Microsoft

MS-102 Free Practice Questions — Page 7

Question 58

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription. You are implementing Microsoft Defender for Cloud Apps. You need to ensure that you can create OAuth app policies. Solution: You connect Microsoft 365 to Defender for Cloud Apps. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: A
Explanation:
To create OAuth app policies in Microsoft Defender for Cloud Apps, you must first connect Microsoft 365 (Office 365) as a connected app. This connection allows Defender for Cloud Apps to discover OAuth-consented applications in the tenant and enables the OAuth app policy templates. Therefore, connecting Microsoft 365 meets the stated goal.

Question 59

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365. You need to create a policy that will quarantine messages containing attachments that match .apk and .appx extensions. Which type of policy should you configure?

A. anti-malware
B. anti-phishing
C. Safe Attachments
D. anti-spam
Show Answer
Correct Answer: A
Explanation:
Quarantining messages based on specific attachment file extensions (such as .apk and .appx) is configured in an Anti-malware policy in Microsoft Defender for Office 365. Anti-malware policies allow you to define file type filters and specify actions like quarantine when those attachments are detected.

Question 60

You have a Microsoft 365 subscription and use Microsoft Defender for Office 365. You need to recommend a solution to educate users on topics that relate to social engineering risks. The users must receive a weekly reminder to complete a learning task. What should you use in the Microsoft Defender portal?

A. Learning hub
B. Campaigns
C. Threat tracker
D. Attack simulation training
Show Answer
Correct Answer: D
Explanation:
Attack simulation training in Microsoft Defender for Office 365 is designed to educate users about social engineering risks. It includes built-in training content, supports assigning learning tasks, and can send automated recurring reminders (such as weekly) to ensure users complete the training. The other options do not provide structured user training with reminders.

Question 61

You have a Microsoft 365 subscription that contains a Microsoft Entra tenant named contoso.com. The tenant includes a user named User1. You plan to use Microsoft Entra ID Protection. You need to ensure that User1 can review the list in Microsoft Entra ID Protection of users flagged for risk. The solution must use the principle of least privilege. To which role should you add User1?

A. Security Reader
B. Reports Reader
C. Service Administrator
D. User Administrator
Show Answer
Correct Answer: A
Explanation:
Microsoft Entra ID Protection risk data is part of security reporting. The Security Reader role allows read-only access to security reports, including users flagged for risk, without granting administrative or configuration permissions. This satisfies the requirement and follows the principle of least privilege. Other roles either lack access (Reports Reader) or grant unnecessary privileges (Service Administrator, User Administrator).

Question 62

You have a Microsoft 365 E5 subscription. The subscription contains users that have the following types of devices: • Windows 11 • Android • iOS To which devices can you apply Endpoint DLP policies?

A. Windows 11 only
B. Windows 11 and Android only
C. Windows 11 and iOS only
D. Windows 11, Android, and iOS
Show Answer
Correct Answer: A
Explanation:
Endpoint Data Loss Prevention (Endpoint DLP) in Microsoft Purview is supported on desktop operating systems, specifically Windows 10/11 (and macOS). It is not supported on mobile platforms such as Android or iOS, which use Intune app protection/MAM instead. Given the listed devices, only Windows 11 can have Endpoint DLP policies applied.

Question 63

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint and Microsoft Intune. All devices run Windows 11 and are Microsoft Entra joined. You are alerted to a zero-day attack. You need to identify which devices were affected by the attack and send a request to Intune administrators to update the affected devices. Which two actions should you perform in the Microsoft Defender portal? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

A. From Threat analytics, view the list of vulnerable devices.
B. From Incidents & alerts, select the latest incident.
C. From Vulnerability management, open the security recommendation.
D. Select the affected devices and request remediation.
Show Answer
Correct Answer: A, D
Explanation:
Threat analytics is used to investigate zero-day threats and view impacted or vulnerable devices associated with the threat. After identifying the affected devices, you can select them and use **Request remediation**, which sends a remediation request to Intune administrators to update or fix those devices.

Question 64

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365. You need to implement a threat policy that will apply a balanced baseline protection profile to protect against spam, phishing, and malware. Solution: You create an anti-phishing policy. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
A balanced baseline protection profile in Microsoft Defender for Office 365 is implemented by using the preset security policies, specifically the Standard protection preset. Creating only an anti-phishing policy does not provide comprehensive baseline protection against spam, phishing, and malware.

Question 65

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint. All the devices in your organization are onboarded to Microsoft Defender for Endpoint. You need to ensure that an alert is generated if malicious activity was detected on a device during the last 24 hours. What should you do?

A. From the Microsoft Purview compliance portal, create a data loss prevention (DLP) policy.
B. From the Microsoft Defender portal, create an alert suppression rule and assign an alert.
C. From Advanced hunting, create a query and a detection rule.
D. From the Microsoft Defender portal, create an Advanced hunting query and a detection rule.
Show Answer
Correct Answer: C
Explanation:
To generate an alert when malicious activity is detected within the last 24 hours, you must create a custom detection. This is done by using Advanced hunting to write a KQL query that looks back 24 hours and then converting that query into a detection rule. Data loss prevention and alert suppression do not create new security alerts, and option D is redundant because Advanced hunting already exists within the Microsoft Defender portal.

Question 66

HOTSPOT - You have a Microsoft 365 E5 subscription. You need to enable passwordless authentication for all users. Which authentication method and portal should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 66
Show Answer
Correct Answer: Authentication method: Microsoft Authenticator Portal: Microsoft Entra admin center
Explanation:
Passwordless authentication in Microsoft 365 is implemented using Microsoft Authenticator (passwordless sign-in with push or FIDO2 support). Configuration and management of authentication methods, including passwordless options, are performed in the Microsoft Entra admin center (formerly Azure AD).

Question 67

HOTSPOT - You have a Microsoft 365 E5 subscription and use Microsoft Defender for Endpoint. The subscription contains Windows 11 devices. You need to create a policy to restrict users from accessing the Device security settings and the Account protection settings in Windows Defender Security Center on the devices. Which type of policy should you create, and which template should you use? To answer, select the appropriate options in the answer area.

Illustration for MS-102 question 67
Show Answer
Correct Answer: Policy type: Endpoint security policy Template: Windows Security Experience
Explanation:
Restricting access to Windows Defender Security Center areas is configured through Intune endpoint security policies. The Windows Security Experience template controls user access to Device security and Account protection settings.

$19

Get all 417 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.