Courseiva

Microsoft 365 Administrator MS-102 (MS-102) — Questions 151–225

712 questions total · 10pages · All types, answers revealed

Page 2

Page 3 of 10

Page 4
151
MCQmedium

You are the Microsoft 365 administrator for Fabrikam, which has a Microsoft 365 E5 tenant and Microsoft Entra ID P2. The security team wants to require multifactor authentication for all users when they access any cloud app from outside the corporate network, but they do not want to affect users working in the office. You create a Conditional Access policy named CA01. You need to configure the policy to meet the requirements. What should you do?

A.Set the Assignments to All users, All cloud apps, and under Conditions configure Locations to include Any location and exclude the corporate network location, then under Access controls set Grant to Require multifactor authentication, and set Enable policy to On.
B.Set the Assignments to All users, All cloud apps, and under Conditions configure Locations to include Any location, then under Access controls set Grant to Require multifactor authentication, and set Enable policy to On.
C.Set the Assignments to All users, All cloud apps, and under Conditions configure Client apps to Exchange ActiveSync clients and other clients, then under Access controls set Grant to Require multifactor authentication, and set Enable policy to On.
D.Set the Assignments to All users, All cloud apps, and under Conditions configure Locations to include Any location, then under Access controls set Grant to Require multifactor authentication, and set Enable policy to Report-only.
AnswerA

Excluding the corporate network location from the Locations condition ensures the policy applies only to sign-ins from outside the trusted network. Setting Grant to Require multifactor authentication enforces MFA for those sign-ins, and enabling the policy makes it active. This precisely matches the requirement to prompt external users while leaving office users unaffected.

Why this answer

The requirement is to enforce MFA only for sign-ins originating outside the corporate network. A Conditional Access policy must include All users and All cloud apps as the assignment scope, then use the Locations condition to exclude the trusted corporate network. With the Grant control set to Require multifactor authentication and the policy enabled, external sign-ins are challenged while internal sign-ins remain unaffected.

Exam trap

The trap here is assuming that selecting Any location automatically limits the policy to external networks, when in fact Any location includes trusted locations unless you explicitly exclude them.

152
Multi-Selecthard

Which TWO settings must be configured to set up a hybrid identity deployment using password hash synchronization?

Select 2 answers
A.Install and configure Microsoft Entra Connect.
B.Configure Seamless Single Sign-On (SSO).
C.Enable password hash synchronization in Entra Connect.
D.Deploy Active Directory Federation Services (AD FS).
E.Configure Pass-Through Authentication.
AnswersA, C

Microsoft Entra Connect provides the sync engine that hashes on-premises Active Directory passwords and writes the resulting hash to Microsoft Entra ID, which is the mechanism password hash synchronization depends on. Without this component, no directory objects or password hashes reach the cloud tenant.

Why this answer

Option A is correct because Microsoft Entra Connect is the required synchronization tool that connects your on-premises Active Directory to Microsoft Entra ID and provides the wizard where directory synchronization and sign-in methods are configured. Option C is correct because password hash synchronization is a sign-in method that must be explicitly enabled in Entra Connect (on the "User sign-in" page, select "Password Hash Synchronization") for the hybrid identity deployment to work as described. Option B is not required because Seamless SSO is an optional feature that can be enabled alongside password hash synchronization but is not necessary to set up the deployment itself.

Option D is incorrect because AD FS is a separate federated authentication method, not part of a password hash synchronization deployment. Option E is incorrect because Pass-Through Authentication is an alternative sign-in method that validates passwords directly against on-premises AD and is mutually exclusive with password hash synchronization as the primary sign-in method.

Exam trap

The trap here is that candidates often include Seamless SSO as a required component for password hash synchronization, when in fact it is optional. The minimal requirements for PHS are simply installing Entra Connect and enabling the PHS feature. SSO enhances the user experience but is not necessary for the synchronization of password hashes.

153
MCQeasy

A company recently added the custom domain 'contoso.com' to their Microsoft 365 tenant. Users report that they cannot receive external email sent to their new domain addresses. The administrator confirmed that the domain status shows 'Active' in the Microsoft 365 admin center. What is the most likely cause of this issue?

A.The domain was not verified with a TXT record.
B.The MX record for the domain is missing or points to an incorrect mail server.
C.The SPF record for the domain is missing or incorrectly configured.
D.The custom domain was not added to the user's primary email address.
AnswerB

The MX record is the authoritative DNS resource that specifies the mail exchanger for a domain. When an external sender tries to deliver to contoso.com, their mail server queries DNS for the MX record to discover which host accepts inbound messages. If this record is absent or points to an incorrect mail server, delivery to Exchange Online cannot occur, causing non-delivery reports or messages routed to the wrong destination. Microsoft 365 requires the MX record to point to contoso-com.mail.protection.outlook.com with the correct priority.

Why this answer

The domain status 'Active' in the Microsoft 365 admin center indicates that the domain has been successfully verified and added to the tenant. However, for external email to be delivered to users at that domain, the public MX record in DNS must point to Microsoft 365's mail servers (e.g., contoso-com.mail.protection.outlook.com). If the MX record is missing or points to an incorrect server, external senders cannot route email to the tenant, even though the domain is verified and active.

Exam trap

The trap here is that candidates see 'Active' domain status and assume all DNS configurations are correct, but Microsoft 365 separates domain verification (TXT record) from mail routing (MX record), so a verified domain can be 'Active' yet still unreachable for inbound email if the MX record is misconfigured.

How to eliminate wrong answers

Option A is wrong because the domain status shows 'Active', which means the TXT verification record was successfully validated; a missing TXT record would prevent the domain from reaching 'Active' status. Option C is wrong because an SPF record affects sender authentication and deliverability of outbound email, but does not prevent inbound email from being received; missing or incorrect SPF would not block external email from arriving at the mailbox. Option D is wrong because adding the custom domain to a user's primary email address is a separate step that affects the user's email address format, but even if not yet assigned, the domain can still receive email for any alias or accepted domain; the core issue is DNS routing, not user assignment.

154
MCQmedium

An organization is implementing Microsoft Entra Verified ID for verifiable credentials. They want to issue credentials to employees that can be used to prove employment status to third parties. Which component must be created first?

A.A presentation request policy
B.A distributed ledger network
C.A credential manifest in the Microsoft Entra admin center
D.A decentralized identifier (DID) for the organization
AnswerC

A credential manifest is the core configuration artifact for issuing a verifiable credential in Microsoft Entra Verified ID. Defined in the Microsoft Entra admin center, it combines rules and display information: the rules definition specifies required claims, such as user attributes and optional validation logic, while the display definition controls the JSON schema and the visual layout of the credential. This manifest is what transforms a user's claim data into a signed verifiable credential, making it essential for any issuance scenario. Without it, the right issuance API calls would lack the necessary structure and would fail.

Why this answer

The credential manifest defines the rules for issuing a verifiable credential, including the claims schema, display information, and issuance policies. In Microsoft Entra Verified ID, you must create the credential manifest in the Entra admin center before any credentials can be issued, as it serves as the template that governs the credential's structure and validation. Without a manifest, there is no definition for what the credential contains or how it should be presented.

Exam trap

The trap here is that candidates often confuse the order of setup steps, assuming the DID must be manually created first, when in fact the DID is automatically generated during the Verified ID service initialization, and the credential manifest is the first component that requires explicit user configuration in the admin center.

How to eliminate wrong answers

Option A is wrong because a presentation request policy is used by verifiers to request proof of a credential from a holder, not to define the credential itself; it is created after the credential manifest. Option B is wrong because Microsoft Entra Verified ID uses a distributed ledger (ION) to anchor DIDs, but the organization does not create or manage a ledger network—it is an existing infrastructure that Microsoft manages. Option D is wrong because the decentralized identifier (DID) for the organization is automatically created when you set up the Verified ID service in the Entra admin center, and it is a prerequisite step that occurs before creating the credential manifest, but the question asks which component must be created first, and the DID is created as part of the initial setup, not as a separate manual creation step; the credential manifest is the first user-defined component after the DID is established.

155
MCQeasy

A company plans to migrate their email from an on-premises Exchange server to Exchange Online. They want to ensure that during the migration, mail sent to users who have already been migrated is delivered to Exchange Online, while mail for non-migrated users is delivered to on-premises. Which type of domain configuration should they use?

A.Coexistence domain
B.Shared domain
C.Split domain
D.Forwarding domain
AnswerC

Split domain (also called shared SMTP address space) is the correct configuration when a single accepted domain has mailboxes both on-premises and in Exchange Online, as in this migration scenario. In an Exchange hybrid deployment, you configure the on-premises organization and Exchange Online to recognize the same domain as authoritative, and then create a send connector and a receiving connector (or use the Hybrid Configuration Wizard) to route messages based on the mailbox location. This allows mail for recipients with the same domain suffix to be delivered correctly to either environment, which is exactly the requirement when migrating mailboxes from on-premises to the cloud.

Why this answer

A split domain configuration is required when some mailboxes reside on-premises and others in Exchange Online during a migration. It uses MX records pointing to Exchange Online Protection (EOP) and internal mail flow connectors to route messages for migrated users to Exchange Online and non-migrated users to on-premises, ensuring each mailbox receives mail at its current location.

Exam trap

The trap here is that candidates confuse 'split domain' with 'hybrid deployment' or 'coexistence,' but the question specifically asks for the domain configuration type, not the overall migration method; Microsoft often tests the exact terminology for mail flow scenarios during phased migrations.

How to eliminate wrong answers

Option A is wrong because a coexistence domain is not a standard Exchange domain type; coexistence is a state achieved through hybrid configuration, not a specific domain configuration. Option B is wrong because a shared domain is not a recognized Exchange domain configuration; it might be confused with a shared mailbox or shared namespace, but it does not describe the routing logic needed for a phased migration. Option D is wrong because a forwarding domain is not a valid Exchange domain type; forwarding is a mailbox-level or transport rule action, not a domain-level configuration for split mail flow.

156
MCQhard

Your company is migrating from on-premises Active Directory to Microsoft Entra ID. You plan to use Microsoft Entra Connect Sync to synchronize user accounts. The security team requires that all cloud-only users must be blocked from syncing to on-premises AD. What should you do to meet this requirement?

A.Configure attribute mapping to filter out cloud-only users from writeback
B.Use the cloudFilter attribute to mark cloud-only users as false
C.Disable directory writeback in Microsoft Entra Connect Sync
D.Configure Selective Password Hash Sync to exclude cloud-only users
AnswerA

Configuring an outbound attribute mapping in Microsoft Entra Connect Sync allows you to set a scoping filter (e.g., `sourceAnchor` present or `cloudAnchored` true) on the writeback rule. Cloud-only users, created directly in Entra ID, have no corresponding on-premises Active Directory object, so the filter prevents the sync engine from attempting to write attributes like `msDS-cloudExtensionAttribute` to a nonexistent object. This selectively permits writeback for synced users while excluding cloud-only identities, thus addressing the selective requirement without disabling writeback globally.

Why this answer

Configuring attribute mapping to filter out cloud-only users from writeback directly prevents those users from being written back to on-premises Active Directory. In Microsoft Entra Connect Sync, attribute mapping rules can include scoping filters that exclude objects based on specific attributes, such as a custom attribute or the cloud-only user indicator. This ensures that only synchronized users are written back, meeting the security requirement without affecting other sync operations.

Exam trap

The trap here is that candidates often confuse the cloudFilter attribute (which controls sync direction from on-premises to cloud) with a mechanism to block cloud-only users from writeback, leading them to incorrectly select option B.

How to eliminate wrong answers

Option B is wrong because the cloudFilter attribute is used in Microsoft Entra Connect Sync to control which objects are synchronized from on-premises to the cloud, not to block cloud-only users from writeback; it cannot be applied to cloud-only objects that do not exist in on-premises AD. Option C is wrong because disabling directory writeback entirely would block all writeback operations, including for synchronized users who need to be written back (e.g., for password writeback or device writeback), which is too broad and does not specifically target cloud-only users. Option D is wrong because Selective Password Hash Sync controls which users have their password hashes synchronized from on-premises to the cloud, not writeback from cloud to on-premises; it is irrelevant to blocking cloud-only users from syncing to on-premises AD.

157
MCQeasy

You need to ensure that only users from your organization's on-premises Active Directory can access Microsoft 365 services. You have Microsoft Entra Connect configured. What is the simplest way to prevent cloud-only user accounts from signing in?

A.Configure a conditional access policy that blocks all users.
B.Delete the cloud-only users from Microsoft Entra ID.
C.Set the 'Block sign in' option to 'Yes' for all cloud-only users in the Microsoft Entra admin center.
D.Remove all licenses from cloud-only users.
AnswerC

Setting 'Block sign in' to Yes in Microsoft Entra ID directly prevents cloud-only accounts from authenticating, satisfying the requirement that only on-premises Active Directory users access Microsoft 365. Because Microsoft Entra Connect already synchronises those on-premises identities, blocking the cloud-only accounts leaves synced users unaffected, and it is the simplest per-account control available.

Why this answer

Setting the 'Block sign in' option to 'Yes' for cloud-only users in the Microsoft Entra admin center directly prevents those accounts from signing in without deleting them or affecting licensed users. This is the simplest and most targeted method. It does not require conditional access policies or license changes.

Exam trap

MS-102 often tests the difference between blocking sign-in for specific users versus conditional access policies; candidates may incorrectly choose a broad conditional access policy that blocks all users.

How to eliminate wrong answers

Option A is wrong because a conditional access policy that blocks all users would also block on-premises synchronized users, which is not the goal. Option B is wrong because deleting cloud-only users is destructive and may cause data loss; it is not the simplest or recommended approach. Option D is wrong because removing licenses does not prevent sign-in; users can still sign in to services that do not require a license, and it may cause unintended service disruptions.

158
Multi-Selectmedium

You are the Microsoft 365 Administrator for a multinational organization that must comply with various regulatory requirements, including GDPR, SOX, and internal data retention policies. You are deploying Microsoft Purview compliance solutions. Which four of the following actions are valid steps when managing compliance using Microsoft Purview? (Choose all that apply. There are four correct answers.)

Select 4 answers
.Create a DLP policy that prevents users from sharing credit card numbers via email with external recipients.
.Use a retention label to automatically delete documents containing trade secrets after 7 years.
.Configure a sensitivity label with sublabels that apply different markings (e.g., 'Confidential' and 'Highly Confidential') to the same document.
.Enable auditing in the Microsoft 365 compliance portal to track user activities such as file downloads and mailbox access.
.Assign a retention policy to a user's mailbox that deletes all emails immediately after they are sent.
.Apply a sensitivity label to a SharePoint site that blocks all external sharing of documents stored in that site.

Why this answer

Creating a DLP policy that prevents sharing credit card numbers via email with external recipients is a valid step because Microsoft Purview Data Loss Prevention (DLP) policies can detect sensitive information types (e.g., credit card numbers) and enforce actions such as blocking external sharing. This directly supports compliance with regulations like GDPR and SOX by preventing unauthorized data exfiltration.

Exam trap

Microsoft often tests the misconception that sensitivity labels can directly control external sharing of documents within a site, when in reality they control site-level settings (e.g., privacy) while external sharing is governed by SharePoint sharing policies.

159
MCQmedium

A company is experiencing a significant number of phishing attempts that target high-level executives by impersonating their email addresses. The security team wants to configure protection against user impersonation in Microsoft Defender for Office 365. Which setting must be enabled in the anti-phishing policy to protect these specific users?

