Microsoft MS-102 Practice Test Questions and Exam Dumps Part9 Q161-180

View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps.

Question 161

Which Microsoft 365 feature helps administrators manage users, groups, and licenses from one location?

  1. Microsoft Defender portal
  2. Microsoft Purview portal
  3. Microsoft 365 admin center
  4. Microsoft Intune

Correct Answer: 3

Explanation

The Microsoft 365 admin center provides a centralized administrative experience for common tenant-management tasks. Administrators can manage users, groups, licenses, domains, service settings, and other organization-wide configurations from this interface. Specialized portals provide deeper controls for individual workloads, but the Microsoft 365 admin center acts as a broad starting point for tenant administration. Defender focuses on security, Purview focuses on compliance and governance, and Intune manages devices and applications. Therefore, the Microsoft 365 admin center is the most appropriate choice for centralized user, group, and license administration.

Question 162

What does Microsoft Entra ID primarily provide?

  1. Identity and access management
  2. Email malware scanning
  3. Document retention
  4. Device application deployment

Correct Answer: 1

Explanation

Microsoft Entra ID is Microsoft’s cloud identity and access management service. It provides capabilities for managing users, groups, authentication, application access, roles, and identity-based security policies. Microsoft 365 services rely heavily on Entra ID for authentication and authorization. Email malware protection is provided by security services such as Defender for Office 365, document retention is handled through Microsoft Purview, and application deployment is supported by Intune. Entra ID therefore forms a core identity layer for Microsoft 365 and many other Microsoft cloud services.

Question 163

An organization wants to automatically place users into groups based on their job title. Which feature should be configured?

  1. Retention policy
  2. Dynamic group membership
  3. Message trace
  4. Safe Links

Correct Answer: 2

Explanation

Dynamic group membership allows supported Microsoft Entra groups to automatically include or remove users based on defined attributes. An administrator can create a membership rule using attributes such as job title, department, location, or other supported properties. When the relevant attribute changes, group membership can be updated automatically according to the rule. Retention policies govern data lifecycle, message trace investigates email delivery, and Safe Links protects users from malicious URLs. Dynamic membership is therefore useful when group membership should follow organizational user attributes.

Question 164

Which Microsoft 365 component provides protection against malicious attachments?

  1. Microsoft Secure Score
  2. Safe Attachments
  3. Conditional Access
  4. Access Reviews

Correct Answer: 2

Explanation

Safe Attachments is a Microsoft Defender for Office 365 capability that helps protect users from potentially malicious attachments. It analyzes attachments according to configured policies and can take protective actions before users interact with harmful content. Conditional Access controls access based on identity and other signals, Access Reviews evaluate whether users should retain access, and Secure Score provides security improvement recommendations. Safe Attachments is therefore specifically designed for attachment-based threat protection in supported Microsoft 365 workloads.

Question 165

What is the purpose of a Microsoft 365 retention label?

  1. Classify content and apply retention or disposition settings
  2. Configure Exchange connectors
  3. Manage device enrollment
  4. Detect suspicious sign-ins

Correct Answer: 1

Explanation

Microsoft Purview retention labels allow organizations to apply specific retention and disposition requirements to individual items or groups of content. Labels can help classify information according to organizational policies and determine how long content should be retained or what should happen when a retention period ends. Exchange connectors manage mail flow, device enrollment is associated with endpoint management, and suspicious sign-ins are investigated through identity security capabilities. Retention labels are therefore used to apply targeted data-lifecycle controls to supported content.

Question 166

A security team needs to investigate alerts from multiple Microsoft Defender workloads together. Which solution is designed for this purpose?

  1. Microsoft 365 admin center
  2. Microsoft Defender XDR
  3. SharePoint admin center
  4. Microsoft Purview Audit

Correct Answer: 2

Explanation

Microsoft Defender XDR provides an integrated security experience that can correlate alerts and incidents across supported Defender workloads. This helps security teams investigate related signals and understand broader attack activity instead of reviewing each alert in isolation. The Microsoft 365 admin center focuses on general tenant administration, SharePoint admin center manages SharePoint and OneDrive settings, and Purview Audit focuses on recorded activities. Defender XDR is therefore designed for cross-workload security investigation and response across supported Microsoft security products.

Question 167

Which email authentication technology uses cryptographic signatures to help verify message authenticity?

  1. SPF
  2. DMARC
  3. DKIM
  4. MX

Correct Answer: 3

Explanation

DomainKeys Identified Mail (DKIM) uses cryptographic signatures to help receiving mail systems verify that a message was signed by an authorized sending domain and that relevant signed content has not been altered. The sending organization publishes the public key through DNS, allowing receiving systems to validate the signature. SPF instead evaluates authorized sending sources, while DMARC uses authentication results to apply domain-level policy and reporting. MX records identify mail servers. DKIM is therefore the email-authentication technology specifically associated with cryptographic message signatures.

