Microsoft

MS-102 Free Practice Questions — Page 14

Question 133

You have a Microsoft 365 E5 subscription. Administrators are issued FIDO2 security keys. You need to create a Conditional Access policy that will use a FIDO2 security key as an authentication method. Which Access controls option should you select for the policy?

A. Require approved client app
B. Require token protection for sign-in sessions
C. Require multifactor authentication
D. Require authentication strength
Show Answer
Correct Answer: D
Explanation:
Use the Conditional Access grant control 'Require authentication strength' to require specific phishing-resistant authentication methods such as FIDO2 security keys. 'Require multifactor authentication' only enforces MFA generally and does not guarantee use of FIDO2. The other options are unrelated to selecting a specific authentication method.

Question 134

You have a Microsoft 365 E5 subscription. You plan to use a third-party protection service to scan email messages before they are delivered to Microsoft 365. You configure a mail flow rule to bypass spam filtering for incoming messages. Which two messages will still be scanned by Microsoft 365 and cannot be bypassed by the mail flow rule? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

A. a message that contains malware
B. a high-confidence phishing message
C. an encrypted message
D. a message that includes HTML code
E. a messages that includes URL links
Show Answer
Correct Answer: A, B
Explanation:
The correct answers are A and B. Microsoft 365 mail flow rules can be used to bypass spam filtering for specific messages, but Secure by Default protections cannot be overridden for malware or high-confidence phishing. Messages containing malware and messages identified as high-confidence phishing are still inspected and acted upon even when a mail flow rule attempts to bypass spam filtering. Encrypted messages, HTML content, and URL links are not inherently exempt from the bypass rule; they are evaluated based on their actual threat content rather than their format.

Question 135

You have a Microsoft 365 E5 subscription. The subscription contains users that have the following types of devices: • Windows 10 • Android • iOS To which devices can you apply Endpoint DLP policies?

A. Windows 10 only
B. Windows 10 and Android only
C. Windows 10 and iOS only
D. Windows 10, Android, and iOS
Show Answer
Correct Answer: A
Explanation:
Endpoint Data Loss Prevention (Endpoint DLP) in Microsoft Purview supports onboarded Windows 10/11 devices (and macOS, which is not listed as an option). It does not apply Endpoint DLP policies to Android or iOS devices. Therefore, among the listed device types, only Windows 10 is supported.

Question 136

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Endpoint. Defender for Endpoint has tamper protection enabled. You have a device named Device1 that is onboarded to Defender for Endpoint. You need to configure antivirus and real-time protection for Device1. What should you do in the Microsoft Defender portal?

A. Initiate a live response session.
B. Create a device group.
C. Enable troubleshooting mode.
D. Isolate Device1.
Show Answer
Correct Answer: C
Explanation:
With tamper protection enabled, Microsoft Defender Antivirus settings such as real-time protection cannot be modified through normal means. Troubleshooting mode temporarily relaxes tamper protection on the specific device so authorized administrators can change antivirus and real-time protection settings for troubleshooting. Creating a device group only affects RBAC and remediation scoping, live response is for investigation/response, and device isolation is a containment action, not a configuration method.

Question 137

You have a Microsoft 365 E5 subscription. You plan to configure multi-factor authentication (MFA). You need to select an authentication method for users. The solution must ensure that each time a user is prompted for MFA, the application name that requires MFA is provided. What should you select?

A. SMS
B. Microsoft Authenticator
C. a voice call
D. email OTP
E. a FIDO2 security key
Show Answer
Correct Answer: B
Explanation:
Microsoft Authenticator supports push notifications with additional context, including displaying the application name that is requesting MFA when the feature is enabled in Microsoft Entra ID. SMS, voice calls, email OTP, and FIDO2 security keys do not provide the application name in the MFA prompt.

Question 138

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the users shown in the following table. You configure a Multifactor authentication registration policy that has the following settings: • Assignments: o Include: Group1 o Exclude: Group2 • Controls: Require Microsoft Entra ID multifactor authentication registration • Policy enforcement: Enabled You create a conditional access policy that has the following settings: • Name: Policy1 • Assignments: o Include: Group2 o Exclude: Group1 • Grant: Require multifactor authentication • Enable policy: On For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 138 Illustration for MS-102 question 138
Show Answer
Correct Answer: User1: No User2: No User3: Yes
Explanation:
The MFA registration policy applies to Group1 but excludes Group2, so User2 is excluded and User3 is out of scope. User1 is only subject to the registration campaign and can defer registration if MFA is not otherwise required. The Conditional Access policy applies to Group2 excluding Group1, so User3 is required to satisfy MFA at sign-in; if not registered, the registration flow is triggered.

Question 139

You use Microsoft Defender for Office 365. You plan to automate an attack simulation campaign. Any users that fail the simulation must take additional training based on the simulation results. What is the maximum number of days the training will be available to the users after the simulation?

A. 7
B. 15
C. 30
D. 45
Show Answer
Correct Answer: C
Explanation:
In Microsoft Defender for Office 365 Attack Simulation Training, when configuring automated training for users who fail a simulation, the training assignment availability can be set up to a maximum of 30 days after the simulation. Therefore, the maximum training availability is 30 days.

Question 140

HOTSPOT - You have a Microsoft 365 E5 subscription and use Microsoft Defender for Endpoint. The subscription contains the devices shown in the following table. You need to create the Endpoint security policies shown in the following table. To which device can you apply each policy? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 140 Illustration for MS-102 question 140 Illustration for MS-102 question 140
Show Answer
Correct Answer: Policy1: Device1 or Device3 only Policy2: Device1 only
Explanation:
The Endpoint security Antivirus policy supports Windows and Linux (not Android). The Device Control template applies only to Windows devices.

Question 141

HOTSPOT - You have a Microsoft 365 E5 subscription. You need to create a Conditional Access policy named Policy1 that meets the following requirements: • Applies to high-risk users • Requires multifactor authentication (MFA) Which two settings should you configure? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 141
Show Answer
Correct Answer: Conditions: User risk = High Grant: Require multifactor authentication
Explanation:
To target high-risk users in a Conditional Access policy, configure the User risk condition to High. Then, under Grant controls, require multifactor authentication to enforce MFA for those users.

Question 142

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365. You are configuring Attack simulation training that will target all users and use the Credential Harvest social engineering technique. You need to ensure that the simulation sends an email message that contains a custom phishing link and company-based terminology and branding. How should you configure the simulation?

A. Create a Tenant payload.
B. Select a Global payload.
C. Select custom end-user notifications.
D. Create a tenant landing page.
Show Answer
Correct Answer: A
Explanation:
A tenant payload is used to create a custom phishing email payload, including custom phishing links and organization-specific terminology and branding. Global payloads are built-in templates and are not intended for these customizations. Custom end-user notifications are separate notification emails related to simulations or training, not the phishing message itself. A tenant landing page customizes the page shown after a user clicks the link, but does not configure the phishing email content or link.

$19

Get all 430 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.