Courseiva

Microsoft 365 Administrator MS-102 (MS-102) — Questions 226–300

712 questions total · 10pages · All types, answers revealed

Page 3

Page 4 of 10

Page 5
226
MCQeasy

An organization has just signed up for Microsoft 365 E3 with the initial domain 'contoso.onmicrosoft.com'. They need to create the first user accounts. What will be the default email address format for these new users if no custom domain is added yet?

A.user@contoso.onmicrosoft.com
B.user@contoso.com
C.user@microsoft.com
D.user@contoso.microsoft.com
AnswerA

The initial domain created when a Microsoft 365 tenant is provisioned always uses the <tenantname>.onmicrosoft.com namespace, and contoso.onmicrosoft.com is the default UPN and email domain for all new users. This domain is automatically reserved for your tenant and cannot be used by any other tenant, so assigning user@contoso.onmicrosoft.com is the only valid option listed without additional configuration.

Why this answer

When a new Microsoft 365 tenant is created with the initial domain 'contoso.onmicrosoft.com' and no custom domain has been added, the default email address format for new users is user@contoso.onmicrosoft.com. This is because the onmicrosoft.com domain is the default tenant domain provisioned by Azure AD, and all user principal names (UPNs) and email addresses are automatically assigned this suffix until a custom domain is verified and set as the primary domain.

Exam trap

The trap here is that candidates assume the email address will automatically match the organization's public domain name (e.g., contoso.com) without realizing that a custom domain must be explicitly added and verified in the Microsoft 365 admin center before it can be used for user email addresses.

How to eliminate wrong answers

Option B is wrong because 'contoso.com' is a custom domain that must be purchased and verified via DNS TXT records before it can be used for email addresses; it is not automatically available. Option C is wrong because 'microsoft.com' is Microsoft's own corporate domain and cannot be used by any tenant. Option D is wrong because 'contoso.microsoft.com' is not a valid domain format for any Microsoft 365 tenant; the default tenant domain always uses the pattern <tenantname>.onmicrosoft.com.

227
Multi-Selecteasy

Your organization uses Microsoft Entra ID. You need to enable users to securely share documents with external partners. Which TWO features should you use?

Select 2 answers
A.Microsoft Entra B2B collaboration
B.Azure AD B2C
C.Microsoft Purview Information Protection
D.Microsoft Entra entitlement management
E.Microsoft Defender for Cloud Apps
AnswersA, D

Microsoft Entra B2B collaboration directly enables external sharing by letting you invite external partners into your tenant as guest users who authenticate with their own organizational or personal identity. It supports granular permissions, conditional access, and revocation without requiring you to manage those users' credentials. This is the core mechanism for giving outside collaborators secure access to your Entra ID-integrated applications.

Why this answer

Microsoft Entra B2B collaboration is correct because it allows you to securely share documents and collaborate with external partners by inviting them as guest users in your Entra ID tenant. This feature leverages existing identities (e.g., Microsoft, Google, or SAML/WS-Fed providers) without requiring external users to create new accounts, enabling controlled access to resources like SharePoint or Teams.

Exam trap

The trap here is confusing Azure AD B2C (customer-facing) with Microsoft Entra B2B collaboration (partner-facing), as both involve external users but serve fundamentally different scenarios—B2C is for consumer apps, while B2B is for enterprise collaboration.

228
Multi-Selecteasy

Which TWO are prerequisites for implementing Microsoft Entra ID Identity Protection? (Choose two.)

Select 2 answers
A.Microsoft Entra ID P2 license
B.Microsoft Entra ID P1 license
C.Identity Protection administrator role assigned
D.Audit logs enabled for sign-in events
E.Self-service password reset configured
AnswersA, C

Microsoft Entra ID P2 licensing is a hard prerequisite for implementing Identity Protection because risk detections, risk-based conditional access policies, and the Identity Protection report views are only included in the P2 tier. Attempting to configure these in a tenant with only P1 or free licensing will fail validation, as the underlying risk engine and policy controls are not provisioned.

Why this answer

Microsoft Entra ID Identity Protection requires a Microsoft Entra ID P2 license because it uses advanced risk detection and automated remediation capabilities (e.g., risk-based Conditional Access policies, user risk and sign-in risk policies) that are only available in the P2 tier. The P1 license provides basic Conditional Access but lacks the risk detection engine and adaptive policies that Identity Protection relies on.

