{"id":16824,"date":"2026-09-19T11:23:36","date_gmt":"2026-09-19T11:23:36","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=16824"},"modified":"2026-09-19T11:23:36","modified_gmt":"2026-09-19T11:23:36","slug":"microsoft-ms-102-practice-test-questions-and-exam-dumps-part15-q281-300","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-ms-102-practice-test-questions-and-exam-dumps-part15-q281-300\/","title":{"rendered":"Microsoft MS-102 Practice Test Questions and Exam Dumps Part15 Q281-300"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ms-102-exam-dumps\"><b>Microsoft MS-102 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<h3><b>Question 281<\/b><\/h3>\n<p><b>Which Microsoft 365 portal provides administrators with information about planned changes and new features?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 admin center Message center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra admin center<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Message center in the Microsoft 365 admin center provides administrators with information about upcoming changes, new features, planned maintenance, and other service-related updates. Reviewing these messages helps administrators understand changes that may affect users and allows organizations to prepare before features are introduced. The Defender portal focuses on security operations, Purview focuses on compliance and governance, and the Entra admin center manages identity services. Therefore, the Microsoft 365 admin center Message center is the appropriate location for tracking planned Microsoft 365 changes.<\/span><\/p>\n<h3><b>Question 282<\/b><\/h3>\n<p><b>A company needs to verify that a new custom domain belongs to the organization before using it in Microsoft 365. What should the administrator configure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS TXT verification record<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MX routing record<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPF policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DKIM selector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 commonly uses a DNS TXT record to verify ownership of a custom domain. The administrator receives a verification value from Microsoft and adds it to the domain&#8217;s DNS configuration. Microsoft then checks the record before confirming ownership. MX records are primarily associated with mail routing, SPF helps authorize sending services, and DKIM supports message authentication. Domain verification must occur before many domain-related Microsoft 365 configurations can be completed, making the DNS TXT verification record the appropriate choice.<\/span><\/p>\n<h3><b>Question 283<\/b><\/h3>\n<p><b>Which Microsoft Entra capability allows an organization to synchronize selected on-premises organizational units with Microsoft Entra ID?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync provides cloud-managed identity synchronization between supported on-premises Active Directory environments and Microsoft Entra ID. Administrators can configure synchronization scope so that only required users, groups, or organizational units are synchronized according to the organization&#8217;s design. Purview Audit records activities, Defender XDR supports security investigations, and Exchange Online Protection protects email. Cloud Sync is therefore the relevant identity service when an organization wants a controlled synchronization scope between its on-premises directory and Microsoft Entra ID.<\/span><\/p>\n<h3><b>Question 284<\/b><\/h3>\n<p><b>A user reports that a legitimate email was incorrectly classified as spam. Which Microsoft 365 security area should the administrator investigate first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview eDiscovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Exchange Online Protection provides filtering and protection for organizational email, including anti-spam processing. When a legitimate message is incorrectly classified as spam, administrators can investigate the relevant anti-spam configuration, message details, and filtering results within the Exchange and Defender security environment. Intune manages devices, Entra ID Protection focuses on identity risks, and eDiscovery supports investigations involving electronically stored information. EOP is therefore the appropriate security area to examine when troubleshooting incorrect spam classification.<\/span><\/p>\n<h3><b>Question 285<\/b><\/h3>\n<p><b>Which Microsoft Purview feature can apply a classification to content so that associated protection settings can follow the information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retention policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sensitivity labels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">eDiscovery cases<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview sensitivity labels allow organizations to classify information according to its sensitivity and can apply associated protection settings when configured. Depending on the configuration, labels can support encryption, access restrictions, content marking, and other controls. Retention policies manage information lifecycle requirements, audit logs record supported activities, and eDiscovery cases support legal or investigative processes. Sensitivity labels are therefore the appropriate Purview capability when the goal is to classify content and associate protection requirements with that classification.<\/span><\/p>\n<h3><b>Question 286<\/b><\/h3>\n<p><b>An administrator needs to determine whether a Microsoft 365 service is currently experiencing an outage. Which resource should be checked?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Service Health<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra sign-in logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 Service Health provides information about service incidents and advisories affecting Microsoft 365 services. Administrators can use it to determine whether Microsoft is already aware of a reported service problem and to review available status information and updates. Purview Audit records supported activities, Entra sign-in logs provide authentication information, and Secure Score provides security recommendations. When users report a widespread Microsoft 365 service problem, Service Health is therefore the appropriate first resource for checking whether Microsoft has identified a related incident.