{"id":16826,"date":"2026-09-19T11:23:09","date_gmt":"2026-09-19T11:23:09","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=16826"},"modified":"2026-09-19T11:23:09","modified_gmt":"2026-09-19T11:23:09","slug":"microsoft-ms-102-practice-test-questions-and-exam-dumps-part17-q321-340","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-ms-102-practice-test-questions-and-exam-dumps-part17-q321-340\/","title":{"rendered":"Microsoft MS-102 Practice Test Questions and Exam Dumps Part17 Q321-340"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ms-102-exam-dumps\"><b>Microsoft MS-102 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<h3><b>Question 321<\/b><\/h3>\n<p><b>Which Microsoft 365 capability helps administrators identify whether a reported service problem is already known by Microsoft?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Service Health<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 Service Health provides administrators with information about active incidents, advisories, and other service-related events affecting Microsoft 365. When users report problems accessing a service, administrators can check Service Health to determine whether Microsoft has identified a corresponding issue and review available updates. Purview Audit records supported activities, Secure Score provides security recommendations, and Entra ID Protection focuses on identity risks. Service Health is therefore the appropriate resource for determining whether a reported Microsoft 365 service problem is already recognized.<\/span><\/p>\n<h3><b>Question 322<\/b><\/h3>\n<p><b>An organization wants to delegate administration of a limited set of users without granting access to manage every user in the tenant. Which feature can help?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra administrative units<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Links<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra administrative units can help organizations establish administrative boundaries for supported objects. By combining administrative units with appropriately scoped administrative roles, an organization can delegate management of a defined group of users without granting unrestricted tenant-wide permissions. Safe Links protects users from malicious URLs, Purview Audit records supported activities, and Exchange Online Protection protects email. Administrative units are therefore useful when an organization needs delegated administration for a specific regional, departmental, or organizational subset.<\/span><\/p>\n<h3><b>Question 323<\/b><\/h3>\n<p><b>Which Microsoft 365 security feature can scan email attachments for potentially malicious content?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Links<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Attachments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Safe Attachments is designed to protect users from potentially malicious files delivered through email and supported Microsoft 365 workloads. It analyzes attachments according to the configured protection policy and can apply an appropriate action when a threat is detected. Safe Links focuses on URLs, Purview DLP protects sensitive information, and Conditional Access controls access based on defined conditions. Therefore, Safe Attachments is the capability specifically associated with analyzing email attachments for potentially harmful content.<\/span><\/p>\n<h3><b>Question 324<\/b><\/h3>\n<p><b>Which DNS record helps specify the authorized sending servers for a domain?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MX<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPF TXT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CNAME<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SRV<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SPF is implemented through a DNS TXT record that identifies authorized mail-sending sources for a domain. Receiving mail systems can evaluate the SPF policy to determine whether a message originated from an authorized source. An MX record identifies mail servers responsible for receiving email, while CNAME and SRV records support other DNS functions. SPF alone does not provide complete email authentication, so organizations commonly use it together with DKIM and DMARC. The SPF TXT record is therefore the correct choice for identifying authorized sending infrastructure.<\/span><\/p>\n<h3><b>Question 325<\/b><\/h3>\n<p><b>A Microsoft 365 administrator wants to identify which users have not recently used a particular service. Which resource should be reviewed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 usage reports<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra PIM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview eDiscovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 usage reports provide activity information for supported services and can help administrators identify usage patterns, including users with little or no recent activity. This information can support license reviews, adoption planning, and account-management decisions. Defender XDR is designed for security investigations, PIM manages privileged access, and eDiscovery supports investigative searches. Usage reports are therefore the appropriate resource when the administrator needs to understand service utilization and identify users who may no longer be actively using a particular Microsoft 365 service.<\/span><\/p>\n<h3><b>Question 326<\/b><\/h3>\n<p><b>Which Microsoft Entra feature can detect potentially risky user accounts and sign-in activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID Protection helps organizations detect and investigate identity-related risks associated with users and sign-ins. It can identify risk signals and provide information that administrators can use when configuring appropriate identity protections. Depending on the configuration and licensing, risk information can also be used with Conditional Access policies to apply additional controls. Purview Audit records activities, Intune manages devices, and Exchange Online Protection secures email. Entra ID Protection is therefore the appropriate capability for detecting and responding to potentially risky identity activity.<\/span><\/p>\n<h3><b>Question 327<\/b><\/h3>\n<p><b>An organization needs to find out which administrator performed a supported action in Microsoft 365 several days ago. Which feature should be queried?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Service Health<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Audit maintains searchable records for supported activities performed across Microsoft 365 services. Administrators can use audit searches to investigate historical actions and review details such as the activity, associated account, and time of the event when that information is available. Service Health reports Microsoft service issues, Secure Score provides security recommendations, and Intune focuses on device and application management. Therefore, Purview Audit is the appropriate feature for investigating which administrator performed a supported action several days earlier.