View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps.
Question 321
Which Microsoft 365 capability helps administrators identify whether a reported service problem is already known by Microsoft?
- Microsoft Purview Audit
- Microsoft 365 Service Health
- Microsoft Secure Score
- Microsoft Entra ID Protection
Correct Answer: 2
Explanation
Microsoft 365 Service Health provides administrators with information about active incidents, advisories, and other service-related events affecting Microsoft 365. When users report problems accessing a service, administrators can check Service Health to determine whether Microsoft has identified a corresponding issue and review available updates. Purview Audit records supported activities, Secure Score provides security recommendations, and Entra ID Protection focuses on identity risks. Service Health is therefore the appropriate resource for determining whether a reported Microsoft 365 service problem is already recognized.
Question 322
An organization wants to delegate administration of a limited set of users without granting access to manage every user in the tenant. Which feature can help?
- Microsoft Entra administrative units
- Safe Links
- Microsoft Purview Audit
- Exchange Online Protection
Correct Answer: 1
Explanation
Microsoft Entra administrative units can help organizations establish administrative boundaries for supported objects. By combining administrative units with appropriately scoped administrative roles, an organization can delegate management of a defined group of users without granting unrestricted tenant-wide permissions. Safe Links protects users from malicious URLs, Purview Audit records supported activities, and Exchange Online Protection protects email. Administrative units are therefore useful when an organization needs delegated administration for a specific regional, departmental, or organizational subset.
Question 323
Which Microsoft 365 security feature can scan email attachments for potentially malicious content?
- Safe Links
- Microsoft Purview DLP
- Safe Attachments
- Microsoft Entra Conditional Access
Correct Answer: 3
Explanation
Safe Attachments is designed to protect users from potentially malicious files delivered through email and supported Microsoft 365 workloads. It analyzes attachments according to the configured protection policy and can apply an appropriate action when a threat is detected. Safe Links focuses on URLs, Purview DLP protects sensitive information, and Conditional Access controls access based on defined conditions. Therefore, Safe Attachments is the capability specifically associated with analyzing email attachments for potentially harmful content.
Question 324
Which DNS record helps specify the authorized sending servers for a domain?
- MX
- SPF TXT
- CNAME
- SRV
Correct Answer: 2
Explanation
SPF is implemented through a DNS TXT record that identifies authorized mail-sending sources for a domain. Receiving mail systems can evaluate the SPF policy to determine whether a message originated from an authorized source. An MX record identifies mail servers responsible for receiving email, while CNAME and SRV records support other DNS functions. SPF alone does not provide complete email authentication, so organizations commonly use it together with DKIM and DMARC. The SPF TXT record is therefore the correct choice for identifying authorized sending infrastructure.
Question 325
A Microsoft 365 administrator wants to identify which users have not recently used a particular service. Which resource should be reviewed?
- Microsoft 365 usage reports
- Microsoft Defender XDR
- Microsoft Entra PIM
- Microsoft Purview eDiscovery
Correct Answer: 1
Explanation
Microsoft 365 usage reports provide activity information for supported services and can help administrators identify usage patterns, including users with little or no recent activity. This information can support license reviews, adoption planning, and account-management decisions. Defender XDR is designed for security investigations, PIM manages privileged access, and eDiscovery supports investigative searches. Usage reports are therefore the appropriate resource when the administrator needs to understand service utilization and identify users who may no longer be actively using a particular Microsoft 365 service.
Question 326
Which Microsoft Entra feature can detect potentially risky user accounts and sign-in activity?
- Microsoft Entra ID Protection
- Microsoft Purview Audit
- Microsoft Intune
- Exchange Online Protection
Correct Answer: 1
Explanation
Microsoft Entra ID Protection helps organizations detect and investigate identity-related risks associated with users and sign-ins. It can identify risk signals and provide information that administrators can use when configuring appropriate identity protections. Depending on the configuration and licensing, risk information can also be used with Conditional Access policies to apply additional controls. Purview Audit records activities, Intune manages devices, and Exchange Online Protection secures email. Entra ID Protection is therefore the appropriate capability for detecting and responding to potentially risky identity activity.
Question 327
An organization needs to find out which administrator performed a supported action in Microsoft 365 several days ago. Which feature should be queried?
- Microsoft 365 Service Health
- Microsoft Purview Audit
- Microsoft Secure Score
- Microsoft Intune
Correct Answer: 2
Explanation
Microsoft Purview Audit maintains searchable records for supported activities performed across Microsoft 365 services. Administrators can use audit searches to investigate historical actions and review details such as the activity, associated account, and time of the event when that information is available. Service Health reports Microsoft service issues, Secure Score provides security recommendations, and Intune focuses on device and application management. Therefore, Purview Audit is the appropriate feature for investigating which administrator performed a supported action several days earlier.
