Microsoft

MS-102 Free Practice Questions — Page 21

Question 204

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the users shown in the following table. The subscription has the following two anti-spam policies: • Name: AntiSpam1 • Priority: 0 • Include these users, groups and domains • Users: User3 • Groups: Group1 • Exclude these users, groups and domains • Groups: Group2 • Message limits • Set a daily message limit: 100 • Name: AntiSpam2 • Priority: 1 • Include these users, groups and domains • Users: User1 • Groups: Group2 • Exclude these users, groups and domains • Users: User3 • Message limits • Set a daily message limit: 50 For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 204 Illustration for MS-102 question 204
Show Answer
Correct Answer: User1: No User2: Yes User3: No
Explanation:
Only the highest-priority applicable anti-spam policy applies to a user, and exclusions override inclusions. - User1 is affected only by AntiSpam2 (limit 50), not a combined 150. - User2 matches AntiSpam2 (limit 50). - User3 is excluded from both policies, so no 100‑message limit applies.

Question 205

HOTSPOT - You have a Microsoft 365 E5 subscription that contains a user named User1 and the administrators shown in the following table. User1 reports that after sending 1,000 email messages in the morning, the user is blocked from sending additional emails. You need to identify the following: • What administrators can unblock User1 • What to configure to allow User1 to send at least 2,000 emails per day without being blocked What should you identify? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 205 Illustration for MS-102 question 205
Show Answer
Correct Answer: Administrators: Admin1 and Admin2 only Settings: Anti-spam
Explanation:
User1 is blocked due to outbound spam limits. Removing a user from Restricted users and adjusting outbound spam limits can be done by Exchange Administrators and Security Administrators. To allow at least 2,000 emails per day, you must configure the outbound spam policy, which is part of Anti-spam settings.

Question 206

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint site named site1. You need to ensure that site1 meets the following requirements: • Retains all data for 10 years • Prevents the sharing of data outside the organization Which two items should you create and apply to site1? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

A. a retention policy
B. a data loss prevention (DLP) policy
C. a retention label policy
D. a sensitive info type
E. a retention label
F. a sensitivity label
Show Answer
Correct Answer: A, F
Explanation:
To retain all data for 10 years at the site level, you apply a retention policy to the SharePoint site. This enforces preservation of all content for the specified period. To prevent sharing data outside the organization, you apply a sensitivity label to the SharePoint site that disables external sharing. Sensitivity labels can be applied to sites and enforce sharing restrictions. DLP policies focus on detecting or blocking sharing of sensitive content, not globally preventing external sharing for a site.

Question 207

You have a Microsoft 365 E5 tenant. You create a retention label named Retention1 as shown in the following exhibit. You apply Retention1 to all the Microsoft OneDrive content. On January 1, 2020, a user stores a file named File1 in OneDrive. On January 10, 2020, the user modifies File1. On February 1, 2020, the user deletes File1. When will File1 be removed permanently and unrecoverable from OneDrive?

A. February 1, 2020
B. July 1, 2020
C. July 10, 2020
D. August 1, 2020
Show Answer
Correct Answer: B
Explanation:
The retention label is configured to retain content for 6 months based on the file’s creation date. File1 was created on January 1, 2020, so the retention period runs until July 1, 2020. Deleting or modifying the file does not reset the retention clock; it is preserved until the retention period expires, after which it is permanently and unrecoverably deleted.

Question 208

HOTSPOT - Overview - Litware, Inc. is a consulting company that has a main office in Montreal and a branch office in Seattle. Litware collaborates with a third-party company named A. Datum Corporation. Environment - On-Premises Environment - The network of Litware contains an Active Directory domain named litware.com. The domain contains three organizational units (OUs) named LitwareAdmins, Montreal Users, and Seattle Users and the users shown in the following table. The domain contains 2,000 Windows 10 Pro devices and 100 servers that run Windows Server 2019. Cloud Environment - Litware has a pilot Microsoft 365 subscription that includes Microsoft Office 365 Enterprise E3 licenses and Azure AD Premium P2 licenses. The subscription contains a verified DNS domain named litware.com. Azure AD Connect is installed and has the following configurations: • Password hash synchronization is enabled. • Synchronization is enabled for the LitwareAdmins OU only. Users are assigned the roles shown in the following table. Self-service password reset (SSPR) is enabled. The Azure AD tenant has Security defaults enabled. Problem Statements - Litware identifies the following issues: • Admin1 cannot create conditional access policies. • Admin4 receives an error when attempting to use SSPR. • Users access new Office 365 service and feature updates before the updates are reviewed by Admin2. Requirements - Planned Changes - Litware plans to implement the following changes: • Implement Microsoft Intune. • Implement Microsoft Teams. • Implement Microsoft Defender for Office 365. • Ensure that users can install Office 365 apps on their device. • Convert all the Windows 10 Pro devices to Windows 10 Enterprise ES. • Configure Azure AD Connect to sync the Montreal Users OU and the Seattle Users OU. Technical Requirements - Litware identifies the following technical requirements: • Administrators must be able to specify which version of an Office 365 desktop app will be available to users and to roll back to previous versions. • Only Admin2 must have access to new Office 365 service and feature updates before they are released to the company. • Litware users must be able to invite A. Datum users to participate in the following activities: • Join Microsoft Teams channels. • Join Microsoft Teams chats. • Access shared files. • Just in time access to critical administrative roles must be required. • Microsoft 365 incidents and advisories must be reviewed monthly. • Office 365 service status notifications must be sent to Admin2. • The principle of least privilege must be used. You need to ensure that Admin4 can use SSPR. Which tool should you use, and which action should you perform? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 208 Illustration for MS-102 question 208 Illustration for MS-102 question 208
Show Answer
Correct Answer: Action: Enable password writeback Tool: Azure AD Connect
Explanation:
Admin4 is a synchronized on-premises user. To allow SSPR to reset the on-premises AD password, password writeback must be enabled in Azure AD Connect. Without writeback, SSPR fails for synced users.

