View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps.
Question 181
Which Microsoft 365 service is used to manage Teams-related organizational settings?
- Microsoft Purview portal
- Exchange admin center
- Microsoft Defender portal
- Microsoft Teams admin center
Correct Answer: 4
Explanation
The Microsoft Teams admin center provides administrative controls for Microsoft Teams across an organization. Administrators can manage Teams policies, meeting settings, messaging policies, voice configurations, users, and other Teams-related options depending on their permissions and licensing. The Purview portal focuses on compliance and data governance, Exchange admin center manages Exchange Online, and Defender handles security operations. When an administrator needs to configure organization-wide Teams behavior or policies, the Teams admin center is the appropriate management interface.
Question 182
Which role provides read-only access to administrative information across Microsoft 365 without allowing configuration changes?
- Global Reader
- Global Administrator
- Exchange Administrator
- User Administrator
Correct Answer: 1
Explanation
The Global Reader role provides read-only access to administrative information and settings across Microsoft 365 and Microsoft Entra environments where supported. It is useful for administrators or personnel who need broad visibility for auditing, troubleshooting, or monitoring but should not be able to make configuration changes. Global Administrator provides extensive write permissions, while Exchange Administrator and User Administrator provide more specialized administrative capabilities. Assigning Global Reader instead of a write-enabled role can support least-privilege principles when an individual only needs visibility into the tenant.
Question 183
An organization needs to verify ownership of a custom domain before using it with Microsoft 365. What is typically required?
- Creating a retention label
- Adding a DNS verification record
- Configuring Safe Links
- Creating an access review
Correct Answer: 2
Explanation
Microsoft 365 requires organizations to verify ownership of a custom domain before using it for supported tenant services. Domain verification is commonly completed by adding a specific DNS record, often a TXT record, provided by Microsoft to the organization’s DNS hosting environment. Microsoft checks the record to confirm control over the domain. Retention labels, Safe Links, and access reviews address data governance, URL security, and access management respectively. DNS verification is therefore an essential step when introducing a custom domain into a Microsoft 365 tenant.
Question 184
Which Microsoft 365 feature can help administrators identify applications that have been granted permissions to access organizational data?
- Exchange message trace
- Microsoft Secure Score
- Microsoft Entra enterprise applications
- SharePoint Version History
Correct Answer: 3
Explanation
Microsoft Entra enterprise applications provides management capabilities for applications that users or administrators have integrated with the organization’s identity environment. Administrators can review application configurations, permissions, assignments, and other settings depending on the application type and available controls. This visibility helps organizations understand which applications have access to organizational resources and manage that access appropriately. Message trace investigates email delivery, Secure Score evaluates security posture, and SharePoint Version History tracks document changes. Enterprise applications is therefore the relevant area for application-access administration.
Question 185
What is the primary purpose of Microsoft 365 audit retention settings?
- Configure email authentication
- Manage endpoint compliance
- Assign Microsoft 365 licenses
- Control how long audit records are retained
Correct Answer: 4
Explanation
Audit retention settings determine how long audit records remain available for investigation and compliance purposes, subject to the applicable Microsoft 365 licensing and auditing capabilities. Maintaining audit records for an appropriate period can help organizations investigate historical activities and meet regulatory or internal requirements. Email authentication is handled through mechanisms such as SPF, DKIM, and DMARC, endpoint compliance is associated with Intune, and licensing is managed through Microsoft 365 administration. Audit retention therefore focuses specifically on preserving recorded activity information for an appropriate period.
Question 186
A user needs access to a SharePoint site but should not automatically receive access to unrelated sites. What principle should guide the configuration?
- Least privilege
- High availability
- Data compression
- Load balancing
Correct Answer: 1
Explanation
Least privilege means providing users only the access necessary to perform their responsibilities. Applying this principle to SharePoint permissions helps prevent users from receiving broader access than required. Administrators can assign permissions at appropriate scopes and avoid unnecessarily granting organization-wide or unrelated site access. High availability focuses on service continuity, data compression reduces storage or transmission size, and load balancing distributes workloads. Least privilege is therefore the appropriate principle when configuring SharePoint access so that a user can work with a required site without gaining unrelated permissions.
Question 187
Which Microsoft 365 capability can help administrators investigate potentially unauthorized access to sensitive files?
- Microsoft Forms
- Microsoft Purview Audit
- Microsoft Bookings
- Microsoft 365 group calendar
Correct Answer: 2
Explanation
Microsoft Purview Audit can provide records of supported activities involving files and other Microsoft 365 resources. Administrators can search relevant audit events to investigate actions such as file access, downloads, sharing, or other recorded activities. This can help establish what occurred and which account performed an action. Microsoft Forms, Bookings, and group calendars are productivity features and do not provide centralized audit investigation capabilities. Purview Audit is therefore the appropriate tool for investigating historical activity involving potentially unauthorized access to sensitive files.