Exam trap

The trap here is that candidates often confuse the licensing requirement for Identity Protection (P2) with the broader Conditional Access feature (P1), or assume that audit logs or SSPR are mandatory prerequisites when they are not directly required for Identity Protection's core functionality.

229
MCQmedium

Your organization uses Microsoft Defender for Office 365 and wants to simulate a phishing attack to train users. You need to configure a simulation that uses a URL link to a credential harvesting page. Which feature should you use?

A.Attack simulation training
B.Anti-phish policies
C.Safe Links policies
D.Safe Attachments policies
AnswerA

Attack simulation training in Microsoft Defender for Office 365 is the dedicated capability for creating and launching realistic phishing simulations. It provides pre-built payload templates and enables you to target specific users or groups, then track who clicked, submitted credentials, or reported the simulated message. This is the only option that actively generates simulated threats rather than enforcing protection on live traffic.

Why this answer

Attack simulation training in Microsoft Defender for Office 365 is the dedicated feature for creating and launching realistic phishing simulations, including those that use a URL link to a credential harvesting page. It allows administrators to configure payloads, target users, and track training completion, directly meeting the requirement to simulate a phishing attack for user education.

Exam trap

The trap here is that candidates confuse the protection features (Anti-phish, Safe Links, Safe Attachments) with the simulation feature, assuming that a security tool designed to block attacks can also be used to simulate them, but Microsoft separates simulation capabilities into the dedicated Attack simulation training feature.

How to eliminate wrong answers

Option B is wrong because Anti-phish policies are protection mechanisms that detect and block phishing attempts in real time, not tools for simulating attacks. Option C is wrong because Safe Links policies protect users by scanning and blocking malicious URLs in emails and Office documents, but they do not create or simulate phishing campaigns. Option D is wrong because Safe Attachments policies scan email attachments for malware and block dangerous files, but they have no capability to simulate phishing attacks or credential harvesting pages.

230
Multi-Selecthard

A security administrator is configuring Microsoft Defender for Cloud Apps. The administrator needs to discover which cloud apps are being used in the organization and then block usage of unsanctioned apps in real time using a reverse proxy. Which two Defender for Cloud Apps features must be configured? (Select the two correct options.)

Select 2 answers
A.Cloud Discovery
B.App governance
C.Conditional Access App Control
D.OAuth app permissions
AnswersA, C

Cloud Discovery is the feature in Microsoft Defender for Cloud Apps that ingests and analyzes traffic logs from network proxies and firewalls to identify all cloud apps in use, including unsanctioned shadow IT. It assigns risk scores to each discovered app and allows you to sanction or unsanction them based on organizational policy. This analysis is the foundational step for any subsequent control, such as Conditional Access App Control.

Why this answer

Cloud Discovery is the correct feature because it identifies which cloud apps are in use by analyzing traffic logs from the organization's network. This provides the visibility needed to determine which apps are unsanctioned. Conditional Access App Control is the correct feature because it uses a reverse proxy to enforce real-time access controls, blocking unsanctioned apps at the session level.

Exam trap

The trap here is that candidates confuse App governance (which manages OAuth app permissions) with the reverse proxy functionality of Conditional Access App Control, or assume Cloud Discovery alone is sufficient for blocking, when it only provides visibility.

231
MCQeasy

You run the Azure CLI command shown in the exhibit. What does the output represent?

A.The application ID for Microsoft Entra ID
B.The application ID for Exchange Online
C.The application ID for SharePoint Online
D.The application ID for Microsoft Graph
AnswerD

The application ID 00000003-0000-0000-c000-000000000000 is the fixed, well-known application ID for Microsoft Graph. This ID is present in every Microsoft Entra ID tenant as the Microsoft Graph service principal and is used by Azure CLI commands to inspect its roles, permission scopes, and other configuration. It is not tied to any single workload like Exchange or SharePoint; it represents the unified Microsoft Graph API across all Microsoft 365 services.

