{"id":16851,"date":"2026-09-19T11:29:56","date_gmt":"2026-09-19T11:29:56","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=16851"},"modified":"2026-09-19T11:29:56","modified_gmt":"2026-09-19T11:29:56","slug":"microsoft-ms-102-practice-test-questions-and-exam-dumps-part4-q61-80","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-ms-102-practice-test-questions-and-exam-dumps-part4-q61-80\/","title":{"rendered":"Microsoft MS-102 Practice Test Questions and Exam Dumps Part4 Q61-80"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ms-102-exam-dumps\"><b>Microsoft MS-102 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 61<\/b><\/h3>\n<p><b>Which Microsoft 365 feature helps administrators manage user accounts, licenses, and organizational settings from a centralized interface?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 admin center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender portal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange admin center<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Microsoft 365 admin center provides a centralized management interface for many Microsoft 365 administrative tasks. Administrators can manage users, groups, licenses, domains, organizational settings, and service-related configurations from this portal. The Purview portal focuses primarily on compliance, governance, and data security, while the Defender portal focuses on security operations. The Exchange admin center is dedicated mainly to Exchange Online configuration. Using the Microsoft 365 admin center allows administrators to manage broad tenant-level settings without moving between multiple specialized portals for common administrative activities.<\/span><\/p>\n<h3><b>Question 62<\/b><\/h3>\n<p><b>A company wants to automatically assign Microsoft 365 licenses to users based on their department membership. What should the administrator use?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">License-based group membership<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic membership rules with group-based licensing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange transport rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retention labels<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic membership rules combined with group-based licensing can automate license assignment based on user attributes such as department, location, or job title. A dynamic group automatically adds or removes users when their attributes satisfy the defined membership rule. When licenses are assigned to that group, eligible members receive the configured licenses automatically. This reduces manual administrative work and helps maintain consistent licensing as employees change roles. Exchange transport rules, retention labels, and ordinary mail settings do not provide this type of attribute-driven license assignment.<\/span><\/p>\n<h3><b>Question 63<\/b><\/h3>\n<p><b>What is the primary purpose of Microsoft Entra Connect Sync?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Synchronize identities between on-premises Active Directory and Microsoft Entra ID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scan email attachments for malware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Apply Microsoft Purview retention labels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitor Microsoft Defender incidents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Connect Sync synchronizes identities from an on-premises Active Directory environment with Microsoft Entra ID. This allows organizations operating hybrid environments to maintain user and group information across both identity platforms. Depending on the configuration, attributes such as usernames, group memberships, and other directory information can be synchronized. It supports hybrid identity scenarios and helps users access Microsoft cloud services using organizational identities. Security portals, Purview controls, and email protection technologies serve different purposes and are not substitutes for directory synchronization.<\/span><\/p>\n<h3><b>Question 64<\/b><\/h3>\n<p><b>An administrator needs to determine whether a user successfully authenticated from an unfamiliar IP address. Which information should be reviewed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview retention explorer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra sign-in information<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online mailbox statistics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score history<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra sign-in information provides details about authentication attempts, including user, application, location, IP address, device information, and authentication status. Administrators can use this information to investigate unusual or unexpected sign-in activity. For example, an unfamiliar IP address or location can be examined to determine whether the authentication succeeded and what access conditions were applied. Retention tools manage data governance, mailbox statistics provide Exchange-related information, and Secure Score evaluates security posture rather than serving as the primary source for individual authentication event details.<\/span><\/p>\n<h3><b>Question 65<\/b><\/h3>\n<p><b>Which capability allows an administrator to assign permissions to a group rather than individually to every user?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Group-based access management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Attachments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit search<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Group-based access management allows permissions or access assignments to be managed through group membership instead of configuring every user individually. When users join or leave an appropriately configured group, their associated access can change accordingly. This approach can simplify administration and improve consistency, particularly in organizations with large numbers of employees. Message trace is used for investigating email delivery, Safe Attachments analyzes potentially malicious files, and audit search reviews recorded activities. Centralizing access through groups can also make administrative reviews easier.<\/span><\/p>\n<h3><b>Question 66<\/b><\/h3>\n<p><b>A Microsoft 365 administrator wants to prevent users from registering applications without administrative approval. Which setting is most relevant?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User consent settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mailbox audit logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retention policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Links policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra user consent settings control how users can grant permissions to applications accessing organizational data. Organizations can restrict or manage user consent so that applications requiring potentially sensitive permissions must undergo administrative review or approval. This helps reduce the risk of users authorizing untrusted applications to access organizational resources. Mailbox auditing concerns Exchange activities, retention policies govern how long data is retained, and Safe Links protects users from malicious URLs. Application consent controls are therefore the relevant administrative mechanism for managing this scenario.