View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps.
Question 141
Which Microsoft 365 capability helps administrators manage organizational domains?
- Microsoft Defender XDR
- Microsoft 365 admin center
- Microsoft Purview Audit
- Microsoft Intune
Correct Answer: 2
Explanation
The Microsoft 365 admin center provides administrative controls for managing domains associated with a Microsoft 365 tenant. Administrators can add domains, verify ownership, and configure relevant domain settings from the tenant administration experience. Domain management is an important part of Microsoft 365 setup because users and services may rely on verified organizational domains. Defender XDR focuses on security operations, Purview Audit records activities, and Intune manages devices and applications. Therefore, the Microsoft 365 admin center is the appropriate starting point for organization-wide domain administration.
Question 142
What is the main purpose of Microsoft Entra Cloud Sync?
- Manage Exchange Online mail flow
- Apply Purview retention policies
- Synchronize selected identities from on-premises Active Directory to Microsoft Entra ID
- Scan Microsoft 365 attachments
Correct Answer: 3
Explanation
Microsoft Entra Cloud Sync provides a lightweight, cloud-managed approach for synchronizing identities from on-premises Active Directory with Microsoft Entra ID. It can be useful for organizations that need hybrid identity synchronization while using an agent-based architecture. Cloud Sync supports scenarios where organizations want identity information to be synchronized to the cloud while maintaining their existing on-premises directory. Exchange mail-flow management, Purview retention, and attachment scanning are separate functions. Cloud Sync is therefore primarily an identity synchronization solution for hybrid Microsoft environments.
Question 143
Which portal is used to manage Microsoft 365 compliance and data governance features?
- Microsoft Purview portal
- Microsoft Defender portal
- Exchange admin center
- Microsoft Intune admin center
Correct Answer: 1
Explanation
The Microsoft Purview portal provides administrative capabilities for compliance, information protection, data governance, auditing, eDiscovery, retention, and related Microsoft 365 compliance functions. Organizations can use it to configure and investigate policies that govern how information is protected and managed. The Defender portal is focused on security threats and incidents, Exchange admin center manages Exchange Online, and Intune admin center handles endpoint and application management. When an administrator needs to configure or investigate Microsoft 365 compliance and governance controls, the Purview portal is the relevant management experience.
Question 144
An organization wants to automatically apply different access restrictions depending on whether a user is accessing Microsoft 365 from a managed or unmanaged device. Which feature should be used?
- Exchange Online Protection
- Microsoft Purview Audit
- Microsoft Entra Conditional Access
- Microsoft 365 group expiration
Correct Answer: 3
Explanation
Microsoft Entra Conditional Access can evaluate device-related conditions and apply different access controls based on the circumstances of a sign-in. Organizations can create policies that require compliant or managed devices for certain applications while applying different controls to unmanaged devices. Depending on the scenario, session controls and other supported restrictions can also be configured. Exchange Online Protection protects email, Purview Audit records activities, and group expiration manages collaborative group lifecycle. Conditional Access is therefore the appropriate feature for applying access decisions based on device state.
Question 145
Which feature can be used to review whether guest users should retain access to organizational resources?
- Microsoft Entra access reviews
- Safe Attachments
- Exchange Online Protection
- Service Health
Correct Answer: 1
Explanation
Microsoft Entra access reviews provide a structured way to periodically evaluate whether users, including guests, should continue to have access to supported resources. Reviewers can examine memberships or assignments and confirm whether access remains necessary. This is particularly useful for organizations that collaborate with external users and want to prevent unnecessary long-term access. Safe Attachments and Exchange Online Protection protect email-related workloads, while Service Health reports Microsoft service incidents. Access reviews therefore provide the appropriate governance mechanism for periodically validating guest access.
Question 146
Which Microsoft 365 feature can be used to apply organization-specific rules to messages as they pass through Exchange Online?
- Microsoft Secure Score
- Exchange mail flow rules
- Microsoft Purview eDiscovery
- Microsoft Entra ID Protection
Correct Answer: 2
Explanation
Exchange Online mail flow rules allow administrators to apply conditions and actions to messages as they move through the organization’s email system. Rules can be used for scenarios such as adding disclaimers, redirecting messages, modifying message properties, or applying other configured actions. Secure Score evaluates security posture, eDiscovery supports investigations, and Entra ID Protection addresses identity risks. Mail flow rules are therefore the appropriate Exchange feature when an organization needs to implement custom processing logic for messages based on defined conditions.
Question 147
A Microsoft 365 administrator wants to identify whether a message was rejected before reaching its intended recipient. Which tool is most appropriate?