Why this answer

The Azure CLI command `az ad sp show --id 00000003-0000-0000-c000-000000000000` retrieves the service principal for the Microsoft Graph API. The GUID `00000003-0000-0000-c000-000000000000` is the well-known application ID for Microsoft Graph in Microsoft Entra ID (formerly Azure AD). This ID is used to grant permissions and consent for Microsoft Graph API access.

Exam trap

The trap here is that candidates confuse the Microsoft Graph application ID with the SharePoint Online application ID because both start with `00000003`, but the middle segment differs (`-0000-0000-c000-` vs `-0000-0ff1-ce00-`), and Microsoft deliberately tests this subtle distinction.

How to eliminate wrong answers

Option A is wrong because the application ID for Microsoft Entra ID (the directory itself) is `00000001-0000-0000-c000-000000000000`, not the one shown. Option B is wrong because Exchange Online has its own application ID (`00000002-0000-0ff1-ce00-000000000000`), which is different from the GUID in the command. Option C is wrong because SharePoint Online uses application ID `00000003-0000-0ff1-ce00-000000000000`, not the Microsoft Graph ID `00000003-0000-0000-c000-000000000000`.

232
MCQeasy

A security administrator needs to view a unified incident queue that correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Defender for Identity. Which console should the administrator open?

A.Microsoft 365 Defender portal (security.microsoft.com)
B.Azure Security Center
C.Microsoft Endpoint Manager admin center
D.Microsoft Purview compliance portal
AnswerA

Microsoft 365 Defender portal (security.microsoft.com) is the single security operations console that aggregates alerts and incidents from Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. Its unified incident queue correlates related alerts into a single incident, enabling triage, investigation, and response across all Microsoft 365 Defender workloads. This portal is the correct destination for viewing a unified incident queue.

Why this answer

The Microsoft 365 Defender portal (security.microsoft.com) provides a unified incident queue that aggregates and correlates alerts from Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. This single-pane-of-glass view enables security administrators to investigate and respond to cross-domain threats without switching between separate consoles.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 Defender portal with Azure Security Center (now Defender for Cloud), mistakenly thinking that all security alerts converge in Azure, when in fact the unified incident queue for Microsoft 365 Defender workloads is exclusive to security.microsoft.com.

How to eliminate wrong answers

Option B is wrong because Azure Security Center (now Microsoft Defender for Cloud) focuses on securing cloud workloads (VMs, containers, SQL) and does not provide a unified incident queue for Microsoft 365 Defender workloads. Option C is wrong because Microsoft Endpoint Manager admin center (intune.microsoft.com) is used for device management, compliance policies, and app deployment, not for security incident correlation. Option D is wrong because the Microsoft Purview compliance portal (compliance.microsoft.com) is dedicated to data governance, eDiscovery, and compliance management, not for real-time threat alert correlation from Defender products.

233
Multi-Selectmedium

Which TWO actions are required to enable Microsoft 365 Copilot for all users in your tenant?

Select 2 answers
A.Run a PowerShell script to enable Copilot in the tenant.
B.Ensure the tenant is on a Microsoft 365 E5 plan.
C.Ensure users have a qualifying Microsoft 365 license (e.g., E3, E5, Business Standard).
D.Assign a Microsoft 365 Copilot license to each user.
E.Provision an Azure subscription for Copilot services.
AnswersC, D

A qualifying base Microsoft 365 license is a foundational prerequisite for Microsoft 365 Copilot because Copilot is an add-on that builds on existing Microsoft 365 services and data. Without a valid base license—such as E3, E5, or Business Standard—a user cannot receive Copilot features, as the add-on license is dependent on the underlying qualifying plan being present and active. Administrators must therefore verify each target user has an eligible base license before assigning the Copilot add-on license.

Why this answer

Microsoft 365 Copilot requires users to have a qualifying base license such as Microsoft 365 E3, E5, or Business Standard. Without one of these base licenses, the Copilot add-on license cannot be assigned or function properly, as Copilot relies on the underlying Microsoft 365 services (e.g., Exchange Online, SharePoint, Teams) that these plans provide.

Exam trap

The trap here is that candidates assume a tenant-wide setting or a specific plan (like E5) is required, when in fact the key requirement is a qualifying base license per user combined with individual Copilot license assignment.

234
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You need to be alerted when a user accesses a cloud app from a risky IP address. What should you configure?

