{"id":16829,"date":"2026-09-19T11:22:28","date_gmt":"2026-09-19T11:22:28","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=16829"},"modified":"2026-09-19T11:22:28","modified_gmt":"2026-09-19T11:22:28","slug":"microsoft-ms-102-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-ms-102-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Microsoft MS-102 Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ms-102-exam-dumps\"><b>Microsoft MS-102 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>Which Microsoft 365 feature allows administrators to review and manage licenses assigned to users?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 admin center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Microsoft 365 admin center provides centralized management capabilities for users, groups, subscriptions, and licenses. Administrators with the required permissions can review a user&#8217;s assigned licenses and make supported changes according to organizational requirements. The Defender portal focuses on security operations, the Purview portal focuses on compliance and information governance, and Entra ID Protection focuses on identity risks. Therefore, the Microsoft 365 admin center is the appropriate administrative location for reviewing and managing user license assignments.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>A company wants to ensure that only approved devices can access a sensitive Microsoft 365 application. Which combination should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit and eDiscovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune and Microsoft Entra Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection and Safe Links<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score and Service Health<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Intune can evaluate device compliance according to organizational requirements, while Microsoft Entra Conditional Access can use that compliance state as an access condition. Together, they can restrict access to sensitive applications when a device does not meet the organization&#8217;s defined requirements. Purview Audit and eDiscovery address auditing and investigations, EOP and Safe Links provide email and URL protection, and Secure Score and Service Health address security recommendations and service status. Intune with Conditional Access is therefore the relevant combination.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>Which Microsoft 365 capability helps identify malicious or suspicious URLs before users interact with them?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Links<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Attachments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra PIM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Safe Links is designed to protect users from malicious or suspicious URLs in supported Microsoft 365 workloads. It can inspect links and apply configured security controls when users interact with them. Safe Attachments instead focuses on potentially harmful files, Purview retention manages information lifecycle, and Privileged Identity Management controls privileged access. Therefore, Safe Links is the appropriate security capability when the organization needs protection specifically against dangerous links delivered through messages or other supported content.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>Which Microsoft Purview feature is designed to detect predefined types of sensitive information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retention labels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sensitive information types<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">eDiscovery cases<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit search<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview sensitive information types use predefined or customizable patterns to detect specific categories of sensitive information. Examples can include financial data, government identifiers, or other organizationally defined information types. These detections can be used by supported compliance and data-protection capabilities, including DLP policies. Retention labels manage content lifecycle, eDiscovery supports investigations, and audit search examines recorded activities. Sensitive information types are therefore the Purview feature specifically designed to recognize defined patterns of sensitive information.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>An administrator needs to find messages that were processed by Exchange Online during a specific period. Which tool should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Service Health<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Exchange Online message trace allows administrators to investigate messages processed during a specified time period. It can provide information about message delivery, processing outcomes, and other available events associated with email flow. This makes it useful for troubleshooting delivery issues, investigating filtering behavior, and verifying message handling. Purview Audit records broader Microsoft 365 activities, Service Health reports service incidents, and Intune manages devices and applications. Message trace is therefore the appropriate tool for investigating Exchange Online message processing during a defined period.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>Which Microsoft Entra capability can apply an access policy based on the country from which a user is connecting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra PIM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra administrative units<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access can use location conditions as part of an access policy. Administrators can define named locations and configure policies that allow, restrict, or require additional controls based on where access originates, subject to the available location signals and configuration. Cloud Sync handles identity synchronization, PIM manages privileged access, and administrative units provide administrative scope. Conditional Access is therefore the Microsoft Entra capability used when geographic or network location needs to influence an access decision.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>Which Microsoft 365 feature can help administrators identify whether a service problem is caused by a broader Microsoft incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Service Health<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra sign-in logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 Service Health provides information about known incidents and advisories affecting Microsoft services. Administrators can review current service status and incident details when users report widespread problems. This helps distinguish a broader Microsoft service issue from an isolated configuration or user problem. Purview Audit provides activity records, Secure Score provides security recommendations, and Entra sign-in logs focus on authentication events. Service Health is therefore the most appropriate resource for determining whether a reported service problem corresponds to a broader Microsoft incident.