A.Enable users to protect against impersonation
B.Enable domains to protect against impersonation
C.Mailbox intelligence
D.Spoofed sender posture
AnswerA

This setting allows you to define a list of specific users (e.g., executives) whose email addresses are protected from being impersonated in inbound emails. When impersonation is detected, the action defined in the policy is applied.

Why this answer

The 'Enable users to protect against impersonation' setting in an anti-phishing policy allows you to specify a list of users (such as high-level executives) whose email identities will be monitored for impersonation attempts. When enabled, Defender for Office 365 analyzes inbound messages for display name and email address matches against the protected users, and if a match is found with a suspicious sender, the message is flagged or quarantined. This directly addresses the scenario of attackers spoofing executive email addresses.

Exam trap

The trap here is that candidates often confuse 'user impersonation protection' with 'domain impersonation protection' or 'spoof intelligence,' but the question specifically asks for protection against impersonation of individual users, which requires the user-based setting, not domain-level or spoof-based controls.

How to eliminate wrong answers

Option B is wrong because 'Enable domains to protect against impersonation' protects against impersonation of entire domains (e.g., contoso.com), not specific individual user mailboxes, so it would not target the high-level executives as individuals. Option C is wrong because 'Mailbox intelligence' is a feature that learns normal sending patterns for users in your organization to detect anomalies, but it does not provide a static list of protected users; it relies on behavioral baselines rather than explicit user protection. Option D is wrong because 'Spoofed sender posture' is part of the spoof intelligence feature that evaluates the authentication status of the sending domain (SPF, DKIM, DMARC), not the impersonation of a specific user's display name or email address.

160
MCQmedium

Your organization uses Microsoft Defender for Identity. You receive an alert about a potential DCSync attack. What should you do to investigate this alert in Microsoft Defender XDR?

A.Review the IdentityDirectoryEvents table for replication-related events.
B.Use IdentityQueryEvents to find LDAP queries related to replication.
C.Check the IdentityAlertEvents table to see if the alert has additional context.
D.Run a KQL query in Advanced Hunting against IdentityLogonEvents to identify suspicious replication attempts.
AnswerD

IdentityLogonEvents is the correct table because it records authentication and logon events, including those that occur when an account attempts to replicate domain data via DRSUAPI. During a DCSync attack, the attacker's replication request appears as a logon event with specific attributes, such as a particular logon type or the use of replication privileges. Running a KQL query against IdentityLogonEvents allows you to filter for these suspicious patterns, such as account names, source IPs, and timing, making it the proper source for identifying replication attempts in Advanced Hunting.

Why this answer

DCSync attacks are performed by requesting domain replication via the MS-DRSR protocol, which generates specific directory replication events. In Microsoft Defender XDR, these replication attempts are logged in the IdentityLogonEvents table when an account authenticates to a domain controller for replication purposes. Running a KQL query against this table allows you to identify the source account, target domain controller, and the specific replication activity that triggered the alert.

Exam trap

The trap here is that candidates confuse the different Advanced Hunting tables: they assume DCSync is an LDAP query (Option B) or a directory object change (Option A), when in fact it is a replication protocol event logged in IdentityLogonEvents.

How to eliminate wrong answers

Option A is wrong because the IdentityDirectoryEvents table captures changes to directory objects (e.g., modifications, creations), not the replication protocol events that indicate a DCSync attack. Option B is wrong because IdentityQueryEvents logs LDAP queries, but DCSync uses the MS-DRSR replication protocol (not LDAP) to request replication of password hashes. Option C is wrong because while IdentityAlertEvents contains alert metadata, it does not contain the raw replication event data needed to investigate the specific replication attempt; you need to query the underlying event tables.

161
MCQeasy

You need to configure Microsoft Teams to allow external access for federation with another organization. The other organization uses a different domain. Which setting must you enable in the Teams admin center?

A.Network roaming policy for the external users.
B.Guest access in Teams settings.
C.Emergency calling policies.
D.External access with the domain of the other organization.
AnswerD

External access (federation) is the correct mechanism to let users in your organization communicate with users from a different organization in Teams. In the Teams admin center, under External access, you can allow federation globally or restrict it to specific domains by adding the other organization's domain to the allowed list. This setting enables chat and calls between your users and those in the external tenant, while keeping each user in their own organization's identity.

Why this answer

To enable federation with another organization that uses a different domain, you must configure External access (also known as federation) in the Teams admin center. Specifically, you need to add the external domain to the allowed domain list under Teams > External access. This allows users in your tenant to communicate with users in the other organization via Teams, using the Session Initiation Protocol (SIP) federation protocol.

Exam trap

The trap here is that candidates often confuse Guest access (Azure AD B2B) with External access (federation), leading them to select Option B, but Guest access is for individual external users, not for domain-level federation with another organization.

How to eliminate wrong answers

Option A is wrong because Network roaming policy controls network configuration settings (such as bandwidth and IP ranges) for users when they are on different networks; it does not control cross-tenant federation. Option B is wrong because Guest access is for inviting external users as guests within your tenant (using Azure AD B2B), not for federating with another organization's entire domain. Option C is wrong because Emergency calling policies define how emergency calls (e.g., to 911) are handled and are unrelated to external federation settings.

162
MCQhard

A security administrator wants to configure Microsoft Defender for Cloud Apps so that when a user accesses a sensitive file in a sanctioned cloud app from an unmanaged device, the user is blocked from downloading the file and a block action is logged in real time. Which type of policy should the administrator configure?

A.Create a session policy with the action 'Block' on the download action for files with a specific sensitivity label
B.Create a file policy that monitors for sensitive files being accessed from unmanaged devices and generates an alert
C.Configure an access policy that blocks access to the cloud app from unmanaged devices
D.Configure an activity policy that monitors download activities from unmanaged devices and triggers automatic remediation
AnswerA

This session policy works through the Microsoft Defender for Cloud Apps reverse proxy, which intercepts and inspects user requests in real time. By combining a 'device as unmanaged' condition with a sensitivity-label file filter, it can block the actual download action at the moment it occurs while still letting the user access the file in the browser. This is the only option that fulfills the requirement of allowing access but preventing a download from an unmanaged device.

Why this answer

A session policy in Microsoft Defender for Cloud Apps allows real-time control over user activities within a sanctioned cloud app. By configuring the action 'Block' on the download action for files with a specific sensitivity label, the administrator can block the download when the session is initiated from an unmanaged device, and the block action is logged in real time. This meets the requirement of blocking the download and logging the action simultaneously.

Exam trap

The trap here is that candidates confuse session policies with access policies or file policies, mistakenly thinking that blocking access to the entire app (Option C) or monitoring after the fact (Option B) achieves the same real-time blocking of a specific download action, when only a session policy provides the required granular, in-session control.

How to eliminate wrong answers

Option B is wrong because a file policy is designed for monitoring and alerting on files that match certain criteria (e.g., sensitivity labels) but does not provide real-time blocking of user actions like downloads; it generates alerts after the fact. Option C is wrong because an access policy blocks entire access to the cloud app from unmanaged devices, which is too broad—it would prevent any access, not just the download of sensitive files, and does not log the specific block action on the download. Option D is wrong because an activity policy monitors activities and can trigger automatic remediation (e.g., suspending a user), but it does not support real-time blocking of a specific download action within a session; it typically acts after the activity has occurred.

163
MCQhard

You are a security administrator for a company that uses Microsoft Defender XDR. You need to ensure that when a file is detected as malware by Microsoft Defender for Endpoint, the file is automatically blocked and added to the indicator list across all devices in the organization. What should you configure?

A.Enable the 'Block at first sight' feature in Microsoft Defender for Endpoint.
B.Configure an automated investigation and response (AIR) playbook to block the file when malware is detected.
C.Set up a Microsoft Defender for Cloud Apps file policy to block the file.
D.Create a custom indicator in Microsoft Defender for Endpoint with the action 'Block and remediate' and scope it to all devices.
AnswerD

Custom indicators in Defender for Endpoint allow you to define file hashes or certificates to block or allow. By setting the action to 'Block and remediate' and scoping to all devices, you ensure the file is blocked organization-wide. This directly meets the requirement.

Why this answer

Custom indicators in Microsoft Defender for Endpoint are the correct way to block files organization-wide. By creating an indicator with the action 'Block and remediate' and setting the scope to all devices, the file is blocked and remediated on any device. Other options either do not add to the indicator list or are not scoped organization-wide.

Exam trap

The trap here is confusing automated response actions or cloud protection features with the explicit indicator list, which is the only way to persistently block a file across all devices.

164
MCQmedium

A security administrator wants to simulate a realistic phishing attack to train users and measure their susceptibility. The simulation should be run from within Microsoft Defender XDR and provide detailed reporting. Which feature should the administrator use?

A.Advanced Hunting
B.Attack Simulation Training
C.Automated Investigation and Response
D.Threat Analytics
AnswerB

Attack Simulation Training is the dedicated feature in Microsoft Defender for Office 365 designed to create realistic phishing simulations and assign targeted training to users who interact with them. It provides prebuilt simulation templates, tracks metrics like click rate and credential submission, and automates follow-up training to improve user resilience. This matches the requirement to simulate a phishing attack and measure user response, so it is the correct answer.

Why this answer

Attack Simulation Training in Microsoft Defender XDR allows security administrators to create and launch realistic phishing campaigns directly from the Microsoft 365 Defender portal. It provides detailed reporting on user interactions, such as who clicked the link or entered credentials, enabling measurement of user susceptibility and targeted training follow-ups.

Exam trap

The trap here is that candidates often confuse Attack Simulation Training with Advanced Hunting, thinking that hunting queries can simulate attacks, but Advanced Hunting is purely a read-only data exploration tool with no simulation or user training features.

How to eliminate wrong answers

Option A is wrong because Advanced Hunting is a query-based tool for proactively searching for threats across raw data, not for simulating attacks or training users. Option C is wrong because Automated Investigation and Response (AIR) automatically responds to detected incidents by running playbooks and remediating threats, but it does not create or manage phishing simulations. Option D is wrong because Threat Analytics provides intelligence reports on active threats and adversary techniques, but it does not include simulation or user training capabilities.

165
MCQmedium

Your organization, Contoso Ltd., has a Microsoft 365 E5 tenant with Microsoft Entra ID P2. You are the Global Administrator. The security team reports that several users have been compromised due to weak passwords. You need to implement a solution that enforces strong password policies and blocks common passwords. The solution must also provide users with the ability to reset their own passwords securely if they forget them, without requiring help desk intervention. Additionally, you need to configure risk-based Conditional Access policies to block sign-ins from anonymous IP addresses and require MFA for high-risk sign-ins. You have the following options: A. Configure password protection in Microsoft Entra ID to enforce a custom banned password list and enable self-service password reset (SSPR) with MFA. Then create Conditional Access policies for sign-in risk and anonymous IP. B. Enable password hash sync and configure pass-through authentication. Create a Conditional Access policy to require MFA for all users. C. Implement Microsoft Entra ID Protection and enable MFA registration policy. Configure password expiration to 90 days. D. Use security defaults in Microsoft Entra ID and enable automatic password rollback. Which option should you choose?

A.Configure password protection with custom banned list, SSPR with MFA, and risk-based Conditional Access policies
B.Enable password hash sync, pass-through authentication, and require MFA for all
C.Implement Identity Protection, enable MFA registration policy, set password expiration to 90 days
D.Use security defaults and enable automatic password rollback
AnswerA

This approach combines Azure AD Password Protection custom banned list to block predictable passwords, SSPR with MFA to enable secure self-service recovery, and risk-based Conditional Access policies that require step-up authentication only when sign-in or user risk is elevated. It directly satisfies the requirement for password strength controls, offers a recovery path without helpdesk involvement, and adaptively enforces access based on real-time threat signals.

Why this answer

Option A directly addresses every stated requirement: Microsoft Entra Password Protection with a custom banned password list enforces strong passwords and blocks common ones, SSPR with MFA lets users reset passwords without help desk involvement, and risk-based Conditional Access policies (sign-in risk and anonymous IP) block risky sign-ins and require MFA for high-risk events. This combination uses the Entra ID P2 features already licensed in the E5 tenant.

Exam trap

MS-102 often tests whether candidates conflate authentication methods (password hash sync, pass-through) with password policy enforcement — the trap is selecting an option that addresses identity synchronization instead of password strength and risk-based access control.

How to eliminate wrong answers

Option B is wrong because password hash sync and pass-through authentication are authentication methods for hybrid identity, not password strength enforcement mechanisms — they do nothing to block weak or common passwords, and requiring MFA for all users is broader than the risk-based requirement. Option C is wrong because Identity Protection's MFA registration policy only ensures users register for MFA; it does not enforce password complexity or block common passwords, and setting password expiration to 90 days is a legacy practice that does not improve password strength. Option D is wrong because security defaults are a baseline set of policies for tenants without Conditional Access licensing and cannot be combined with custom risk-based policies; 'automatic password rollback' is not a real Entra ID feature.

166
Multi-Selectmedium

Which TWO actions are required to configure a custom domain for your Microsoft 365 tenant?

Select 2 answers
A.Add an SPF TXT record in the public DNS zone.
B.Add a CNAME record for autodiscover.
C.Add an MX record in the public DNS zone.
D.Add the domain name in the Microsoft 365 admin center.
E.Verify domain ownership by adding a TXT record provided by Microsoft.
AnswersD, E

The first required action is to register the domain with your tenant by navigating to Settings > Domains > Add domain and typing the fully qualified domain name, such as contoso.com. This initiates the Microsoft 365 domain provisioning workflow, enabling you to confirm that you are not using a domain already claimed by another tenant and to receive the verification token. Without this admin-center entry, no verification or DNS setup can proceed.

Why this answer

Adding the custom domain name in the Microsoft 365 admin center is the first step to register the domain with the tenant. Option E is correct because Microsoft requires you to prove ownership of the domain by adding a specific TXT record (or sometimes a CNAME or MX record) to the public DNS zone; this verification step ensures only the domain owner can configure it for the tenant.

Exam trap

The trap here is that candidates often confuse optional service-specific DNS records (like SPF, MX, or autodiscover CNAME) with the mandatory domain ownership verification record, leading them to select A, B, or C instead of the correct verification TXT record option.

167
MCQeasy

Your organization wants to use Microsoft Defender for Office 365 to protect against malicious links and attachments in email. Which Defender plan is required?

A.Microsoft Defender for Office 365 Plan 1.
B.Exchange Online Protection.
C.Microsoft Defender for Endpoint.
D.Microsoft Defender for Office 365 Plan 2.
AnswerA

Microsoft Defender for Office 365 Plan 1 is correct because it includes Safe Attachments and Safe Links, which are the core advanced email protection features. Safe Attachments detonates email attachments in a sandbox to detect malicious behavior, while Safe Links checks URLs at click time against real-time reputation data. Plan 1 also includes enhanced anti-phishing policies and anti-spam capabilities beyond the baseline EOP layer. This makes Plan 1 the minimum license that fulfills the organization's requirement to use Defender for Office 365 for email protection.

Why this answer

Microsoft Defender for Office 365 Plan 1 includes Safe Links and Safe Attachments, which are the specific features required to protect against malicious links and attachments in email. These features scan URLs and attachments in real time to block malicious content before it reaches users.

Exam trap

The trap here is that candidates often assume Plan 2 is required for any advanced protection, but Microsoft specifically designed Plan 1 to cover Safe Links and Safe Attachments, while Plan 2 adds post-breach investigation and automation features.

