Microsoft

MS-102 Free Practice Questions — Page 19

Question 181

Overview - Fabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide. Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States. Existing Environment - Active Directory Environment - The network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top-level organizational unit (OU) that contains several child OUs for user accounts and computer accounts. All users authenticate to on-premises applications by signing in to their device by using a UPN format of . Fabrikam does NOT plan to implement identity federation. Network Infrastructure - Each office has a high-speed connection to the Internet. Each office contains two domain controllers. All domain controllers are configured as DNS servers. The public zone for fabrikam.com is managed by an external DNS server. All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed. All shared company documents are stored on a Microsoft SharePoint Server farm. Requirements - Planned Changes - Fabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription. Fabrikam plans to implement two pilot projects: • Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365. • Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users. Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses. Technical Requirements - Fabrikam identifies the following technical requirements: • All users must be able to exchange email messages successfully during Project1 by using their current email address. • Users must be able to authenticate to cloud services if Active Directory becomes unavailable. • A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal. • Microsoft 365 Apps for enterprise applications must be installed from a network share only. • Disruptions to email access must be minimized. Application Requirements - Fabrikam identifies the following application requirements: • An on-premises web application named App1 must allow users to complete their expense reports online. App1 must be available to users from the My Apps portal. • The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized. Security Requirements - Fabrikam identifies the following security requirements: • After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN. • The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically. • After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically. • The principle of least privilege must be used. You are evaluating the required processes for Project1. You need to recommend which DNS record must be created while adding a domain name to the tenant for the project. Which DNS record should you recommend?

A. alias (CNAME)
B. host information (HINFO)
C. host (A)
D. text (TXT)
Show Answer
Correct Answer: D
Explanation:
When adding a custom domain to a Microsoft 365 tenant, Microsoft requires proof of domain ownership before services such as Exchange Online can be configured. The standard and recommended method is to create a TXT record in the public DNS zone with a value provided by Microsoft (for example, MS=xxxxxxxx). This satisfies the domain verification requirement without impacting existing mail flow, which is critical during Project1 to minimize email disruption.

Question 182

Your network contains an Active Directory domain. You have an Azure AD tenant that has Security defaults disabled. Azure AD Connect is configured for directory synchronization. Password hash synchronization and pass-through authentication are disabled. You need to enable Azure AD Identity Protection to detect leaked credentials. What should you do first?

A. From Azure AD Connect, enable password hash synchronization.
B. From the Microsoft Entra admin center, enable Security defaults.
C. From the Microsoft Entra admin center, configure verifiable credentials.
D. From Azure AD Connect, enable pass-through authentication.
Show Answer
Correct Answer: A
Explanation:
Azure AD Identity Protection detects leaked credentials by comparing leaked username/password pairs against password hashes synced to Azure AD. This capability requires Password Hash Synchronization (PHS) to be enabled. Without PHS, Azure AD has no password hash data to evaluate for leaked credentials. Security defaults, pass-through authentication, and verifiable credentials are not prerequisites for leaked credential detection.

Question 183

You have a Microsoft 365 E5 tenant. The Microsoft Secure Score for the tenant is shown in the following exhibit. You plan to enable Security defaults for Azure AD. Which three improvement actions will this affect? NOTE: Each correct selection is worth one point.

A. Require MFA for administrative roles
B. Ensure all users can complete multi-factor authentication for secure access
C. Enable policy to block legacy authentication
D. Enable self-service password reset
E. Use limited administrative roles
Show Answer
Correct Answer: A, B, C
Explanation:
Enabling Azure AD Security defaults enforces a baseline set of protections: administrators must use MFA, all users must register for and use MFA when required, and legacy authentication protocols are blocked. It does not configure self-service password reset or role scoping, so only actions A, B, and C are affected.

Question 184

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the devices shown in the following table. All the devices are onboarded to Microsoft Defender for Endpoint. You plan to use Microsoft Defender Vulnerability Management to meet the following requirements: • Detect operating system vulnerabilities. • Perform a configuration assessment of the operating system. Which devices support each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 184 Illustration for MS-102 question 184
Show Answer
Correct Answer: Detect operating system vulnerabilities: Device1, Device2, Device3, and Device4 Perform a configuration assessment of the operating system: Device1 and Device2 only
Explanation:
Microsoft Defender Vulnerability Management can detect OS vulnerabilities across Windows, Android, and iOS devices. However, OS configuration assessment is supported only on Windows 10 and Windows 11, not on Android or iOS.

Question 185

HOTSPOT - You have a Microsoft 365 subscription that uses Microsoft Defender for Office 365. You need to identify the settings that are configured less secure than the Standard protection profile settings in the preset security policies. What should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 185
Show Answer
Correct Answer: Portal: Microsoft 365 Defender portal Feature: Configuration analyzer
Explanation:
The Configuration analyzer in the Microsoft 365 Defender portal compares your current Defender for Office 365 settings against the Standard protection preset and highlights configurations that are less secure.