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>A security team wants to investigate an incident involving an identity alert, an endpoint alert, and suspicious email activity. Which platform provides a unified investigation experience?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 admin center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender XDR provides a unified security investigation experience across supported Microsoft security products. It can correlate related signals and alerts involving areas such as identity, endpoints, email, and other supported security workloads. This allows security teams to investigate related activity as part of a broader incident rather than handling each alert separately. Purview focuses on compliance and information governance, the Microsoft 365 admin center handles general administration, and Cloud Sync manages identity synchronization. Defender XDR is therefore the appropriate platform for this cross-domain investigation.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>Which Microsoft 365 capability allows administrators to review whether a guest should retain access to an organizational resource?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Attachments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra access reviews provide a structured mechanism for periodically reviewing access to supported resources, including guest access scenarios. Organizations can configure recurring reviews so that responsible reviewers determine whether external users still require access. This helps prevent unnecessary access from remaining indefinitely after a project or business relationship ends. Safe Attachments protects against malicious files, Secure Score provides security recommendations, and Exchange Online Protection protects email. Access reviews are therefore the appropriate capability for reviewing whether guest access should continue.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>Which Microsoft 365 administrative resource provides information about upcoming product changes and planned features?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra sign-in logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 admin center Message center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Microsoft 365 admin center Message center provides administrators with announcements concerning planned changes, new features, service updates, and other Microsoft 365 developments. Reviewing these messages can help organizations prepare users, test upcoming functionality, update documentation, and make required administrative adjustments. Exchange message trace investigates email processing, Entra sign-in logs record authentication events, and Purview Audit records supported activities. The Message center is therefore the appropriate resource for monitoring upcoming Microsoft 365 product changes.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>An organization wants to reduce the amount of sensitive information that users can accidentally share externally. Which Microsoft Purview capability should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra PIM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Service Health<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention helps organizations detect and protect sensitive information according to configured policies. DLP can identify supported sensitive data and apply actions or notifications when users perform activities that match defined conditions. Depending on the workload and configuration, these controls can help reduce accidental external disclosure. PIM manages privileged access, Service Health reports service incidents, and Secure Score provides security recommendations. Purview DLP is therefore the relevant capability for protecting sensitive information from inappropriate sharing.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>Which Microsoft Entra feature can provide temporary elevated permissions to an administrator who normally does not have an active privileged role?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra administrative units<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra dynamic groups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management supports eligible privileged role assignments that can be activated when elevated permissions are required. This approach reduces the need for users to maintain active privileged permissions at all times. Organizations can also configure activation requirements such as multifactor authentication, approval, justification, and time limits. Administrative units provide management scope, dynamic groups automate group membership, and Cloud Sync synchronizes identities. PIM is therefore the appropriate capability for providing controlled, temporary elevation to privileged administrative roles.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>A Microsoft 365 administrator wants to determine which administrative action occurred at a specific time. Which resource should be searched?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Service Health<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Audit provides searchable records for supported activities across Microsoft 365. Administrators can use audit searches to investigate actions performed during a particular time period and review available information about the activity and associated account. This is useful for troubleshooting, security investigations, compliance reviews, and administrative accountability. Secure Score provides recommendations, Service Health reports service issues, and Intune manages devices and applications. Purview Audit is therefore the appropriate resource for investigating a supported administrative action that occurred at a specific time.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>Which Microsoft 365 service provides centralized cloud management for organizational endpoints?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Intune provides cloud-based management capabilities for organizational endpoints, including supported device configuration, compliance policies, application management, and related endpoint controls. It can work with Microsoft Entra Conditional Access to enforce access requirements based on device compliance. Purview provides compliance and information-governance capabilities, Defender XDR focuses on security operations, and Exchange Online Protection protects email. Intune is therefore the Microsoft 365 service most directly associated with centralized cloud management of organizational endpoints.