- Microsoft Purview Audit
- Microsoft Secure Score
- Exchange Online message trace
- Microsoft Intune
Correct Answer: 3
Explanation
Exchange Online message trace provides information about how email messages were processed within the service. Administrators can use message trace to investigate whether a message was received, delivered, rejected, deferred, or otherwise processed according to available tracking information. This makes it useful for diagnosing delivery failures and understanding the processing path of individual messages. Purview Audit focuses on recorded activities, Secure Score evaluates security posture, and Intune manages devices. Message trace is therefore the appropriate tool for investigating whether an email was rejected during processing.
Question 148
What does Microsoft Defender for Endpoint primarily protect?
- Microsoft 365 billing data
- Endpoints such as computers and supported devices
- Exchange transport configuration
- SharePoint retention schedules
Correct Answer: 2
Explanation
Microsoft Defender for Endpoint provides endpoint security capabilities designed to help protect supported devices from threats. It can provide capabilities such as threat detection, investigation, response, and endpoint security monitoring depending on the organization’s licensing and configuration. Exchange transport configuration belongs to Exchange Online, SharePoint retention requirements are handled through applicable governance controls, and billing is unrelated to endpoint protection. Defender for Endpoint is therefore focused primarily on securing organizational endpoints and helping security teams detect and respond to threats affecting those devices.
Question 149
Which DNS record type is commonly used when publishing an SPF policy?
- MX
- CNAME
- TXT
- PTR
Correct Answer: 3
Explanation
SPF information is commonly published in a DNS TXT record associated with the sending domain. The record identifies authorized mail-sending sources that receiving mail systems can evaluate when checking whether a message originated from an approved source. MX records identify mail servers, CNAME records provide aliases, and PTR records support reverse DNS lookups. SPF is therefore normally published using a TXT record. Administrators configuring Microsoft 365 email authentication should ensure that the domain’s DNS configuration accurately reflects the organization’s authorized sending infrastructure.
Question 150
Which Microsoft 365 security feature evaluates the security posture of a tenant and provides improvement recommendations?
- Microsoft Secure Score
- Exchange Online Protection
- Microsoft Forms
- SharePoint admin center
Correct Answer: 1
Explanation
Microsoft Secure Score evaluates aspects of an organization’s Microsoft security posture and provides recommendations for improving security controls. Administrators can review available improvement actions and determine which recommendations are suitable for their environment. The score and recommendations can help organizations identify areas where additional security measures may be appropriate. Exchange Online Protection focuses on email security, Microsoft Forms supports form creation, and the SharePoint admin center manages SharePoint and OneDrive settings. Secure Score is therefore the feature designed specifically for security posture assessment and improvement guidance.
Question 151
An administrator needs to investigate who changed a SharePoint site’s sharing configuration. Which capability should be used?
- Microsoft Intune
- Microsoft Purview Audit
- Exchange Online Protection
- Microsoft 365 Service Health
Correct Answer: 2
Explanation
Microsoft Purview Audit can record supported activities performed within Microsoft 365 services, including relevant SharePoint administrative and user actions. By searching appropriate audit records, administrators can investigate activities associated with changes to SharePoint resources and determine which account performed a recorded action. Intune manages endpoints, Exchange Online Protection protects email, and Service Health reports service incidents. Audit records are therefore the appropriate source when investigating historical activity involving SharePoint configuration or sharing changes.
Question 152
Which Microsoft 365 capability can help an organization control access to sensitive information when users work with unmanaged devices?
- Microsoft Entra Conditional Access
- Exchange mailbox archive
- DKIM
- Microsoft 365 group expiration
Correct Answer: 1
Explanation
Microsoft Entra Conditional Access can apply access and session controls based on device conditions. For unmanaged devices, organizations can configure policies that restrict access or apply supported session controls to reduce the risk of sensitive information being downloaded or accessed without appropriate device protections. The exact controls depend on the application, licensing, and configuration. Exchange archiving manages mailbox storage, DKIM supports email authentication, and group expiration manages Microsoft 365 group lifecycle. Conditional Access is therefore the relevant capability for device-aware access decisions.
Question 153
What is the purpose of an Exchange Online connector?
- To synchronize user passwords
- To create Microsoft 365 groups
- To establish controlled mail flow between Microsoft 365 and another email system
- To apply sensitivity labels
Correct Answer: 3
Explanation
Exchange Online connectors are used to configure controlled mail flow between Microsoft 365 and external or specialized email systems. Organizations may use connectors when messages need to pass between Microsoft 365 and another mail environment, security appliance, trusted partner, or application. Connector configuration can establish how messages are routed and under what conditions communication is accepted. Password synchronization is handled through identity technologies, Microsoft 365 groups support collaboration, and sensitivity labels are managed through Purview. Connectors are therefore specifically associated with controlled email-system integration.
Question 154
Which role is designed to provide administrative access to Exchange Online without granting all tenant-wide privileges?