Question 188
Which Microsoft Entra capability can automatically provision users to supported applications?
- Access reviews
- Conditional Access
- Application provisioning
- Password writeback
Correct Answer: 3
Explanation
Microsoft Entra application provisioning can automate the creation, updating, and removal of user accounts in supported applications. This reduces manual administration and helps keep application identities synchronized with organizational identity information. For example, when an employee joins or leaves an organization, provisioning workflows can update connected applications according to configured rules. Access reviews evaluate existing access, Conditional Access controls access decisions, and password writeback synchronizes password changes in supported hybrid identity scenarios. Application provisioning is therefore the feature intended for automated application account lifecycle management.
Question 189
An organization wants to require administrator approval before certain users can activate privileged roles. Which capability supports this requirement?
- Microsoft Secure Score
- Exchange Online Protection
- Microsoft Purview Audit
- Microsoft Entra Privileged Identity Management
Correct Answer: 4
Explanation
Microsoft Entra Privileged Identity Management supports controlled activation of eligible privileged roles and can be configured to require approval before activation. Other safeguards can also be applied, including multifactor authentication, justification, and limited activation duration. This approach helps organizations reduce persistent privileged access while ensuring that elevated permissions can be granted when necessary. Secure Score provides security recommendations, Exchange Online Protection protects email, and Purview Audit records activities. PIM is therefore the appropriate capability for approval-based activation of privileged administrative roles.
Question 190
Which Microsoft 365 feature helps administrators monitor important organizational messages about service changes?
- Microsoft 365 message center
- Microsoft Purview eDiscovery
- Exchange mailbox archive
- Microsoft Entra ID Protection
Correct Answer: 1
Explanation
The Microsoft 365 message center provides administrators with communications about service changes, feature updates, planned releases, and other developments that may affect their organization. Reviewing these messages helps administrators understand upcoming changes and prepare users, configurations, or operational processes where necessary. Purview eDiscovery supports compliance investigations, Exchange mailbox archive addresses storage, and Entra ID Protection focuses on identity risk. The message center is therefore the appropriate administrative resource for monitoring important Microsoft 365 service communications and planned changes.
Question 191
Which feature can help prevent users from accessing Microsoft 365 resources when their devices do not meet organizational security requirements?
- Microsoft Purview Audit
- Exchange Online Protection
- Microsoft Entra Conditional Access
- Microsoft 365 group expiration
Correct Answer: 3
Explanation
Microsoft Entra Conditional Access can use device compliance as an access condition when integrated with Microsoft Intune. An organization can create policies requiring devices to meet defined compliance requirements before users are permitted to access selected Microsoft 365 resources. If the device does not satisfy the configured conditions, the policy can block access or apply another supported control. Purview Audit records activities, Exchange Online Protection secures email, and group expiration manages collaborative groups. Conditional Access is therefore the appropriate feature for enforcing device-based access requirements.
Question 192
What is the purpose of Microsoft 365 usage reports?
- Encrypt all Microsoft 365 content
- Provide information about service and user usage
- Replace Microsoft Entra ID
- Configure DNS authentication
Correct Answer: 2
Explanation
Microsoft 365 usage reports provide information about how users and organizations are using various Microsoft 365 services. Depending on the workload, reports can provide information about active users, application usage, collaboration activity, and other service-specific metrics. Administrators can use this information to understand adoption, identify inactive usage, and support administrative planning. Usage reports do not replace Microsoft Entra ID, provide universal encryption, or configure DNS authentication. Their primary purpose is to provide visibility into Microsoft 365 service and user usage patterns.
Question 193
An administrator wants to delegate only password-reset responsibilities for users. Which role is most appropriate?
- Global Administrator
- Exchange Administrator
- User Administrator
- Helpdesk Administrator
Correct Answer: 4
Explanation
The Helpdesk Administrator role is designed to provide support-related administrative capabilities, including resetting passwords for certain users according to the role’s permissions and applicable Microsoft Entra controls. Assigning a specialized support role can reduce the need to grant broad directory permissions to helpdesk personnel. Global Administrator has extensive tenant-wide privileges, Exchange Administrator focuses on Exchange Online, and User Administrator has broader user-management capabilities. For a narrowly scoped password-reset responsibility, a dedicated helpdesk-oriented role better supports least-privilege administration.
Question 194
Which Microsoft 365 feature can help an administrator determine why a message was classified as spam?