Question 186

Your network contains an Active Directory domain named adatum.com that is synced to Azure AD. The domain contains 100 user accounts. The city attribute for all the users is set to the city where the user resides. You need to modify the value of the city attribute to the three-letter airport code of each city. What should you do?

A. From Azure Cloud Shell, run the Get-MsolUser and Set-MsolUser cmdlets.
B. From Windows PowerShell on a domain controller, run the Get-MgUser and Update-MgUser cmdlets.
C. From Active Directory Administrative Center, select the Active Directory users, and then modify the Properties settings.
D. From Azure Cloud Shell, run the Get-MgUser and Update-MgUser cmdlets.
Show Answer
Correct Answer: C
Explanation:
The users are synchronized from on-premises Active Directory to Azure AD. For synchronized attributes such as the city attribute, the authoritative source is on-premises Active Directory. Therefore, the city value must be modified in Active Directory (for example, using Active Directory Administrative Center), and the change will then sync to Azure AD. Changes made directly in Azure AD or via Graph/MSOL cmdlets would not be authoritative for synced users.

Question 187

Your network contains an on-premises Active Directory domain. The domain contains 2,000 computers that run Windows 10. You purchase a Microsoft 365 subscription. You implement password hash synchronization and Azure AD Seamless Single Sign-On (Seamless SSO). You need to ensure that users can use Seamless SSO from the Windows 10 computers. What should you do?

A. Join the computers to Azure AD.
B. Create a conditional access policy in Azure AD.
C. Modify the Intranet zone settings by using Group Policy.
D. Deploy an Azure AD Connect staging server.
Show Answer
Correct Answer: C
Explanation:
Azure AD Seamless SSO relies on Kerberos authentication from domain-joined Windows devices to Azure AD endpoints. Browsers will only send Kerberos tickets automatically to sites in the Local Intranet zone. Therefore, you must use Group Policy to add the Azure AD Seamless SSO URLs to the Intranet zone (Site to Zone Assignment List). This enables users on Windows 10 domain-joined computers to use Seamless SSO without additional prompts.

Question 188

HOTSPOT - Your network contains an on-premises Active Directory domain that is synced to Azure AD as shown in the following exhibit. An on-premises Active Directory user account named Allan Yoo is synchronized to Azure AD. You view Allan’s account from Microsoft 365 and notice that his username is set to . For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 188 Illustration for MS-102 question 188
Show Answer
Correct Answer: No No Yes
Explanation:
The user is synchronized from on-premises Active Directory via Azure AD Connect. Password writeback is disabled, so passwords cannot be reset from the Azure portal. User attributes like job title are mastered on-premises and cannot be edited in Azure AD. Usage location is a cloud-only attribute and can be configured in the Azure portal for synced users.

Question 189

You have a Microsoft 365 E5 subscription that contains users in the United States, Europe, and Asia. You use Azure AD Identity Protection. You have a virtual desktop infrastructure (VDI). All VDI servers are located in the United States. Users connect to Microsoft 365 from laptops and the VDI. Some VDI users report that they are blocked from signing in to Microsoft 365 due to a high sign-in risk. You need to reduce the likelihood that the VDI users will be erroneously blocked from signing in to Microsoft 365. The solution must ensure that sign-ins from the VDI environment are protected by using Identity Protection. What should you configure?

A. ExpressRoute for Microsoft 365
B. a trusted location
C. a Satellite Geography location
D. a Conditional Access policy
Show Answer
Correct Answer: B
Explanation:
Sign-ins from the VDI all originate from U.S.-based IP addresses, which can trigger high sign-in risk for users whose normal locations are Europe or Asia. Configuring the VDI IP range as a trusted location reduces false-positive risky sign-ins while still allowing Azure AD Identity Protection to evaluate and protect those sign-ins appropriately. Other options do not address Identity Protection risk evaluation for VDI traffic.

Question 190

Your network contains an Active Directory domain and an Azure AD tenant. The network uses a firewall that contains a list of allowed outbound domains. You begin to implement directory synchronization. You discover that the firewall configuration contains only the following domain names in the list of allowed domains: • *.microsoft.com • *.office.com Directory synchronization fails. You need to ensure that directory synchronization completes successfully. What is the best approach to achieve the goal? More than one answer choice may achieve the goal. Select the BEST answer.

A. From the firewall, modify the list of allowed outbound domains.
B. From Azure AD Connect, modify the Customize synchronization options task.
C. From the firewall, create a list of allowed inbound domains.
D. Deploy an Azure AD Connect sync server in staging mode.
E. From the firewall, allow the IP address range of the Azure data center for outbound communication.
Show Answer
Correct Answer: A
Explanation:
Azure AD Connect requires outbound access to several Azure AD–specific endpoints (such as login.microsoftonline.com and other identity-related services) that are not covered by only *.microsoft.com and *.office.com. Directory synchronization fails because the firewall is blocking required outbound traffic. The correct solution is to modify the firewall’s allowed outbound domain list to include the required Azure AD and Azure AD Connect endpoints. Other options do not address the root firewall restriction causing the failure.

$19

Get all 417 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.