View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps.
Question 21
Which Microsoft 365 service provides centralized management for creating and configuring user accounts, groups, licenses, and tenant settings?
- Microsoft Purview
- Microsoft Defender portal
- Microsoft 365 admin center
- Exchange admin center
Correct Answer: 3
Explanation
The Microsoft 365 admin center provides a centralized administrative interface for managing many tenant-level Microsoft 365 tasks. Administrators can manage users, groups, licenses, billing, organizational settings, and service-related configuration from this portal. Although specialized portals exist for workloads such as Exchange, Microsoft Entra, Defender, and Purview, the Microsoft 365 admin center serves as a central location for many common administrative operations. Administrators should use the appropriate specialized portal when a task requires workload-specific configuration or security management.
Question 22
A user leaves the organization. What should the administrator do to prevent the account from being used to access Microsoft 365 resources?
- Increase the mailbox quota
- Block sign-in
- Add a sensitivity label
- Enable Safe Links
Correct Answer: 2
Explanation
Blocking sign-in prevents a user account from authenticating to Microsoft 365 while allowing administrators to retain the account and associated data for appropriate administrative or compliance purposes. During offboarding, administrators should also review licenses, group memberships, mailbox access, application permissions, devices, and other resources associated with the user. The exact offboarding process should follow organizational policy. Simply deleting an account immediately may interfere with retention, investigation, or business continuity requirements, so administrators should carefully coordinate account disablement with other offboarding activities.
Question 23
Which Microsoft 365 role provides broad administrative control over most settings in the tenant?
- Global Administrator
- Helpdesk Administrator
- Reports Reader
- Message Center Reader
Correct Answer: 1
Explanation
The Global Administrator role provides extensive administrative privileges across Microsoft 365 and Microsoft Entra environments. Because the role can affect many critical services and security settings, it should be assigned sparingly and protected with strong authentication and privileged-access controls. Microsoft recommends using more specific administrative roles whenever possible so administrators receive only the permissions required for their responsibilities. Organizations should also monitor privileged activity, review role assignments regularly, and use just-in-time elevation where appropriate to reduce the risks associated with standing global administrative privileges.
Question 24
An administrator wants to determine which Microsoft 365 licenses are currently assigned and how many are still available. Where should the administrator look?
- Microsoft Purview portal
- Billing and license management
- Microsoft Defender portal
- Exchange message trace
Correct Answer: 2
Explanation
Microsoft 365 license management allows administrators to review available subscriptions, assigned licenses, and remaining license capacity. This information is useful when onboarding users, changing licensing assignments, or investigating why a user cannot receive a required service. Administrators should regularly review license utilization to avoid unnecessary costs and ensure critical users have the required service plans. License assignment can be performed individually or through group-based licensing, depending on organizational requirements. Licensing availability also depends on the specific subscriptions purchased by the organization.
Question 25
What is the primary purpose of Exchange Online Protection?
- Manage SharePoint permissions
- Protect email against spam and malware
- Synchronize on-premises identities
- Classify confidential documents
Correct Answer: 2
Explanation
Exchange Online Protection, or EOP, provides cloud-based email protection for Microsoft 365 organizations. It helps defend against threats such as spam, malware, and certain email-based attacks before messages reach users’ mailboxes. EOP also provides mail-flow and protection capabilities that administrators can configure according to organizational requirements. Microsoft Defender for Office 365 can provide additional advanced protection features, including Safe Links and Safe Attachments. Administrators should configure appropriate anti-spam, anti-malware, and mail-flow policies to establish layered email security.
Question 26
An administrator needs to trace a message to determine whether it was delivered, rejected, delayed, or filtered. Which Exchange Online feature should be used?
- Message trace
- Service Health
- Audit log
- Secure Score
Correct Answer: 1
Explanation
Message trace in Exchange Online helps administrators investigate the path and processing status of email messages. It can provide information useful for determining whether a message was received, delivered, rejected, delayed, or otherwise processed by the service. Message trace is particularly valuable when troubleshooting mail-flow problems reported by users. Administrators can use available message details to identify issues involving delivery or filtering. It is different from the Microsoft Purview audit functionality, which focuses more broadly on recording and investigating user and administrative activities.
Question 27
Which Microsoft 365 feature allows administrators to create rules that modify or control messages as they pass through Exchange Online?
- Retention policy
- Mail flow rule
- Sensitivity label
- Conditional Access policy
Correct Answer: 2
Explanation
Exchange Online mail flow rules, also known as transport rules, allow administrators to apply conditions and actions to messages as they move through the organization’s email system. Rules can be used for scenarios such as adding disclaimers, redirecting messages, blocking specific content, applying classifications, or modifying message properties. Administrators should design rules carefully because overlapping conditions or actions can produce unexpected mail-flow behavior. Testing changes before applying them broadly is recommended, particularly in environments with complex routing or regulatory requirements.
