Microsoft MS-102 Practice Test Questions and Exam Dumps Part6 Q101-120

View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps.

Question 101

Which Microsoft 365 service is used to manage organizational devices?

  1. Microsoft Purview
  2. Microsoft Intune
  3. Exchange Online
  4. Microsoft Defender for Office 365

Correct Answer: 2

Explanation

Microsoft Intune is a cloud-based service for managing organizational devices, applications, and endpoint policies. Administrators can use Intune to configure supported devices, deploy applications, enforce security requirements, and manage access-related device conditions. Intune can also integrate with Microsoft Entra ID and Conditional Access so that access decisions can consider device compliance. Microsoft Purview focuses on compliance and data governance, Exchange Online provides email services, and Defender for Office 365 protects collaboration and email workloads. Therefore, Intune is the appropriate service for centralized device management.

Question 102

A company wants to require employees to use Microsoft Authenticator for multifactor authentication. Which area should the administrator configure?

  1. Microsoft Entra authentication methods
  2. Exchange transport rules
  3. SharePoint permissions
  4. Purview retention settings

Correct Answer: 1

Explanation

Microsoft Entra authentication methods policies allow organizations to manage which authentication methods users can register and use. Microsoft Authenticator can be enabled and configured as an authentication method, while administrators can control its availability for appropriate users or groups. This supports stronger authentication for Microsoft 365 accounts. Exchange transport rules affect mail flow, SharePoint permissions control access to SharePoint resources, and Purview retention settings govern data lifecycle requirements. Authentication method configuration should therefore be performed within the Microsoft Entra identity and authentication management capabilities.

Question 103

What does Microsoft Entra Conditional Access evaluate before granting access?

  1. Access signals and policy conditions
  2. Only mailbox size
  3. Only SharePoint storage
  4. Only DNS records

Correct Answer: 1

Explanation

Microsoft Entra Conditional Access evaluates signals and conditions associated with a sign-in before applying an access control decision. Depending on the configured policies, these signals can include the user, group, application, device, location, sign-in risk, and other supported conditions. Administrators can then require controls such as multifactor authentication, compliant devices, or other access requirements. Conditional Access is therefore more flexible than a single-factor rule based on mailbox size, SharePoint storage, or DNS information. It provides policy-based access control for supported Microsoft cloud resources.

Question 104

Which tool can help identify directory objects that may cause synchronization problems before they are synchronized to Microsoft Entra ID?

  1. IdFix
  2. Message Trace
  3. Secure Score
  4. Safe Links

Correct Answer: 1

Explanation

IdFix is designed to help administrators identify and remediate common identity-related errors in on-premises Active Directory before synchronization with Microsoft Entra ID. It can detect issues involving attributes such as duplicate values, invalid characters, and formatting problems that could interfere with synchronization. Message Trace is used to investigate email delivery, Secure Score evaluates security posture, and Safe Links protects users from malicious URLs. By identifying directory data problems early, IdFix can help organizations reduce synchronization errors during hybrid identity deployments.

Question 105

An administrator needs to delegate management of users in one department without granting tenant-wide administrative permissions. Which feature is useful?

  1. Administrative units
  2. Mail flow rules
  3. Retention labels
  4. Safe Attachments

Correct Answer: 1

Explanation

Microsoft Entra administrative units allow organizations to define administrative scopes for directory objects. They can be useful when a department, region, campus, or other organizational unit needs delegated administration without granting an administrator unrestricted control over the entire tenant. Appropriate roles can be assigned with a scope associated with the administrative unit. Mail flow rules manage email processing, retention labels support data governance, and Safe Attachments analyzes potentially harmful email attachments. Administrative units therefore provide a mechanism for more limited and structured directory administration.

Question 106

Which feature can help protect users from malicious URLs contained in email messages?

  1. Safe Links
  2. Safe Attachments
  3. Retention policy
  4. Access review

Correct Answer: 1

Explanation

Safe Links is a Microsoft Defender for Office 365 capability designed to provide protection against malicious URLs. It can inspect links and apply configured policies when users interact with URLs in supported Microsoft 365 workloads. Safe Attachments has a different purpose: it evaluates potentially malicious email attachments. Retention policies govern how long data is retained, while access reviews help organizations review user access. Therefore, when the security concern specifically involves harmful links in email or other supported messages, Safe Links is the relevant protection mechanism.

Question 107

Which feature analyzes potentially harmful email attachments?

  1. Safe Links
  2. Safe Attachments
  3. Conditional Access
  4. Access Reviews

Correct Answer: 2

Explanation

Safe Attachments is a Microsoft Defender for Office 365 capability that helps protect organizations from malicious files delivered through email and supported collaboration workloads. It analyzes attachments according to the configured protection policy and can take actions designed to prevent users from interacting with harmful content. Safe Links instead focuses on URLs, while Conditional Access controls access based on identity and other signals. Access Reviews are used to periodically review permissions or memberships. Safe Attachments is therefore specifically suited to protecting users from malicious or suspicious email attachments.

