Microsoft MS-102 Practice Test Questions and Exam Dumps Part11 Q201-220

View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps.

 

Question 201

Which Microsoft 365 service provides centralized administration for user accounts, groups, licenses, and tenant settings?

  1. Microsoft Defender portal
  2. Microsoft 365 admin center
  3. Microsoft Purview portal
  4. Microsoft Intune

Correct Answer: 2

Explanation

The Microsoft 365 admin center provides a centralized interface for managing many organization-wide Microsoft 365 administrative tasks. Administrators can manage users, groups, licenses, domains, service settings, and other tenant-level configurations from this portal. Specialized portals provide deeper controls for particular workloads, but the Microsoft 365 admin center is commonly used as the central administrative starting point. Defender focuses on security operations, Purview handles compliance and governance, and Intune manages devices and applications. Therefore, the Microsoft 365 admin center is the appropriate choice for broad tenant administration.

Question 202

An organization has users in multiple departments and wants each department’s users to receive different Microsoft 365 licenses automatically. Which approach is appropriate?

  1. Message trace
  2. Group-based licensing with appropriate groups
  3. Safe Links
  4. Microsoft Purview Audit

Correct Answer: 2

Explanation

Group-based licensing can automate license assignment by associating Microsoft 365 licenses with groups whose membership represents organizational requirements. For example, separate groups can be created for different departments, with each group receiving the licenses required by its members. As users are added to or removed from these groups, the applicable group-based license assignments can be managed automatically. Message trace investigates email delivery, Safe Links protects against malicious URLs, and Purview Audit records activities. Group-based licensing is therefore the appropriate approach for department-based automated licensing.

Question 203

Which Microsoft Entra feature can restrict access to Microsoft 365 based on user location?

  1. Conditional Access
  2. Exchange Online Protection
  3. Retention labels
  4. Microsoft Secure Score

Correct Answer: 1

Explanation

Microsoft Entra Conditional Access can use location as one of the conditions evaluated during an authentication attempt. Administrators can define named locations and create policies that apply different access controls based on whether a sign-in originates from an approved or restricted location. This can help organizations enforce geographic or network-based access requirements. Exchange Online Protection protects email, retention labels manage content lifecycle, and Secure Score provides security recommendations. Conditional Access is therefore the Microsoft Entra capability used to apply location-based access policies.

Question 204

What is the primary function of Microsoft Purview Data Loss Prevention?

  1. Manage device enrollment
  2. Protect sensitive information from inappropriate use or sharing
  3. Configure DNS records
  4. Manage Teams meetings

Correct Answer: 2

Explanation

Microsoft Purview Data Loss Prevention helps organizations identify sensitive information and apply policies that can prevent or control inappropriate activities involving that information. Depending on the workload and configuration, DLP can provide notifications, policy tips, alerts, or restrictions when users attempt actions that could expose sensitive content. Device enrollment is handled by Intune, DNS configuration is managed through domain and DNS administration, and Teams meetings are configured through Teams-related settings. DLP is therefore primarily concerned with protecting sensitive information from inappropriate handling or disclosure.

Question 205

Which Microsoft 365 feature can help administrators investigate activities performed on OneDrive files?

  1. Microsoft Purview Audit
  2. Microsoft Secure Score
  3. Exchange Online Protection
  4. Microsoft Entra Cloud Sync

Correct Answer: 1

Explanation

Microsoft Purview Audit records supported activities across Microsoft 365 workloads, including relevant OneDrive activities. Administrators can search audit records for events such as file access, sharing, downloads, modifications, or other supported actions. This information can assist with security investigations, compliance reviews, and troubleshooting. Secure Score evaluates security posture, Exchange Online Protection protects email, and Entra Cloud Sync synchronizes identities. When the investigation concerns historical activity involving OneDrive files, Purview Audit is therefore the appropriate capability to examine.

Question 206

An administrator wants to allow a user to manage Exchange settings but not manage Microsoft Entra users. Which role is most appropriate?

  1. Global Administrator
  2. User Administrator
  3. Exchange Administrator
  4. Global Reader

Correct Answer: 3

Explanation

The Exchange Administrator role provides permissions for managing Exchange Online without granting the broader directory-management capabilities associated with roles such as Global Administrator or User Administrator. Assigning a workload-specific role supports least privilege because the administrator receives permissions aligned with the actual job responsibility. Global Administrator has extensive tenant-wide privileges, User Administrator manages users and groups, and Global Reader provides read-only access. Therefore, an administrator whose responsibilities are limited to Exchange Online should generally receive the Exchange Administrator role.

Question 207

Which capability can require approval before a privileged Microsoft Entra role becomes active?