A.Create an anomaly detection policy with the 'Activity from risky IP address' template.
B.Create a session policy to monitor risky IP addresses.
C.Create a file policy to detect access from risky IPs.
D.Create an access policy to block risky IPs.
AnswerA

The 'Activity from risky IP address' template is a built-in anomaly detection policy in Microsoft Defender for Cloud Apps that leverages Microsoft threat intelligence to identify IP addresses associated with malicious activity, such as anonymous proxies, Tor exit nodes, or known botnets. When a user performs an activity from one of these IPs, the policy generates an alert, giving security teams immediate visibility into the potentially compromised session. This is exactly the alerting capability needed in this scenario.

Why this answer

An anomaly detection policy can alert on activities from risky IP addresses. Option B is wrong because session policies control real-time access. Option C is wrong because file policies monitor data.

Option D is wrong because access policies control access based on conditions.

235
MCQhard

You are implementing Microsoft Entra Identity Protection. You need to configure automated responses to medium and high user risk. Which policy should you create?

A.Sign-in risk policy
B.Conditional Access policy with grant controls
C.MFA registration policy
D.User risk policy
AnswerD

The user risk policy responds to the aggregate probability that a user's identity has been compromised, based on multiple risk detections associated with that account. It can be configured to automatically block all access or trigger a secure password change with required MFA, based on the user risk level (low, medium, high). This is precisely the Microsoft Entra ID Protection mechanism designed for user risk levels, making it the correct answer.

Why this answer

User risk policy in Microsoft Entra Identity Protection is specifically designed to automatically respond to user risk levels (low, medium, high) by triggering remediation actions such as requiring a password change or blocking sign-in. Since the question asks for automated responses to medium and high user risk, the correct policy is the User risk policy, which evaluates risk based on user behavior and leaked credentials.

Exam trap

The trap here is confusing User risk policy (which responds to user-level risk like compromised accounts) with Sign-in risk policy (which responds to session-level risk like suspicious sign-in attempts), leading candidates to incorrectly choose the sign-in risk policy for user risk remediation.

How to eliminate wrong answers

Option A is wrong because Sign-in risk policy responds to real-time sign-in risks (e.g., anonymous IP, atypical travel) rather than user risk levels. Option B is wrong because Conditional Access policy with grant controls is a broader policy that can enforce MFA or block access but is not specifically designed to automate responses to user risk from Identity Protection; it can integrate with risk policies but is not the primary policy for user risk remediation. Option C is wrong because MFA registration policy is used to enforce MFA registration for all users, not to respond to user risk levels.

236
MCQhard

Your organization uses Microsoft Defender for Endpoint and Microsoft Defender for Identity. A user reports that their account was used to send a large volume of email messages to internal recipients, which appears to be a potential account compromise. You need to determine if the account is compromised and if any lateral movement occurred. Which data sources should you analyze in Microsoft Defender XDR?

A.EmailEvents and EmailAttachmentInfo
B.DeviceNetworkEvents and DeviceProcessEvents
C.DeviceEvents and DeviceNetworkEvents
D.IdentityLogonEvents, EmailEvents, and DeviceProcessEvents
AnswerD

Together, these tables provide a complete attack chain: IdentityLogonEvents records sign-in and logon attempts, revealing suspicious authentication patterns tied to a specific account; EmailEvents tracks email send/receive activity, enabling correlation of a phishing email or malicious attachment; and DeviceProcessEvents logs process creation, which exposes lateral movement when a compromised account launches a remote service, script, or executable. Joining these tables on user SID and device ID lets an investigator reconstruct the timeline from email receipt to identity compromise to endpoint execution.

Why this answer

IdentityLogonEvents (from Microsoft Defender for Identity) provide logon activities, EmailEvents (from Microsoft Defender for Office 365) show email sending patterns, and DeviceProcessEvents (from Microsoft Defender for Endpoint) reveal process creations that may indicate lateral movement (e.g., PsExec, WMI). Together, these three data sources allow correlation of identity, email, and device events to confirm a compromise and detect lateral movement. Option A is incorrect because EmailEvents and EmailAttachmentInfo cover only email context, lacking identity and lateral movement data.