Question 168

Which feature can require multifactor authentication when users access selected Microsoft 365 applications?

  1. Microsoft Entra Conditional Access
  2. Exchange Online Archive
  3. Microsoft Purview Audit
  4. SharePoint Version History

Correct Answer: 1

Explanation

Microsoft Entra Conditional Access can require multifactor authentication when users access specified applications or resources. Administrators can create policies using conditions such as user, group, application, location, device, or risk and then require controls such as MFA. This provides a flexible way to strengthen authentication for sensitive applications. Exchange Online Archive manages mailbox storage, Purview Audit records activities, and SharePoint Version History tracks document changes. Conditional Access is therefore the appropriate feature for requiring MFA based on defined access conditions.

Question 169

An administrator wants to know whether Microsoft 365 has a known outage affecting users. What should be checked?

  1. Service Health
  2. Access Reviews
  3. Microsoft Entra ID Protection
  4. Retention labels

Correct Answer: 1

Explanation

Microsoft 365 Service Health provides information about service incidents, advisories, and other events that may affect an organization’s Microsoft 365 services. Administrators can use it to determine whether reported problems correspond to a known Microsoft service issue. Access Reviews evaluate user access, Entra ID Protection handles identity risks, and retention labels manage content lifecycle requirements. Service Health is therefore the appropriate place to investigate whether a current Microsoft 365 service problem has already been identified and documented by Microsoft.

Question 170

Which feature helps administrators investigate whether an email reached its recipient?

  1. Microsoft Purview Audit
  2. Exchange Online message trace
  3. Microsoft Secure Score
  4. Microsoft Intune

Correct Answer: 2

Explanation

Exchange Online message trace provides information about the processing and delivery status of email messages. Administrators can use it to investigate whether messages were received, delivered, rejected, deferred, quarantined, or otherwise processed according to available tracking information. This makes it a useful tool for troubleshooting missing or delayed email. Purview Audit focuses on recorded activities, Secure Score evaluates security posture, and Intune manages devices and applications. Message trace is therefore the appropriate tool when the administrator needs to investigate the delivery path of a specific email.

Question 171

What is the main purpose of Exchange Online Protection?

  1. Manage Microsoft 365 licenses
  2. Protect email from spam and malware
  3. Manage device compliance
  4. Create retention labels

Correct Answer: 2

Explanation

Exchange Online Protection (EOP) provides foundational email security for Microsoft 365 organizations. It helps filter unwanted and malicious messages, including spam and malware, before or during delivery to users. EOP is integrated with Exchange Online and forms an important part of the organization’s email protection architecture. License management is handled through Microsoft 365 administration, device compliance is managed through Intune and related services, and retention labels are part of Microsoft Purview. EOP is therefore specifically associated with protecting organizational email from common threats.

Question 172

Which Microsoft Entra capability can help determine whether an identity may have been compromised?

  1. Microsoft Entra ID Protection
  2. Microsoft 365 Service Health
  3. Exchange message trace
  4. SharePoint admin center

Correct Answer: 1

Explanation

Microsoft Entra ID Protection provides risk detection and investigation capabilities for identities and sign-ins. It can identify risk signals that may indicate compromised accounts or suspicious authentication activity and provide information that administrators can use for investigation and response. Service Health monitors Microsoft service availability, message trace investigates email delivery, and SharePoint admin center manages SharePoint and OneDrive settings. Entra ID Protection is therefore the capability specifically designed to help organizations detect and respond to identity-related risks.

Question 173

Which Microsoft Purview capability can identify sensitive data such as credit card numbers?

  1. Microsoft Purview Audit
  2. Sensitive information types
  3. Microsoft Purview eDiscovery
  4. Service Health

Correct Answer: 2

Explanation

Sensitive information types provide detection patterns that Microsoft Purview can use to identify categories of sensitive data within supported content. Built-in types can recognize information such as credit card numbers and other predefined sensitive data patterns, while organizations can also create custom sensitive information types for specialized requirements. Purview Audit records activities, eDiscovery supports investigations, and Service Health provides service-status information. Sensitive information types therefore provide the detection mechanism needed when a compliance policy must recognize particular categories of sensitive information.

Question 174

An administrator wants to prevent ordinary users from receiving unnecessary administrative privileges. Which principle should guide role assignment?

  1. Least privilege
  2. Data residency
  3. High availability
  4. Load balancing

Correct Answer: 1

Explanation

The principle of least privilege means that users and administrators should receive only the permissions required to perform their assigned responsibilities. In Microsoft 365, this principle can be implemented through specialized administrative roles instead of assigning broad privileges such as Global Administrator unnecessarily. Limiting permissions reduces the potential impact of compromised or misused accounts and improves administrative control. Data residency concerns where information is stored, high availability concerns service continuity, and load balancing distributes workloads. Least privilege is therefore the relevant principle for limiting unnecessary administrative access.