How to eliminate wrong answers

Option B is wrong because Exchange Online Protection (EOP) provides baseline anti-malware and anti-spam protection but does not include Safe Links or Safe Attachments, which are the advanced protections needed for malicious links and attachments. Option C is wrong because Microsoft Defender for Endpoint is designed to protect devices (endpoints) from threats, not to scan email links and attachments within Microsoft 365. Option D is wrong because Microsoft Defender for Office 365 Plan 2 includes all features of Plan 1 plus additional capabilities like threat investigation and automated response, but Plan 1 alone is sufficient for the stated requirement of protecting against malicious links and attachments.

168
MCQmedium

A compliance officer needs to retain all documents in a SharePoint Online site associated with the Finance department for 7 years, and after that automatically delete them. During the retention period, users must not be able to edit or delete the documents. Which solution should they use?

A.Create a retention policy scoped to the site with 'Retain as records' action
B.Create a retention label with 'Retain as regulatory records' and publish it to the site, then use auto-apply based on site location
C.Create a sensitivity label with 'Retain as records' and apply it manually
D.Create a litigation hold for the site
AnswerB

A regulatory records label is the only way to make content both uneditable and undeletable; publishing the label to the site makes it available, and an auto-apply policy scoped by site location automatically assigns it to every document, eliminating reliance on manual user action. Once applied, the label blocks editing and deletion by users and even administrators, and the retention period cannot be shortened. This fully satisfies the compliance requirement for retaining all documents with record integrity.

Why this answer

A retention label with 'Retain as regulatory records' locks the document against editing or deletion during the retention period, and auto-applying the label based on site location ensures all documents in the Finance site inherit the 7-year retention and automatic deletion. This meets the compliance officer's requirement for immutable retention and automatic disposal without manual user intervention.

Exam trap

The trap here is confusing 'Retain as records' (which only prevents deletion after the retention period) with 'Retain as regulatory records' (which prevents editing and deletion during the entire retention period), leading candidates to incorrectly choose Option A.

How to eliminate wrong answers

Option A is wrong because a retention policy with 'Retain as records' action does not prevent users from editing or deleting documents during the retention period; it only prevents deletion after the retention period ends. Option C is wrong because a sensitivity label with 'Retain as records' is not a valid construct; sensitivity labels manage sensitivity and protection, not retention, and manual application does not guarantee all documents are covered. Option D is wrong because a litigation hold preserves documents indefinitely (until the hold is released) and does not enforce a specific 7-year retention period or automatic deletion; it also does not prevent editing, only deletion.

169
MCQeasy

Your company is implementing Microsoft Purview Records Management. You need to ensure that invoices are retained for seven years after they are paid, and then automatically deleted. Which type of label should you create?

A.Disposition review label assigned to invoices
B.Retention policy applied to all documents in SharePoint
C.Retention label with disposition review after the trigger event
D.Sensitivity label with auto-labeling
AnswerC

Retention labels can start retention from a trigger event and then dispose.

Why this answer

A retention label with a disposition review after a trigger event can automate deletion after a specified period (7 years) triggered by an event (invoice payment). Option A is incorrect because a disposition review label requires manual review before deletion, whereas the requirement is automatic deletion. Option B is incorrect because a retention policy applies to all documents in a location and cannot be scoped to specific items based on metadata like payment date.

Option D is incorrect because sensitivity labels are for classification and protection, not retention management.

170
MCQeasy

An administrator wants to configure the company's organization profile in Microsoft 365, including the display name, technical contact, and privacy settings. Where should the administrator go in the Microsoft 365 admin center?

A.User management > Active users
B.Org settings > Organization profile
C.Setup > Onboarding
D.Billing > Licenses
AnswerB

Org settings > Organization profile is the dedicated location in the Microsoft 365 admin center for configurating the identity of the organization itself, not individual users. Here you can edit the organization display name, address, technical contact, privacy contact, and release preferences, and these values are used across Microsoft 365 services such as Teams, Exchange, and compliance. As the central repository for these tenant-level attributes, this page satisfies the requirement to configure the company's organization profile.

Why this answer

The organization profile, which includes the display name, technical contact, and privacy settings, is managed under 'Org settings' in the Microsoft 365 admin center. Specifically, the 'Organization profile' tab within 'Org settings' provides the interface to update these tenant-wide properties, such as the organization's display name (used in Microsoft 365 services and notifications) and the technical contact email (used for service communications). This is the correct location because these settings are tenant-level configurations, not user-specific or billing-related.

Exam trap

The trap here is that candidates often confuse 'Org settings' with 'Setup' or 'User management', mistakenly thinking that tenant-wide profile settings are part of user management or initial onboarding wizards, when in fact they are a distinct configuration area under 'Org settings'.

How to eliminate wrong answers

Option A is wrong because 'User management > Active users' is for managing individual user accounts, passwords, and licenses, not tenant-wide organization profile settings like the display name or technical contact. Option C is wrong because 'Setup > Onboarding' provides guided wizards for initial tenant setup and migration tasks, but does not include the organization profile settings; those are under 'Org settings'. Option D is wrong because 'Billing > Licenses' is for managing subscription licenses and billing details, not for configuring the organization's display name, technical contact, or privacy settings.

171
MCQmedium

Your organization's Microsoft Intune environment enforces device compliance policies for iOS devices. You need to ensure that only devices with a passcode that is at least 6 characters and have jailbreak detection enabled are considered compliant. What should you configure?

A.Configure a conditional access policy to require compliant devices.
B.Create a device configuration profile for iOS with the required settings.
C.Create an app protection policy for iOS to require passcode.
D.Create a device compliance policy for iOS with required passcode length and jailbreak detection.
AnswerD

A device compliance policy in Microsoft Intune is specifically designed to define the rules and settings that devices must meet to be considered compliant. By configuring passcode length and jailbreak detection for iOS, the policy evaluates these conditions and reports a compliant or noncompliant status. This compliance state can then be consumed by conditional access policies to enforce access controls. Therefore, this is the correct mechanism to define the required security conditions.

Why this answer

Device compliance policies in Microsoft Intune define the rules that devices must meet to be considered compliant, such as minimum OS version, passcode length, and jailbreak detection. Option D correctly specifies creating a compliance policy for iOS that requires a passcode of at least 6 characters and enables jailbreak detection, which directly enforces the stated requirements. Compliance policies are evaluated before granting access, and non-compliant devices can be blocked or marked for remediation.

Exam trap

The trap here is that candidates often confuse device compliance policies (which enforce device-level security requirements) with conditional access policies (which use compliance results to control access) or device configuration profiles (which push settings but do not evaluate compliance).

How to eliminate wrong answers

Option A is wrong because a conditional access policy requires compliant devices but does not define the compliance rules themselves; it references an existing compliance policy. Option B is wrong because a device configuration profile manages device settings (e.g., Wi-Fi, VPN, restrictions) but does not enforce compliance checks like passcode length or jailbreak detection. Option C is wrong because an app protection policy manages data protection at the app level (e.g., requiring a PIN for app access) and does not evaluate device-level compliance attributes such as jailbreak status or system passcode length.

172
MCQmedium

A company uses Microsoft Entra ID P2 licenses. They want to require multi-factor authentication (MFA) for all users when accessing the Azure Management portal, but only from devices that are not marked as compliant. Additionally, a group named 'BreakGlass' must be excluded from this requirement. Which Conditional Access policy configuration should be applied?

A.Assign to 'All users', condition: 'Device state (preview) is not compliant', grant: 'Require MFA', exclude: 'BreakGlass group'
B.Assign to 'All users', condition: 'Sign-in risk is medium or higher', grant: 'Require MFA', exclude: 'BreakGlass group'
C.Assign to 'All users', condition: 'Client apps: Browser and Mobile apps', grant: 'Block access', exclude: 'BreakGlass group'
D.Assign to 'All users', condition: 'Device platform: Android, iOS, Windows, macOS', grant: 'Require MFA', exclude: 'BreakGlass group'
AnswerA

This configuration correctly targets non-compliant devices using the Device state condition, which checks the compliance status reported by Intune. When a device is not compliant, the policy requires MFA for access to the Azure Management portal, adding an extra security layer. Excluding the BreakGlass group preserves emergency access accounts from being locked out by this policy, which is a standard best practice in Conditional Access design.

Why this answer

It directly maps the requirement: assign the policy to 'All users', use the 'Device state (preview) is not compliant' condition to target only non-compliant devices, grant 'Require MFA' for the Azure Management portal (selected via the 'Cloud apps' condition), and exclude the 'BreakGlass' group. This ensures MFA is enforced only when accessing the Azure Management portal from non-compliant devices, while break-glass accounts are exempt.

Exam trap

The trap here is confusing 'Device state (preview) is not compliant' with other conditions like 'Sign-in risk' or 'Device platform', leading candidates to pick options that target risk levels or OS types instead of the specific compliance status required.

How to eliminate wrong answers

Option B is wrong because 'Sign-in risk is medium or higher' targets risky sign-ins, not device compliance; this would require Azure AD Identity Protection and does not address the device compliance condition. Option C is wrong because 'Client apps: Browser and Mobile apps' with 'Block access' would block all access from browsers and mobile apps, not just non-compliant devices, and does not enforce MFA. Option D is wrong because 'Device platform: Android, iOS, Windows, macOS' targets specific operating systems, not device compliance; this would apply MFA to all devices of those platforms regardless of compliance status.

173
Multi-Selecteasy

Which TWO features in Microsoft Defender for Office 365 help protect against zero-day malware in email attachments?

Select 2 answers
A.Safe Attachments
B.Mail flow rules
C.Anti-spam policies
D.Anti-phishing policies
E.Zero-hour auto purge (ZAP)
AnswersA, E

Safe Attachments routes email attachments to a hypervisor-isolated detonation chamber where files are opened and executed in a virtual environment to observe behavioral indicators. The resulting signals, combined with global threat intelligence, identify zero-day malware and trigger actions such as blocking, replacing, or alerting before delivery to the user.

Why this answer

Safe Attachments (Option A) is correct because it uses a detonation chamber environment to open email attachments in a virtualized sandbox, analyzing behavior for zero-day malware before delivery. This process catches unknown threats by executing the attachment and observing malicious actions, unlike signature-based detection.

Exam trap

The trap here is that candidates confuse Zero-hour auto purge (ZAP) as a proactive protection feature, when it is actually a reactive remediation tool that acts on already-delivered messages, not a prevention mechanism for zero-day malware in attachments.

174
MCQhard

A security administrator needs to create an automated investigation and response (AIR) playbook that automatically isolates a device whenever a high-severity alert from Microsoft Defender for Endpoint is generated. The playbook should run without requiring manual approval. Which capability in Microsoft 365 Defender should the administrator configure?

A.Automated investigation and response (AIR) action policy
B.Custom detection rule
C.Threat analytics
D.Attack simulation training
AnswerA

AIR action policies allow administrators to define automatic responses to specific alert types. By setting the isolation action for high-severity alerts from Microsoft Defender for Endpoint, the device can be isolated automatically without manual intervention.

Why this answer

Automated Investigation and Response (AIR) action policies in Microsoft 365 Defender allow administrators to define automated remediation actions—such as device isolation—that execute automatically when specific alert conditions are met, without requiring manual approval. The policy can be configured to trigger on high-severity alerts from Microsoft Defender for Endpoint, enabling fully automated containment of compromised devices.

Exam trap

The trap here is that candidates often confuse custom detection rules (Option B) with automated response capabilities, mistakenly thinking that creating a detection rule can also trigger automatic remediation, when in fact custom detection rules only generate alerts and require an AIR policy or manual action to respond.

How to eliminate wrong answers

Option B is wrong because custom detection rules are used to create custom analytics queries (e.g., using KQL) to detect specific threats or behaviors, but they do not directly configure automated response actions like device isolation; they rely on AIR policies or manual steps for remediation. Option C is wrong because Threat Analytics provides threat intelligence reports, vulnerability assessments, and mitigation recommendations, but it does not include the ability to configure automated response actions or playbooks. Option D is wrong because Attack Simulation Training is a tool for running simulated phishing and attack campaigns to test user awareness, not for automating incident response actions like device isolation.

175
Matchingmedium

Match each PowerShell command to its function in Microsoft 365.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Connects to Azure AD

Connects to Exchange Online

Connects to MS Online (legacy)

Lists mailboxes

Resets a user's password

Why these pairings

Correct matches: Connect-ExchangeOnline for Exchange Online, Get-Mailbox for mailbox properties, Get-MgUser for Azure AD users. Common confusion: mixing Exchange and Azure AD commands.

176
MCQeasy

A user in your organization receives a 'Message blocked' notification when trying to send an email with a credit card number. The DLP policy is configured to block such emails. The user claims the credit card number is a valid test number used for training. What should you do to allow the email while maintaining security?

A.Configure a policy tip to allow override with a business justification.
B.Exclude the user from the DLP policy.
C.Disable the DLP policy temporarily.
D.Add the user to the DLP policy's super user group.
AnswerA

Configuring a DLP policy tip to allow an override with a business justification enables the user to send the blocked message while the event is recorded in the audit log and DLP reports. This preserves the policy for all other users and content, and provides a controlled, reviewable exception for legitimate business needs. Unlike broader changes, this is the intended mechanism to balance productivity with data protection.

Why this answer

Configuring a policy tip with override allows the user to justify the override with a business justification, which is audited. This maintains security by notifying the user and recording the override for compliance. Option B (excluding the user) removes DLP protection entirely for that user, which is insecure.

Option C (disabling the policy) disables protection for all users. Option D (adding to super user group) bypasses all DLP checks for the user, which is too permissive.

177
Multi-Selectmedium

Your organization has a Microsoft 365 E5 tenant with Microsoft Defender for Cloud Apps. You need to discover and control the use of unsanctioned cloud apps. Which TWO actions should you take? (Choose two.)

Select 2 answers
A.Define sanctioned and unsanctioned app categories in Microsoft Defender for Cloud Apps
B.Deploy Microsoft Purview Data Loss Prevention policies
C.Configure Microsoft Entra ID App Registrations to log app usage
D.Use Cloud Discovery in Microsoft Defender for Cloud Apps to analyze traffic logs
E.Create a Conditional Access policy to block all unsanctioned apps
AnswersA, D

Sanctioned and unsanctioned app tags let Defender for Cloud Apps apply governance actions such as blocking or unsanctioning, converting discovery data into enforcement. Without these categories, discovered apps cannot be controlled, which the scenario explicitly requires.

Why this answer

Option D is correct because Cloud Discovery in Microsoft Defender for Cloud Apps is the feature that ingests and analyzes traffic logs (from firewalls, proxies, or Defender for Endpoint) to identify which cloud apps are being used in the organization, which is the required first step for discovering unsanctioned apps. Option A is correct because after discovery, you use the app catalog to tag apps as Sanctioned or Unsanctioned (and assign categories/risk scores), which is how Defender for Cloud Apps enforces the governance decision and drives downstream controls like blocking or alerting. Option B is not correct because Microsoft Purview DLP policies protect sensitive data in sanctioned workloads; they do not discover or sanction/unsanction cloud apps.

Option C is not correct because Entra ID App Registrations are for registering and permissioning your own applications with the identity platform, not for logging or discovering third-party cloud app usage. Option E is not correct because Conditional Access cannot target 'all unsanctioned apps' generically; enforcement against unsanctioned apps is done via Defender for Cloud Apps app governance and Conditional Access App Control (session/access policies) after apps are tagged, not by a blanket CA policy.

