Courseiva

Microsoft 365 Administrator MS-102 (MS-102) — Questions 1–75

712 questions total · 10pages · All types, answers revealed

Page 1 of 10

Page 2
1
MCQmedium

A company uses Azure AD Identity Protection. The security administrator wants to block user sign-ins when the sign-in risk level is detected as 'High' for a custom SaaS application. Which Conditional Access policy configuration should the administrator use?

A.Create a Conditional Access policy with a grant control to require MFA when sign-in risk is high
B.Create a Conditional Access policy set to block access when sign-in risk is high
C.Configure a session control in Conditional Access to sign out users when risk is high
D.Enable Identity Protection risk policy to automatically block users
AnswerB

Setting the Conditional Access grant control to 'Block access' with the condition 'Sign-in risk: High' directly denies the authentication attempt before any token is issued. This policy can be scoped to the specific application, providing finer granularity than a global Identity Protection risk policy. Blocking is the only control that guarantees a high-risk sign-in cannot begin a session.

Why this answer

The requirement is to block sign-ins when the sign-in risk level is 'High' for a custom SaaS application. In Microsoft Entra ID (formerly Azure AD), a Conditional Access policy can be configured with a 'Block access' grant control, which directly denies authentication when the specified condition (sign-in risk level equals High) is met. This is the most straightforward and secure approach to prevent access without relying on additional authentication factors or session controls.

Exam trap

The trap here is that candidates often confuse Identity Protection risk policies with Conditional Access policies, or mistakenly think that requiring MFA is equivalent to blocking access when the requirement explicitly states 'block user sign-ins.'

How to eliminate wrong answers

Option A is wrong because requiring MFA when sign-in risk is high does not block access; it allows access after successful MFA, which does not meet the requirement to block sign-ins. Option C is wrong because session controls, such as 'Sign out users when risk is high,' apply after authentication has already occurred and do not prevent the initial sign-in; they manage active sessions but do not block the authentication request itself. Option D is wrong because Identity Protection risk policies (user risk or sign-in risk policies) are separate from Conditional Access and can automatically block users, but the question specifically asks for a Conditional Access policy configuration, making this option incorrect in context.

2
Multi-Selecthard

You are deploying Microsoft Entra ID Governance. Which THREE capabilities should you include to meet compliance requirements for access recertification and lifecycle management?

Select 3 answers
A.Identity Protection
B.Access Reviews
C.B2B Collaboration
D.Lifecycle Workflows
E.Entitlement Management
AnswersB, D, E

Access Reviews periodically recertify group membership, application access and privileged role assignments, producing reviewer decisions and audit records. This directly satisfies the compliance requirement for access recertification within Microsoft Entra ID Governance, complementing entitlement management and lifecycle workflows.

Why this answer

Access Reviews (B) is correct because it is the Entra ID Governance capability that drives access recertification, letting reviewers periodically attest to group memberships, application assignments, and privileged role assignments so stale or excessive access is removed. Lifecycle Workflows (D) is correct because it automates joiner, mover, and leaver tasks—such as pre-hire provisioning, attribute-based updates, and post-termination access removal—which is exactly the lifecycle management requirement. Entitlement Management (E) is correct because access packages, catalogs, and assignment policies govern who can request and retain access, with expiration and approval controls that support recertification and lifecycle governance.

Identity Protection (A) is not included because it is a risk-detection and conditional access signal service, not a recertification or lifecycle tool, and B2B Collaboration (C) is not included because it only enables external guest access rather than providing the required governance capabilities.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based conditional access with governance recertification, or assume B2B Collaboration covers lifecycle management, when in fact only Access Reviews, Lifecycle Workflows, and Entitlement Management directly address compliance-driven access recertification and lifecycle automation.

3
MCQeasy

A compliance officer needs to ensure that all documents in a SharePoint Online library are automatically labeled with a 'Confidential' sensitivity label if they contain at least one of a predefined list of sensitive information types such as credit card numbers or social security numbers. Users should be able to override the label with a business justification. Which Microsoft Purview feature should the officer configure?

A.Auto-labeling policy for SharePoint Online
B.Data Loss Prevention (DLP) policy
C.Retention label policy
D.Sensitivity label with manual classification
AnswerA

Auto-labeling policies in the Microsoft Purview compliance portal let you define conditions—such as sensitive info types, trainable classifiers, or custom keywords—that trigger automatic application of a sensitivity label to matching SharePoint Online documents. Once created, the policy runs continuously, and in enforcement mode it labels every existing and new file that meets the criteria, providing a scalable, centralized solution. You can also require users to justify lowering or removing the label, balancing automation with user oversight. This directly satisfies the need to ensure all relevant documents are classified automatically.

Why this answer

Auto-labeling policies in Microsoft Purview can automatically apply sensitivity labels to documents in SharePoint Online based on the detection of sensitive information types (e.g., credit card numbers, SSNs). This policy supports user override with a business justification, meeting the compliance officer's requirement exactly. Manual classification (Option D) would not automate the labeling, and DLP policies (Option B) focus on preventing data loss, not applying sensitivity labels.

Exam trap

Microsoft often tests the distinction between auto-labeling policies (which apply sensitivity labels automatically) and DLP policies (which enforce actions like blocking or alerting), causing candidates to confuse the two because both can detect sensitive information types.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) policies are designed to detect and block the sharing of sensitive data, not to automatically apply sensitivity labels to documents; they can trigger alerts or block actions but do not label content. Option C is wrong because retention label policies manage how long content is kept or deleted, not sensitivity classification; they are unrelated to labeling based on sensitive information types. Option D is wrong because a sensitivity label with manual classification requires users to manually apply the label, which does not satisfy the requirement for automatic labeling based on content detection.

4
MCQhard

An organization uses Microsoft Entra ID with Pass-through Authentication (PTA) and Seamless Single Sign-On (SSO). They notice that password changes in on-premises Active Directory are not reflecting immediately in Microsoft Entra ID for some users. What is the most likely cause?

A.The PTA agents are overloaded
B.The user's password change has not replicated to all domain controllers
C.The Seamless SSO feature is disabled
D.Microsoft Entra ID has a password hash sync delay
AnswerB

The PTA agent validates each password request by contacting a domain controller in the on-premises AD environment. Because AD replication is multi-master and asynchronous, a password change made on one DC may not yet have reached the DC that the agent happens to query. Until replication completes, that DC still accepts the old password and rejects the new one, producing the exact issue described. This is the most likely cause for password changes not being reflected immediately, especially in environments with multiple domain controllers or slow site links.

Why this answer

In a Pass-through Authentication environment, password changes are processed by on-premises Active Directory. The password change must replicate to all domain controllers before Microsoft Entra ID can authenticate the new password via the PTA agent. If replication is incomplete, the PTA agent may contact a domain controller that still has the old password, causing the delay.

Exam trap

The trap here is that candidates often assume PTA agents instantly reflect on-premises changes, overlooking the critical dependency on Active Directory replication latency across domain controllers.

How to eliminate wrong answers

Option A is wrong because PTA agents are stateless and forward authentication requests to on-premises AD; overloaded agents would cause authentication failures or timeouts, not a delay in reflecting password changes. Option C is wrong because Seamless SSO is a Kerberos-based feature that provides silent sign-on for domain-joined devices; disabling it does not affect how password changes are propagated to Microsoft Entra ID. Option D is wrong because password hash sync is not used in a PTA-only deployment; the delay described is not due to hash sync, as PTA relies on real-time validation against on-premises AD.

5
MCQhard

A security administrator wants to create a custom detection rule in Microsoft Defender XDR that alerts when a device initiates an outbound TCP connection to a known malicious IP address on a non-standard port (e.g., port 4444). Which advanced hunting table should be queried to find these network connections?

A.DeviceNetworkEvents
B.DeviceProcessEvents
C.EmailEvents
D.IdentityLogonEvents
AnswerA

DeviceNetworkEvents is the advanced hunting table in Microsoft Defender XDR that records each network connection event on monitored endpoints, including LocalIP, RemoteIP, LocalPort, RemotePort, Protocol, and ActionType (e.g., ConnectionAttempt, ConnectionSuccess). For a custom detection rule that needs to flag suspicious outbound connectivity, this table is the authoritative source because every row represents an actual device-initiated or accepted network connection with the exact destination endpoint needed for threshold or indicator matching.

Why this answer

DeviceNetworkEvents is the correct table because it specifically captures network connection events, including outbound TCP connections to IP addresses and ports. This table contains fields like RemoteIP, RemotePort, and Protocol, making it ideal for detecting connections to known malicious IPs on non-standard ports such as 4444.

Exam trap

The trap here is that candidates may confuse DeviceProcessEvents with network events because processes often initiate network connections, but DeviceProcessEvents does not contain network-level details like remote IP or port, leading to an incorrect choice.

How to eliminate wrong answers

Option B is wrong because DeviceProcessEvents logs process creation and execution events, not network connections; it lacks network-specific fields like RemoteIP or RemotePort. Option C is wrong because EmailEvents tracks email-related activities (delivery, phishing, etc.) and has no network connection data. Option D is wrong because IdentityLogonEvents records authentication and logon events for user identities, not device-level network traffic.

6
MCQmedium

Your company is implementing a Zero Trust security model. You need to ensure that all user access requests to corporate resources are verified continuously, not just at the initial sign-in. Which Microsoft Entra ID feature should you use?

A.Continuous Access Evaluation (CAE)
B.Microsoft Entra Identity Protection
C.Microsoft Entra Privileged Identity Management (PIM)
D.Microsoft Entra Verified ID
AnswerA

Continuous Access Evaluation (CAE) is the feature that enforces zero trust continuous verification by allowing Entra ID and resource providers to respond in real time to critical events. When a user is disabled, a password is changed, or a conditional access policy is updated, CAE revokes access within seconds—even if the token itself is still technically valid. It does this through a shared token validation mechanism: resource providers like Exchange Online and SharePoint Online consult a revocation table and reject tokens for sessions that have been terminated, instead of waiting for token expiration. This gives administrators immediate, policy-driven access revocation that aligns exactly with the scenario described.

Why this answer

Continuous Access Evaluation (CAE) is the correct choice because it enforces real-time token validation and policy enforcement for every access request, not just at initial authentication. CAE works by having critical events (e.g., user disablement, IP address change, or risk elevation) trigger a revocation message to the resource provider, which then immediately blocks access—even if the token is still valid. This aligns directly with the Zero Trust principle of 'verify explicitly and continuously' rather than relying on a one-time sign-in.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based conditional access policies with continuous enforcement, but Identity Protection only triggers a block at sign-in or via a conditional access policy check, not mid-session for every subsequent request.

How to eliminate wrong answers

Option B (Microsoft Entra Identity Protection) is wrong because it focuses on detecting and responding to identity-based risks (e.g., leaked credentials, anomalous sign-ins) but does not provide continuous, real-time access enforcement for every resource request—it is a risk-detection and remediation tool, not a session-level enforcement mechanism. Option C (Microsoft Entra Privileged Identity Management) is wrong because it manages just-in-time privileged role activation and approval workflows, not continuous verification of all user access requests; it addresses privilege escalation, not ongoing access validation. Option D (Microsoft Entra Verified ID) is wrong because it is a decentralized identity solution for verifying credentials (e.g., employment or education claims) via verifiable credentials, not a mechanism for continuously evaluating access tokens or enforcing policy at runtime.

7
MCQeasy

A company wants to ensure that all new users register for multi-factor authentication (MFA) within 14 days of account creation. Which Microsoft Entra ID feature should be used?

A.MFA registration campaign
B.Conditional Access policy
C.Identity Protection
D.Access Reviews
AnswerA

The MFA registration campaign is an Entra ID feature that proactively forces all users to register their MFA authentication methods within a configurable enforcement period (e.g., 14 days). It sends email and portal notifications, tracks registration completion, and blocks users who miss the deadline, making it the only option here that directly drives enrollment. This is exactly what 'ensure all new users register for MFA' requires, as it combines a hard deadline with communication and blocking.

Why this answer

The MFA registration campaign in Microsoft Entra ID is specifically designed to enforce user registration for MFA within a defined time frame, such as 14 days. It targets new users and sends them reminders to register, blocking access until registration is completed, which directly meets the company's requirement.

Exam trap

The trap here is that candidates often confuse Conditional Access policies (which enforce MFA at sign-in) with the registration campaign (which enforces the initial setup), leading them to select Conditional Access as the solution for a time-bound registration requirement.

How to eliminate wrong answers

Option B is wrong because Conditional Access policies enforce MFA during sign-in but do not natively enforce a registration deadline for new users; they require MFA to be already registered. Option C is wrong because Identity Protection detects risks and can trigger MFA, but it does not manage the initial registration process or enforce a time-bound registration campaign. Option D is wrong because Access Reviews are used to audit and recertify existing access assignments, not to enforce new user MFA registration within a specific period.

8
MCQmedium

A company has a Microsoft 365 tenant with the domain contoso.com. They acquire a subsidiary with the domain fabrikam.com and want to add it as an additional domain to the same tenant. The domain is already purchased and DNS management is available. What is the first step the administrator should take in the Microsoft 365 admin center?

A.Add the domain and verify ownership by adding a TXT record
B.Create a new tenant for fabrikam.com
C.Set up email forwarding from contoso.com to fabrikam.com
D.Convert fabrikam.com to a federated domain
AnswerA

Adding the domain and verifying ownership via a TXT record is the mandatory first step; Microsoft 365 cannot use fabrikam.com until DNS proof of ownership succeeds. Only after verification can you create users, assign licences, or set fabrikam.com as default.

Why this answer

To add an existing domain like fabrikam.com to a Microsoft 365 tenant, the first step is to add the domain in the Microsoft 365 admin center and then verify ownership by adding a TXT record to the domain's DNS zone. This verification proves the administrator controls the domain, which is a prerequisite for using it with Microsoft 365 services such as Exchange Online or SharePoint.

Exam trap

The trap here is that candidates may confuse the order of operations and attempt to configure advanced features like federation or email routing before completing the mandatory domain verification step, which is always the first action required when adding a new domain to a tenant.

How to eliminate wrong answers

Option B is wrong because creating a new tenant for fabrikam.com would isolate the subsidiary's users and resources from the existing contoso.com tenant, defeating the purpose of consolidating domains under one tenant. Option C is wrong because email forwarding from contoso.com to fabrikam.com is a post-verification routing configuration, not a domain addition step, and it does not establish domain ownership. Option D is wrong because converting fabrikam.com to a federated domain requires the domain to first be added and verified in the tenant; federation is an advanced authentication configuration that cannot be performed as the initial step.

9
MCQeasy

A compliance officer needs to prevent users from sharing emails that contain credit card numbers with external recipients. When a user attempts to send such an email, it should be blocked immediately, and a policy tip should notify the user. Which Microsoft Purview solution should the officer configure?

A.Data Loss Prevention (DLP) policy
B.sensitivity label
C.retention label
D.An information barrier policy
AnswerA

A Data Loss Prevention (DLP) policy in Microsoft Purview can inspect outbound email messages in real time for sensitive information types (e.g., credit card numbers, PII) and apply actions such as blocking delivery, redirecting the message, or allowing override with justification. While composing, the policy can display a policy tip to the user, providing immediate feedback that sharing such content is prohibited, which directly enforces the compliance officer's requirement to prevent email sharing.

Why this answer

A Data Loss Prevention (DLP) policy is the correct solution because it is specifically designed to detect sensitive information, such as credit card numbers, in transit (e.g., email) and enforce actions like blocking the message and displaying a policy tip to the user. DLP policies use sensitive information types (e.g., Credit Card Number) and rules to inspect content in Exchange Online, SharePoint, OneDrive, and Teams, allowing real-time blocking with user notification. This directly meets the compliance officer's requirement to prevent external sharing and provide immediate feedback.

Exam trap

Microsoft often tests the distinction between DLP policies and sensitivity labels, where candidates mistakenly think a sensitivity label alone can block email transmission, but labels require a DLP policy to enforce actions like blocking, while DLP policies can work independently of labels.

