Microsoft

MS-102 Free Practice Questions — Page 14

Question 130

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. You register a cloud app named App1 in Microsoft Entra ID. You need to create an access policy for App1. What should you do first?

A. Deploy Conditional Access App Control to App1.
B. Create an app tag for App1.
C. Add a security information and event management (SIEM) agent to Defender for Cloud Apps.
D. Configure an app connector to Defender for Cloud Apps.
Show Answer
Correct Answer: A
Explanation:
Access policies in Microsoft Defender for Cloud Apps are enforced through Conditional Access App Control (reverse proxy). Before you can create and apply an access policy for an Entra ID–registered app, you must first deploy Conditional Access App Control for that app via a Conditional Access policy. App connectors are API-based integrations for supported SaaS apps and are not required to create access policies.

Question 131

HOTSPOT - You have a Microsoft 365 E5 subscription. You plan to use Microsoft Graph PowerShell to perform the following tasks: • Change the Company name property for all users. • Create new Microsoft 365 groups. Which PowerShell cmdlet should you run? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 131
Show Answer
Correct Answer: To change the property: Update-MgUser To create the groups: New-MgGroup
Explanation:
CompanyName is updated on user objects using the Microsoft Graph Users module via Update-MgUser. Microsoft 365 (Unified) groups are created with New-MgGroup by specifying GroupTypes "Unified" along with mail and security settings.

Question 132

You have a Microsoft 365 E5 subscription. You create a user named Admin1. You need to ensure that Admin1 can view Endpoint security policies from the Microsoft Defender portal. The solution must follow the principle of least privilege. Which Microsoft Entra role should you assign to Admin1?

A. Cloud Device Administrator
B. Security Reader
C. Global Reader
D. Security Administrator
E. Security Operator
Show Answer
Correct Answer: B
Explanation:
Viewing Endpoint security policies in the Microsoft Defender portal requires read-only access to security data. The Security Reader role provides visibility into security information, alerts, and policies without granting modification rights. This satisfies the requirement and adheres to the principle of least privilege. Other roles either grant broader permissions than necessary or focus on device or operational management.

Question 133

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the users shown in the following table. The subscription contains the groups shown in the following table. Which users and groups can you delete? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 133 Illustration for MS-102 question 133 Illustration for MS-102 question 133
Show Answer
Correct Answer: Users: User1, User2, User3, and User4 Groups: Group1 and Group3 only
Explanation:
Users can be deleted regardless of license assignment or group membership. Groups with active licenses assigned cannot be deleted. Group2 and Group4 have licenses, so they cannot be deleted. Group1 and Group3 have no licenses assigned and can be deleted, even if they participate in group nesting.

Question 134

You have a Microsoft 365 E5 subscription. You create the users shown in the following table. You plan to use Microsoft Entra ID Protection. Which users will be added automatically to the User at risk detected alerts list?

A. Admin1 only
B. Admin2 only
C. Admin1 and Admin2 only
D. Admin1 and Admin3 only
E. Admin1, Admin2, and Admin3
Show Answer
Correct Answer: D
Explanation:
In Microsoft Entra ID Protection, users are automatically added to the **User at risk detected alerts** list only if they are actively assigned one of the following roles: **Global Administrator, Security Administrator, or Security Reader**, and have a valid email or alternate email configured. From the scenario, **Admin1** and **Admin3** hold qualifying roles, while **Admin2** is a Security Operator, which is *not* included in the automatic alerting scope. Therefore, only Admin1 and Admin3 are added automatically.

Question 135

HOTSPOT - You have a Microsoft 365 E5 subscription. You are investigating a suspicious email message that generated alerts in the Microsoft Defender portal. You need to examine the email message header and submit the message to Microsoft for review. Which two settings should you use? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 135
Show Answer
Correct Answer: Email preview Take action
Explanation:
Email preview is used to open the message and view the full email headers. Take action provides the option to submit the message to Microsoft for review and analysis.

Question 136

You have a Microsoft 365 E5 subscription. You plan to implement an authentication policy that will user FIDO2 security key as a user authentication method. You need to ensure that during enrollment, each FIDO2 security key is verified by using the FIDO Alliance Metadata Service. Which setting should you enable?

A. Allow self-service setup
B. Restrict specific keys
C. Enforce attestation
D. Enforce key restrictions
Show Answer
Correct Answer: C
Explanation:
To ensure each FIDO2 security key is verified during enrollment using the FIDO Alliance Metadata Service, you must enable **Enforce attestation**. This setting requires that the security key’s attestation data be validated against metadata published in the FIDO Alliance Metadata Service, confirming the key model is genuine and from a trusted vendor.

Question 137

Your company has a Microsoft Entra tenant named contoso.com and a Microsoft 365 subscription. All users use Windows 10 devices to access Microsoft Office 365 apps. All the devices are in a workgroup. You plan to implement password less sign-in to contoso.com. You need to recommend changes to the infrastructure for the planned implementation. What should you include in the recommendation?

A. Join all the devices to contoso.com.
B. Deploy Microsoft Entra Application Proxy.
C. Deploy the Microsoft Entra Connect provisioning agent.
D. Deploy the Microsoft Authenticator app.
Show Answer
Correct Answer: A
Explanation:
To implement passwordless sign-in on Windows 10 devices for Microsoft Entra ID, the devices must be joined to the Entra tenant to support Windows-based passwordless methods such as Windows Hello for Business. The other options do not enable passwordless sign-in for Windows devices at the infrastructure level.

Question 138

You have a Microsoft 365 E5 subscription. You plan to use Microsoft Entra ID Protection. You need to ensure that account passwords must be changed if account credentials are leaked. What should you configure?

A. a user risk policy
B. Password protection
C. a sign-in risk policy
D. self-service password reset (SSPR)
Show Answer
Correct Answer: A
Explanation:
Leaked credentials are evaluated as **user risk** in Microsoft Entra ID Protection. A **user risk policy** can be configured to require a **password change** when the user risk level is detected as high, ensuring compromised credentials are remediated. Sign-in risk policies focus on MFA or access controls for risky sign-ins, not mandatory password changes, and the other options do not address leaked credentials enforcement.

Question 139

You have a Microsoft 365 E5 subscription. You are creating a data loss prevention (DLP) policy applied to the locations as shown in the following exhibit. Which condition can you use in the DLP rules of the policy?

A. sensitive info types
B. sensitivity labels
C. keywords
D. content search queries
Show Answer
Correct Answer: A
Explanation:
In Microsoft Purview DLP policies, rule conditions are based on content inspection such as Sensitive Information Types (SITs), which detect patterns like credit card or ID numbers. Sensitivity labels are applied metadata and are not selectable as DLP rule conditions for the specified locations, and content search queries are not supported in DLP rules. Therefore, Sensitive Information Types is the valid condition.

$19

Get all 417 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.