Exam trap

The trap here is that candidates often confuse Conditional Access policies with the ability to block unsanctioned apps, but Conditional Access requires the app to be registered in Entra ID and cannot discover or block apps that are not already known to the tenant.

178
MCQeasy

Your organization needs to prevent users from sharing documents containing personally identifiable information (PII) with external users. You have Microsoft Purview Data Loss Prevention (DLP) deployed. What should you configure?

A.Apply a sensitivity label that blocks external sharing.
B.Create a DLP policy that detects PII and restricts sharing to external users.
C.Configure a conditional access policy in Microsoft Entra ID to block external sharing.
D.Enable auditing for all document sharing activities.
AnswerB

A DLP policy scoped to the PII sensitive information type inspects documents and enforces restrictions when external sharing is attempted. Microsoft Purview evaluates the content against that classifier and blocks or warns on the sharing action, directly satisfying the requirement to stop PII leaving to external users.

Why this answer

Microsoft Purview DLP is specifically designed to detect sensitive information types (like PII) in documents and apply protective actions, such as blocking external sharing. A DLP policy can be scoped to locations like SharePoint, OneDrive, Exchange, and Teams, and can enforce rules that prevent users from sharing content containing PII with external users. This directly addresses the requirement by combining detection and enforcement.

Exam trap

MS-102 often tests the distinction between DLP and sensitivity labels, where candidates might think a sensitivity label alone can block external sharing, but DLP is required for content-based enforcement.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are primarily for classification and protection (e.g., encryption), but they do not inherently block external sharing; labels can be used with DLP, but alone they do not enforce sharing restrictions. Option C is wrong because conditional access policies in Microsoft Entra ID control access to cloud apps based on conditions like user, device, and location, but they do not inspect document content for PII or block sharing actions. Option D is wrong because enabling auditing only provides visibility into sharing activities; it does not prevent or block the sharing of PII.

179
MCQeasy

You are configuring Microsoft Entra ID to allow external users from a partner organization to access a specific SharePoint Online site. You need to ensure that the external users authenticate using their own corporate credentials and are automatically invited when they first access the resource. What should you configure?

A.Microsoft Entra External ID (B2C)
B.Microsoft Entra B2B direct connect
C.Microsoft Entra entitlement management access packages
D.Microsoft Entra B2B collaboration with manual invitation
AnswerC

Microsoft Entra entitlement management access packages are the correct solution because they enable admins to create cataloged resource collections—such as groups, applications, and SharePoint sites—and define policies that automatically invite external users, including B2B collaboration invitations when access is approved. These policies enforce access requirements, approval workflows, time-limited assignments, and recurring access reviews, providing full lifecycle governance for external users. This automation and centralized management distinguish it from manual invitation methods.

Why this answer

Microsoft Entra entitlement management access packages allow you to create a policy that automatically sends an invitation to external users when they request access to a resource, such as a SharePoint Online site. This policy can be configured to require that external users authenticate using their own corporate credentials (via their home tenant) and be automatically added to the resource upon first access, without manual invitation. Entitlement management integrates with B2B collaboration under the hood, but adds the automation and approval workflows needed for this scenario.

Exam trap

The trap here is that candidates confuse Microsoft Entra B2B collaboration (which requires manual invitation) with entitlement management access packages (which automate the invitation and access lifecycle), or they incorrectly assume B2B direct connect can be used for SharePoint Online site access when it is actually limited to Teams Connect shared channels.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra External ID (B2C) is designed for consumer-facing identity management (social or local accounts), not for enabling partner organizations to use their own corporate credentials for resource access. Option B is wrong because Microsoft Entra B2B direct connect is used for establishing mutual trust between two tenants for real-time collaboration (e.g., Teams Connect shared channels), but it does not support automatic invitation or access package-based provisioning for SharePoint Online sites. Option D is wrong because Microsoft Entra B2B collaboration with manual invitation requires an admin to manually send an invitation email or CSV upload, which does not meet the requirement for automatic invitation when users first access the resource.

180
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You need to generate alerts when a user downloads a large number of files from Microsoft SharePoint Online in a short period. What should you create?

A.App Discovery policy
B.Activity policy
C.Anomaly Detection policy
D.Cloud Discovery policy
AnswerB

An Activity policy is the correct choice because it gives you full control to create a conditional rule that matches a specific activity, such as downloading a file, and then combines it with parameters like the user, device, IP address, or even a repeated-activity threshold. You can set the policy to trigger when a user performs more than a defined number of downloads within a short period, which directly detects mass download behavior. This is the standard mechanism in Defender for Cloud Apps for defining custom, business-specific activity monitoring.

Why this answer

Activity policies in Defender for Cloud Apps allow you to create custom rules to detect specific activities like mass download. Option A (App Discovery policy) is used to discover apps in use in your organization. Option C (Anomaly Detection policy) is for pre-built anomalies.

Option D (Cloud Discovery policy) is for shadow IT.

181
MCQeasy

Your company is implementing Microsoft 365 Copilot for Microsoft 365. You need to ensure that Copilot can access data from across the organization, but only for users who have the appropriate permissions. What is the primary security boundary for Copilot data access?

A.Microsoft 365 permissions and sensitivity labels
B.A dedicated Copilot security group in Microsoft Entra ID
C.Microsoft Purview Information Protection labels
D.The geographic location of the data
AnswerA

Copilot honours the signed-in user's existing Microsoft 365 permissions and sensitivity labels, so it only surfaces content that user can already access. This permission-trimming model is the primary boundary, ensuring no oversharing occurs beyond each user's granted entitlements.

Why this answer

Microsoft 365 Copilot respects the existing Microsoft 365 permissions and sensitivity labels as its primary security boundary. Copilot only surfaces data that the signed-in user already has permission to access, and sensitivity labels govern how that data can be used or shared. This means Copilot inherits the tenant's existing security model rather than introducing a separate one.

Exam trap

MS-102 often tests the misconception that Copilot requires a new security group or that Purview labels alone define access — the correct answer is that Copilot inherits existing Microsoft 365 permissions and sensitivity labels.

How to eliminate wrong answers

Option B is wrong because there is no dedicated Copilot security group in Microsoft Entra ID that acts as the data-access boundary — Copilot uses the user's existing Microsoft 365 permissions. Option C is wrong because Microsoft Purview Information Protection labels are a subset of the broader permissions and sensitivity label model; they are not the primary boundary by themselves, and the question asks for the primary boundary which includes Microsoft 365 permissions. Option D is wrong because geographic location of data affects data residency and compliance, not the per-user access boundary that Copilot enforces.

182
MCQhard

Refer to the exhibit. You are reviewing an app registration in Microsoft Entra ID for the Microsoft Teams Admin Center. The permission shown is for another resource. What is the consequence of this permission configuration?

A.The app can access Microsoft Graph data without a signed-in user, and admin consent is required
B.The app can only be used by users who have consented to the permission
C.The app can access Teams data but not other Microsoft 365 data
D.The app can access Microsoft Graph on behalf of the signed-in user only
AnswerA

Application permissions (indicated by the Role type) allow the app to authenticate as its own identity, not any user, and call Microsoft Graph for tenant-wide data such as Exchange mail or Teams resources. Because these permissions are not restricted to a single user, AAD requires a tenant administrator to grant consent, effectively pre-approving the app for the entire organization, and each such permission exposes broad, high-privilege capabilities that should be vetted carefully.

Why this answer

The exhibit shows an application permission (not a delegated permission) for Microsoft Graph, which means the app can access data without a signed-in user. Admin consent is required because application permissions grant tenant-wide access and cannot be consented to by individual users. This is why option A is correct.

Exam trap

Microsoft often tests the distinction between delegated permissions (requiring user consent and acting on behalf of a user) and application permissions (requiring admin consent and acting without a user), and the trap here is that candidates may confuse the 'signed-in user' requirement with delegated permissions, incorrectly assuming the app needs user consent or can only run with a user present.

How to eliminate wrong answers

Option B is wrong because application permissions do not require per-user consent; they require tenant-wide admin consent, and the app can be used by any user once admin consent is granted. Option C is wrong because the permission is for Microsoft Graph, which provides access to a broad range of Microsoft 365 data beyond just Teams, including Exchange, SharePoint, and more. Option D is wrong because application permissions are not delegated; they allow the app to act as itself without any signed-in user context, unlike delegated permissions which operate on behalf of the signed-in user.

183
Multi-Selecthard

Which THREE conditions must be met for a tenant-to-tenant migration of SharePoint Online content?

Select 3 answers
A.The destination site collection or OneDrive must already exist in the target tenant.
B.Cross-tenant trust must be established or a third-party migration tool must be used.
C.The source user performing the migration must be a global admin in the target tenant.
D.The target tenant must have an active Microsoft 365 subscription.
E.Both tenants must have at least one user with PowerShell access.
AnswersA, B, D

The destination site collection or OneDrive container must be provisioned and exist in the target tenant before the migration runs. Content is copied into an existing container; neither SharePoint nor OneDrive migration creates the target site automatically. For OneDrive, the destination user must have a licensed OneDrive site, and for SharePoint the target site collection must already be created in the appropriate location.

Why this answer

SharePoint Online tenant-to-tenant migration requires the destination site collection or OneDrive to already exist in the target tenant. The migration process copies content into a pre-provisioned container; it does not create the site or OneDrive automatically. This ensures that the target structure is ready to receive the migrated data without requiring dynamic provisioning during the migration.

Exam trap

The trap here is that candidates often assume global admin privileges are required across both tenants for migration, but in reality, SharePoint admin or site collection admin permissions suffice, and PowerShell access is not a prerequisite.

184
MCQeasy

You are a Microsoft 365 administrator for a company that uses Microsoft Defender XDR. A security analyst needs to view a unified list of incidents and alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Defender for Identity. Where should the analyst go to see this unified view?

A.Microsoft 365 Defender portal (security.microsoft.com) under Incidents.
B.Azure Sentinel (azure.microsoft.com/services/azure-sentinel) under Incidents.
C.Microsoft Defender for Endpoint portal (securitycenter.windows.com) under Alerts.
D.Microsoft 365 compliance center (compliance.microsoft.com) under Alerts.
AnswerA

The Microsoft 365 Defender portal at security.microsoft.com provides a unified incidents queue that aggregates alerts from Microsoft Defender for Endpoint, Office 365, Identity, and Cloud Apps. This is the central location for cross-domain incident management, meeting the analyst's need for a unified view.

Why this answer

The Microsoft 365 Defender portal at security.microsoft.com is the centralized console for Microsoft Defender XDR. It aggregates alerts and incidents from Defender for Endpoint, Office 365, Identity, and Cloud Apps into a single queue, enabling analysts to investigate and respond across domains without switching portals.

Exam trap

The trap here is thinking that the individual Defender portals or Azure Sentinel provide the native unified incident view; only the Microsoft 365 Defender portal aggregates incidents across all Defender XDR workloads out of the box.

185
Matchingmedium

Match each Microsoft 365 threat scenario to the appropriate protection.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Anti-phishing policy in Defender for Office 365

Safe Attachments policy

Safe Links policy

Identity Protection and Conditional Access

Data Loss Prevention policy

Why these pairings

Correct matches: Phishing links → Safe Links; Malware attachments → Safe Attachments; Data leaks → DLP; Ransomware → Anti-ransomware policies. Common mistakes include confusing Safe Links with Safe Attachments and DLP with Defender protections.

186
MCQhard

You manage a Microsoft 365 tenant for a multinational corporation. You need to implement Microsoft Purview Information Protection to automatically classify and protect documents containing credit card numbers. The solution must apply encryption automatically when a document is saved to SharePoint Online. What should you do?

A.Create an auto-labeling policy in Microsoft Purview that uses a sensitivity label configured with encryption.
B.Create a DLP policy in Microsoft Purview that blocks sharing of documents containing credit card numbers.
C.Configure client-side labeling via Microsoft 365 Apps to prompt users to label documents.
D.Set a default sensitivity label for SharePoint Online document libraries.
AnswerA

Auto-labelling policies scan SharePoint Online content and apply sensitivity labels automatically, satisfying the requirement that encryption be applied on save. The label's encryption setting enforces protection, while the policy's condition detects credit card numbers via a sensitive info type, removing any need for manual user action.

Why this answer

To automatically classify and protect documents containing credit card numbers with encryption when saved to SharePoint Online, you should create an auto-labeling policy in Microsoft Purview that uses a sensitivity label configured with encryption. Auto-labeling policies can detect sensitive information types (e.g., credit card numbers) and automatically apply the label, which enforces encryption.

Exam trap

MS-102 often tests the confusion between DLP policies (which block actions) and auto-labeling policies (which classify and protect), leading candidates to choose DLP when encryption is required.

How to eliminate wrong answers

Option B is wrong because a DLP policy blocks sharing but does not apply encryption or classification; it only prevents certain actions. Option C is wrong because client-side labeling prompts users to label manually, which is not automatic and relies on user action. Option D is wrong because setting a default sensitivity label for SharePoint document libraries applies the label to all documents in the library, not based on content, and may not enforce encryption for specific sensitive data.

187
MCQhard

You are a Microsoft 365 administrator for Contoso Pharmaceuticals, which uses Microsoft Entra ID P2. The company has a partnership with a research firm that needs access to a specific set of SharePoint Online sites and a custom line-of-business application. The partners must authenticate by using their own Microsoft Entra ID credentials. You need to provide access while ensuring that the partners' access is reviewed every quarter and that they can request access through a self-service portal. What should you do?

A.Configure Microsoft Entra B2B collaboration and create an entitlement management access package that includes the SharePoint sites and the application, with a quarterly access review and an external catalog for partner self-service requests.
B.Configure cross-tenant synchronization to synchronize partner users into the tenant and assign them to the resources.
C.Configure a Conditional Access policy that requires MFA for guest users and grants access to the SharePoint sites and application.
D.Configure Microsoft Entra B2B collaboration and create a guest user for each partner, then assign them directly to the SharePoint sites and application.
AnswerA

Entitlement management access packages allow you to bundle resources and configure access reviews on a schedule. By creating an access package with the required resources and a quarterly review, and exposing it through an external catalog, partners can request access via a self-service portal. B2B collaboration lets them use their own credentials, meeting all requirements.

Why this answer

The requirements are for partners to use their own credentials, to access specific resources, to have quarterly access reviews, and to request access via self-service. Entitlement management access packages with B2B collaboration meet all these needs: access packages bundle resources, support external catalogs for self-service, and allow scheduled access reviews. This is the correct solution.

Exam trap

The trap here is assuming that B2B collaboration alone provides governance features like access reviews and self-service portals, when those require entitlement management access packages.

188
MCQhard

You are the Microsoft 365 administrator for a company that uses Microsoft 365 E5. The company has a Microsoft Entra tenant with 10,000 users. You need to ensure that when users sign in to Microsoft 365 from unmanaged devices, they are required to use multi-factor authentication (MFA) and cannot download files from SharePoint Online. Users on managed devices should not be prompted for MFA and should be able to download files. What should you configure?