How to eliminate wrong answers

Option B (sensitivity label) is wrong because sensitivity labels classify and protect data at rest (e.g., encryption, visual markings) but do not natively block email transmission based on content inspection or provide policy tips in real-time; they require additional DLP policies to enforce actions on labeled content. Option C (retention label) is wrong because retention labels manage data lifecycle (retention and deletion) and have no capability to inspect email content for sensitive data or block messages. Option D (information barrier policy) is wrong because information barriers restrict communication between specific user groups (e.g., to prevent conflicts of interest) and do not scan for sensitive data like credit card numbers or block external sharing.

10
MCQmedium

A company is deploying Microsoft 365 and wants to ensure that users in the finance department have access to only the apps they need. You need to recommend a licensing strategy that minimizes administrative overhead while enforcing access restrictions. What should you do?

A.Create a security group with explicit membership and assign licenses to the group.
B.Create a dynamic Azure AD group based on department attribute and assign licenses using group-based licensing.
C.Assign licenses to users one by one in the Microsoft 365 admin center.
D.Use PowerShell to assign licenses based on user department attribute.
AnswerB

Creating a dynamic Azure AD group with a rule such as user.department -eq 'Finance' ensures that users are automatically added to the group when their department attribute matches and removed when it changes. When you assign licenses using group-based licensing, the license is automatically applied to every member and automatically removed from users who are removed from the group. This fully automates the lifecycle of license assignment, eliminating manual intervention and ensuring compliance with the department's actual headcount.

Why this answer

Using a dynamic Azure AD group based on the department attribute automates membership updates as users change departments, and group-based licensing assigns the appropriate licenses to all members without manual intervention. This minimizes administrative overhead by eliminating the need to manually add or remove users from the group or assign licenses individually, while enforcing access restrictions by ensuring only finance users receive the licensed apps.

Exam trap

The trap here is that candidates often choose Option A (security group with explicit membership) because they think it provides more control, but they overlook the administrative overhead of manual membership management and the fact that group-based licensing works with any Azure AD group type, including security groups, as long as the group is used for license assignment.

How to eliminate wrong answers

Option A is wrong because a security group with explicit membership requires manual updates when users join or leave the finance department, increasing administrative overhead and risking stale memberships. Option C is wrong because assigning licenses one by one in the Microsoft 365 admin center is highly manual and does not scale, nor does it enforce dynamic access restrictions based on department changes. Option D is wrong because using PowerShell to assign licenses based on department attribute requires scripting, scheduled runs, and error handling, which adds complexity and overhead compared to the built-in dynamic group and group-based licensing feature.

11
Multi-Selectmedium

Contoso wants to require multi-factor authentication (MFA) for all users when accessing cloud applications from any network except the corporate headquarters (trusted IP range). They plan to use Azure AD Conditional Access. Which two components must be configured to achieve this requirement? (Select all that apply.)

Select 2 answers
A.Conditional Access policy targeting all users and cloud apps, with conditions for locations
B.named location defining the corporate headquarters' trusted IP ranges
C.An Identity Protection user risk policy
D.An MFA registration policy requiring users to register for MFA
AnswersA, B

A Conditional Access policy is the operational enforcement point for MFA. By targeting all users and cloud apps and adding a location condition, you can require MFA for every sign-in that occurs outside defined trusted networks. This policy works by evaluating the user's IP address and applying an MFA challenge when the location is untrusted, which directly satisfies the goal of enforcing MFA universally. It also allows the use of 'report-only' mode for pre-testing before enforcement.

Why this answer

A Conditional Access policy must be created to enforce MFA based on location conditions. The policy targets all users and cloud apps, and uses the 'locations' condition to exclude the trusted IP range (corporate headquarters) while requiring MFA for all other locations. This ensures MFA is triggered only when access originates from outside the trusted network.

Exam trap

The trap here is that candidates often confuse the MFA registration policy (which only ensures users have registered MFA methods) with the Conditional Access policy that actually enforces MFA based on location conditions, leading them to incorrectly select Option D as a required component.

12
MCQeasy

A user reports that they cannot access a legitimate external website because Microsoft Defender for Endpoint is blocking it. The website is required for business. What should you do to allow access while maintaining security?

A.Exclude the device from the policy
B.Disable network protection for the device
C.Add the URL to the custom indicators allow list
D.Add the user to a custom group with lower security
AnswerC

Custom indicators in Microsoft Defender for Endpoint let you define allow entries that override block decisions for specific URLs, files or certificates. Adding the business URL to the allow list permits access while the rest of the indicator and protection stack stays enforced, satisfying the requirement to unblock one legitimate site.

Why this answer

Adding the URL to the custom indicators allow list in Microsoft Defender for Endpoint allows the specific URL while maintaining network protection for all other traffic. This is the granular approach to permit a legitimate business site without disabling security controls. The allow list overrides block actions for that indicator.

Exam trap

The trap is choosing to disable network protection or exclude the device entirely, which are heavy-handed and reduce security, instead of using the targeted allow list feature.

How to eliminate wrong answers

Option A is wrong because excluding the device from the policy removes all protections for that device, which is too broad and reduces security. Option B is wrong because disabling network protection for the device turns off the feature entirely, leaving the device vulnerable. Option D is wrong because adding the user to a custom group with lower security does not specifically allow the URL and may weaken security posture overall.

13
MCQmedium

A security administrator wants to prevent attackers from stealing credentials by blocking access to the Local Security Authority Subsystem Service (LSASS) from untrusted processes. Which Attack Surface Reduction (ASR) rule should the administrator enable to meet this requirement?

A.Block credential stealing from the Windows local security authority subsystem (lsass.exe).
B.Block executable files from running unless they meet a prevalence, age, or trusted list criterion.
C.Block Office applications from creating child processes.
D.Block persistence through Windows Management Instrumentation (WMI) event subscription.
AnswerA

LSASS is the Windows Local Security Authority Subsystem, which stores or caches credentials for single sign-on. Attackers use tools like Mimikatz or process injection to read the memory of lsass.exe and extract password hashes or plaintext credentials. The Block credential stealing from the Windows local security authority subsystem (lsass.exe) ASR rule prevents untrusted and non-signed processes from accessing lsass.exe, directly disrupting this credential-theft technique before it can succeed.

Why this answer

The ASR rule 'Block credential stealing from the Windows local security authority subsystem (lsass.exe)' (GUID: 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2) directly prevents untrusted processes from accessing LSASS memory, which is a common technique used by attackers to dump credentials via tools like Mimikatz. This rule blocks attempts to open lsass.exe with specific access rights (e.g., PROCESS_VM_READ) from non-trusted processes, thereby protecting credential material stored in LSASS.

Exam trap

The trap here is that candidates often confuse the 'Block credential stealing from LSASS' rule with other ASR rules that address different attack vectors, such as blocking executable files or Office child processes, because they all fall under the same 'Attack Surface Reduction' umbrella but target distinct behaviors.

How to eliminate wrong answers

Option B is wrong because it addresses executable file execution based on prevalence, age, or trusted list criteria, which is a different ASR rule (GUID: 01443614-cd74-433a-b99e-2ecdc07bfc25) focused on preventing untrusted or unknown executables from running, not specifically protecting LSASS from credential theft. Option C is wrong because it blocks Office applications from creating child processes (GUID: d4f940ab-401b-4efc-aadc-ad5f3c50688a), which prevents malware from using Office apps as a launch point but does not directly protect LSASS from credential access. Option D is wrong because it blocks persistence through WMI event subscription (GUID: e6db77e5-3df2-4cf1-b95a-636979351e5b), which prevents attackers from establishing persistence via WMI, but does not address the immediate credential theft from LSASS.

14
Multi-Selecthard

Which THREE are features of Microsoft Entra ID Governance? (Choose three.)

Select 3 answers
A.Password protection
B.Entitlement management
C.Conditional access policies
D.Access reviews
E.Privileged Identity Management (PIM)
AnswersB, D, E

Entitlement management is a core Microsoft Entra ID Governance feature that creates and manages access packages containing groups, apps, and SharePoint sites. It lets administrators define policies for requesting access, including approvals, separation-of-duties checks, and automatic expiration, so access is granted consistently and governed through the resource's lifecycle. By automating the full access-assignment lifecycle and supporting connected organizations for external collaboration, entitlement management directly achieves identity governance objectives.

Why this answer

Entitlement management is a core feature of Microsoft Entra ID Governance that enables organizations to manage the lifecycle of access for internal and external users through access packages, catalogs, and policies. It automates access requests, approvals, and assignments, ensuring users have the right access to resources like groups, apps, and SharePoint sites.

Exam trap

The trap here is that candidates confuse security features like password protection or conditional access with governance features, but Entra ID Governance specifically focuses on identity lifecycle, access requests, reviews, and privileged role management (PIM).

15
Multi-Selectmedium

Your organization uses Microsoft Defender for Endpoint. You need to configure advanced hunting to query device information. Which TWO tables contain device-related data?

Select 2 answers
A.AlertInfo
B.EmailEvents
C.IdentityLogonEvents
D.DeviceInfo
E.DeviceTvmInfoGathering
AnswersD, E

DeviceInfo is the core table in Microsoft Defender for Endpoint's Advanced Hunting that maintains a comprehensive inventory of all onboarded devices, including device ID, device name, OS platform, OS version, and last seen timestamp. It is the authoritative source for answering questions like 'which devices run Windows 11' or 'what OS versions are present.' By querying DeviceInfo and filtering on the OSVersion column, you can quickly retrieve the required device details.

Why this answer

DeviceInfo is correct because it is the primary table in Microsoft Defender for Endpoint advanced hunting that stores comprehensive device metadata, including OS version, device name, and sensor health. This table is essential for querying device-related information such as device inventory, onboarding status, and configuration details.

Exam trap

The trap here is that candidates may confuse tables that contain device identifiers (like IdentityLogonEvents or AlertInfo) with tables that store actual device-related data, leading them to select tables that only reference devices indirectly rather than containing device properties.

16
Multi-Selectmedium

Your organization is implementing Microsoft Purview Data Loss Prevention (DLP). You need to ensure that sensitive data such as credit card numbers cannot be shared externally via email. Which THREE components should you configure?

Select 3 answers
A.Define sensitive information types for credit card numbers
B.Enable Microsoft Purview Insider Risk Management
C.Configure DLP rule actions to block external sharing
D.Configure a retention policy for email
E.Create a DLP policy in Microsoft Purview
AnswersA, C, E

Sensitive information types are the detection backbone of a Microsoft Purview DLP policy. Built-in SITs such as "Credit Card Number" use pattern matching, checksum validation, and keyword evidence to identify card data in Exchange, SharePoint, OneDrive, and Teams. Defining or fine-tuning these SITs (e.g., confidence levels or custom patterns) ensures that the DLP policy accurately detects credit card numbers before rules and actions can act on them.

Why this answer

A is correct because sensitive information types (SITs) are predefined or custom patterns that detect specific data like credit card numbers (e.g., regex matching major credit card formats). Defining the SIT for credit card numbers allows the DLP policy to identify this sensitive content in emails, which is the first step before any action can be taken.

Exam trap

The trap here is that candidates may confuse Insider Risk Management (a behavior-based tool) with DLP (a content-based policy), or think a retention policy is needed to block sharing, when in fact DLP policies alone handle detection and enforcement via SITs and rule actions.

17
MCQeasy

A company has purchased Microsoft 365 Business Premium and added a custom domain 'contoso.com' to the tenant. They want all new users to have email addresses like user@contoso.com instead of the default onmicrosoft.com domain. What should the administrator do in the Microsoft 365 admin center?

A.Set the custom domain as the default domain in the Domains settings.
B.Add a DNS TXT record for the custom domain.
C.Change the primary domain in the tenant's organization profile.
D.Update the MX record for the custom domain to point to Exchange Online.
AnswerA

Setting the custom domain as the default domain in the Microsoft 365 Domains settings is the correct action because the default domain is directly assigned to newly created user mailboxes and email addresses. When you select a verified custom domain and mark it as default, all new users will automatically receive email addresses ending with that domain, such as user@yourdomain.com, instead of the initial onmicrosoft.com domain. This configuration is managed under Admin > Domains, where the 'Default' indicator appears on the domain that will be used for new user creation. Note that this does not change the tenant's primary domain, which is fixed for the initial Azure AD organization.

Why this answer

Setting the custom domain as the default domain in the Domains settings ensures that any new user created in the Microsoft 365 admin center automatically receives an email address ending with @contoso.com instead of the default @<tenant>.onmicrosoft.com. This is the correct administrative action because the default domain setting controls the domain suffix applied to new user principal names (UPNs) and email addresses during user creation.

Exam trap

The trap here is that candidates confuse the default domain for new users with domain verification (TXT records) or mail routing (MX records), leading them to select options that are necessary for domain setup but not for controlling the email address assigned to new users.

How to eliminate wrong answers

Option B is wrong because adding a DNS TXT record is used for domain ownership verification, not for setting the default email domain for new users. Option C is wrong because changing the primary domain in the tenant's organization profile affects the initial onmicrosoft.com domain used for the tenant itself, not the default domain for new user email addresses. Option D is wrong because updating the MX record controls mail routing for the domain, not the default domain assigned to new users' email addresses.

18
MCQmedium

A company with 200 on-premises Exchange mailboxes plans to migrate to Exchange Online. They want to use a Microsoft-provided tool that supports granular control over mailbox migrations, allows batch migrations, and provides detailed reporting. Which migration method should the administrator choose?

A.Azure AD Connect
B.Exchange Admin Center (EAC) migration dashboard
C.Third-party migration tool (e.g., BitTitan MigrationWiz)
D.IMAP migration
AnswerB

The Exchange Admin Center (EAC) migration dashboard is the correct native Microsoft tool for a 200-mailbox on-premises Exchange environment. It uses the Mailbox Replication Service (MRS) to move entire mailboxes into Exchange Online, supporting cutover, staged, and hybrid migration models. The dashboard provides batch creation, incremental sync, status reporting, per-mailbox error logs, and the ability to schedule and manage multiple batches, making it purpose-built for mailbox migration.

Why this answer

The Exchange Admin Center (EAC) migration dashboard is the correct choice because it is a Microsoft-provided tool that supports granular control over mailbox migrations (e.g., selecting specific users, setting migration endpoints, and configuring throttling), allows batch migrations with the ability to start, stop, and monitor multiple batches simultaneously, and provides detailed reporting on migration status, errors, and sync progress. This method is specifically designed for migrating on-premises Exchange mailboxes to Exchange Online in a controlled, staged manner, making it ideal for the scenario described.

Exam trap

The trap here is that candidates often confuse Azure AD Connect (identity sync) with a migration tool, or they assume any Microsoft tool (like IMAP migration) is sufficient, but the question specifically requires granular control, batch support, and detailed reporting, which only the EAC migration dashboard provides for on-premises Exchange to Exchange Online migrations.

How to eliminate wrong answers

Option A is wrong because Azure AD Connect is a directory synchronization tool that syncs on-premises Active Directory objects to Azure AD, but it does not perform mailbox migration, provide granular control over mailbox moves, or offer batch migration reporting; it handles identity only. Option C is wrong because while third-party tools like BitTitan MigrationWiz can offer granular control and reporting, the question explicitly asks for a 'Microsoft-provided tool,' so a third-party solution does not meet that requirement. Option D is wrong because IMAP migration only migrates email data (folders, messages) from an IMAP-enabled source, not full mailbox items like calendar, contacts, or tasks, and it lacks granular control over individual mailboxes, batch management, and detailed reporting; it is a basic cutover method, not suitable for a controlled, staged migration from on-premises Exchange.

19
MCQeasy

You need to ensure that all documents in a SharePoint Online site are automatically labeled with a 'Confidential' sensitivity label. Which Microsoft Purview feature should you use?

A.Microsoft Purview auto-labeling policy
B.Microsoft Purview Data Loss Prevention policy
C.Microsoft Purview retention policy
D.Microsoft Purview manual labeling
AnswerA

Microsoft Purview auto-labeling policies apply sensitivity labels automatically to items matching specified conditions, such as documents in a SharePoint Online site, without user intervention. That satisfies the stem's requirement that all documents be labelled Confidential automatically rather than through manual or default labelling.

Why this answer

Auto-labeling policies can automatically apply sensitivity labels to documents in SharePoint Online based on conditions. Option B is wrong because Data Loss Prevention policies detect and protect sensitive data but do not apply labels. Option C is wrong because retention policies manage data retention and deletion, not sensitivity labels.

