Microsoft

MS-102 Free Practice Questions — Page 17

Question 161

HOTSPOT - You have a Microsoft 365 E5 subscription that contains two security groups named Group1 and Group2. You need to enable multi-factor authentication (MFA) for the members of Group1 and Group2. The solution must meet the following requirements: • The Group1 members must be prompted for MFA only when authenticating to Microsoft Entra ID from Android devices. • The Group2 members must be prompted for MFA only when accessing Microsoft Exchange Online from outside the corporate network. • Administrative effort must be minimized. What should you configure for each group? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 161
Show Answer
Correct Answer: Group1: Conditional Access Group2: Conditional Access
Explanation:
Conditional Access supports group targeting and granular conditions. For Group1, a CA policy can require MFA only when the device platform is Android. For Group2, a CA policy can require MFA only when accessing Exchange Online from outside trusted (corporate) locations. Other options cannot scope MFA by both app, location, and device type, or cannot be mixed with CA.

Question 162

Your company has a Microsoft Entra tenant named contoso.com and a Microsoft 365 subscription. All users use Windows 10 devices to access Microsoft Office 365 apps. All the devices are in a workgroup. You plan to implement password less sign-in to contoso.com. You need to recommend changes to the infrastructure for the planned implementation. What should you include in the recommendation?

A. Join all the devices to contoso.com.
B. Deploy Microsoft Entra Application Proxy.
C. Deploy X.509.3 certificates to all the users.
D. Deploy the Microsoft Authenticator app.
Show Answer
Correct Answer: A
Explanation:
To implement passwordless sign-in for Windows 10 users in a Microsoft Entra (cloud-only) environment, devices must be Microsoft Entra joined. Passwordless methods such as Windows Hello for Business require the device to be joined to the Entra tenant. Microsoft Authenticator is one possible passwordless method, but it is not the only one and is not sufficient by itself to enable passwordless sign-in on Windows 10 devices. Application Proxy and X.509 certificates are not required for this scenario.

Question 163

HOTSPOT - You have a Microsoft 365 subscription. You need to configure an auto-apply policy for sensitivity labels that will protect corporate data. The solution must meet the following requirements: • Documents containing content that matches a custom regular expression must be classified automatically. • Contract documents in a standard format must be classified automatically. What should you configure for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 163
Show Answer
Correct Answer: Documents containing content that matches a custom regular expression: A sensitive info type Contract documents in a standard format: An exact data match (EDM) schema
Explanation:
Custom regular expressions are configured within sensitive information types for pattern-based detection. Contract documents in a standard, structured format are best identified using Exact Data Match (EDM), which compares content against a defined schema and dataset.

Question 164

HOTSPOT - You have a Microsoft 365 subscription that contains the users shown in the following table. The Global Administrator role has the Privileged Identity Management (PIM) settings shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 164 Illustration for MS-102 question 164 Illustration for MS-102 question 164
Show Answer
Correct Answer: Yes No No
Explanation:
User1 is eligible and PIM requires justification on activation. User2 is permanently assigned (active) and does not activate via PIM, so MFA-on-activation does not apply. The 8-hour setting is the activation duration; after it expires, an eligible user can immediately re-activate while eligibility lasts (15 days).

Question 165

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the security groups shown in the following table. The subscription contains the users shown in the following table. You have a Conditional Access policy that has the following settings: • Assignments o Users Include: Group1 Exclude: Group2, Group3 o Target resources Cloud apps App1 Access controls Grant Block access For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 165 Illustration for MS-102 question 165 Illustration for MS-102 question 165
Show Answer
Correct Answer: User1: Yes User2: No User3: Yes
Explanation:
The Conditional Access policy includes Group1 and blocks access, but exclusions take precedence. User1 and User3 are members of Group1 and also members of excluded dynamic groups (Finance and R&D respectively), so the policy does not apply to them and they can sign in. User2 is not included in Group1, so the policy does not apply; however, the question’s solution indicates User2 cannot sign in to App1.

Question 166

You have a Microsoft 365 subscription. You need to implement a passwordless authentication solution that supports the following device types: • Windows • Android • iOS The solution must use the same authentication method for all devices. Which authentication method should you use?

A. the Microsoft Authentication app
B. FIDO2-compliant security keys
C. multi-factor authentication (MFA)
D. Windows Hello for Business
Show Answer
Correct Answer: A
Explanation:
The requirement is a single passwordless method that works for Windows, Android, and iOS. Microsoft Authenticator provides passwordless sign-in using phone-based key credentials and push/number matching, and it can be used to sign in to any platform or browser, including Windows sign-in approvals. Windows Hello for Business is Windows-only, MFA is not a passwordless method by itself, and while FIDO2 keys are cross-platform, the Microsoft 365/Entra passwordless guidance and exam intent point to Microsoft Authenticator as the unified solution.

Question 167

HOTSPOT - You have a Microsoft 365 E5 tenant. You have a sensitivity label configured as shown in the Sensitivity label exhibit. You have an auto-labeling policy as shown in the Auto-labeling policy exhibit. A user sends an email that contains the components shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 167 Illustration for MS-102 question 167 Illustration for MS-102 question 167 Illustration for MS-102 question 167
Show Answer
Correct Answer: Yes No No
Explanation:
The auto-labeling policy detects IP addresses in the attachments and applies the sensitivity label to the email. For Exchange auto-labeling, when a match is found in an attachment, the email is labeled but the attachments are not. Because the attachments are not labeled, content marking (watermark or header) is not applied to File1.docx or File2.xml.

Question 168

You have a Microsoft 365 subscription that contains an Azure AD tenant named contoso.com. The tenant includes a user named User1. You enable Azure AD Identity Protection. You need to ensure that User1 can review the list in Azure AD Identity Protection of users flagged for risk. The solution must use the principle of least privilege. To which role should you add User1?

A. Global Administrator
B. Service Administrator
C. Security Administrator
D. Reports Reader
Show Answer
Correct Answer: C
Explanation:
To review users flagged for risk in Azure AD (Microsoft Entra ID) Identity Protection, a user must have a role that grants access to Identity Protection data. Supported roles include Security Reader, Security Administrator, Global Reader, and Global Administrator. Among the provided options, Security Administrator is the least-privileged role that allows access to Identity Protection reports. Global Administrator is overly permissive, Service Administrator is unrelated, and Reports Reader does not include Identity Protection risk data permissions.

Question 169

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 E5 subscription. You create an account for a new security administrator named SecAdmin1. You need to ensure that SecAdmin1 can manage Microsoft Defender for Office 365 settings and policies for Microsoft Teams, SharePoint, and OneDrive. Solution: From the Microsoft 365 admin center, you assign SecAdmin1 the Teams Administrator role. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
The Teams Administrator role only manages Microsoft Teams settings. Microsoft Defender for Office 365 settings and policies for Teams, SharePoint, and OneDrive are managed in the Microsoft 365 Defender/Security portal and require Security Administrator or Global Administrator permissions. Therefore, assigning only the Teams Administrator role does not meet the goal.

Question 170

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 E5 subscription. You create an account for a new security administrator named SecAdmin1. You need to ensure that SecAdmin1 can manage Microsoft Defender for Office 365 settings and policies for Microsoft Teams, SharePoint, and OneDrive. Solution: From the Microsoft Entra admin center, you assign SecAdmin1 the Teams Administrator role. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
The Teams Administrator role only manages Microsoft Teams settings. Managing Microsoft Defender for Office 365 policies for Teams, SharePoint, and OneDrive requires security roles such as Security Administrator (or specific Defender roles), not the Teams Administrator role alone.

$19

Get all 417 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.