Microsoft MS-102 Practice Test Questions and Exam Dumps Part14 Q261-280

View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps.

 

Question 261

Which Microsoft 365 feature is used to manage organizational email authentication policies through Exchange Online?

  1. Exchange Online Protection
  2. Microsoft Intune
  3. Microsoft Purview eDiscovery
  4. Microsoft Entra ID Protection

Correct Answer: 1

Explanation

Exchange Online Protection provides foundational email security capabilities for Microsoft 365 organizations. It helps protect inbound and outbound email from spam, malware, phishing, and other common threats. Administrators can configure relevant anti-spam, anti-malware, and mail-flow protections according to organizational requirements. Intune manages devices and applications, Purview eDiscovery supports investigations, and Entra ID Protection focuses on identity risks. EOP is therefore the Microsoft 365 service most directly associated with protecting organizational email and supporting secure email-processing policies.

Question 262

An administrator needs to determine which users are members of a particular Microsoft 365 group. Which administrative resource can provide this information?

  1. Microsoft Defender portal
  2. Microsoft 365 admin center
  3. Microsoft Purview portal
  4. Microsoft Secure Score

Correct Answer: 2

Explanation

The Microsoft 365 admin center provides administrative capabilities for managing users and groups. Administrators with the appropriate permissions can review group properties, membership, ownership, and other relevant information. This makes the admin center useful for routine Microsoft 365 group-management tasks. Defender is focused on security operations, Purview handles compliance and governance, and Secure Score provides security recommendations. Therefore, when an administrator needs to inspect membership of a Microsoft 365 group as part of routine tenant administration, the Microsoft 365 admin center is an appropriate resource.

Question 263

Which Microsoft Entra feature can provide information about failed authentication attempts?

  1. Microsoft Entra sign-in logs
  2. Microsoft Purview Audit
  3. Microsoft 365 Service Health
  4. Exchange Online Protection

Correct Answer: 1

Explanation

Microsoft Entra sign-in logs provide information about authentication attempts, including successful and failed sign-ins. Administrators can use these records to troubleshoot authentication problems and investigate suspicious sign-in activity. Depending on the available data, administrators can examine information such as the user, application, time, location, and result of the sign-in. Purview Audit records broader Microsoft 365 activities, Service Health reports service issues, and Exchange Online Protection protects email. Sign-in logs are therefore the most directly relevant resource for investigating failed authentication attempts.

Question 264

A company wants to prevent users from permanently retaining access to an application after their business need ends. Which approach is appropriate?

  1. Safe Attachments
  2. Exchange message trace
  3. Microsoft Entra access reviews
  4. Microsoft Secure Score

Correct Answer: 3

Explanation

Microsoft Entra access reviews can help organizations periodically evaluate whether users should continue to have access to applications and other supported resources. Regular reviews are particularly useful when access is granted to temporary workers, guests, project teams, or other users whose requirements may change over time. Reviewers can evaluate current access and take action according to organizational policies. Safe Attachments protects against malicious files, message trace investigates email processing, and Secure Score provides security recommendations. Access reviews therefore support recurring validation of application access.

Question 265

Which Microsoft 365 feature can automatically apply a retention requirement to content based on defined organizational rules?

  1. Microsoft Defender XDR
  2. Microsoft Purview retention policy
  3. Microsoft Entra Cloud Sync
  4. Exchange Online Protection

Correct Answer: 2

Explanation

Microsoft Purview retention policies allow organizations to define how long supported content should be retained and how it should be managed throughout its lifecycle. Policies can apply to selected Microsoft 365 locations and can help organizations meet business, legal, and regulatory requirements. Defender XDR provides security investigation capabilities, Entra Cloud Sync synchronizes identities, and Exchange Online Protection protects email. A Purview retention policy is therefore the appropriate capability when an organization needs to apply systematic retention requirements across supported Microsoft 365 content.

Question 266

Which Microsoft 365 feature provides protection against potentially malicious files attached to messages?

  1. Microsoft Entra Conditional Access
  2. Microsoft Purview Audit
  3. Safe Attachments
  4. Microsoft 365 Service Health

Correct Answer: 3

Explanation

Safe Attachments is a Microsoft Defender for Office 365 capability designed to help protect users from malicious attachments. It can analyze supported attachments and apply configured protection actions before users interact with potentially harmful content. Conditional Access controls access decisions, Purview Audit records supported activities, and Service Health provides information about Microsoft service incidents. Safe Attachments is therefore the feature specifically associated with analyzing and protecting users from potentially dangerous files delivered through email and supported collaboration workloads.

Question 267

An organization wants administrators to manage only Exchange Online settings without receiving tenant-wide permissions. Which role should be assigned?