Option D is wrong because manual labeling requires user action, not automatic application.

20
MCQmedium

An administrator has configured group-based licensing in Azure AD. After adding users to the group, some users do not receive licenses. The users are in the group and have an assigned usage location. What is a possible reason?

A.The group is a mail-enabled security group, which is not supported for group-based licensing
B.The license product name in the group setting does not match the available licenses in the tenant
C.The users have conflicting license assignments from another source
D.The users have not accepted the Microsoft Online Service Terms
AnswerC

Conflicting license assignments are a common cause of partial group-based licensing failures. When a user already holds a license assigned directly or through another group that contains the same or conflicting service plans, Azure AD group-based licensing detects the conflict and places that user in an error state rather than applying the group license. The affected users will appear with an error status such as 'Conflicting service plans' in the Azure AD licensing blade, while other users without such conflicts get the license successfully.

Why this answer

Group-based licensing in Azure AD can fail when a user already has a license assigned from another source, such as direct assignment or another group. Azure AD's group-based licensing processes assignments in a deterministic order, and if a conflict arises (e.g., different service plans or SKUs), the system may skip the user and log an error in the audit logs. This is a common scenario when users are migrated from direct licensing to group-based licensing without removing the existing assignments.

Exam trap

The trap here is that candidates often assume group-based licensing always works if the user is in the group and has a usage location, overlooking the common real-world scenario where pre-existing direct license assignments cause silent failures that require manual conflict resolution.

How to eliminate wrong answers

Option A is wrong because mail-enabled security groups are fully supported for group-based licensing in Azure AD, as long as the group is a security group (mail-enabled or not). Option B is wrong because if the license product name in the group setting does not match an available license in the tenant, the group-based licensing assignment would fail for all users, not just some, and the administrator would receive a clear error during configuration. Option D is wrong because Microsoft Online Service Terms acceptance is a tenant-wide prerequisite that must be completed before any licensing can be applied; if it were not accepted, no users in the tenant would receive licenses at all, not just some users in a group.

21
MCQmedium

Refer to the exhibit. You need to ensure that users accessing Exchange Online from unmanaged devices are blocked. What should you modify in the policy?

A.Remove the MFA control
B.Add the 'approvedClientApp' grant control with OR
C.Add a session control for app protection policies
D.Change the operator from OR to AND
AnswerD

Changing the operator from OR to AND makes both grant controls mandatory, so a user must both complete MFA and use a compliant device. Since an unmanaged device cannot be marked as compliant, it will be blocked, while managed devices still benefit from MFA, exactly fulfilling the stated access requirement.

Why this answer

The exhibit shows a conditional access policy with two grant controls: 'Require multi-factor authentication' and 'Require device to be marked as compliant', connected by OR. With OR, users can satisfy either control, so unmanaged devices can still authenticate via MFA alone. Changing the operator to AND forces both MFA and device compliance, blocking access from unmanaged devices that cannot be compliant.

Exam trap

The trap here is that candidates overlook the OR operator and assume both controls are already required, not realizing that OR creates an alternative path that allows unmanaged devices to authenticate with just MFA.

How to eliminate wrong answers

Option A is wrong because removing the MFA control would leave only the device compliance requirement, which still blocks unmanaged devices but weakens security by removing MFA for managed devices. Option B is wrong because adding 'approvedClientApp' with OR would introduce another alternative path, making it even easier for unmanaged devices to bypass the block. Option C is wrong because session controls for app protection policies apply after access is granted (to restrict data exfiltration), not to block initial access from unmanaged devices.

22
MCQeasy

You need to allow external users from a specific partner organization to access a SharePoint Online site using their own Microsoft Entra ID credentials. Which feature should you configure?

A.Direct Federation
B.Self-service password reset
C.Microsoft Entra B2C
D.Microsoft Entra B2B collaboration
AnswerD

Microsoft Entra B2B collaboration is the correct solution because it enables you to invite external users from a partner organization into your tenant as guest accounts, where they authenticate using their own corporate credentials from their home identity provider. B2B collaboration creates a lightweight guest user object in your directory, then federates authentication back to the partner's Entra tenant or other supported IdP, so you do not need to manage or store their passwords. It allows you to apply conditional access, MFA, and access reviews to those guest accounts, and you can grant granular permissions to specific apps or SharePoint sites, which directly meets the requirement of allowing external users from a specific partner org.

Why this answer

Microsoft Entra B2B collaboration is the correct feature because it allows you to invite external users from a partner organization to access your SharePoint Online site using their own Microsoft Entra ID (or other identity provider) credentials. B2B collaboration uses cross-tenant trust to authenticate the external user against their home tenant, enabling seamless access without creating local accounts.

Exam trap

The trap here is that candidates often confuse Microsoft Entra B2B collaboration with Microsoft Entra B2C, mistakenly thinking B2C is for business partners, when in fact B2C is for consumer-facing identity management, not for granting access to enterprise resources like SharePoint Online.

How to eliminate wrong answers

Option A is wrong because Direct Federation (also known as direct federation with SAML/WS-Fed identity providers) is used for external identities that are not managed in Microsoft Entra ID, such as those from a generic SAML 2.0 IdP, and does not specifically enable partner users to use their own Microsoft Entra ID credentials. Option B is wrong because Self-service password reset (SSPR) is an internal feature that allows users in your own tenant to reset their passwords, not a mechanism for granting external users access to resources. Option C is wrong because Microsoft Entra B2C (Business-to-Consumer) is designed for customer-facing applications where users sign up with social or local accounts, not for granting partner organizations access to SharePoint Online using their corporate Microsoft Entra ID credentials.

23
MCQhard

You are troubleshooting an issue where users from a partner organization cannot access a shared app in your Microsoft Entra ID tenant. The partner uses Microsoft Entra ID with a custom domain. You have configured cross-tenant access settings. Which setting is most likely misconfigured?

A.Outbound cross-tenant access settings for the partner's tenant ID
B.The app's user assignment and provisioning configuration
C.Default inbound cross-tenant access settings for the partner's tenant ID
D.The partner's inbound cross-tenant access settings for your tenant
AnswerC

Default inbound cross-tenant access settings for the partner's tenant ID are the correct place to check because these settings determine whether external partner users are allowed to authenticate into your tenant and access your applications. Azure AD evaluates cross-tenant access policies individually for each external tenant, and the default inbound policy applies unless a tenant-specific override exists, so a block here would prevent partner users from signing in.

Why this answer

The default inbound cross-tenant access settings control how external users from other tenants access your tenant's resources. Since the partner cannot access the shared app, the most likely misconfiguration is that the default inbound settings for the partner's tenant ID are set to block access, or the partner's tenant ID is not explicitly allowed in the inbound settings. This overrides any app-level permissions, as cross-tenant access settings act as a gate before user assignment is evaluated.

Exam trap

The trap here is that candidates often focus on app-level configuration (user assignment or provisioning) or confuse inbound/outbound directions, overlooking that cross-tenant access settings act as a mandatory first gate that must explicitly allow the partner's tenant ID before any app access can occur.

How to eliminate wrong answers

Option A is wrong because outbound cross-tenant access settings control how your users access resources in the partner's tenant, not how partner users access your app. Option B is wrong because user assignment and provisioning configuration are app-level settings that only apply after cross-tenant access is allowed; if inbound access is blocked, the app settings are irrelevant. Option D is wrong because the partner's inbound cross-tenant access settings control access to their own resources, not to your tenant's app; you configure settings for your tenant, not the partner's.

24
MCQeasy

You are a security administrator. You need to configure Microsoft Defender for Cloud Apps to detect anomalous user activities such as impossible travel. Which feature should you enable?

A.App Discovery
B.Cloud Discovery
C.Anomaly Detection policies
D.Conditional Access App Control
AnswerC

Anomaly Detection policies are the correct selection because they leverage User and Entity Behavior Analytics (UEBA) in Microsoft Defender for Cloud Apps to establish a baseline of normal user behavior and then generate alerts for deviations such as impossible travel, anonymous IP access, or mass file download. These policies employ machine learning to detect suspicious activities and can automatically trigger governance actions, directly meeting the security administrator's goal.

Why this answer

Anomaly Detection policies in Microsoft Defender for Cloud Apps are specifically designed to identify user behavior anomalies, such as impossible travel (a user logging in from two geographically distant locations within an impossible timeframe). These policies leverage machine learning and user entity behavior analytics (UEBA) to establish a baseline and flag deviations, making them the correct feature for detecting impossible travel.

Exam trap

The trap here is that candidates often confuse Cloud Discovery (which discovers cloud apps) with Anomaly Detection policies (which detect user behavior anomalies), leading them to select Cloud Discovery for impossible travel detection.

How to eliminate wrong answers

Option A is wrong because App Discovery is a feature that identifies shadow IT by discovering cloud apps used in the organization, not for detecting user behavior anomalies like impossible travel. Option B is wrong because Cloud Discovery focuses on discovering and assessing cloud app usage and risk, not on analyzing user activity patterns for anomalies. Option D is wrong because Conditional Access App Control is a reverse proxy feature that enforces access policies in real time (e.g., session monitoring or blocking downloads), but it does not perform historical or behavioral anomaly detection like impossible travel.

25
MCQeasy

A security team wants to automatically investigate and respond to security incidents across endpoints, email, and identities without manual intervention. Which Microsoft Defender XDR capability provides this automation?

A.Automated investigation and response (AIR)
B.Advanced hunting
C.Threat analytics
D.Attack surface reduction rules
AnswerA

Automated investigation and response (AIR) in Microsoft Defender XDR automatically investigates alerts across endpoints, email, and identities, then applies remediation actions without analyst input. This directly satisfies the stem's requirement for hands-off response spanning all three workloads, unlike standalone playbooks or manual triage.

Why this answer

Automated investigation and response (AIR) is the Microsoft Defender XDR capability that automatically investigates alerts and takes remediation actions across endpoints, email, and identities without manual intervention. It uses playbooks and machine learning to triage incidents, determine scope, and apply actions like isolating devices or deleting malicious emails.

Exam trap

The trap here is that candidates confuse 'automated investigation and response' with 'advanced hunting' because both involve security analysis, but only AIR provides the automated remediation workflow without manual querying.

How to eliminate wrong answers

Option B is wrong because advanced hunting is a query-based tool for manually searching raw telemetry data using Kusto Query Language (KQL), not an automated response mechanism. Option C is wrong because threat analytics provides threat intelligence reports and vulnerability assessments but does not perform automated investigation or response actions. Option D is wrong because attack surface reduction rules are endpoint-specific configurations that block common attack techniques (e.g., Office macro execution), but they do not automate the investigation and response lifecycle across multiple domains.

26
MCQhard

You are configuring Microsoft Defender for Office 365 anti-phish policy. You want to protect against user impersonation attacks. The CEO and CFO are frequent targets. What should you configure in the anti-phish policy?

A.Configure spoof intelligence
B.Add the CEO and CFO's domains to domain impersonation
C.Enable user impersonation protection and add the CEO and CFO as protected users
D.Enable mailbox intelligence
AnswerC

User impersonation protection compares the sender's display name and address against a defined list, so adding the CEO and CFO as protected users blocks spoofed messages impersonating those executives, directly meeting the stated targeting of frequent executive targets.

Why this answer

User impersonation protection in anti-phish policies allows you to add specific users (e.g., CEO and CFO) as protected users. This protects against attacks where an attacker impersonates those users. Option A is incorrect because spoof intelligence protects against domain spoofing, not user impersonation.

Option B is incorrect because domain impersonation protects against impersonation of entire domains, not individual users. Option D is incorrect because mailbox intelligence is a feature that learns user communication patterns to detect impersonation, but it is not the configuration to protect specific users.

27
MCQmedium

A company uses Password Hash Synchronization (PHS) to synchronize identities to Microsoft Entra ID. They want to enable users to access Microsoft 365 applications from their domain-joined work devices without being prompted to re-enter their credentials. Which feature should they enable in addition to PHS?

A.Seamless Single Sign-On
B.Pass-through Authentication
C.Azure AD Connect Health
D.Conditional Access
AnswerA

Seamless Single Sign-On is the correct choice because it extends PHS by silently authenticating domain-joined devices via the on-premises Kerberos TGT, which Azure AD converts into a user token without prompting for credentials. This eliminates the repeated sign-in prompts that would otherwise occur after PHS validates a password hash, delivering a transparent single sign-on experience. It is a dedicated Azure AD Connect feature designed specifically to complement PHS or PTA in hybrid environments.

Why this answer

Seamless Single Sign-On (SSO) is the correct feature to enable alongside Password Hash Synchronization (PHS) because it allows users on domain-joined devices to automatically authenticate to Microsoft 365 applications without being prompted for credentials. It works by integrating with Kerberos authentication, using a computer account in the on-premises Active Directory to issue a Kerberos ticket that Microsoft Entra ID can validate, eliminating the need for re-authentication.

Exam trap

The trap here is that candidates often confuse Pass-through Authentication (PTA) with Seamless SSO, thinking PTA alone provides the same credential-free experience, but PTA only handles password validation without the automatic ticket-based sign-on that Seamless SSO provides.

How to eliminate wrong answers

Option B (Pass-through Authentication) is wrong because it validates passwords directly against on-premises Active Directory without using password hashes, and while it can also be combined with Seamless SSO, the question specifically asks for a feature to add to PHS to avoid credential prompts, not a replacement for PHS. Option C (Azure AD Connect Health) is wrong because it is a monitoring and diagnostics tool for the synchronization infrastructure, not an authentication feature that provides single sign-on. Option D (Conditional Access) is wrong because it is a policy-based access control mechanism that enforces conditions like device compliance or location, but it does not eliminate the need for users to re-enter credentials; it only controls access after authentication.

28
MCQmedium

A user reports that they are unable to access a file in SharePoint Online. You check the audit log and see that the file was quarantined by Microsoft Defender for Office 365. What is the most likely reason?

A.The file was overwritten by a previous version.
B.The file was detected as malware by Safe Attachments.
C.The file has a retention policy that moved it to the Preservation Hold library.
D.The file was labeled as highly confidential by Microsoft Purview Information Protection.
E.The file contains sensitive information and triggered a Data Loss Prevention (DLP) policy.
AnswerB

Safe Attachments detonates email attachments in a sandbox before delivery, and files found malicious are quarantined. Since the stem confirms Microsoft Defender for Office 365 quarantined the SharePoint file, malware detection by Safe Attachments is the mechanism that satisfies this constraint.

Why this answer

Microsoft Defender for Office 365 uses Safe Attachments to detect and quarantine malicious files in SharePoint Online. Option A is wrong because overwriting by a previous version does not trigger quarantine. Option C is wrong because retention policies move files to Preservation Hold library, not quarantine.

Option D is wrong because sensitivity labels classify files but do not quarantine them. Option E is wrong because DLP policies block sharing or apply protections, but do not quarantine files.

29
MCQmedium

An organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They want to create a policy that blocks users from pasting credit card numbers into web forms in Microsoft Edge. Which type of DLP policy should they configure?

A.Endpoint DLP
B.Exchange DLP
C.SharePoint DLP
D.Teams DLP
AnswerA

Endpoint DLP is the correct selection because it monitors Windows and macOS devices and can inspect user activities such as copying sensitive content to the clipboard. When a user attempts to paste that data into a web form, Endpoint DLP in Microsoft Edge or another supported Chromium-based browser can evaluate the policy condition and block the paste action. The capability relies on the Microsoft Purview endpoint agent being onboarded on the device, and it is the only option that controls clipboard operations at the endpoint itself.

Why this answer

Endpoint DLP is correct because it monitors and controls activities on Windows 10/11 and macOS endpoints, including the ability to block pasting sensitive data like credit card numbers into web forms in Microsoft Edge. This policy extends DLP protection to unmanaged browsers and specific user actions, such as paste, clipboard, and print, which are not covered by cloud-based DLP policies.

Exam trap

The trap here is that candidates often assume all DLP policies are cloud-based and overlook that only Endpoint DLP can enforce restrictions on local user actions like pasting into web forms, confusing it with Exchange or SharePoint DLP which only inspect data at rest or in transit within Microsoft 365 services.