Option B is incorrect because DeviceNetworkEvents and DeviceProcessEvents lack identity and email context. Option C is incorrect because DeviceEvents and DeviceNetworkEvents also miss identity and email context.

237
MCQhard

An organization has multiple Microsoft Entra ID tenants and wants to allow partner users to access internal applications using their own corporate credentials. Which feature should be used to enable this?

A.Microsoft Entra B2B collaboration
B.Microsoft Entra B2C
C.Azure AD Connect
D.Tenant-to-tenant migration
AnswerA

Microsoft Entra B2B collaboration is the appropriate feature because it allows you to invite external partner users from another Azure AD/Microsoft Entra tenant to access your resources while they authenticate with their own home-tenant credentials. This approach eliminates the need for creating separate accounts, maintains the partner's own identity lifecycle, and integrates with conditional access policies and access reviews, making it ideal for multi-tenant collaboration.

Why this answer

Microsoft Entra B2B collaboration is the correct feature because it allows partner users to access internal applications using their own corporate credentials (their home tenant identity) without requiring any external accounts or local user management. B2B collaboration uses cross-tenant trust relationships, enabling seamless single sign-on (SSO) via SAML/WS-Fed or OIDC protocols, which aligns with the requirement to use existing partner credentials.

Exam trap

The trap here is that candidates often confuse Microsoft Entra B2B (for business partners) with Microsoft Entra B2C (for customers), leading them to select B2C because both involve external identities, but B2C does not support using the partner's own corporate credentials from another Entra ID tenant.

How to eliminate wrong answers

Option B (Microsoft Entra B2C) is wrong because it is designed for customer-facing applications where users sign up with social or local accounts, not for partner users who need to use their own corporate credentials from another Entra ID tenant. Option C (Azure AD Connect) is wrong because it synchronizes on-premises Active Directory objects to a single Entra ID tenant, and does not enable cross-tenant access for external partner identities. Option D (Tenant-to-tenant migration) is wrong because it is a process for moving data and users between tenants, not a feature for granting ongoing access to partner users with their existing credentials.

238
MCQeasy

A user reports they cannot access SharePoint Online but can access Outlook. The admin verifies the user has an E3 license assigned. What is the most likely cause?

A.License not assigned
B.MFA challenge failing
C.User account is disabled
D.SharePoint Online service plan is disabled
AnswerD

This is the correct answer because Microsoft 365 licenses contain granular service plans, and each plan can be independently toggled on or off for a user while the license remains assigned. If the SharePoint Online (SHAREPOINT) service plan is disabled, the user loses access to SharePoint Online but continues to access other services like Exchange Online. This selectively prevents access only to SharePoint, matching the user's report.

Why this answer

The user can access Outlook (Exchange Online) but not SharePoint Online, which indicates that the user's E3 license is assigned and the account is active. The most likely cause is that the SharePoint Online service plan within the E3 license is disabled. Each Microsoft 365 license includes multiple service plans (e.g., Exchange Online, SharePoint Online, Teams), and an admin can disable individual plans while keeping the license assigned.

If the SharePoint Online service plan is disabled, the user will be blocked from accessing SharePoint Online despite having a valid license.

Exam trap

The trap here is that candidates assume a licensed user has full access to all services included in the license, overlooking that individual service plans can be disabled independently.

How to eliminate wrong answers

Option A is wrong because the user can access Outlook, which requires a valid license; if no license were assigned, the user would be blocked from all services, not just SharePoint Online. Option B is wrong because an MFA challenge failure would block access to all Microsoft 365 services, including Outlook, not just SharePoint Online. Option C is wrong because a disabled user account would prevent access to all services, including Outlook, but the user can access Outlook, so the account is active.

239
MCQmedium

A company's security team needs to investigate a suspicious email that was reported by a user. The email was not blocked by Exchange Online Protection (EOP) and was delivered to the user's inbox. The security team wants to use Microsoft Defender XDR to analyze the email and its attachments. Which feature should they use to submit the email for automated investigation?

A.Submissions
B.Advanced Hunting
C.Threat Explorer
D.Attack Simulator
AnswerA

Submissions in Microsoft Defender XDR lets administrators send user-reported or suspicious emails, including attachments, for automated investigation and rescanning. It satisfies the requirement because the message was delivered, so it must be submitted manually rather than relying on EOP blocking.