Question 209

Overview - Fabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide. Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States. Existing Environment - Active Directory Environment - The network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top-level organizational unit (OU) that contains several child OUs for user accounts and computer accounts. All users authenticate to on-premises applications by signing in to their device by using a UPN format of . Fabrikam does NOT plan to implement identity federation. Network Infrastructure - Each office has a high-speed connection to the Internet. Each office contains two domain controllers. All domain controllers are configured as DNS servers. The public zone for fabrikam.com is managed by an external DNS server. All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed. All shared company documents are stored on a Microsoft SharePoint Server farm. Requirements - Planned Changes - Fabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription. Fabrikam plans to implement two pilot projects: • Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365. • Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users. Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses. Technical Requirements - Fabrikam identifies the following technical requirements: • All users must be able to exchange email messages successfully during Project1 by using their current email address. • Users must be able to authenticate to cloud services if Active Directory becomes unavailable. • A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal. • Microsoft 365 Apps for enterprise applications must be installed from a network share only. • Disruptions to email access must be minimized. Application Requirements - Fabrikam identifies the following application requirements: • An on-premises web application named App1 must allow users to complete their expense reports online. App1 must be available to users from the My Apps portal. • The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized. Security Requirements - Fabrikam identifies the following security requirements: • After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN. • The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically. • After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically. • The principle of least privilege must be used. You are evaluating the required processes for Project1. You need to recommend which DNS record must be created while adding a domain name for the project. Which DNS record should you recommend?

A. mail exchanger (MX)
B. alias (CNAME)
C. host information (HINFO)
D. host (AAAA)
Show Answer
Correct Answer: A
Explanation:
When adding a custom domain to Microsoft 365 for Project1, the domain must be verified. If a TXT record cannot be used, Microsoft 365 supports verifying domain ownership by creating a special MX record. This MX record is used only for domain verification and not for mail flow. Therefore, the correct DNS record to recommend during the domain addition process is an MX record.

Question 210

You have a Microsoft 365 subscription. You plan to use Adoption Score and need to ensure that it can obtain device and software metrics. What should you do?

A. Enable privileged access.
B. Enable Endpoint analytics.
C. Configure Support integration.
D. Run the Microsoft 365 network connectivity test on each device.
Show Answer
Correct Answer: B
Explanation:
Adoption Score relies on device and software metrics collected from managed endpoints. Enabling Endpoint analytics in Microsoft Intune allows Microsoft 365 to gather hardware, software, and performance data from devices, which is required for Adoption Score to obtain these metrics. The other options do not provide device and software telemetry.

Question 211

You have a Microsoft 365 E5 subscription that has Microsoft Defender for Endpoint integrated with Microsoft Intune. Devices are onboarded by using Microsoft Defender for Endpoint. You plan to block devices based on the results of the machine risk score calculated by Microsoft Defender for Endpoint. What should you create first?

A. a device configuration policy
B. a device compliance policy
C. a conditional access policy
D. an endpoint detection and response policy
Show Answer
Correct Answer: B
Explanation:
To block devices based on the Microsoft Defender for Endpoint machine risk score, Intune must first evaluate that risk as a compliance signal. This is done by creating a device compliance policy that includes Defender for Endpoint risk levels. Conditional Access can then use the compliance state to block access, but it depends on the compliance policy existing first.

Question 212

You have a Microsoft 365 E5 subscription. You need to ensure that administrators receive an email when Microsoft 365 Defender detects a sign-in from a risky IP address. What should you create?

A. a vulnerability notification rule
B. an alert
C. an incident assignment filter
D. an incident notification rule
Show Answer
Correct Answer: B
Explanation:
Microsoft 365 Defender generates alerts for risky activities such as sign-ins from risky or suspicious IP addresses. To notify administrators by email when such a detection occurs, you configure an alert and its alert notification settings. Vulnerability notification rules and incident-related rules do not apply to sign-in risk detections.

Question 213

Your company has three main offices and one branch office. The branch office is used for research. The company plans to implement a Microsoft 365 tenant and to deploy multi-factor authentication. You need to recommend a Microsoft 365 solution to ensure that multi-factor authentication is enforced only for users in the branch office. What should you include in the recommendation?

A. Azure AD password protection
B. a Microsoft Intune device configuration profile
C. a Microsoft Intune device compliance policy
D. Azure AD conditional access
Show Answer
Correct Answer: D
Explanation:
Azure AD Conditional Access allows you to target specific users or locations (such as the branch office network) and require multi-factor authentication only for those sign-ins. This is the correct Microsoft 365 feature for enforcing MFA selectively based on location.

$19

Get all 417 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.