A.Create a conditional access policy that targets all users and SharePoint Online, set the device state condition to 'Include: Unmanaged', and grant access with 'Require multifactor authentication' and 'Require device to be marked as compliant'.
B.Create a conditional access policy that targets all users and SharePoint Online, set the device state condition to 'Exclude: Unmanaged', and grant access with 'Require multifactor authentication' and 'Require app enforced restrictions'.
C.Create a conditional access policy that targets all users and SharePoint Online, set the device state condition to 'Include: Unmanaged', and grant access with 'Require device to be marked as compliant' and 'Require app enforced restrictions'.
D.Create a conditional access policy that targets all users and SharePoint Online, set the device state condition to 'Include: Unmanaged', and grant access with 'Require multifactor authentication' and 'Require app enforced restrictions'.
AnswerD

This policy applies to unmanaged devices and requires MFA while enabling app enforced restrictions. App enforced restrictions allow SharePoint Online to provide limited access, such as blocking downloads, on unmanaged devices. This meets the requirement for MFA and no downloads on unmanaged devices.

Why this answer

A conditional access policy targeting unmanaged devices with MFA and app enforced restrictions ensures that users on unmanaged devices must use MFA and are subject to restrictions that prevent downloads from SharePoint Online. Managed devices are not targeted by this policy, so they are not prompted for MFA and can download files.

Exam trap

The trap here is confusing app enforced restrictions with device compliance, or incorrectly excluding unmanaged devices when the policy should target them.

189
MCQmedium

An organization wants to configure Self-Service Password Reset (SSPR) for all users. The administrator must ensure that users register two authentication methods: one from the mobile app category (e.g., notification or code) and one from the phone call category (e.g., office phone or mobile phone). Which combination of methods should the administrator select in the SSPR settings?

A.Mobile app notification and Office phone
B.Mobile app code and Security questions
C.Email and Mobile phone
D.Security questions and Office phone
AnswerA

SSPR requires two methods from distinct categories. Mobile app notification belongs to the mobile app category, while office phone belongs to the phone call category, so this pairing satisfies the requirement for one method from each.

Why this answer

The SSPR policy requires users to register two authentication methods from distinct categories. The mobile app notification (from the mobile app category) and office phone (from the phone call category) satisfy this requirement. This combination ensures that users have one method from the mobile app category and one from the phone call category, as specified in the question.

Exam trap

The trap here is that candidates often confuse the 'mobile app' category with 'email' or 'security questions', or assume that 'mobile phone' (which is in the phone call category) counts as a mobile app method, leading them to select combinations that do not meet the category requirement.

How to eliminate wrong answers

Option B is wrong because security questions are not in the phone call category; they belong to the security questions category, so this combination does not include a method from the phone call category. Option C is wrong because email is not in the mobile app category; it belongs to the email category, and mobile phone is in the phone call category, so this combination lacks a method from the mobile app category. Option D is wrong because security questions are not in the mobile app category, and office phone is in the phone call category, so this combination lacks a method from the mobile app category.

190
Multi-Selectmedium

A compliance officer needs to automatically apply a sensitivity label that encrypts documents in SharePoint Online when the documents contain a custom regex pattern (e.g., employee ID). The labeling must occur automatically without requiring user interaction. Which two Microsoft Purview components must be configured? (Select the option that correctly identifies both components.)

Select 1 answer
A.An auto-labeling policy and a sensitivity label with encryption configured
B.Data Loss Prevention (DLP) policy and a sensitivity label
C.retention label and an auto-labeling policy
D.sensitive info type and a sensitivity label
AnswersA

Correct. An auto-labeling policy automatically applies the sensitivity label to documents matching the custom regex pattern, and the sensitivity label with encryption provides the required protection.

Why this answer

Auto-labeling in Microsoft Purview requires three elements: (1) a custom sensitive info type (SIT) defined with the regex pattern (e.g., employee ID), (2) a sensitivity label configured with encryption, and (3) an auto-labeling policy that uses the SIT as a condition to apply the label without user interaction. Option A is incomplete because it omits the custom SIT needed to detect the regex pattern; without it, the auto-labeling policy has no condition to match. Option D includes the SIT and label but lacks the auto-labeling policy, so it cannot apply labels automatically.

The question's framing as 'two components' is flawed; the correct set is the SIT, the label, and the auto-labeling policy.

Exam trap

Candidates often forget that auto-labeling policies require a sensitive info type (SIT) as the detection condition. A custom regex pattern must be defined as a custom SIT; the label and policy alone cannot detect it. Also, DLP policies do not apply sensitivity labels—they only detect and protect/block.

191
MCQhard

Your organization uses Microsoft Defender for Cloud Apps. You want to set up a policy that automatically suspends a user if they download more than 100 files from SharePoint Online within 10 minutes. Which type of policy should you create?

A.Session policy
B.Activity policy
C.File policy
D.App discovery policy
AnswerB

Activity policies monitor user, admin, and sign-in activities for anomalous patterns, such as impossible travel, mass download, or failed sign-ins. When a threshold or heuristic is breached, the policy can automatically trigger a governance action, including suspending the affected user account. This makes the Activity policy the correct option for post-detection user suspension, as it reacts to logged activity rather than controlling the live session.

Why this answer

An Activity policy in Microsoft Defender for Cloud Apps monitors user activities across connected apps and can trigger automated actions, such as suspending a user, when a specific threshold of downloads from SharePoint Online is exceeded within a defined time window. This policy type is designed to detect anomalous behavior patterns like mass file downloads, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates often confuse Activity policies with Session policies, mistakenly thinking session-level controls can enforce download limits, but session policies only act on real-time actions within a single session and cannot trigger user suspension based on aggregated activity history.

How to eliminate wrong answers

Option A is wrong because a Session policy controls real-time user actions during a session (e.g., blocking uploads or requiring authentication) but does not evaluate historical activity counts or trigger user suspension based on past downloads. Option C is wrong because a File policy focuses on scanning files for content, metadata, or sharing permissions, not on monitoring the volume of download activities by a user. Option D is wrong because an App discovery policy analyzes cloud app usage and shadow IT, not user-specific download thresholds within a single app like SharePoint Online.

192
MCQmedium

A compliance officer needs to monitor employee communications across Microsoft Teams and Outlook for potential insider trading, using predefined policies. The solution must detect keywords like 'insider tip' and 'stock' and allow designated reviewers to take action. Which Microsoft Purview solution should the officer use?

A.Communication Compliance
B.Data Loss Prevention
C.eDiscovery (Premium)
D.Records Management
AnswerA

Communication Compliance is a Microsoft Purview solution that provides proactive monitoring of user communications across email, Microsoft Teams, Yammer, and third-party sources. It uses customizable policies and machine learning-based trainable classifiers to detect potential regulatory violations—including insider trading, harassment, or conflicts of interest—and then routes alerts for investigation and remediation within the compliance portal. This makes it the correct tool for an ongoing, automated surveillance of employee communications rather than a reactive or archival mechanism.

Why this answer

Communication Compliance is the correct Microsoft Purview solution because it is specifically designed to detect sensitive keywords (e.g., 'insider tip' and 'stock') in Microsoft Teams chats, channel messages, and Outlook emails using predefined or customizable policies. It enables designated reviewers to investigate and take remediation actions such as removing messages or escalating for legal review, directly addressing the insider trading monitoring requirement.

Exam trap

The trap here is that candidates confuse Communication Compliance with Data Loss Prevention because both involve policy-based detection, but DLP is about preventing data exfiltration, not monitoring for insider trading keywords with reviewer workflows.

How to eliminate wrong answers

Option B (Data Loss Prevention) is wrong because DLP focuses on preventing unauthorized sharing of sensitive data (e.g., credit card numbers or PII) by blocking or alerting on outbound content, not on monitoring communications for insider trading keywords or enabling reviewer actions. Option C (eDiscovery Premium) is wrong because eDiscovery is used for legal hold, search, and export of content as evidence in litigation or investigations, not for real-time policy-based monitoring and remediation of communications. Option D (Records Management) is wrong because Records Management deals with classifying, retaining, and disposing of records based on regulatory requirements, not with detecting specific keywords in live communications or enabling reviewer workflows.

193
MCQmedium

A company has a hybrid identity with password hash synchronization. They want to ensure that any user whose account is disabled in on-premises Active Directory is automatically prevented from signing in to Microsoft 365. How can this be achieved?

A.Ensure Microsoft Entra Connect is configured to synchronize the disabled status; this happens automatically.
B.Create a dynamic group based on accountEnabled attribute and apply a Conditional Access policy to block access.
C.Run a PowerShell script daily to disable matching accounts in Microsoft Entra ID.
D.Enable cloud HR provisioning.
AnswerA

Microsoft Entra Connect's default synchronization rules automatically map the on-premises Active Directory userAccountControl disabled bit to the accountEnabled attribute in Entra ID. When you disable an on-premises user, the next delta sync changes the cloud account's accountEnabled to false, which immediately prevents that user from obtaining tokens. No additional configuration is required, and password hash synchronization remains unaffected because status and password are separate attributes.

Why this answer

Microsoft Entra Connect (formerly Azure AD Connect) by default synchronizes the `userAccountControl` attribute from on-premises Active Directory, which includes the disabled status (bit 2, ACCOUNTDISABLE). When an on-premises user account is disabled, the corresponding `accountEnabled` attribute in Microsoft Entra ID is set to `false`, preventing sign-in to Microsoft 365 without additional configuration.

Exam trap

The trap here is that candidates may overthink the solution and assume additional configuration or scripting is required, when in fact Entra Connect automatically synchronizes the disabled status as part of its default attribute mapping.

How to eliminate wrong answers

Option B is wrong because a dynamic group based on `accountEnabled` attribute cannot be used in a Conditional Access policy to block access; Conditional Access policies apply to users or groups, but the `accountEnabled` attribute is not directly evaluated by Conditional Access, and disabling the account in Entra ID already blocks sign-in. Option C is wrong because running a PowerShell script daily to disable matching accounts in Microsoft Entra ID is unnecessary and introduces latency and potential inconsistency; Entra Connect already synchronizes the disabled status in near real-time (every 30 minutes by default). Option D is wrong because cloud HR provisioning (e.g., Workday or SuccessFactors) is designed for creating and managing user identities from HR systems, not for synchronizing the disabled status from on-premises Active Directory to Microsoft Entra ID.

194
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You want to detect when a user accesses a sanctioned cloud app from an anonymous IP address. What should you configure?

A.Configure an app discovery policy
B.Set up a session policy to block access from anonymous IPs
C.Enable the cloud discovery shadow IT report
D.Create an activity policy in Defender for Cloud Apps
AnswerD

Activity policies in Microsoft Defender for Cloud Apps evaluate user activity against filters such as anonymous IP proxy, generating alerts when a sanctioned app is accessed from an anonymising source. This matches the detection requirement precisely.

Why this answer

An activity policy in Microsoft Defender for Cloud Apps is designed to monitor user activities and generate alerts based on conditions such as anonymous IP address usage. Since the requirement is to detect (not block) access from anonymous IPs, an activity policy with the 'Anonymous IP address' filter is the correct configuration. It leverages the built-in anonymous IP detection in Defender for Cloud Apps.

Exam trap

MS-102 often tests the difference between activity policies (detection/alerting on user actions) and session policies (real-time control of app sessions) — candidates pick session policy because 'anonymous IP' sounds like a blocking condition, but the question asks for detection.

How to eliminate wrong answers

Option A is wrong because an app discovery policy is used to identify shadow IT and unsanctioned apps from traffic logs, not to detect user activity from anonymous IPs. Option B is wrong because a session policy controls real-time session behavior (block/download restrictions) for sanctioned apps, and the requirement is detection, not blocking. Option C is wrong because the cloud discovery shadow IT report identifies unsanctioned apps, not anonymous IP access to sanctioned apps.

195
MCQhard

You manage a Microsoft 365 E5 tenant with Microsoft Entra ID P2. The security team wants to ensure that when a user is assigned the Global Administrator role, the assignment is time-bound, requires approval, and requires multifactor authentication for activation. You need to configure Privileged Identity Management (PIM). Which setting should you configure?

A.In PIM, for the Global Administrator role, configure the role settings to require justification and enable alerts for role activation.
B.In Microsoft Entra ID, create a Conditional Access policy that requires MFA for users assigned the Global Administrator role.
C.In PIM, for the Global Administrator role, set the assignment type to Eligible, configure activation settings to require approval and Azure MFA, and set the maximum activation duration.
D.In PIM, for the Global Administrator role, set the assignment type to Active and configure the assignment to expire after 30 days.
AnswerC

Making the Global Administrator role eligible allows users to activate it on demand. Configuring activation settings to require approval and Azure MFA ensures the activation is controlled and secure. Setting the maximum activation duration makes the assignment time-bound. This combination meets all stated requirements for time-bound, approval-based, and MFA-protected activation.

Why this answer

Privileged Identity Management (PIM) enables just-in-time role activation. To meet the requirements, the Global Administrator role must be assigned as eligible, and the role settings must require approval and Azure MFA for activation, with a maximum activation duration. This ensures time-bound, approved, and MFA-protected access, which is the core purpose of PIM.

Exam trap

The trap here is confusing active assignments with eligible assignments; only eligible assignments require activation, which can then enforce approval and MFA.

196
MCQmedium

Your organization uses Microsoft Entra ID and has a Conditional Access policy that requires MFA for all external users. However, guest users from a partner organization are being blocked when they try to access a SharePoint Online site. You need to ensure that guest users can access the site without being prompted for MFA if they have already satisfied MFA in their home tenant. What should you configure?

A.Disable MFA requirement for guest users in Conditional Access
B.Configure authentication methods policy to accept MFA from external identities
C.Enable the trust MFA for external users setting in cross-tenant access settings
D.Use B2B direct connect instead of B2B collaboration
AnswerC

Enabling the 'Trust MFA for external users' setting in cross-tenant access settings instructs the resource tenant to accept the multifactor authentication claim that a guest user already satisfied in their home Microsoft Entra tenant. This allows the guest to access applications protected by an MFA Conditional Access policy without being prompted again, streamlining the sign-in experience while maintaining a verified MFA state. The setting applies to inbound B2B collaboration access and can be scoped to all external users or specific tenants, precisely matching the scenario of avoiding redundant MFA challenges.

Why this answer

The cross-tenant access settings in Microsoft Entra ID include a 'Trust MFA from external tenants' option. When enabled, this setting allows guest users who have already satisfied MFA in their home tenant to access resources in your tenant without being prompted for MFA again. This respects the partner's MFA claims and avoids redundant authentication, which directly resolves the blocking issue caused by the Conditional Access policy requiring MFA for all external users.

Exam trap

The trap here is that candidates often confuse the 'authentication methods policy' (which governs allowed MFA methods in your tenant) with the cross-tenant trust setting, leading them to choose Option B, when in fact the correct solution is to enable the trust setting in cross-tenant access settings.

How to eliminate wrong answers

Option A is wrong because disabling MFA for guest users in Conditional Access would remove the security requirement entirely, which violates the organization's policy and exposes resources to unauthenticated access. Option B is wrong because the authentication methods policy controls which methods are allowed for MFA in your tenant, not whether MFA claims from external identities are trusted; it does not accept or reject MFA from other tenants. Option D is wrong because B2B direct connect is designed for real-time, unmanaged collaboration (e.g., Teams shared channels) and does not support SharePoint Online site access via invitations; B2B collaboration is the correct model for granting guest users access to SharePoint sites.

197
MCQeasy

As a Microsoft 365 administrator, you need to ensure that sensitive data is not shared externally via email. You configure Data Loss Prevention (DLP) policies in Microsoft Purview. What is the primary purpose of a DLP policy?

