Microsoft MS-102 Practice Test Questions and Exam Dumps Part19 Q361-380

View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps.

 

Question 361

Which Microsoft 365 capability can administrators use to review whether a user’s license is assigned correctly?

  1. Microsoft Defender XDR
  2. Microsoft 365 admin center
  3. Microsoft Purview Audit
  4. Microsoft Entra ID Protection

Correct Answer: 2

Explanation

The Microsoft 365 admin center provides administrative capabilities for managing users and their assigned licenses. Administrators with appropriate permissions can review a user’s account, examine assigned licenses, and make supported licensing changes. Defender XDR focuses on security operations, Purview Audit records supported activities, and Entra ID Protection focuses on identity risks. Therefore, the Microsoft 365 admin center is the appropriate location when an administrator needs to review or manage a user’s Microsoft 365 licensing assignment.

Question 362

A company wants to protect users from messages containing malicious files while allowing administrators to configure how those files are handled. Which capability should be used?

  1. Safe Attachments
  2. Safe Links
  3. Microsoft Entra access reviews
  4. Microsoft Secure Score

Correct Answer: 1

Explanation

Safe Attachments provides protection against potentially malicious files delivered through supported email and collaboration scenarios. Administrators can configure policies that determine how messages containing suspicious attachments are handled according to the organization’s security requirements. Safe Links is designed for URL protection, access reviews evaluate permissions, and Secure Score provides security recommendations. Safe Attachments is therefore the appropriate capability when the organization specifically needs protection against harmful or suspicious files included in messages.

Question 363

Which Microsoft Entra feature allows administrators to create policies that evaluate users, applications, locations, and device conditions before granting access?

  1. Microsoft Entra Conditional Access
  2. Microsoft Entra Cloud Sync
  3. Microsoft Entra administrative units
  4. Microsoft Entra access reviews

Correct Answer: 1

Explanation

Microsoft Entra Conditional Access evaluates configured signals and conditions before applying access controls to supported resources. Administrators can create policies based on factors such as users, groups, applications, locations, device state, and risk, depending on the configuration. Cloud Sync synchronizes identities, administrative units establish management scopes, and access reviews periodically evaluate existing permissions. Conditional Access is therefore the Microsoft Entra capability designed to make access decisions using multiple contextual conditions.

Question 364

An administrator wants to determine whether a suspicious sign-in was associated with an unusual location or device. Which resource should be examined first?

  1. Microsoft 365 usage reports
  2. Microsoft Entra sign-in logs
  3. Microsoft Purview retention labels
  4. Exchange Online message trace

Correct Answer: 2

Explanation

Microsoft Entra sign-in logs provide information about authentication events and can include details such as the user, application, time, location, device-related information, and authentication result when available. These details can help administrators investigate unusual sign-in activity and determine whether the event warrants further investigation. Usage reports provide broader service activity information, retention labels manage information lifecycle, and message trace investigates email processing. Sign-in logs are therefore the most relevant starting point for investigating suspicious authentication activity.

Question 365

Which Microsoft Purview feature is designed to apply retention requirements to selected content locations?

  1. Microsoft Purview retention policy
  2. Microsoft Defender XDR
  3. Microsoft Entra PIM
  4. Exchange Online Protection

Correct Answer: 1

Explanation

Microsoft Purview retention policies allow organizations to define retention requirements for supported content locations. Administrators can configure policies according to organizational, legal, regulatory, or business requirements and apply them to selected Microsoft 365 workloads. Defender XDR manages security incidents, PIM manages privileged access, and Exchange Online Protection protects email. Retention policies are therefore the appropriate Microsoft Purview feature when the organization needs to establish retention requirements across selected Microsoft 365 content locations.

Question 366

A user reports that a message was delayed before reaching the recipient. Which Exchange Online capability can help investigate the delay?

  1. Microsoft Secure Score
  2. Exchange Online message trace
  3. Microsoft Intune
  4. Microsoft Entra ID Protection

Correct Answer: 2

Explanation

Exchange Online message trace can provide information about how a message was processed and can help administrators investigate delivery delays. The trace can show available processing events and outcomes associated with the message, allowing administrators to determine what happened during its journey through Exchange Online. Secure Score evaluates security posture, Intune manages devices and applications, and Entra ID Protection handles identity risks. Message trace is therefore the appropriate tool for investigating an individual email that was delayed during delivery.

Question 367

Which Microsoft 365 capability can help organizations apply information protection according to the sensitivity of documents?

  1. Microsoft Purview sensitivity labels
  2. Microsoft 365 Service Health
  3. Microsoft Entra Cloud Sync
  4. Exchange message trace

Correct Answer: 1

Explanation

Microsoft Purview sensitivity labels allow organizations to classify supported content according to sensitivity and apply configured protection settings. Depending on the label configuration, protection can include encryption, access restrictions, content markings, and other controls. Service Health reports operational issues, Cloud Sync synchronizes directory objects, and message trace investigates email processing. Sensitivity labels are therefore appropriate when an organization wants document protection to be associated with the sensitivity classification assigned to the information.

