{"id":16815,"date":"2026-09-19T11:25:47","date_gmt":"2026-09-19T11:25:47","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=16815"},"modified":"2026-09-19T11:25:47","modified_gmt":"2026-09-19T11:25:47","slug":"microsoft-ms-102-practice-test-questions-and-exam-dumps-part6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-ms-102-practice-test-questions-and-exam-dumps-part6-q101-120\/","title":{"rendered":"Microsoft MS-102 Practice Test Questions and Exam Dumps Part6 Q101-120"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ms-102-exam-dumps\"><b>Microsoft MS-102 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<h3><b>Question 101<\/b><\/h3>\n<p><b>Which Microsoft 365 service is used to manage organizational devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Office 365<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Intune is a cloud-based service for managing organizational devices, applications, and endpoint policies. Administrators can use Intune to configure supported devices, deploy applications, enforce security requirements, and manage access-related device conditions. Intune can also integrate with Microsoft Entra ID and Conditional Access so that access decisions can consider device compliance. Microsoft Purview focuses on compliance and data governance, Exchange Online provides email services, and Defender for Office 365 protects collaboration and email workloads. Therefore, Intune is the appropriate service for centralized device management.<\/span><\/p>\n<h3><b>Question 102<\/b><\/h3>\n<p><b>A company wants to require employees to use Microsoft Authenticator for multifactor authentication. Which area should the administrator configure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra authentication methods<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange transport rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Purview retention settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra authentication methods policies allow organizations to manage which authentication methods users can register and use. Microsoft Authenticator can be enabled and configured as an authentication method, while administrators can control its availability for appropriate users or groups. This supports stronger authentication for Microsoft 365 accounts. Exchange transport rules affect mail flow, SharePoint permissions control access to SharePoint resources, and Purview retention settings govern data lifecycle requirements. Authentication method configuration should therefore be performed within the Microsoft Entra identity and authentication management capabilities.<\/span><\/p>\n<h3><b>Question 103<\/b><\/h3>\n<p><b>What does Microsoft Entra Conditional Access evaluate before granting access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access signals and policy conditions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only mailbox size<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only SharePoint storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only DNS records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access evaluates signals and conditions associated with a sign-in before applying an access control decision. Depending on the configured policies, these signals can include the user, group, application, device, location, sign-in risk, and other supported conditions. Administrators can then require controls such as multifactor authentication, compliant devices, or other access requirements. Conditional Access is therefore more flexible than a single-factor rule based on mailbox size, SharePoint storage, or DNS information. It provides policy-based access control for supported Microsoft cloud resources.<\/span><\/p>\n<h3><b>Question 104<\/b><\/h3>\n<p><b>Which tool can help identify directory objects that may cause synchronization problems before they are synchronized to Microsoft Entra ID?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IdFix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message Trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Links<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IdFix is designed to help administrators identify and remediate common identity-related errors in on-premises Active Directory before synchronization with Microsoft Entra ID. It can detect issues involving attributes such as duplicate values, invalid characters, and formatting problems that could interfere with synchronization. Message Trace is used to investigate email delivery, Secure Score evaluates security posture, and Safe Links protects users from malicious URLs. By identifying directory data problems early, IdFix can help organizations reduce synchronization errors during hybrid identity deployments.<\/span><\/p>\n<h3><b>Question 105<\/b><\/h3>\n<p><b>An administrator needs to delegate management of users in one department without granting tenant-wide administrative permissions. Which feature is useful?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrative units<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mail flow rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retention labels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Attachments<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra administrative units allow organizations to define administrative scopes for directory objects. They can be useful when a department, region, campus, or other organizational unit needs delegated administration without granting an administrator unrestricted control over the entire tenant. Appropriate roles can be assigned with a scope associated with the administrative unit. Mail flow rules manage email processing, retention labels support data governance, and Safe Attachments analyzes potentially harmful email attachments. Administrative units therefore provide a mechanism for more limited and structured directory administration.<\/span><\/p>\n<h3><b>Question 106<\/b><\/h3>\n<p><b>Which feature can help protect users from malicious URLs contained in email messages?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Links<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Attachments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retention policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Safe Links is a Microsoft Defender for Office 365 capability designed to provide protection against malicious URLs. It can inspect links and apply configured policies when users interact with URLs in supported Microsoft 365 workloads. Safe Attachments has a different purpose: it evaluates potentially malicious email attachments. Retention policies govern how long data is retained, while access reviews help organizations review user access. Therefore, when the security concern specifically involves harmful links in email or other supported messages, Safe Links is the relevant protection mechanism.<\/span><\/p>\n<h3><b>Question 107<\/b><\/h3>\n<p><b>Which feature analyzes potentially harmful email attachments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Links<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Attachments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access Reviews<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Safe Attachments is a Microsoft Defender for Office 365 capability that helps protect organizations from malicious files delivered through email and supported collaboration workloads. It analyzes attachments according to the configured protection policy and can take actions designed to prevent users from interacting with harmful content. Safe Links instead focuses on URLs, while Conditional Access controls access based on identity and other signals. Access Reviews are used to periodically review permissions or memberships. Safe Attachments is therefore specifically suited to protecting users from malicious or suspicious email attachments.