Question 328
Which Microsoft 365 feature can automatically classify users into groups according to attributes such as office location?
- Exchange mail flow rules
- Microsoft Purview retention labels
- Microsoft Entra dynamic membership
- Microsoft Defender XDR
Correct Answer: 3
Explanation
Microsoft Entra dynamic membership allows group membership to be determined automatically according to configured user or device attributes. For example, a dynamic group can use an attribute such as department, job title, or office location to determine which users belong to the group. This reduces manual membership maintenance when directory attributes are properly maintained. Exchange mail flow rules process messages, retention labels manage information lifecycle, and Defender XDR supports security operations. Dynamic membership is therefore the appropriate capability for attribute-based automatic group membership.
Question 329
Which Microsoft 365 feature can help protect sensitive information by warning users when they attempt a potentially risky action?
- Microsoft Purview DLP
- Microsoft 365 Service Health
- Microsoft Entra Cloud Sync
- Exchange message trace
Correct Answer: 1
Explanation
Microsoft Purview Data Loss Prevention can provide user notifications and policy tips when supported activities involving sensitive information match configured policy conditions. These notifications can help users understand organizational requirements and may prevent accidental disclosure of protected information. The exact actions available depend on the workload, policy configuration, and licensing. Service Health monitors Microsoft services, Cloud Sync synchronizes identities, and message trace investigates email processing. Purview DLP is therefore the appropriate capability for applying data-protection controls and user guidance around sensitive information.
Question 330
An administrator needs to determine whether a specific email reached its intended recipient. Which tool should be used?
- Microsoft Purview Audit
- Exchange Online message trace
- Microsoft Secure Score
- Microsoft Entra sign-in logs
Correct Answer: 2
Explanation
Exchange Online message trace is designed to provide information about email processing and delivery. Administrators can use it to investigate whether a message was received, delivered, rejected, delayed, or otherwise processed according to the available trace details. Purview Audit serves broader auditing purposes, Secure Score evaluates security posture, and Entra sign-in logs concern authentication events rather than email delivery. Therefore, when the administrator needs to determine what happened to a particular email message, Exchange Online message trace is the appropriate tool.
Question 331
Which role is appropriate when an administrator needs broad read-only visibility across Microsoft 365 but should not make configuration changes?
- Global Reader
- Global Administrator
- Exchange Administrator
- User Administrator
Correct Answer: 1
Explanation
Global Reader provides broad read-only visibility across many Microsoft 365 administrative areas. It can be useful for auditors, support personnel, or administrators who need to inspect tenant configuration without requiring permissions to change it. Global Administrator provides extensive management permissions, Exchange Administrator focuses on Exchange Online, and User Administrator handles supported user-management functions. Assigning Global Reader can therefore help organizations follow least-privilege principles when an individual requires broad administrative visibility but does not need write access.
Question 332
Which Microsoft Purview capability can preserve and investigate content associated with a legal or organizational investigation?
- Microsoft Secure Score
- Microsoft Purview eDiscovery
- Microsoft Intune
- Microsoft Entra Cloud Sync
Correct Answer: 2
Explanation
Microsoft Purview eDiscovery provides capabilities for conducting structured investigations involving electronic information. Depending on the eDiscovery features and licensing available, organizations can identify relevant content, create cases, search supported data sources, and perform review-related activities. Secure Score focuses on security recommendations, Intune manages devices and applications, and Cloud Sync synchronizes identities. Therefore, eDiscovery is the appropriate Microsoft Purview capability when an organization needs to investigate and manage potentially relevant content associated with a legal, regulatory, or internal matter.
Question 333
An organization wants to require compliant devices before users can access a sensitive cloud application. Which two Microsoft services are most directly involved?
- Exchange Online and Microsoft Defender XDR
- Microsoft Intune and Microsoft Entra Conditional Access
- Microsoft Purview and Exchange Online Protection
- Microsoft Secure Score and Microsoft 365 Service Health
Correct Answer: 2
Explanation
Microsoft Intune can evaluate device compliance according to organizational requirements, while Microsoft Entra Conditional Access can use device compliance as a condition in access policies. Together, they can help enforce a requirement that users access sensitive applications only from devices meeting defined compliance standards. Exchange Online and Defender XDR do not provide this specific combination of device compliance and access control. Purview and EOP address data governance and email protection, while Secure Score and Service Health serve different purposes. Intune and Conditional Access are therefore the relevant combination.
Question 334
Which Microsoft 365 security capability can provide information about the security posture of a tenant and recommended improvement actions?