Question 28
A company wants users to access Microsoft 365 services from a single identity while maintaining centralized authentication. Which capability supports this requirement?
- Single sign-on
- Data Loss Prevention
- eDiscovery
- Retention management
Correct Answer: 1
Explanation
Single sign-on, or SSO, allows users to authenticate once and then access multiple authorized applications without repeatedly entering credentials. In Microsoft 365 environments, SSO can improve user experience while allowing organizations to centralize identity and authentication controls. SSO does not eliminate the need for strong authentication or access policies. Administrators should combine it with appropriate Conditional Access policies, multifactor authentication, device controls, and identity protection measures. Properly configured SSO can also reduce password-related support requirements and improve consistency across supported applications.
Question 29
Which Microsoft Entra feature can require a compliant device before allowing access to a Microsoft 365 application?
- Administrative units
- Conditional Access
- Group-based licensing
- Access reviews
Correct Answer: 2
Explanation
Conditional Access can evaluate device-related conditions when determining whether a user should be granted access to Microsoft 365 resources. An organization can create policies that require a device to meet defined compliance requirements before access is permitted. Device compliance information can be supplied through supported device-management integrations such as Microsoft Intune. Conditional Access policies can combine multiple conditions, including users, applications, locations, risks, and device state. Administrators should test policies carefully and establish appropriate exclusions to avoid accidentally preventing legitimate administrative or emergency access.
Question 30
A Microsoft 365 administrator needs to review sign-in attempts and determine when users authenticated from suspicious locations. Which log should be examined?
- Microsoft Entra sign-in logs
- Exchange message trace
- SharePoint version history
- Purview retention logs
Correct Answer: 1
Explanation
Microsoft Entra sign-in logs provide information about authentication attempts involving identities in the organization’s directory. Administrators can use these logs to investigate successful and failed sign-ins, authentication methods, applications, locations, devices, and other available details. They are useful when investigating suspicious authentication patterns or troubleshooting access problems. Sign-in logs can also support investigations involving Conditional Access and identity risk. Organizations should establish appropriate retention and monitoring practices because security investigations may require historical authentication information.
Question 31
Which Microsoft 365 capability helps administrators review actions performed by users and administrators for security and compliance investigations?
- Audit
- Service Health
- Secure Score
- Message trace
Correct Answer: 1
Explanation
Microsoft Purview Audit provides audit records that can help organizations investigate activities performed across supported Microsoft 365 services. Depending on the service and configuration, audit records can contain information about activities such as administrative changes, file operations, authentication-related events, and other user actions. Audit data can support security investigations, compliance activities, and internal reviews. Administrators should understand the available audit capabilities, retention periods, permissions, and licensing requirements because the information available can vary according to the organization’s Microsoft 365 configuration and subscription.
Question 32
A compliance team wants to locate electronically stored information relevant to a legal investigation. Which Microsoft Purview capability should be used?
- Microsoft Secure Score
- eDiscovery
- Safe Attachments
- Microsoft Entra ID Protection
Correct Answer: 2
Explanation
Microsoft Purview eDiscovery helps organizations identify, collect, review, and manage electronically stored information relevant to investigations, legal matters, and other supported scenarios. Depending on the available capabilities and licensing, eDiscovery can search across supported Microsoft 365 data sources and provide tools for managing investigation content. Administrators should define appropriate permissions and follow organizational legal and compliance procedures when handling potentially sensitive information. eDiscovery is distinct from retention management because its primary purpose is investigation and discovery rather than simply controlling information lifecycle.
Question 33
Which feature can be used to periodically confirm that users still require access to applications or groups?
- Access reviews
- Safe Links
- Mail flow rules
- Service Health
Correct Answer: 1
Explanation
Microsoft Entra access reviews help organizations periodically review whether users should continue to have access to groups, applications, and other supported resources. Reviewers can confirm or remove access based on current business requirements. This capability supports least privilege and helps reduce the accumulation of outdated permissions. Access reviews are particularly useful for guest users, privileged access, and membership in sensitive groups. Organizations should establish appropriate review frequencies and assign responsible reviewers so that unnecessary access is identified and removed consistently.
Question 34
An organization has many external guest users in Microsoft 365. Which practice can help reduce unnecessary long-term access?
