Microsoft MS-102 Practice Test Questions and Exam Dumps Part7 Q121-140

View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps.

Question 121

Which Microsoft 365 service is primarily used to manage SharePoint sites and OneDrive settings?

  1. Exchange admin center
  2. Microsoft Defender portal
  3. SharePoint admin center
  4. Microsoft Purview portal

Correct Answer: 3

Explanation

The SharePoint admin center provides administrative controls for SharePoint Online and OneDrive for Business. Administrators can manage site settings, sharing controls, storage configuration, access-related options, and other SharePoint and OneDrive features from this portal. The Exchange admin center focuses on email administration, while the Defender portal provides security management and Purview focuses on compliance and data governance. When an administrator needs to configure organization-wide SharePoint or OneDrive behavior, the SharePoint admin center is the appropriate administrative interface.

Question 122

What does Microsoft 365 Apps admin center primarily help administrators manage?

  1. Microsoft 365 Apps deployment and configuration
  2. Email authentication
  3. Purview eDiscovery cases
  4. Entra administrative units

Correct Answer: 1

Explanation

The Microsoft 365 Apps admin center provides tools for managing Microsoft 365 Apps deployment, configuration, and related application-management tasks. Administrators can use it to manage deployment configurations and monitor relevant application information across an organization. Email authentication is handled through Exchange Online and DNS-based controls, eDiscovery is managed through Microsoft Purview, and administrative units belong to Microsoft Entra administration. The Apps admin center is therefore focused on the lifecycle and administration of Microsoft 365 desktop applications rather than identity, compliance, or email security.

Question 123

An administrator wants to control whether users can create Microsoft 365 groups. Which setting is relevant?

  1. Safe Links policy
  2. Microsoft 365 group creation settings
  3. Retention label
  4. Device compliance policy

Correct Answer: 2

Explanation

Microsoft 365 provides controls that organizations can use to manage who is permitted to create Microsoft 365 groups. Restricting group creation can help organizations maintain governance over collaborative resources and prevent uncontrolled growth of groups. The configuration can be used to limit group creation to designated users or groups according to organizational requirements. Safe Links protects against malicious URLs, retention labels manage information protection and lifecycle requirements, and device compliance policies govern endpoint conditions. Group creation settings are therefore the relevant control for this scenario.

Question 124

Which feature can be used to assign Microsoft 365 licenses to members of a specific group?

  1. Message trace
  2. Safe Attachments
  3. Group-based licensing
  4. Service Health

Correct Answer: 3

Explanation

Group-based licensing allows administrators to assign supported Microsoft 365 licenses to members of a group rather than configuring every user individually. When users become members of the group, the applicable license assignment can be applied automatically. This simplifies licensing administration and helps maintain consistent assignments as membership changes. Message trace is used for email investigation, Safe Attachments protects against malicious files, and Service Health provides information about Microsoft service incidents. Group-based licensing is therefore the appropriate feature when licensing needs to follow group membership.

Question 125

Which role can manage user and group settings in Microsoft Entra ID without requiring Global Administrator permissions for every task?

  1. User Administrator
  2. Billing Administrator
  3. Service Support Administrator
  4. Message Center Reader

Correct Answer: 1

Explanation

The User Administrator role provides permissions for managing many user and group-related tasks in Microsoft Entra ID without requiring the broad privileges of the Global Administrator role. Using specialized roles supports the principle of least privilege by giving administrators only the permissions required for their responsibilities. Billing Administrator is focused on billing functions, Service Support Administrator supports service-related tasks, and Message Center Reader primarily provides access to service communications. The User Administrator role is therefore more appropriate for routine user and group management responsibilities.

Question 126

A company wants to prevent users from accessing Microsoft 365 from countries where the organization does not operate. Which Conditional Access condition can support this requirement?

  1. Device ownership
  2. Named locations
  3. Mailbox type
  4. Sensitivity label

Correct Answer: 2

Explanation

Conditional Access named locations can represent specific network locations or geographic regions and can be used as conditions in access policies. Administrators can configure policies that apply different access controls depending on whether a sign-in originates from an approved or restricted location. This can help organizations control access based on geographic or network requirements. Device ownership, mailbox type, and sensitivity labels serve different purposes and do not provide the geographic access condition described. Named locations are therefore relevant when implementing location-based Conditional Access policies.

Question 127

What is the primary purpose of Microsoft 365 Service Health?

  1. Manage user passwords
  2. Configure device policies
  3. Display information about service incidents and advisories
  4. Search audit records

Correct Answer: 3

Explanation

Microsoft 365 Service Health provides administrators with information about incidents, advisories, planned maintenance, and other service-related events that may affect their organization. It helps administrators determine whether an issue reported by users could be related to a Microsoft service problem rather than an internal configuration. Service Health is not intended for password administration, device management, or audit searching. Those tasks belong to identity, endpoint management, and compliance tools respectively. Service Health therefore provides operational visibility into the availability and status of Microsoft 365 services.