  1. Microsoft Purview Audit
  2. Microsoft Entra Privileged Identity Management
  3. Exchange Online Protection
  4. Microsoft 365 Service Health

Correct Answer: 2

Explanation

Microsoft Entra Privileged Identity Management supports controlled activation of eligible privileged roles. Organizations can configure approval requirements so that an administrator must obtain authorization before activating certain elevated permissions. Additional controls can include multifactor authentication, justification, and limited activation periods. Purview Audit records activities, Exchange Online Protection protects email, and Service Health reports Microsoft service issues. PIM is therefore the appropriate capability when an organization wants privileged role activation to require an approval workflow rather than leaving elevated permissions permanently active.

Question 208

Which email authentication method publishes authorized sending servers in DNS?

  1. SPF
  2. DKIM
  3. DMARC
  4. Message trace

Correct Answer: 1

Explanation

Sender Policy Framework (SPF) allows a domain owner to publish information identifying authorized email-sending sources. This information is normally published in a DNS TXT record, and receiving mail systems can use it when evaluating whether a message originated from an authorized source. DKIM uses cryptographic signatures, while DMARC defines policy and reporting around authentication results. Message trace is an Exchange Online investigation tool rather than an email-authentication mechanism. SPF is therefore the authentication technology specifically associated with publishing authorized sending servers or sources.

Question 209

What does Microsoft 365 Defender’s incident view help security teams understand?

  1. Related security alerts and investigation context
  2. User license expiration dates
  3. SharePoint storage quotas
  4. Microsoft 365 billing invoices

Correct Answer: 1

Explanation

Microsoft Defender’s incident view can group and correlate related security alerts to provide broader investigation context. Instead of treating every alert as an isolated event, security teams can review related signals and investigate the activity as a potential security incident. This can improve visibility into the scope and relationships between detected threats. License expiration, SharePoint storage, and billing information are handled through other administrative systems. The Defender incident view is therefore primarily designed to support security investigation and response by bringing related security information together.

Question 210

Which feature can automatically remove users from a dynamic group when they no longer meet the membership rule?

  1. Exchange transport rule
  2. Dynamic group membership
  3. Retention policy
  4. Safe Attachments

Correct Answer: 2

Explanation

Dynamic group membership is evaluated against configured rules based on supported user or device attributes. When an object no longer satisfies the membership criteria, it can be removed from the dynamic group automatically. This allows group membership to remain aligned with changing organizational information without requiring administrators to manually update every membership change. Exchange transport rules process email, retention policies govern information lifecycle, and Safe Attachments analyzes potentially malicious files. Dynamic membership is therefore the capability designed for automatic attribute-based group membership changes.

Question 211

An organization wants to review whether external guests still require access to a sensitive Microsoft 365 group. Which feature should be used?

  1. Microsoft Entra access reviews
  2. Microsoft Secure Score
  3. Exchange message trace
  4. Microsoft 365 Service Health

Correct Answer: 1

Explanation

Microsoft Entra access reviews provide a structured way to periodically evaluate whether users should continue to have access to supported resources. They are especially useful for reviewing guest access to groups and applications because external users may retain access after a collaboration requirement has ended. Reviewers can evaluate current membership and take appropriate action according to organizational policies. Secure Score provides security recommendations, message trace investigates email delivery, and Service Health reports service incidents. Access reviews are therefore the relevant feature for recurring guest-access validation.

Question 212

Which Microsoft 365 feature helps administrators identify suspicious identity-related sign-ins?

  1. Microsoft Entra ID Protection
  2. SharePoint Version History
  3. Exchange Online Archive
  4. Microsoft Forms

Correct Answer: 1

Explanation

Microsoft Entra ID Protection provides capabilities for detecting and investigating identity-related risks. It uses available risk signals associated with users and sign-ins to identify potentially suspicious authentication activity and compromised identities. Administrators can use the resulting risk information with other Microsoft Entra controls to determine appropriate responses. SharePoint Version History tracks document changes, Exchange Online Archive provides mailbox storage, and Microsoft Forms supports form creation. Entra ID Protection is therefore the Microsoft 365 identity-security capability specifically designed for detecting and responding to identity risks.

Question 213

Which Microsoft Purview feature can help classify organizational information based on sensitivity?

  1. Message trace
  2. Sensitivity labels
  3. Safe Links
  4. Device enrollment

Correct Answer: 2

Explanation

Microsoft Purview sensitivity labels allow organizations to classify information according to its sensitivity and apply appropriate protection settings. Depending on the configuration and supported workload, labels can be associated with controls such as encryption, access restrictions, or markings. This helps organizations apply consistent protection to sensitive information. Message trace investigates email delivery, Safe Links protects against malicious URLs, and device enrollment is an endpoint-management function. Sensitivity labels are therefore the appropriate Purview capability when an organization needs to classify and protect information based on sensitivity.

Question 214

A user reports that an email is missing. Which tool should an administrator use first to investigate its delivery status?