<\/span><\/p>\n<h3><b>Question 328<\/b><\/h3>\n<p><b>Which Microsoft 365 feature can automatically classify users into groups according to attributes such as office location?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange mail flow rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview retention labels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra dynamic membership<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra dynamic membership allows group membership to be determined automatically according to configured user or device attributes. For example, a dynamic group can use an attribute such as department, job title, or office location to determine which users belong to the group. This reduces manual membership maintenance when directory attributes are properly maintained. Exchange mail flow rules process messages, retention labels manage information lifecycle, and Defender XDR supports security operations. Dynamic membership is therefore the appropriate capability for attribute-based automatic group membership.<\/span><\/p>\n<h3><b>Question 329<\/b><\/h3>\n<p><b>Which Microsoft 365 feature can help protect sensitive information by warning users when they attempt a potentially risky action?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Service Health<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange message trace<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention can provide user notifications and policy tips when supported activities involving sensitive information match configured policy conditions. These notifications can help users understand organizational requirements and may prevent accidental disclosure of protected information. The exact actions available depend on the workload, policy configuration, and licensing. Service Health monitors Microsoft services, Cloud Sync synchronizes identities, and message trace investigates email processing. Purview DLP is therefore the appropriate capability for applying data-protection controls and user guidance around sensitive information.<\/span><\/p>\n<h3><b>Question 330<\/b><\/h3>\n<p><b>An administrator needs to determine whether a specific email reached its intended recipient. Which tool should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra sign-in logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Exchange Online message trace is designed to provide information about email processing and delivery. Administrators can use it to investigate whether a message was received, delivered, rejected, delayed, or otherwise processed according to the available trace details. Purview Audit serves broader auditing purposes, Secure Score evaluates security posture, and Entra sign-in logs concern authentication events rather than email delivery. Therefore, when the administrator needs to determine what happened to a particular email message, Exchange Online message trace is the appropriate tool.<\/span><\/p>\n<h3><b>Question 331<\/b><\/h3>\n<p><b>Which role is appropriate when an administrator needs broad read-only visibility across Microsoft 365 but should not make configuration changes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global Reader<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User Administrator<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Global Reader provides broad read-only visibility across many Microsoft 365 administrative areas. It can be useful for auditors, support personnel, or administrators who need to inspect tenant configuration without requiring permissions to change it. Global Administrator provides extensive management permissions, Exchange Administrator focuses on Exchange Online, and User Administrator handles supported user-management functions. Assigning Global Reader can therefore help organizations follow least-privilege principles when an individual requires broad administrative visibility but does not need write access.<\/span><\/p>\n<h3><b>Question 332<\/b><\/h3>\n<p><b>Which Microsoft Purview capability can preserve and investigate content associated with a legal or organizational investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview eDiscovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview eDiscovery provides capabilities for conducting structured investigations involving electronic information. Depending on the eDiscovery features and licensing available, organizations can identify relevant content, create cases, search supported data sources, and perform review-related activities. Secure Score focuses on security recommendations, Intune manages devices and applications, and Cloud Sync synchronizes identities. Therefore, eDiscovery is the appropriate Microsoft Purview capability when an organization needs to investigate and manage potentially relevant content associated with a legal, regulatory, or internal matter.<\/span><\/p>\n<h3><b>Question 333<\/b><\/h3>\n<p><b>An organization wants to require compliant devices before users can access a sensitive cloud application. Which two Microsoft services are most directly involved?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online and Microsoft Defender XDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune and Microsoft Entra Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview and Exchange Online Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score and Microsoft 365 Service Health<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Intune can evaluate device compliance according to organizational requirements, while Microsoft Entra Conditional Access can use device compliance as a condition in access policies. Together, they can help enforce a requirement that users access sensitive applications only from devices meeting defined compliance standards. Exchange Online and Defender XDR do not provide this specific combination of device compliance and access control. Purview and EOP address data governance and email protection, while Secure Score and Service Health serve different purposes. Intune and Conditional Access are therefore the relevant combination.<\/span><\/p>\n<h3><b>Question 334<\/b><\/h3>\n<p><b>Which Microsoft 365 security capability can provide information about the security posture of a tenant and recommended improvement actions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Secure Score provides an overview of an organization&#8217;s security posture and includes recommendations for improving supported security configurations. Administrators can review the recommendations and determine which actions align with their organization&#8217;s requirements and risk-management approach. Purview Audit provides activity records, message trace investigates email processing, and Cloud Sync handles identity synchronization. Secure Score is therefore the Microsoft 365 capability most directly associated with assessing security posture and presenting actionable security improvement recommendations.