<\/span><\/p>\n<h3><b>Question 287<\/b><\/h3>\n<p><b>Which role is designed to provide read-only access to administrative information without allowing configuration changes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global Reader<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User Administrator<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Global Reader role provides read-only access to many administrative settings and information across Microsoft services. It is useful when an administrator, auditor, or support person needs broad visibility but should not be able to modify configurations. Global Administrator has extensive write permissions, Exchange Administrator focuses on Exchange management, and User Administrator handles supported user-management tasks. Assigning Global Reader can therefore support least-privilege administration when an individual needs broad visibility without requiring permission to make tenant-wide configuration changes.<\/span><\/p>\n<h3><b>Question 288<\/b><\/h3>\n<p><b>A company wants to detect when users share sensitive information externally and apply protection controls. Which Microsoft Purview capability is most relevant?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 usage reports<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Service Health<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention helps organizations identify and protect sensitive information according to configured policies. DLP policies can inspect supported content and communication locations for sensitive information types and apply actions when defined conditions are met. Depending on configuration, these actions can include blocking or restricting certain activities, generating alerts, or notifying users. Usage reports provide adoption information, Cloud Sync handles identity synchronization, and Service Health reports service status. Purview DLP is therefore the relevant capability for controlling potentially risky external sharing of sensitive information.<\/span><\/p>\n<h3><b>Question 289<\/b><\/h3>\n<p><b>Which Microsoft Entra feature can organize users into groups automatically based on attributes such as department or job title?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security defaults<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic membership groups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access reviews<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra dynamic membership groups can automatically evaluate user or device attributes and adjust group membership according to configured rules. For example, an organization can create a group that includes users whose department attribute matches a defined value. This reduces manual membership management when organizational attributes are maintained accurately. Security defaults provide baseline identity protections, Conditional Access controls access decisions, and access reviews evaluate existing access. Dynamic membership groups are therefore the appropriate feature for automatically maintaining group membership based on attributes.<\/span><\/p>\n<h3><b>Question 290<\/b><\/h3>\n<p><b>An administrator wants to determine which administrative account changed a Microsoft 365 configuration setting. Which capability should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Audit can record supported administrative activities across Microsoft 365 services. Administrators can search audit records to investigate configuration changes and identify information such as the account associated with an action, the activity performed, and the time of the event. Secure Score evaluates security posture, Intune manages devices and applications, and Exchange Online Protection focuses on email security. Therefore, Purview Audit is the appropriate capability for reviewing historical administrative actions and determining which account performed a recorded configuration change.<\/span><\/p>\n<h3><b>Question 291<\/b><\/h3>\n<p><b>Which Microsoft 365 service can help an administrator identify inactive users based on service activity reports?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 usage reports<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview eDiscovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 usage reports provide information about user activity and service adoption across supported workloads. Administrators can use available activity information to identify users who may no longer be actively using particular Microsoft 365 services. This information can support account reviews, license optimization, and administrative planning. Entra ID Protection focuses on identity risks, Defender for Endpoint protects endpoints, and eDiscovery supports investigations. Usage reports are therefore the most relevant resource for reviewing activity patterns and identifying potentially inactive users.<\/span><\/p>\n<h3><b>Question 292<\/b><\/h3>\n<p><b>A company wants to protect users from malicious URLs contained in email messages. Which capability should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Attachments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Links<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retention labels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Safe Links is a Microsoft Defender for Office 365 capability designed to provide protection against malicious or unsafe URLs. It can examine links in supported messages and apply configured protection when users interact with them. Safe Attachments addresses potentially harmful files rather than URLs. Retention labels manage information lifecycle requirements, while Conditional Access controls access based on conditions such as identity, device, or risk. Therefore, Safe Links is the appropriate capability when an organization wants to protect users from malicious links delivered through email and supported Microsoft 365 workloads.<\/span><\/p>\n<h3><b>Question 293<\/b><\/h3>\n<p><b>Which Microsoft 365 capability is designed to investigate and manage security incidents across multiple Microsoft security products?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 admin center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender XDR provides a unified security environment for investigating and responding to incidents across supported Microsoft security products. It can correlate related alerts and provide security teams with a broader view of an attack or suspicious activity. This can help reduce fragmented investigations across individual security services. Purview retention manages information lifecycle, the Microsoft 365 admin center handles general tenant administration, and Cloud Sync handles identity synchronization. Defender XDR is therefore the appropriate platform for centralized investigation and management of supported security incidents.<\/span><\/p>\n<h3><b>Question 294<\/b><\/h3>\n<p><b>An administrator needs to investigate the delivery status of a particular email sent through Exchange Online. Which tool should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Exchange Online message trace provides information about the processing and delivery of email messages. Administrators can use it to investigate whether a message was received, delivered, rejected, delayed, or otherwise processed according to the available trace information. Purview Audit serves broader auditing requirements, Secure Score evaluates security posture, and Intune manages devices and applications. When the investigation specifically concerns the path or delivery result of an Exchange Online message, message trace is the appropriate administrative tool.