A.Prevent users from sending any external email.
B.Block all inbound emails from untrusted domains.
C.Encrypt all outgoing emails automatically.
D.Detect and prevent the sharing of sensitive information via email and other channels.
AnswerD

This is precisely the purpose of Microsoft Purview DLP: it uses sensitive information types, trainable classifiers, and exact data match to detect and prevent the unauthorized sharing of sensitive data across email, SharePoint, OneDrive, Teams, and endpoints. When a policy match occurs, DLP can block transmission, notify users with tips, or restrict access, thereby protecting regulated data such as financial and health information. DLP's scope extends beyond email to multiple channels, making this the accurate description of its core functionality.

Why this answer

Data Loss Prevention (DLP) policies in Microsoft Purview are designed to detect and prevent the sharing of sensitive information via email, Microsoft Teams, SharePoint, and other channels. Option A is incorrect because DLP does not block all external emails; it only blocks specific sensitive data. Option B is incorrect because blocking inbound emails from untrusted domains is typically handled by anti-spam or anti-phishing policies in Exchange Online Protection.

Option C is incorrect because email encryption is provided by Azure Information Protection or Office 365 Message Encryption, not DLP.

198
Multi-Selecthard

Which THREE of the following are valid permissions in Microsoft Entra ID custom roles? (Choose three.)

Select 4 answers
A.microsoft.directory/applications/delete
B.microsoft.directory/applications/credentials/update
C.microsoft.directory/users/update
D.microsoft.directory/roles/assign
E.microsoft.directory/groups/members/update
AnswersA, B, C, E

It is a valid permission for deleting applications.

Why this answer

Option A, microsoft.directory/applications/delete, is a valid permission for deleting applications. Option B, microsoft.directory/applications/credentials/update, is valid for managing application credentials. Option C, microsoft.directory/users/update, is valid for updating user properties.

Option D, microsoft.directory/roles/assign, is not valid; role assignment uses the microsoft.directory/roleAssignments/assign action. Option E, microsoft.directory/groups/members/update, is valid for updating group membership. Therefore, the valid permissions are A, B, C, and E.

Exam trap

The trap is that candidates may think only common permissions like application delete and user update are valid, missing that credentials/update and group members/update are also valid. Additionally, role assignment uses a different path ('roleAssignments') than expected.

199
MCQmedium

Your organization uses Microsoft Entra ID P2 licenses. You need to configure a Conditional Access policy that requires phishing-resistant multifactor authentication (MFA) for all users accessing sensitive applications. Which authentication strength should you select in the policy?

A.Phishing-resistant MFA
B.Passwordless MFA
C.Multifactor authentication
D.No authentication strength
AnswerA

Phishing-resistant MFA is correct because Microsoft Entra ID P2 authentication strength policies can enforce device-bound credential types such as FIDO2 security keys or certificate-based authentication. These methods cryptographically tie the sign-in to the specific relying party and origin, which prevents relay attacks and adversary-in-the-middle phishing. The user proves possession of a private key stored in tamper-resistant hardware, making credentials impossible to replay on a fraudulent site.

Why this answer

The scenario explicitly requires 'phishing-resistant multifactor authentication (MFA).' Microsoft Entra ID authentication strengths allow you to enforce specific authentication methods. The 'Phishing-resistant MFA' strength includes methods like FIDO2 security keys and certificate-based authentication (CBA), which are resistant to phishing attacks. Selecting this strength ensures that only phishing-resistant methods are accepted for the Conditional Access policy.

Exam trap

The trap here is that candidates often confuse 'passwordless MFA' with 'phishing-resistant MFA,' not realizing that passwordless methods like Microsoft Authenticator phone sign-in are not considered phishing-resistant because they can still be intercepted by a sophisticated adversary-in-the-middle attack.

How to eliminate wrong answers

Option B is wrong because 'Passwordless MFA' includes methods like Microsoft Authenticator (phone sign-in) and Windows Hello for Business, which, while passwordless, are not all inherently phishing-resistant (e.g., phone sign-in can still be vulnerable to man-in-the-middle attacks). Option C is wrong because 'Multifactor authentication' is a generic strength that includes any MFA method (e.g., SMS, voice call, OTP), many of which are not phishing-resistant. Option D is wrong because selecting 'No authentication strength' means the policy will not enforce any specific authentication method, leaving the system to use the default MFA settings, which do not guarantee phishing resistance.

200
Multi-Selectmedium

Your organization is implementing a zero-trust security model. Which TWO Microsoft Entra ID features should you enable to enforce least-privilege access and continuous verification?

Select 2 answers
A.Conditional Access
B.Self-service password reset (SSPR)
C.Privileged Identity Management (PIM)
D.Application Proxy
E.Microsoft Entra Join
AnswersA, C

Conditional Access is the core policy engine for zero trust, continuously evaluating signals like user risk, device compliance, location, and session context in real time. It enforces granular access controls—block, require MFA, or restrict session—before and during access, embodying the 'verify explicitly' principle of zero trust. Without it, other security controls lack a unified mechanism to apply context-aware, adaptive policies.

Why this answer

Conditional Access (A) is correct because it enforces least-privilege access by applying policies that require specific conditions (e.g., device compliance, location, risk level) before granting access to resources. It also enables continuous verification by evaluating signals in real time during each authentication request, ensuring that access is revoked if conditions change (e.g., user risk increases). This aligns directly with the zero-trust principle of 'never trust, always verify.'

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) as solely for role activation, but PIM enforces least-privilege by requiring just-in-time (JIT) elevation for admin roles, which is a core zero-trust requirement for privileged access, while Conditional Access handles continuous verification for all users.

201
MCQhard

A company (Contoso) frequently collaborates with a partner company (Fabrikam) via B2B collaboration. Contoso wants to require Fabrikam's guest users to perform MFA using Contoso's MFA policies, ignoring any MFA claims from the Fabrikam home tenant. However, Fabrikam's users already have MFA enabled in their home tenant. What should Contoso configure in their cross-tenant access settings?

A.Set the inbound trust settings to accept MFA claims from Fabrikam
B.Set the inbound trust settings to accept compliant device claims
C.Set the inbound trust settings to block MFA and require Contoso's MFA
D.Disable trust for MFA from the external tenant in the cross-tenant access settings
AnswerD

Disabling trust for MFA from the external tenant prevents Contoso from honoring the MFA claim that Fabrikam issued in its own tenant. As a result, when Fabrikam guest users access Contoso resources, Entra ID treats their session as not having completed MFA and applies Contoso's conditional access policies. This ensures that Contoso's own MFA requirements, whether via conditional access or per-user MFA, are enforced for partner users.

Why this answer

Contoso wants to ignore MFA claims from Fabrikam's home tenant and enforce its own MFA policies on Fabrikam's guest users. In cross-tenant access settings, disabling trust for MFA from the external tenant ensures that Contoso does not honor any MFA claims issued by Fabrikam, thereby requiring Fabrikam's users to perform MFA again according to Contoso's conditional access policies.

Exam trap

The trap here is that candidates may think they need to explicitly 'block MFA' (Option C) rather than understanding that disabling trust for MFA claims achieves the same effect by ignoring the external tenant's MFA, forcing Contoso's own MFA policies to apply.

How to eliminate wrong answers

Option A is wrong because accepting MFA claims from Fabrikam would honor Fabrikam's MFA claims, which is the opposite of what Contoso wants. Option B is wrong because accepting compliant device claims is unrelated to MFA enforcement; it controls device trust, not authentication strength. Option C is wrong because there is no setting to 'block MFA and require Contoso's MFA' in cross-tenant trust settings; the correct mechanism is to disable trust for MFA from the external tenant, which effectively forces Contoso's MFA to be evaluated.

202
Multi-Selecthard

A company experiences a ransomware attack that encrypts files on several endpoints. The security team wants to use automated investigation and response (AIR) capabilities in Microsoft Defender XDR to contain the threat. Which TWO actions can be taken automatically by AIR? (Select TWO.)

Select 2 answers
A.Block the sender's email domain in Defender for Office 365.
B.Remove malicious files detected by Defender for Endpoint.
C.Isolate an affected device from the network.
D.Disable user accounts associated with the attack.
E.Reset user passwords for affected accounts.
AnswersB, C

AIR can automatically remediate endpoint artefacts by removing or quarantining malicious files that Defender for Endpoint detects, directly containing ransomware payloads without analyst intervention. This satisfies the scenario's requirement to contain the threat across affected endpoints.

Why this answer

Option B is correct because Microsoft Defender XDR's automated investigation and response (AIR) can automatically remediate endpoint threats by quarantining or removing malicious files that Defender for Endpoint detects during an investigation. Option C is correct because AIR can automatically isolate an affected device from the network to prevent lateral movement and further compromise while the investigation proceeds. Option A is not an AIR action in this context; blocking a sender's email domain is a manual or policy-driven action in Defender for Office 365, not an automatic endpoint containment response.

Option D is incorrect because disabling user accounts is an identity protection action typically performed manually or via Microsoft Entra ID Protection, not an automatic AIR containment step. Option E is also incorrect because password resets are identity remediation actions handled through Microsoft Entra ID, not automated endpoint containment by AIR.

Exam trap

MS-102 often tests which AIR actions are truly automatic versus which require approval — candidates overestimate AIR's scope and pick identity or email actions that are actually manual or playbook-driven.

203
MCQhard

Your Microsoft 365 tenant contains sensitive financial data that must be retained for 7 years. You configure a retention policy in Microsoft Purview compliance portal. After 7 years, the data is still accessible to users. What is the most likely reason?

A.The retention policy does not include a deletion action.
B.A litigation hold is applied to the data.
C.The retention policy is configured to retain data for 7 years and then delete it.
D.The data is marked as a record and requires disposition review.
AnswerA

A retention policy without a deletion action is configured to only retain content for a specified period. In Microsoft 365, when a policy has only a retention action (no 'Delete items automatically' option selected), items remain indefinitely after the retention period expires. Because the policy never schedules a purge, the sensitive data persists in the tenant even after the retention timeframe elapses. This directly matches the scenario in the question.

Why this answer

A retention policy in Microsoft Purview can be configured to only retain data without a deletion action. If the policy lacks a deletion action, data will be preserved for the specified period but will not be automatically removed after that period expires, leaving it accessible to users. The scenario describes data still being accessible after 7 years, which directly indicates that no deletion action was configured to remove the data at the end of the retention period.

Exam trap

The trap here is that candidates often assume a retention policy automatically deletes data after the retention period ends, but Microsoft Purview requires an explicit deletion action to be configured for automatic removal; otherwise, the data is retained indefinitely.

How to eliminate wrong answers

Option B is wrong because a litigation hold preserves data indefinitely and prevents deletion, but it does not cause data to remain accessible after a retention period ends if the retention policy itself lacks a deletion action; the hold would keep the data, but the core issue is the missing deletion action. Option C is wrong because if the retention policy were configured to retain data for 7 years and then delete it, the data would be automatically removed after 7 years and would not remain accessible to users. Option D is wrong because marking data as a record and requiring disposition review means the data must be manually reviewed and approved before deletion, but this does not automatically keep the data accessible after the retention period; disposition review can delay deletion but does not explain why data remains accessible without any deletion action.

204
MCQeasy

You need to ensure that only users from your organization can access a SharePoint Online site. Which setting should you configure?

A.Set the SharePoint Online external sharing setting to 'Only people in your organization'
B.Create a Conditional Access policy to block external users
C.Configure the Microsoft Entra ID external collaboration settings
D.Modify the site permissions to remove external users
AnswerA

Setting the SharePoint Online external sharing option to 'Only people in your organization' disables all tenant-level external sharing, preventing internal users from creating external sharing links and removing access for any external users via existing links. This tenant-wide setting overrides site-level configurations and is the only way to proactively guarantee that only authenticated users within your Microsoft Entra ID can access sites. This restriction is enforced at the SharePoint service level, so it covers all sites, including those previously configured to allow external access.

Why this answer

The SharePoint Online external sharing setting 'Only people in your organization' explicitly restricts all sharing and access to users who have a valid identity in your Microsoft Entra ID tenant. This setting prevents any external user (including guests) from accessing the site, regardless of how they were invited or authenticated. It is the most direct and effective control for limiting access to internal users only.

Exam trap

The trap here is that candidates often confuse tenant-level external collaboration settings (Microsoft Entra ID) with site-level external sharing settings (SharePoint Online), assuming that blocking external users in Entra ID automatically restricts access to SharePoint sites, which is not the case because SharePoint has its own independent sharing controls.

How to eliminate wrong answers

Option B is wrong because a Conditional Access policy can block external users from signing in, but it does not prevent external users who are already guests from accessing the site if they have been granted permissions through sharing. Option C is wrong because configuring the Microsoft Entra ID external collaboration settings controls the overall guest invitation behavior for the tenant, but it does not override the per-site external sharing setting; a site could still be shared externally if its own sharing setting allows it. Option D is wrong because modifying site permissions to remove external users is a manual, reactive approach that does not prevent future external sharing or access; it does not enforce a policy that blocks external users from being added or accessing the site.

205
MCQhard

A security analyst wants to create a custom detection rule that triggers when a device communicates with a new, unclassified IP address that has been flagged by Microsoft threat intelligence as potentially malicious. The rule should run every hour and create an incident if more than 5 such communications from the same device occur within a 24-hour window. Which advanced hunting tables should be joined in the KQL query for this rule?

A.DeviceNetworkEvents and IPReputation
B.DeviceProcessEvents and AlertInfo
C.DeviceFileEvents and DeviceIPInfo
D.EmailEvents and DeviceNetworkEvents
AnswerA

DeviceNetworkEvents records network connections including remote IPs. IPReputation provides Microsoft's threat intelligence score for IP addresses, allowing the rule to filter for connections to flagged IPs. These tables can be joined on the RemoteIP column.

Why this answer

The rule requires detecting network communications to potentially malicious IP addresses, which involves joining `DeviceNetworkEvents` (which logs network connections from devices) with `IPReputation` (which contains Microsoft's threat intelligence classifications for IP addresses). This join allows the query to filter for communications where the destination IP is flagged as malicious and then aggregate by device to trigger an incident when the count exceeds 5 within a 24-hour window.

Exam trap

The trap here is that candidates often confuse `DeviceNetworkEvents` with `DeviceProcessEvents` or `DeviceFileEvents`, mistakenly thinking process or file events can indicate network communication patterns, or they overlook that `IPReputation` is the specific table providing threat intelligence classification for IP addresses.

How to eliminate wrong answers

Option B is wrong because `DeviceProcessEvents` logs process creation events, not network communications, and `AlertInfo` contains metadata about alerts, not IP reputation data; this combination cannot detect communications with malicious IPs. Option C is wrong because `DeviceFileEvents` logs file creation/modification events, not network connections, and `DeviceIPInfo` provides IP configuration details (like DHCP leases) rather than threat intelligence reputation scores. Option D is wrong because `EmailEvents` tracks email delivery and phishing events, not device-level network communications, and joining it with `DeviceNetworkEvents` would not provide the required IP reputation data from Microsoft threat intelligence.

206
MCQmedium

A company wants to implement just-in-time (JIT) privileged access for the Security Administrator role. Users must be able to activate the role with a business justification, and the activation must be approved by a designated group of approvers. The role activation should expire after 4 hours. Which Privileged Identity Management (PIM) configuration should the administrator modify?

A.Role settings for the Security Administrator role
B.Assignments (Eligible) for the Security Administrator role
C.Assignments (Active) for the Security Administrator role
D.Notifications settings under PIM
AnswerA

Role settings for the Security Administrator role in Privileged Identity Management (PIM) define the activation policy for that role. This is the primary control point for just-in-time (JIT) access because it specifies the maximum activation duration, whether an approval workflow is required, and whether users must provide a justification and pass Microsoft Entra MFA. Without properly configured role settings, eligible users could activate with weak or no controls, so this is the correct place to enforce JIT.