<\/span><\/p>\n<h3><b>Question 335<\/b><\/h3>\n<p><b>A company wants to ensure that users cannot access a sensitive application unless they complete multifactor authentication. Which policy should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview retention policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange mail flow rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR incident<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Microsoft Entra Conditional Access policy can require multifactor authentication when users access specified applications or resources. Administrators can define conditions such as users, groups, applications, locations, device states, or risk and then specify MFA as an access control. This allows authentication requirements to be targeted rather than applied indiscriminately. Purview retention controls information lifecycle, Exchange mail flow rules process messages, and Defender XDR incidents support security investigations. Conditional Access is therefore the appropriate policy mechanism for requiring MFA for access to a sensitive application.<\/span><\/p>\n<h3><b>Question 336<\/b><\/h3>\n<p><b>Which Microsoft 365 capability can protect corporate data by controlling access to sensitive content based on classification?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview sensitivity labels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Service Health<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange message trace<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview sensitivity labels allow organizations to classify supported content according to sensitivity and apply configured protection settings. Depending on the configuration, labels can support encryption, access restrictions, markings, and other controls. This allows organizations to associate protection requirements with the classification of information. Service Health provides service-status information, Cloud Sync handles identity synchronization, and message trace investigates email processing. Sensitivity labels are therefore the relevant Microsoft Purview capability for classifying sensitive content and applying associated protection controls.<\/span><\/p>\n<h3><b>Question 337<\/b><\/h3>\n<p><b>An organization wants to reduce permanent assignment of privileged roles while still allowing administrators to perform occasional elevated tasks. Which approach should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign Global Administrator permanently<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Create a shared administrator account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use Microsoft Entra Privileged Identity Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable privileged account auditing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management supports eligible role assignments and controlled activation of privileged roles. Administrators can activate elevated permissions when required rather than retaining permanent active access. Organizations can also configure additional controls such as approval, multifactor authentication, justification, and time limits. Permanent Global Administrator assignments increase standing privilege, shared accounts reduce accountability, and disabling auditing removes useful records. PIM therefore provides a structured approach for reducing standing privileged access while still allowing administrators to perform authorized elevated tasks when necessary.<\/span><\/p>\n<h3><b>Question 338<\/b><\/h3>\n<p><b>Which Microsoft 365 capability helps organizations review whether guest access should continue?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Attachments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra access reviews allow organizations to periodically review access granted to users, including supported guest access scenarios. Reviewers can determine whether external users still require access and take action according to organizational policies. This is useful because guest access may remain after the original business requirement has ended. Safe Attachments protects against malicious files, Secure Score provides security recommendations, and Exchange Online Protection secures email. Access reviews are therefore the appropriate governance capability for periodically validating whether guest access remains necessary.<\/span><\/p>\n<h3><b>Question 339<\/b><\/h3>\n<p><b>Which Microsoft 365 capability can provide centralized management of security incidents generated by supported Microsoft security products?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 usage reports<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender XDR provides a centralized security operations experience for supported Microsoft security products. It can bring related alerts together into incidents and provide investigation information across areas such as endpoint, identity, email, and other supported security signals. Usage reports provide service activity information, Purview retention manages information lifecycle, and Cloud Sync synchronizes identities. Defender XDR is therefore the appropriate capability when security personnel need a centralized environment for investigating and responding to correlated security incidents.<\/span><\/p>\n<h3><b>Question 340<\/b><\/h3>\n<p><b>An administrator needs to see upcoming Microsoft 365 feature changes before they affect users. Where should the administrator look?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra sign-in logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 admin center Message center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange message trace<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Microsoft 365 admin center Message center provides administrators with announcements about planned changes, new capabilities, feature updates, and other developments affecting Microsoft 365 services. Reviewing these messages allows organizations to understand upcoming changes and determine whether preparation, testing, communication, or configuration work may be required. Entra sign-in logs contain authentication records, Purview Audit contains supported activity records, and message trace concerns email processing. The Message center is therefore the appropriate location for monitoring upcoming Microsoft 365 feature changes.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps. Question 321 Which Microsoft 365 capability helps administrators identify whether a reported service problem is already known by Microsoft? Microsoft Purview Audit Microsoft 365 Service Health Microsoft Secure Score Microsoft Entra ID Protection Correct Answer: 2 Explanation Microsoft 365 Service Health provides administrators with information [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16826"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=16826"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16826\/revisions"}],"predecessor-version":[{"id":16833,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16826\/revisions\/16833"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=16826"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=16826"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=16826"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}