Microsoft · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
32% of exam · 6 sample questions below
A security administrator needs a single console to investigate and respond to a complex incident involving alerts from endpoints, email, and identities. Which Microsoft portal should they use?
Microsoft 365 Defender portal
Microsoft 365 Defender portal unifies signals from Defender for Endpoint, Defender for Office 365, and Microsoft Entra ID Protection into one incident view, enabling cross-domain investigation and response. This single console satisfies the requirement to correlate endpoint, email, and identity alerts for a complex incident.
Microsoft Sentinel
Microsoft Defender for Cloud
Microsoft 365 compliance center
An organization uses Microsoft Defender for Cloud Apps to monitor shadow IT. They want to enforce policies that block downloads from risky cloud apps. Which Microsoft Defender XDR component provides this capability?
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that discovers sanctioned and unsanctioned cloud apps, assesses risk via the Cloud App Catalog, and enforces real-time session and access policies. It can restrict risky app usage using conditional access app controls, block downloads, or apply DLP checks across thousands of third-party SaaS services — capabilities no workload-specific Defender product can provide.
Microsoft Defender for Endpoint
Microsoft Defender for Identity
Microsoft Defender for Office 365
An organization wants to prevent users from running executable files from the Windows Temp folder. Which Microsoft Defender for Endpoint capability should be configured?
Attack surface reduction rules
Attack surface reduction (ASR) rules are a Windows Defender Exploit Guard capability that can specifically block process creation from common temporary folders (such as %Temp% and %AppData%) using a predefined rule like 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' or the explicit temp-folder rule, preventing malware from launching from file paths where droppers commonly execute. ASR rules are client-side, configured via Microsoft Intune, Configuration Manager, or GPO, and operate before the executable is allowed to spawn by intercepting process creation in the kernel and user-mode. This makes ASR the correct choice because it directly restricts executable execution based on file location and reputation, rather than merely restricting network or data access.
Network protection
Exploit protection
Controlled folder access
A security team wants to automatically investigate and respond to security incidents across endpoints, email, and identities without manual intervention. Which Microsoft Defender XDR capability provides this automation?
Automated investigation and response (AIR)
Automated investigation and response (AIR) in Microsoft Defender XDR automatically investigates alerts across endpoints, email, and identities, then applies remediation actions without analyst input. This directly satisfies the stem's requirement for hands-off response spanning all three workloads, unlike standalone playbooks or manual triage.
Advanced hunting
Threat analytics
Attack surface reduction rules
A security administrator notices that users are receiving phishing emails that evade built-in anti-spam filters. The administrator wants to enable users to report these suspicious emails from Outlook and have them automatically trigger an investigation and block the sender. Which feature should be configured in Microsoft Defender for Office 365?
Attack simulation training
Threat Explorer
User reported settings in the Microsoft 365 Defender portal
User reported settings in the Microsoft 365 Defender portal, found under Settings > Email & collaboration, are the native control plane that connects end-user report actions to backend automation. An admin can route reported messages to Microsoft for analysis, to a custom mailbox, or directly into automated investigation and response, and can enable the automatically block sender rule so that confirmed phishing verdicts instantly update the tenant block list. This is precisely the kind of correlated, report-initiated blocking that the other options lack, making it the correct choice for this scenario.
Safe Links
A security administrator wants to automatically block malicious IP addresses from sending email to Exchange Online mailboxes. Which Microsoft Defender component should be configured?
Exchange Online Protection (EOP)
Exchange Online Protection (EOP) is the correct answer because its connection filtering feature evaluates the source IP address of every inbound SMTP connection against Microsoft's default and tenant-specific IP allow/block lists and real-time reputation data. Malicious IPs are rejected at the transport layer before the message is accepted, and admins can explicitly add IPs to the block list in the anti-spam policy to enforce a custom allow/deny set for inbound mail flow.
Microsoft Defender for Endpoint
Microsoft Defender for Identity
Microsoft Defender for Cloud Apps
Want more Manage security and threats by using Microsoft Defender XDR practice?
Practice this domain28% of exam · 6 sample questions below
An administrator is onboarding a new custom domain for email in a Microsoft 365 tenant. Which step should be performed first?
Add the domain in the Microsoft 365 admin center
The first step in onboarding a custom email domain is to add it in the Microsoft 365 admin center (Settings > Domains > Add domain). This action registers the domain with your tenant and generates the necessary verification token, allowing you to proceed to the next step of proving ownership. This must occur before any TXT record or DNS changes can be associated with the domain.