Question 368

An organization needs a process to periodically review whether users still need access to a shared resource. Which feature should be configured?

  1. Microsoft Defender XDR
  2. Microsoft Entra access reviews
  3. Microsoft Secure Score
  4. Exchange Online Protection

Correct Answer: 2

Explanation

Microsoft Entra access reviews provide a recurring process for evaluating whether users should continue to have access to supported resources. Reviewers can periodically assess current access and take action based on organizational requirements. This is useful when permissions may become unnecessary as employees change roles, projects end, or external collaborators leave. Defender XDR focuses on security incidents, Secure Score provides recommendations, and Exchange Online Protection protects email. Access reviews are therefore the appropriate feature for periodic access validation.

Question 369

Which Microsoft 365 service provides cloud-based management of organizational devices and their compliance settings?

  1. Microsoft Intune
  2. Microsoft Purview Audit
  3. Exchange Online
  4. Microsoft Entra Cloud Sync

Correct Answer: 1

Explanation

Microsoft Intune provides cloud-based endpoint and device-management capabilities. Administrators can configure supported device policies, application-management settings, and compliance requirements through Intune. Compliance information can also be used with Microsoft Entra Conditional Access to control access to organizational resources. Purview Audit records activities, Exchange Online provides email services, and Cloud Sync synchronizes identities. Intune is therefore the appropriate Microsoft 365 service when the organization needs centralized cloud management of devices and their compliance settings.

Question 370

Which Microsoft 365 security capability can correlate related alerts into incidents for investigation?

  1. Microsoft Purview eDiscovery
  2. Microsoft Defender XDR
  3. Microsoft 365 admin center
  4. Microsoft Entra administrative units

Correct Answer: 2

Explanation

Microsoft Defender XDR can correlate related security alerts and present them as incidents within its security investigation environment. This helps security teams understand related activity across supported security products instead of investigating every alert independently. Purview eDiscovery supports information investigations, the Microsoft 365 admin center provides general administration, and administrative units define management scopes. Defender XDR is therefore the appropriate capability when security teams need correlated incidents and a unified view of related security activity.

Question 371

Which Microsoft 365 capability can provide information about an administrator’s historical configuration change?

  1. Microsoft Purview Audit
  2. Microsoft Secure Score
  3. Microsoft 365 Service Health
  4. Microsoft Defender for Endpoint

Correct Answer: 1

Explanation

Microsoft Purview Audit can provide searchable records of supported administrative activities. When investigating a historical configuration change, administrators can search the audit records and examine information such as the activity, account, and time associated with the event when available. Secure Score provides recommendations, Service Health reports service issues, and Defender for Endpoint focuses on endpoint security. Purview Audit is therefore the most relevant capability for investigating supported historical administrative configuration changes.

Question 372

A company wants to prevent unauthorized applications from receiving excessive permissions to organizational data. Which Microsoft Entra area should administrators review?

  1. Microsoft Entra enterprise applications and application permissions
  2. Microsoft 365 usage reports
  3. Exchange message trace
  4. Microsoft Purview retention policies

Correct Answer: 1

Explanation

Microsoft Entra enterprise applications and related application-permission controls allow administrators to review how applications interact with organizational resources. Reviewing application assignments, permissions, and consent-related settings can help organizations control which applications are allowed to access data and under what circumstances. Usage reports provide service activity information, message trace investigates email, and retention policies manage information lifecycle. Therefore, the Microsoft Entra enterprise application and permission-management area is the relevant place to review application access to organizational data.

Question 373

Which Microsoft 365 capability can provide users with policy guidance when their actions involve sensitive organizational information?

  1. Microsoft Purview DLP
  2. Microsoft Entra Cloud Sync
  3. Microsoft Secure Score
  4. Microsoft 365 Service Health

Correct Answer: 1

Explanation

Microsoft Purview Data Loss Prevention can provide policy tips and notifications to users when supported activities involving sensitive information match configured DLP conditions. These user-facing controls can help employees understand organizational requirements and reduce accidental data exposure. Cloud Sync manages identity synchronization, Secure Score provides security recommendations, and Service Health reports service incidents. Purview DLP is therefore the appropriate capability when an organization wants to combine sensitive-data detection with user guidance during potentially risky activities.

Question 374

An administrator wants to review upcoming changes to Microsoft 365 services before implementation. Which resource should be checked regularly?

