{"id":16814,"date":"2026-09-19T11:26:02","date_gmt":"2026-09-19T11:26:02","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=16814"},"modified":"2026-09-19T11:26:02","modified_gmt":"2026-09-19T11:26:02","slug":"microsoft-ms-102-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-ms-102-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"Microsoft MS-102 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ms-102-exam-dumps\"><b>Microsoft MS-102 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<h3><b>Question 81<\/b><\/h3>\n<p><b>Which Microsoft 365 feature can be used to manage organization-wide password expiration and account lockout settings?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID provides identity and authentication management capabilities for Microsoft 365 users. Depending on the organization&#8217;s identity configuration, administrators can manage password-related settings and account controls through Microsoft Entra and associated identity policies. These controls help organizations establish requirements for authentication and account security. Microsoft Purview focuses on compliance and data governance, Defender XDR focuses on security detection and response, and Exchange Online manages email services. Identity-related password and authentication administration therefore belongs primarily within Microsoft Entra ID.<\/span><\/p>\n<h3><b>Question 82<\/b><\/h3>\n<p><b>An administrator wants to see whether a Microsoft 365 user has been assigned the correct product licenses. Where should the administrator check first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 admin center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint admin center<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Microsoft 365 admin center provides administrative tools for managing users and their assigned licenses. An administrator can open the relevant user account and review the products and services assigned to that account. This makes the admin center an appropriate starting point when troubleshooting licensing issues. The Defender portal focuses on security, Purview handles compliance and governance, and SharePoint administration focuses on SharePoint and OneDrive configuration. Reviewing the user&#8217;s license assignments through the Microsoft 365 admin center can help identify missing or incorrectly assigned subscriptions.<\/span><\/p>\n<h3><b>Question 83<\/b><\/h3>\n<p><b>Which Microsoft 365 service helps protect incoming email from spam and malware before delivery?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Exchange Online Protection (EOP) provides cloud-based email filtering and protection for Microsoft 365 organizations. It helps detect and filter threats such as spam, malware, and other unwanted messages before they reach users&#8217; mailboxes. EOP is integrated with Exchange Online and provides foundational email security capabilities. Microsoft Intune manages devices and applications, Microsoft Purview focuses on compliance and data governance, and Microsoft Entra ID manages identity and access. EOP is therefore the Microsoft 365 service specifically designed for the described inbound email protection function.<\/span><\/p>\n<h3><b>Question 84<\/b><\/h3>\n<p><b>A user reports that a legitimate email was incorrectly placed in the junk folder. Which investigation should the administrator perform first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Review the message trace and applicable anti-spam results<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Review SharePoint site permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Examine device compliance policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Search retention labels<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a legitimate message is incorrectly classified as spam, an administrator should investigate the message&#8217;s delivery path and filtering results. Message trace can help determine how Exchange Online processed the message, while anti-spam information can provide additional details about filtering decisions. Reviewing these details helps identify whether a policy, reputation signal, or filtering mechanism affected delivery. SharePoint permissions, device compliance, and retention labels address unrelated areas. The combination of message trace and email protection information provides a practical starting point for troubleshooting false-positive spam classifications.<\/span><\/p>\n<h3><b>Question 85<\/b><\/h3>\n<p><b>What is the primary purpose of Microsoft Intune in a Microsoft 365 environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manage devices and applications<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manage email transport rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Investigate audit events<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manage compliance searches<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Intune is a cloud-based endpoint management service used to manage devices, applications, and related organizational policies. Administrators can use Intune to establish device configuration requirements, deploy applications, manage mobile devices, and support organizational security requirements. Intune can also work with Microsoft Entra Conditional Access to help enforce device-based access decisions. Email transport rules belong primarily to Exchange Online, audit investigation is handled through Microsoft Purview, and compliance searches are associated with Purview capabilities. Intune therefore focuses primarily on endpoint and application management.<\/span><\/p>\n<h3><b>Question 86<\/b><\/h3>\n<p><b>Which Microsoft 365 capability can automatically remove a user&#8217;s license when the user no longer belongs to a licensing group?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Group-based licensing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Links<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retention policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Group-based licensing can automatically manage license assignments according to group membership. When a user is added to a properly configured licensing group, the assigned license can be applied automatically. When the user is removed from that group, the associated group-based license assignment can also be removed, subject to the tenant&#8217;s configuration and other direct assignments. This approach helps administrators automate license lifecycle management. Message trace, Safe Links, and retention policies serve email investigation, URL protection, and data governance functions respectively rather than license management.<\/span><\/p>\n<h3><b>Question 87<\/b><\/h3>\n<p><b>An organization needs to determine which Microsoft 365 administrators changed a specific tenant setting. Which capability should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Bookings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender Antivirus<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Audit can record administrative activities across supported Microsoft 365 services, allowing authorized administrators and compliance personnel to search for relevant events. When investigating a change to a tenant configuration, audit records can help identify the account associated with the action and provide information about when the activity occurred. This can be useful for accountability, security investigations, and troubleshooting unexpected configuration changes. Bookings, Intune, and Defender Antivirus have different purposes and are not the primary centralized source for investigating Microsoft 365 administrative activity.