Microsoft

MS-102 Free Practice Questions — Page 22

Question 214

You are testing a data loss prevention (DLP) policy to protect the sharing of credit card information with external users. During testing, you discover that a user can share credit card information with external users by using email. However, the user is prevented from sharing files that contain credit card information by using Microsoft SharePoint. You need to prevent the user from sharing the credit card information by using email and SharePoint. What should you configure?

A. the locations of the DLP policy
B. the conditions of the DLP policy rule
C. the user overrides of the DLP policy rule
D. the status of the DLP policy
Show Answer
Correct Answer: A
Explanation:
The DLP policy is already blocking credit card information in SharePoint but not in email, which indicates the policy is not applied to Exchange Online. Configure the DLP policy locations so it includes both Exchange Online and SharePoint Online. Changing conditions, overrides, or policy status would not explain why it works in one workload but not the other.

Question 215

You have a Microsoft 365 E5 tenant. You create an auto-labeling policy to encrypt emails that contain a sensitive info type. You specify the locations where the policy will be applied. You need to deploy the policy. What should you do first?

A. Run the policy in simulation mode.
B. Configure Azure Information Protection analytics.
C. Review the sensitive information in Activity explorer.
D. Turn on the policy.
Show Answer
Correct Answer: A
Explanation:
Auto-labeling policies for Microsoft Purview should first be run in simulation mode. Simulation lets you evaluate which emails and documents would be labeled and encrypted, review the results, and refine the policy before enabling enforcement. After a successful simulation, you can turn the policy on.

Question 216

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the users shown in the following table. You have labels in Microsoft 365 as shown in the following table. The content in Microsoft 365 is assigned labels as shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 216 Illustration for MS-102 question 216 Illustration for MS-102 question 216 Illustration for MS-102 question 216
Show Answer
Correct Answer: Yes No Yes
Explanation:
Content Explorer Content Viewer allows viewing item contents; List Viewer allows viewing items and assigned labels but not contents. Thus Admin1 can view File1 contents, Admin2 cannot, and Admin2 can verify the retention label assignment on Mail1.

Question 217

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the users shown in the following table. The subscription has the following two anti-spam policies: • Name: AntiSpam1 • Priority: 0 • Include these users, groups and domains • Users: User3 • Groups: Group1 • Exclude these users, groups and domains • Groups: Group2 • Message limits • Set a daily message limit: 100 • Name: AntiSpam2 • Priority: 1 • Include these users, groups and domains • Users: User1 • Groups: Group2 • Exclude these users, groups and domains • Users: User3 • Message limits • Set a daily message limit: 50 For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 217 Illustration for MS-102 question 217
Show Answer
Correct Answer: No Yes No
Explanation:
Only the highest-priority applicable anti-spam policy applies. Exclusions override inclusions within a policy. User1 gets AntiSpam1 (100, not 150). User2 is excluded from AntiSpam1 via Group2, so AntiSpam2 applies (50). User3 is excluded from AntiSpam1 (Group2) and excluded from AntiSpam2 (direct exclusion), so neither policy applies; therefore the statement that the maximum is 100 is false.

Question 218

HOTSPOT - You have a Microsoft 365 E5 subscription that contains a user named User1 and the administrators shown in the following table. User1 reports that after sending 1,000 email messages in the morning, the user is blocked from sending additional emails. You need to identify the following: • What administrators can unblock User1 • What to configure to allow User1 to send at least 2,000 emails per day without being blocked What should you identify? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 218 Illustration for MS-102 question 218
Show Answer
Correct Answer: Administrators: Admin1 and Admin2 only Settings: Anti-spam
Explanation:
Users blocked after high outbound mail volume are placed on the Restricted entities list managed through Microsoft Defender. Exchange Administrators and Security Administrators can remove the restriction, and outbound sending limits are configured through the outbound anti-spam policy.

