View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps.
Question 341
Which Microsoft 365 capability allows administrators to review the status of Microsoft services and active incidents?
- Microsoft Secure Score
- Microsoft 365 Service Health
- Microsoft Purview Audit
- Microsoft Entra PIM
Correct Answer: 2
Explanation
Microsoft 365 Service Health provides administrators with information about service incidents, advisories, and other issues affecting Microsoft 365 services. It is useful when users report widespread problems because administrators can determine whether Microsoft has identified a related service issue and review available updates. Secure Score focuses on security recommendations, Purview Audit records supported activities, and Privileged Identity Management manages privileged access. Service Health is therefore the appropriate capability for monitoring the operational status of Microsoft 365 services.
Question 342
A company needs to apply different administrative permissions to regional administrators who manage separate groups of users. Which Microsoft Entra feature is designed for this purpose?
- Safe Links
- Microsoft Entra administrative units
- Microsoft Purview eDiscovery
- Exchange Online Protection
Correct Answer: 2
Explanation
Microsoft Entra administrative units can be used to establish administrative boundaries for supported objects. Organizations can place users or other supported resources into administrative units and assign appropriately scoped roles so delegated administrators can manage only the objects within their assigned scope. This can be useful for regional, departmental, or organizational administration. Safe Links protects URLs, eDiscovery supports investigations, and Exchange Online Protection secures email. Administrative units are therefore the appropriate feature when the organization needs delegated administration with a limited management scope.
Question 343
Which Microsoft 365 security feature evaluates potentially harmful links when users interact with them?
- Safe Attachments
- Microsoft Purview DLP
- Safe Links
- Microsoft Entra ID Protection
Correct Answer: 3
Explanation
Safe Links is a Microsoft Defender for Office 365 capability designed to protect users from malicious or suspicious URLs. It can evaluate links in supported messages and other supported locations and apply configured protection when users interact with them. Safe Attachments focuses on potentially malicious files, Purview DLP protects sensitive information, and Entra ID Protection focuses on identity risks. Therefore, Safe Links is the appropriate security feature when the organization needs protection specifically against harmful URLs.
Question 344
Which DNS record is used by Exchange Online to determine where incoming email for a domain should be delivered?
- TXT
- CNAME
- MX
- PTR
Correct Answer: 3
Explanation
An MX record specifies the mail servers responsible for receiving email for a domain. When an organization configures a custom domain to use Exchange Online for inbound mail, the domain’s MX configuration is typically updated to direct incoming messages to the appropriate Microsoft 365 mail service. TXT records can support verification and email authentication, CNAME records provide aliases or service-specific mappings, and PTR records are associated with reverse DNS. Therefore, the MX record is the relevant DNS record for directing incoming domain email.
Question 345
An administrator wants to understand how extensively users are using Microsoft Teams and other Microsoft 365 services. Which resource is most appropriate?
- Microsoft 365 usage reports
- Microsoft Purview Audit
- Microsoft Entra sign-in logs
- Microsoft Defender XDR
Correct Answer: 1
Explanation
Microsoft 365 usage reports provide information about adoption and activity across supported Microsoft 365 workloads. Administrators can use these reports to understand usage patterns, identify inactive users, and monitor how services are being adopted within the organization. Purview Audit provides detailed records of supported activities, Entra sign-in logs focus on authentication events, and Defender XDR is designed for security operations. Usage reports are therefore the most appropriate resource when the requirement is to understand broad user adoption and activity across Microsoft 365 services.
Question 346
Which Microsoft Entra capability can evaluate the risk associated with a sign-in and provide information that can be used in access decisions?
- Microsoft Purview Audit
- Microsoft Entra ID Protection
- Microsoft Intune
- Microsoft 365 Service Health
Correct Answer: 2
Explanation
Microsoft Entra ID Protection provides risk detection capabilities for users and sign-ins. It can identify risk signals associated with potentially compromised identities or suspicious authentication activity. Organizations can use this information with supported identity controls, including Conditional Access, to apply appropriate responses based on configured policies. Purview Audit records activities, Intune manages devices and applications, and Service Health reports Microsoft service status. Entra ID Protection is therefore the relevant capability when an organization needs to assess identity and sign-in risk.
Question 347
An administrator needs to determine which user performed a supported file-sharing activity in SharePoint Online. Which capability should be used?
- Microsoft Secure Score
- Microsoft Purview Audit
- Microsoft 365 Service Health
- Microsoft Entra Cloud Sync
Correct Answer: 2
Explanation
Microsoft Purview Audit can record supported SharePoint Online and OneDrive activities, including certain file and sharing operations. Administrators can search audit records to investigate when an activity occurred and identify the account associated with the recorded event when available. Secure Score provides security recommendations, Service Health reports service incidents, and Cloud Sync synchronizes identities. Therefore, Purview Audit is the appropriate capability for investigating historical supported file-sharing activity and determining which account performed the action.