<\/span><\/p>\n<h3><b>Question 67<\/b><\/h3>\n<p><b>Which Microsoft 365 component is responsible for managing organization-wide email authentication records such as DKIM configuration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Office 365<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Exchange Online manages important mail-flow and email authentication configurations within Microsoft 365, including DKIM-related configuration. DKIM uses cryptographic signing to help receiving mail systems verify that messages claiming to originate from an organization&#8217;s domain were authorized by that domain. Administrators configure the required settings and DNS records as part of the organization&#8217;s email authentication strategy. Microsoft Purview focuses on compliance and governance, Intune manages devices and applications, and Defender provides security capabilities around email and other workloads rather than replacing Exchange Online&#8217;s core mail configuration functions.<\/span><\/p>\n<h3><b>Question 68<\/b><\/h3>\n<p><b>What does a Microsoft Entra administrative unit primarily provide?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A way to segment administrative scope<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A method for encrypting email<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A replacement for Microsoft 365 licenses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A system for scanning documents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra administrative units allow organizations to divide users and other directory objects into logical administrative scopes. This can be useful when an organization has regional offices, departments, campuses, or other organizational divisions that require delegated administration. Administrators can assign appropriate roles with a limited scope rather than giving access across the entire directory. Administrative units do not replace licensing, provide email encryption by themselves, or scan documents. Their primary purpose is to support more controlled and segmented directory administration.<\/span><\/p>\n<h3><b>Question 69<\/b><\/h3>\n<p><b>A security administrator wants to investigate potentially malicious activity across Microsoft 365 services from one security investigation interface. Which solution is designed for this purpose?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender XDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 admin center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Bookings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint admin center<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender XDR provides an integrated security investigation and response experience across supported Microsoft security workloads. It can correlate alerts and incidents from services such as Defender for Endpoint, Defender for Office 365, and other Microsoft security products. This cross-workload visibility helps security teams investigate related activities without treating every alert as an isolated event. The Microsoft 365 admin center is primarily intended for administrative management, while Bookings and SharePoint administration address specific productivity and collaboration workloads rather than centralized security investigation.<\/span><\/p>\n<h3><b>Question 70<\/b><\/h3>\n<p><b>Which feature can require users to register authentication methods before they need them for account recovery or multifactor authentication?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra authentication methods registration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview eDiscovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defender Safe Attachments<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra authentication methods registration enables organizations to manage how users register authentication methods such as Microsoft Authenticator or other supported methods. Requiring users to register appropriate methods in advance helps ensure they can complete multifactor authentication or use supported recovery processes when needed. Administrators can apply registration requirements through Microsoft Entra capabilities and appropriate policies. Message trace investigates email delivery, eDiscovery supports compliance investigations, and Safe Attachments analyzes files in email. These services do not manage user authentication-method registration.<\/span><\/p>\n<h3><b>Question 71<\/b><\/h3>\n<p><b>Which Microsoft 365 service provides centralized management of compliance policies, investigations, and data governance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Intune<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Teams admin center<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview provides capabilities for compliance, information governance, data security, and regulatory requirements across Microsoft 365 and other supported data sources. Administrators can use Purview to manage areas such as data loss prevention, retention, auditing, eDiscovery, and information protection. Microsoft Defender is primarily focused on security threats and incident response, while Intune manages devices and applications. The Teams admin center focuses on Microsoft Teams configuration and management. Purview therefore provides the centralized compliance and governance capabilities described in the scenario.<\/span><\/p>\n<h3><b>Question 72<\/b><\/h3>\n<p><b>An organization wants administrators to receive alerts when Microsoft 365 services experience an outage. Which Microsoft 365 capability should they monitor?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service Health<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit Explorer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compliance Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft 365 Service Health provides information about the current status of Microsoft 365 services and known incidents that may affect an organization. Administrators can review service incidents, advisories, updates, and relevant details through the Microsoft 365 admin center. This helps administrators determine whether a reported problem is related to a broader Microsoft service issue. Secure Score focuses on security posture, Audit Explorer supports activity investigation, and Compliance Manager helps assess compliance requirements. Service Health is therefore the appropriate capability for monitoring service availability and outages.<\/span><\/p>\n<h3><b>Question 73<\/b><\/h3>\n<p><b>Which control can limit access to Microsoft 365 resources based on a user&#8217;s device compliance status?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender Antivirus<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Conditional Access can evaluate signals such as user identity, device state, application, location, and risk before allowing access to Microsoft 365 resources. When integrated with Microsoft Intune, Conditional Access can require a device to be marked compliant before access is granted. This allows organizations to enforce security requirements such as encryption, password policies, or minimum operating-system versions before users access corporate resources. Exchange Online Protection protects email, Purview Audit records activities, and Defender Antivirus provides endpoint malware protection rather than making the described access decision.<\/span><\/p>\n<h3><b>Question 74<\/b><\/h3>\n<p><b>What is the main purpose of a Microsoft 365 group?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Provide a shared collaboration space for users<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace Microsoft Entra ID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypt all organizational files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure DNS authentication records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Microsoft 365 group provides a collaboration framework that can connect users with shared resources such as a group mailbox, calendar, SharePoint site, and other Microsoft 365 services depending on the workload. It is designed to support collaboration among a defined set of users rather than simply acting as an identity directory. Microsoft Entra ID remains the identity platform, while DNS authentication records are configured separately for email security. Microsoft 365 groups therefore provide a convenient way to organize collaborative resources around a group of users.