<\/span><\/p>\n<h3><b>Question 88<\/b><\/h3>\n<p><b>Which DNS record is commonly used to identify authorized mail servers for a domain?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TXT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CNAME<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MX<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PTR<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An MX, or Mail Exchange, record identifies the mail servers responsible for receiving email for a domain. When configuring a domain for Microsoft 365 email, the appropriate MX record directs incoming messages toward the organization&#8217;s designated mail service. TXT records are commonly used for information such as SPF and domain verification, CNAME records provide aliases and are used in several Microsoft 365 configurations, and PTR records support reverse DNS. Therefore, the MX record is the DNS record directly associated with identifying a domain&#8217;s receiving mail servers.<\/span><\/p>\n<h3><b>Question 89<\/b><\/h3>\n<p><b>What does SPF help a receiving mail system determine?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether the sending IP is authorized for the domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether a user has a valid Microsoft 365 license<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether a device is compliant<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether a file contains malware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Sender Policy Framework (SPF) helps receiving mail systems determine whether an email was sent from an IP address or mail server authorized by the domain&#8217;s SPF policy. The domain owner publishes an SPF record in DNS containing the relevant authorized sending sources. Receiving systems can evaluate that information as part of their email authentication and anti-spoofing decisions. SPF does not verify user licensing, device compliance, or file malware status. Those functions belong to different Microsoft 365 services and security controls.<\/span><\/p>\n<h3><b>Question 90<\/b><\/h3>\n<p><b>Which Microsoft 365 feature can help administrators manage the lifecycle of inactive Microsoft 365 groups?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 group expiration policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Attachments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender Antivirus<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 group expiration policies help organizations manage the lifecycle of groups that are no longer actively used. When expiration is configured, group owners may receive renewal notifications, and groups that are not renewed can eventually be marked for expiration according to the configured process. This helps reduce the accumulation of obsolete groups and associated resources. Message trace investigates email delivery, Safe Attachments analyzes potentially malicious files, and Defender Antivirus protects endpoints. Group expiration is therefore the relevant capability for managing inactive collaborative groups.<\/span><\/p>\n<h3><b>Question 91<\/b><\/h3>\n<p><b>An administrator wants users to access Microsoft 365 applications using their existing organizational credentials without maintaining separate application passwords. Which technology supports this?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data Loss Prevention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retention policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message trace<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Single sign-on (SSO) allows users to authenticate with an organizational identity provider and then access supported applications without repeatedly entering separate credentials for each application. In Microsoft 365 environments, Microsoft Entra ID provides identity and authentication services that support SSO for many cloud applications. This can improve the user experience while allowing administrators to apply centralized identity and access controls. Data Loss Prevention protects sensitive information, retention policies govern data lifecycle requirements, and message trace investigates email delivery rather than providing application authentication.<\/span><\/p>\n<h3><b>Question 92<\/b><\/h3>\n<p><b>Which Microsoft 365 capability helps organizations review whether users still need their assigned access to resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Links<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange archive<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra access reviews help organizations periodically review user access to groups, applications, and other supported resources. Reviewers can confirm whether users still require access and take appropriate actions based on the review results. This is particularly useful for managing guest access, privileged assignments, and membership in sensitive groups. Message trace investigates email delivery, Safe Links protects users from malicious URLs, and Exchange archive manages mailbox storage. Access reviews therefore provide a structured mechanism for validating that existing access remains appropriate over time.<\/span><\/p>\n<h3><b>Question 93<\/b><\/h3>\n<p><b>A company wants to allow only approved applications to access organizational Microsoft 365 data. Which identity capability is most relevant?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra application consent controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online archiving<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint version history<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra application consent controls help organizations manage how applications obtain permissions to access organizational data. Administrators can configure consent policies that restrict user consent and require administrative approval for certain application permissions. This provides greater control over third-party and enterprise applications requesting access to Microsoft 365 resources. Exchange archiving manages mailbox storage, SharePoint version history tracks document versions, and Secure Score provides security posture recommendations. Application consent management is therefore the appropriate identity control when organizations need tighter governance over application access.<\/span><\/p>\n<h3><b>Question 94<\/b><\/h3>\n<p><b>Which Microsoft 365 portal is primarily used to investigate security incidents and alerts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 admin center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint admin center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange admin center<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Microsoft Defender portal provides security teams with tools for investigating alerts, incidents, threats, and security-related activity across supported Microsoft security products. It can bring information from multiple Defender workloads into an integrated investigation experience. The Microsoft 365 admin center is intended for broader tenant administration, while SharePoint and Exchange admin centers focus on their respective services. When an administrator or security analyst needs to investigate security incidents rather than general tenant configuration, the Defender portal is the appropriate primary interface.<\/span><\/p>\n<h3><b>Question 95<\/b><\/h3>\n<p><b>What is the purpose of Microsoft Purview sensitivity labels?