{"id":16819,"date":"2026-09-19T11:24:58","date_gmt":"2026-09-19T11:24:58","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=16819"},"modified":"2026-09-19T11:24:58","modified_gmt":"2026-09-19T11:24:58","slug":"microsoft-ms-102-practice-test-questions-and-exam-dumps-part10-q181-200","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-ms-102-practice-test-questions-and-exam-dumps-part10-q181-200\/","title":{"rendered":"Microsoft MS-102 Practice Test Questions and Exam Dumps Part10 Q181-200"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ms-102-exam-dumps\"><b>Microsoft MS-102 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 181<\/b><\/h3>\n<p><b>Which Microsoft 365 service is used to manage Teams-related organizational settings?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange admin center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Teams admin center<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Microsoft Teams admin center provides administrative controls for Microsoft Teams across an organization. Administrators can manage Teams policies, meeting settings, messaging policies, voice configurations, users, and other Teams-related options depending on their permissions and licensing. The Purview portal focuses on compliance and data governance, Exchange admin center manages Exchange Online, and Defender handles security operations. When an administrator needs to configure organization-wide Teams behavior or policies, the Teams admin center is the appropriate management interface.<\/span><\/p>\n<h3><b>Question 182<\/b><\/h3>\n<p><b>Which role provides read-only access to administrative information across Microsoft 365 without allowing configuration changes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global Reader<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User Administrator<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Global Reader role provides read-only access to administrative information and settings across Microsoft 365 and Microsoft Entra environments where supported. It is useful for administrators or personnel who need broad visibility for auditing, troubleshooting, or monitoring but should not be able to make configuration changes. Global Administrator provides extensive write permissions, while Exchange Administrator and User Administrator provide more specialized administrative capabilities. Assigning Global Reader instead of a write-enabled role can support least-privilege principles when an individual only needs visibility into the tenant.<\/span><\/p>\n<h3><b>Question 183<\/b><\/h3>\n<p><b>An organization needs to verify ownership of a custom domain before using it with Microsoft 365. What is typically required?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Creating a retention label<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adding a DNS verification record<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuring Safe Links<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Creating an access review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 requires organizations to verify ownership of a custom domain before using it for supported tenant services. Domain verification is commonly completed by adding a specific DNS record, often a TXT record, provided by Microsoft to the organization&#8217;s DNS hosting environment. Microsoft checks the record to confirm control over the domain. Retention labels, Safe Links, and access reviews address data governance, URL security, and access management respectively. DNS verification is therefore an essential step when introducing a custom domain into a Microsoft 365 tenant.<\/span><\/p>\n<h3><b>Question 184<\/b><\/h3>\n<p><b>Which Microsoft 365 feature can help administrators identify applications that have been granted permissions to access organizational data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra enterprise applications<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint Version History<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra enterprise applications provides management capabilities for applications that users or administrators have integrated with the organization&#8217;s identity environment. Administrators can review application configurations, permissions, assignments, and other settings depending on the application type and available controls. This visibility helps organizations understand which applications have access to organizational resources and manage that access appropriately. Message trace investigates email delivery, Secure Score evaluates security posture, and SharePoint Version History tracks document changes. Enterprise applications is therefore the relevant area for application-access administration.<\/span><\/p>\n<h3><b>Question 185<\/b><\/h3>\n<p><b>What is the primary purpose of Microsoft 365 audit retention settings?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure email authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manage endpoint compliance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign Microsoft 365 licenses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control how long audit records are retained<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Audit retention settings determine how long audit records remain available for investigation and compliance purposes, subject to the applicable Microsoft 365 licensing and auditing capabilities. Maintaining audit records for an appropriate period can help organizations investigate historical activities and meet regulatory or internal requirements. Email authentication is handled through mechanisms such as SPF, DKIM, and DMARC, endpoint compliance is associated with Intune, and licensing is managed through Microsoft 365 administration. Audit retention therefore focuses specifically on preserving recorded activity information for an appropriate period.<\/span><\/p>\n<h3><b>Question 186<\/b><\/h3>\n<p><b>A user needs access to a SharePoint site but should not automatically receive access to unrelated sites. What principle should guide the configuration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">High availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege means providing users only the access necessary to perform their responsibilities. Applying this principle to SharePoint permissions helps prevent users from receiving broader access than required. Administrators can assign permissions at appropriate scopes and avoid unnecessarily granting organization-wide or unrelated site access. High availability focuses on service continuity, data compression reduces storage or transmission size, and load balancing distributes workloads. Least privilege is therefore the appropriate principle when configuring SharePoint access so that a user can work with a required site without gaining unrelated permissions.<\/span><\/p>\n<h3><b>Question 187<\/b><\/h3>\n<p><b>Which Microsoft 365 capability can help administrators investigate potentially unauthorized access to sensitive files?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Forms<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Bookings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 group calendar<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Audit can provide records of supported activities involving files and other Microsoft 365 resources. Administrators can search relevant audit events to investigate actions such as file access, downloads, sharing, or other recorded activities. This can help establish what occurred and which account performed an action. Microsoft Forms, Bookings, and group calendars are productivity features and do not provide centralized audit investigation capabilities. Purview Audit is therefore the appropriate tool for investigating historical activity involving potentially unauthorized access to sensitive files.