Question 128

Which setting can help restrict external sharing in SharePoint Online?

  1. External sharing configuration
  2. Exchange mailbox quota
  3. Microsoft Entra password policy
  4. Safe Attachments

Correct Answer: 1

Explanation

SharePoint Online provides external sharing settings that administrators can use to control how content is shared with people outside the organization. Depending on the configured organizational and site-level settings, administrators can restrict or permit different types of external sharing. These controls help organizations balance collaboration requirements with information-protection needs. Exchange mailbox quotas manage mailbox storage, Microsoft Entra password policies concern authentication, and Safe Attachments protects against malicious files. External sharing configuration is therefore the appropriate control when the goal is to limit external access to SharePoint content.

Question 129

An administrator needs to configure mail flow between Microsoft 365 and an external email system. Which Exchange feature should be considered?

  1. Retention labels
  2. Connectors
  3. Access reviews
  4. Authentication methods

Correct Answer: 2

Explanation

Exchange Online connectors provide a mechanism for configuring mail flow between Microsoft 365 and external or specialized email systems. Organizations may use connectors when integrating Microsoft 365 with another mail environment, security service, or trusted mail-flow partner. Connector configuration can define how messages are routed and how communication between systems is handled. Retention labels are related to data governance, access reviews evaluate permissions, and authentication methods manage identity verification. Connectors are therefore the relevant Exchange feature when an organization needs to establish controlled mail flow with another email system.

Question 130

Which Microsoft Purview capability helps organizations identify sensitive data using predefined or custom detection patterns?

  1. Microsoft Secure Score
  2. Microsoft Purview Audit
  3. Sensitive information types
  4. Service Health

Correct Answer: 3

Explanation

Sensitive information types are used by Microsoft Purview to identify specific categories of sensitive information within supported content. They can detect patterns associated with data such as financial information, identification numbers, or other organizationally defined sensitive content. Organizations can use built-in sensitive information types or create custom ones for specific requirements. Secure Score evaluates security posture, Audit records activities, and Service Health reports service status. Sensitive information types therefore provide the detection foundation used by several Purview compliance and data-protection capabilities.

Question 131

What is the purpose of Microsoft 365 message center?

  1. Provide information about upcoming changes and new Microsoft 365 features
  2. Manage mailbox transport rules
  3. Configure endpoint antivirus
  4. Create retention labels

Correct Answer: 1

Explanation

The Microsoft 365 message center provides administrators with information about planned changes, new features, service updates, and other developments that may affect their organization. Reviewing message center communications helps administrators prepare for changes and understand actions that may be required before or after a feature update. Mailbox transport rules are managed through Exchange Online, endpoint security is handled through appropriate Defender and Intune capabilities, and retention labels are managed through Microsoft Purview. Message center is therefore an important source of operational and service-change information for Microsoft 365 administrators.

Question 132

Which Microsoft 365 capability can help an administrator review the health and security posture of a tenant from an administrative perspective?

  1. Microsoft 365 admin center
  2. Exchange Online Archive
  3. SharePoint Version History
  4. Microsoft Forms

Correct Answer: 1

Explanation

The Microsoft 365 admin center provides a broad administrative view of the tenant, including users, licenses, domains, service status, organizational settings, and links to other management experiences. It serves as a central starting point for many Microsoft 365 administrative activities. Exchange Online Archive focuses on mailbox storage, SharePoint Version History tracks document changes, and Microsoft Forms provides survey and form capabilities. While specialized portals provide deeper functionality for individual workloads, the Microsoft 365 admin center provides broad tenant-level administrative visibility.

Question 133

A user leaves the company. Which action should an administrator consider as part of the account offboarding process?

  1. Increase the user’s mailbox quota
  2. Block the user’s sign-in
  3. Disable all audit logging
  4. Remove the organization’s DNS records

Correct Answer: 2

Explanation

Blocking a departing user’s sign-in is an important step in account offboarding because it prevents the account from continuing to authenticate to organizational resources. Administrators should also consider other lifecycle actions based on organizational procedures, such as handling licenses, mailbox access, data retention, and ownership of resources. Increasing mailbox capacity or removing organizational DNS records would not address the user’s access. Disabling audit logging would also remove useful security and accountability information. Blocking sign-in is therefore a fundamental identity-management action during user offboarding.

Question 134

Which Microsoft 365 feature can help administrators review and manage inactive user accounts?

  1. User account and sign-in activity information
  2. Safe Links
  3. DKIM
  4. SharePoint version history

Correct Answer: 1

Explanation

User account and sign-in activity information can help administrators identify accounts that have not been used recently. Reviewing authentication activity is useful for account lifecycle management because inactive accounts may require investigation, disabling, or other administrative action according to organizational policies. Safe Links protects users from malicious URLs, DKIM provides email authentication, and SharePoint version history tracks document changes. Administrators should consider sign-in activity alongside organizational retention and account-management procedures when identifying potentially inactive accounts.