How to eliminate wrong answers

Option B (Exchange DLP) is wrong because it only applies to email messages in transit or at rest in Exchange Online, not to web form pasting in Edge. Option C (SharePoint DLP) is wrong because it protects documents stored in SharePoint Online and OneDrive for Business, not user actions in a browser. Option D (Teams DLP) is wrong because it covers messages and files in Microsoft Teams chats and channels, not web form interactions in Edge.

30
MCQhard

You are configuring Microsoft Purview Information Protection for your tenant. You need to ensure that documents containing credit card numbers are automatically labeled as 'Highly Confidential' and encrypted. Which two components must you configure?

A.A data loss prevention (DLP) policy.
B.A sensitive info type for credit card numbers.
C.An auto-labeling policy for sensitivity labels.
D.A retention label.
AnswerB, C

A sensitive info type detects credit card numbers using pattern matching and validation, supplying the condition an auto-labelling policy needs. Without it, Microsoft Purview cannot identify the content to classify, so the label would never be applied automatically.

Why this answer

To automatically label and encrypt documents containing credit card numbers, you need a sensitive info type that detects credit card numbers and an auto-labeling policy for sensitivity labels that applies the 'Highly Confidential' label with encryption. The sensitive info type defines what to look for, and the auto-labeling policy defines the label to apply and the conditions.

Exam trap

MS-102 often tests the confusion between DLP policies and auto-labeling policies — candidates must remember that DLP enforces actions like block or warn, while auto-labeling applies sensitivity labels with encryption.

How to eliminate wrong answers

Option A is wrong because a DLP policy can block or warn on sensitive content but does not automatically apply sensitivity labels with encryption — that is the role of auto-labeling policies. Option D is wrong because a retention label governs how long content is kept or deleted, not how it is classified or encrypted.

31
MCQeasy

You run the above KQL query in Microsoft Defender XDR Advanced Hunting. The query returns no results. What is the most likely reason?

A.The EmailDirection filter should be 'Outbound'.
B.No inbound emails were blocked in the last 30 days.
C.The time range should be 7 days instead of 30 days.
D.The column name SenderDomain does not exist in EmailEvents.
AnswerD

EmailEvents in Microsoft 365 Defender Advanced Hunting does not contain a column named SenderDomain; the domain can be accessed through SenderMailFromDomain (envelope domain) or SenderFromDomain (display domain). Because the query references an invalid schema field, the entire query fails with a recognized column not found error before any rows can be processed. Using the correct domain column would allow the hunt to run.

Why this answer

The most likely reason is that the column name 'SenderDomain' does not exist in the EmailEvents table. In Microsoft Defender XDR Advanced Hunting, the EmailEvents table contains columns like 'SenderFromDomain' or 'SenderMailFromDomain', but not 'SenderDomain'. Therefore, the query would fail to return results because of an invalid column reference.

Exam trap

MS-102 often tests knowledge of the exact column names in Advanced Hunting tables, and candidates may assume a column exists based on common sense rather than verifying the schema.

How to eliminate wrong answers

Option A is wrong because the EmailDirection filter should be 'Inbound' for inbound emails; changing to 'Outbound' would not fix the issue if the query is about inbound emails. Option B is wrong because if no inbound emails were blocked, the query would return no results, but that is a possible reason, not the most likely; the question implies the query itself is flawed. Option C is wrong because the time range of 30 days is valid and would not cause no results unless there were no events, but again, the column name error is more fundamental.

32
MCQeasy

Your organization uses Microsoft Defender for Endpoint (MDE). You need to configure an automated investigation and response (AIR) capability that will automatically remediate a confirmed malware infection on endpoints. Which action should you enable?

A.Run antivirus scan
B.Notify users via email
C.Automatically resolve alerts
D.Isolate device
AnswerC

Enabling the 'Automatically resolve alerts' option instructs Defender for Endpoint's automated investigation engine to execute appropriate remediation actions and then close the alert when the investigation reaches a conclusion. This setting is the key to connecting determined threat severity with response steps, allowing alert incidents to be resolved without manual triage. It ensures that if remediation succeeds, the alert is automatically marked as resolved.

Why this answer

Enabling 'Automatically resolve alerts' in Microsoft Defender for Endpoint's automated investigation and response (AIR) capabilities allows the system to automatically remediate confirmed malware infections by resolving the alert and applying the appropriate remediation actions (e.g., quarantining files, terminating processes) without manual intervention. This setting ensures that once an investigation confirms a threat, the response is executed automatically, aligning with the requirement for automated remediation.

Exam trap

The trap here is that candidates often confuse enabling a specific remediation action (like 'Isolate device') with configuring the overall automated investigation and response capability, whereas the correct approach is to enable 'Automatically resolve alerts' which then triggers the appropriate remediation actions based on the investigation verdict.

How to eliminate wrong answers

Option A is wrong because 'Run antivirus scan' is a manual or scheduled action, not an automated response that triggers upon a confirmed malware infection; AIR uses pre-configured remediation actions, not on-demand scans. Option B is wrong because 'Notify users via email' is a notification action, not a remediation action; it informs users but does not automatically remediate the infection. Option D is wrong because 'Isolate device' is a specific remediation action that can be part of AIR, but enabling it alone does not configure the automated investigation and response capability; the correct setting to enable automatic remediation is 'Automatically resolve alerts', which then applies actions like isolation based on the investigation verdict.

33
MCQeasy

A company needs to automatically retain all emails sent to or from external partners for 7 years. They also need to ensure that after 7 years, the emails are permanently deleted. What should you configure in Microsoft Purview?

A.Create a retention label with a retention period of 7 years and publish it to all users.
B.Create a retention policy for Exchange email with a retention period of 7 years, followed by deletion.
C.Create an eDiscovery hold for all external partner communications.
D.Create a data loss prevention (DLP) policy to block deletion of emails after 7 years.
AnswerB

A retention policy scoped to Exchange mailboxes applies a seven-year retention period then deletes items, satisfying both the retain and permanent-deletion requirements. Retention policies act at workload level, covering all external-partner correspondence without per-item configuration.

Why this answer

A retention policy in Microsoft Purview can be scoped to Exchange email and configured with a 7-year retention period followed by permanent deletion. This automatically applies to all mailboxes and meets both the retain and delete requirements without user action.

Exam trap

The trap is confusing retention labels (manual/auto-applied per item) with retention policies (automatic, workload-wide); the requirement for 'all emails' points to a policy, not a label.

How to eliminate wrong answers

Option A is wrong because a retention label published to users requires manual or auto-labeling and does not guarantee automatic application to all emails; it is better for content that needs classification. Option C is wrong because an eDiscovery hold preserves content indefinitely for legal purposes and does not delete after 7 years. Option D is wrong because a DLP policy prevents sharing of sensitive data; it does not manage retention or deletion lifecycles.

34
MCQmedium

A company wants to display a custom help desk phone number and email on the Microsoft 365 sign-in page so that users can contact support easily. Which area of the Microsoft 365 admin center should the administrator use to configure this?

A.Settings > Org settings > Security & privacy
B.Settings > Org settings > Organization profile
C.Billing > Licenses
D.Health > Service Health
AnswerB

The correct path is Settings > Org settings > Organization profile, which contains a 'Custom branding' tab (or 'Sign-in and branding' section) where administrators can configure the sign-in page's logo, text, and support information. Under 'Custom branding', you can specify a support email address, phone number, and support URL that will be shown to users when they access the sign-in page. This is the only location in the Microsoft 365 admin center that maps directly to the help desk contact info on the sign-in page.

Why this answer

The custom help desk contact information (phone number and email) for the Microsoft 365 sign-in page is configured under Settings > Org settings > Organization profile, specifically in the 'Custom branding' section. This setting allows administrators to add custom support contact details that appear on the sign-in page, enhancing user self-service and support accessibility.

Exam trap

The trap here is that candidates often confuse the 'Security & privacy' settings (Option A) with branding customization, mistakenly thinking that support contact details are a security-related configuration rather than a branding and user experience setting.

How to eliminate wrong answers

Option A is wrong because Settings > Org settings > Security & privacy is used for configuring security policies, data loss prevention, and privacy-related settings, not for customizing the sign-in page branding or support contact information. Option C is wrong because Billing > Licenses is used to manage user licenses, subscriptions, and billing details, not for tenant-wide branding or support contact configuration. Option D is wrong because Health > Service Health provides real-time service status and incident information, but does not allow customization of the sign-in page or support contact details.

35
MCQmedium

A user reports that they cannot access Microsoft Teams from their mobile device. Other Microsoft 365 services work fine. You verify that the device is compliant with Intune policies. What is the most likely cause?

A.The user's authentication method is not registered for Microsoft Entra ID
B.The Microsoft Teams service is degraded
C.A Conditional Access policy requires an approved client app for Teams
D.The device is not enrolled in Microsoft Intune
AnswerC

A Conditional Access policy requires an approved client app for Teams. If the policy is configured under Conditional Access > Grant > 'Require approved client app' for the Microsoft Teams cloud app, access is allowed only when the requesting app is in the approved list and is protected by an Intune app protection policy (APP). The user is likely using a non-approved client (e.g., a web browser or a third-party Teams client) or an app that has not received the required APP policy, so the Conditional Access engine blocks the session even though sign-in succeeded. This is an app-level access control, which exactly matches the symptom of a single user (if other users are on compliant clients) or a device-specific gap.

Why this answer

A Conditional Access policy requiring an approved client app for Microsoft Teams would block access from a mobile device even if the device is Intune-compliant, as the policy specifically checks for the use of an approved app (e.g., the official Microsoft Teams app) rather than just device compliance. Since the user can access other Microsoft 365 services, the issue is isolated to Teams, and the device compliance status rules out broader device-level blocks.

Exam trap

The trap here is that candidates assume device compliance alone guarantees access, overlooking that Conditional Access policies can impose app-level requirements that are separate from device health checks.

How to eliminate wrong answers

Option A is wrong because authentication method registration for Microsoft Entra ID affects sign-in capabilities across all services, not just Teams, and the user can access other Microsoft 365 services, indicating authentication is functional. Option B is wrong because a degraded Microsoft Teams service would impact all users and devices, not just a single user on a mobile device, and the user can access other services, ruling out a widespread service issue. Option D is wrong because the device is explicitly stated to be compliant with Intune policies, which implies it is enrolled in Microsoft Intune; non-enrollment would prevent compliance evaluation entirely.

36
MCQmedium

Your organization uses Microsoft Defender for Identity. You need to configure a honeytoken account to detect attackers trying to use the account. In which location should you place the honeytoken account?

A.A domain user account with no privileges
B.A service account with high privileges
C.A non-existent account alias in AD
D.A guest account
AnswerA

A domain user account with no privileges is the correct honeytoken because Microsoft Defender for Identity treats any authentication attempt using this account as suspicious. Since the account is a real Active Directory object, MDI can monitor and alert on its activity, and because it lacks any privileged group memberships or legitimate permissions, there is no valid reason for it to authenticate to any resource. This ensures that any authentication event involving the account is a high-confidence indicator of attacker activity, minimizing false positives while maximizing detection value.

Why this answer

A honeytoken account in Microsoft Defender for Identity is designed to lure attackers by appearing as a real, low-privilege account that no legitimate user should ever authenticate with. Placing it as a domain user account with no privileges ensures that any authentication attempt using its credentials is suspicious and triggers an alert, because no legitimate activity should involve this account. This allows Defender for Identity to detect lateral movement or credential theft attempts without risking exposure of sensitive resources.

Exam trap

The trap here is that candidates assume a honeytoken must have high privileges to be attractive to attackers, but Microsoft Defender for Identity specifically requires a low-privilege account that no legitimate user would ever use, so any authentication is automatically suspicious.

How to eliminate wrong answers

Option B is wrong because a service account with high privileges would be a legitimate target for attackers, and using it as a honeytoken could result in real privilege escalation if the account is compromised, defeating the purpose of a decoy. Option C is wrong because a non-existent account alias in AD cannot be used as a honeytoken; Defender for Identity requires an actual user object in Active Directory to monitor for authentication attempts. Option D is wrong because a guest account is typically disabled or has known usage patterns, and using it as a honeytoken would generate false positives from legitimate guest access or automated processes, reducing detection accuracy.

37
MCQhard

A security administrator needs to block outbound network connections from a compromised Windows device to command-and-control servers. The solution must work at the network layer and be centrally managed via Microsoft 365 Defender. Which feature should the administrator enable?

A.Network Protection
B.Attack Surface Reduction rules
C.Session control in Defender for Cloud Apps
D.Windows Firewall with Advanced Security
AnswerA

Network Protection in Microsoft Defender for Endpoint explicitly blocks outbound connections to malicious IP addresses, domains, and URLs using the Windows Filtering Platform. Unlike a static firewall rule, it dynamically enforces cloud-sourced threat intelligence, cutting off command-and-control traffic from a compromised device in real time. It is centrally configured and monitored through Microsoft 365 Defender, making it the correct tool for this network-layer containment scenario.

Why this answer

Network Protection in Microsoft Defender for Endpoint blocks outbound connections to command-and-control (C2) servers at the network layer by inspecting traffic using the Windows Filtering Platform (WFP). It is centrally managed via Microsoft 365 Defender policies and does not require per-device firewall rule configuration, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates confuse 'network layer blocking' with Windows Firewall, but the question specifically requires a solution centrally managed via Microsoft 365 Defender, which Network Protection fulfills through the Defender for Endpoint security configuration.

How to eliminate wrong answers

Option B is wrong because Attack Surface Reduction (ASR) rules focus on blocking file-based and script-based attack techniques (e.g., Office macro execution, credential theft from LSASS), not network-layer outbound connections to C2 servers. Option C is wrong because Session control in Defender for Cloud Apps operates at the application layer (HTTP/S) via reverse proxy, not the network layer, and is designed for controlling access to cloud apps, not blocking C2 traffic from a compromised device. Option D is wrong because Windows Firewall with Advanced Security can block outbound connections but is not centrally managed via Microsoft 365 Defender; it requires Group Policy or PowerShell for centralized management, and it lacks the threat intelligence integration that Network Protection provides for dynamic C2 blocking.

38
Multi-Selecteasy

You are configuring Microsoft 365 tenant-to-tenant migration. Which THREE tasks must be completed before migrating users?

Select 3 answers
A.Change MX records to point to the target tenant
B.Obtain tenant consent for data migration (e.g., via admin consent)
C.Delete source tenant user mailboxes
D.Verify domain ownership in the target tenant
E.Set up directory synchronization between tenants (if needed)
AnswersB, D, E

Before commencing a tenant-to-tenant migration, the migration application (often a third-party tool) requires explicit authorisation to access user data within both the source and target Microsoft Entra ID tenants. This authorisation is typically granted through admin consent, where an administrator approves the application's requested API permissions to read and write user data, mailboxes, and OneDrive files. Without this consent, the migration service cannot legally or technically access the necessary resources to facilitate the transfer of user identities and data.

Why this answer

Option B is correct because tenant-to-tenant migrations require explicit authorization between the source and target tenants, typically granted through an admin consent URL that creates an enterprise application/service principal in the source tenant so the migration tool can read and write data. Option D is correct because you must add and verify the source domain (via a TXT record) in the target Microsoft 365 tenant before you can pre-stage or map users, mailboxes, and domains during migration. Option E is correct because directory synchronization (for example, using Microsoft Entra Connect or cross-tenant synchronization/Identity Manager) is needed to establish matching user identities and mail-enabled objects between tenants so migrated users retain proper object references.

Option A is not required before migrating users; MX record changes are part of the final cutover and should occur only after mailboxes and mail flow are ready, otherwise mail delivery breaks. Option C is wrong because deleting source mailboxes before migration would destroy the data being migrated; source mailboxes must remain intact until the migration and cutover are complete.

Exam trap

The trap here is that candidates confuse the order of operations, thinking MX record changes (Option A) must happen early, when in fact they are a cutover step performed after migration is complete to avoid email disruption.

39
Multi-Selecteasy

Your organization uses Microsoft Entra ID and wants to implement a passwordless authentication strategy. Which TWO authentication methods are considered passwordless by Microsoft? (Choose two.)

