Microsoft

MS-102 Free Practice Questions — Page 7

Question 63

HOTSPOT - You have an on-premises server named Server1 that runs Windows Server. Server1 is used to access a software as a service (SaaS) app named App1. You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps, Microsoft Defender XDR, Microsoft Defender for Endpoint, and Microsoft Defender for Identity. You configure Cloud Discovery for App1 and Server1. You need to meet the following requirements: • Tag Server1 as a high-value device. • Ensure that an alert is triggered when App1 is accessed. What should you do for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 63
Show Answer
Correct Answer: Tag Server1 as a high-value device: Create a critical asset classification in Microsoft Defender XDR. Ensure that an alert is triggered when App1 is accessed: Tag App1 in Defender for Cloud Apps.
Explanation:
High-value devices are designated through the unified critical asset classification in Defender XDR. For cloud app access alerts, tagging the app in Defender for Cloud Apps (for example, as unsanctioned) enables alerting when the app is accessed.

Question 64

You have a Microsoft 365 subscription that includes Microsoft Defender XDR. From the Microsoft Defender portal, you review the Microsoft Secure Score improvement actions shown in the following table. You plan to update the status of the improvement actions as shown in the following table. How many points will the Secure Score increase after the update?

A. 0
B. 4
C. 7
D. 13
E. 16
Show Answer
Correct Answer: B
Explanation:
Changing an improvement action to 'Resolved through third party' grants the action's Secure Score points because the risk is considered mitigated by an alternate solution. Marking an action as 'Risk accepted' does not award Secure Score points, and marking an action as 'Planned' also does not increase the score. Therefore, only the 4-point action contributes, for a total increase of 4 points.

Question 65

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint. All the devices in your organization are onboarded to Microsoft Defender for Endpoint. You need to ensure that an alert is generated if malicious activity was detected on a device during the last 24 hours. What should you do?

A. From the Microsoft Defender portal, create an alert suppression rule and assign an alert.
B. From the Microsoft Purview compliance portal, create an audit log search.
C. From the Microsoft Purview compliance portal, create a data loss prevention (DLP) policy.
D. From the Microsoft Defender portal, create an Advanced hunting query and a detection rule.
Show Answer
Correct Answer: D
Explanation:
Create an Advanced hunting query and convert it into a custom detection rule in the Microsoft Defender portal. Detection rules run on a schedule (such as looking back over the last 24 hours) and generate alerts when the query identifies matching malicious activity. Alert suppression reduces or hides alerts rather than creating them, while Purview audit log searches and DLP policies do not generate Microsoft Defender for Endpoint malware detection alerts.

Question 66

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. You are reviewing the activity log of the subscription. You need to ensure that events originating from the on-premises network are categorized automatically as Administrative. What should you create?

A. a critical asset classification
B. an indicator for IP addresses
C. an IP address range
D. a named location
Show Answer
Correct Answer: C
Explanation:
In Microsoft Defender for Cloud Apps, you create IP address ranges and assign them a Category such as Administrative, Corporate, VPN, Cloud Provider, or Risky. Activities originating from those IP ranges are then automatically categorized in the activity log. Named locations are an Entra ID feature and do not provide the Defender for Cloud Apps Administrative category.

Question 67

You have a Microsoft 365 tenant. You plan to manage incidents in the tenant by using the Microsoft Defender XDR. Which Microsoft service source will appear on the Incidents page of the Microsoft Defender portal?

A. Microsoft Purview
B. Azure Arc
C. Microsoft Defender for Cloud
D. Microsoft Defender for Identity
Show Answer
Correct Answer: C, D
Explanation:
The Microsoft Defender portal Incidents page can show incidents from multiple integrated service sources. Both Microsoft Defender for Cloud and Microsoft Defender for Identity are valid service sources that appear in the Service source filter. Azure Arc is not an incident source, and Microsoft Purview as a whole is not the service source label used here (specific Purview workloads such as DLP or Insider Risk are separate integrations). Sources: https://learn.microsoft.com/en-us/defender-xdr/incidents-overview https://learn.microsoft.com/en-us/defender-xdr/manage-incidents https://learn.microsoft.com/en-us/defender-xdr/dlp-investigate-alerts-defender

Question 68

DRAG DROP - You have a Microsoft 365 E5 subscription that contains two security groups named Group1 and Group2. You need to recommend an authentication solution to meet the following requirements: • Administrators must be able to generate a time-limited code to allow the members of Group1 to authenticate without using their password. • The members of Group2 must be able to authenticate by confirming a two-digit code on their mobile device. Which authentication method should you recommend for each group? To answer, drag the appropriate methods to the correct groups. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 68
Show Answer
Correct Answer: Group1: A Temporary Access Pass Group2: Microsoft Authenticator
Explanation:
A Temporary Access Pass (TAP) is a time-limited passcode that administrators can issue to let users sign in without their password. Microsoft Authenticator supports passwordless phone sign-in with number matching, where users confirm a two-digit code on their mobile device.

Question 69

You have a Microsoft 365 E5 subscription. The subscription contains users that have Windows 11 devices. You plan to onboard the devices to Microsoft Defender for Endpoint. The devices will connect to Defender for Endpoint through a proxy service. You need to ensure that the devices use consolidated URLs and static IP ranges when connecting to Defender for Endpoint. What should you do?

A. Use the standard connectivity type.
B. Use the streamlined connectivity type.
C. Configure a device group.
D. Enable device discovery.
Show Answer
Correct Answer: B
Explanation:
The streamlined connectivity type is designed for Microsoft Defender for Endpoint environments that require simplified networking, including consolidated service URLs and support for static IP ranges, making it appropriate for devices connecting through a proxy. The standard connectivity type uses a broader set of endpoints, while device groups and device discovery do not control endpoint connectivity.

Question 70

You have an on-premises server named Server1 that runs Windows Server. You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. You plan to configure Cloud Discovery and enable automatic log upload. You need to ensure that you can run the log collector on Server1. What should you install on Server1?

A. the Microsoft Graph PowerShell SDK
B. .NET Framework 4.8
C. Docker
D. the Azure Connected Machine agent
Show Answer
Correct Answer: C
Explanation:
For Microsoft Defender for Cloud Apps Cloud Discovery, the log collector is deployed as a Docker container. Therefore, the on-premises Windows Server must have Docker installed to run the log collector. The other options are not a prerequisite for running the log collector.

Question 71

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription. You integrate Microsoft Defender for Endpoint with Microsoft Intune. You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune. Solution: You create a compliance policy. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
Creating a compliance policy does not onboard devices to Microsoft Defender for Endpoint. Automatic onboarding for Intune-enrolled devices is configured by enabling the Microsoft Defender for Endpoint connection and using the Endpoint security/Defender for Endpoint onboarding settings, not by a compliance policy.

Question 72

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription. You are implementing Microsoft Defender for Cloud Apps. You need to ensure that you can create OAuth app policies. Solution: You connect Microsoft 365 to Defender for Cloud Apps. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: A
Explanation:
OAuth app policies in Microsoft Defender for Cloud Apps require the relevant SaaS application (such as Microsoft 365/Office 365) to be connected so Defender for Cloud Apps can discover OAuth-authorized applications. Connecting Microsoft 365 enables OAuth app visibility and allows creation of OAuth app policies.

$19

Get all 430 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.