Microsoft

MS-102 Free Practice Questions — Page 9

Question 78

DRAG DROP - You have a Microsoft 365 E5 subscription that contains two security groups named Group1 and Group2. You need to recommend an authentication solution that meets the following requirements: • Members of Group1 must be able to authenticate by using a hardware token. • Members of Group2 must be able to authenticate by using a public key infrastructure (PKI). Which authentication method should you recommend for each group? To answer, drag the appropriate methods to the correct groups. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 78
Show Answer
Correct Answer: Group1: A FIDO2 security key Group2: Certificate-based authentication
Explanation:
Hardware tokens in Microsoft Entra ID are implemented using FIDO2 security keys. PKI-based authentication is provided through certificate-based authentication.

Question 79

You have a Microsoft 365 E5 subscription. You plan to configure Privileged Identity Management (PIM) for the User Administrator role in Microsoft Entra. You need to ensure that a user can make a role assignment request for the User Administrator role only during the next six months. How should you configure the assignment?

A. Set Assignment type to Eligible.
B. Set Assignment type to Active.
C. Set Allow permanent active to assignment Yes.
D. Set Allow permanent eligible assignment to Yes.
Show Answer
Correct Answer: A
Explanation:
To allow a user to request activation of the User Administrator role only within a defined time window (the next six months), the role must be assigned as **Eligible** with a start and end date. Eligible assignments require the user to make a request to activate the role and can be time-bound. Active assignments grant immediate access without a request, and the permanent assignment settings only control whether assignments can be unlimited in duration, not whether requests are time-limited.

Question 80

You have a Microsoft 365 E5 subscription that contains Windows 11 devices. All the devices are onboarded to Microsoft Defender for Endpoint. You need to compare the configuration of the devices against industry standard benchmarks. What should you use?

A. Initiatives
B. Events
C. Security baselines assessment
D. Attack surface map
Show Answer
Correct Answer: C
Explanation:
Security baselines assessment in Microsoft Defender for Endpoint compares device configurations against industry-standard benchmarks and best-practice security baselines, enabling you to assess compliance and gaps across Windows 11 devices.

Question 81

HOTSPOT - Your company has offices in Montreal, Seattle, and New York City. You have a Microsoft 365 E5 subscription that contains the users shown in the following table. The offices have the IP addresses shown in the following table. From Microsoft Defender for Cloud Apps, you create the activity policy shown in the following exhibit. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 81 Illustration for MS-102 question 81 Illustration for MS-102 question 81 Illustration for MS-102 question 81
Show Answer
Correct Answer: Yes No No
Explanation:
The policy triggers on repeated downloads (≥30 within 1 minute) and matches activities where the Raw IP equals 10.10.0.0/24 or 194.25.2.0/24. • Montreal: Downloads meet the threshold within 1 minute and match the specified IP filter, so an alert is created. • Seattle: Although the IP matches, the rate (1 per second) does not meet the minimum of 30 downloads within any 1‑minute window. • New York City: The IP ranges do not match the policy filter, so no alert is created.

Question 82

HOTSPOT - You have a Microsoft 365 E5 subscription that contains three users named User1, User2, and User3. You use Microsoft Entra ID Protection. You configure the Users at risk detected alerts setting to send an alert when a user risk level of low or above is detected. Users are assigned the risk levels shown in the following table. By the end of the day, how many alerts were generated for User1, and how many alerts were generated for User2 and User3? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 82 Illustration for MS-102 question 82
Show Answer
Correct Answer: User1: 4 User2 and User3: 6
Explanation:
Alerts are triggered when risk is Low or higher, with email notifications throttled to one alert per 5-second window and aggregated across users. User1 generates four distinct alert windows across the day. User2 and User3 together generate six alert windows when considering aggregation and the 5-second suppression rule.

Question 83

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen. You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365. You need to implement a threat policy that will apply a balanced baseline protection profile to protect against spam, phishing, and malware. Solution: You create a Standard preset security policy. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: A
Explanation:
Microsoft Defender for Office 365 preset security policies include two baseline profiles: Standard and Strict. The Standard preset is explicitly designed to provide a balanced level of protection against spam, phishing, and malware. Therefore, creating a Standard preset security policy meets the requirement for a balanced baseline protection profile.

Question 84

HOTSPOT - You have a Microsoft 365 E5 subscription that contains a user named User1. User1 has a Windows 11 device named Device1 that is onboarded to Microsoft Defender for Endpoint. User1 reports that various files were deleted from Device1. You need to create a filter to identify which service deleted the files. Which settings should you configure, and which type of filter should you create in the Microsoft Defender portal? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 84
Show Answer
Correct Answer: Settings: Devices Filter type: Timeline for Device1
Explanation:
File deletion events and the responsible service are investigated from a specific device’s timeline in Microsoft Defender for Endpoint, which is accessed under Devices.

Question 85

HOTSPOT - You have a Microsoft 365 subscription. You integrate Microsoft Defender for Cloud Apps with Microsoft Defender for Endpoint. You need to create a policy to block users from accessing discovered apps that have a risk score of 4 or lower. Which two settings should you configure? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 85
Show Answer
Correct Answer: Apps matching all of the following: Risk score is 4 or lower Governance actions: Tag app as unsanctioned
Explanation:
A Cloud Discovery policy must filter discovered apps by risk score (4 or lower). Tagging the app as unsanctioned integrates with Defender for Endpoint to block user access to those risky apps.

Question 86

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the users shown in the following table. You use Microsoft Entra ID Protection. For the Users at risk detected alerts setting, you configure the following: • Recipient: Admin1 • Alert on user risk level at or above: Medium User1 signs in to Microsoft 365 services and is assigned the detected risk levels shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MS-102 question 86 Illustration for MS-102 question 86 Illustration for MS-102 question 86
Show Answer
Correct Answer: Admin1: No Admin2: Yes Admin3: No
Explanation:
Alerts trigger when user risk is Medium or higher (2:00 PM, 3:00 PM, 4:00 PM → three alerts). Admin1 is the configured recipient, so receives three alerts (not two). Security Readers (Admin2) are automatically included and receive the same three alerts. User Administrators (Admin3) are not included, so receive none.

Question 87

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365. You need to implement a social engineering awareness solution that meets the following requirements: • To reset a user's password, emulate an email message that contains a link. • Track any users that selects the email message link. • Suggest further social engineering training. What should you use in the Microsoft Defender portal?

A. Exposure insights
B. Learning hub
C. Attack simulation training
D. Threat tracker
Show Answer
Correct Answer: C
Explanation:
Attack simulation training in Microsoft Defender for Office 365 allows you to create phishing and social engineering simulations that emulate real emails containing links (such as password reset messages), track which users click the links, and automatically recommend or assign follow-up training based on user behavior. The other options provide insights or content but do not support end-to-end simulation, tracking, and training.

$19

Get all 417 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.