Select 2 answers
A.Windows Hello for Business
B.Microsoft Authenticator with notification
C.Password Hash Synchronization
D.FIDO2 security keys
E.SMS-based one-time passcode
AnswersA, D

Windows Hello for Business is a passwordless sign-in method built into Windows devices that uses biometrics or a PIN tied to the user's device through an asymmetric key pair. The private key is protected by the TPM and never leaves the device, while the public key is registered in Microsoft Entra ID. This satisfies passwordless authentication because no shared secret is transmitted over the network, and it supports both cloud and hybrid deployments.

Why this answer

Windows Hello for Business is a passwordless authentication method that uses biometric or PIN-based credentials tied to a user's device, leveraging asymmetric key pairs to authenticate against Microsoft Entra ID without transmitting a password. It satisfies Microsoft's definition of passwordless because the private key never leaves the device, and authentication is performed via a cryptographic challenge-response protocol.

Exam trap

The trap here is that Microsoft Authenticator with notification is often marketed as 'passwordless' in casual contexts, but Microsoft's official documentation strictly classifies it as a multi-factor authentication method, not a passwordless one, because it still requires a password as the first factor.

40
Multi-Selecteasy

You are a security analyst. You need to investigate a potential malware outbreak on a device using Microsoft Defender XDR. Which three data sources can you include in an advanced hunting query to gather relevant information? (Choose three.)

Select 3 answers
A.CloudAppEvents
B.DeviceFileEvents
C.EmailAttachmentInfo
D.DeviceNetworkEvents
E.DeviceProcessEvents
AnswersB, D, E

DeviceFileEvents records file creation, modification and deletion activity on endpoints, so it surfaces the file writes and drops that malware typically performs. Including it in the advanced hunting query satisfies the requirement to gather device-level file telemetry alongside the other chosen sources.

Why this answer

DeviceFileEvents (B) is correct because it records file creation, modification, and other file-system activity on the endpoint, which is essential for tracing malware dropped or modified files during an outbreak. DeviceNetworkEvents (D) is correct because it captures network connections and related telemetry, allowing you to identify command-and-control traffic, lateral movement, or data exfiltration tied to the malware. DeviceProcessEvents (E) is correct because it logs process creation and execution details, letting you trace malicious process trees, parent-child relationships, and command lines used by the malware.

CloudAppEvents (A) is not among the marked answers because it covers cloud app and SaaS activity rather than endpoint malware artifacts, and EmailAttachmentInfo (C) is not marked because it concerns email attachment metadata, which is relevant to phishing delivery but not to the endpoint-focused advanced hunting sources selected here.

Exam trap

MS-102 often tests the distinction between device-centric and cloud/email-centric data sources — candidates may incorrectly include CloudAppEvents or EmailAttachmentInfo, which are not device-focused, when asked about malware on a device.

41
MCQmedium

You are a Microsoft 365 administrator. A user reports that they received a Microsoft Teams message from an external user containing a link to a malicious website. The user clicked the link but did not enter any credentials. You need to prevent similar incidents in the future. What should you configure?

A.Configure a Teams messaging policy to block all messages from external users.
B.Enable Safe Attachments for SharePoint, OneDrive, and Microsoft Teams.
C.Enable Safe Links for Microsoft Teams in Defender for Office 365.
D.Configure an anti-phishing policy to protect against impersonation in Teams.
AnswerC

Safe Links for Microsoft Teams rewrites and detonates URLs at click time, blocking malicious destinations even after delivery. This satisfies the stem's requirement to prevent future incidents, since the threat arrived via Teams chat rather than email, where Safe Links policies for Teams specifically apply.

Why this answer

Enabling Safe Links for Microsoft Teams in Defender for Office 365 provides time-of-click protection for links shared in Teams. Option A is wrong because blocking all external messages would hinder collaboration. Option B is wrong because Safe Attachments scans files, not links.

Option D is wrong because anti-phishing policies protect against impersonation, not malicious links.

42
MCQhard

The exhibit shows the output of a PowerShell command for a user. The user reports that they cannot access Microsoft Teams, although they have an E3 license (ENTERPRISEPACK). What is the most likely cause?

A.The Teams service plan is disabled in the user's license.
B.The user's license is suspended.
C.The user's license has expired.
D.The user does not have a license assigned.
AnswerA

The PowerShell output, such as from `Get-MsolUser -LicenseDetails`, would display a ServicePlan entry for Teams with a `ProvisioningStatus` of `Disabled` or a `CapabilityStatus` of `Disabled`. This indicates the Teams service plan is present in the user's assigned license but has been explicitly turned off, so the user is licensed but cannot access Teams. The `IsLicensed` property remains True because other service plans in the same license, like Exchange Online or SharePoint Online, are still active.

Why this answer

The PowerShell output shows the user has an E3 license (ENTERPRISEPACK) assigned, but the Teams service plan is disabled. Even with an active E3 license, if the Teams service plan is explicitly turned off in the license assignment, the user cannot access Microsoft Teams. This is a common configuration where an admin disables specific service plans to control feature access.

Exam trap

The trap here is that candidates assume an assigned E3 license grants access to all included services by default, overlooking that individual service plans can be disabled within the license, which is a common configuration tested in MS-102.

How to eliminate wrong answers

Option B is wrong because a suspended license would typically show a status of 'Suspended' or 'Disabled' in the output, and the user would lose access to all licensed services, not just Teams. Option C is wrong because an expired license would also affect all services under that license, and the output would likely show an expiration date or a 'Disabled' status; the E3 license shown is still active. Option D is wrong because the output clearly shows the user has an ENTERPRISEPACK license assigned, so they do have a license.

43
MCQeasy

You are a Microsoft 365 administrator. Users report that they cannot access Microsoft Teams. You check the Microsoft 365 admin center and see that the service health for Microsoft Teams shows a 'Service degradation' incident. What is the most appropriate initial action?

A.Contact the Microsoft regional escalation engineer immediately.
B.Open a support request with Microsoft to report the outage.
C.Review the incident details in the service health dashboard for an estimated resolution time and workaround.
D.Restart the Microsoft Teams service on all client machines.
AnswerC

The Service Health Dashboard is the designated place to see live incident status, the affected workload, the problem statement, the estimated time for restoration, and any Microsoft-issued workaround. By reviewing the incident details, you can quickly correlate user reports with a known root cause and then set accurate expectations with your organization. The dashboard also provides an incident history timeline and the option to get email alerts, making it the best evidence-based first action.

Why this answer

The most appropriate initial action when a service degradation incident is already visible in the Microsoft 365 admin center is to review the incident details in the service health dashboard. This provides the estimated resolution time, current status, and any available workarounds published by Microsoft, allowing you to inform users and mitigate impact without immediately escalating or opening a support request.

Exam trap

The trap here is that candidates assume a service degradation requires immediate escalation or a support ticket, but the correct first step is to check the service health dashboard for existing incident details and workarounds before taking any further action.

How to eliminate wrong answers

Option A is wrong because contacting a Microsoft regional escalation engineer is a premature escalation step; this should only be done after reviewing the incident details and if the issue is critical and not being addressed. Option B is wrong because opening a support request to report the outage is redundant when Microsoft has already acknowledged the incident in the service health dashboard; support requests are for issues not yet recognized or requiring tenant-specific troubleshooting. Option D is wrong because restarting the Microsoft Teams service on client machines is a client-side action that cannot resolve a service-wide degradation incident that originates from Microsoft's infrastructure.

44
MCQeasy

An administrator is setting up a new Microsoft 365 tenant and has added the custom domain 'contoso.com'. The domain status shows 'Pending verification'. Which type of DNS record must the administrator add to the public DNS zone to complete domain ownership verification?

A.MX record
B.TXT record
C.CNAME record
D.SPF record
AnswerB

A TXT record proves ownership without affecting mail flow, unlike MX records which route email. Microsoft Entra ID reads the unique value at the zone apex, so adding it to the public DNS zone resolves the 'Pending verification' status and confirms the tenant controls contoso.com.

Why this answer

To verify domain ownership in Microsoft 365, you must add a TXT record containing the unique verification string provided by the Microsoft 365 admin center to the public DNS zone. The TXT record proves you control the domain by allowing Microsoft to query the DNS and match the value. This is the standard method defined by RFC 1035 for domain validation.

Exam trap

The trap here is that candidates often confuse the TXT record used for domain verification with the SPF record, which is also a TXT record but serves a completely different purpose, leading them to select SPF instead of the generic TXT record option.

How to eliminate wrong answers

Option A is wrong because an MX record specifies the mail exchange server for the domain and is not used for domain ownership verification; it would be added later for mail routing. Option C is wrong because a CNAME record maps an alias to a canonical name and is not used for verification; it is typically used for services like autodiscover. Option D is wrong because an SPF record is a TXT record that specifies authorized mail servers to prevent spoofing, but it is not the specific record type used for domain verification; the verification requires a unique TXT record with a specific value, not an SPF policy.

45
Multi-Selecteasy

Your organization is deploying Microsoft 365 Copilot. You need to ensure that data security is maintained. Which THREE actions should you take?

Select 3 answers
A.Disable Microsoft 365 Copilot for all users.
B.Block all external sharing for SharePoint and OneDrive.
C.Enable audit logging in Microsoft 365.
D.Configure data loss prevention (DLP) policies.
E.Create sensitivity labels to classify and protect data.
AnswersC, D, E

Enable audit logging in Microsoft 365 so that Copilot user prompts and responses, along with related file access events, are recorded in the unified audit log. This telemetry is essential for security teams to detect abnormal Copilot usage, investigate data exfiltration attempts, and produce evidence for compliance. Without audit logging, administrators lack the visibility needed to confirm whether Copilot is being used appropriately.

Why this answer

Enabling audit logging in Microsoft 365 is essential for tracking user interactions with Microsoft 365 Copilot, including prompts, responses, and data access events. This provides a forensic trail to detect unauthorized data exposure or misuse, which is a foundational requirement for maintaining data security in AI-powered workloads.

Exam trap

The trap here is that candidates often assume blocking external sharing (Option B) is a primary security control for Copilot, when in fact Copilot's data security risks are more about internal data leakage through AI processing, which requires audit logging, DLP, and sensitivity labels to mitigate.

46
MCQhard

A security analyst needs to identify the specific process (filename) that initiated a network connection from a device to a known malicious IP address over the last 24 hours. Which advanced hunting table in Microsoft Defender XDR provides the necessary data including the initiating process filename and the remote IP address?

A.DeviceNetworkEvents
B.DeviceProcessEvents
C.DeviceEvents
D.DeviceRegistryEvents
AnswerA

DeviceNetworkEvents is the Advanced Hunting table that records network connections observed on a device, with dedicated columns such as RemoteIP, RemotePort, LocalIP, LocalPort, Protocol, and the initiating process details (InitiatingProcessId, InitiatingProcessFileName). To identify the specific process that made a given network connection, an analyst can query this table and filter by the remote endpoint or timestamp, then read the initiating process information directly. This is the only table in the Advanced Hunting schema purpose-built for correlating process activity with network endpoints.

Why this answer

DeviceNetworkEvents is the correct table because it specifically captures network connection events, including the initiating process filename (InitiatingProcessFileName) and the remote IP address (RemoteIP). This table is designed for hunting network-related activities, such as connections to known malicious IPs, within Microsoft Defender XDR's advanced hunting schema.

Exam trap

The trap here is that candidates often confuse DeviceProcessEvents (which shows process creation) with network connection data, mistakenly thinking that process events include network details, but DeviceProcessEvents lacks the RemoteIP field entirely.

How to eliminate wrong answers

Option B (DeviceProcessEvents) is wrong because it focuses on process creation events (e.g., file execution, command-line arguments) and does not include network-specific fields like RemoteIP or remote port. Option C (DeviceEvents) is wrong because it aggregates various system-level events (e.g., file creation, registry modifications) but lacks the dedicated network connection fields required to identify the initiating process filename and remote IP address. Option D (DeviceRegistryEvents) is wrong because it only captures registry modification events (e.g., key changes, value writes) and has no relevance to network connections or IP addresses.

47
Multi-Selecthard

Which THREE factors are considered when Microsoft Entra ID evaluates a conditional access policy?

Select 3 answers
A.User or group membership
B.Mailbox size
C.User's department attribute in Microsoft Entra ID
D.Location (IP range or country)
E.Device platform (e.g., Windows, iOS)
AnswersA, D, E

User or group membership is the fundamental assignment in a Microsoft Entra Conditional Access policy, defining the exact identities that will be evaluated. You can target All users, specific users, or groups, and you should always exclude at least one emergency access account. Group membership can be static or dynamic, with dynamic groups enabling attribute-based inclusion, but the policy condition itself evaluates membership rather than arbitrary directory attributes.

Why this answer

Microsoft Entra ID evaluates conditional access policies based on signals from the user, device, and location. User or group membership (Option A) is a primary signal because policies are typically assigned to specific users or groups to control access. Location (Option D) is evaluated using IP ranges or country codes to enforce restrictions like blocking access from untrusted networks.

Device platform (Option E) allows policies to target specific operating systems (e.g., Windows, iOS) to enforce compliance requirements like requiring Intune enrollment.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID attributes (like department) with actual conditional access conditions, but Microsoft only supports specific signals (user/group, location, device platform, risk, client apps, and sign-in risk) and not arbitrary directory attributes.

48
MCQeasy

Your company uses Microsoft Entra ID and wants to use Microsoft's recommendation to protect against password spray attacks. Which feature should you enable?

A.Smart Lockout
B.Identity Protection
C.Password Hash Synchronization
D.Multifactor Authentication
AnswerA

Smart Lockout in Microsoft Entra ID uses adaptive machine learning to detect and block password spray and brute-force attacks by locking an account after a defined number of failed sign-in attempts. It learns the user's normal sign-in patterns, such as frequently used IP addresses and devices, and adjusts lockout thresholds accordingly, so legitimate users are less likely to be locked out while attackers are effectively denied access. This is precisely the account lockout capability the company needs to prevent attackers from cycling through passwords.

Why this answer

Smart Lockout is Microsoft's recommended feature to protect against password spray attacks because it intelligently locks out bad actors after a threshold of failed attempts while allowing legitimate users to continue. It uses adaptive logic to distinguish between real users and attackers by considering the sign-in pattern and IP address, making it the correct choice for this specific threat.

Exam trap

The trap here is that candidates often confuse Identity Protection (which detects risky sign-ins) with the direct mitigation feature Smart Lockout, or they assume MFA alone is sufficient to stop password spray attacks, when in fact Smart Lockout is the specific Microsoft-recommended control for this attack vector.

How to eliminate wrong answers

Option B (Identity Protection) is wrong because it is a broader risk-detection and remediation service that identifies compromised identities and risky sign-ins, but it does not directly lock out attackers during a password spray attack; it relies on policies like Conditional Access to act on risks. Option C (Password Hash Synchronization) is wrong because it is a synchronization mechanism for password hashes from on-premises AD to Entra ID, not a security feature that mitigates password spray attacks. Option D (Multifactor Authentication) is wrong because while MFA adds a second layer of verification, it does not prevent the initial password spray attempts from being made, and Microsoft recommends Smart Lockout as the primary defense against this brute-force pattern.

49
Multi-Selectmedium

An administrator needs to open a Microsoft 365 support request because all users are experiencing intermittent service outages for Exchange Online. Before contacting support, which two pieces of information should the administrator have ready to ensure efficient troubleshooting? (Choose two.)

Select 2 answers
A.Tenant ID (or Microsoft 365 tenant domain name)
B.Number of affected users
C.Detailed description of the problem and troubleshooting steps attempted
D.Network bandwidth graph from the past 24 hours
AnswersA, C

Tenant ID (or the Microsoft 365 tenant domain name such as contoso.onmicrosoft.com) is the primary key Microsoft Support uses to locate your specific tenancy in their backend systems. It lets support immediately verify service health, tenant-level configurations, and any recent changes or incidents affecting that environment. Without this identifier, they cannot authenticate the tenant context, route the request correctly, or correlate your issue with backend telemetry.