  1. Exchange Administrator
  2. Global Administrator
  3. User Administrator
  4. Global Reader

Correct Answer: 1

Explanation

The Exchange Administrator role provides administrative permissions focused on Exchange Online. Assigning this role instead of Global Administrator helps implement least privilege because the administrator receives permissions appropriate to email-management responsibilities without automatically receiving the broadest tenant-wide privileges. User Administrator focuses on user and group management, while Global Reader provides read-only visibility. Therefore, an administrator whose responsibilities are limited to Exchange Online should generally be assigned the Exchange Administrator role rather than a broader administrative role.

Question 268

What does Microsoft Purview Audit primarily provide?

  1. Email encryption
  2. Recorded information about supported user and administrative activities
  3. Device compliance management
  4. DNS domain verification

Correct Answer: 2

Explanation

Microsoft Purview Audit provides searchable records of supported activities performed across Microsoft 365 services. These records can assist with compliance reviews, security investigations, troubleshooting, and accountability. Depending on the workload, audit information can include activities involving files, users, administrators, sharing, and configuration changes. Email encryption, device compliance, and domain verification are separate functions handled by other Microsoft technologies. Purview Audit is therefore primarily used to review historical records of supported actions performed within the Microsoft 365 environment.

Question 269

Which Microsoft Entra capability can use device compliance as a condition for granting access?

  1. Microsoft Purview eDiscovery
  2. Microsoft Entra Conditional Access
  3. Exchange Online Protection
  4. Microsoft Secure Score

Correct Answer: 2

Explanation

Microsoft Entra Conditional Access can evaluate device compliance when integrated with Microsoft Intune and then apply access controls according to the organization’s policies. For example, a company can require users to access sensitive Microsoft 365 applications only from devices that satisfy defined compliance requirements. Purview eDiscovery supports investigations, Exchange Online Protection secures email, and Secure Score evaluates security posture. Conditional Access is therefore the Microsoft Entra capability used to incorporate device compliance into access decisions.

Question 270

Which Microsoft 365 feature helps administrators monitor adoption of Microsoft 365 services?

  1. Microsoft Purview Audit
  2. Microsoft Entra ID Protection
  3. Microsoft 365 usage reports
  4. Exchange mail flow rules

Correct Answer: 3

Explanation

Microsoft 365 usage reports provide administrators with information about service usage and user activity across supported workloads. These reports can help organizations understand adoption patterns, identify inactive users, and determine how actively different Microsoft 365 services are being used. Purview Audit provides more detailed records of supported activities, Entra ID Protection focuses on identity risks, and mail flow rules control message processing. Usage reports are therefore the appropriate resource when administrators need broader information about Microsoft 365 service adoption and utilization.

Question 271

An administrator wants to create a rule that automatically adds a disclaimer to outgoing emails. Which Exchange feature should be used?

  1. Microsoft Purview DLP
  2. Exchange mail flow rule
  3. Microsoft Entra access review
  4. Microsoft Secure Score

Correct Answer: 2

Explanation

Exchange Online mail flow rules can inspect messages as they pass through the service and perform configured actions. One common use is adding disclaimers to messages that meet specified conditions. Administrators can create conditions based on factors such as sender, recipient, message characteristics, or other supported criteria and then apply an action such as adding a disclaimer. Purview DLP focuses on sensitive-information protection, access reviews evaluate permissions, and Secure Score evaluates security posture. Mail flow rules are therefore appropriate for automatically adding email disclaimers.

Question 272

Which Microsoft Purview capability can identify predefined patterns such as passport numbers or financial information?

  1. Microsoft Purview sensitive information types
  2. Microsoft 365 Service Health
  3. Microsoft Intune
  4. Microsoft Defender XDR

Correct Answer: 1

Explanation

Microsoft Purview sensitive information types use predefined or custom detection patterns to identify specific categories of sensitive information. Examples can include financial information, government identifiers, or other regulated data depending on the available built-in definitions and organizational configuration. These detections can support DLP, classification, and other compliance controls. Service Health monitors Microsoft services, Intune manages devices, and Defender XDR focuses on security incidents. Sensitive information types are therefore the appropriate Purview capability for recognizing specific patterns of sensitive organizational data.

Question 273

Which Microsoft 365 capability can help investigate an email that was quarantined?

  1. Microsoft Intune
  2. Microsoft Purview retention
  3. Microsoft Defender portal
  4. Microsoft Entra Cloud Sync

Correct Answer: 3

Explanation

The Microsoft Defender portal provides security-focused investigation and management capabilities for email threats and quarantine-related activities, depending on the organization’s licensing and configuration. Administrators can review security alerts, messages, threats, and other relevant information to investigate why a message was treated as suspicious or malicious. Intune manages endpoints, Purview retention manages information lifecycle, and Cloud Sync synchronizes identities. The Defender portal is therefore the appropriate security-focused interface for investigating email threats and quarantine events.

Question 274

What is the main benefit of assigning Microsoft Entra roles according to job responsibilities?

