View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps.
Question 221
Which Microsoft 365 capability allows administrators to review recommendations for improving tenant security?
- Microsoft Purview eDiscovery
- Microsoft Secure Score
- Exchange Online Archive
- Microsoft Bookings
Correct Answer: 2
Explanation
Microsoft Secure Score provides organizations with an assessment of their security posture and recommended improvement actions. Administrators can review these recommendations and determine which changes are appropriate for their environment. The recommendations may cover identity, device, data, applications, and other security areas. Purview eDiscovery supports investigations, Exchange Online Archive manages mailbox storage, and Bookings handles appointment scheduling. Secure Score is therefore the Microsoft 365 capability specifically designed to provide security improvement guidance and help administrators monitor progress toward stronger security controls.
Question 222
An administrator needs to create a policy that blocks sign-ins from a specific country. Which feature should be configured?
- Microsoft Entra Conditional Access
- Microsoft Purview Audit
- Exchange Online Protection
- Microsoft 365 group expiration
Correct Answer: 1
Explanation
Microsoft Entra Conditional Access can use location conditions to apply access controls to users based on the geographic origin of a sign-in. Administrators can define named locations and create policies that allow or block access according to organizational requirements. This can be useful when access from certain countries or regions should be restricted. Purview Audit records activities, Exchange Online Protection protects email, and group expiration manages collaborative resources. Conditional Access is therefore the appropriate feature for implementing a location-based sign-in restriction.
Question 223
What is the purpose of a Microsoft 365 group?
- To scan email attachments
- To provide collaborative membership-based access to supported Microsoft 365 resources
- To authenticate DNS records
- To manage Windows updates
Correct Answer: 2
Explanation
A Microsoft 365 group provides a membership-based collaboration model that can support shared resources such as conversations, calendars, files, and other connected Microsoft 365 services. Group membership can be managed centrally, and the associated resources are designed to facilitate collaboration among members. Attachment scanning is handled by security services, DNS authentication uses technologies such as SPF, DKIM, and DMARC, and Windows update management is associated with endpoint-management capabilities. Microsoft 365 groups are therefore primarily intended to support collaboration around shared organizational resources.
Question 224
Which Microsoft 365 feature can be used to investigate potentially malicious URLs delivered through email?
- Safe Links
- Microsoft Purview retention
- Microsoft Entra Cloud Sync
- Exchange mailbox archive
Correct Answer: 1
Explanation
Safe Links is a Microsoft Defender for Office 365 capability designed to help protect users from malicious or suspicious URLs. It can evaluate links when users interact with them and apply organizationally configured protection policies. This helps reduce the risk associated with phishing and other attacks that rely on malicious web destinations. Purview retention manages information lifecycle, Entra Cloud Sync synchronizes identities, and mailbox archiving manages storage. Safe Links is therefore the Microsoft 365 security feature most directly associated with protecting users from malicious URLs.
Question 225
An organization wants administrators to receive notifications when Microsoft 365 service incidents change status. Which resource should they monitor?
- Microsoft 365 Service Health
- Microsoft Entra access reviews
- Microsoft Purview eDiscovery
- Microsoft Intune
Correct Answer: 1
Explanation
Microsoft 365 Service Health provides information about active service incidents and advisories, including status updates as Microsoft investigates and resolves issues. Administrators can use this information to understand whether an observed problem is related to a known Microsoft service event and monitor its progress. Access reviews evaluate permissions, eDiscovery supports investigations, and Intune manages devices and applications. Service Health is therefore the appropriate resource for monitoring Microsoft 365 service incidents and their updates.
Question 226
Which Microsoft Entra feature can help automatically remove inactive guest access after an organizational review?
- Microsoft Secure Score
- Access reviews
- Exchange Online Protection
- DKIM
Correct Answer: 2
Explanation
Microsoft Entra access reviews can be configured to periodically evaluate guest access and, depending on the supported scenario and configuration, apply review decisions to access assignments. This helps organizations prevent external users from retaining access indefinitely after their business need has ended. Secure Score provides security recommendations, Exchange Online Protection protects email, and DKIM authenticates email using cryptographic signatures. Access reviews are therefore the appropriate governance mechanism for recurring evaluation and cleanup of guest access.
Question 227
Which Microsoft 365 administrative role is focused on managing user accounts and groups?
- Exchange Administrator
- Global Reader
- User Administrator
- Compliance Administrator
Correct Answer: 3
Explanation
The User Administrator role provides administrative permissions related to managing users and groups within Microsoft Entra and Microsoft 365, subject to the role’s defined scope and permissions. This role can be useful when helpdesk or identity administrators need broader user-management capabilities without receiving the extensive permissions of Global Administrator. Exchange Administrator focuses on Exchange Online, Global Reader provides read-only access, and compliance-focused roles handle governance tasks. User Administrator is therefore the most directly relevant role for routine user and group administration.
