Microsoft

MS-102 Free Practice Questions — Page 18

Question 173

DRAG DROP - You have an Azure subscription that is linked to a hybrid Microsoft Entra tenant. All users sync from Active Directory Domain Services (AD DS) to the tenant by using Express Settings in Microsoft Entra Connect. You plan to implement self-service password reset (SSPR). You need to ensure that when a user resets or changes a password, the password syncs with AD DS. Which actions should you perform in sequence? To answer, drag the appropriate actions to the correct order. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 173
Show Answer
Correct Answer: Step 1: Select Password writeback in Microsoft Entra Connect. Step 2: From the Microsoft Entra admin center, configure on-premises integration password writeback. Step 3: From the Microsoft Entra admin center, configure the authentication methods for SSPR.
Explanation:
Enable password writeback in Entra Connect first, then enable/configure tenant-side password writeback integration, and finally configure the SSPR authentication methods users will use. Group writeback is unrelated.

Question 174

HOTSPOT - You have a Microsoft 365 E5 subscription that contains two security groups named Group1 and Group2. You need to enable multi-factor authentication (MFA) for the members of Group1 and Group2. The solution must meet the following requirements: • The Group1 members must be prompted for MFA only when authenticating to Microsoft Entra ID from Android devices. • The Group2 members must be prompted for MFA only when accessing Microsoft Exchange Online from outside the corporate network. • Administrative effort must be minimized. What should you configure for each group? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 174
Show Answer
Correct Answer: Group1: Conditional Access Group2: Conditional Access
Explanation:
Conditional Access supports targeting groups and applying MFA based on device platform (Android), cloud app (Exchange Online), and named locations (outside the corporate network). Per-user MFA and Security Defaults cannot provide these granular conditions, and Identity Protection/PIM are not intended for these scenarios.

Question 175

Your company has a Microsoft Entra tenant named contoso.com and a Microsoft 365 subscription. All users use Windows 10 devices to access Microsoft Office 365 apps. All the devices are in a workgroup. You plan to implement password less sign-in to contoso.com. You need to recommend changes to the infrastructure for the planned implementation. What should you include in the recommendation?

A. Join all the devices to contoso.com.
B. Deploy Microsoft Entra Application Proxy.
C. Deploy X.509.3 certificates to all the users.
D. Deploy the Microsoft Authenticator app.
Show Answer
Correct Answer: A
Explanation:
The best recommendation is to Microsoft Entra join (Azure AD join) the Windows 10 devices to the contoso.com tenant. In a cloud-only environment, joining devices to Microsoft Entra enables native passwordless sign-in experiences such as Windows Hello for Business. Microsoft Authenticator is one passwordless method, but deploying it alone is not an infrastructure change and is not required for all passwordless scenarios. Entra Application Proxy is unrelated, and X.509 certificates are not required for this implementation.

Question 176

HOTSPOT - You have a Microsoft 365 subscription. You need to configure an auto-apply policy for sensitivity labels that will protect corporate data. The solution must meet the following requirements: • Documents containing content that matches a custom regular expression must be classified automatically. • Contract documents in a standard format must be classified automatically. What should you configure for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 176
Show Answer
Correct Answer: Documents containing content that matches a custom regular expression: A sensitive info type Contract documents in a standard format: A trainable classifier
Explanation:
Custom regular expressions are implemented with custom Sensitive Information Types (SITs). Trainable classifiers identify document categories such as contracts based on learned content and document characteristics rather than exact pattern matching.

Question 177

HOTSPOT - You have a Microsoft 365 subscription that contains the users shown in the following table. The Global Administrator role has the Privileged Identity Management (PIM) settings shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 177 Illustration for MS-102 question 177 Illustration for MS-102 question 177
Show Answer
Correct Answer: Yes No No
Explanation:
Eligible users must satisfy activation requirements (including justification). Assigned (active) users do not activate the role. The 8-hour setting is the maximum active duration per activation, while eligibility expires after 15 days, so the user can reactivate after the activation ends until eligibility expires.

Question 178

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the security groups shown in the following table. The subscription contains the users shown in the following table. You have a Conditional Access policy that has the following settings: • Assignments o Users Include: Group1 Exclude: Group2, Group3 o Target resources Cloud apps App1 Access controls Grant Block access For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 178 Illustration for MS-102 question 178 Illustration for MS-102 question 178
Show Answer
Correct Answer: Yes Yes Yes
Explanation:
The Conditional Access policy includes Group1 but excludes Group2 and Group3. Exclusions take precedence over inclusions. User1 is excluded via the Finance dynamic group, User3 is excluded via the R&D dynamic group, and User2 is never included, so the blocking policy does not apply to any of them. All can sign in to App1.

Question 179

You have a Microsoft 365 subscription. You need to implement a passwordless authentication solution that supports the following device types: • Windows • Android • iOS The solution must use the same authentication method for all devices. Which authentication method should you use?

A. the Microsoft Authentication app
B. FIDO2-compliant security keys
C. multi-factor authentication (MFA)
D. Windows Hello for Business
Show Answer
Correct Answer: A
Explanation:
Microsoft Authenticator supports Microsoft Entra passwordless sign-in across Windows, Android, and iOS by using the phone as the passwordless credential. Windows Hello for Business is Windows-only, MFA is not inherently passwordless, and FIDO2 keys are cross-platform but this exam objective typically expects the Microsoft Authenticator passwordless phone sign-in method for a single authentication method across these device types.

Question 180

HOTSPOT - You have a Microsoft 365 E5 tenant. You have a sensitivity label configured as shown in the Sensitivity label exhibit. You have an auto-labeling policy as shown in the Auto-labeling policy exhibit. A user sends an email that contains the components shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 180 Illustration for MS-102 question 180 Illustration for MS-102 question 180 Illustration for MS-102 question 180
Show Answer
Correct Answer: Yes No No
Explanation:
Exchange Online auto-labeling scans supported email attachments (such as Office files) for sensitive info. A match in an attachment can label the email, but the attachment itself is not labeled by the Exchange auto-labeling policy. Therefore, the email gets the sensitivity label, while watermark/header content marking is not applied to the attachments.

Question 181

You have a Microsoft 365 subscription that contains an Azure AD tenant named contoso.com. The tenant includes a user named User1. You enable Azure AD Identity Protection. You need to ensure that User1 can review the list in Azure AD Identity Protection of users flagged for risk. The solution must use the principle of least privilege. To which role should you add User1?

A. Global Administrator
B. Service Administrator
C. Security Administrator
D. Reports Reader
Show Answer
Correct Answer: C
Explanation:
To review users flagged for risk in Azure AD Identity Protection, supported roles include Security Reader, Security Operator, Security Administrator, Global Reader, and Global Administrator. Since Security Reader is not an available option, the least-privileged valid choice from the listed answers is Security Administrator. Reports Reader can view reports but does not grant access to Identity Protection risk data.

Question 182

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 E5 subscription. You create an account for a new security administrator named SecAdmin1. You need to ensure that SecAdmin1 can manage Microsoft Defender for Office 365 settings and policies for Microsoft Teams, SharePoint, and OneDrive. Solution: From the Microsoft 365 admin center, you assign SecAdmin1 the Teams Administrator role. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
Managing Microsoft Defender for Office 365 settings and policies is done through the Microsoft Defender portal and requires an appropriate security role such as Security Administrator. The Teams Administrator role manages Microsoft Teams service configuration but does not grant permissions to manage Defender for Office 365 security policies across Teams, SharePoint, and OneDrive.

$19

Get all 430 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.