Why this answer

Microsoft Defender XDR's Submissions feature (under Email & Collaboration > Submissions) allows security teams to submit suspicious emails, attachments, and URLs to Microsoft for automated analysis. When a user reports a phish that EOP missed, the admin can submit it via Submissions, which triggers automated investigation, detonation, and re-classification. This is the correct tool for analyzing a specific reported email and its attachments.

Exam trap

MS-102 often tests the distinction between investigation tools — the trap is confusing Threat Explorer (viewing threats) with Submissions (reporting threats for analysis), or picking Advanced Hunting when the question asks about submitting a specific email.

How to eliminate wrong answers

Option B (Advanced Hunting) is wrong because it is a KQL-based query tool for proactively searching telemetry across Defender workloads — it does not submit emails for automated investigation or re-classification. Option C (Threat Explorer) is wrong because it is a real-time reporting and investigation dashboard for email threats, but it does not submit items to Microsoft for analysis; it is for viewing and filtering existing threat data. Option D (Attack Simulator) is wrong because it is used to create and run simulated phishing campaigns for user training, not to analyze real reported emails.

240
MCQhard

Your organization has a Microsoft 365 tenant with 10,000 users. You are configuring Microsoft Entra ID Identity Protection to detect risky sign-ins. You need to ensure that when a sign-in risk level of 'High' is detected, the user is blocked from signing in and an administrator is notified. What should you configure?

A.Create a Conditional Access policy with 'Sign-in risk' condition set to 'High' and 'Block access', and configure alert notifications in Identity Protection
B.Create a user risk policy in Identity Protection to block high-risk users
C.Create an MFA registration policy in Identity Protection
D.Enable Security defaults and configure notifications
AnswerA

A Conditional Access policy with a Sign-in risk condition evaluates the risk score that Azure AD Identity Protection assigns to each authentication attempt in real time. Setting the condition to 'High' and the access control to 'Block access' prevents compromised credentials from being used before a session is established. Separately configuring alert notifications in Identity Protection ensures that administrators are immediately notified when such high-risk sign-ins are attempted, providing both remediation and visibility.

Why this answer

It combines a Conditional Access policy that blocks access when the sign-in risk level is 'High' with an alert notification configured in Identity Protection. The Conditional Access policy enforces the block at the authentication level, while the Identity Protection alert ensures administrators are notified of the high-risk sign-in event. This directly meets the requirement to both block the user and notify an admin.

Exam trap

The trap here is that candidates often confuse user risk policies (which target compromised accounts) with sign-in risk policies (which target risky authentication sessions), leading them to select Option B instead of the correct combination of Conditional Access and alert notifications.

How to eliminate wrong answers

Option B is wrong because a user risk policy in Identity Protection targets user accounts that have been compromised (e.g., leaked credentials) and can block sign-ins or require password reset, but it does not address sign-in risk from a specific session (e.g., anonymous IP address, atypical travel). Option C is wrong because an MFA registration policy in Identity Protection only enforces that users register for multifactor authentication, not that high-risk sign-ins are blocked or that admins are notified. Option D is wrong because Security defaults enforce baseline security policies (like requiring MFA for all users) but do not allow granular control to block only high-risk sign-ins or send targeted admin notifications for such events.

241
MCQhard

You are the Microsoft 365 administrator for a company with a hybrid identity configuration using Azure AD Connect. The company has a custom domain 'contoso.com' federated with Active Directory Federation Services (ADFS). All users are synced from on-premises Active Directory. The security team wants to implement Microsoft Entra ID Protection to detect risky sign-ins. However, they are concerned that federated authentication bypasses some risk detection capabilities. You need to ensure that Microsoft Entra ID Protection can evaluate risk for all sign-ins, including federated ones. What should you do?

A.Switch from federated authentication to Pass-through Authentication (PTA) or Password Hash Sync (PHS).
B.Configure the federated trust in Microsoft Entra ID to use the new claims.
C.Configure ADFS to send the ipaddr and xms_ep claims to Azure AD.
D.Enable Azure AD Application Proxy to publish ADFS internally.
AnswerA

With federated authentication, Azure AD redirects authentication to ADFS, so Azure AD never performs or observes the actual password validation and cannot compute sign-in risk for that exchange. Switching to Pass-through Authentication (PTA) or Password Hash Sync (PHS) makes Azure AD the authentication authority: PTA validates against on-prem AD through an agent, while PHS validates against synced hashes. Because the token is issued by Azure AD after credential verification, Identity Protection can evaluate risk before the user receives access.