Question 228
Which Microsoft Purview capability supports searching and reviewing content collected for an investigation?
- Microsoft Purview eDiscovery
- Microsoft Secure Score
- Safe Attachments
- Microsoft Entra ID Protection
Correct Answer: 1
Explanation
Microsoft Purview eDiscovery provides tools for managing electronic information involved in investigations. Depending on the eDiscovery capabilities available to the organization, authorized users can create cases, identify relevant information, collect content, and review material associated with legal, regulatory, or internal investigations. Secure Score evaluates security posture, Safe Attachments protects against malicious files, and Entra ID Protection addresses identity risks. eDiscovery is therefore the Microsoft Purview capability most directly associated with searching and reviewing information relevant to an investigation.
Question 229
A company wants to identify whether a user’s sign-in has an elevated risk level before granting access. Which capability is relevant?
- Microsoft Entra ID Protection
- Exchange Online Archive
- Microsoft Forms
- SharePoint Version History
Correct Answer: 1
Explanation
Microsoft Entra ID Protection provides risk detection capabilities for users and sign-ins. It can evaluate available signals and identify authentication activity that may indicate increased identity risk. These risk signals can be used with other Microsoft Entra security controls, including Conditional Access, to determine appropriate access requirements. Exchange Online Archive manages mailbox storage, Microsoft Forms supports form creation, and SharePoint Version History tracks document changes. Entra ID Protection is therefore the capability most directly associated with identifying risky sign-in activity.
Question 230
Which technology allows an organization to publish a policy describing which servers may send email for its domain?
- DKIM
- SPF
- DMARC
- Microsoft Purview DLP
Correct Answer: 2
Explanation
Sender Policy Framework (SPF) allows a domain owner to publish information identifying authorized email-sending sources. The SPF policy is normally published as a DNS TXT record, and receiving mail systems can evaluate the sending source against the published policy. DKIM provides cryptographic signatures, while DMARC builds on authentication results and allows domain owners to specify handling policies and receive reports. Purview DLP protects sensitive information. SPF is therefore the technology specifically used to publish authorized email-sending sources for a domain.
Question 231
Which feature can help an organization protect administrative accounts by requiring stronger authentication for privileged users?
- Microsoft 365 group expiration
- Microsoft Entra Conditional Access
- Exchange message trace
- Microsoft Purview retention
Correct Answer: 2
Explanation
Microsoft Entra Conditional Access can apply stronger authentication requirements to selected users, groups, applications, and access scenarios. Organizations can create policies requiring multifactor authentication for privileged administrative accounts, helping protect highly sensitive identities against password-based compromise. Group expiration manages collaboration resources, message trace investigates email delivery, and Purview retention manages data lifecycle requirements. Conditional Access is therefore a key Microsoft Entra capability for enforcing stronger authentication requirements on privileged users.
Question 232
An organization wants to prevent users from accessing Microsoft 365 applications from devices that fail its compliance requirements. What should be integrated with Conditional Access?
- Microsoft Intune
- Microsoft Forms
- Exchange Online Protection
- Microsoft Purview Audit
Correct Answer: 1
Explanation
Microsoft Intune can evaluate device compliance according to organizational policies, while Microsoft Entra Conditional Access can use that compliance status when making access decisions. For example, an organization can require a device to meet defined security requirements before allowing access to selected Microsoft 365 applications. Forms is a productivity service, Exchange Online Protection protects email, and Purview Audit records activities. Integrating Intune compliance with Conditional Access therefore provides a mechanism for restricting access when devices do not meet organizational security requirements.
Question 233
Which feature is most appropriate for identifying who changed a Microsoft 365 configuration setting?
- Microsoft Purview Audit
- Microsoft Secure Score
- Microsoft 365 Service Health
- Safe Links
Correct Answer: 1
Explanation
Microsoft Purview Audit records supported activities performed by users and administrators across Microsoft 365 services. When a configuration change is recorded, audit information can help administrators determine which account performed the action and when it occurred. This supports accountability, troubleshooting, compliance investigations, and security reviews. Secure Score provides security recommendations, Service Health reports service incidents, and Safe Links protects against malicious URLs. Purview Audit is therefore the most appropriate capability for investigating who made a recorded Microsoft 365 configuration change.
Question 234
What is the main purpose of DMARC?