<\/span><\/p>\n<h3><b>Question 295<\/b><\/h3>\n<p><b>Which Microsoft Entra capability can require multifactor authentication when users attempt to access selected applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access can apply access controls based on conditions such as user, group, application, location, device, and risk. One commonly configured control is requiring multifactor authentication before allowing access to selected applications or resources. This allows organizations to apply stronger authentication requirements to sensitive workloads or user populations. Purview Audit records supported activities, EOP protects email, and Defender XDR supports security operations. Conditional Access is therefore the appropriate Microsoft Entra capability for enforcing application-specific multifactor authentication requirements.<\/span><\/p>\n<h3><b>Question 296<\/b><\/h3>\n<p><b>Which Microsoft Purview capability is intended to support searches and investigations involving potentially relevant electronic information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview eDiscovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview eDiscovery provides capabilities for identifying, collecting, reviewing, and managing electronic information relevant to legal, regulatory, or organizational investigations, subject to the applicable features and licensing. Investigators can work with cases and searches to locate potentially relevant content across supported Microsoft 365 data sources. Intune manages devices and applications, Defender for Endpoint focuses on endpoint security, and Cloud Sync synchronizes identities. eDiscovery is therefore the appropriate Purview capability when an organization needs to conduct structured investigations involving electronic information.<\/span><\/p>\n<h3><b>Question 297<\/b><\/h3>\n<p><b>An organization wants to prevent users from accessing Microsoft 365 resources from a specified country. Which feature should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 usage reports<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access can use location-based conditions to control access according to organizational policies. Administrators can define named locations and use them in Conditional Access policies to allow, require additional controls, or block access depending on the configured conditions. Purview Audit records activities, EOP protects email, and usage reports provide service-activity information. Therefore, Conditional Access is the appropriate capability when an organization needs to apply access restrictions based on geographic location or network location.<\/span><\/p>\n<h3><b>Question 298<\/b><\/h3>\n<p><b>Which Microsoft 365 security capability provides recommendations intended to improve an organization&#8217;s security posture?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview eDiscovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange message trace<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Secure Score provides security posture information and recommendations that organizations can use to identify opportunities for improving their Microsoft security configuration. Recommendations can address areas such as identity protection, device security, data protection, and other supported controls. Secure Score is intended to help administrators understand security improvement opportunities rather than investigate individual email messages or synchronize identities. Purview eDiscovery supports investigations, Cloud Sync handles directory synchronization, and message trace investigates email processing. Secure Score is therefore the relevant capability for security-improvement recommendations.<\/span><\/p>\n<h3><b>Question 299<\/b><\/h3>\n<p><b>A user is leaving the organization. Which action should an administrator take to immediately prevent the account from being used to sign in?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Add the user to a Microsoft 365 group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Block sign-in for the user account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign Global Reader<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enable Safe Links<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Blocking sign-in prevents the departing user&#8217;s account from being used to authenticate to Microsoft 365 and other connected services that rely on the account. This is an important offboarding action, although organizations may have additional steps for handling licenses, sessions, devices, mailboxes, files, and data retention. Adding a user to a group does not disable access, Global Reader grants administrative visibility, and Safe Links protects against malicious URLs. Blocking sign-in is therefore the direct action for preventing further account authentication during offboarding.<\/span><\/p>\n<h3><b>Question 300<\/b><\/h3>\n<p><b>Which Microsoft 365 capability can help an organization review whether guest users still require access to resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Service Health<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra access reviews can be configured to periodically review guest access and determine whether external users should continue to have access to supported resources. This helps organizations avoid allowing guest permissions to remain indefinitely when business requirements have changed. Reviewers can evaluate access and take appropriate action based on organizational policies. Defender XDR handles security operations, Exchange Online Protection protects email, and Service Health reports Microsoft service issues. Access reviews are therefore the relevant capability for recurring validation of guest-user access.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps. Question 281 Which Microsoft 365 portal provides administrators with information about planned changes and new features? Microsoft Defender portal Microsoft Purview portal Microsoft 365 admin center Message center Microsoft Entra admin center Correct Answer: 3 Explanation The Message center in the Microsoft 365 admin center [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16824"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=16824"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16824\/revisions"}],"predecessor-version":[{"id":16835,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16824\/revisions\/16835"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=16824"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=16824"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=16824"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}