Why this answer

The Tenant ID (or Microsoft 365 tenant domain name) is required by Microsoft Support to uniquely identify your tenant in their systems, enabling them to pull up your service configuration, subscription details, and relevant health data. This identifier is essential for routing the support request to the correct engineering team and for correlating the issue with backend telemetry.

Exam trap

The trap here is that candidates often confuse 'nice-to-have' diagnostic data (like the number of affected users or network graphs) with the mandatory identification and problem description that Microsoft Support requires to initiate a case.

50
MCQeasy

Your organization has a Microsoft 365 E5 subscription. You want to enable Microsoft Defender for Office 365 to protect against malicious attachments in email. Which policy should you configure?

A.Anti-phishing policy
B.Anti-malware policy
C.Safe Attachments policy
D.Safe Links policy
AnswerC

Safe Attachments policy is the correct answer because it routes each email attachment to an isolated Microsoft detonation chamber, where the file is opened and executed in a virtualized environment to observe its run-time behavior. It can block or replace the attachment if unknown malware or zero-day exploit activity is detected, and it can also redirect the message for admin review. This is the Defender for Office 365 mechanism specifically built to protect against malicious attachments that evade classic signature-based scanning.

Why this answer

Safe Attachments policy is the correct choice because Microsoft Defender for Office 365's Safe Attachments feature specifically protects against malicious attachments in email by detonating them in a virtual sandbox environment before delivery. This policy allows you to configure actions for detected malware, such as blocking, replacing, or dynamically delivering attachments based on threat analysis.

Exam trap

The trap here is that candidates often confuse the basic Anti-malware policy (which uses signature-based detection) with the advanced Safe Attachments policy (which uses sandbox detonation), leading them to select Option B incorrectly.

How to eliminate wrong answers

Option A is wrong because Anti-phishing policy protects against phishing attempts by analyzing sender reputation, impersonation, and spoofing, not by scanning attachments for malware. Option B is wrong because Anti-malware policy provides basic malware protection using the built-in malware engine but does not include the advanced sandboxing and detonation capabilities of Safe Attachments. Option D is wrong because Safe Links policy protects users from malicious URLs in email and Office documents by checking links at time of click, not by scanning attachments.

51
Multi-Selecteasy

Which TWO Microsoft Purview solutions are primarily used for data classification?

Select 2 answers
A.Data Loss Prevention
B.Auto-labeling
C.Communication Compliance
D.Data Lifecycle Management
E.Sensitivity labels
AnswersB, E

Auto-labeling is a primary Purview solution used to classify data by automatically applying sensitivity labels to content. It evaluates files, emails, and other content against sensitive info types, patterns, and conditions, then assigns the appropriate label without manual intervention. This enables consistent, bulk classification across hybrid environments, and it can run in client-side or service-side (server-side) modes to label content before or after it is stored.

Why this answer

Auto-labeling (B) is correct because it is a Microsoft Purview Information Protection capability that automatically applies sensitivity labels to content by scanning it for sensitive information types, trainable classifiers, or exact data match, which is a core data-classification function. Sensitivity labels (E) are also correct because they are the primary mechanism in Microsoft Purview for manually classifying and protecting content by tagging it with a classification (for example, Confidential or Highly Confidential) that can enforce encryption and other protections. Together, sensitivity labels and auto-labeling form the classification backbone of Microsoft Purview Information Protection.

Data Loss Prevention (A) is not primarily a classification tool; it uses classification results to detect and block risky sharing of sensitive data. Communication Compliance (C) focuses on detecting policy violations in communications such as harassment or inappropriate content, not on classifying data. Data Lifecycle Management (D) governs retention and deletion of content rather than classifying it.

Exam trap

MS-102 often tests the distinction between classification and protection solutions, causing candidates to confuse DLP (which enforces) with auto-labeling (which classifies).

52
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) for role activation. They want to require that any activation of the Security Administrator role be approved by a designated group of approvers called 'Security Approvers'. Activations must include a ticket number and expire after 8 hours. Which PIM configuration should the administrator modify?

A.Role settings for Security Administrator
B.Role assignments for Security Administrator
C.Access reviews for Security Administrator
D.Alerts for Security Administrator
AnswerA

In Microsoft Entra PIM (formerly Azure AD PIM), the Role settings blade for a specific role defines the activation policy: it allows you to configure 'Require approval to activate', 'Require justification on activation', 'Require Azure AD MFA', and set the maximum activation duration. These settings are role-specific, so editing the Security Administrator role settings is exactly where you control how that role's eligible members activate privileged access. No other PIM area (assignments, reviews, alerts) modifies these activation requirements.

Why this answer

Azure AD PIM role settings for a specific role, such as Security Administrator, control activation requirements including approval workflow, justification (ticket number), and maximum activation duration. By modifying the role settings, the administrator can require approval from the 'Security Approvers' group, mandate a ticket number, and set an 8-hour expiration.

Exam trap

The trap here is confusing role settings (which control activation policies) with role assignments (which control who can activate), leading candidates to mistakenly choose Option B when the question asks about activation requirements rather than eligibility.

How to eliminate wrong answers

Option B is wrong because role assignments define who is eligible or active for the role, not the activation policies like approval or duration. Option C is wrong because access reviews are periodic attestations of existing assignments, not a mechanism to configure activation requirements. Option D is wrong because alerts in PIM notify about suspicious activities or configuration changes, but do not control activation settings.

53
MCQhard

Your company is deploying Microsoft Copilot for Microsoft 365. You need to ensure that only users who have completed a specific training course can use Copilot. What should you configure?

A.Use Terms of Use to require acceptance of training policy
B.Configure Authentication strengths to require training certificate
C.Create a Conditional Access policy that requires a custom attribute indicating training completion
D.Assign Copilot licenses only to users who completed training
AnswerC

This is correct because Microsoft Entra ID supports custom security attributes that can be assigned to user or resource objects, and Conditional Access policies can evaluate these attributes during sign-in. After training is completed, an administrator can set a custom attribute like 'CopilotTrainingCompleted=TRUE' via Graph API or automated workflow; the CA policy then grants access to the Copilot app only when that attribute is present. This provides a true runtime enforcement tied to the user's current directory state, rather than a static license or a one-time agreement.

Why this answer

A Conditional Access policy can evaluate a custom security attribute assigned to a user or group to enforce access controls. By requiring a custom attribute that indicates training completion, you can block or grant access to Copilot for Microsoft 365 based on that attribute. This approach integrates directly with Microsoft Entra ID's policy engine, allowing granular, attribute-based access control without relying on license assignment or user acceptance.

Exam trap

The trap here is that candidates often confuse license-based assignment (Option D) with attribute-based access control, assuming that simply not assigning a license is sufficient, but Microsoft Copilot for Microsoft 365 can still be accessed via trial or free features if not blocked by a Conditional Access policy; the exam tests your understanding that Conditional Access policies are the correct mechanism for enforcing granular, attribute-driven access restrictions.

How to eliminate wrong answers

Option A is wrong because Terms of Use (ToU) only require a user to accept a policy statement; they do not verify or enforce completion of a specific training course, nor can they evaluate dynamic attributes like training status. Option B is wrong because Authentication strengths control which authentication methods (e.g., FIDO2, certificate-based auth) are allowed during sign-in, not whether a user has completed training; a training certificate is not a standard authentication method and cannot be evaluated by Conditional Access as a condition. Option D is wrong because assigning Copilot licenses only to users who completed training is a manual, administrative approach that does not enforce ongoing compliance; a user could complete training, receive a license, and then later lose the training status without automatic revocation, and it does not integrate with Entra ID's policy engine for real-time enforcement.

54
MCQhard

You are deploying Microsoft 365 for a new subsidiary. The subsidiary has a single domain subsidiary.com. You need to configure a hybrid identity solution with Microsoft Entra ID. The on-premises Active Directory has a single domain and all user accounts are synchronized using Microsoft Entra Connect. You want to ensure that users can sign in to Microsoft 365 using their on-premises credentials without exposing the password hash to Microsoft. What should you do?

A.Configure password hash synchronization.
B.Create cloud-only user accounts and disable on-premises authentication.
C.Implement Active Directory Federation Services (AD FS) with Microsoft Entra ID.
D.Enable pass-through authentication (PTA) with Microsoft Entra Connect.
AnswerD

Pass-through authentication validates passwords directly against on-premises Active Directory via a lightweight agent, so credentials are never stored in Microsoft Entra ID and no password hash is synchronised to the cloud, satisfying the requirement to avoid exposing password hashes to Microsoft.

Why this answer

Pass-through authentication (PTA) allows users to sign in to Microsoft 365 using their on-premises credentials without storing password hashes in Microsoft Entra ID. PTA validates passwords directly against on-premises Active Directory via an agent, ensuring no password hash is exposed to Microsoft, which meets the stated requirement.

Exam trap

The trap here is that candidates often confuse pass-through authentication with password hash synchronization, assuming both expose credentials, but PTA avoids any hash storage while still enabling cloud authentication.

How to eliminate wrong answers

Option A is wrong because password hash synchronization stores a hash of the on-premises password in Microsoft Entra ID, which directly exposes the password hash to Microsoft, violating the requirement. Option B is wrong because creating cloud-only user accounts and disabling on-premises authentication would break the hybrid identity requirement, as users would no longer use their on-premises credentials for sign-in. Option C is wrong because while AD FS also avoids storing password hashes in the cloud, it introduces additional infrastructure complexity and is not the simplest solution; PTA is the recommended choice for this specific scenario where password hash exposure must be avoided without deploying federation servers.

55
MCQmedium

A compliance officer needs to automatically retain emails that contain personally identifiable information (PII) for 10 years and then permanently delete them. Which Microsoft Purview feature should be configured?

A.Auto-apply retention labels based on sensitive information types
B.Data Lifecycle Management retention policy
C.Data classification
D.eDiscovery
AnswerA

Auto-apply retention labels are content-aware and can be configured to trigger whenever a sensitive information type—such as a credit card number, passport number, or other PII—is detected in an email. Once the label is applied, its retention settings enforce the 10-year retention period and, at the end of that period, automatically dispose of the item. This satisfies the requirement to selectively retain emails based on content, not just location or folder.

Why this answer

Auto-apply retention labels based on sensitive information types allow you to automatically classify and retain emails containing PII for a specified period (10 years) and then permanently delete them. This feature uses sensitive information types (e.g., Social Security Number, Credit Card Number) to detect PII and applies a retention label that enforces the retention and deletion actions at the item level, which is required for targeted compliance scenarios.

Exam trap

The trap here is that candidates often confuse Data Lifecycle Management retention policies (which apply broadly to all content in a location) with auto-apply retention labels (which apply only to content matching specific sensitive information types), leading them to incorrectly select option B.

How to eliminate wrong answers

Option B is wrong because Data Lifecycle Management retention policy applies to all content in a location (e.g., entire mailbox or site) and cannot automatically target only emails containing specific sensitive information like PII; it lacks the auto-classification capability based on content inspection. Option C is wrong because Data classification is a discovery and labeling tool that identifies and categorizes data but does not itself enforce retention or deletion actions; it requires a retention label or policy to act on the classification. Option D is wrong because eDiscovery is used for searching and exporting content for legal or investigative purposes, not for automated retention and deletion based on content type.

56
MCQmedium

A compliance officer needs to prevent users from sending emails that contain credit card numbers to external recipients. When a user attempts to send such an email, the action should be blocked and a policy tip should be displayed in Outlook telling them why the email was blocked. Which Microsoft Purview solution should be configured?

A.Data Loss Prevention (DLP) policy
B.Retention label policy
C.Microsoft Purview Information Protection sensitivity label
D.Compliance Manager
AnswerA

A Microsoft Purview Data Loss Prevention policy inspects Exchange email for sensitive information types such as credit card numbers, then enforces a block action for external recipients and surfaces a policy tip in Outlook explaining the block. This directly satisfies the stem's requirement to stop the send and notify the user.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft Purview is designed to detect and block sensitive information, such as credit card numbers, from being sent to external recipients. When configured with a 'Block' action and a policy tip, it prevents the email from being sent and displays a customizable notification in Outlook explaining the reason. This directly meets the compliance officer's requirement to block the email and show a policy tip.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which classify and protect data) with DLP policies (which enforce actions like blocking based on content inspection), leading them to choose Option C because they think labeling alone can block emails.

How to eliminate wrong answers

Option B is wrong because a Retention label policy is used to retain or delete data based on compliance requirements, not to block the transmission of sensitive content in emails. Option C is wrong because a Microsoft Purview Information Protection sensitivity label applies classification and protection (e.g., encryption) to content, but it does not natively block outbound emails containing credit card numbers or display policy tips in Outlook. Option D is wrong because Compliance Manager is a risk assessment and compliance management tool that provides recommendations and tracks compliance posture, not a policy that enforces real-time blocking of sensitive data in email.

57
MCQhard

You are the Microsoft 365 administrator for Contoso Ltd., a company with 500 users. The company uses a hybrid identity with Azure AD Connect. You have a dynamic group named 'SalesGroup' that includes all users with department attribute equal to 'Sales'. Recently, the HR system updated the department for 20 users from 'Sales' to 'Marketing'. The Azure AD Connect sync completed successfully, and the attribute changes are reflected in Azure AD. However, after 48 hours, these users are still members of 'SalesGroup'. You need to ensure that the group membership accurately reflects the department attribute within the next hour. The solution must use minimal administrative effort. What should you do?

A.Remove the users from the group manually
B.Delete and recreate the dynamic group with the same rule
C.Trigger a manual evaluation of the dynamic group in Azure AD
D.Wait another 24 hours for the next automatic evaluation
AnswerC

Triggering a manual evaluation of the dynamic group in Azure AD forces the membership processing engine to run immediately, updating the group's membership in near real time. This is done by selecting the 'Reprocess' option in the Dynamic group rules pane or via Microsoft Graph, which is the recommended resolution when membership is stale and time is critical. It does not change the rule, but it accelerates the evaluation that would otherwise happen on the next automatic cycle.

Why this answer

Azure AD dynamic groups are not automatically re-evaluated immediately after a sync; they rely on a periodic background evaluation process that can take up to 24 hours. By triggering a manual evaluation in the Azure AD admin center or via PowerShell (using the `Invoke-MgGraphRequest` or `Update-MgGroup` cmdlet), you force an immediate recalculation of group membership based on the current attribute values, ensuring the 20 users are removed from SalesGroup within the hour with minimal administrative effort.

Exam trap

The trap here is that candidates assume dynamic groups are evaluated immediately after an attribute sync, but Microsoft deliberately tests the understanding that dynamic group membership evaluation is asynchronous and can take up to 24 hours unless manually triggered.

How to eliminate wrong answers

Option A is wrong because manually removing users defeats the purpose of a dynamic group and requires ongoing administrative effort, which contradicts the 'minimal administrative effort' requirement and does not fix the underlying evaluation delay. Option B is wrong because deleting and recreating the dynamic group would cause temporary loss of the group object, potentially breaking assigned permissions or licenses, and still requires waiting for the new group to be evaluated; it is an unnecessary and disruptive workaround. Option D is wrong because waiting another 24 hours does not meet the requirement to resolve the issue within the next hour, and the automatic evaluation could take up to 24 hours from the last evaluation, not from the sync completion.

58
MCQmedium

A company uses Microsoft Entra ID P2 licenses. The security team wants to require multi-factor authentication (MFA) for all users when accessing any cloud application from networks that are not trusted corporate locations. A group named 'BreakGlass' must be excluded from MFA requirements. Additionally, the company wants to block legacy authentication protocols. Which approach should the administrator use?

A.Create one Conditional Access policy for MFA (targeting all users, excluding BreakGlass, with location condition) and another policy to block legacy authentication (targeting all users, with client apps condition)
B.Create a single Conditional Access policy that grants access only if MFA is performed and block legacy client apps in the same policy
C.Enable Security defaults in Entra ID
D.Use baseline Conditional Access policies
AnswerA

Creating two separate Conditional Access policies allows independent lifecycle management and precise condition targeting. The MFA policy applies to all users except BreakGlass and includes a location condition (e.g., require MFA from untrusted networks), while the legacy authentication policy strictly targets client apps using basic auth via the client apps condition. This separation ensures that changes to one control do not affect the other, simplifying troubleshooting and regulatory reporting, and aligns with Microsoft's recommended best practice for Conditional Access.

