Microsoft

MS-102 Free Practice Questions — Page 12

Question 109

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription. You integrate Microsoft Defender for Endpoint with Microsoft Intune. You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune. Solution: You create an endpoint detection and response (EDR) policy. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: A
Explanation:
Yes. After Microsoft Defender for Endpoint is integrated with Intune, creating and assigning an Endpoint Detection and Response (EDR) policy in Intune enables automatic onboarding of enrolled devices to Defender for Endpoint. This is one of the supported onboarding methods and meets the stated goal.

Question 110

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. You plan to perform a security audit of all the apps detected by Cloud Discovery. You need to track which apps were audited. The solution must ensure that the list of audited apps can be displayed in the cloud app catalog. What should you do?

A. Define each app as a critical asset.
B. Deploy Conditional Access App Control.
C. Enable app governance.
D. Generate a Cloud Discovery snapshot report.
E. Apply a custom app tag to each app.
Show Answer
Correct Answer: E
Explanation:
To track which discovered cloud apps have been audited and display that status directly in the cloud app catalog, you should apply a custom app tag to each app. Microsoft Defender for Cloud Apps supports custom tags that appear in the Cloud App Catalog and can be used specifically to mark audit status (for example, "Audited"). Other options do not provide a visible, persistent audit-tracking indicator within the catalog.

Question 111

You have a Microsoft 365 subscription that includes Microsoft Intune and Microsoft Defender XDR. All users have devices that run Windows 11. From the Microsoft Defender portal, you review the Microsoft Secure Score recommendations. One of the top recommendations is to block all Microsoft Office applications from creating child processes. You need to increase the secure score by addressing the recommendation. What should you do?

A. Select Safe Documents for Office clients.
B. Create a policy for Office applications.
C. Configure an endpoint detection and response (EDR) policy.
D. Create an attack surface reduction (ASR) policy.
Show Answer
Correct Answer: D
Explanation:
The Secure Score recommendation to block Microsoft Office applications from creating child processes corresponds to an Attack Surface Reduction (ASR) rule in Microsoft Defender for Endpoint. Creating and deploying an ASR policy enables the specific rule 'Block all Office applications from creating child processes,' which directly addresses the recommendation and increases the Secure Score.

Question 112

You have a Microsoft 365 E5 subscription. You need to use Microsoft Defender for Cloud Apps to monitor user mailbox activities. What should you do?

A. Create an activity policy.
B. Create an access policy.
C. Enable mailbox audit logging.
D. Create an app connector for Microsoft 365.
Show Answer
Correct Answer: C
Explanation:
To monitor user mailbox activities in Microsoft Defender for Cloud Apps, the underlying data source must be available. Defender for Cloud Apps relies on Exchange Online mailbox audit logs to capture mailbox actions (such as message access, delete, or move). Therefore, mailbox audit logging must be enabled before mailbox activities can be monitored. Creating activity or access policies only generates alerts after data is available, and Microsoft 365 is already natively connected without requiring an app connector.

Question 113

You have a Microsoft 365 E5 subscription. You plan to create an anti-malware policy named Policy1. You need to ensure that Policy1 can detect malicious email messages that were already delivered to a user's mailbox. What should you do in the Microsoft Defender portal?

A. Enable zero-hour auto purge (ZAP).
B. Enable enhanced filtering.
C. Configure a quarantine policy.
D. Modify the common attachments filter.
Show Answer
Correct Answer: A
Explanation:
Zero-hour auto purge (ZAP) enables Microsoft Defender for Office 365 to retroactively detect and remove malicious emails that were already delivered to user mailboxes when new threat intelligence becomes available. This directly meets the requirement to detect (and act on) malicious messages after delivery. The other options do not provide post-delivery detection and remediation.

Question 114

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. The subscription contains users that have Windows 11 devices. You need to use the Cloud Discovery snapshot report to analyze cloud app usage on the devices. What should you do before generating a report?

A. Create an activity policy.
B. Deploy the Azure Monitor Agent on the devices.
C. Export traffic logs from firewalls and proxies.
D. Create an app discovery policy.
Show Answer
Correct Answer: C
Explanation:
The Cloud Discovery snapshot report in Microsoft Defender for Cloud Apps is generated by uploading or ingesting network traffic logs. Before you can analyze cloud app usage, you must export traffic logs from firewalls or proxy devices (or equivalent network sources). The other options relate to policies or agents that are not required for snapshot-based Cloud Discovery.

Question 115

HOTSPOT - You have an Azure subscription. You have a Microsoft 365 E5 subscription. You are licensed to use Microsoft Defender XDR. You need to monitor activities from suspicious IP addresses and unusual administrative activities in Azure. What should you use to monitor the activities, and what should you use to integrate Azure with Microsoft Defender XDR? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 115
Show Answer
Correct Answer: Monitor: Microsoft Defender for Cloud Apps Integrate: A directory services account
Explanation:
Microsoft Defender for Cloud Apps provides built-in anomaly detection for Azure activities, including suspicious IP addresses and unusual administrative actions. Integration of Azure with Microsoft Defender XDR for this monitoring scenario is done by configuring a directory services account, which enables visibility into Azure activity logs and identity-related actions.

Question 116

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Endpoint. You integrate Microsoft Defender for Endpoint with Microsoft Intune. From Microsoft Defender Vulnerability Management, you review the top security recommendations and discover a recommendation to update Microsoft Edge (Chromium) to a later version. You need to ensure that a security task is added to Intune to address the recommendation. What should you do?

A. From the Microsoft Intune admin center, configure Windows Autopatch.
B. From the Microsoft Intune admin center, configure a security baseline.
C. From the Microsoft Defender portal, select Request remediation.
D. From the Microsoft Defender portal add an incident notification rule.
Show Answer
Correct Answer: C
Explanation:
Microsoft Defender Vulnerability Management integrates with Intune to create remediation tasks. From the Microsoft Defender portal, using **Request remediation** on a security recommendation (such as updating Microsoft Edge) creates a security task in Intune to address the issue. Other options do not create remediation tasks directly from Defender recommendations.

Question 117

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. From Policy management, you open Information protection as shown in the following exhibit. Which type of policy can you create?

A. session policy
B. activity policy
C. OAuth app policy
D. access policy
E. file policy
Show Answer
Correct Answer: E
Explanation:
In Microsoft Defender for Cloud Apps, the **Information protection** section of Policy management is specifically used to create **file policies**. Other policy types (session, activity, OAuth app, access) belong to Conditional access or Threat detection categories, not Information protection.

Question 118

You have a Microsoft 365 E5 subscription that includes Microsoft Intune. You manage all iOS devices by using Intune. You plan to protect corporate-owned iOS devices by using Microsoft Defender for Endpoint. You configure a connection between Intune and Defender for Endpoint. You need to onboard the devices to Defender for Endpoint. What should you do?

A. Download an onboarding package.
B. Create an app protection policy.
C. Enable Microsoft Defender for Cloud.
D. Add an app to Intune.
Show Answer
Correct Answer: D
Explanation:
For iOS devices managed by Intune, onboarding to Microsoft Defender for Endpoint is done by deploying the Microsoft Defender for Endpoint iOS app through Intune. There is no onboarding package for iOS like there is for Windows or macOS. App protection policies apply to unmanaged (MAM) scenarios, and Defender for Cloud is unrelated. Therefore, you must add and deploy the Defender app in Intune.

$19

Get all 417 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.