Why this answer

To configure just-in-time (JIT) privileged access with approval, expiration, and justification requirements, you must modify the Role settings for the Security Administrator role in Privileged Identity Management (PIM). Role settings control activation parameters such as maximum activation duration (4 hours), whether approval is required, and whether justification is mandatory. This is the only place where these activation policies are defined.

Exam trap

The trap here is that candidates confuse 'assignments' (who can use the role) with 'role settings' (how the role can be activated), leading them to choose Eligible assignments instead of Role settings when asked about activation policies like duration, approval, or justification.

How to eliminate wrong answers

Option B is wrong because Eligible assignments define which users are allowed to activate the role, not the activation policies like duration, approval, or justification. Option C is wrong because Active assignments grant permanent, always-on access without requiring activation, which defeats the purpose of JIT and approval. Option D is wrong because Notifications settings only control who receives email alerts for PIM events (e.g., activation, approval), not the activation rules themselves.

207
MCQmedium

A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a device establishes a network connection to an IP address that has been recently observed in threat intelligence feeds as a new, malicious command-and-control server. The rule should analyze network communication events. Which advanced hunting table should be the primary data source for the Kusto Query Language (KQL) query?

A.DeviceProcessEvents
B.DeviceNetworkEvents
C.EmailEvents
D.AlertEvidence
AnswerB

DeviceNetworkEvents is the correct table because it records actual network connection events, including TCP, UDP, and ICMP traffic, with fields such as RemoteIP, RemotePort, LocalIP, LocalPort, and Protocol. A custom detection rule can filter directly on RemoteIP to flag connections to a known malicious IP address. It also provides DeviceId and other machine identifiers, enabling correlation with process and user context. This table is specifically designed for hunting network-based threats, making it the appropriate choice for IP-based detection rules.

Why this answer

DeviceNetworkEvents is the correct primary data source because it captures network connection events, including source and destination IP addresses, ports, and protocols. To detect a device connecting to a newly observed malicious command-and-control server, the KQL query must analyze network communication events, which are stored exclusively in this table.

Exam trap

Microsoft often tests the confusion between process-level and network-level tables, leading candidates to choose DeviceProcessEvents because they mistakenly think process creation is the primary indicator of malicious network activity.

How to eliminate wrong answers

Option A is wrong because DeviceProcessEvents logs process creation and execution events, not network connections; it cannot provide IP address or port information. Option C is wrong because EmailEvents tracks email delivery and phishing events, not device-level network connections to external IPs. Option D is wrong because AlertEvidence contains evidence linked to existing alerts, not raw network communication logs; it is used for investigating alerts, not as a primary source for custom detection rules.

208
MCQmedium

You are reviewing a conditional access policy in Microsoft Entra ID as shown in the exhibit. The policy is intended to block sign-ins that are considered risky. However, some high-risk users are still able to sign in. What is the most likely reason?

A.The policy requires user risk and sign-in risk to both be high
B.The policy requires multi-factor authentication instead of blocking
C.The policy does not include sign-in risk levels
D.The policy requires both user risk and sign-in risk to be at specified levels simultaneously
AnswerD

The policy applies only when both the user risk and sign-in risk conditions are satisfied at the same time, because the conditions are joined with AND logic. For example, even if user risk is High, a sign-in risk of Low prevents the policy from triggering. This simultaneous requirement is the key to understanding when the block control will be enforced.

Why this answer

The conditional access policy only blocks sign-ins when both user risk is high AND sign-in risk is medium or high. If a user has high user risk but low sign-in risk, the policy does not apply, allowing them to sign in. Options A, B, and C are incorrect: A states both must be high, but the policy may require medium or high for sign-in risk; B is not about MFA; C is wrong because sign-in risk levels are included.

209
MCQmedium

A company uses Microsoft Entra ID with Pass-through Authentication. The security team wants to block all sign-ins from countries that are not approved (e.g., high-risk regions). Which feature should they use?

A.Conditional Access policy with country location condition
B.Identity Protection sign-in risk policy
C.Identity Protection user risk policy
D.Named locations with blocked countries
AnswerA

A Conditional Access policy with a location condition evaluates the sign-in's source country and blocks or challenges it, satisfying the requirement to bar unapproved regions. This works independently of Pass-through Authentication, since the policy is enforced by Microsoft Entra ID before the on-premises password validation.

Why this answer

Conditional Access policies in Microsoft Entra ID can include a location condition that uses IP addresses to determine the country of origin. By configuring a policy to block access from specific countries (e.g., high-risk regions), the security team can enforce this requirement. This is the correct feature because it directly evaluates the geographic location of the sign-in request and applies an access control (block) accordingly.

Exam trap

The trap here is that candidates confuse Named locations (which are just definitions) with the actual enforcement mechanism, forgetting that a Conditional Access policy is required to apply the block action based on those locations.

How to eliminate wrong answers

Option B is wrong because Identity Protection sign-in risk policy evaluates the probability that a sign-in is compromised based on signals like anonymous IP addresses or atypical travel, not the geographic country of the sign-in. Option C is wrong because Identity Protection user risk policy assesses the likelihood that a user's identity has been compromised (e.g., leaked credentials), not the location of the sign-in. Option D is wrong because Named locations define a set of IP address ranges or countries/regions for use in Conditional Access policies, but they cannot directly block sign-ins; they must be referenced within a Conditional Access policy to enforce a block action.

210
MCQmedium

A company uses Microsoft Entra ID with password hash synchronization. The security team wants to prevent users from setting passwords that include their username or common terms from a custom dictionary (e.g., company name, product names). Which feature should be configured?

A.Enable Azure AD Identity Protection with user risk policies.
B.Configure a custom banned passwords list in Microsoft Entra ID Password Protection.
C.Set a fine-grained password policy in on-premises Active Directory and sync it to Azure AD.
D.Enable MFA registration campaign to force users to register for MFA.
AnswerB

Configuring a custom banned passwords list in Microsoft Entra ID Password Protection allows you to define words, patterns, or strings that Entra ID automatically rejects whenever a user creates or resets a password. The service uses fuzzy matching (e.g., normalizing case, substitutions like '0' for 'o') and evaluates both the global Microsoft-list and your custom list, ensuring users cannot choose any password that fails the policy. This directly fulfills the requirement for a cloud-based password restriction.

Why this answer

Microsoft Entra ID Password Protection allows administrators to enforce custom banned password lists that prevent users from including specific terms (e.g., company name, product names) or their username in passwords. This feature works with password hash synchronization to block weak passwords at the cloud level, directly addressing the security team's requirement.

Exam trap

The trap here is that candidates often confuse password policies (which are set in on-premises AD and cannot be synced to Azure AD) with password protection features (which are configured directly in Microsoft Entra ID), leading them to incorrectly select Option C.

How to eliminate wrong answers

Option A is wrong because Azure AD Identity Protection with user risk policies detects and responds to compromised credentials or risky sign-ins, but it does not enforce password content restrictions like banning specific terms. Option C is wrong because fine-grained password policies in on-premises Active Directory cannot be synced to Azure AD; password hash synchronization only syncs password hashes, not password policies, and Azure AD does not support on-premises password policy enforcement. Option D is wrong because the MFA registration campaign forces users to register for multifactor authentication, which adds a second layer of security but does not prevent users from setting weak passwords that include banned terms.

211
MCQhard

A security administrator wants to prevent users from uploading files to unsanctioned cloud storage apps (e.g., personal Dropbox or Google Drive) from managed Windows devices. The solution must use a reverse proxy to control file uploads in real time. Which Microsoft Defender for Cloud Apps feature should the administrator configure?

A.App discovery policy
B.Access policy
C.Session policy
D.Activity policy
AnswerC

Session policies are the correct mechanism to prevent uploads because they utilize the Conditional Access App Control reverse proxy to intercept every HTTP request and response within an active cloud app session. The reverse proxy inspects the request payload and can identify a file upload attempt to unsanctioned storage, then block the action in real time or prompt the user with a warning. This capability is session-scoped, meaning it can allow other activities like reading or downloading while specifically blocking uploads. Thus a session policy provides the precise, real-time enforcement the requirement demands.

Why this answer

Session policy in Microsoft Defender for Cloud Apps uses reverse proxy capabilities to monitor and control user activities in real time. When configured with the 'Control file upload' action, it can block or restrict uploads to unsanctioned cloud storage apps like personal Dropbox or Google Drive from managed Windows devices, meeting the requirement exactly.

Exam trap

The trap here is confusing session policies (real-time reverse proxy control) with access policies (pre-session conditional access), leading candidates to choose access policy because it also uses Conditional Access, but it cannot inspect or block file uploads within an active session.

How to eliminate wrong answers

Option A is wrong because App discovery policy identifies cloud apps in use but does not enforce real-time controls via reverse proxy. Option B is wrong because Access policy controls access based on user/device context but does not inspect or block file uploads within a session. Option D is wrong because Activity policy detects and alerts on specific activities (e.g., uploads) but cannot block them in real time using a reverse proxy; it is reactive, not proactive.

212
MCQeasy

You are the administrator for a Microsoft 365 tenant. Users report that they cannot sign in to Microsoft Entra ID because their accounts are locked after multiple failed password attempts. You need to reduce the number of lockouts caused by users forgetting their passwords and to allow users to unlock their own accounts without calling the help desk. What should you do?

A.Configure a Conditional Access policy that requires multifactor authentication for all users.
B.Increase the account lockout threshold in Microsoft Entra password protection policies.
C.Enable Microsoft Entra Password Protection with a custom banned password list.
D.Enable self-service password reset (SSPR) for all users and configure the option to require users to register when they sign in.
AnswerD

SSPR allows users to reset their own passwords and unlock their accounts after lockout, reducing help desk calls. Requiring registration at sign-in ensures users enroll authentication methods before they need them. This directly addresses the requirement to reduce lockouts from forgotten passwords and enable self-service account unlocking.

Why this answer

Self-service password reset (SSPR) is the feature that lets users reset forgotten passwords and unlock their accounts without help desk involvement. Enabling SSPR and requiring registration at sign-in ensures users can self-remediate lockouts. Other options improve security but do not provide self-service account recovery, so they do not meet the requirement.

Exam trap

The trap here is thinking that increasing the lockout threshold or enabling MFA solves forgotten password lockouts, when only SSPR provides self-service reset and unlock.

213
MCQeasy

A new employee has been hired and their account already exists in the on-premises Active Directory. The administrator needs to provide the employee with access to Microsoft 365 services as quickly as possible. What is the most efficient way to enable the user?

A.Create a new cloud-only user in the Microsoft 365 admin center and assign a license.
B.Sync the on-premises user using Azure AD Connect and then assign the license.
C.Manually create a user in Microsoft Entra ID with the same name and assign license.
D.Use Azure AD B2B collaboration to invite the on-premises user as a guest.
AnswerB

Synchronize the existing on-premises user using Microsoft Entra Connect (formerly Azure AD Connect), which creates a user object in Microsoft Entra ID with the correct sourceAnchor for a stable, immutable link. This ensures the cloud identity is the same as the on-premises identity, enabling password hash sync or pass-through authentication for unified credentials. After the user is synced and visible in the portal, assign the required Microsoft 365 license to activate services like Exchange Online and Teams, preserving a single source of identity authority.

Why this answer

The user already exists in on-premises Active Directory, and the fastest way to enable Microsoft 365 access is to synchronize that identity using Azure AD Connect. Once synchronized, the user object appears in Microsoft Entra ID (formerly Azure AD), and the administrator can immediately assign a license without re-creating the account. This avoids the delays of manual creation or guest invitations and leverages the existing identity lifecycle.

Exam trap

The trap here is that candidates often confuse the speed of creating a new cloud user (Option A) with the efficiency of leveraging an existing synchronized identity, failing to recognize that synchronization is the intended and fastest path for hybrid environments.

How to eliminate wrong answers

Option A is wrong because creating a new cloud-only user would result in a duplicate identity that is not linked to the on-premises AD account, breaking password sync and future management. Option C is wrong because manually creating a user in Microsoft Entra ID with the same name does not establish a source-of-authority connection to the on-premises object, leading to conflicts and no automatic attribute synchronization. Option D is wrong because Azure AD B2B collaboration is designed for external guest access, not for enabling an internal employee with full Microsoft 365 services; it would create a separate guest identity without proper license assignment or directory integration.

214
Multi-Selectmedium

You are planning the initial deployment of a new Microsoft 365 tenant for Contoso Ltd. Which three of the following actions are required or recommended as part of the tenant provisioning and initial configuration process? (Choose three.)

Select 3 answers
.Register a custom domain name (e.g., contoso.com) and verify ownership via DNS TXT record.
.Assign Microsoft 365 licenses to all user accounts before creating the accounts.
.Configure the default tenant-level password expiration policy to 90 days using the Microsoft 365 admin center.
.Create the initial global administrator account with a strong, unique password and enable multi-factor authentication.
.Set up a secondary domain as the default email domain to avoid conflicts with the initial onmicrosoft.com domain.
.Configure tenant-wide service settings such as external sharing for SharePoint and OneDrive.

Why this answer

Registering and verifying a custom domain (e.g., contoso.com) via a DNS TXT record is a required step to use your own domain for email and user identities instead of the default onmicrosoft.com domain. Creating the initial global administrator account with a strong password and enabling multi-factor authentication (MFA) is a critical security best practice and is recommended by Microsoft to protect the highest-privileged role. Configuring tenant-wide service settings, such as external sharing for SharePoint and OneDrive, is recommended during initial setup to align with organizational security and collaboration policies before users begin working.

Exam trap

The trap here is that candidates may think password expiration policies are still relevant in Microsoft 365, but Microsoft deprecated them in favor of modern authentication and MFA, making the 90-day policy option a distractor.

215
MCQeasy

A company wants to use Microsoft Defender XDR to automatically investigate and remediate threats across email, endpoints, and identities. Which role is required to configure automation settings in the Microsoft 365 Defender portal?

A.Global Reader
B.Compliance Administrator
C.Security Administrator
D.Security Reader
AnswerC

The Security Administrator role in Microsoft Entra ID grants the permissions needed to configure automated investigation and remediation settings in the Microsoft 365 Defender portal, satisfying the requirement to manage Defender XDR automation across email, endpoints and identities.

Why this answer

The Security Administrator role in Microsoft Entra ID (Azure AD) grants the permissions needed to configure automation settings, including automated investigation and remediation (AIR) policies, in the Microsoft 365 Defender portal. This role is purpose-built for managing security features across Defender workloads without granting full tenant administrative rights.

Exam trap

MS-102 often tests the difference between read-only security roles (Security Reader, Global Reader) and the write-capable Security Administrator — candidates pick Security Reader thinking it can configure settings because it sounds security-focused.

How to eliminate wrong answers

Option A is wrong because Global Reader is a read-only role — it can view configuration and reports but cannot modify automation settings or any security policy. Option B is wrong because Compliance Administrator manages compliance-related features such as eDiscovery, data loss prevention, and retention policies, not Defender XDR automation settings. Option D is wrong because Security Reader, like Global Reader, is read-only for security features — it can view incidents and alerts but cannot configure or change automation policies.