Question 135

Which Microsoft 365 capability provides a centralized view of security incidents generated by supported Defender services?

  1. Microsoft 365 admin center
  2. Microsoft Defender XDR incidents
  3. SharePoint admin center
  4. Microsoft Purview retention

Correct Answer: 2

Explanation

Microsoft Defender XDR provides an incident-management experience that can correlate related alerts from supported Microsoft security products. Instead of investigating every alert independently, security teams can review incidents containing related security signals and investigate the broader activity. This helps provide context around potentially connected threats. The Microsoft 365 admin center handles general tenant administration, SharePoint admin center manages SharePoint and OneDrive settings, and Purview retention manages data lifecycle requirements. Defender XDR incidents are therefore the appropriate centralized security investigation view.

Question 136

An organization wants to make sure only compliant devices can access corporate applications. What combination is most relevant?

  1. Exchange Online and DKIM
  2. Microsoft Purview and eDiscovery
  3. Microsoft Intune and Conditional Access
  4. SharePoint and retention labels

Correct Answer: 3

Explanation

Microsoft Intune and Conditional Access can work together to enforce device-based access requirements. Intune evaluates and manages device compliance according to configured policies, while Conditional Access can require a device to be compliant before allowing access to specified applications or resources. This combination allows organizations to connect endpoint security requirements with identity-based access decisions. Exchange Online and DKIM address email authentication, Purview and eDiscovery address compliance investigations, and SharePoint with retention labels addresses content management. Intune and Conditional Access directly support the described access requirement.

Question 137

What does a DMARC policy help a domain owner communicate to receiving mail systems?

  1. How to handle messages that fail specified email authentication checks
  2. Which users should receive Microsoft 365 licenses
  3. Which devices are compliant
  4. Which SharePoint sites should expire

Correct Answer: 1

Explanation

DMARC, or Domain-based Message Authentication, Reporting, and Conformance, allows a domain owner to publish a policy describing how receiving mail systems should handle messages that fail the domain’s authentication requirements. DMARC works with mechanisms such as SPF and DKIM and can also provide reporting information depending on the configuration. Licensing, device compliance, and SharePoint lifecycle management are unrelated functions. DMARC is therefore an important component of an organization’s email-authentication and anti-spoofing strategy.

Question 138

Which Microsoft 365 feature allows administrators to create policies that detect and protect sensitive information across supported workloads?

  1. Microsoft Purview DLP
  2. Microsoft Entra Connect Sync
  3. Exchange mailbox archive
  4. Microsoft 365 Service Health

Correct Answer: 1

Explanation

Microsoft Purview Data Loss Prevention policies can identify sensitive information and apply configured actions when users perform activities involving that information. Depending on the workload and policy configuration, DLP can provide notifications, alerts, policy tips, or restrictions for certain activities. This allows organizations to reduce accidental or inappropriate exposure of sensitive information. Entra Connect Sync synchronizes identities, mailbox archiving manages email storage, and Service Health reports service issues. Purview DLP is therefore the appropriate capability for creating sensitive-data protection policies across supported workloads.

Question 139

Which Microsoft Entra feature can provide temporary elevated access to a privileged role?

  1. Dynamic groups
  2. Microsoft Entra Privileged Identity Management
  3. User Administrator
  4. Password writeback

Correct Answer: 2

Explanation

Microsoft Entra Privileged Identity Management supports controlled, time-limited activation of privileged roles. Instead of requiring administrators to maintain permanent active privileges, eligible users can activate a role when elevated permissions are needed. Organizations can configure additional requirements such as multifactor authentication, approval, justification, and activation duration. Dynamic groups automate group membership, the User Administrator is a directory role, and password writeback supports synchronization of password changes to on-premises environments. PIM is therefore specifically designed for controlling and limiting privileged role activation.

Question 140

An administrator needs to confirm whether a recently reported Microsoft 365 problem is part of a known service incident. Where should the administrator look?

  1. Microsoft Purview Audit
  2. Microsoft Defender portal
  3. Microsoft 365 Service Health
  4. Microsoft Entra ID Protection

Correct Answer: 3

Explanation

Microsoft 365 Service Health is the appropriate place to determine whether Microsoft has reported a known service incident or advisory affecting the organization. It provides information about service status, incidents, advisories, and relevant updates. This can help administrators distinguish a Microsoft service issue from a tenant-specific configuration problem. Purview Audit is used for activity investigation, Defender focuses on security threats, and Entra ID Protection addresses identity risks. Therefore, Service Health should be checked first when an administrator suspects that a reported Microsoft 365 problem may be part of a broader service incident.