Verify domain ownership by adding a TXT record
Configure DNS records for Microsoft services
Set the domain as the primary email domain
A company wants to prevent their Microsoft 365 tenant from allowing external users to be invited by default. Only specific administrators should be able to invite guests. Which setting should be changed?
External Identities – External collaboration settings
In Entra ID (Azure AD), navigate to External Identities > External collaboration settings and change the Guest invite settings to 'Only users assigned to specific admin roles can invite guests' (or 'No one can invite guests'). This is the administrative toggle that directly restricts who can issue B2B invitations, so it is the correct control to prevent the tenant from broadcasting external-user invitation privileges.
Conditional Access policy to block external users
Tenant restrictions
B2B direct connect
A company is planning to migrate from on-premises Exchange to Exchange Online and needs to ensure that mail flow can coexist between the two environments during the transition. Which tool should the administrator use to configure this hybrid deployment?
Microsoft Entra Connect
Exchange Hybrid Configuration Wizard
The Exchange Hybrid Configuration Wizard automates creation of the hybrid configuration, including connectors, accepted domains, OAuth and the free/busy sharing needed for coexistence. It is the supported tool for establishing mail flow between on-premises Exchange and Exchange Online during migration.
Microsoft 365 Admin Center
Exchange Admin Center
A newly hired administrator needs to manage user accounts, licenses, and reset passwords. Which portal should they access?
Microsoft 365 admin center
The Microsoft 365 admin center is the designated operational hub for managing Microsoft 365 user accounts, including creating new users, resetting passwords, adding users from a CSV, and assigning or revoking Microsoft 365 subscription licenses. It provides a service-aware view of all M365 workloads and is the primary portal for common administrative tasks like user lifecycle management and billing. While identity data resides in Microsoft Entra ID, the M365 admin center is the intended interface for day-to-day account administration.
Microsoft Entra admin center
Microsoft 365 Defender
Microsoft Entra ID admin center
An administrator has created a new user account in Microsoft Entra ID. To ensure the user has a mailbox in Exchange Online, what is the next step?
Assign an Exchange Online license to the user
In Microsoft Entra ID (Azure AD), a user object does not automatically have an Exchange Online mailbox until a license that contains the Exchange Online service plan (e.g., Microsoft 365 E3/E5, Exchange Online Plan 1/2) is assigned. Once assigned, the Exchange Online provisioning service creates the mailbox automatically, usually within minutes to a few hours, and the user can log in to Outlook or Outlook on the web. This is the only supported, self-service method for creating a mailbox for a standard user in a cloud-only environment.
Create an Exchange mailbox manually
Run the Microsoft 365 Setup wizard
Configure DNS records for the domain
An organization has registered the domain contoso.com and added it to their Microsoft 365 tenant. What is the next step to use this domain for user email addresses?
Add a DNS TXT record provided by Microsoft to the domain registrar
Domain ownership verification in Microsoft 365 is performed by adding the exact TXT record—containing a unique verification string generated in the Microsoft 365 admin center—to the domain's public DNS zone at the registrar. Microsoft periodically queries the TXT record for that domain; when the value matches, the domain is marked as verified and becomes an accepted domain. This must complete successfully before any user accounts, mail routing, or other service records can be associated with the custom domain.
Create user accounts with the new domain
Configure Exchange Online connectors
Set up MX records for email routing
Want more Deploy and manage a Microsoft 365 tenant practice?
Practice this domain12% of exam · 6 sample questions below
A compliance officer needs to automatically retain emails that contain personally identifiable information (PII) for 10 years and then permanently delete them. Which Microsoft Purview feature should be configured?
Auto-apply retention labels based on sensitive information types
Auto-apply retention labels are content-aware and can be configured to trigger whenever a sensitive information type—such as a credit card number, passport number, or other PII—is detected in an email. Once the label is applied, its retention settings enforce the 10-year retention period and, at the end of that period, automatically dispose of the item. This satisfies the requirement to selectively retain emails based on content, not just location or folder.
Data Lifecycle Management retention policy
Data classification
eDiscovery
A compliance officer needs to prevent external users from printing or copying content from documents stored in a SharePoint Online site. Which Microsoft Purview feature should be configured to enforce this restriction?