216
MCQmedium

You are the identity administrator for a Microsoft 365 E5 tenant. The security team wants to enforce Microsoft Entra multifactor authentication (MFA) for all users when they access Microsoft 365 apps from outside the corporate network, but allow seamless access from the corporate office IP range 203.0.113.0/24. You create a Conditional Access policy named 'Require MFA offsite'. Which configuration should you use to meet the requirement?

A.Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, and Grant to Require multifactor authentication.
B.Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, and Grant to Block access, then create a separate policy to allow the corporate IP range.
C.Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, exclude the trusted IP 203.0.113.0/24, and Grant to Require multifactor authentication.
D.Set Assignments > Users to All users, Cloud apps to Office 365, Conditions > Locations to Any location, and Session to Use app enforced restrictions.
AnswerC

This is the correct approach: the policy targets all users and Office 365, applies from any location, but excludes the corporate IP range, so MFA is required only when users are outside the trusted network. The Grant control enforces MFA for the remaining sessions, satisfying the offsite-only requirement without affecting onsite access.

Why this answer

The requirement is to require MFA only when users are outside the corporate network. A Conditional Access policy that targets all users and Office 365, applies to any location, excludes the trusted corporate IP range, and grants multifactor authentication achieves this. Excluding the trusted location ensures onsite users are not prompted, while offsite sessions must satisfy the MFA grant control.

Exam trap

The trap here is assuming that 'Any location' means you cannot exclude the corporate range, when in fact trusted locations are configured as an exclusion within the Locations condition.

217
MCQhard

Your organization uses Microsoft Defender for Identity (MDI) and Microsoft Defender for Cloud Apps. You receive an alert about a user who is performing an unusual number of failed logon attempts from a non-corporate IP address. The user is a member of the Finance group. What is the recommended first step?

A.Reset the user's password and require MFA.
B.Contact the user to verify if the activity is legitimate.
C.Disable the user account immediately.
D.Block the IP address in the firewall.
E.Close the alert as a false positive.
AnswerB

Verifying with the user confirms whether the failed logons are genuine mistyping or credential-stuffing before escalating. This satisfies the recommended first step, since contacting the account owner quickly establishes legitimacy without prematurely disabling a Finance user's access.

Why this answer

When an alert indicates unusual failed logon attempts from a non-corporate IP address, the recommended first step is to contact the user to verify if the activity is legitimate. This follows the principle of verification before action, as the activity could be due to a forgotten password or a misconfigured application. Option B is correct.

Option A (resetting password and requiring MFA) is premature without verification, as it may disrupt legitimate access. Option C (disabling the account) could be too disruptive and should only be done after confirming malicious intent. Option D (blocking the IP) might block legitimate users or shared IPs.

Option E (closing as false positive) skips investigation and could miss a real threat.

218
MCQmedium

You are the Microsoft 365 administrator for a company that uses Microsoft Entra ID P2. The security team wants to require members of the 'Finance' group to use multifactor authentication (MFA) when they access any cloud app from outside the corporate network. You create a Conditional Access policy and assign it to the Finance group. You need to configure the policy to meet the requirement while minimizing impact on other users. What should you do?

A.Set the policy to report-only mode and monitor the sign-in logs.
B.Configure the policy to apply to all users and all cloud apps, and require MFA.
C.Create a named location for the corporate network and exclude it from the policy.
D.Enable security defaults in Microsoft Entra ID.
AnswerC

A named location defines trusted IP ranges. By excluding the corporate network, the policy applies only when Finance users are outside that network, satisfying the requirement to require MFA externally while not affecting internal access. This is the standard method to scope Conditional Access by network location.

Why this answer

The requirement is to require MFA for Finance group members only when they access cloud apps from outside the corporate network. This is achieved by creating a named location for the corporate network and excluding it from the Conditional Access policy. The policy then applies only to sign-ins from other locations, enforcing MFA externally without impacting internal users.

Exam trap

The trap here is assuming that report-only mode enforces MFA or that security defaults can be scoped to a group.

219
MCQhard

A compliance officer needs to preserve all communications (email and Teams messages) for employees in the legal department for a minimum of 7 years. Additionally, any deletion (by users or system) must be blocked, and after the retention period, the items must be disposed of automatically. The solution must also ensure that the communications are marked as 'records' to prevent tampering. Which Microsoft Purview solution should the officer configure?

A.Litigation hold on the legal department's mailboxes and Teams
B.retention label configured with 'Mark items as a record' and a retention period of 7 years, then delete automatically
C.Preservation hold library in SharePoint Online
D.Data Loss Prevention (DLP) policy with retention action
AnswerB

A retention label configured with 'Mark items as a record' makes content immutable: after application, users and administrators cannot edit or delete the item until the retention period expires. Setting the retention period to 7 years and selecting 'delete automatically' ensures the communication is preserved for the full regulatory period and then automatically purged. This is the only option that combines record immutability, a fixed 7-year timeframe, and automatic deletion, which matches the compliance officer's exact requirement.

Why this answer

A retention label with 'Mark items as a record' enforces immutability (prevents tampering) and, when configured with a 7-year retention period followed by automatic deletion, meets the compliance officer's requirements for preservation, blocking deletion, and automatic disposal. This label can be applied to both Exchange Online mailboxes (email) and Teams messages via auto-labeling policies, covering all communications for the legal department.

Exam trap

The trap here is that candidates often confuse Litigation Hold (which preserves indefinitely without automatic deletion) with a retention label that includes both a fixed retention period and record marking, failing to recognize that Litigation Hold does not meet the 'dispose automatically after 7 years' requirement.

How to eliminate wrong answers

Option A is wrong because a Litigation Hold preserves content indefinitely (or until manually removed) but does not enforce automatic deletion after a specific period, nor does it mark items as 'records' to prevent tampering. Option C is wrong because the Preservation Hold Library is a SharePoint Online feature that applies to document libraries, not to Exchange Online mailboxes or Teams messages, and it does not provide record marking or automatic deletion scheduling. Option D is wrong because a Data Loss Prevention (DLP) policy is designed to detect and prevent sensitive data leakage, not to enforce retention, record marking, or automatic disposal; it lacks the ability to block deletion or mark items as records.

220
MCQeasy

A company needs to ensure that only users from specific IP ranges can access Exchange Online. Which tool should be used?

A.Azure AD Conditional Access with Named Locations
B.Security & Compliance Center
C.Multi-factor authentication
D.Azure AD Connect
AnswerA

Azure AD Conditional Access with Named Locations is the correct approach because Named Locations define a set of trusted public IP address ranges or countries that can be referenced in a Conditional Access policy. You can create a policy that targets all users and either blocks sign-ins from any IP not included in the trusted location or requires additional controls such as MFA for exceptions. This provides dynamic, IP-based network access enforcement at the authentication layer.

Why this answer

Azure AD Conditional Access with Named Locations is the correct tool because it allows administrators to define trusted IP ranges as named locations and then enforce access policies that restrict Exchange Online access to only those IP ranges. This integrates directly with Azure AD authentication, evaluating the user's IP address during sign-in to grant or block access based on the policy.

Exam trap

The trap here is that candidates often confuse the Security & Compliance Center's transport rules or mailbox policies with network-level access control, or they assume MFA alone can restrict access by IP, when in fact Conditional Access is the dedicated feature for location-based policies.

How to eliminate wrong answers

Option B is wrong because the Security & Compliance Center is used for data governance, threat management, and compliance features like retention policies and eDiscovery, not for controlling network-level access to Exchange Online. Option C is wrong because Multi-Factor Authentication (MFA) adds a second verification factor but does not restrict access based on source IP addresses; it can be combined with Conditional Access but alone does not enforce IP range restrictions. Option D is wrong because Azure AD Connect is a tool for synchronizing on-premises directory objects to Azure AD and enabling hybrid identity, not for configuring access policies based on IP ranges.

221
MCQhard

You are the identity administrator for a Microsoft 365 E5 tenant. The company uses Microsoft Entra ID P2. The security team wants to implement just-in-time role activation for the 'Security Administrator' role. They want to ensure that when a user activates the role, they must provide a justification and approve via multi-factor authentication. They also want the activation to last for a maximum of 4 hours. You configure Privileged Identity Management (PIM). Which setting should you configure to meet the requirement for justification and MFA?

A.Assign the role as eligible and set the maximum activation duration to 4 hours.
B.In the role settings, enable 'Require justification on activation' and 'Require Microsoft Entra multifactor authentication on activation'.
C.Configure a Conditional Access policy that requires MFA for the Security Administrator role.
D.In the role settings, enable 'Require approval to activate' and specify approvers.
AnswerB

These settings are part of the role settings in PIM. Enabling 'Require justification on activation' forces users to provide a reason when activating. Enabling 'Require Microsoft Entra multifactor authentication on activation' enforces MFA during activation. Together, they meet the requirement for justification and MFA, and the maximum activation duration can be set separately.

Why this answer

In PIM, role settings include options to require justification and Microsoft Entra multifactor authentication on activation. Enabling both ensures that when a user activates the Security Administrator role, they must provide a reason and complete MFA. The maximum activation duration is set separately in the same role settings.

This configuration satisfies the just-in-time access requirements with the specified controls.

Exam trap

The trap here is confusing PIM activation requirements with Conditional Access MFA, which does not provide justification or just-in-time activation.

222
MCQeasy

You are implementing Microsoft Entra Verified ID to issue verifiable credentials to employees for proof of employment. Which component is required to issue and verify credentials?

A.Microsoft Entra ID P2 licenses for all users
B.A certificate from a public certificate authority (CA)
C.An Azure AD B2C tenant
D.A decentralized identifier (DID) and a trusted identity system
AnswerD

A decentralized identifier (DID) serves as the globally unique, cryptographically verifiable identifier for each participant in a verifiable credential ecosystem, paired with a trusted identity system that publishes and resolves DID documents. The DID document contains the public keys used to verify the credential issuer's signature, and the trust system establishes how DIDs are registered and discovered—through methods like did:ion or did:web. This combination replaces the need for a centralized CA, because trust is anchored in the cryptographic agreement of the DID infrastructure. Together, they form the core requirement for issuing and verifying verifiable credentials with Microsoft Entra Verified ID.

Why this answer

Microsoft Entra Verified ID uses a decentralized identity model where each issuer and verifier has a unique decentralized identifier (DID) and a trusted identity system (such as a blockchain-based ION network or a web-based DID method) to publish and resolve DID documents. The DID and the trusted identity system are the core components required to cryptographically sign verifiable credentials and verify them without relying on a central authority, making option D correct.

Exam trap

The trap here is that candidates often assume a traditional PKI certificate or a premium license is required, but Microsoft Entra Verified ID relies on decentralized identifiers (DIDs) and a trusted identity system, not on CA-issued certificates or specific license tiers.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID P2 licenses provide advanced identity protection and governance features but are not a prerequisite for issuing or verifying verifiable credentials; Verified ID can work with any Azure AD tenant. Option B is wrong because a certificate from a public certificate authority (CA) is used for traditional PKI-based identity systems, but Verified ID uses DIDs and key pairs generated by the issuer, not a CA-issued certificate. Option C is wrong because Azure AD B2C is a customer identity and access management solution for external users, not a required component for Verified ID; Verified ID uses its own decentralized identity infrastructure.

223
MCQhard

A ransomware alert is confirmed in Microsoft Defender XDR on a user device that is still communicating with other endpoints. What should the administrator do first to reduce spread while preserving the ability to investigate?

A.Isolate the affected device from the network
B.Collect a forensic package before taking containment action
C.Run a full antivirus scan before isolating the device
D.Wait for automated investigation to complete before responding
AnswerA

Isolate the affected device using Microsoft Defender for Endpoint's device isolation capability. Containment blocks all network traffic to and from the endpoint, including SMB and RDP, while preserving the management channel so Defender can continue telemetry and remediation. This immediately halts ransomware propagation, lateral movement, and command-and-control communication, giving responders time to analyze and remediate safely.

Why this answer

Immediately isolating the affected device from the network stops the ransomware from spreading laterally to other endpoints via SMB, RDP, or other protocols, while preserving the device's state for forensic analysis. Microsoft Defender XDR's device isolation feature blocks all inbound and outbound communication except with the Defender for Endpoint cloud service, allowing investigation to continue without the risk of further infection.

Exam trap

The trap here is that candidates often think they must preserve evidence first (Option B) or let automation run (Option D), but Microsoft explicitly prioritizes containment over collection in active ransomware outbreaks to prevent lateral spread.

How to eliminate wrong answers

Option B is wrong because collecting a forensic package before containment delays the response, allowing ransomware to continue spreading to other endpoints during the collection process. Option C is wrong because running a full antivirus scan before isolation is time-consuming and ineffective against active ransomware that may have already disabled or evaded the scanner, and it does not prevent lateral movement. Option D is wrong because waiting for automated investigation to complete gives the ransomware more time to encrypt files and propagate, whereas manual isolation is the recommended first step in confirmed ransomware incidents to contain the threat immediately.

224
MCQmedium

Your organization uses Microsoft 365 Defender. You need to configure automated investigation and response (AIR) to automatically remediate high-confidence phishing emails. What should you configure?

A.Automated investigation and response for collaboration content
B.Automated investigation and response for identities
C.Automated investigation and response for email
D.Automated investigation and response for devices
AnswerC

Automated investigation and response for email is the correct capability because it directly addresses threats found in email messages, including phishing, malware, and spam. When a suspicious email is detected, this AIR capability automatically launches an investigation, gathers evidence, and can take built-in remediation actions such as soft-deleting the message from all mailboxes, quarantining it, or blocking the sender. This is the only AIR workflow specifically tuned for email-borne threats in Microsoft 365 Defender.

Why this answer

Automated investigation and response (AIR) for email in Microsoft 365 Defender automatically investigates and remediates phishing emails, including high-confidence detections. Configuring AIR for email enables the system to take remediation actions like soft-deleting messages, blocking senders, and removing malicious content without manual intervention.

Exam trap

The trap is that AIR is a cross-workload capability, so candidates must map the specific scenario (phishing emails) to the email workload — picking devices or identities because those are more commonly discussed in Defender contexts.

How to eliminate wrong answers

Option A is wrong because AIR for collaboration content covers Teams, SharePoint, and OneDrive — not email phishing. Option B is wrong because AIR for identities covers compromised user accounts and identity-based attacks, not email content remediation. Option D is wrong because AIR for devices covers endpoint investigations and remediation, not email phishing emails.

225
MCQmedium

You are a security administrator for a company that uses Microsoft Defender XDR. You need to create a custom detection rule that triggers when a process named 'mimikatz.exe' is executed on any device. The rule should run every hour and generate an alert. Which of the following should you use to create this rule?

A.Microsoft Defender for Office 365 threat explorer
B.Microsoft 365 Defender incident queue
C.Microsoft Defender for Cloud Apps activity log
D.Microsoft Defender for Endpoint advanced hunting with a custom detection rule
AnswerD

Advanced hunting in Microsoft Defender for Endpoint allows you to write KQL queries against raw event data, and custom detection rules can be created from these queries to run on a schedule, such as hourly, and generate alerts when conditions are met. This is the correct method to detect process execution like mimikatz.exe.

Why this answer

Custom detection rules in Microsoft Defender for Endpoint allow security teams to create scheduled KQL queries that run against advanced hunting data and generate alerts when specific conditions are met. This is the appropriate tool for detecting process execution like mimikatz.exe on endpoints, as it provides the necessary data and scheduling capabilities.

Exam trap

The trap here is confusing the incident queue with a rule creation interface, when actually incident queue is only for viewing and managing existing alerts.

Page 2

Page 3 of 10

Page 4

All pages