- Access reviews
- Increasing mailbox quotas
- Disabling audit logging
- Creating more global administrators
Correct Answer: 1
Explanation
Access reviews can help organizations periodically evaluate whether guest users should retain access to Microsoft 365 resources. External users may continue to have access after their original collaboration requirement has ended unless organizations actively review their permissions. By establishing recurring reviews, administrators or designated reviewers can confirm legitimate access and remove unnecessary memberships. Guest access should also be governed through appropriate identity policies, lifecycle processes, and monitoring. Combining access reviews with least privilege helps reduce the risk associated with stale external accounts.
Question 35
Which Microsoft 365 capability provides recommendations for improving the security configuration of an organization’s tenant?
- Secure Score
- Message trace
- Exchange archive
- SharePoint recycle bin
Correct Answer: 1
Explanation
Microsoft Secure Score provides security recommendations based on applicable Microsoft 365 security controls and configurations. It can help administrators identify areas where security improvements may be possible and track progress on selected improvement actions. Secure Score is useful as an administrative assessment tool, but organizations should not treat its score as a complete representation of overall cybersecurity risk. Administrators should evaluate recommendations against business requirements, user impact, technical feasibility, licensing, and organizational risk before implementing changes.
Question 36
What should an administrator use to assign permissions to multiple users based on their job responsibilities?
- Role-based access control
- Manual mailbox forwarding
- Message trace
- Retention labels
Correct Answer: 1
Explanation
Role-based access control assigns permissions according to predefined roles and responsibilities. In Microsoft 365 administration, role-based administrative permissions allow organizations to delegate specific management tasks without giving every administrator broad privileges. For example, an administrator may receive permissions for user management without receiving unrestricted security or compliance privileges. This supports least privilege and reduces the risk associated with excessive administrative access. Organizations should define roles carefully, review assignments regularly, and use the most narrowly scoped role that meets each administrator’s responsibilities.
Question 37
A Microsoft 365 administrator needs to delegate only password-reset capabilities to a support employee. What approach should be used?
- Assign Global Administrator
- Assign the appropriate limited administrative role
- Give the employee the user’s password
- Add the employee to every security group
Correct Answer: 2
Explanation
Microsoft 365 provides specialized administrative roles that allow organizations to delegate specific administrative capabilities without granting unrestricted tenant access. For a support employee who only needs to perform password-related tasks, the administrator should select the appropriate limited role rather than assigning Global Administrator privileges. This follows the principle of least privilege and reduces the potential impact of an account compromise or administrative mistake. Role assignments should be reviewed periodically to ensure that support personnel continue to have only the permissions required for their current responsibilities.
Question 38
Which Microsoft 365 portal is primarily used to manage compliance, data governance, retention, and information protection capabilities?
- Microsoft Defender portal
- Microsoft Purview portal
- Microsoft Entra admin center
- Exchange admin center
Correct Answer: 2
Explanation
The Microsoft Purview portal provides administrative capabilities for Microsoft Purview solutions related to compliance, information protection, data governance, risk, and related areas. Depending on licensing and configuration, administrators can manage features such as sensitivity labels, retention, Data Loss Prevention, eDiscovery, audit, and insider risk. Microsoft Purview complements Microsoft Defender, which focuses primarily on security and threat protection. Administrators should assign appropriate permissions for compliance tasks because Purview capabilities can expose sensitive organizational information and investigation data.
Question 39
An organization wants to identify whether Microsoft 365 configuration changes are being made by unauthorized administrators. Which security practice is most useful?
- Audit logging and review
- Disabling administrator accounts
- Removing all security roles
- Increasing user mailbox limits
Correct Answer: 1
Explanation
Audit logging and regular review can help organizations identify administrative activities and investigate potentially unauthorized changes. Microsoft 365 audit capabilities can record relevant activities performed by users and administrators across supported services. Security teams can use these records to establish what happened, which account performed an action, and when the activity occurred, subject to available logging and retention capabilities. Organizations should protect audit information from unauthorized modification and establish monitoring procedures for high-risk administrative activities.
Question 40
A company wants to ensure that administrators use strong authentication when accessing privileged Microsoft 365 roles. Which control should be prioritized?
- Multifactor authentication
- Mailbox delegation
- Email forwarding
- Anonymous sharing
Correct Answer: 1
Explanation
Multifactor authentication provides stronger protection for privileged accounts by requiring authentication evidence from multiple factor categories. Privileged administrators can make changes affecting identities, security controls, data, and services, making their accounts especially valuable targets for attackers. Requiring MFA reduces the risk associated with compromised passwords because an attacker would generally need an additional authentication factor. Organizations should combine MFA with Conditional Access, privileged identity management, strong administrative practices, monitoring, and least-privilege role assignments to provide layered protection for privileged accounts.