Question 108

An organization wants to control access to corporate resources when a sign-in is detected as risky. Which feature should be configured?

  1. Conditional Access
  2. Exchange Online Archive
  3. SharePoint Version History
  4. Microsoft 365 Service Health

Correct Answer: 1

Explanation

Conditional Access can use sign-in risk as a condition when integrated with Microsoft Entra risk detection capabilities. An organization can create policies that require additional controls or block access when the risk level meets defined criteria. This allows access decisions to respond dynamically to suspicious authentication activity. Exchange Online Archive manages mailbox storage, SharePoint Version History maintains document versions, and Service Health reports Microsoft service status. Conditional Access is therefore the appropriate policy mechanism for applying access controls based on detected sign-in risk.

Question 109

What is the purpose of Microsoft Defender for Office 365?

  1. Protect collaboration and email workloads from security threats
  2. Manage Microsoft 365 billing
  3. Configure organizational domains
  4. Manage SharePoint document versions

Correct Answer: 1

Explanation

Microsoft Defender for Office 365 provides security capabilities for supported Microsoft 365 collaboration and communication workloads. It helps protect organizations against threats such as malicious links, harmful attachments, phishing, and other email-related attacks, depending on the licensed features and configuration. Billing is managed through Microsoft 365 administrative capabilities, domains are managed through tenant administration, and SharePoint version history handles document versions. Defender for Office 365 is therefore primarily focused on protecting users and organizational data from threats delivered through email and collaboration services.

Question 110

Which Microsoft 365 feature can provide recommendations for strengthening security controls?

  1. Microsoft Secure Score
  2. Microsoft 365 Calendar
  3. Exchange Online Archive
  4. SharePoint Version History

Correct Answer: 1

Explanation

Microsoft Secure Score provides organizations with security posture information and recommended improvement actions. Administrators can review recommendations related to identity, devices, data, applications, and other security areas, depending on the services and configuration in use. The recommendations can help administrators identify security controls that may be strengthened and monitor changes in the organization’s posture. Calendar, Exchange archive, and SharePoint version history are productivity or storage features and do not provide the same centralized security improvement guidance.

Question 111

An administrator needs to investigate a suspicious sign-in involving an unusual location. Which data should be reviewed?

  1. Microsoft Entra sign-in logs
  2. Exchange mailbox quota
  3. SharePoint storage metrics
  4. Microsoft 365 billing history

Correct Answer: 1

Explanation

Microsoft Entra sign-in logs contain information about authentication events and can help administrators investigate suspicious access. Depending on the event and available signals, administrators can review details such as the user, application, IP address, location, device, authentication result, and Conditional Access information. These details can help determine whether the sign-in succeeded and what controls were applied. Mailbox quotas, SharePoint storage metrics, and billing information do not provide the necessary authentication context. Sign-in logs are therefore the appropriate starting point for investigating unusual sign-in locations.

Question 112

Which Microsoft 365 capability allows an organization to search recorded activities across supported services?

  1. Microsoft Purview Audit
  2. Microsoft Intune
  3. Exchange Online Protection
  4. Microsoft Entra Connect Sync

Correct Answer: 1

Explanation

Microsoft Purview Audit provides tools for searching and reviewing recorded activities across supported Microsoft 365 services. Audit data can assist with security investigations, compliance reviews, troubleshooting, and accountability. Depending on the workload, administrators can investigate activities such as file operations, administrative changes, sharing events, and other recorded actions. Intune manages devices and applications, Exchange Online Protection protects email, and Microsoft Entra Connect Sync synchronizes identities between environments. Purview Audit is therefore the appropriate capability when the objective is searching recorded user or administrator activities.

Question 113

Which identity feature can automatically add users to a group based on attributes such as department or job title?

  1. Dynamic membership
  2. Manual licensing
  3. Message trace
  4. Mail flow rules

Correct Answer: 1

Explanation

Dynamic membership allows supported Microsoft Entra groups to automatically include or remove users based on defined user or device attributes. An organization could create a rule that includes users whose department equals a particular value or whose job title matches a defined condition. Membership is then evaluated automatically as relevant attributes change. Manual licensing requires administrator action, message trace investigates email delivery, and mail flow rules process messages. Dynamic membership is therefore useful for maintaining groups automatically when organizational attributes determine membership.

Question 114

A company wants to prevent employees from sending documents containing credit card information outside the organization. Which technology should be considered?