<\/span><\/p>\n<h3><b>Question 188<\/b><\/h3>\n<p><b>Which Microsoft Entra capability can automatically provision users to supported applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application provisioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password writeback<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra application provisioning can automate the creation, updating, and removal of user accounts in supported applications. This reduces manual administration and helps keep application identities synchronized with organizational identity information. For example, when an employee joins or leaves an organization, provisioning workflows can update connected applications according to configured rules. Access reviews evaluate existing access, Conditional Access controls access decisions, and password writeback synchronizes password changes in supported hybrid identity scenarios. Application provisioning is therefore the feature intended for automated application account lifecycle management.<\/span><\/p>\n<h3><b>Question 189<\/b><\/h3>\n<p><b>An organization wants to require administrator approval before certain users can activate privileged roles. Which capability supports this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management supports controlled activation of eligible privileged roles and can be configured to require approval before activation. Other safeguards can also be applied, including multifactor authentication, justification, and limited activation duration. This approach helps organizations reduce persistent privileged access while ensuring that elevated permissions can be granted when necessary. Secure Score provides security recommendations, Exchange Online Protection protects email, and Purview Audit records activities. PIM is therefore the appropriate capability for approval-based activation of privileged administrative roles.<\/span><\/p>\n<h3><b>Question 190<\/b><\/h3>\n<p><b>Which Microsoft 365 feature helps administrators monitor important organizational messages about service changes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 message center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview eDiscovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange mailbox archive<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Microsoft 365 message center provides administrators with communications about service changes, feature updates, planned releases, and other developments that may affect their organization. Reviewing these messages helps administrators understand upcoming changes and prepare users, configurations, or operational processes where necessary. Purview eDiscovery supports compliance investigations, Exchange mailbox archive addresses storage, and Entra ID Protection focuses on identity risk. The message center is therefore the appropriate administrative resource for monitoring important Microsoft 365 service communications and planned changes.<\/span><\/p>\n<h3><b>Question 191<\/b><\/h3>\n<p><b>Which feature can help prevent users from accessing Microsoft 365 resources when their devices do not meet organizational security requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 group expiration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access can use device compliance as an access condition when integrated with Microsoft Intune. An organization can create policies requiring devices to meet defined compliance requirements before users are permitted to access selected Microsoft 365 resources. If the device does not satisfy the configured conditions, the policy can block access or apply another supported control. Purview Audit records activities, Exchange Online Protection secures email, and group expiration manages collaborative groups. Conditional Access is therefore the appropriate feature for enforcing device-based access requirements.<\/span><\/p>\n<h3><b>Question 192<\/b><\/h3>\n<p><b>What is the purpose of Microsoft 365 usage reports?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypt all Microsoft 365 content<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Provide information about service and user usage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace Microsoft Entra ID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure DNS authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 usage reports provide information about how users and organizations are using various Microsoft 365 services. Depending on the workload, reports can provide information about active users, application usage, collaboration activity, and other service-specific metrics. Administrators can use this information to understand adoption, identify inactive usage, and support administrative planning. Usage reports do not replace Microsoft Entra ID, provide universal encryption, or configure DNS authentication. Their primary purpose is to provide visibility into Microsoft 365 service and user usage patterns.<\/span><\/p>\n<h3><b>Question 193<\/b><\/h3>\n<p><b>An administrator wants to delegate only password-reset responsibilities for users. Which role is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Helpdesk Administrator<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Helpdesk Administrator role is designed to provide support-related administrative capabilities, including resetting passwords for certain users according to the role&#8217;s permissions and applicable Microsoft Entra controls. Assigning a specialized support role can reduce the need to grant broad directory permissions to helpdesk personnel. Global Administrator has extensive tenant-wide privileges, Exchange Administrator focuses on Exchange Online, and User Administrator has broader user-management capabilities. For a narrowly scoped password-reset responsibility, a dedicated helpdesk-oriented role better supports least-privilege administration.<\/span><\/p>\n<h3><b>Question 194<\/b><\/h3>\n<p><b>Which Microsoft 365 feature can help an administrator determine why a message was classified as spam?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message trace and anti-spam investigation information<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint Version History<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune compliance reports<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra access reviews<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Message trace and available anti-spam investigation information can help administrators understand how Exchange Online processed a message and whether filtering mechanisms affected its delivery. Reviewing the message details and applicable anti-spam results can help identify whether a message was classified as spam, rejected, quarantined, or otherwise handled by email protection policies. SharePoint Version History tracks document changes, Intune reports device compliance, and access reviews evaluate permissions. Email investigation tools are therefore the appropriate choice for troubleshooting a spam-classification issue.