View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps.
Question 81
Which Microsoft 365 feature can be used to manage organization-wide password expiration and account lockout settings?
- Microsoft Purview
- Microsoft Entra ID
- Microsoft Defender XDR
- Exchange Online
Correct Answer: 2
Explanation
Microsoft Entra ID provides identity and authentication management capabilities for Microsoft 365 users. Depending on the organization’s identity configuration, administrators can manage password-related settings and account controls through Microsoft Entra and associated identity policies. These controls help organizations establish requirements for authentication and account security. Microsoft Purview focuses on compliance and data governance, Defender XDR focuses on security detection and response, and Exchange Online manages email services. Identity-related password and authentication administration therefore belongs primarily within Microsoft Entra ID.
Question 82
An administrator wants to see whether a Microsoft 365 user has been assigned the correct product licenses. Where should the administrator check first?
- Microsoft 365 admin center
- Microsoft Defender portal
- Microsoft Purview portal
- SharePoint admin center
Correct Answer: 1
Explanation
The Microsoft 365 admin center provides administrative tools for managing users and their assigned licenses. An administrator can open the relevant user account and review the products and services assigned to that account. This makes the admin center an appropriate starting point when troubleshooting licensing issues. The Defender portal focuses on security, Purview handles compliance and governance, and SharePoint administration focuses on SharePoint and OneDrive configuration. Reviewing the user’s license assignments through the Microsoft 365 admin center can help identify missing or incorrectly assigned subscriptions.
Question 83
Which Microsoft 365 service helps protect incoming email from spam and malware before delivery?
- Microsoft Intune
- Exchange Online Protection
- Microsoft Purview
- Microsoft Entra ID
Correct Answer: 2
Explanation
Exchange Online Protection (EOP) provides cloud-based email filtering and protection for Microsoft 365 organizations. It helps detect and filter threats such as spam, malware, and other unwanted messages before they reach users’ mailboxes. EOP is integrated with Exchange Online and provides foundational email security capabilities. Microsoft Intune manages devices and applications, Microsoft Purview focuses on compliance and data governance, and Microsoft Entra ID manages identity and access. EOP is therefore the Microsoft 365 service specifically designed for the described inbound email protection function.
Question 84
A user reports that a legitimate email was incorrectly placed in the junk folder. Which investigation should the administrator perform first?
- Review the message trace and applicable anti-spam results
- Review SharePoint site permissions
- Examine device compliance policies
- Search retention labels
Correct Answer: 1
Explanation
When a legitimate message is incorrectly classified as spam, an administrator should investigate the message’s delivery path and filtering results. Message trace can help determine how Exchange Online processed the message, while anti-spam information can provide additional details about filtering decisions. Reviewing these details helps identify whether a policy, reputation signal, or filtering mechanism affected delivery. SharePoint permissions, device compliance, and retention labels address unrelated areas. The combination of message trace and email protection information provides a practical starting point for troubleshooting false-positive spam classifications.
Question 85
What is the primary purpose of Microsoft Intune in a Microsoft 365 environment?
- Manage devices and applications
- Manage email transport rules
- Investigate audit events
- Manage compliance searches
Correct Answer: 1
Explanation
Microsoft Intune is a cloud-based endpoint management service used to manage devices, applications, and related organizational policies. Administrators can use Intune to establish device configuration requirements, deploy applications, manage mobile devices, and support organizational security requirements. Intune can also work with Microsoft Entra Conditional Access to help enforce device-based access decisions. Email transport rules belong primarily to Exchange Online, audit investigation is handled through Microsoft Purview, and compliance searches are associated with Purview capabilities. Intune therefore focuses primarily on endpoint and application management.
Question 86
Which Microsoft 365 capability can automatically remove a user’s license when the user no longer belongs to a licensing group?
- Group-based licensing
- Message trace
- Safe Links
- Retention policy
Correct Answer: 1
Explanation
Group-based licensing can automatically manage license assignments according to group membership. When a user is added to a properly configured licensing group, the assigned license can be applied automatically. When the user is removed from that group, the associated group-based license assignment can also be removed, subject to the tenant’s configuration and other direct assignments. This approach helps administrators automate license lifecycle management. Message trace, Safe Links, and retention policies serve email investigation, URL protection, and data governance functions respectively rather than license management.
Question 87
An organization needs to determine which Microsoft 365 administrators changed a specific tenant setting. Which capability should be used?
- Microsoft Purview Audit
- Microsoft Bookings
- Microsoft Intune
- Microsoft Defender Antivirus
Correct Answer: 1
Explanation
Microsoft Purview Audit can record administrative activities across supported Microsoft 365 services, allowing authorized administrators and compliance personnel to search for relevant events. When investigating a change to a tenant configuration, audit records can help identify the account associated with the action and provide information about when the activity occurred. This can be useful for accountability, security investigations, and troubleshooting unexpected configuration changes. Bookings, Intune, and Defender Antivirus have different purposes and are not the primary centralized source for investigating Microsoft 365 administrative activity.