Why this answer

It separates the MFA requirement and legacy authentication block into two distinct Conditional Access policies, which is the recommended approach for granular control. The MFA policy targets all users except the BreakGlass group and uses the location condition to require MFA only from untrusted networks. The second policy blocks legacy authentication by targeting all users with the client apps condition set to 'Exchange ActiveSync clients' and 'Other clients', effectively preventing protocols like POP3, IMAP, and SMTP from bypassing modern authentication.

Exam trap

The trap here is that candidates often think a single Conditional Access policy can logically combine a block and a grant control, but Microsoft's policy engine evaluates all conditions and controls together, so a block control overrides any grant control, making it impossible to require MFA while also blocking legacy clients in the same policy without unintended consequences.

How to eliminate wrong answers

Option B is wrong because combining the MFA grant control and the block legacy client apps control in a single policy would cause the policy to evaluate both conditions simultaneously; if a user accesses from a trusted location but uses a legacy client, the policy would still block access, but the MFA requirement would not apply as expected, leading to inconsistent behavior. Option C is wrong because Security defaults enforces MFA for all users, including the BreakGlass group, and does not allow exclusion of specific groups or granular location-based conditions; it also blocks legacy authentication but lacks the flexibility to exclude break-glass accounts. Option D is wrong because baseline Conditional Access policies are deprecated and do not support the exclusion of a BreakGlass group or the precise location-based MFA requirement; they are rigid and cannot be customized to meet the specified requirements.

59
MCQmedium

A company wants to ensure that all new users created in Microsoft 365 are automatically assigned a specific set of licenses based on their department. The company has 200 users across Sales, Marketing, and IT departments. Each department uses different Microsoft 365 license plans. Which approach should the administrator use?

A.A: Create a PowerShell script that runs on a schedule to assign licenses based on department attribute.
B.B: Use group-based licensing and assign each department's users to a security group with the appropriate license.
C.C: Use Azure AD Dynamic Groups to automatically add users to groups based on department, and then assign licenses to those groups.
D.D: Manually assign licenses to each user after creation.
AnswerC

To meet the requirement, combine Azure AD dynamic groups with group-based licensing: define a dynamic membership rule such as "user.department -eq 'Sales'" so Azure AD automatically adds and removes users as their department attribute changes. When a new user is created with the department attribute set, Azure AD evaluates the rule, adds the user to the matching group, and group-based licensing automatically assigns the appropriate license to that user without any manual or scripted intervention. This is a declarative, natively supported solution that scales to thousands of users and works in near real time for new directory objects.

Why this answer

Azure AD Dynamic Groups can automatically add users to groups based on their department attribute (e.g., using a rule like `user.department -eq "Sales"`), and group-based licensing can then assign the appropriate Microsoft 365 license plan to each dynamic group. This ensures that any new user created with the correct department attribute is automatically added to the corresponding group and receives the license without manual intervention or scheduled scripts.

Exam trap

The trap here is that candidates often confuse 'group-based licensing' (which requires groups to be populated) with 'dynamic groups' (which automate group membership), leading them to choose Option B because they think group-based licensing alone is sufficient, but without dynamic groups, the groups must be manually maintained.

How to eliminate wrong answers

Option A is wrong because a scheduled PowerShell script introduces latency (users may not get licenses until the script runs), requires maintenance, and is less reliable than Azure AD's native automatic licensing engine. Option B is wrong because it suggests manually assigning users to security groups, which does not automate the process for new users; group-based licensing requires the groups to be populated automatically (via dynamic groups) to achieve the stated goal. Option D is wrong because manual assignment is not scalable for 200 users and does not meet the requirement of automatic license assignment for new users.

60
MCQmedium

A security analyst has identified a new malware sample with a specific SHA256 hash. The analyst needs to immediately block this file from executing on any managed endpoint across the organization, including prevention of future execution. Which Microsoft Defender for Endpoint capability should the analyst use?

A.Attack surface reduction (ASR) rules
B.Indicators (IoCs) for file hashes
C.Custom detection rules via advanced hunting
D.Microsoft Defender Vulnerability Management
AnswerB

File hash indicators are the correct solution because Microsoft Defender for Endpoint supports creating a file hash indicator with the action 'Block and Remediate,' which prevents the file from running and automatically removes matching files from protected devices. The indicator is honored by both the anti-malware engine and the behavior monitoring layer, so execution is stopped preemptively even before the process starts. This gives an immediate, global block across all onboarded endpoints.

Why this answer

Indicators of Compromise (IoCs) for file hashes in Microsoft Defender for Endpoint allow an analyst to create a block indicator for a specific SHA256 hash. This action immediately prevents the file from executing on any managed endpoint and persists across reboots, effectively blocking future execution attempts. Unlike other capabilities, IoCs provide a direct, hash-based block that is enforced by the Microsoft Defender Antivirus engine at the point of execution.

Exam trap

The trap here is that candidates often confuse ASR rules (which block behaviors) with IoC-based blocking (which blocks specific file hashes), or they assume custom detection rules can directly block execution when they only generate alerts or run limited response actions.

How to eliminate wrong answers

Option A is wrong because Attack Surface Reduction (ASR) rules are behavior-based policies that reduce the attack surface by blocking common malware behaviors (e.g., Office apps creating child processes), not by blocking specific file hashes. Option C is wrong because Custom detection rules via advanced hunting are used to create custom alerts based on query results, but they do not directly block file execution; they only trigger alerts or run response actions that may not be immediate or persistent. Option D is wrong because Microsoft Defender Vulnerability Management focuses on identifying, assessing, and remediating vulnerabilities (e.g., missing patches), not on blocking specific malware file hashes.

61
MCQmedium

Your company has a Microsoft 365 E5 subscription and uses Microsoft Entra ID. You need to configure a conditional access policy that blocks access from devices that are not compliant with your organization's device compliance policies, as defined by Microsoft Intune. Which assignment should you configure in the policy?

A.Grant > Require hybrid Azure AD joined device
B.Grant > Require multifactor authentication
C.Grant > Require device to be marked as compliant
D.Grant > Require approved client app
AnswerC

Requiring the device to be marked as compliant evaluates the actual compliance status reported by Intune. This ensures the device meets organizational policies, such as OS version, disk encryption, and threat level. It is the precise control for enforcing device compliance in Conditional Access.

Why this answer

The 'Require device to be marked as compliant' grant control in a Conditional Access policy enforces access decisions based on the compliance status reported by Microsoft Intune. When a device is marked as non-compliant by Intune (e.g., missing required updates or having an unapproved app), the policy blocks access. This directly meets the requirement to block devices that do not meet the organization's device compliance policies.

Exam trap

The trap here is that candidates often confuse 'device compliance' with 'hybrid Azure AD join' or 'MFA', assuming any of those controls enforce device health, but only the 'Require device to be marked as compliant' grant directly uses Intune's compliance evaluation.

How to eliminate wrong answers

Option A is wrong because 'Require hybrid Azure AD joined device' controls access based on domain join status, not Intune compliance; a hybrid joined device could still be non-compliant with Intune policies. Option B is wrong because 'Require multifactor authentication' addresses identity verification, not device health or compliance; a non-compliant device can still satisfy MFA. Option D is wrong because 'Require approved client app' restricts access to specific applications (e.g., Outlook mobile) but does not evaluate the device's compliance with Intune policies.

62
MCQhard

The security team at Contoso wants to require that any activation of the Global Administrator role in Azure AD Privileged Identity Management (PIM) must be approved by members of a security group named 'GA-Approvers'. Activations must require a business justification and expire after 4 hours. Which PIM configuration should the administrator modify to achieve this?

A.The role settings for Global Administrator, on the Activation tab
B.The role settings for Global Administrator, on the Assignment tab
C.The role settings for Global Administrator, on the Notification tab
D.The role settings for Global Administrator, on the Alert tab
AnswerA

The Activation tab within Global Administrator role settings holds the controls for requiring approval, enforcing business justification, and setting activation duration. Configuring these there satisfies all three stem constraints: GA-Approvers approval, justification, and four-hour expiry.

Why this answer

The Activation tab in the role settings for Global Administrator allows you to configure approval requirements, justification, and maximum activation duration. By setting 'Require approval to activate' to 'Enabled' and specifying the 'GA-Approvers' group as the approver, requiring a business justification, and setting the activation maximum duration to 4 hours, you meet all the stated requirements.

Exam trap

The trap here is that candidates often confuse the Assignment tab (which deals with role eligibility duration and permanent assignment) with the Activation tab (which controls the activation process including approval, justification, and maximum activation time).

How to eliminate wrong answers

Option B is wrong because the Assignment tab controls settings for eligible and active assignments (such as assignment duration and whether permanent assignment is allowed), not the activation process. Option C is wrong because the Notification tab configures email alerts for role activations, assignments, or alerts, but does not control approval, justification, or duration settings. Option D is wrong because the Alert tab manages security alerts and risk-based policies, not the activation approval workflow or duration.

63
MCQmedium

A security administrator wants to configure Microsoft Defender for Cloud Apps to block downloads of sensitive files from Salesforce to unmanaged devices in real time. Which Defender for Cloud Apps component must be configured?

A.Cloud Discovery
B.App Connectors
C.Conditional Access App Control
D.Activity policies
AnswerC

Conditional Access App Control proxies sessions through Defender for Cloud Apps, enabling real-time inline enforcement such as blocking downloads to unmanaged devices. Session policies alone cannot block in real time, so this component satisfies the real-time blocking constraint for Salesforce.

Why this answer

Conditional Access App Control (CAAC) is the correct component because it enables real-time session-level monitoring and control of user activities in SaaS apps like Salesforce. By integrating with Azure AD Conditional Access, CAAC can enforce policies to block downloads of sensitive files to unmanaged devices at the moment of access, using reverse proxy architecture to inspect and intervene in the traffic.

Exam trap

The trap here is that candidates often confuse App Connectors (API-based governance) with Conditional Access App Control (proxy-based real-time control), assuming both can block downloads in real time, but only the reverse proxy can intercept and block actions during the session.

How to eliminate wrong answers

Option A is wrong because Cloud Discovery is used to identify shadow IT and analyze traffic logs to discover cloud apps in use, not to enforce real-time blocking policies on managed SaaS apps. Option B is wrong because App Connectors are used for API-based integration to scan and govern data at rest (e.g., applying DLP labels or quarantine), not for real-time session control of downloads. Option D is wrong because Activity policies are reactive, rule-based alerts triggered after an activity occurs (e.g., multiple failed logins), and cannot block actions in real time during the session.

64
MCQmedium

A company uses Microsoft Entra ID and has enabled self-service password reset (SSPR). Users are required to register for SSPR. Management wants to ensure that users from the HR department, who handle sensitive data, must use two methods for authentication during SSPR, while other users can use one method. What is the best way to achieve this?

A.Create a separate SSPR policy for the HR department using PowerShell
B.Use Microsoft Entra ID Governance to create an access package that requires two methods
C.Assign the HR users to a group and configure the SSPR policy for that group in the Entra admin center
D.This is not possible because SSPR authentication method requirements are tenant-wide
AnswerD

The requirement for two authentication methods to reset a password is a tenant-wide SSPR setting that cannot be overridden for a subset of users. In Microsoft Entra, the SSPR policy, including the number of methods required and the authentication methods available, is global. To enforce a different number of methods for HR, you would need a separate tenant or an alternative mechanism like Conditional Access MFA, which is not the same as SSPR's method count.

Why this answer

SSPR authentication method requirements in Microsoft Entra ID are configured at the tenant level, not per user or group. This means you cannot specify that one group of users must use two methods while others use one; the number of methods required applies uniformly to all users enabled for SSPR. Therefore, option D is correct because the requirement cannot be differentiated by department or group.

Exam trap

The trap here is that candidates assume group-based targeting for SSPR extends to authentication method requirements, when in reality group targeting only controls which users are enabled for SSPR, not the number of methods required, which is a tenant-wide setting.

How to eliminate wrong answers

Option A is wrong because PowerShell can be used to configure SSPR settings, but it cannot override the tenant-wide nature of authentication method requirements; any policy created would still apply to all users. Option B is wrong because Microsoft Entra ID Governance access packages manage resource access and entitlements, not SSPR authentication method requirements, which are a separate feature. Option C is wrong because while you can target SSPR to a group, the number of methods required is a tenant-wide setting and cannot be configured per group in the Entra admin center.

65
MCQeasy

A user reports that they cannot access their Microsoft 365 mailbox from the Outlook desktop client, but they can access it via Outlook on the web. Other users in the same tenant are not experiencing issues. What is the most likely cause?

A.There is a service incident affecting only the Outlook desktop client.
B.The user's Outlook profile is corrupted or needs to be re-created.
C.The user's account has been disabled.
D.The user's Microsoft 365 license has expired.
AnswerB

A corrupted Outlook profile is the most plausible cause when a user cannot access their mailbox from the Outlook desktop client but can still access it via Outlook on the web. The Outlook profile contains local configuration data, cache files (.ost), and authentication tokens; if this data becomes corrupted, the client may fail to start, hang, or repeatedly prompt for credentials. Re-creating the profile forces Outlook to rebuild the local cache and re-fetch the server-side mailbox, which resolves the issue without any impact on the server data.

Why this answer

If a user can access their mailbox via Outlook on the web but not the desktop client, while other users are unaffected, the issue is isolated to the local Outlook profile or client configuration. A corrupted Outlook profile is the most common cause and is resolved by creating a new profile. This scenario rules out tenant-wide service incidents, account disablement, or license expiry because those would also block OWA access.

Exam trap

MS-102 often tests the distinction between client-side and service-side failures — candidates may jump to service incidents or licensing, but the key differentiator is that OWA works, which points to a local client issue.

How to eliminate wrong answers

Option A is wrong because a service incident affecting only the Outlook desktop client would impact multiple users, not just one, and would not spare OWA for that same user. Option C is wrong because a disabled account would prevent all access, including OWA, and would typically show a sign-in error. Option D is wrong because an expired Microsoft 365 license would also block OWA access and would affect the user's ability to authenticate to the service entirely.

66
MCQeasy

You are a Microsoft 365 administrator for a small business with 50 users. The company is using Microsoft 365 Business Basic. You need to configure email for the custom domain contoso.com. You have added the domain in the Microsoft 365 admin center and verified ownership. Users currently have onmicrosoft.com email addresses. You need to change the primary email address for all users to their custom domain (e.g., user@contoso.com). What should you do?

A.Remove the onmicrosoft.com domain from the tenant.
B.Convert all mailboxes to shared mailboxes and reassign licenses.
C.Change the primary email address for each user to user@contoso.com in the admin center.
D.Configure the MX record for contoso.com to point to Exchange Online.
AnswerC

After contoso.com is added and verified in the tenant, you open Users > Active users, select a user, choose Manage username and email, and set user@contoso.com as the primary email address. This updates the primary SMTP proxy address in Exchange Online, giving each mailbox a valid address on the custom domain while optionally keeping the onmicrosoft.com address as a proxy alias for continuity.

Why this answer

In Microsoft 365, after adding and verifying a custom domain, you must manually update each user's primary email address (User Principal Name and primary SMTP address) from the default onmicrosoft.com domain to the custom domain. This is done in the Microsoft 365 admin center under Users > Active Users, by editing the username and email fields. Simply adding the domain does not automatically change existing user addresses.

Exam trap

The trap here is that candidates assume adding and verifying a custom domain automatically updates existing user email addresses, when in fact it only makes the domain available for use, requiring manual or scripted updates per user.

How to eliminate wrong answers

Option A is wrong because removing the onmicrosoft.com domain is not possible—it is a reserved default domain that cannot be deleted, and doing so would break authentication and routing for users still using it. Option B is wrong because converting mailboxes to shared mailboxes and reassigning licenses does not change the primary email address; shared mailboxes have their own SMTP addresses and are not a mechanism for domain migration. Option D is wrong because configuring the MX record for contoso.com to point to Exchange Online is a DNS step for mail routing, but it does not change the primary email address of existing users; that requires explicit user attribute updates.

67
MCQmedium

An administrator wants to receive real-time notifications for service incidents in Microsoft 365. The notifications must be sent to a Microsoft Teams channel instead of email. Which configuration should the administrator set up?