- Message trace and anti-spam investigation information
- SharePoint Version History
- Microsoft Intune compliance reports
- Microsoft Entra access reviews
Correct Answer: 1
Explanation
Message trace and available anti-spam investigation information can help administrators understand how Exchange Online processed a message and whether filtering mechanisms affected its delivery. Reviewing the message details and applicable anti-spam results can help identify whether a message was classified as spam, rejected, quarantined, or otherwise handled by email protection policies. SharePoint Version History tracks document changes, Intune reports device compliance, and access reviews evaluate permissions. Email investigation tools are therefore the appropriate choice for troubleshooting a spam-classification issue.
Question 195
Which Microsoft Purview capability is designed to help organizations investigate regulatory or legal matters involving electronic data?
- Microsoft Secure Score
- Microsoft Purview eDiscovery
- Safe Links
- Microsoft Entra Cloud Sync
Correct Answer: 2
Explanation
Microsoft Purview eDiscovery provides capabilities for identifying, collecting, reviewing, and managing electronically stored information relevant to legal or compliance investigations. Authorized users can work with cases and supported data sources to locate information relevant to an investigation according to organizational processes and permissions. Secure Score focuses on security posture, Safe Links protects against malicious URLs, and Entra Cloud Sync synchronizes identities. eDiscovery is therefore the Microsoft Purview capability specifically designed to support investigations involving electronic information for legal, regulatory, or compliance purposes.
Question 196
Which DNS record directs incoming email for a domain to its designated mail server?
- TXT
- CNAME
- MX
- SRV
Correct Answer: 3
Explanation
An MX record identifies the mail servers responsible for receiving email for a domain. When configuring email for a Microsoft 365 domain, the relevant MX record directs incoming mail toward the appropriate Microsoft 365 mail endpoint or configured mail service. TXT records can publish information such as SPF policies, CNAME records provide aliases for supported services, and SRV records identify services and ports for specific protocols. Therefore, the MX record is the DNS record used to specify where incoming email for a domain should be delivered.
Question 197
Which Microsoft 365 security capability can help identify whether an endpoint is affected by a security threat?
- Microsoft Defender for Endpoint
- Microsoft 365 message center
- Microsoft Purview retention
- Exchange Online Archive
Correct Answer: 1
Explanation
Microsoft Defender for Endpoint provides endpoint security capabilities for supported devices. It can help organizations detect, investigate, and respond to threats affecting endpoints, with capabilities that may include threat detection, behavioral analysis, investigation, and response actions depending on licensing and configuration. Message center provides service communications, Purview retention manages data lifecycle requirements, and Exchange Online Archive provides mailbox storage capabilities. Defender for Endpoint is therefore the appropriate Microsoft security solution when administrators need to investigate threats affecting organizational devices.
Question 198
An organization wants to limit access to an application based on the user’s sign-in risk. Which two capabilities work together?
- Exchange Online and DKIM
- Microsoft Entra ID Protection and Conditional Access
- Microsoft Purview and eDiscovery
- SharePoint and retention labels
Correct Answer: 2
Explanation
Microsoft Entra ID Protection can provide risk information associated with users and sign-ins, while Conditional Access can use supported risk conditions to apply access controls. Together, these capabilities allow an organization to respond to potentially risky authentication activity by requiring additional controls or restricting access according to configured policies. Exchange Online and DKIM address email authentication, Purview and eDiscovery address compliance investigations, and SharePoint with retention labels addresses content management. Entra ID Protection and Conditional Access are therefore the relevant combination for risk-based access control.
Question 199
Which administrative control can help ensure that only authorized administrators can perform sensitive Microsoft 365 tasks?
- Privileged role management
- Microsoft 365 calendar
- SharePoint version history
- Exchange mailbox archive
Correct Answer: 1
Explanation
Privileged role management helps organizations control who receives administrative permissions and how those permissions are used. Microsoft Entra Privileged Identity Management can provide eligible role assignments, just-in-time activation, approval requirements, multifactor authentication, and time-limited privileged access depending on configuration. These controls can reduce unnecessary persistent administrative privileges. Calendars, SharePoint version history, and mailbox archives support collaboration or storage functions rather than privileged-access governance. Privileged role management is therefore an important administrative control for protecting sensitive Microsoft 365 operations.
Question 200
A company is reviewing its Microsoft 365 tenant and wants to reduce unnecessary administrative access. Which action directly supports this goal?
- Assign Global Administrator to all IT staff
- Share one privileged account among administrators
- Replace audit logging with manual records
- Review role assignments and remove permissions that are no longer required
Correct Answer: 4
Explanation
Regularly reviewing administrative role assignments and removing permissions that are no longer required directly supports least-privilege administration. As employees change responsibilities, permissions that were previously necessary may become excessive. Periodic reviews help organizations identify unnecessary access and reduce the number of accounts capable of making sensitive changes. Assigning Global Administrator broadly, sharing privileged accounts, or replacing audit logs with manual records can increase security and accountability risks. Reviewing and appropriately reducing administrative permissions is therefore an important part of maintaining a controlled Microsoft 365 environment.