Why this answer

Microsoft Entra ID Protection relies on signals such as IP addresses, device information, and sign-in patterns to calculate risk. In a federated setup with ADFS, the authentication happens on-premises, and Azure AD only receives a token—not the raw sign-in details needed for real-time risk evaluation. Switching to Pass-through Authentication (PTA) or Password Hash Sync (PHS) ensures that the authentication process flows through Azure AD directly, allowing Entra ID Protection to capture and analyze all sign-in events, including those from federated users.

Exam trap

The trap here is that candidates may think adding claims (Option C) or changing the trust configuration (Option B) can compensate for the architectural limitation, but only moving the authentication flow to Azure AD (Option A) gives Entra ID Protection the raw sign-in data it needs for real-time risk evaluation.

How to eliminate wrong answers

Option B is wrong because configuring the federated trust to use new claims does not change the fundamental architecture—ADFS still performs authentication, and Azure AD still lacks the raw sign-in data (e.g., IP address, user agent) required for real-time risk detection. Option C is wrong because while sending ipaddr and xms_ep claims can provide some additional context, it does not enable Entra ID Protection to evaluate risk in real time; the authentication still occurs on-premises, and risk evaluation is limited to post-authentication token analysis. Option D is wrong because enabling Azure AD Application Proxy to publish ADFS internally only changes the access method to ADFS, not the authentication flow—federated authentication still bypasses Azure AD's direct sign-in event collection.

242
MCQhard

You are the Microsoft 365 administrator for a company that uses Microsoft 365 E5. The company has a hybrid deployment with Exchange Server 2019 on-premises and Exchange Online. You need to configure a mail flow rule that adds a disclaimer to all emails sent from on-premises mailboxes to external recipients. The disclaimer must be applied only to messages that originate from on-premises and are sent to external domains. What should you do?

A.Create a mail flow rule in the EAC in Exchange Online. Set the rule to apply to messages sent to 'Outside the organization'. Add a condition 'The sender is located' and select 'Inside the organization'. Add an action to prepend a disclaimer. Then create a second rule that applies to messages sent from on-premises mailboxes using a header condition, and block the first rule.
B.Create a mail flow rule in the EAC on the on-premises Exchange Server. Set the rule to apply to messages sent to 'Outside the organization'. Add an action to prepend a disclaimer. Enable the rule.
C.Create a mail flow rule in the EAC in Exchange Online. Set the rule to apply to messages sent to 'Outside the organization'. Add a condition 'The sender is located' and select 'Inside the organization'. Add an action to prepend a disclaimer. Enable the rule.
D.Create a mail flow rule in the Exchange admin center (EAC) in Exchange Online. Set the rule to apply to messages sent to 'Outside the organization'. Add a condition 'The sender is located' and select 'Outside the organization'. Add an action to prepend a disclaimer. Enable the rule.
AnswerC

In a hybrid deployment, on-premises mailboxes are treated as 'Inside the organization' by Exchange Online. Therefore, a rule that applies to messages sent to 'Outside the organization' and has a condition that the sender is located 'Inside the organization' will correctly match messages sent from on-premises mailboxes to external recipients. The action to prepend a disclaimer will add the disclaimer to those messages. This configuration meets the requirement precisely and is the standard method for applying disclaimers to outbound mail from on-premises senders in a hybrid setup.

Why this answer

In a hybrid deployment, on-premises mailboxes are considered part of the organization by Exchange Online. Therefore, a mail flow rule in Exchange Online that applies to messages sent to 'Outside the organization' and has a condition that the sender is located 'Inside the organization' will correctly match messages originating from on-premises mailboxes and sent to external recipients. The disclaimer action then adds the required text.

This is the standard and most reliable method for applying disclaimers to outbound mail from on-premises senders in a hybrid environment.

Exam trap

The trap here is assuming that on-premises mailboxes are considered 'Outside the organization' in Exchange Online, when in fact they are treated as 'Inside the organization' due to the hybrid configuration.