A.Configure a webhook connector in Microsoft Teams to subscribe to the Office 365 Service Communications API.
B.Configure an email notification rule in the Microsoft 365 admin center and forward it to a Teams email address.
C.Use Power Automate to check service health and post to Teams every 5 minutes.
D.Configure a message center alert to email and then use a third-party integration to post to Teams.
AnswerA

The Office 365 Service Communications API publishes webhook subscriptions that deliver service incident updates to a Teams channel via an incoming webhook connector. Once you register the Teams webhook URL and subscribe to relevant incidents, Microsoft pushes notifications as they occur, eliminating polling intervals. This is the only option that gives zero-latency, event-driven delivery without intermediaries or unsupported email forwarding.

Why this answer

The Office 365 Service Communications API provides real-time webhook-based notifications for service incidents. By configuring a webhook connector in Microsoft Teams, the administrator can subscribe to this API and receive incident alerts directly in a Teams channel without polling or email forwarding.

Exam trap

The trap here is that candidates may assume Power Automate or email forwarding is sufficient for real-time needs, but the exam specifically tests the understanding that webhook subscriptions to the Service Communications API are the only method that guarantees real-time, push-based notifications to a Teams channel.

How to eliminate wrong answers

Option B is wrong because forwarding an email notification to a Teams email address does not provide real-time delivery; Teams email integration is asynchronous and subject to delays, and the admin center email rules do not support direct Teams channel posting. Option C is wrong because Power Automate polling every 5 minutes introduces latency and is not real-time; the requirement specifies real-time notifications, which the Service Communications API webhook delivers instantly. Option D is wrong because it adds unnecessary complexity and delay by relying on email as an intermediary and a third-party integration, whereas a native webhook connector directly subscribes to the API for immediate delivery.

68
MCQhard

Your company uses Microsoft Entra ID and has a hybrid identity with PHS. You need to ensure that when an on-premises user account is disabled, the corresponding cloud user is also blocked from signing in within 5 minutes. What should you configure?

A.Deploy Azure AD Connect cloud sync
B.Enable password writeback
C.Configure Azure AD Connect to sync the 'userAccountControl' attribute
D.Configure Microsoft Entra Connect Sync to use filtered synchronization
AnswerA

Deploying Microsoft Entra Cloud Sync is correct because the cloud sync agent can be configured to synchronize identity changes—including the userAccountControl disabled flag—as frequently as every 1 minute, which satisfies the 5-minute latency requirement. Unlike Entra Connect Sync's 30-minute default cycle, Cloud Sync uses a lightweight agent that can run in parallel with Connect Sync (for non-overlapping scopes) or as a replacement, enabling near-real-time propagation of account disables for security and compliance.

Why this answer

Azure AD Connect cloud sync can be configured to synchronize the on-premises Active Directory 'userAccountControl' attribute, which includes the 'ACCOUNTDISABLE' flag. When an on-premises user account is disabled, this flag changes, and cloud sync can trigger a block on the corresponding cloud user's sign-in within a few minutes (typically under 5 minutes) due to its near-real-time sync cycle. This meets the requirement without relying on the slower default sync interval of Azure AD Connect.

Exam trap

The trap here is that candidates assume Azure AD Connect's 'userAccountControl' attribute sync (Option C) is sufficient, but they overlook the default 30-minute sync interval, which fails the 5-minute requirement, whereas cloud sync provides the needed speed.

How to eliminate wrong answers

Option B is wrong because password writeback enables users to reset their on-premises passwords from the cloud, but it does not control account disablement or sign-in blocking. Option C is wrong because while Azure AD Connect can sync the 'userAccountControl' attribute, the default sync interval is 30 minutes, which cannot guarantee the 5-minute requirement; cloud sync offers faster sync. Option D is wrong because filtered synchronization limits which objects are synced (e.g., by OU or domain), but it does not affect the sync speed or the ability to block sign-ins within 5 minutes.

69
MCQeasy

A company recently acquired another company and needs to allow users from the acquired tenant to access its SharePoint Online sites as guest users, but only if those users already have accounts in the acquired Azure AD tenant. Which Microsoft 365 feature should be configured?

A.Cross-tenant access settings for B2B collaboration
B.B2B direct connect
C.Multi-Geo
D.Tenant Restrictions
AnswerA

Cross-tenant access settings for B2B collaboration are the correct method for controlling and enabling guest access across Microsoft 365 tenants. These settings let you configure inbound and outbound access policies, apply cross-tenant trust for Multi-factor Authentication and device compliance, and set specific automatic redemption options. They govern SharePoint external sharing by controlling which external Azure AD tenants can authenticate and how their guest identities are treated, making this the correct tool for the scenario.

Why this answer

Cross-tenant access settings for B2B collaboration allow you to configure inbound and outbound access between two Azure AD tenants. By enabling B2B collaboration with the acquired tenant and setting the appropriate cross-tenant access policies, you can invite users who already have accounts in that tenant as guest users to access SharePoint Online sites. This ensures that only authenticated users from the acquired tenant are granted access, meeting the requirement.

Exam trap

The trap here is that candidates confuse B2B direct connect with B2B collaboration, assuming both provide guest access to SharePoint, but B2B direct connect is limited to Teams shared channels and does not support SharePoint guest invitations.

How to eliminate wrong answers

Option B (B2B direct connect) is wrong because it is designed for Teams Connect shared channels, not for granting guest access to SharePoint Online sites, and it does not support inviting users as guests with Azure AD accounts. Option C (Multi-Geo) is wrong because it addresses data residency and geographic location of tenant data, not cross-tenant user access or guest invitations. Option D (Tenant Restrictions) is wrong because it controls access to SaaS apps based on tenant ID via HTTP headers, but it does not enable inviting external users from another tenant as guests.

70
MCQmedium

Your organization uses Microsoft Defender for Endpoint. You need to ensure that when a device is onboarded, it automatically receives all current threat intelligence signatures. What should you verify is configured?

A.The device is configured to receive updates from Microsoft Update.
B.Network protection is enabled in the attack surface reduction rules.
C.Sample submission is enabled in the advanced features.
D.Cloud-delivered protection is enabled in the Microsoft 365 Defender portal.
AnswerD

Cloud-delivered protection is the core mechanism connecting Microsoft Defender for Endpoint to Microsoft's cloud security intelligence. When enabled, the endpoint sends telemetry to the cloud and receives near-real-time responses, including newly generated signatures, 'block at first sight' decisions, and behavioral detections. This low-latency, dynamic channel is exactly what ensures the device gets real-time signature updates, beyond the static definitions delivered by Microsoft Update.

Why this answer

Cloud-delivered protection in the Microsoft 365 Defender portal ensures that devices receive the latest threat intelligence signatures in near real-time. When enabled, Defender for Endpoint uses the Microsoft Intelligent Security Graph to push updated signatures and machine learning models to onboarded devices automatically, without relying on manual update cycles.

Exam trap

The trap here is that candidates confuse cloud-delivered protection (which provides real-time signature updates) with other security features like network protection or sample submission, or assume that standard Microsoft Update handles Defender signatures.

How to eliminate wrong answers

Option A is wrong because Microsoft Update delivers Windows and Office updates, not Defender for Endpoint threat intelligence signatures; signature updates are managed through Windows Update for Defender or cloud-delivered protection. Option B is wrong because network protection is a component of attack surface reduction that blocks outbound connections to malicious IPs/domains, but it does not control the delivery of threat intelligence signatures. Option C is wrong because sample submission enables automatic file submission for analysis to improve detection, but it does not affect how current threat intelligence signatures are received by devices.

71
Multi-Selectmedium

Which TWO Microsoft Defender XDR components provide protection for email and collaboration tools? (Choose two.)

Select 2 answers
A.Microsoft Defender for Identity
B.Microsoft Defender for Office 365
C.Microsoft Defender for Cloud
D.Microsoft Defender for Cloud Apps
E.Microsoft Defender for Endpoint
AnswersB, D

Defender for Office 365 protects Exchange Online, SharePoint, OneDrive, and Microsoft Teams through features like anti-phishing, anti-spam, Safe Attachments, and Safe Links. It directly filters email traffic and inspects collaboration workloads for malicious content. This makes it the core email and collaboration protection component in Microsoft Defender XDR.

Why this answer

Microsoft Defender for Office 365 is the correct choice because it is the dedicated component that protects email and collaboration tools (Exchange Online, SharePoint Online, OneDrive for Business, and Teams) against threats like phishing, malware, and spam. It uses advanced machine learning and detonation analysis in Safe Attachments and Safe Links to inspect attachments and URLs in real time.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps (which provides cloud access security broker (CASB) controls for SaaS apps like Office 365) with direct email protection, but it is Defender for Office 365 that specifically handles email and collaboration threat protection, while Defender for Cloud Apps adds visibility and governance over sanctioned and unsanctioned cloud apps.

72
MCQmedium

Your organization has Microsoft Defender for Office 365. Users report that legitimate emails from a partner domain are being quarantined. You need to ensure these emails are delivered while maintaining security. What should you do?

A.Add the partner domain to the Allow list in the Tenant Allow/Block List.
B.Disable spam filtering for the partner domain.
C.Lower the spam confidence level (SCL) threshold for the organization.
D.Create a mail flow rule to bypass spam filtering for the partner domain.
AnswerA

Adding the partner domain to the Tenant Allow/Block List overrides the quarantine verdict for that sender, satisfying the requirement that legitimate partner mail be delivered. Entries here take precedence over filtering verdicts, so messages bypass quarantine while spoofing and malware protection remain active for all other senders.

Why this answer

The Tenant Allow/Block List in Microsoft Defender for Office 365 is the supported, granular mechanism for allowing specific senders or domains that are being incorrectly quarantined. Adding the partner domain as an allow entry tells Exchange Online Protection (EOP) to skip filtering actions (quarantine, junk, etc.) for messages from that domain while still applying other protections like malware scanning and Safe Links. This preserves security posture because only the specific false-positive source is exempted, not the entire filtering pipeline.

Exam trap

MS-102 often tests the misconception that a mail flow rule (transport rule) is the best way to bypass spam filtering, when in fact the Tenant Allow/Block List is the recommended, granular, and auditable method for allowing specific senders or domains.

How to eliminate wrong answers

Option B is wrong because disabling spam filtering for a domain is not a supported per-domain action in EOP; spam filtering is controlled by policies (anti-spam policies, connection filtering) that apply broadly, and turning it off would expose the tenant to all spam from that domain. Option C is wrong because lowering the SCL threshold organization-wide would make filtering more aggressive (or less, depending on direction) for all mail, not just the partner domain, and would not reliably fix a false positive while weakening overall protection. Option D is wrong because while a mail flow rule can set an SCL of -1 to bypass spam filtering, it is a blunt workaround that also bypasses other protections and is not the recommended, auditable method for allow-listing a domain; the Tenant Allow/Block List is the purpose-built control.

73
MCQeasy

A company uses Microsoft Entra ID for identity management. The security team wants to ensure that users cannot register applications in the tenant to prevent potential data leakage. Which setting should be configured?

A.Set the 'Admin consent requests' setting to 'Allow'
B.Enable the 'Admin consent workflow'
C.Set 'Users can register applications' to 'No' in User settings
D.Set 'Users can consent to apps accessing company data' to 'No'
AnswerC

The 'Users can register applications' setting, found under Microsoft Entra ID > User settings, is the directory-wide toggle that controls whether non-admin users can create application registrations in the tenant. Setting it to 'No' revokes the default user permission to self-register apps, ensuring only users with applicable administrative roles (such as Application Administrator) can register applications. This directly satisfies the requirement to prevent user app registration.

Why this answer

Setting 'Users can register applications' to 'No' in the Microsoft Entra ID User settings explicitly prevents non-admin users from creating application registrations in the tenant. This directly addresses the security team's goal of blocking users from registering apps, which could otherwise expose tenant data through misconfigured or malicious applications.

Exam trap

The trap here is that candidates often confuse 'users registering applications' with 'users consenting to applications,' leading them to select Option D, which only controls consent, not the creation of the app registration itself.

How to eliminate wrong answers

Option A is wrong because 'Admin consent requests' setting controls whether users can request admin consent for applications, not whether users can register applications themselves. Option B is wrong because enabling the 'Admin consent workflow' allows users to request admin approval for app permissions, but does not block user-initiated app registration. Option D is wrong because setting 'Users can consent to apps accessing company data' to 'No' prevents users from granting permissions to apps, but does not prevent users from registering new applications in the tenant.

74
MCQeasy

You are the Microsoft 365 administrator for a company that uses Microsoft 365 E3. The company has a single Microsoft 365 tenant. The IT manager asks you to create a new user account for a temporary employee who will start next week and will need access to Exchange Online and SharePoint Online. The employee will leave after three months. You need to create the user account with the minimum required licenses. What should you do?

A.Create a new user in the Microsoft 365 admin center and assign a Microsoft 365 Business Premium license.
B.Create a new user in the Microsoft 365 admin center and assign a Microsoft 365 E3 license, then disable all services except Exchange Online and SharePoint Online.
C.Create a new user in the Microsoft 365 admin center and assign an Exchange Online (Plan 1) license and a SharePoint Online (Plan 1) license.
D.Create a new user in the Microsoft 365 admin center and assign a Microsoft 365 E3 license.
AnswerC

Assigning Exchange Online (Plan 1) and SharePoint Online (Plan 1) licenses provides exactly the services required by the temporary employee: Exchange Online and SharePoint Online. This meets the minimum required licenses because it does not include unnecessary services. These licenses are available as standalone subscriptions and can be assigned individually. This is the most cost-effective and precise solution for the scenario, ensuring the user has access only to what they need.

Why this answer

The requirement is to provide access to Exchange Online and SharePoint Online with the minimum required licenses. Assigning standalone Exchange Online (Plan 1) and SharePoint Online (Plan 1) licenses achieves this by providing exactly the needed services without the extra cost and features of a suite license. Using a suite license like Microsoft 365 E3 or Business Premium would grant more services than necessary and does not meet the minimum license requirement.

Disabling services within a suite license still consumes the full license.

Exam trap

The trap here is assuming that a suite license like Microsoft 365 E3 is required for Exchange Online and SharePoint Online access, when standalone service licenses are available and more cost-effective for specific needs.

75
MCQeasy

A user account was accidentally deleted 10 days ago. The administrator needs to restore the user's mailbox and OneDrive for Business content. Which method should the administrator use?

A.Recreate the user account with the same name, and the data will be automatically restored.
B.Restore the user from the 'Deleted users' page in the Microsoft 365 admin center.
C.Use the Exchange admin center to recover the mailbox only.
D.Submit a support request to Microsoft to recover the deleted data.
AnswerB

In the Microsoft 365 admin center, navigate to Users > Deleted users, locate the accidentally deleted user, and choose Restore. This is the supported self-service recovery path for soft-deleted user objects within the 30-day retention period, and it re-associates the user's existing Exchange Online mailbox, OneDrive for Business, and other workload data with the restored account.

Why this answer

Microsoft 365 retains deleted user objects, including their Exchange Online mailbox and OneDrive for Business data, for 30 days in the 'Deleted users' list. Restoring the user from this page within the retention period automatically recovers the associated mailbox and OneDrive content without requiring separate tools or support requests.

Exam trap

The trap here is that candidates often confuse the 30-day soft-delete retention with the ability to simply recreate the user account, or they assume that separate admin centers are required for mailbox and OneDrive recovery, when in fact the unified 'Deleted users' restore handles both.

How to eliminate wrong answers

Option A is wrong because simply recreating a user account with the same name does not automatically restore the original mailbox or OneDrive data; the new account receives a fresh mailbox and OneDrive, and the deleted user's data remains in the recycle bin only if the original object is restored. Option C is wrong because the Exchange admin center can recover a soft-deleted mailbox only if the user object still exists or was recently deleted, but it cannot recover OneDrive for Business content, which requires the full user restoration from the Microsoft 365 admin center. Option D is wrong because Microsoft support is not needed for this scenario; the administrator can self-service restore the user from the 'Deleted users' page within the 30-day retention period without submitting a support request.

Page 1 of 10

Page 2

All pages