Question 348
Which Microsoft 365 feature automatically adds users to a group when their directory attributes satisfy a defined rule?
- Microsoft Entra dynamic membership
- Microsoft Entra access reviews
- Microsoft Purview eDiscovery
- Microsoft Defender XDR
Correct Answer: 1
Explanation
Microsoft Entra dynamic membership allows group membership to be determined by rules based on user or device attributes. For example, an organization can define a rule that includes users whose department, location, or job-related attribute matches specified criteria. Membership can then update automatically as directory attributes change. Access reviews evaluate existing access, eDiscovery supports investigations, and Defender XDR handles security operations. Dynamic membership is therefore the correct capability when group membership should automatically reflect defined directory attributes.
Question 349
A company wants to apply a policy when users attempt to share documents containing credit card information. Which Microsoft Purview capability should be configured?
- Microsoft Purview Data Loss Prevention
- Microsoft Entra PIM
- Microsoft 365 Service Health
- Exchange message trace
Correct Answer: 1
Explanation
Microsoft Purview Data Loss Prevention can detect sensitive information using configured sensitive information types and apply policy actions when defined conditions are met. For example, a DLP policy can be designed to identify credit card information and respond when users attempt activities such as inappropriate sharing, depending on the workload and policy configuration. PIM manages privileged access, Service Health reports service issues, and message trace investigates email processing. Purview DLP is therefore the appropriate capability for protecting sensitive information during potentially risky sharing activities.
Question 350
Which Microsoft 365 tool is designed to investigate the processing and delivery of individual email messages?
- Microsoft Secure Score
- Microsoft Purview Audit
- Exchange Online message trace
- Microsoft Intune
Correct Answer: 3
Explanation
Exchange Online message trace provides information about the processing of individual email messages. Administrators can use it to investigate whether messages were received, delivered, rejected, delayed, or otherwise processed by Exchange Online according to available trace information. Secure Score evaluates security posture, Purview Audit records supported activities across Microsoft 365, and Intune manages devices and applications. Therefore, message trace is the most appropriate tool when troubleshooting a specific email delivery or processing issue.
Question 351
Which role provides broad read-only access to Microsoft 365 administrative information?
- Global Reader
- Global Administrator
- User Administrator
- Exchange Administrator
Correct Answer: 1
Explanation
Global Reader is intended for scenarios where an administrator needs broad visibility across Microsoft 365 but should not be able to modify tenant configuration. It can be useful for auditing, monitoring, and support activities where read-only access is sufficient. Global Administrator has extensive management permissions, User Administrator focuses on supported user and group management, and Exchange Administrator focuses on Exchange Online. Global Reader therefore provides the broad read-only administrative visibility required by the scenario while supporting a least-privilege approach.
Question 352
Which Microsoft Purview capability is primarily used to manage how long information should be retained?
- Microsoft Defender XDR
- Microsoft Purview retention policies
- Microsoft Entra ID Protection
- Exchange Online Protection
Correct Answer: 2
Explanation
Microsoft Purview retention policies help organizations define how long supported content should be retained and how information should be managed during its lifecycle. Policies can be applied to supported Microsoft 365 locations according to organizational requirements. This can assist with regulatory, legal, business, and information-governance obligations. Defender XDR focuses on security incidents, Entra ID Protection detects identity risks, and Exchange Online Protection secures email. Retention policies are therefore the appropriate Purview capability for establishing organization-wide information retention requirements.
Question 353
An organization wants to require approval before an administrator can activate a highly privileged role. Which capability should be configured?
- Microsoft Entra Privileged Identity Management
- Microsoft Purview Audit
- Microsoft 365 usage reports
- Exchange Online Protection
Correct Answer: 1
Explanation
Microsoft Entra Privileged Identity Management can support approval workflows for activation of eligible privileged roles when configured for that purpose. An administrator can remain eligible for a role while requiring an authorized person to approve activation before elevated permissions become active. PIM can also support controls such as multifactor authentication, justification, and limited activation duration. Purview Audit records activities, usage reports provide adoption information, and EOP protects email. PIM is therefore the appropriate capability for controlling privileged-role activation through an approval process.
Question 354
Which Microsoft 365 portal is primarily used to investigate security alerts and threats across supported Microsoft security products?
- Microsoft 365 admin center
- Microsoft Purview portal
- Microsoft Defender portal
- Microsoft Entra admin center
Correct Answer: 3
Explanation
The Microsoft Defender portal provides security-focused capabilities for investigating alerts, threats, incidents, and other security information across supported Microsoft security products. It can provide administrators and security teams with a centralized interface for reviewing security events and taking supported response actions. The Microsoft 365 admin center focuses on general tenant administration, Purview focuses on compliance and information governance, and the Entra admin center focuses on identity and access management. Therefore, the Defender portal is the appropriate security investigation interface.