- Global Administrator
- Exchange Administrator
- Billing Administrator
- Global Reader
Correct Answer: 2
Explanation
The Exchange Administrator role provides permissions for managing Exchange Online while avoiding the broader privileges associated with the Global Administrator role. Using workload-specific roles supports least-privilege administration because administrators can receive permissions appropriate to their responsibilities. Global Administrator has extensive control across the Microsoft 365 environment, Billing Administrator focuses on billing-related tasks, and Global Reader provides broad read-only visibility. For administrators responsible specifically for Exchange Online, the Exchange Administrator role is the more targeted administrative assignment.
Question 155
A company wants to prevent users from consenting to applications that request high-risk permissions. Which Microsoft Entra capability should be reviewed?
- Application consent policies
- Exchange archive policies
- Safe Attachments
- SharePoint version history
Correct Answer: 1
Explanation
Microsoft Entra application consent policies allow organizations to control how users can consent to applications requesting access to organizational data. Administrators can restrict user consent and require administrative approval for applications or permissions that present greater risk. This helps reduce the possibility that users unintentionally grant applications excessive access to organizational resources. Exchange archive policies manage mailbox storage, Safe Attachments protects against malicious files, and SharePoint version history tracks document changes. Application consent controls are therefore the appropriate identity-management capability for this scenario.
Question 156
Which Microsoft Purview feature can help preserve and manage information that must be retained for compliance reasons?
- Microsoft Secure Score
- Retention policies
- Safe Links
- Microsoft Entra Connect Sync
Correct Answer: 2
Explanation
Microsoft Purview retention policies help organizations manage how long supported content should be retained and, where applicable, how it should be handled when the retention period ends. These policies can support organizational, legal, and regulatory requirements for information retention. Secure Score provides security recommendations, Safe Links protects against malicious URLs, and Entra Connect Sync synchronizes identities. Retention policies are therefore the relevant Purview capability when an organization needs to establish systematic requirements for keeping organizational information for defined periods.
Question 157
Which Microsoft 365 capability provides information about upcoming changes that administrators may need to prepare for?
- Microsoft 365 message center
- Exchange message trace
- Microsoft Purview Audit
- Microsoft Entra ID Protection
Correct Answer: 1
Explanation
The Microsoft 365 message center provides administrators with communications about upcoming changes, new features, planned updates, and other service developments that may affect their organization. Reviewing these messages helps administrators understand changes and prepare users, configurations, or processes when action is required. Exchange message trace is used for email investigation, Purview Audit records activities, and Entra ID Protection addresses identity risks. Message center is therefore the appropriate Microsoft 365 administrative resource for monitoring important service announcements and upcoming changes.
Question 158
An organization wants to use a centralized system to manage Windows device configuration, compliance, and application deployment. Which service should be used?
- Microsoft Purview
- Microsoft Defender XDR
- Microsoft Intune
- Exchange Online
Correct Answer: 3
Explanation
Microsoft Intune provides centralized cloud-based management for supported devices, applications, and endpoint policies. Administrators can configure device settings, establish compliance policies, deploy applications, and manage organizational endpoints through Intune. It can also work with Microsoft Entra Conditional Access to use device compliance as part of access decisions. Purview manages compliance and information governance, Defender XDR provides security investigation capabilities, and Exchange Online manages email services. Intune is therefore the service most directly suited to centralized device configuration, compliance management, and application deployment.
Question 159
Which Microsoft 365 feature can help identify configuration changes made by administrators?
- Microsoft Purview Audit
- Exchange Online Archive
- Microsoft Forms
- Safe Links
Correct Answer: 1
Explanation
Microsoft Purview Audit can record supported administrative activities across Microsoft 365 services. Audit searches can help administrators and compliance personnel investigate changes made to supported configurations and determine which account performed a recorded action. This provides an important source of accountability and investigation evidence. Exchange Online Archive handles mailbox storage, Microsoft Forms supports form creation, and Safe Links protects users from malicious URLs. When the objective is to investigate historical administrative actions, Purview Audit is therefore the appropriate capability to review.
Question 160
Which approach best supports secure administration of a Microsoft 365 tenant?
- Use one shared Global Administrator account for all administrators
- Give every administrator unrestricted access
- Disable audit logging to reduce administrative overhead
- Use role-based permissions, privileged account protection, and regular access reviews
Correct Answer: 4
Explanation
Secure Microsoft 365 administration benefits from multiple complementary controls. Role-based permissions help apply least privilege, privileged account protection reduces exposure of highly sensitive administrative credentials, and regular access reviews help verify that administrators still require their assigned permissions. A shared Global Administrator account weakens accountability, unrestricted access increases unnecessary privilege, and disabling audit logging removes valuable evidence for investigations. Combining role separation, strong privileged-access controls, and periodic reviews provides a structured approach to reducing administrative risk while maintaining the permissions necessary for operational responsibilities.