Question 219

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint site named site1. You need to ensure that site1 meets the following requirements: • Retains all data for 10 years • Prevents the sharing of data outside the organization Which two items should you create and apply to site1? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

A. a retention policy
B. a data loss prevention (DLP) policy
C. a retention label policy
D. a sensitive info type
E. a retention label
F. a sensitivity label
Show Answer
Correct Answer: A, F
Explanation:
A retention policy applied to the SharePoint site ensures all content is retained for 10 years. To prevent sharing outside the organization at the SharePoint site level, apply a sensitivity label configured for containers (SharePoint sites/Microsoft 365 groups) to restrict external sharing. A DLP policy is designed to detect and block sharing of sensitive content based on conditions, but the requirement is to prevent external sharing for the site itself rather than inspect specific data.

Question 220

You have a Microsoft 365 E5 tenant. You create a retention label named Retention1 as shown in the following exhibit. You apply Retention1 to all the Microsoft OneDrive content. On January 1, 2020, a user stores a file named File1 in OneDrive. On January 10, 2020, the user modifies File1. On February 1, 2020, the user deletes File1. When will File1 be removed permanently and unrecoverable from OneDrive?

A. February 1, 2020
B. July 1, 2020
C. July 10, 2020
D. August 1, 2020
Show Answer
Correct Answer: B
Explanation:
The retention label retains the file for 6 months based on its creation date (as indicated by the exhibit context). File1 was created on January 1, 2020, so the retention period ends on July 1, 2020. Although the user deleted the file on February 1, 2020, retention prevents permanent deletion until the retention period expires. At that point it is permanently removed and unrecoverable.

Question 221

HOTSPOT - Overview - Litware, Inc. is a consulting company that has a main office in Montreal and a branch office in Seattle. Litware collaborates with a third-party company named A. Datum Corporation. Environment - On-Premises Environment - The network of Litware contains an Active Directory domain named litware.com. The domain contains three organizational units (OUs) named LitwareAdmins, Montreal Users, and Seattle Users and the users shown in the following table. The domain contains 2,000 Windows 10 Pro devices and 100 servers that run Windows Server 2019. Cloud Environment - Litware has a pilot Microsoft 365 subscription that includes Microsoft Office 365 Enterprise E3 licenses and Azure AD Premium P2 licenses. The subscription contains a verified DNS domain named litware.com. Azure AD Connect is installed and has the following configurations: • Password hash synchronization is enabled. • Synchronization is enabled for the LitwareAdmins OU only. Users are assigned the roles shown in the following table. Self-service password reset (SSPR) is enabled. The Azure AD tenant has Security defaults enabled. Problem Statements - Litware identifies the following issues: • Admin1 cannot create conditional access policies. • Admin4 receives an error when attempting to use SSPR. • Users access new Office 365 service and feature updates before the updates are reviewed by Admin2. Requirements - Planned Changes - Litware plans to implement the following changes: • Implement Microsoft Intune. • Implement Microsoft Teams. • Implement Microsoft Defender for Office 365. • Ensure that users can install Office 365 apps on their device. • Convert all the Windows 10 Pro devices to Windows 10 Enterprise ES. • Configure Azure AD Connect to sync the Montreal Users OU and the Seattle Users OU. Technical Requirements - Litware identifies the following technical requirements: • Administrators must be able to specify which version of an Office 365 desktop app will be available to users and to roll back to previous versions. • Only Admin2 must have access to new Office 365 service and feature updates before they are released to the company. • Litware users must be able to invite A. Datum users to participate in the following activities: • Join Microsoft Teams channels. • Join Microsoft Teams chats. • Access shared files. • Just in time access to critical administrative roles must be required. • Microsoft 365 incidents and advisories must be reviewed monthly. • Office 365 service status notifications must be sent to Admin2. • The principle of least privilege must be used. You need to ensure that Admin4 can use SSPR. Which tool should you use, and which action should you perform? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 221 Illustration for MS-102 question 221 Illustration for MS-102 question 221
Show Answer
Correct Answer: Action: Enable password writeback Tool: Azure AD Connect
Explanation:
SSPR for synchronized on-premises users requires password writeback so password changes can be written back to Active Directory. Password writeback is enabled in Azure AD Connect (Microsoft Entra Connect).