- To synchronize passwords
- To manage device compliance
- To define how receiving systems should handle messages that fail domain authentication checks
- To archive Exchange mailboxes
Correct Answer: 3
Explanation
Domain-based Message Authentication, Reporting, and Conformance (DMARC) allows a domain owner to publish a policy describing how receiving mail systems should handle messages that do not pass required authentication alignment checks. DMARC works with SPF and DKIM and can also provide reporting information. Password synchronization, device compliance, and mailbox archiving are unrelated functions. DMARC is therefore primarily used to establish domain-level email authentication policy and reporting, helping organizations manage messages that fail the configured authentication requirements.
Question 235
Which Microsoft 365 service can provide a centralized view of security incidents across supported Defender products?
- Microsoft Defender XDR
- Microsoft 365 admin center
- Microsoft Purview portal
- Microsoft Teams admin center
Correct Answer: 1
Explanation
Microsoft Defender XDR provides an integrated security experience that can correlate signals and incidents across supported Microsoft Defender products. This enables security teams to investigate related alerts in a broader context and coordinate response activities. The Microsoft 365 admin center provides general tenant administration, Purview focuses on compliance and governance, and Teams admin center manages Teams settings. Defender XDR is therefore the service designed to provide a consolidated security investigation and incident-response experience across supported Defender workloads.
Question 236
An organization needs to retain certain documents for seven years according to internal requirements. Which capability should be considered?
- Microsoft Purview retention
- Microsoft Entra Cloud Sync
- Safe Links
- Exchange message trace
Correct Answer: 1
Explanation
Microsoft Purview retention capabilities allow organizations to establish rules for how long supported content should be retained and how it should be handled during its lifecycle. A retention requirement such as seven years can be implemented through appropriate retention policies or labels, depending on the content and organizational scenario. Entra Cloud Sync handles identity synchronization, Safe Links protects against malicious URLs, and message trace investigates email processing. Purview retention is therefore the appropriate capability for implementing defined document-retention requirements.
Question 237
Which role would normally be more appropriate than Global Administrator for someone responsible only for Microsoft 365 compliance administration?
- Exchange Administrator
- Compliance Administrator
- Global Reader
- User Administrator
Correct Answer: 2
Explanation
The Compliance Administrator role provides permissions focused on compliance-related administrative tasks without requiring the broad tenant-wide privileges associated with Global Administrator. Using a specialized role supports least privilege by aligning permissions with the administrator’s actual responsibilities. Exchange Administrator manages Exchange Online, Global Reader provides read-only visibility, and User Administrator focuses on users and groups. For an administrator whose responsibilities center on Microsoft 365 compliance functions, the Compliance Administrator role is therefore more appropriately scoped than granting unrestricted Global Administrator access.
Question 238
Which Microsoft 365 feature can help administrators determine whether users are actively using assigned services?
- Microsoft 365 usage reports
- Microsoft Purview Audit
- Safe Attachments
- Microsoft Entra ID Protection
Correct Answer: 1
Explanation
Microsoft 365 usage reports provide information about service and user activity across supported workloads. Administrators can use these reports to understand adoption, identify inactive users, observe service utilization, and support decisions about Microsoft 365 administration. Purview Audit is focused on detailed activity records, Safe Attachments protects against malicious files, and Entra ID Protection identifies identity risks. Usage reports are therefore the appropriate resource when administrators need a broader view of whether users are actively using assigned Microsoft 365 services.
Question 239
An administrator wants to restrict access to a cloud application unless the user completes multifactor authentication. Which feature should be configured?
- Microsoft Purview Audit
- Microsoft Entra Conditional Access
- Exchange Online Protection
- Microsoft 365 Service Health
Correct Answer: 2
Explanation
Microsoft Entra Conditional Access can require multifactor authentication for access to selected cloud applications. Administrators can define policies based on users, groups, applications, locations, devices, risk, and other supported conditions, then specify MFA as an access control. This allows authentication requirements to be applied selectively rather than universally. Purview Audit records activity, Exchange Online Protection protects email, and Service Health reports Microsoft service incidents. Conditional Access is therefore the appropriate feature for requiring MFA before users can access a specified cloud application.
Question 240
Which practice provides stronger accountability for privileged Microsoft 365 administration?
- Sharing one Global Administrator account among the IT team
- Giving all support staff unrestricted administrative access
- Using individual administrator accounts with appropriate roles and auditing
- Disabling audit records for administrators
Correct Answer: 3
Explanation
Using individual administrative accounts with appropriately scoped roles and maintaining audit records provides stronger accountability for privileged Microsoft 365 administration. Individual accounts allow actions to be associated with specific administrators, while role-based permissions help limit unnecessary access. Audit records can then support investigation and review when changes occur. Shared privileged accounts reduce accountability, unrestricted permissions increase exposure, and disabling audit records removes valuable evidence. Individual identities, least-privilege role assignments, and auditing therefore form an important combination for accountable Microsoft 365 administration.