Sensitivity labels with encryption and usage rights
Sensitivity labels with encryption and usage rights directly enforce document-level restrictions by applying Azure Rights Management (RMS) protection. When an external user opens the document, the RMS client enforces usage rights that explicitly deny actions such as printing, copying, and editing, regardless of where the file is stored or how it is shared. These restrictions travel with the file itself, making them effective even after the file leaves your tenant, and they can be scoped to specific external users or groups.
Data Loss Prevention (DLP) policy
Information Barriers
Microsoft Purview Information Protection without encryption
A compliance officer needs to automatically classify documents in SharePoint Online that contain credit card numbers. The classification should apply a label that restricts access and adds a header. Which two Microsoft Purview features must be configured? (Choose two.)
Sensitivity labels
Sensitivity labels are the core classification mechanism in Microsoft Purview Information Protection. When applied, they embed metadata into the document and enforce protection settings such as encryption, rights management restrictions, and visual markings like headers, footers, or watermarks. The label persists with the content even when it leaves the organization, ensuring classification and protection follow the file. This directly satisfies the compliance officer's need to classify documents, especially when combined with auto-labeling for full automation.
Retention labels
Data Loss Prevention (DLP) policies
Auto-labeling policies
Auto-labeling policies automate the assignment of sensitivity labels by scanning content against conditions such as sensitive info types, keywords, or trainable classifiers. They can run in simulation mode to assess impact before enforcement, and they are able to label documents at rest in SharePoint/OneDrive as well as emails in transit in Exchange. This is the direct mechanism that lets a compliance officer automatically classify documents at scale without requiring manual user effort. Auto-labeling works hand-in-hand with sensitivity labels, making the classification process consistent and policy-driven.
A compliance administrator needs to ensure that all documents in a SharePoint library are retained for exactly 7 years and then allow users to manually dispose of them sooner after a review. What should they configure in Microsoft Purview?
Create a retention label with a retention period of 7 years and enable disposition review
A retention label with a 7-year period and disposition review is the correct choice because it retains the document for the full regulatory period, yet the disposition review step triggers a manual approval workflow at the end of the retention period. During that review, an authorized user can approve early disposal, satisfying the requirement that documents be manually dispose-able if approved, rather than being automatically deleted or locked indefinitely.
Create a retention label with a retention period of 7 years and no additional action
Create a sensitivity label that restricts access
Create a record label
An organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They want to create a policy that blocks users from pasting credit card numbers into web forms in Microsoft Edge. Which type of DLP policy should they configure?
Endpoint DLP
Endpoint DLP is the correct selection because it monitors Windows and macOS devices and can inspect user activities such as copying sensitive content to the clipboard. When a user attempts to paste that data into a web form, Endpoint DLP in Microsoft Edge or another supported Chromium-based browser can evaluate the policy condition and block the paste action. The capability relies on the Microsoft Purview endpoint agent being onboarded on the device, and it is the only option that controls clipboard operations at the endpoint itself.
Exchange DLP
SharePoint DLP
Teams DLP
A legal department needs to preserve all communications related to an ongoing lawsuit. They identify specific users and require that their mailbox items and OneDrive files are not altered or deleted. Which Microsoft Purview feature should be used?
Litigation Hold
Litigation Hold is the correct mechanism because it places a preservation hold on an entire mailbox and OneDrive for Business site in-place, preventing items from being permanently deleted or altered. Every version of a document and every mailbox item, including deleted items and items edited by users, is retained in the Recoverable Items folder until the hold is released. Deletion by users, as well as cleanup by retention policies, is blocked for held content, ensuring all communications related to the legal matter remain discoverable in their original location.
Retention Policy
Data Loss Prevention (DLP)
eDiscovery
Want more Manage compliance by using Microsoft Purview practice?
Practice this domain28% of exam · 6 sample questions below
A company uses Microsoft Entra ID for identity management. The security team wants to ensure that users cannot register applications in the tenant to prevent potential data leakage. Which setting should be configured?
Set the 'Admin consent requests' setting to 'Allow'
Enable the 'Admin consent workflow'
Set 'Users can register applications' to 'No' in User settings
The 'Users can register applications' setting, found under Microsoft Entra ID > User settings, is the directory-wide toggle that controls whether non-admin users can create application registrations in the tenant. Setting it to 'No' revokes the default user permission to self-register apps, ensuring only users with applicable administrative roles (such as Application Administrator) can register applications. This directly satisfies the requirement to prevent user app registration.