  1. It increases mailbox storage automatically
  2. It supports least-privilege administration
  3. It disables audit logging
  4. It removes the need for authentication

Correct Answer: 2

Explanation

Assigning Microsoft Entra roles according to actual job responsibilities supports the principle of least privilege. Administrators receive the permissions necessary to perform their duties without automatically receiving unrelated or excessive administrative capabilities. This reduces the potential impact of compromised accounts and limits accidental configuration changes. Role-based administration also improves accountability because permissions can be associated with defined responsibilities. Increased mailbox storage, disabling audit logs, and removing authentication requirements are unrelated and potentially harmful outcomes. Role assignment based on responsibility therefore supports more controlled and secure administration.

Question 275

An organization needs to investigate who shared a sensitive document with an external user. Which capability should be examined?

  1. Microsoft Purview Audit
  2. Microsoft Secure Score
  3. Microsoft 365 Service Health
  4. Exchange Online Protection

Correct Answer: 1

Explanation

Microsoft Purview Audit can record supported sharing and file-related activities across Microsoft 365 workloads. Administrators can search relevant audit events to investigate actions involving documents, including supported sharing activities, and identify the account associated with a recorded event. This information can help determine what happened during a potential data-exposure incident. Secure Score provides security recommendations, Service Health reports service incidents, and Exchange Online Protection protects email. Purview Audit is therefore the most appropriate capability for investigating historical document-sharing activity.

Question 276

Which Microsoft 365 service is responsible for cloud-based device and application management?

  1. Microsoft Defender XDR
  2. Microsoft Purview
  3. Microsoft Intune
  4. Exchange Online

Correct Answer: 3

Explanation

Microsoft Intune provides cloud-based management capabilities for organizational devices and applications. Administrators can configure device policies, establish compliance requirements, deploy supported applications, and manage endpoint settings through Intune. Defender XDR focuses on security operations, Purview provides compliance and information-governance capabilities, and Exchange Online provides cloud email services. Intune is therefore the Microsoft 365 service most directly responsible for centralized device and application management.

Question 277

Which feature can help an organization require administrators to provide justification when activating a privileged role?

  1. Microsoft 365 usage reports
  2. Microsoft Entra Privileged Identity Management
  3. Exchange message trace
  4. Safe Links

Correct Answer: 2

Explanation

Microsoft Entra Privileged Identity Management can be configured with controls such as justification requirements when administrators activate eligible privileged roles. This creates an additional governance step around elevated access and can provide useful context for why a privileged action was necessary. PIM can also support other controls, including approval, multifactor authentication, and time-limited activation. Usage reports provide service activity information, message trace investigates email, and Safe Links protects against malicious URLs. PIM is therefore the appropriate capability for requiring justification during privileged-role activation.

Question 278

An administrator wants to prevent a user from accessing Microsoft 365 when the account is considered high risk. Which combination is most appropriate?

  1. Microsoft Entra ID Protection with Conditional Access
  2. Exchange Online Protection with Safe Attachments
  3. Microsoft Purview Audit with retention labels
  4. Microsoft Intune with Exchange message trace

Correct Answer: 1

Explanation

Microsoft Entra ID Protection can identify risk associated with users and sign-ins, while Conditional Access can use supported risk conditions to enforce access controls. Together, these capabilities can support policies that require additional authentication or block access when an account reaches a configured risk level. EOP and Safe Attachments protect email, Purview Audit and retention labels address activity recording and information lifecycle, and Intune with message trace combines unrelated endpoint and email functions. Entra ID Protection and Conditional Access are therefore the appropriate combination for risk-based identity access control.

Question 279

Which Microsoft 365 feature helps organizations control how long specific content should remain available?

  1. Microsoft Defender XDR
  2. Microsoft Entra ID Protection
  3. Microsoft Purview retention labels
  4. Exchange Online Protection

Correct Answer: 3

Explanation

Microsoft Purview retention labels allow organizations to apply specific retention requirements to supported content. A label can be associated with a defined retention period and other lifecycle settings according to organizational policies and applicable compliance requirements. This provides more targeted control over individual items or categories of information than relying only on broad service settings. Defender XDR handles security operations, Entra ID Protection manages identity risk, and Exchange Online Protection protects email. Retention labels are therefore appropriate when specific content requires defined lifecycle management.

Question 280

A Microsoft 365 administrator wants to reduce the number of users with permanent high-level privileges. Which action is most appropriate?

  1. Assign Global Administrator to every helpdesk employee
  2. Use Microsoft Entra Privileged Identity Management for eligible privileged roles
  3. Create one shared administrator account
  4. Disable administrative audit logging

Correct Answer: 2

Explanation

Microsoft Entra Privileged Identity Management can reduce permanent privileged access by allowing administrators to remain eligible for roles and activate them only when elevated permissions are needed. Organizations can apply additional safeguards such as multifactor authentication, approval, justification, and limited activation duration. Assigning Global Administrator broadly or sharing administrator credentials increases security and accountability risks, while disabling audit logging removes valuable investigation information. PIM therefore provides a structured method for reducing standing administrative privileges while preserving the ability to perform necessary privileged tasks.