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Classify and protect sensitive organizational information<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure Exchange mailbox quotas<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manage endpoint hardware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route inbound email<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview sensitivity labels help organizations classify and protect information according to its sensitivity. Depending on the configuration and supported workload, labels can apply protection settings such as encryption, access restrictions, or visual markings. They can help users and administrators apply consistent information-protection controls to sensitive content. Mailbox quotas are managed through Exchange-related administration, endpoint hardware management is associated with device-management solutions such as Intune, and inbound email routing is handled through Exchange Online. Sensitivity labels therefore focus on information classification and protection.<\/span><\/p>\n<h3><b>Question 96<\/b><\/h3>\n<p><b>An administrator needs to investigate whether a user downloaded files from SharePoint. Which Microsoft 365 capability is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Service Health<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Audit can record supported user activities involving Microsoft 365 services, including relevant SharePoint and OneDrive operations. Administrators can search audit records for activities such as file access, downloads, sharing, and other supported events. This can help establish what actions occurred and which account performed them. Service Health reports service incidents, Exchange Online Protection protects email, and Secure Score evaluates security posture. For an investigation focused on whether a user downloaded files from SharePoint, Purview Audit is the appropriate source to examine.<\/span><\/p>\n<h3><b>Question 97<\/b><\/h3>\n<p><b>Which Microsoft 365 capability can help detect and investigate insider-related risks involving organizational data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Insider Risk Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune App Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Service Health<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Insider Risk Management is designed to help organizations identify, investigate, and respond to potential insider risks involving organizational information. It can use signals from supported activities and policies to identify potentially risky behavior while incorporating privacy-oriented controls and investigation workflows. Exchange Online Protection focuses on email threats, Intune App Protection applies controls to applications and data on supported devices, and Service Health reports Microsoft service status. Insider Risk Management is therefore the capability specifically associated with identifying potential insider-related data security risks.<\/span><\/p>\n<h3><b>Question 98<\/b><\/h3>\n<p><b>What is the main purpose of a retention policy in Microsoft Purview?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manage how long organizational content is retained or disposed of<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authenticate incoming email<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manage Windows device configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detect endpoint malware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview retention policies help organizations manage the lifecycle of supported content by specifying how long information should be retained and, where applicable, what should happen when the retention period ends. Retention requirements can support legal, regulatory, and organizational information-governance needs. Retention policies are different from email authentication, device management, and malware protection. SPF and related DNS controls address email authentication, Intune manages devices, and Defender security products detect threats. Purview retention capabilities therefore focus on controlling the lifecycle of organizational data.<\/span><\/p>\n<h3><b>Question 99<\/b><\/h3>\n<p><b>An organization wants administrators to receive recommendations for improving its Microsoft 365 security posture. Which feature should they review?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Archive<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 group calendar<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint Version History<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Secure Score provides an assessment of an organization&#8217;s security posture and presents recommended actions that can improve security controls. Administrators can review recommendations, determine which changes are appropriate for the organization&#8217;s environment, and track improvements over time. Secure Score is not simply an incident investigation system; it is intended to provide security improvement guidance across relevant Microsoft 365 controls. Exchange archiving, group calendars, and SharePoint version history provide storage or collaboration capabilities and do not serve as the primary mechanism for security posture recommendations.<\/span><\/p>\n<h3><b>Question 100<\/b><\/h3>\n<p><b>Which administrative approach best reduces the risk of unauthorized changes to sensitive Microsoft 365 settings?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Give all administrators Global Administrator access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use specialized roles and require stronger authentication for privileged accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable auditing for administrative activities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow administrators to share credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Using specialized administrative roles together with stronger authentication for privileged accounts helps reduce the risk associated with highly privileged access. Specialized roles support least-privilege administration by limiting administrators to permissions required for their responsibilities, while strong authentication provides additional protection against credential compromise. Giving every administrator Global Administrator access increases the potential impact of a compromised account. Disabling auditing removes valuable investigation evidence, and credential sharing weakens accountability. A combination of role separation, strong authentication, and appropriate monitoring provides a more controlled administrative model.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps. Question 81 Which Microsoft 365 feature can be used to manage organization-wide password expiration and account lockout settings? Microsoft Purview Microsoft Entra ID Microsoft Defender XDR Exchange Online Correct Answer: 2 Explanation Microsoft Entra ID provides identity and authentication management capabilities for Microsoft 365 users. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16814"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=16814"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16814\/revisions"}],"predecessor-version":[{"id":16845,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16814\/revisions\/16845"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=16814"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=16814"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=16814"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}