Microsoft

MS-102 Free Practice Questions — Page 6

Question 53

You have a Microsoft 365 E5 subscription that contains a group named Group1. The subscription uses Microsoft Defender for Cloud Apps. You configure cloud discovery. You need to ensure that you can create a custom report that details shadow IT usage by the members of Group1. What should you do first?

A. Configure user enrichment.
B. Disable anonymization.
C. Add an app connector.
D. Configure user monitoring.
Show Answer
Correct Answer: A
Explanation:
To create reports on shadow IT usage by members of a specific Microsoft Entra group, Defender for Cloud Apps first needs user enrichment so discovered users are mapped to Microsoft Entra ID identities and group memberships. This enables filtering and reporting by Group1. Disabling anonymization only reveals user identities after monitoring is configured, app connectors are unrelated to Cloud Discovery, and user monitoring depends on enriched identity information for group-based reporting.

Question 54

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. You need to ensure that when a user-based alert is triggered in Defender for Cloud Apps, the user is marked as compromised. Which two options can you use to automate the response? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point

A. a Microsoft Power Automate playbook
B. a user tag
C. a custom detection rule
D. a block script
E. an automated remediation level
Show Answer
Correct Answer: A, C
Explanation:
A Power Automate playbook can be triggered by Defender for Cloud Apps alerts and invoke the Microsoft Entra action to mark a user as compromised. In the unified Microsoft Defender experience, a custom detection rule can generate identity response actions, including marking the user as compromised, providing another automated solution. User tags do not mark an Entra user as compromised, block scripts are unrelated, and automated remediation levels apply to endpoint/device remediation rather than this identity action. Sources: https://learn.microsoft.com/en-us/defender-cloud-apps/user-activity-policies

Question 55

You have a Microsoft 365 subscription. You need to identify which shadow IT apps users connect to by using Cloud Discovery in Microsoft Defender for Cloud Apps. What should you create first?

A. a Cloud Discovery snapshot report
B. a session policy
C. an app discovery policy
D. a Conditional Access policy
Show Answer
Correct Answer: A
Explanation:
Cloud Discovery first requires collecting and analyzing traffic data to discover cloud app usage. A Cloud Discovery snapshot report is the initial artifact used to identify shadow IT apps from uploaded traffic logs. App discovery policies are created afterward to generate ongoing alerts based on discovered activity. Session policies and Conditional Access policies do not perform the initial discovery.

Question 56

HOTSPOT - Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server. The domain contains the users shown in the following table. You have a Microsoft 365 subscription that contains the following user accounts: • • On Server1, you configure Microsoft Entra Connect Sync in staging mode and select the following organizational units (OUs): • OU=Department1,DC=Contoso,DC=LOCAL • OU=Team1,OU=Department2,DC=Contoso,DC=LOCAL You disable staging mode on Server1. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 56 Illustration for MS-102 question 56
Show Answer
Correct Answer: Yes No No
Explanation:
User1 is in a selected OU and soft-matches the existing Microsoft 365 account by UPN. User2 is in scope but its on-prem UPN/email (.local) do not match the existing cloud account (.com), so it does not sync to that account. User3 is outside the selected synchronization scope, so no new Microsoft 365 user is created.

Question 57

HOTSPOT - You have a Microsoft 365 E5 subscription that uses Microsoft Purview. You receive the alerts shown in the exhibit. (Click the Exhibit tab.) Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 57 Illustration for MS-102 question 57
Show Answer
Correct Answer: File1.docx: Investigating, Dismissed, or Resolved File2.docx: cannot be changed
Explanation:
The exhibit shows File1.docx is Active, which can be updated to Investigating, Dismissed, or Resolved. File2.docx is already Resolved, which is treated as a final state in the Purview DLP alerts experience shown.

Question 58

Your network contains two on-premises Active Directory Domain Services (AD DS) forests named contoso.com and fabrikam.com that are connected by using a forest trust. You have a Microsoft 365 E5 subscription. You need to sync a subset of users from both forests to Microsoft Entra. The solution must support device objects and device writeback. What should you use?

A. Microsoft Entra Cloud Sync
B. Microsoft Entra Domain Services
C. Microsoft Entra Connect Sync
D. Active Directory Federation Services (AD FS)
Show Answer
Correct Answer: C
Explanation:
Microsoft Entra Connect Sync supports synchronization from multiple on-premises AD DS forests into Microsoft Entra ID, including filtering subsets of users. It also supports hybrid device scenarios, synchronization of device objects, and device writeback. Microsoft Entra Cloud Sync does not support device writeback, Entra Domain Services is a managed domain service rather than a synchronization tool, and AD FS provides federation for authentication rather than directory synchronization.

Question 59

You have a Microsoft 365 E5 subscription. You plan to deploy Microsoft Defender for Cloud Apps and connect Microsoft 365 to Defender for Cloud Apps. You need to ensure that you can enable all the Microsoft 365 components when you add the app connector. What should you do first?

A. Configure Conditional Access app control.
B. Enable file monitoring for Defender for Cloud Apps.
C. Add an API token to Defender for Cloud Apps.
D. Configure Cloud Discovery.
Show Answer
Correct Answer: B
Explanation:
To enable all Microsoft 365 components during the Defender for Cloud Apps app connector setup, file monitoring must be enabled first. This prerequisite allows integration with file-related capabilities for SharePoint Online, OneDrive, and other Microsoft 365 workloads. Conditional Access app control and Cloud Discovery are separate features, and adding an API token is part of the connector authorization rather than the prerequisite that unlocks all Microsoft 365 components.

Question 60

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription. You are implementing Microsoft Defender for Cloud Apps. You need to ensure that you can create OAuth app policies. Solution: You configure Cloud Discovery. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
OAuth app policies in Microsoft Defender for Cloud Apps require connecting supported SaaS apps (via App Connectors) so OAuth app permissions can be evaluated. Configuring Cloud Discovery enables shadow IT discovery and does not enable creation of OAuth app policies.

Question 61

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription. You are implementing Microsoft Defender for Cloud Apps. You need to ensure that you can create OAuth app policies. Solution: You configure Conditional Access app control. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
Conditional Access App Control provides real-time session control and monitoring for cloud apps, but it is not the prerequisite for creating OAuth app policies in Microsoft Defender for Cloud Apps. OAuth app policies require connected app integration (such as connecting the Microsoft 365 app) so Defender for Cloud Apps can discover and evaluate OAuth-authorized applications. Therefore, configuring Conditional Access App Control alone does not meet the goal.

Question 62

HOTSPOT - You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. You need to create a file policy to generate an alert when a file is shared with a domain named fabrikam.com. How should you complete the filter for the policy? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 62
Show Answer
Correct Answer: Collaborators Any from domain Access level
Explanation:
Filter on collaborators from the specified domain (fabrikam.com), then require the sharing access level to be Public/External so an alert is generated when the file is shared with that domain.

$19

Get all 430 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.