<\/span><\/p>\n<h3><b>Question 195<\/b><\/h3>\n<p><b>Which Microsoft Purview capability is designed to help organizations investigate regulatory or legal matters involving electronic data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview eDiscovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Links<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview eDiscovery provides capabilities for identifying, collecting, reviewing, and managing electronically stored information relevant to legal or compliance investigations. Authorized users can work with cases and supported data sources to locate information relevant to an investigation according to organizational processes and permissions. Secure Score focuses on security posture, Safe Links protects against malicious URLs, and Entra Cloud Sync synchronizes identities. eDiscovery is therefore the Microsoft Purview capability specifically designed to support investigations involving electronic information for legal, regulatory, or compliance purposes.<\/span><\/p>\n<h3><b>Question 196<\/b><\/h3>\n<p><b>Which DNS record directs incoming email for a domain to its designated mail server?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TXT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CNAME<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MX<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SRV<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An MX record identifies the mail servers responsible for receiving email for a domain. When configuring email for a Microsoft 365 domain, the relevant MX record directs incoming mail toward the appropriate Microsoft 365 mail endpoint or configured mail service. TXT records can publish information such as SPF policies, CNAME records provide aliases for supported services, and SRV records identify services and ports for specific protocols. Therefore, the MX record is the DNS record used to specify where incoming email for a domain should be delivered.<\/span><\/p>\n<h3><b>Question 197<\/b><\/h3>\n<p><b>Which Microsoft 365 security capability can help identify whether an endpoint is affected by a security threat?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 message center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Archive<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint provides endpoint security capabilities for supported devices. It can help organizations detect, investigate, and respond to threats affecting endpoints, with capabilities that may include threat detection, behavioral analysis, investigation, and response actions depending on licensing and configuration. Message center provides service communications, Purview retention manages data lifecycle requirements, and Exchange Online Archive provides mailbox storage capabilities. Defender for Endpoint is therefore the appropriate Microsoft security solution when administrators need to investigate threats affecting organizational devices.<\/span><\/p>\n<h3><b>Question 198<\/b><\/h3>\n<p><b>An organization wants to limit access to an application based on the user&#8217;s sign-in risk. Which two capabilities work together?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online and DKIM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection and Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview and eDiscovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint and retention labels<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID Protection can provide risk information associated with users and sign-ins, while Conditional Access can use supported risk conditions to apply access controls. Together, these capabilities allow an organization to respond to potentially risky authentication activity by requiring additional controls or restricting access according to configured policies. Exchange Online and DKIM address email authentication, Purview and eDiscovery address compliance investigations, and SharePoint with retention labels addresses content management. Entra ID Protection and Conditional Access are therefore the relevant combination for risk-based access control.<\/span><\/p>\n<h3><b>Question 199<\/b><\/h3>\n<p><b>Which administrative control can help ensure that only authorized administrators can perform sensitive Microsoft 365 tasks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privileged role management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 calendar<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint version history<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange mailbox archive<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged role management helps organizations control who receives administrative permissions and how those permissions are used. Microsoft Entra Privileged Identity Management can provide eligible role assignments, just-in-time activation, approval requirements, multifactor authentication, and time-limited privileged access depending on configuration. These controls can reduce unnecessary persistent administrative privileges. Calendars, SharePoint version history, and mailbox archives support collaboration or storage functions rather than privileged-access governance. Privileged role management is therefore an important administrative control for protecting sensitive Microsoft 365 operations.<\/span><\/p>\n<h3><b>Question 200<\/b><\/h3>\n<p><b>A company is reviewing its Microsoft 365 tenant and wants to reduce unnecessary administrative access. Which action directly supports this goal?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign Global Administrator to all IT staff<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Share one privileged account among administrators<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace audit logging with manual records<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Review role assignments and remove permissions that are no longer required<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Regularly reviewing administrative role assignments and removing permissions that are no longer required directly supports least-privilege administration. As employees change responsibilities, permissions that were previously necessary may become excessive. Periodic reviews help organizations identify unnecessary access and reduce the number of accounts capable of making sensitive changes. Assigning Global Administrator broadly, sharing privileged accounts, or replacing audit logs with manual records can increase security and accountability risks. Reviewing and appropriately reducing administrative permissions is therefore an important part of maintaining a controlled Microsoft 365 environment.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps. &nbsp; Question 181 Which Microsoft 365 service is used to manage Teams-related organizational settings? Microsoft Purview portal Exchange admin center Microsoft Defender portal Microsoft Teams admin center Correct Answer: 4 Explanation The Microsoft Teams admin center provides administrative controls for Microsoft Teams across an organization. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16819"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=16819"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16819\/revisions"}],"predecessor-version":[{"id":16840,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16819\/revisions\/16840"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=16819"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=16819"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=16819"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}