<\/span><\/p>\n<h3><b>Question 75<\/b><\/h3>\n<p><b>An administrator needs to identify which users have not signed in recently so inactive accounts can be reviewed. What should be examined?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User sign-in activity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DKIM selector records<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Safe Links reports<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retention labels<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User sign-in activity can help administrators identify accounts that have not authenticated recently. Reviewing sign-in information is useful for account lifecycle management, security investigations, and identifying potentially stale accounts. Administrators can use Microsoft Entra information to examine authentication activity and determine whether accounts remain actively used. DKIM records relate to email authentication, Safe Links reports concern URL protection, and retention labels control data retention or disposition. Inactive account reviews should therefore begin with authentication and sign-in activity rather than unrelated Microsoft 365 security or compliance controls.<\/span><\/p>\n<h3><b>Question 76<\/b><\/h3>\n<p><b>Which Microsoft 365 capability helps administrators identify and review potentially risky user sign-ins?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SharePoint Version History<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online Archive<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Apps admin center<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID Protection detects and helps investigate identity-related risks, including potentially risky sign-ins and compromised identities. It uses signals associated with authentication activity to identify suspicious patterns and provides risk information that can be used with other identity controls. Administrators can investigate detected risks and configure appropriate responses based on organizational requirements. SharePoint Version History manages document versions, Exchange Online Archive handles mailbox storage, and the Microsoft 365 Apps admin center focuses on application deployment and management rather than identity risk detection.<\/span><\/p>\n<h3><b>Question 77<\/b><\/h3>\n<p><b>A company wants to prevent external users from accessing a SharePoint document containing sensitive financial information. Which Microsoft 365 capability can help enforce this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Online message trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Service Health<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention can help organizations identify sensitive information and apply policies that restrict or control actions involving protected content. Depending on the workload and configured policy conditions, DLP can help prevent inappropriate sharing of sensitive information through supported Microsoft 365 services, including SharePoint and OneDrive. Message trace is intended for email-flow investigation, Secure Score provides security improvement recommendations, and Service Health reports service incidents. DLP is therefore the relevant capability when the primary objective is preventing inappropriate exposure of sensitive organizational information.<\/span><\/p>\n<h3><b>Question 78<\/b><\/h3>\n<p><b>Which role is generally appropriate for managing Exchange Online settings without granting full Microsoft 365 administrative privileges?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exchange Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Billing Administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service Support Administrator<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Exchange Administrator role is designed to provide administrative permissions for Exchange Online without requiring the broad privileges associated with the Global Administrator role. Using specialized administrative roles supports least-privilege administration because administrators receive access relevant to their responsibilities. A Global Administrator has much broader control across the tenant, while Billing Administrator focuses on billing-related functions and Service Support Administrator is intended for support-related tasks. Assigning Exchange-specific administration to the Exchange Administrator role can therefore reduce unnecessary privileges while still allowing required mailbox and mail-flow management.<\/span><\/p>\n<h3><b>Question 79<\/b><\/h3>\n<p><b>Which Microsoft 365 feature allows an organization to review recorded administrative and user activities for investigation purposes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Purview Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft 365 Apps<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Bookings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Forms<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Audit records and provides tools for searching activities performed across supported Microsoft 365 services. Administrators and compliance teams can use audit information to investigate actions such as administrative changes, file activities, sharing events, and other recorded operations. The exact events available depend on the workload and auditing configuration. Microsoft 365 Apps, Bookings, and Forms provide productivity capabilities rather than centralized audit investigation. Audit information can support security investigations, compliance reviews, and troubleshooting by establishing a record of relevant user or administrator activity.<\/span><\/p>\n<h3><b>Question 80<\/b><\/h3>\n<p><b>An organization wants to reduce the number of highly privileged accounts by assigning administrators only the permissions required for their jobs. Which security principle does this represent?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Nonrepudiation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The principle of least privilege requires users and administrators to receive only the permissions necessary to perform their assigned responsibilities. In Microsoft 365, this can be implemented through specialized administrative roles and appropriately scoped permissions instead of giving many administrators Global Administrator access. Reducing unnecessary privileges limits the potential impact if an account is compromised or misused. Defense in depth refers to multiple layers of security, data minimization concerns limiting unnecessary data collection or retention, and nonrepudiation concerns proving the origin or integrity of an action.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft MS-102 Exam Dumps and Practice Test Dumps. &nbsp; Question 61 Which Microsoft 365 feature helps administrators manage user accounts, licenses, and organizational settings from a centralized interface? Microsoft Purview portal Microsoft 365 admin center Microsoft Defender portal Exchange admin center Correct Answer: 2 Explanation The Microsoft 365 admin center provides a centralized [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16851"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=16851"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16851\/revisions"}],"predecessor-version":[{"id":16852,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16851\/revisions\/16852"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=16851"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=16851"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=16851"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}