<\/span><\/p>\n<h3><b>Question 108<\/b><\/h3>\n<p><b>An organization wants to control access to corporate resources when a sign-in is detected as risky. Which feature should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Archive<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint Version History<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Service Health<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Conditional Access can use sign-in risk as a condition when integrated with Microsoft Entra risk detection capabilities. An organization can create policies that require additional controls or block access when the risk level meets defined criteria. This allows access decisions to respond dynamically to suspicious authentication activity. Exchange Online Archive manages mailbox storage, SharePoint Version History maintains document versions, and Service Health reports Microsoft service status. Conditional Access is therefore the appropriate policy mechanism for applying access controls based on detected sign-in risk.<\/span><\/p>\n<h3><b>Question 109<\/b><\/h3>\n<p><b>What is the purpose of Microsoft Defender for Office 365?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Protect collaboration and email workloads from security threats<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manage Microsoft 365 billing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure organizational domains<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manage SharePoint document versions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Office 365 provides security capabilities for supported Microsoft 365 collaboration and communication workloads. It helps protect organizations against threats such as malicious links, harmful attachments, phishing, and other email-related attacks, depending on the licensed features and configuration. Billing is managed through Microsoft 365 administrative capabilities, domains are managed through tenant administration, and SharePoint version history handles document versions. Defender for Office 365 is therefore primarily focused on protecting users and organizational data from threats delivered through email and collaboration services.<\/span><\/p>\n<h3><b>Question 110<\/b><\/h3>\n<p><b>Which Microsoft 365 feature can provide recommendations for strengthening security controls?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Calendar<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Archive<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint Version History<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Secure Score provides organizations with security posture information and recommended improvement actions. Administrators can review recommendations related to identity, devices, data, applications, and other security areas, depending on the services and configuration in use. The recommendations can help administrators identify security controls that may be strengthened and monitor changes in the organization&#8217;s posture. Calendar, Exchange archive, and SharePoint version history are productivity or storage features and do not provide the same centralized security improvement guidance.<\/span><\/p>\n<h3><b>Question 111<\/b><\/h3>\n<p><b>An administrator needs to investigate a suspicious sign-in involving an unusual location. Which data should be reviewed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra sign-in logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange mailbox quota<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint storage metrics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 billing history<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra sign-in logs contain information about authentication events and can help administrators investigate suspicious access. Depending on the event and available signals, administrators can review details such as the user, application, IP address, location, device, authentication result, and Conditional Access information. These details can help determine whether the sign-in succeeded and what controls were applied. Mailbox quotas, SharePoint storage metrics, and billing information do not provide the necessary authentication context. Sign-in logs are therefore the appropriate starting point for investigating unusual sign-in locations.<\/span><\/p>\n<h3><b>Question 112<\/b><\/h3>\n<p><b>Which Microsoft 365 capability allows an organization to search recorded activities across supported services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Connect Sync<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Audit provides tools for searching and reviewing recorded activities across supported Microsoft 365 services. Audit data can assist with security investigations, compliance reviews, troubleshooting, and accountability. Depending on the workload, administrators can investigate activities such as file operations, administrative changes, sharing events, and other recorded actions. Intune manages devices and applications, Exchange Online Protection protects email, and Microsoft Entra Connect Sync synchronizes identities between environments. Purview Audit is therefore the appropriate capability when the objective is searching recorded user or administrator activities.<\/span><\/p>\n<h3><b>Question 113<\/b><\/h3>\n<p><b>Which identity feature can automatically add users to a group based on attributes such as department or job title?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic membership<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual licensing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mail flow rules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic membership allows supported Microsoft Entra groups to automatically include or remove users based on defined user or device attributes. An organization could create a rule that includes users whose department equals a particular value or whose job title matches a defined condition. Membership is then evaluated automatically as relevant attributes change. Manual licensing requires administrator action, message trace investigates email delivery, and mail flow rules process messages. Dynamic membership is therefore useful for maintaining groups automatically when organizational attributes determine membership.<\/span><\/p>\n<h3><b>Question 114<\/b><\/h3>\n<p><b>A company wants to prevent employees from sending documents containing credit card information outside the organization. Which technology should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Service Health<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Archive<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Connect Sync<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention can identify sensitive information types and apply policies designed to prevent or control inappropriate sharing of protected information. Credit card numbers are an example of sensitive information that can be detected using supported sensitive information types. Depending on the workload and policy configuration, DLP can provide policy tips, alerts, or blocking actions for certain activities. Service Health monitors Microsoft service status, Exchange archiving manages mailbox storage, and Entra Connect Sync handles identity synchronization. DLP is therefore the relevant technology for controlling sensitive-data transmission.