- Microsoft Secure Score
- Microsoft Purview Audit
- Exchange message trace
- Microsoft Entra Cloud Sync
Correct Answer: 1
Explanation
Microsoft Secure Score provides an overview of an organization’s security posture and includes recommendations for improving supported security configurations. Administrators can review the recommendations and determine which actions align with their organization’s requirements and risk-management approach. Purview Audit provides activity records, message trace investigates email processing, and Cloud Sync handles identity synchronization. Secure Score is therefore the Microsoft 365 capability most directly associated with assessing security posture and presenting actionable security improvement recommendations.
Question 335
A company wants to ensure that users cannot access a sensitive application unless they complete multifactor authentication. Which policy should be configured?
- Microsoft Purview retention policy
- Exchange mail flow rule
- Microsoft Entra Conditional Access policy
- Microsoft Defender XDR incident
Correct Answer: 3
Explanation
A Microsoft Entra Conditional Access policy can require multifactor authentication when users access specified applications or resources. Administrators can define conditions such as users, groups, applications, locations, device states, or risk and then specify MFA as an access control. This allows authentication requirements to be targeted rather than applied indiscriminately. Purview retention controls information lifecycle, Exchange mail flow rules process messages, and Defender XDR incidents support security investigations. Conditional Access is therefore the appropriate policy mechanism for requiring MFA for access to a sensitive application.
Question 336
Which Microsoft 365 capability can protect corporate data by controlling access to sensitive content based on classification?
- Microsoft Purview sensitivity labels
- Microsoft 365 Service Health
- Microsoft Entra Cloud Sync
- Exchange message trace
Correct Answer: 1
Explanation
Microsoft Purview sensitivity labels allow organizations to classify supported content according to sensitivity and apply configured protection settings. Depending on the configuration, labels can support encryption, access restrictions, markings, and other controls. This allows organizations to associate protection requirements with the classification of information. Service Health provides service-status information, Cloud Sync handles identity synchronization, and message trace investigates email processing. Sensitivity labels are therefore the relevant Microsoft Purview capability for classifying sensitive content and applying associated protection controls.
Question 337
An organization wants to reduce permanent assignment of privileged roles while still allowing administrators to perform occasional elevated tasks. Which approach should be used?
- Assign Global Administrator permanently
- Create a shared administrator account
- Use Microsoft Entra Privileged Identity Management
- Disable privileged account auditing
Correct Answer: 3
Explanation
Microsoft Entra Privileged Identity Management supports eligible role assignments and controlled activation of privileged roles. Administrators can activate elevated permissions when required rather than retaining permanent active access. Organizations can also configure additional controls such as approval, multifactor authentication, justification, and time limits. Permanent Global Administrator assignments increase standing privilege, shared accounts reduce accountability, and disabling auditing removes useful records. PIM therefore provides a structured approach for reducing standing privileged access while still allowing administrators to perform authorized elevated tasks when necessary.
Question 338
Which Microsoft 365 capability helps organizations review whether guest access should continue?
- Microsoft Entra access reviews
- Safe Attachments
- Microsoft Secure Score
- Exchange Online Protection
Correct Answer: 1
Explanation
Microsoft Entra access reviews allow organizations to periodically review access granted to users, including supported guest access scenarios. Reviewers can determine whether external users still require access and take action according to organizational policies. This is useful because guest access may remain after the original business requirement has ended. Safe Attachments protects against malicious files, Secure Score provides security recommendations, and Exchange Online Protection secures email. Access reviews are therefore the appropriate governance capability for periodically validating whether guest access remains necessary.
Question 339
Which Microsoft 365 capability can provide centralized management of security incidents generated by supported Microsoft security products?
- Microsoft 365 usage reports
- Microsoft Defender XDR
- Microsoft Purview retention
- Microsoft Entra Cloud Sync
Correct Answer: 2
Explanation
Microsoft Defender XDR provides a centralized security operations experience for supported Microsoft security products. It can bring related alerts together into incidents and provide investigation information across areas such as endpoint, identity, email, and other supported security signals. Usage reports provide service activity information, Purview retention manages information lifecycle, and Cloud Sync synchronizes identities. Defender XDR is therefore the appropriate capability when security personnel need a centralized environment for investigating and responding to correlated security incidents.
Question 340
An administrator needs to see upcoming Microsoft 365 feature changes before they affect users. Where should the administrator look?
- Microsoft Entra sign-in logs
- Microsoft Purview Audit
- Microsoft 365 admin center Message center
- Exchange message trace
Correct Answer: 3
Explanation
The Microsoft 365 admin center Message center provides administrators with announcements about planned changes, new capabilities, feature updates, and other developments affecting Microsoft 365 services. Reviewing these messages allows organizations to understand upcoming changes and determine whether preparation, testing, communication, or configuration work may be required. Entra sign-in logs contain authentication records, Purview Audit contains supported activity records, and message trace concerns email processing. The Message center is therefore the appropriate location for monitoring upcoming Microsoft 365 feature changes.