Question 175

Which Microsoft 365 feature can help administrators review whether privileged role assignments are still required?

  1. Microsoft Entra access reviews
  2. Microsoft Forms
  3. Exchange Online Protection
  4. Safe Attachments

Correct Answer: 1

Explanation

Microsoft Entra access reviews can help organizations periodically evaluate access assignments and determine whether users should continue to have specific access. Depending on the supported scenario, reviews can be used to assess privileged or other sensitive access and help organizations remove permissions that are no longer required. Microsoft Forms is a productivity tool, Exchange Online Protection protects email, and Safe Attachments protects against malicious files. Access reviews therefore provide a governance mechanism for periodically validating whether sensitive access assignments remain appropriate.

Question 176

Which capability can provide temporary administrative elevation instead of keeping a privileged role permanently active?

  1. Microsoft Entra Privileged Identity Management
  2. Microsoft Secure Score
  3. Exchange Online Protection
  4. Microsoft Purview Audit

Correct Answer: 1

Explanation

Microsoft Entra Privileged Identity Management supports just-in-time activation of eligible privileged roles. Administrators can remain eligible for a role and activate it only when elevated permissions are needed. Organizations can configure additional safeguards such as multifactor authentication, approval, justification, and limited activation duration. Secure Score evaluates security posture, Exchange Online Protection protects email, and Purview Audit records activities. PIM is therefore the Microsoft Entra capability specifically designed to reduce persistent privileged access while still allowing authorized administrators to perform elevated tasks when required.

Question 177

Which Microsoft 365 portal provides tools for investigating phishing, malware, and other security alerts?

  1. Microsoft Purview portal
  2. Microsoft Defender portal
  3. Microsoft 365 admin center
  4. SharePoint admin center

Correct Answer: 2

Explanation

The Microsoft Defender portal provides security operations capabilities for investigating alerts, incidents, threats, and related security activity. Depending on the organization’s licensed services, administrators and security teams can investigate phishing, malware, endpoint threats, and other incidents from the Defender ecosystem. Purview focuses primarily on compliance and data governance, the Microsoft 365 admin center handles general tenant administration, and SharePoint admin center manages SharePoint and OneDrive. The Defender portal is therefore the appropriate security-focused investigation interface for phishing and malware-related alerts.

Question 178

A company wants to prevent users from accidentally sharing sensitive files with external recipients. Which solution is most relevant?

  1. Microsoft Purview DLP
  2. Exchange mailbox archive
  3. Microsoft 365 Service Health
  4. Microsoft Entra Connect Sync

Correct Answer: 1

Explanation

Microsoft Purview Data Loss Prevention can identify sensitive information and apply policies to activities involving that information across supported Microsoft 365 workloads. Depending on the workload and configuration, DLP can warn users or restrict certain sharing actions when sensitive content is being exposed. This can help reduce accidental disclosure of protected information. Exchange mailbox archiving manages storage, Service Health reports service incidents, and Entra Connect Sync synchronizes identities. Purview DLP is therefore the most relevant solution for controlling inappropriate sharing of sensitive organizational content.

Question 179

Which Microsoft 365 capability is used to manage the lifecycle of inactive Microsoft 365 groups?

  1. Safe Links
  2. Microsoft 365 group expiration policy
  3. Message trace
  4. Microsoft Entra ID Protection

Correct Answer: 2

Explanation

Microsoft 365 group expiration policies help organizations manage the lifecycle of groups that may no longer be actively used. When configured, group owners can receive renewal notifications, and groups that are not renewed can proceed through the expiration process according to the organization’s configuration. This helps reduce unnecessary accumulation of inactive collaborative resources. Safe Links protects against malicious URLs, message trace investigates email delivery, and Entra ID Protection focuses on identity risks. Group expiration is therefore the relevant capability for managing inactive Microsoft 365 groups.

Question 180

An administrator needs to determine which user performed a specific administrative action several days ago. Which capability should be checked?

  1. Microsoft Secure Score
  2. Microsoft Purview Audit
  3. Microsoft Intune
  4. Exchange Online Protection

Correct Answer: 2

Explanation

Microsoft Purview Audit provides searchable records of supported activities performed across Microsoft 365 services. When investigating an administrative action, an administrator can use audit information to determine whether the activity was recorded and review details such as the account associated with the event and the time of the action. Secure Score provides security recommendations, Intune manages endpoints, and Exchange Online Protection protects email. Purview Audit is therefore the appropriate capability for investigating historical administrative actions and establishing an activity record.