptops and tablets support Virtual Smart Cards.What should you do? A.Ensure that each laptop and tablet has a Trusted Platform Module (TPM) chip of version 1.2 or greater.B.Ensure that BitLocker Drive Encryption is enabled on a system drive of the laptops and tablets.C.Ensure that each laptop and tablet can read a physical smart card.D.Ensure that the laptops and tablets are running Windows 10 Enterprise edition.
Show answer & explanation
Correct answer: A
- Question 6Intermediate
Your network contains an Active Directory domain named contoso.com. Contoso.com is synchronized to a Microsoft Azure Active Directory. You have a MicrosoftIntune subscription.Your company plans to implement a Bring Your Own Device (BYOD) policy. You will provide users with access to corporate data from their personal iOS devices.You need to ensure that you can manage the personal iOS devices.What should you do first? A.Install the Company Portal app from the Apple App Store.B.Create a device enrollment manager account.C.Set a DNS alias for the enrollment server address.D.Configure the Intune Service to Service Connector for Hosted Exchange.E.Enroll for an Apple Push Notification (APN) certificate.
Show answer & explanation
Correct answer: E
- Question 7Intermediate
You manage Microsoft Intune for a company named Contoso. Intune client computers run Windows 10 Enterprise.You notice that there are 25 mandatory updates listed in the Intune administration console.You need to prevent users from receiving prompts to restart Windows following the installation of mandatory updates.Which policy template should you use? A.Microsoft Intune Agent SettingsB.Windows Configuration PolicyC.Microsoft Intune Center SettingsD.Windows Custom Policy (Windows 10 and Windows 10 Mobile)
Show answer & explanation
Correct answer: A
- Question 8IntermediateSelect 2
You have an Active Directory domain named contoso.com that contains a deployment of Microsoft System Center 2012 Configuration Manager Service Pack 1(SP1). You have a Microsoft Intune subscription that is synchronized to contoso.com by using the Microsoft Azure Active Directory Synchronization Tool (DirSync.)You need to ensure that you can use Configuration Manager to manage the devices that are registered to your Microsoft Intune subscription.Which two actions should you perform? Each correct answer presents a part of the solution. A.In Microsoft Intune, create a new device enrollment manager account.B.Install and configure Azure Active Directory Synchronization Services (AAD Sync.)C.In Microsoft Intune, configure an Exchange Connector.D.In Configuration Manager, configure the Microsoft Intune Connector role.E.In Configuration Manager, create the Microsoft Intune subscription.

Show answer & explanation
Correct answers: D, E
- Question 9Intermediate
You have a Microsoft Intune subscription.You have three security groups named Security1, Security2 and Security3. Security1 is the parent group of Security2. Security2 has 100 users.You need to change the parent group of Security2 to be Security3.What should you do first? A.Edit the properties of Security1.B.Edit the properties of Security2.C.Delete security2.D.Remove all users from Security2.
Show answer & explanation
Correct answer: C
- Question 10Advanced
Manage identity · Configure Assigned Access for Kiosk Devices
A manufacturing company, Fabrikam Inc., is deploying Windows 10 Enterprise to 500 new kiosk-style devices on the factory floor. These devices will be used by multiple shift workers for a single, specific line-of-business (LOB) application. The devices are joined to an on-premises Active Directory domain. The primary requirements are to ensure that users can only access the specified LOB application, cannot access the file system or other system settings, and that the device automatically logs into a generic, low-privilege domain account upon startup. You must achieve this using Group Policy.
Which configuration approach should you implement to meet all these requirements?
Show answer & explanation
Correct answer: C
Assigned Access is the purpose-built feature in Windows 10 Enterprise for creating single-app kiosk devices. When configured via Group Policy for a domain account, it automatically signs in that user and launches the specified UWP app in a locked-down, full-screen mode, preventing access to any other system functions. AppLocker and Shell Launcher are valid lockdown technologies, but Assigned Access is the most direct and comprehensive solution for a single UWP app kiosk scenario and handles the automatic logon and lockdown process seamlessly.
Ready for the real thing?
The full 70-697 simulator has every exam-style question, timed mode, and instant scoring.