Question 355
A company wants to review whether administrators are still assigned the roles required for their current responsibilities. Which approach is appropriate?
- Review Microsoft Entra role assignments
- Run an Exchange message trace
- Review Microsoft 365 Service Health
- Configure Safe Attachments
Correct Answer: 1
Explanation
Reviewing Microsoft Entra role assignments allows an organization to determine which administrative roles are assigned to users and whether those assignments remain appropriate. This supports least privilege by helping administrators remove unnecessary permissions and identify excessive access. Message trace investigates email processing, Service Health monitors Microsoft service incidents, and Safe Attachments protects against malicious files. Regular role-assignment reviews are therefore an important administrative practice for maintaining appropriate privileges and reducing unnecessary access to sensitive management capabilities.
Question 356
Which Microsoft 365 capability can identify sensitive information patterns that DLP policies can use as conditions?
- Microsoft Entra Cloud Sync
- Microsoft Purview sensitive information types
- Microsoft Secure Score
- Microsoft Defender XDR
Correct Answer: 2
Explanation
Microsoft Purview sensitive information types provide predefined and customizable detection patterns for identifying specific categories of sensitive information. DLP policies can use these detections when determining whether content matches policy conditions and whether an action should be applied. Cloud Sync handles identity synchronization, Secure Score provides security recommendations, and Defender XDR focuses on security incidents. Sensitive information types are therefore an important component of Microsoft Purview data-protection workflows where organizations need to detect specific types of sensitive information.
Question 357
An administrator wants to prevent access to Microsoft 365 resources from devices that do not satisfy organizational compliance requirements. Which solution should be used?
- Microsoft Intune with Microsoft Entra Conditional Access
- Microsoft Purview Audit with eDiscovery
- Exchange Online Protection with Safe Links
- Microsoft Defender XDR with Service Health
Correct Answer: 1
Explanation
Microsoft Intune can evaluate device compliance based on configured organizational requirements, while Microsoft Entra Conditional Access can use compliance status as an access condition. This combination allows organizations to restrict access when a device does not meet the required compliance state. Purview Audit and eDiscovery address auditing and investigations, EOP and Safe Links protect email and URLs, and Defender XDR with Service Health serves security operations and service monitoring. Intune combined with Conditional Access is therefore the appropriate solution for enforcing device-compliance requirements during access.
Question 358
Which Microsoft 365 capability can help an organization investigate who downloaded a file from OneDrive?
- Microsoft Secure Score
- Microsoft Purview Audit
- Microsoft 365 Service Health
- Microsoft Entra PIM
Correct Answer: 2
Explanation
Microsoft Purview Audit can record supported OneDrive activities, including relevant file-access or download events. Administrators can search the audit records to determine whether a supported download activity occurred and review information associated with the event, such as the account and time when available. Secure Score provides security recommendations, Service Health reports service incidents, and PIM manages privileged access. Therefore, Purview Audit is the appropriate capability for investigating historical OneDrive file-download activity.
Question 359
Which Microsoft 365 feature can help an administrator identify upcoming changes that may require user communication or preparation?
- Microsoft 365 admin center Message center
- Microsoft Entra sign-in logs
- Microsoft Purview Audit
- Exchange message trace
Correct Answer: 1
Explanation
The Message center in the Microsoft 365 admin center provides information about planned changes, new features, service updates, and other developments that may affect an organization. Administrators can review these messages to determine whether user communication, testing, configuration changes, or other preparation is required. Entra sign-in logs contain authentication records, Purview Audit records supported activities, and message trace investigates email processing. Therefore, the Message center is the appropriate resource for monitoring upcoming changes and preparing users for Microsoft 365 updates.
Question 360
An organization wants to ensure that privileged administrators use stronger authentication when accessing administrative resources. Which control should be included in the access policy?
- Exchange mail flow rule
- Microsoft Purview retention policy
- Microsoft Entra Conditional Access requiring MFA
- Microsoft 365 usage report
Correct Answer: 3
Explanation
Microsoft Entra Conditional Access can require multifactor authentication for selected users, groups, applications, or other supported conditions. Organizations can use this capability to apply stronger authentication requirements to privileged administrators and sensitive administrative resources. This reduces reliance on passwords alone and provides an additional authentication factor. Exchange mail flow rules control email processing, Purview retention policies manage information lifecycle, and usage reports provide service-activity information. Conditional Access with MFA is therefore the appropriate control for strengthening authentication requirements for privileged administrative access.