Question 88
Which DNS record is commonly used to identify authorized mail servers for a domain?
- TXT
- CNAME
- MX
- PTR
Correct Answer: 3
Explanation
An MX, or Mail Exchange, record identifies the mail servers responsible for receiving email for a domain. When configuring a domain for Microsoft 365 email, the appropriate MX record directs incoming messages toward the organization’s designated mail service. TXT records are commonly used for information such as SPF and domain verification, CNAME records provide aliases and are used in several Microsoft 365 configurations, and PTR records support reverse DNS. Therefore, the MX record is the DNS record directly associated with identifying a domain’s receiving mail servers.
Question 89
What does SPF help a receiving mail system determine?
- Whether the sending IP is authorized for the domain
- Whether a user has a valid Microsoft 365 license
- Whether a device is compliant
- Whether a file contains malware
Correct Answer: 1
Explanation
Sender Policy Framework (SPF) helps receiving mail systems determine whether an email was sent from an IP address or mail server authorized by the domain’s SPF policy. The domain owner publishes an SPF record in DNS containing the relevant authorized sending sources. Receiving systems can evaluate that information as part of their email authentication and anti-spoofing decisions. SPF does not verify user licensing, device compliance, or file malware status. Those functions belong to different Microsoft 365 services and security controls.
Question 90
Which Microsoft 365 feature can help administrators manage the lifecycle of inactive Microsoft 365 groups?
- Microsoft 365 group expiration policy
- Exchange message trace
- Safe Attachments
- Microsoft Defender Antivirus
Correct Answer: 1
Explanation
Microsoft 365 group expiration policies help organizations manage the lifecycle of groups that are no longer actively used. When expiration is configured, group owners may receive renewal notifications, and groups that are not renewed can eventually be marked for expiration according to the configured process. This helps reduce the accumulation of obsolete groups and associated resources. Message trace investigates email delivery, Safe Attachments analyzes potentially malicious files, and Defender Antivirus protects endpoints. Group expiration is therefore the relevant capability for managing inactive collaborative groups.
Question 91
An administrator wants users to access Microsoft 365 applications using their existing organizational credentials without maintaining separate application passwords. Which technology supports this?
- Single sign-on
- Data Loss Prevention
- Retention policy
- Message trace
Correct Answer: 1
Explanation
Single sign-on (SSO) allows users to authenticate with an organizational identity provider and then access supported applications without repeatedly entering separate credentials for each application. In Microsoft 365 environments, Microsoft Entra ID provides identity and authentication services that support SSO for many cloud applications. This can improve the user experience while allowing administrators to apply centralized identity and access controls. Data Loss Prevention protects sensitive information, retention policies govern data lifecycle requirements, and message trace investigates email delivery rather than providing application authentication.
Question 92
Which Microsoft 365 capability helps organizations review whether users still need their assigned access to resources?
- Access reviews
- Message trace
- Safe Links
- Exchange archive
Correct Answer: 1
Explanation
Microsoft Entra access reviews help organizations periodically review user access to groups, applications, and other supported resources. Reviewers can confirm whether users still require access and take appropriate actions based on the review results. This is particularly useful for managing guest access, privileged assignments, and membership in sensitive groups. Message trace investigates email delivery, Safe Links protects users from malicious URLs, and Exchange archive manages mailbox storage. Access reviews therefore provide a structured mechanism for validating that existing access remains appropriate over time.
Question 93
A company wants to allow only approved applications to access organizational Microsoft 365 data. Which identity capability is most relevant?
- Microsoft Entra application consent controls
- Exchange Online archiving
- SharePoint version history
- Microsoft Secure Score
Correct Answer: 1
Explanation
Microsoft Entra application consent controls help organizations manage how applications obtain permissions to access organizational data. Administrators can configure consent policies that restrict user consent and require administrative approval for certain application permissions. This provides greater control over third-party and enterprise applications requesting access to Microsoft 365 resources. Exchange archiving manages mailbox storage, SharePoint version history tracks document versions, and Secure Score provides security posture recommendations. Application consent management is therefore the appropriate identity control when organizations need tighter governance over application access.
Question 94
Which Microsoft 365 portal is primarily used to investigate security incidents and alerts?
