Microsoft

MS-102 Free Practice Questions — Page 10

Question 88

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription. You integrate Microsoft Defender for Endpoint with Microsoft Intune. You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune. Solution: You configure a device configuration profile. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: A
Explanation:
The goal is automatic onboarding to Microsoft Defender for Endpoint when devices enroll in Intune. This can be achieved by using an Intune device configuration profile (for example, the built‑in Defender for Endpoint onboarding profile or a custom MDM profile) once Intune and Defender for Endpoint are integrated. Endpoint security EDR policies are the newer, recommended approach, but a device configuration profile still satisfies the requirement. Therefore, the solution meets the goal.

Question 89

HOTSPOT - You have a Microsoft 365 E5 subscription that contains a Windows 11 device named Device1. Device1 is onboarded to Microsoft Defender for Endpoint. You need to ensure that Device1 is blocked from connecting to IP address 131.107.10.15. What should you configure in the Microsoft Defender Endpoint settings? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 89
Show Answer
Correct Answer: Advanced features: Custom network indicators Rules: Indicators
Explanation:
Blocking a specific IP address in Microsoft Defender for Endpoint is done by creating an IP indicator. This requires enabling Custom network indicators under Advanced features and configuring the block under Rules > Indicators.

Question 91

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the identities shown in the following table. From the Microsoft Defender portal, you create an anti-spam inbound policy named Policy1 that has the following settings: • Include these users, groups and domains o Users: User3 o Groups: Group 1 • Exclude these users, groups and domains o Users: User1 Policy1 has the following Bulk email threshold & spam properties settings: • Mark as spam о Empty messages: On о Object tags in HTML On о Sensitive words: Off о Backscatter: On Policy1 has the following Actions settings: • Message actions o Spam: Move message to Junk Email folder o High confidence spam: Move message to Junk Email folder For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 91 Illustration for MS-102 question 91
Show Answer
Correct Answer: No No Yes
Explanation:
Policy1 applies only to included recipients and exclusions take precedence. 1) User1 is explicitly excluded, so messages from User1 are not evaluated by Policy1, regardless of the recipient’s group membership. 2) The Sensitive words spam property is set to Off, so messages containing sensitive words are not marked as spam. 3) User1 is excluded as a sender, but here User1 is the recipient; User3 is included directly, and empty messages are marked as spam, so the message is moved to User1’s Junk Email folder.

Question 92

You have a Microsoft 365 E5 subscription. You need to be alerted when Microsoft Defender XDR detects high-severity incidents. What should you use?

A. a custom detection rule
B. a threat policy
C. a notification rule
Show Answer
Correct Answer: C
Explanation:
Microsoft Defender XDR allows you to configure notification rules to send alerts (email, etc.) when incidents of a specified severity, such as high severity, are detected. Custom detection rules are for creating detections, and threat policies manage protection settings, not alerting.

Question 93

HOTSPOT - You have a Microsoft 365 E5 subscription. The subscription contains users that have devices onboarded to Microsoft Defender for Endpoint. Defender for Endpoint is configured to forward signals to Microsoft Defender for Cloud Apps. Cloud Discovery identifies a risky web app named App1. You need to block users from connecting to Appl from Microsoft Edge. Users must be able to bypass the restriction. Which type of app tag should you use. and what should you configure to integrate Defender for Endpoint with Defender for Cloud Apps? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 93
Show Answer
Correct Answer: App tag type: Monitored Integrate by configuring: Enforce app access
Explanation:
The Monitored app tag enables a soft block with user warning and allows bypass in Microsoft Edge. Enforce app access integrates Microsoft Defender for Endpoint with Defender for Cloud Apps to apply browser-based control and user prompts.

Question 94

DRAG DROP - You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. You need to configure Cloud Discovery to generate a report that identifies top potential risks and provides a workflow to mitigate and manage the risks. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Illustration for MS-102 question 94
Show Answer
Correct Answer: Export network traffic logs from firewall and proxy devices. Generate a Cloud Discovery snapshot report. Generate a Cloud Discovery executive report.
Explanation:
Cloud Discovery requires traffic logs to identify used apps. A snapshot report parses and analyzes the uploaded logs. The executive report then summarizes top potential risks and provides guidance to mitigate and manage those risks.

Question 95

HOTSPOT - You have a Microsoft 365 E5 subscription. You connect a cloud app that contains a group named Group1 to Microsoft Defender for Cloud Apps. You need to configure the Cloud apps settings to monitor all activities performed by the members of Group1. Which two settings should you configure? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 95
Show Answer
Correct Answer: Scoped deployment and privacy User groups
Explanation:
Scoped deployment and privacy is used to limit monitoring to specific users or groups. User groups must be imported and selected so Defender for Cloud Apps can monitor all activities performed by members of Group1.

Question 96

HOTSPOT - You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. You have a cloud app named App1. You need to implement a security solution for App1 that meets the following requirements: • Enables the real-time monitoring of user activities • Blocks specific activities as needed What should you include in the solution for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 96
Show Answer
Correct Answer: Conditional Access App Control A session policy
Explanation:
Conditional Access App Control enables real-time monitoring and control of user activities within cloud apps. Session policies allow blocking or restricting specific activities (such as downloads or uploads) during an active user session.

Question 97

You have a Microsoft 365 E5 subscription that contains a user named User1. You have a Conditional Access policy applied to a cloud-based app named App1. App1 has Conditional Access App Control deployed. You need to create a Microsoft Defender for Cloud Apps policy to block User1 from printing from App1. Which type of policy should you create?

A. activity policy
B. session policy
C. OAuth app policy
D. Cloud Discovery anomaly detection policy
Show Answer
Correct Answer: B
Explanation:
Blocking specific user actions such as printing within a cloud app requires real-time control of the user session. In Microsoft Defender for Cloud Apps, this is done with a session policy, which works with Conditional Access App Control to monitor and restrict activities like download, upload, copy, and print during the session.

Question 98

HOTSPOT - Your company has an office in London. You have a Microsoft 365 subscription. You need to create a Conditional Access policy named Policy that meets the following requirements: • Only FIDO2 security keys, Windows Hello for Business, and certificates must be supported for authentication. • The London office must be marked as a trusted location and excluded from Policy1. How should you configure Policy1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 98
Show Answer
Correct Answer: Authentication strength: Phishing-resistant MFA Named location: IP ranges
Explanation:
Phishing-resistant MFA restricts authentication to FIDO2 security keys, Windows Hello for Business, and certificate-based authentication. Defining a named location using IP ranges allows the London office’s public IPs to be marked as a trusted location, which can then be excluded from the Conditional Access policy.

$19

Get all 417 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.