Microsoft

MS-102 Free Practice Questions — Page 17

Question 163

HOTSPOT - You have a Microsoft 365 E5 subscription. You need to configure Privileged Identity Management (PIM) for the User Administrator role in Microsoft Entra. Eligible users must meet the following requirements: • Always be able to request the User Administrator role • Must provide a reason when requesting the User Administrator role • Must require multi-factor authentication (MFA) when activating the User Administrator role The solution must minimize administrative effort. How should you configure the Role settings for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 163
Show Answer
Correct Answer: Set Allow permanent eligible assignment to yes. Select Require justification on activation. Set On activation require to Azure MFA.
Explanation:
Permanent eligible assignment lets eligible users always activate/request the role. Requiring justification on activation enforces a reason. Requiring Azure MFA on activation enforces MFA when activating the eligible role.

Question 164

Your network contains an Active Directory domain named adatum.com that is synced to a Microsoft Entra tenant. The domain contains 100 user accounts. The city attribute for all the users is set to the city where the user resides. You need to modify the value of the city attribute to the three-letter airport code of each city. What should you do?

A. From Windows PowerShell on a domain controller, run the Get-ADUser and Set-ADUser cmdlets.
B. From Azure Cloud Shell, run the Get-MgUser and Update-MgUser cmdlets.
C. From the Microsoft Entra admin center, select all the Microsoft Entra users, and then use the User settings blade.
D. From the Microsoft 365 admin center, select the users, and then use the Bulk actions option.
Show Answer
Correct Answer: A
Explanation:
The users are synchronized from on-premises Active Directory to Microsoft Entra ID. For synchronized objects, authoritative attributes such as the city attribute must be changed in the on-premises Active Directory and then synchronized to Microsoft Entra. Using the Active Directory PowerShell cmdlets (Get-ADUser and Set-ADUser) is the appropriate way to bulk update the attribute.

Question 165

You have a Microsoft 365 E5 subscription. From the Microsoft 365 Defender portal, you review your company’s Microsoft Secure Score. You discover a large number of recommended actions. You need to ensure that the actions can be filtered based on specific department names. What should you create first?

A. a dynamic security group
B. a tag
C. an administrative unit
D. a custom detection rule
Show Answer
Correct Answer: B
Explanation:
The correct answer is B. In Microsoft 365 Defender Secure Score, tags can be created and applied to recommended actions, allowing those actions to be filtered by tag. To filter recommendations based on department names, you would first create tags representing those departments. Dynamic security groups and administrative units do not provide Secure Score recommendation filtering, and custom detection rules are unrelated to Secure Score recommendations.

Question 166

HOTSPOT - You have a Microsoft 365 E5 subscription. You need to create a Conditional Access policy that will require the use of FIDO2 security keys only when users join their Windows devices to Microsoft Entra ID. How should you configure the policy? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 166
Show Answer
Correct Answer: Target resources: User actions Conditions: Device platforms Grant access: Require authentication strength
Explanation:
Target the Register or join devices user action, scope the policy to Windows device platforms, and use an authentication strength that allows only FIDO2 security keys.

Question 167

HOTSPOT - You have a Microsoft 365 subscription. You plan to update the EmployeeType attribute for all the users in a group named Contractors. You retrieve the GroupId value of the Contractors group. You need to use Microsoft Graph PowerShell to retrieve all the Contractors group users and set their EmployeeType attribute to Part-time. How should you complete the PowerShell script? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 167
Show Answer
Correct Answer: Get-MgGroupMember Update-MgUser -UserId
Explanation:
Use Microsoft Graph PowerShell. Retrieve group members with Get-MgGroupMember, then update each user with Update-MgUser using the -UserId parameter to set EmployeeType.

Question 168

HOTSPOT - You have a Microsoft 365 subscription that contains two administrative units named AU1 and AU2. The subscription contains the users shown in the following table. The subscription contains the groups shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 168 Illustration for MS-102 question 168 Illustration for MS-102 question 168
Show Answer
Correct Answer: No Yes Yes
Explanation:
User1 is a User Administrator scoped to AU1 and cannot reset the password of a Global Administrator. User2 is a Global Administrator with tenant-wide permissions, so can manage Group1. User3 is a non-admin user in AU1, so User1 can reset User3's password.

Question 169

HOTSPOT - You have a Microsoft 365 subscription. You need to identify all users that have an Enterprise Mobility + Security plan, and then provide a list of the users in the CSV format. Which settings should you use in the Microsoft 365 admin center, and which option should you select? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 169
Show Answer
Correct Answer: Settings: Licenses Option: Export users
Explanation:
Go to Licenses, select the Enterprise Mobility + Security license, then export the assigned users as a CSV.

Question 170

You have two Microsoft 365 tenants. Users have accounts in both tenants. You plan to deploy a single device to each user. Each device will contain the Microsoft Authenticator app. You need to ensure that the users can use their device to authenticate to both tenants by using passwordless authentication. Which platform should you provide?

A. iOS
B. Android
C. Windows
D. macOS
Show Answer
Correct Answer: B
Explanation:
For passwordless phone sign-in using Microsoft Authenticator across two Microsoft 365 (Microsoft Entra ID) tenants on the same device, Android supports multiple passwordless phone sign-in accounts. Windows and macOS are not applicable because they do not use the Authenticator app for this scenario. Earlier documentation distinguished Android from iOS for multi-account passwordless phone sign-in; although newer platform capabilities have evolved, the exam objective aligns with Android.

Question 171

HOTSPOT - You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Office 365. You need to automate Attack simulation training for users when a phishing campaign is detected in real-time. Which type of automation should you use, and which condition should you configure for the Attack simulation training? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 171
Show Answer
Correct Answer: Automation type: Randomized simulation automation Condition: Credential Harvest
Explanation:
Randomized simulation automations are triggered by real-time phishing detections in Microsoft Defender for Office 365. Configure the automation for the Credential Harvest phishing technique to automatically assign relevant simulation training when that type of campaign is detected.

Question 172

You have a Microsoft 365 subscription that uses Microsoft 365 Defender. You need to compare your company's security configurations to Microsoft best practices and review improvement actions to increase the security posture. What should you use?

A. Microsoft Secure Score
B. Cloud discovery
C. Exposure distribution
D. Threat tracker
E. Exposure score
Show Answer
Correct Answer: A
Explanation:
Microsoft Secure Score is the Microsoft 365 Defender feature that compares an organization's security configuration against Microsoft-recommended best practices and provides improvement actions to strengthen the overall security posture. Cloud discovery identifies cloud app usage, Threat tracker monitors emerging threats, Exposure score measures exposure, and Exposure distribution visualizes exposure across assets rather than providing best-practice configuration recommendations.

$19

Get all 430 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.