  1. Microsoft Purview Data Loss Prevention
  2. Microsoft 365 Service Health
  3. Exchange Online Archive
  4. Microsoft Entra Connect Sync

Correct Answer: 1

Explanation

Microsoft Purview Data Loss Prevention can identify sensitive information types and apply policies designed to prevent or control inappropriate sharing of protected information. Credit card numbers are an example of sensitive information that can be detected using supported sensitive information types. Depending on the workload and policy configuration, DLP can provide policy tips, alerts, or blocking actions for certain activities. Service Health monitors Microsoft service status, Exchange archiving manages mailbox storage, and Entra Connect Sync handles identity synchronization. DLP is therefore the relevant technology for controlling sensitive-data transmission.

Question 115

What is the main function of Microsoft Entra ID Protection?

  1. Detect and help respond to identity risks
  2. Manage SharePoint storage
  3. Configure Exchange connectors
  4. Scan document versions

Correct Answer: 1

Explanation

Microsoft Entra ID Protection helps organizations detect, investigate, and respond to identity-related risks. It can identify risk signals associated with users and sign-ins and provide risk information that can be incorporated into identity security processes. Administrators can use this information alongside other Microsoft Entra capabilities to apply appropriate responses. SharePoint storage management, Exchange connector configuration, and document version control are unrelated functions. Entra ID Protection is specifically focused on protecting identities by identifying potentially compromised users and suspicious authentication activity.

Question 116

Which Microsoft Purview feature helps an organization investigate and manage electronic evidence for legal or compliance matters?

  1. eDiscovery
  2. Safe Links
  3. Secure Score
  4. Device compliance

Correct Answer: 1

Explanation

Microsoft Purview eDiscovery provides capabilities for identifying, collecting, reviewing, and managing electronically stored information relevant to legal or compliance investigations. Authorized users can work with cases and supported data sources to locate potentially relevant content according to organizational procedures and permissions. Safe Links protects against malicious URLs, Secure Score provides security posture recommendations, and device compliance evaluates endpoint requirements. eDiscovery is therefore the Microsoft Purview capability specifically designed to support investigations involving electronically stored information.

Question 117

Which Microsoft 365 feature allows an administrator to trace an email to determine how it was processed?

  1. Message trace
  2. Access review
  3. Audit retention
  4. Device enrollment

Correct Answer: 1

Explanation

Message trace in Exchange Online helps administrators investigate the path and processing of email messages. It can provide information about whether a message was received, delivered, rejected, quarantined, or otherwise processed according to available tracking information. This makes message trace useful when troubleshooting missing messages, delayed delivery, or suspected mail-flow issues. Access reviews concern permissions, audit retention concerns the preservation of audit records, and device enrollment relates to endpoint management. For an email-delivery investigation, message trace is the appropriate administrative tool.

Question 118

An administrator wants to assign a role only when elevated permissions are required instead of keeping the role active permanently. Which capability supports this approach?

  1. Microsoft Entra Privileged Identity Management
  2. Exchange Online Protection
  3. Microsoft Purview retention
  4. SharePoint Version History

Correct Answer: 1

Explanation

Microsoft Entra Privileged Identity Management (PIM) supports just-in-time and controlled access to privileged roles. Instead of keeping elevated permissions permanently active, eligible administrators can activate roles when necessary according to configured requirements and controls. Depending on the configuration, activation can involve multifactor authentication, approval, justification, or time limits. Exchange Online Protection protects email, Purview retention manages data lifecycle requirements, and SharePoint Version History tracks document versions. PIM is therefore the capability designed to reduce persistent privileged access while supporting administrative responsibilities.

Question 119

Which Microsoft 365 capability can help administrators manage external guest access over time?

  1. Microsoft Entra access reviews
  2. Exchange message trace
  3. Safe Attachments
  4. Microsoft Secure Score

Correct Answer: 1

Explanation

Microsoft Entra access reviews can be used to periodically review guest users and determine whether they still require access to organizational resources. Reviewers can assess guest membership and take appropriate action according to organizational policies. This helps reduce the risk of retaining unnecessary external access for long periods. Message trace investigates email delivery, Safe Attachments protects against malicious files, and Secure Score provides security recommendations. Access reviews are therefore particularly useful for maintaining appropriate guest access as collaboration relationships change.

Question 120

Which administrative practice provides the strongest foundation for protecting privileged Microsoft 365 accounts?

  1. Share one administrator account among several employees
  2. Assign broad roles to every support employee
  3. Use dedicated privileged accounts with multifactor authentication and limited roles
  4. Disable sign-in auditing for administrators

Correct Answer: 3

Explanation

Dedicated privileged accounts, multifactor authentication, and appropriately limited administrative roles provide multiple layers of protection for privileged access. Separating administrative activity from normal user activity reduces exposure of elevated credentials, while multifactor authentication adds an additional authentication requirement. Limiting roles reduces the permissions available if an administrative account is compromised. Shared administrator accounts weaken accountability, broad role assignments increase unnecessary privilege, and disabling auditing removes valuable evidence. Combining identity separation, strong authentication, and least-privilege role assignment provides a controlled administrative model.