Microsoft

MS-102 Free Practice Questions — Page 15

Question 143

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. You register a cloud app named App1 in Microsoft Entra ID. You need to create an access policy for App1. What should you do first?

A. Deploy Conditional Access App Control to App1.
B. Create an app tag for App1.
C. Add a security information and event management (SIEM) agent to Defender for Cloud Apps.
D. Configure an app connector to Defender for Cloud Apps.
Show Answer
Correct Answer: A
Explanation:
Access policies in Microsoft Defender for Cloud Apps are part of Conditional Access App Control (reverse proxy). Before you can create and enforce an access policy for an app, the app must be onboarded to Conditional Access App Control via a Microsoft Entra Conditional Access policy. App connectors are for API-based integration and are not the prerequisite for access policies. Sources: https://learn.microsoft.com/en-us/defender-cloud-apps/proxy-intro-aad

Question 144

HOTSPOT - You have a Microsoft 365 E5 subscription. You plan to use Microsoft Graph PowerShell to perform the following tasks: • Change the Company name property for all users. • Create new Microsoft 365 groups. Which PowerShell cmdlet should you run? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 144
Show Answer
Correct Answer: To change the property: Update-MgUser To create the groups: New-MgGroup
Explanation:
In Microsoft Graph PowerShell, Update-MgUser modifies user properties such as CompanyName. Microsoft 365 (Unified) groups are created with New-MgGroup by specifying GroupTypes 'Unified' and the appropriate mail/security settings.

Question 145

You have a Microsoft 365 E5 subscription. You create a user named Admin1. You need to ensure that Admin1 can view Endpoint security policies from the Microsoft Defender portal. The solution must follow the principle of least privilege. Which Microsoft Entra role should you assign to Admin1?

A. Cloud Device Administrator
B. Security Reader
C. Global Reader
D. Security Administrator
E. Security Operator
Show Answer
Correct Answer: B
Explanation:
The Security Reader Microsoft Entra role provides read-only access to security-related features, including viewing security information in Microsoft Defender portals. Because the requirement is only to view Endpoint security policies and to follow the principle of least privilege, Security Reader is the appropriate role. Security Administrator and Security Operator grant broader permissions than necessary, while Cloud Device Administrator and Global Reader are not the least-privileged fit for this security-specific task.

Question 146

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the users shown in the following table. The subscription contains the groups shown in the following table. Which users and groups can you delete? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 146 Illustration for MS-102 question 146 Illustration for MS-102 question 146
Show Answer
Correct Answer: Users: User1, User2, User3, and User4 Groups: Group1 only
Explanation:
User accounts can be deleted even if they have directly assigned or inherited licenses. Groups with an active license assignment cannot be deleted until the license is removed. Group2 and Group4 are licensed; Group3 is a member of licensed Group4 and cannot be selected here because the only valid deletable option provided is Group1.

Question 147

You have a Microsoft 365 E5 subscription. You create the users shown in the following table. You plan to use Microsoft Entra ID Protection. Which users will be added automatically to the User at risk detected alerts list?

A. Admin1 only
B. Admin2 only
C. Admin1 and Admin2 only
D. Admin1 and Admin3 only
E. Admin1, Admin2, and Admin3
Show Answer
Correct Answer: D
Explanation:
Microsoft Entra ID Protection automatically adds users who are actively assigned the Global Administrator, Security Administrator, or Security Reader roles to the 'User at risk detected alerts' notification list (provided they have a valid email or alternate email). The Security Operator role is not included. Therefore, assuming Admin1 is Global Administrator, Admin2 is Security Operator, and Admin3 is Security Reader, the users added automatically are Admin1 and Admin3.

Question 148

HOTSPOT - You have a Microsoft 365 E5 subscription. You are investigating a suspicious email message that generated alerts in the Microsoft Defender portal. You need to examine the email message header and submit the message to Microsoft for review. Which two settings should you use? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 148
Show Answer
Correct Answer: Email preview Take action
Explanation:
Use Email preview to inspect the message, including the full email headers. Use Take action to submit the message to Microsoft for review/analysis.

Question 149

You have a Microsoft 365 E5 subscription. You plan to implement an authentication policy that will user FIDO2 security key as a user authentication method. You need to ensure that during enrollment, each FIDO2 security key is verified by using the FIDO Alliance Metadata Service. Which setting should you enable?

A. Allow self-service setup
B. Restrict specific keys
C. Enforce attestation
D. Enforce key restrictions
Show Answer
Correct Answer: C
Explanation:
Enabling 'Enforce attestation' requires attestation during FIDO2 security key enrollment. Microsoft Entra ID verifies supported FIDO2 security keys using metadata published through the FIDO Alliance Metadata Service, ensuring the key model is genuine and trusted.

Question 150

Your company has a Microsoft Entra tenant named contoso.com and a Microsoft 365 subscription. All users use Windows 10 devices to access Microsoft Office 365 apps. All the devices are in a workgroup. You plan to implement password less sign-in to contoso.com. You need to recommend changes to the infrastructure for the planned implementation. What should you include in the recommendation?

A. Join all the devices to contoso.com.
B. Deploy Microsoft Entra Application Proxy.
C. Deploy the Microsoft Entra Connect provisioning agent.
D. Deploy the Microsoft Authenticator app.
Show Answer
Correct Answer: D
Explanation:
Microsoft Entra passwordless sign-in methods include the Microsoft Authenticator app, FIDO2 security keys, and Windows Hello for Business. For users on workgroup Windows 10 devices accessing Microsoft 365 apps, deploying the Microsoft Authenticator app enables passwordless authentication without requiring devices to be joined to Microsoft Entra. The other options (Application Proxy, Entra Connect provisioning agent) are unrelated, and joining devices is not a prerequisite for using Microsoft Authenticator passwordless sign-in to Microsoft 365.

Question 151

You have a Microsoft 365 E5 subscription. You plan to use Microsoft Entra ID Protection. You need to ensure that account passwords must be changed if account credentials are leaked. What should you configure?

A. a user risk policy
B. Password protection
C. a sign-in risk policy
D. self-service password reset (SSPR)
Show Answer
Correct Answer: A
Explanation:
A user risk policy in Microsoft Entra ID Protection evaluates the likelihood that a user's credentials have been compromised (including leaked credentials). The policy can be configured to require a secure password change when user risk reaches the configured threshold. Password protection only blocks weak/banned passwords, sign-in risk policy addresses risky sign-ins (typically requiring MFA), and SSPR enables password reset but does not itself enforce password changes based on leaked credentials.

Question 152

You have a Microsoft 365 E5 subscription. You are creating a data loss prevention (DLP) policy applied to the locations as shown in the following exhibit. Which condition can you use in the DLP rules of the policy?

A. sensitive info types
B. sensitivity labels
C. keywords
D. content search queries
Show Answer
Correct Answer: A
Explanation:
The applicable DLP rule condition is Sensitive info types. Microsoft Purview DLP rules commonly use sensitive information types to detect data such as credit card numbers, passport numbers, and other regulated identifiers. Sensitivity labels are generally actions or conditions only in specific policy scenarios, but for the described DLP policy condition options, the supported rule condition is Sensitive info types. Keywords and content search queries are not standard DLP rule conditions.

$19

Get all 430 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.