<\/span><\/p>\n<h3><b>Question 115<\/b><\/h3>\n<p><b>What is the main function of Microsoft Entra ID Protection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detect and help respond to identity risks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manage SharePoint storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure Exchange connectors<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scan document versions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID Protection helps organizations detect, investigate, and respond to identity-related risks. It can identify risk signals associated with users and sign-ins and provide risk information that can be incorporated into identity security processes. Administrators can use this information alongside other Microsoft Entra capabilities to apply appropriate responses. SharePoint storage management, Exchange connector configuration, and document version control are unrelated functions. Entra ID Protection is specifically focused on protecting identities by identifying potentially compromised users and suspicious authentication activity.<\/span><\/p>\n<h3><b>Question 116<\/b><\/h3>\n<p><b>Which Microsoft Purview feature helps an organization investigate and manage electronic evidence for legal or compliance matters?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">eDiscovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Links<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device compliance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview eDiscovery provides capabilities for identifying, collecting, reviewing, and managing electronically stored information relevant to legal or compliance investigations. Authorized users can work with cases and supported data sources to locate potentially relevant content according to organizational procedures and permissions. Safe Links protects against malicious URLs, Secure Score provides security posture recommendations, and device compliance evaluates endpoint requirements. eDiscovery is therefore the Microsoft Purview capability specifically designed to support investigations involving electronically stored information.<\/span><\/p>\n<h3><b>Question 117<\/b><\/h3>\n<p><b>Which Microsoft 365 feature allows an administrator to trace an email to determine how it was processed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device enrollment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Message trace in Exchange Online helps administrators investigate the path and processing of email messages. It can provide information about whether a message was received, delivered, rejected, quarantined, or otherwise processed according to available tracking information. This makes message trace useful when troubleshooting missing messages, delayed delivery, or suspected mail-flow issues. Access reviews concern permissions, audit retention concerns the preservation of audit records, and device enrollment relates to endpoint management. For an email-delivery investigation, message trace is the appropriate administrative tool.<\/span><\/p>\n<h3><b>Question 118<\/b><\/h3>\n<p><b>An administrator wants to assign a role only when elevated permissions are required instead of keeping the role active permanently. Which capability supports this approach?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint Version History<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management (PIM) supports just-in-time and controlled access to privileged roles. Instead of keeping elevated permissions permanently active, eligible administrators can activate roles when necessary according to configured requirements and controls. Depending on the configuration, activation can involve multifactor authentication, approval, justification, or time limits. Exchange Online Protection protects email, Purview retention manages data lifecycle requirements, and SharePoint Version History tracks document versions. PIM is therefore the capability designed to reduce persistent privileged access while supporting administrative responsibilities.<\/span><\/p>\n<h3><b>Question 119<\/b><\/h3>\n<p><b>Which Microsoft 365 capability can help administrators manage external guest access over time?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Attachments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra access reviews can be used to periodically review guest users and determine whether they still require access to organizational resources. Reviewers can assess guest membership and take appropriate action according to organizational policies. This helps reduce the risk of retaining unnecessary external access for long periods. Message trace investigates email delivery, Safe Attachments protects against malicious files, and Secure Score provides security recommendations. Access reviews are therefore particularly useful for maintaining appropriate guest access as collaboration relationships change.<\/span><\/p>\n<h3><b>Question 120<\/b><\/h3>\n<p><b>Which administrative practice provides the strongest foundation for protecting privileged Microsoft 365 accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Share one administrator account among several employees<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign broad roles to every support employee<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use dedicated privileged accounts with multifactor authentication and limited roles<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable sign-in auditing for administrators<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dedicated privileged accounts, multifactor authentication, and appropriately limited administrative roles provide multiple layers of protection for privileged access. Separating administrative activity from normal user activity reduces exposure of elevated credentials, while multifactor authentication adds an additional authentication requirement. Limiting roles reduces the permissions available if an administrative account is compromised. Shared administrator accounts weaken accountability, broad role assignments increase unnecessary privilege, and disabling auditing removes valuable evidence. Combining identity separation, strong authentication, and least-privilege role assignment provides a controlled administrative model.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps. Question 101 Which Microsoft 365 service is used to manage organizational devices? Microsoft Purview Microsoft Intune Exchange Online Microsoft Defender for Office 365 Correct Answer: 2 Explanation Microsoft Intune is a cloud-based service for managing organizational devices, applications, and endpoint policies. Administrators can use Intune [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16815"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=16815"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16815\/revisions"}],"predecessor-version":[{"id":16844,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16815\/revisions\/16844"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=16815"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=16815"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=16815"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}