Set 'Users can consent to apps accessing company data' to 'No'
Your organization is migrating from on-premises Active Directory to Microsoft Entra ID. You need to ensure that users can use their existing on-premises passwords to log in to cloud services, while maintaining password policy enforcement on-premises. Which feature should you implement?
Password Hash Synchronization (PHS)
Pass-through Authentication with Seamless SSO
Pass-through Authentication with Seamless SSO is not the best option because it uses lightweight agents on-premises to validate passwords directly against Active Directory in real time, rather than synchronizing any password hash to Entra ID. While PTA avoids storing password hashes in the cloud, it introduces a dependency on on-premises agent availability, requires agent high availability planning, and Seamless SSO only provides silent sign-in on domain-joined devices. For a simple migration to cloud authentication, PTA is operationally more complex than PHS and does not allow cloud-based sign-in if the on-premises directory becomes unreachable.
Active Directory Federation Services (AD FS)
Install Microsoft Entra Connect with default settings
A multinational company uses Microsoft Entra ID with Conditional Access policies. They have a policy that requires multi-factor authentication (MFA) for all users when accessing the company's custom SaaS application. However, users from the European branch are reporting that they are prompted for MFA every time, even though they have already authenticated via a compliant device. What is the most likely cause?
The user's device is not marked as compliant
The user has per-user MFA enabled
The Conditional Access policy has a session control that requires sign-in frequency
Sign-in frequency is a Conditional Access session control that configures how often a user must re-authenticate, regardless of whether their device is compliant. Once the configured time window expires, the session's refresh token is no longer valid for re-authentication, forcing the user to provide MFA again. This exactly matches the reported behavior—repeated MFA prompts on a compliant device—because the policy is not checking device health but enforcing token lifetime limits.
The policy includes a location condition that is not met
You are configuring Microsoft Entra ID Protection. You want to automatically respond to a specific risk level by requiring the user to change their password. Which risk policy should you configure?
MFA registration policy
Sign-in risk policy
Session risk policy
User risk policy
User risk policy targets the user account itself, so its remediation action is a password change, satisfying the stem's requirement. Sign-in risk policy instead blocks or demands MFA at authentication, which cannot force a credential reset. Configuring user risk to High and allowing password change enforces the required response.
An organization is implementing Microsoft Entra Verified ID for verifiable credentials. They want to issue credentials to employees that can be used to prove employment status to third parties. Which component must be created first?
A presentation request policy
A distributed ledger network
A credential manifest in the Microsoft Entra admin center
A credential manifest is the core configuration artifact for issuing a verifiable credential in Microsoft Entra Verified ID. Defined in the Microsoft Entra admin center, it combines rules and display information: the rules definition specifies required claims, such as user attributes and optional validation logic, while the display definition controls the JSON schema and the visual layout of the credential. This manifest is what transforms a user's claim data into a signed verifiable credential, making it essential for any issuance scenario. Without it, the right issuance API calls would lack the necessary structure and would fail.
A decentralized identifier (DID) for the organization
Your company uses Microsoft Entra ID and has a hybrid identity with PHS. You need to ensure that when an on-premises user account is disabled, the corresponding cloud user is also blocked from signing in within 5 minutes. What should you configure?
Deploy Microsoft Entra Connect cloud sync
Deploying Microsoft Entra Cloud Sync is correct because the cloud sync agent can be configured to synchronize identity changes—including the userAccountControl disabled flag—as frequently as every 1 minute, which satisfies the 5-minute latency requirement. Unlike Entra Connect Sync's 30-minute default cycle, Cloud Sync uses a lightweight agent that can run in parallel with Connect Sync (for non-overlapping scopes) or as a replacement, enabling near-real-time propagation of account disables for security and compliance.
Enable password writeback
Configure Microsoft Entra Connect to sync the 'userAccountControl' attribute
Configure Microsoft Entra Connect Sync to use filtered synchronization
Want more Implement and manage Microsoft Entra identity and access practice?
Practice this domainThe MS-102 exam has 50 questions and must be completed in 120 minutes. The passing score is 700/1000.
Microsoft 365 administration scenario questions covering tenant management, compliance, security, messaging, and collaboration services.
The exam covers 4 domains: Manage security and threats by using Microsoft Defender XDR, Deploy and manage a Microsoft 365 tenant, Manage compliance by using Microsoft Purview, Implement and manage Microsoft Entra identity and access. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Microsoft MS-102 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.