  1. Microsoft Purview eDiscovery
  2. Microsoft Entra ID Protection
  3. Exchange Online message trace
  4. Microsoft Secure Score

Correct Answer: 3

Explanation

Exchange Online message trace is designed to investigate how email messages were processed through the service. Administrators can use it to determine whether a message was received, delivered, rejected, deferred, quarantined, or otherwise processed according to available tracking information. This makes it an appropriate first step when troubleshooting a missing message. Purview eDiscovery supports broader compliance investigations, Entra ID Protection addresses identity risk, and Secure Score evaluates security posture. Message trace is therefore the most directly relevant tool for determining the delivery status of a specific email.

Question 215

Which Microsoft 365 service can help manage Windows application deployment and device configuration?

  1. Microsoft Purview
  2. Microsoft Intune
  3. Exchange Online
  4. Microsoft Defender portal

Correct Answer: 2

Explanation

Microsoft Intune provides cloud-based management for devices and applications. Administrators can use Intune to deploy supported applications, configure device policies, establish compliance requirements, and manage organizational endpoints. Intune can also integrate with Microsoft Entra identity controls to support device-based access decisions. Purview manages compliance and information governance, Exchange Online provides email services, and Defender provides security capabilities. When the requirement involves centralized application deployment and device configuration, Microsoft Intune is the appropriate Microsoft 365 service.

Question 216

Which DNS record is normally used to publish a domain’s DKIM public key?

  1. MX
  2. TXT
  3. PTR
  4. A

Correct Answer: 2

Explanation

DKIM public keys are published in DNS, commonly through TXT records associated with the DKIM selector for the domain. When receiving mail systems validate a DKIM signature, they can retrieve the corresponding public key from the published DNS record. MX records identify mail servers, PTR records support reverse DNS, and A records map hostnames to IPv4 addresses. Therefore, TXT records are commonly used to publish DKIM public-key information. Correct DNS configuration is an important part of implementing domain-based email authentication.

Question 217

Which Microsoft 365 feature provides administrators with a central location to review service incidents affecting their tenant?

  1. Microsoft 365 Service Health
  2. Microsoft Purview Audit
  3. Microsoft Entra access reviews
  4. Microsoft Intune

Correct Answer: 1

Explanation

Microsoft 365 Service Health provides information about service incidents and advisories that may affect an organization’s tenant. Administrators can review incident descriptions, affected services, current status, updates, and other available information to help determine whether an operational problem is related to Microsoft infrastructure. Purview Audit records user and administrative activities, access reviews evaluate permissions, and Intune manages devices and applications. Service Health is therefore the appropriate centralized resource for monitoring known Microsoft 365 service incidents.

Question 218

An administrator wants to prevent sensitive information from being shared externally through supported Microsoft 365 workloads. Which policy is most relevant?

  1. Microsoft Purview DLP
  2. Microsoft 365 group expiration
  3. Microsoft Secure Score
  4. Exchange Online Archive

Correct Answer: 1

Explanation

Microsoft Purview Data Loss Prevention policies can identify sensitive information and apply controls when users perform activities that could expose that information. Depending on the workload and configuration, DLP can provide warnings, alerts, or restrictions for external sharing and other risky actions. Group expiration manages the lifecycle of Microsoft 365 groups, Secure Score provides security recommendations, and Exchange Online Archive manages mailbox storage. DLP is therefore the most relevant policy when an organization needs to reduce inappropriate external sharing of sensitive information.

Question 219

Which Microsoft 365 capability helps administrators review recorded actions performed by users and administrators?

  1. Microsoft Defender Antivirus
  2. Microsoft Purview Audit
  3. Microsoft Forms
  4. Microsoft Bookings

Correct Answer: 2

Explanation

Microsoft Purview Audit provides searchable records of supported activities performed by users and administrators across Microsoft 365 services. These records can support compliance investigations, security reviews, troubleshooting, and accountability. Depending on the workload, administrators can investigate activities involving files, sharing, administrative changes, and other recorded operations. Defender Antivirus protects endpoints, Forms supports data collection and surveys, and Bookings supports appointment scheduling. Purview Audit is therefore the appropriate capability for reviewing historical recorded actions across supported Microsoft 365 workloads.

Question 220

A company wants to reduce permanent privileged access while allowing administrators to activate elevated permissions when needed. Which approach should be implemented?

  1. Assign Global Administrator permanently to all IT staff
  2. Use shared administrator credentials
  3. Use Microsoft Entra Privileged Identity Management with eligible role assignments
  4. Disable privileged account auditing

Correct Answer: 3

Explanation

Microsoft Entra Privileged Identity Management supports eligible role assignments and controlled activation of privileged permissions when elevated access is required. This approach can reduce the amount of time that powerful administrative roles remain active. Organizations can also configure controls such as multifactor authentication, approval, justification, and activation limits depending on their requirements. Permanently assigning Global Administrator, sharing privileged credentials, or disabling auditing would increase administrative risk. PIM therefore provides a structured approach to reducing persistent privileged access while maintaining the ability to perform necessary administrative tasks.