Question 222

Overview - Fabrikam, Inc. is an electronics company that produces consumer products. Fabrikam has 10,000 employees worldwide. Fabrikam has a main office in London and branch offices in major cities in Europe, Asia, and the United States. Existing Environment - Active Directory Environment - The network contains an Active Directory forest named fabrikam.com. The forest contains all the identities used for user and computer authentication. Each department is represented by a top-level organizational unit (OU) that contains several child OUs for user accounts and computer accounts. All users authenticate to on-premises applications by signing in to their device by using a UPN format of . Fabrikam does NOT plan to implement identity federation. Network Infrastructure - Each office has a high-speed connection to the Internet. Each office contains two domain controllers. All domain controllers are configured as DNS servers. The public zone for fabrikam.com is managed by an external DNS server. All users connect to an on-premises Microsoft Exchange Server 2016 organization. The users access their email by using Outlook Anywhere, Outlook on the web, or the Microsoft Outlook app for iOS. All the Exchange servers have the latest cumulative updates installed. All shared company documents are stored on a Microsoft SharePoint Server farm. Requirements - Planned Changes - Fabrikam plans to implement a Microsoft 365 Enterprise subscription and move all email and shared documents to the subscription. Fabrikam plans to implement two pilot projects: • Project1: During Project1, the mailboxes of 100 users in the sales department will be moved to Microsoft 365. • Project2: After the successful completion of Project1, Microsoft Teams will be enabled in Microsoft 365 for the sales department users. Fabrikam plans to create a group named UserLicenses that will manage the allocation of all Microsoft 365 bulk licenses. Technical Requirements - Fabrikam identifies the following technical requirements: • All users must be able to exchange email messages successfully during Project1 by using their current email address. • Users must be able to authenticate to cloud services if Active Directory becomes unavailable. • A user named User1 must be able to view all DLP reports from the Microsoft Purview compliance portal. • Microsoft 365 Apps for enterprise applications must be installed from a network share only. • Disruptions to email access must be minimized. Application Requirements - Fabrikam identifies the following application requirements: • An on-premises web application named App1 must allow users to complete their expense reports online. App1 must be available to users from the My Apps portal. • The installation of feature updates for Microsoft 365 Apps for enterprise must be minimized. Security Requirements - Fabrikam identifies the following security requirements: • After the planned migration to Microsoft 365, all users must continue to authenticate to their mailbox and to SharePoint sites by using their UPN. • The membership of the UserLicenses group must be validated monthly. Unused user accounts must be removed from the group automatically. • After the planned migration to Microsoft 365, all users must be signed in to on-premises and cloud-based applications automatically. • The principle of least privilege must be used. You are evaluating the required processes for Project1. You need to recommend which DNS record must be created while adding a domain name for the project. Which DNS record should you recommend?

A. mail exchanger (MX)
B. alias (CNAME)
C. host information (HINFO)
D. host (AAAA)
Show Answer
Correct Answer: A
Explanation:
When adding a custom domain to Microsoft 365, domain ownership must be verified. The preferred method is a TXT record, but if TXT is not available among the options, Microsoft supports using a special MX record for domain verification. This is separate from the production mail-flow MX record and is used only to verify ownership during domain setup.

Question 223

You have a Microsoft 365 subscription. You plan to use Adoption Score and need to ensure that it can obtain device and software metrics. What should you do?

A. Enable privileged access.
B. Enable Endpoint analytics.
C. Configure Support integration.
D. Run the Microsoft 365 network connectivity test on each device.
Show Answer
Correct Answer: B
Explanation:
Adoption Score obtains device and software metrics through Endpoint analytics, which collects device performance, health, hardware, and software information from managed endpoints. The other options do not enable the collection of these metrics for Adoption Score.

$19

Get all 430 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.