- Microsoft Defender portal
- Microsoft 365 admin center
- SharePoint admin center
- Exchange admin center
Correct Answer: 2
Explanation
The Microsoft Defender portal provides security teams with tools for investigating alerts, incidents, threats, and security-related activity across supported Microsoft security products. It can bring information from multiple Defender workloads into an integrated investigation experience. The Microsoft 365 admin center is intended for broader tenant administration, while SharePoint and Exchange admin centers focus on their respective services. When an administrator or security analyst needs to investigate security incidents rather than general tenant configuration, the Defender portal is the appropriate primary interface.
Question 95
What is the purpose of Microsoft Purview sensitivity labels?
- Classify and protect sensitive organizational information
- Configure Exchange mailbox quotas
- Manage endpoint hardware
- Route inbound email
Correct Answer: 1
Explanation
Microsoft Purview sensitivity labels help organizations classify and protect information according to its sensitivity. Depending on the configuration and supported workload, labels can apply protection settings such as encryption, access restrictions, or visual markings. They can help users and administrators apply consistent information-protection controls to sensitive content. Mailbox quotas are managed through Exchange-related administration, endpoint hardware management is associated with device-management solutions such as Intune, and inbound email routing is handled through Exchange Online. Sensitivity labels therefore focus on information classification and protection.
Question 96
An administrator needs to investigate whether a user downloaded files from SharePoint. Which Microsoft 365 capability is most appropriate?
- Microsoft Purview Audit
- Microsoft 365 Service Health
- Exchange Online Protection
- Microsoft Secure Score
Correct Answer: 1
Explanation
Microsoft Purview Audit can record supported user activities involving Microsoft 365 services, including relevant SharePoint and OneDrive operations. Administrators can search audit records for activities such as file access, downloads, sharing, and other supported events. This can help establish what actions occurred and which account performed them. Service Health reports service incidents, Exchange Online Protection protects email, and Secure Score evaluates security posture. For an investigation focused on whether a user downloaded files from SharePoint, Purview Audit is the appropriate source to examine.
Question 97
Which Microsoft 365 capability can help detect and investigate insider-related risks involving organizational data?
- Microsoft Purview Insider Risk Management
- Exchange Online Protection
- Microsoft Intune App Protection
- Microsoft 365 Service Health
Correct Answer: 1
Explanation
Microsoft Purview Insider Risk Management is designed to help organizations identify, investigate, and respond to potential insider risks involving organizational information. It can use signals from supported activities and policies to identify potentially risky behavior while incorporating privacy-oriented controls and investigation workflows. Exchange Online Protection focuses on email threats, Intune App Protection applies controls to applications and data on supported devices, and Service Health reports Microsoft service status. Insider Risk Management is therefore the capability specifically associated with identifying potential insider-related data security risks.
Question 98
What is the main purpose of a retention policy in Microsoft Purview?
- Manage how long organizational content is retained or disposed of
- Authenticate incoming email
- Manage Windows device configuration
- Detect endpoint malware
Correct Answer: 4
Explanation
Microsoft Purview retention policies help organizations manage the lifecycle of supported content by specifying how long information should be retained and, where applicable, what should happen when the retention period ends. Retention requirements can support legal, regulatory, and organizational information-governance needs. Retention policies are different from email authentication, device management, and malware protection. SPF and related DNS controls address email authentication, Intune manages devices, and Defender security products detect threats. Purview retention capabilities therefore focus on controlling the lifecycle of organizational data.
Question 99
An organization wants administrators to receive recommendations for improving its Microsoft 365 security posture. Which feature should they review?
- Microsoft Secure Score
- Exchange Online Archive
- Microsoft 365 group calendar
- SharePoint Version History
Correct Answer: 1
Explanation
Microsoft Secure Score provides an assessment of an organization’s security posture and presents recommended actions that can improve security controls. Administrators can review recommendations, determine which changes are appropriate for the organization’s environment, and track improvements over time. Secure Score is not simply an incident investigation system; it is intended to provide security improvement guidance across relevant Microsoft 365 controls. Exchange archiving, group calendars, and SharePoint version history provide storage or collaboration capabilities and do not serve as the primary mechanism for security posture recommendations.
Question 100
Which administrative approach best reduces the risk of unauthorized changes to sensitive Microsoft 365 settings?
- Give all administrators Global Administrator access
- Use specialized roles and require stronger authentication for privileged accounts
- Disable auditing for administrative activities
- Allow administrators to share credentials
Correct Answer: 2
Explanation
Using specialized administrative roles together with stronger authentication for privileged accounts helps reduce the risk associated with highly privileged access. Specialized roles support least-privilege administration by limiting administrators to permissions required for their responsibilities, while strong authentication provides additional protection against credential compromise. Giving every administrator Global Administrator access increases the potential impact of a compromised account. Disabling auditing removes valuable investigation evidence, and credential sharing weakens accountability. A combination of role separation, strong authentication, and appropriate monitoring provides a more controlled administrative model.