  1. Microsoft Entra sign-in logs
  2. Microsoft 365 admin center Message center
  3. Microsoft Purview Audit
  4. Exchange message trace

Correct Answer: 2

Explanation

The Microsoft 365 admin center Message center provides information about planned changes, new features, service updates, and other announcements affecting Microsoft 365. Regularly reviewing these messages allows administrators to prepare users, test changes where appropriate, update documentation, and adjust configurations when required. Entra sign-in logs provide authentication information, Purview Audit records supported activities, and message trace investigates email processing. The Message center is therefore the appropriate administrative resource for monitoring upcoming Microsoft 365 changes.

Question 375

Which Microsoft Entra capability is used to manage eligible assignments for privileged administrative roles?

  1. Microsoft Entra Privileged Identity Management
  2. Microsoft Entra Cloud Sync
  3. Microsoft Entra dynamic groups
  4. Microsoft Entra administrative units

Correct Answer: 1

Explanation

Microsoft Entra Privileged Identity Management manages privileged role assignments and supports eligible access that can be activated when elevated permissions are needed. Organizations can configure additional requirements such as approval, multifactor authentication, justification, and activation time limits. Cloud Sync handles directory synchronization, dynamic groups manage membership automatically based on attributes, and administrative units provide administrative scope. PIM is therefore the appropriate Microsoft Entra capability for managing eligible assignments and controlled activation of privileged administrative roles.

Question 376

Which feature should an administrator use to determine whether an email was rejected by an Exchange Online mail flow rule?

  1. Microsoft Purview eDiscovery
  2. Microsoft Intune
  3. Exchange Online message trace
  4. Microsoft Secure Score

Correct Answer: 3

Explanation

Exchange Online message trace provides information about the processing of email messages and can help administrators investigate delivery failures, including messages that may have been rejected or affected by mail-flow processing. Administrators can review available trace details to understand how Exchange handled the message. eDiscovery supports information investigations, Intune manages devices and applications, and Secure Score provides security recommendations. Therefore, message trace is the appropriate tool for investigating whether a message was rejected during Exchange Online processing.

Question 377

An organization wants to classify confidential documents and apply protection settings based on that classification. Which solution should be used?

  1. Microsoft Purview sensitivity labels
  2. Microsoft 365 Service Health
  3. Microsoft Entra sign-in logs
  4. Microsoft Defender XDR

Correct Answer: 1

Explanation

Microsoft Purview sensitivity labels allow organizations to classify information according to defined sensitivity levels and apply associated protection settings. Depending on configuration, labels can support encryption, access controls, content markings, and other information-protection capabilities. Service Health monitors Microsoft services, sign-in logs record authentication events, and Defender XDR manages security investigations. Sensitivity labels are therefore the appropriate solution when an organization wants confidential documents to receive protection based on their classification.

Question 378

Which Microsoft 365 capability is most appropriate for reviewing whether a user’s access to an application should continue?

  1. Microsoft Defender XDR
  2. Microsoft Entra access review
  3. Exchange Online Protection
  4. Microsoft Secure Score

Correct Answer: 2

Explanation

Microsoft Entra access reviews allow organizations to periodically evaluate whether users should retain access to supported applications and resources. Reviewers can assess current access and take action according to organizational requirements. This is particularly useful for temporary workers, guests, project members, and users whose responsibilities change over time. Defender XDR handles security incidents, Exchange Online Protection protects email, and Secure Score provides security recommendations. Access reviews are therefore the appropriate governance mechanism for determining whether application access should continue.

Question 379

Which Microsoft 365 capability can provide a searchable record of supported user and administrator activities?

  1. Microsoft Purview Audit
  2. Microsoft 365 Service Health
  3. Microsoft Secure Score
  4. Microsoft Entra Cloud Sync

Correct Answer: 1

Explanation

Microsoft Purview Audit provides searchable records of supported activities performed by users and administrators across Microsoft 365 services. These records can support security investigations, compliance activities, troubleshooting, and accountability. The exact events available depend on the workload, configuration, and applicable auditing capabilities. Service Health reports service issues, Secure Score provides security recommendations, and Cloud Sync synchronizes identities. Purview Audit is therefore the appropriate capability when an organization needs a searchable historical record of supported Microsoft 365 activities.

Question 380

A company wants to use temporary administrative privileges, require stronger authentication during activation, and record the reason for elevation. Which solution provides these capabilities together?

  1. Microsoft Purview eDiscovery
  2. Microsoft 365 usage reports
  3. Microsoft Entra Privileged Identity Management
  4. Exchange Online Protection

Correct Answer: 3

Explanation

Microsoft Entra Privileged Identity Management supports controlled activation of eligible privileged roles and can be configured with safeguards such as multifactor authentication and justification. Organizations can also use approval and time-limited activation controls where appropriate. These capabilities reduce unnecessary standing privilege while providing additional governance around elevated access. Purview eDiscovery supports investigations, usage reports provide service activity information, and Exchange Online Protection protects email. PIM is therefore the solution that most directly combines temporary privileged access with additional authentication and justification requirements.