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>Which Microsoft 365 capability can help determine whether users are actively using assigned services and licenses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 usage reports<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview eDiscovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra PIM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 usage reports provide activity and adoption information across supported services. Administrators can use these reports to understand how actively users are using Microsoft 365 workloads and identify accounts with limited activity. This information can support license-management reviews and broader adoption planning. eDiscovery supports investigations, PIM manages privileged access, and Defender XDR provides security operations capabilities. Usage reports are therefore the appropriate resource when administrators need information about service activity that can assist with reviewing user and license utilization.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>An organization wants to prevent users with risky sign-ins from accessing sensitive resources until additional requirements are satisfied. Which combination is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection and Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune and Exchange message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit and retention policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Attachments and Safe Links<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID Protection can identify risk associated with users and sign-ins, while Conditional Access can use supported risk conditions to apply access controls. Depending on the configured policy, an organization can require additional authentication or block access when risk reaches a defined level. Intune with message trace combines unrelated endpoint and email functions, Purview Audit and retention address auditing and information lifecycle, and Safe Attachments and Safe Links protect email content. Entra ID Protection with Conditional Access is therefore the appropriate combination for risk-based access control.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>Which Microsoft Purview feature is most appropriate when an organization needs to search for potentially relevant information as part of an investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview eDiscovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Cloud Sync<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview eDiscovery provides capabilities for investigating electronically stored information across supported Microsoft 365 data sources. Investigators can create cases and perform searches to identify content that may be relevant to a legal, regulatory, or internal investigation, depending on the available eDiscovery features and licensing. Secure Score evaluates security posture, Cloud Sync synchronizes identities, and Exchange Online Protection secures email. eDiscovery is therefore the appropriate Purview capability when the primary requirement is to locate and investigate potentially relevant information.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>Which Microsoft 365 security feature provides recommendations for improving security configurations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange message trace<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Secure Score provides information about an organization&#8217;s security posture and presents recommendations for improving supported security configurations. Administrators can review these recommendations and determine which changes are appropriate based on their environment and organizational requirements. Access reviews focus on evaluating permissions, Purview Audit records supported activities, and message trace investigates email processing. Secure Score is therefore the capability designed to help administrators identify configuration improvements that can strengthen the organization&#8217;s Microsoft security posture.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>An organization wants to limit a helpdesk employee to resetting user passwords without granting broad tenant administration rights. Which role is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Helpdesk Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global Reader<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Helpdesk Administrator role is designed for supported helpdesk-related tasks, including resetting passwords for users within its permission scope. Assigning a focused role instead of Global Administrator supports the principle of least privilege by limiting the employee&#8217;s administrative permissions to responsibilities appropriate for the helpdesk function. Exchange Administrator focuses on Exchange Online, while Global Reader provides read-only visibility. Therefore, Helpdesk Administrator is the appropriate role when the employee primarily needs to perform password-reset and related helpdesk tasks.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>Which approach best supports secure Microsoft 365 administration by combining limited permissions, stronger authentication, and controlled privileged access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Give all administrators permanent Global Administrator access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use shared administrator credentials to simplify management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign role-based permissions, require MFA, and use Privileged Identity Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable audit logging for privileged accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Microsoft 365 administration should combine several complementary controls rather than rely on a single protection mechanism. Role-based permissions limit administrators to the access required for their responsibilities, multifactor authentication provides stronger protection for privileged identities, and Privileged Identity Management can reduce standing privileged access through controlled activation. Permanent Global Administrator assignments and shared credentials increase exposure and reduce accountability, while disabling audit logging removes valuable evidence. Combining least privilege, MFA, and controlled privileged access therefore establishes a structured administrative security model.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps. Question 381 Which Microsoft 365 feature allows administrators to review and manage licenses assigned to users? Microsoft Defender portal Microsoft 365 admin center Microsoft Purview portal Microsoft Entra ID Protection Correct Answer: 2 Explanation The Microsoft 365 admin center provides centralized management capabilities for users, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16829"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=16829"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16829\/revisions"}],"predecessor-version":[{"id":16830,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16829\/revisions\/16830"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=16829"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=16829"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=16829"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}