Microsoft

MS-102 Free Practice Questions — Page 12

Question 113

You have a Microsoft 365 E5 subscription that contains a user named User1. You create an outbound anti-spam policy named Policy1 as shown in the following exhibit. You assign Policy1 to User1. What is the maximum number of email messages that User1 can send in a 24-hour period?

A. 30
B. 720
C. 1000
D. 1030
Show Answer
Correct Answer: B
Explanation:
The configured outbound anti-spam policy enforces separate hourly recipient limits (10 external recipients/hour and 20 internal recipients/hour) plus a daily recipient limit of 1000. The hourly limits are the constraining factor: at most 30 recipients per hour (10 external + 20 internal). Over 24 hours, that yields a maximum of 30 × 24 = 720 recipients/messages, which is below the daily limit of 1000.

Question 114

You have a Microsoft 365 E5 subscription that contains devices onboarded to Microsoft Defender for Endpoint. You integrate Microsoft Defender for Cloud Apps with Defender for Endpoint. You need identify which cloud apps and services were used most during the last 30 days. What should you do?

A. Generate a monthly security summary report.
B. Generate a Cloud Discovery snapshot report.
C. Create a threat analytics alert notification.
D. Generate a Cloud Discovery executive report.
Show Answer
Correct Answer: D
Explanation:
With Microsoft Defender for Endpoint integrated into Microsoft Defender for Cloud Apps, Cloud Discovery continuously collects endpoint telemetry. To identify the cloud apps and services used most over a recent period such as the last 30 days, the Cloud Discovery executive report provides a high-level summary of discovered cloud app usage and trends. A snapshot report is intended for ad hoc analysis of manually uploaded firewall/proxy logs rather than the integrated continuous discovery scenario described.

Question 115

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. From Automatic remediation in the Microsoft Defender portal, you set Automation level to Semi – require approval for non-temp folders for the endpoints. You need to identify the impact of the Automation level setting on the endpoints. Which two actions will occur based on the remediation settings? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

A. Devices will be remediated only after end-user approval.
B. Devices will be remediated automatically if a threat is detected in the \program files (X86)\* folder
C. Devices will be remediated automatically if a threat is detected in the \windows\ folder.
D. Devices will be remediated automatically if a threat is detected in the \users\*\downloads\* folder.
Show Answer
Correct Answer: B, D
Explanation:
With the automation level set to 'Semi – require approval for non-temp folders', remediation is automatic for locations Microsoft classifies as temporary folders and requires approval for non-temporary folders. Microsoft explicitly includes \Program Files (x86)\* and \Users\*\Downloads\* in the temporary-folder examples for this automation level, whereas the option refers to \Windows\ (not \Windows\Temp\), which is not automatically remediated under this setting. End-user approval is not how this feature works; approvals are handled through the Action Center.

Question 116

You have a Microsoft 365 E5 subscription. You plan to ingest syslog data from a supported firewall device to Microsoft Defender for Cloud Apps. You need to configure automatic log upload. Which two components should you configure for the log collector? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

A. the receiver type
B. the data source
C. the username and password
D. a connection string
E. the host IP address or FQDN
Show Answer
Correct Answer: B, E
Explanation:
To configure automatic log upload for Microsoft Defender for Cloud Apps, you first configure a data source (which includes settings such as the receiver type), and then configure the log collector with its host IP address or FQDN and associate it with the data source. Receiver type is a property within the data source configuration rather than a separate log collector component, so the complete configuration components are the data source and the host IP address/FQDN.

Question 117

HOTSPOT - You have a Microsoft Entra tenant that has security defaults enabled. You create a user named Admin1. You need to ensure that Admin1 can create and apply Conditional Access policies. Which two settings should you configure? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 117
Show Answer
Correct Answer: Roles and administrators Properties
Explanation:
Assign Admin1 the Conditional Access Administrator (or Global Administrator) role under Roles and administrators. Because security defaults are enabled, disable Security defaults from the tenant Properties page before Conditional Access policies can be created and used.

Question 118

You have a Microsoft 365 subscription and use Microsoft Defender for Office 365. You need to create a policy to ensure that any email messages containing an attachment that has the .extl extension is quarantined for inspection. Which type of policy should you create?

A. anti-phishing
B. quarantine
C. anti-spam
D. anti-malware
Show Answer
Correct Answer: D
Explanation:
An anti-malware policy in Microsoft Defender for Office 365 can be configured to detect specific attachment file types/extensions and take actions such as quarantining the message. A quarantine policy only defines how quarantined messages are handled after they are quarantined; it does not determine which messages are quarantined. Anti-phishing and anti-spam policies are not used to block specific attachment extensions.

Question 119

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription. You integrate Microsoft Defender for Endpoint with Microsoft Intune. You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune. Solution: You configure a compliance policy. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
No. A compliance policy does not automatically onboard devices to Microsoft Defender for Endpoint. Automatic onboarding for Intune-enrolled devices is configured by deploying a Microsoft Defender for Endpoint Endpoint Detection and Response (EDR) policy (or the appropriate Defender onboarding profile) in Intune. Compliance policies evaluate device compliance; they do not perform Defender onboarding. Sources: https://www.secexams.com/exams/Microsoft/md-102/view/34 https://www.pass4success.com/microsoft/discussions/exam-ms-102-topic-1-question-7-discussion

Question 120

You have a Microsoft 365 E5 subscription. You need to assign a Microsoft Defender for Endpoint baseline. Which portal should you use?

A. the Microsoft Intune admin center
B. the Microsoft Purview compliance portal
C. the Microsoft Defender portal
D. the Microsoft 365 admin center
Show Answer
Correct Answer: A
Explanation:
Microsoft Defender for Endpoint security baselines are assigned through Microsoft Intune. In the Intune admin center, go to Endpoint security > Security baselines and create or assign the Microsoft Defender for Endpoint baseline to device groups. The Defender portal is used for endpoint protection management, but baseline assignment is an Intune feature.

Question 121

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription. You integrate Microsoft Defender for Endpoint with Microsoft Intune. You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune. Solution: You enable co-management. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
Enabling co-management does not automatically onboard Intune-enrolled devices to Microsoft Defender for Endpoint. Co-management is for shared management between Configuration Manager and Intune. Automatic onboarding is achieved by configuring the Microsoft Defender for Endpoint (Endpoint detection and response) onboarding policy in Intune (or the Defender connector/settings), not by enabling co-management alone.

Question 122

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription. You integrate Microsoft Defender for Endpoint with Microsoft Intune. You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune. Solution: You create an endpoint detection and response (EDR) policy. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: A
Explanation:
Yes. After Microsoft Defender for Endpoint is integrated with Microsoft Intune, creating an Endpoint detection and response (EDR) policy in Intune can automatically onboard enrolled Windows devices to Defender for Endpoint. This satisfies the goal of automatic onboarding during Intune enrollment.

$19

Get all 430 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.