243
MCQeasy

You are a security administrator for a company that uses Microsoft Defender XDR. You need to generate a report that shows the number of incidents closed as true positive, false positive, and benign in the last 30 days. You want to use built-in features without writing custom queries. What should you do?

A.Use the Microsoft Defender for Endpoint reports section.
B.Use the Device health report in Microsoft Defender XDR.
C.Navigate to Threat analytics in the Defender XDR portal.
D.In the Microsoft Defender XDR portal, go to Reports > General > Incident summary.
AnswerD

The Incident summary report is a built-in Defender XDR report that aggregates incident classifications, including true positive, false positive and benign counts, over a selectable period such as 30 days. It satisfies the no-custom-queries constraint directly, unlike advanced hunting or custom workbooks.

Why this answer

The Microsoft Defender XDR portal includes a built-in Reports section under General with an Incident summary report that shows incident counts by classification (true positive, false positive, benign) over a selected period such as 30 days. This requires no custom queries and directly provides the requested metrics. Navigating to Reports > General > Incident summary is the correct built-in path.

Exam trap

MS-102 often tests the trap of choosing Advanced Hunting or Threat Analytics for reporting when the question specifies 'built-in features without custom queries' — the correct answer is the built-in Reports section.

How to eliminate wrong answers

Option A is wrong because the Defender for Endpoint reports section focuses on endpoint-specific reports (device health, threat protection) and does not provide the cross-workload incident classification summary. Option B is wrong because the Device health report shows endpoint sensor health and onboarding status, not incident classifications. Option C is wrong because Threat analytics provides curated threat intelligence and campaign tracking, not a count of incidents by classification.

244
Multi-Selectmedium

Your company is implementing Microsoft Entra Conditional Access. You need to require multifactor authentication (MFA) for all users except those accessing from the corporate office. Which TWO components do you need?

Select 2 answers
A.Microsoft Intune compliance policies
B.Conditional Access policy configured with grant control requiring MFA and excluding Named Locations
C.Named Locations configuration
D.Microsoft Entra multifactor authentication registration policy
E.Microsoft Entra Identity Protection
AnswersB, C

To enforce MFA everywhere except the corporate office, you create a Conditional Access policy assigned to the target users and cloud apps, add your trusted corporate IP ranges as a Named Location, and set that location in the Exclude condition. Then, in Grant, you select 'Require multifactor authentication.' For sign-ins from any IP address that does not match the excluded Named Location, the grant control is applied and MFA is required; for sign-ins from the corporate location, the exclusion prevents MFA from being required. This is the actual policy object that implements the stated requirement.

Why this answer

To require MFA for all users except those accessing from the corporate office, you need a Conditional Access policy that grants access only if MFA is completed, and you must exclude the corporate office location. The 'Named Locations' configuration defines the corporate office IP ranges or trusted locations, and the Conditional Access policy uses that exclusion. Together, these two components enforce the requirement.

Exam trap

The trap here is that candidates often think a separate MFA registration policy (Option D) or Identity Protection (Option E) can handle location-based exclusions, but neither supports excluding Named Locations; only a Conditional Access policy with the 'Exclude' condition on Named Locations can achieve this.

245
MCQeasy

You are the Microsoft 365 administrator for a company that has a Microsoft 365 E3 tenant. The company wants to ensure that users can only access Microsoft 365 services from compliant devices. You need to configure a policy that enforces this requirement. What should you create?

A.A Microsoft 365 compliance policy in the Microsoft Purview compliance portal that restricts access to SharePoint Online.
B.An Intune device compliance policy that blocks access to Exchange Online.
C.A Microsoft Entra Conditional Access policy that requires the device to be marked as compliant.
D.A Microsoft Defender for Cloud Apps session policy that blocks downloads from non-compliant devices.
AnswerC

Conditional Access policies in Microsoft Entra ID can enforce that devices must be marked as compliant by Intune or another MDM solution before granting access to Microsoft 365 services. This directly meets the requirement by evaluating device compliance at sign-in and blocking non-compliant devices.

Why this answer

To enforce that users can only access Microsoft 365 services from compliant devices, you must use a Microsoft Entra Conditional Access policy. This policy evaluates device compliance status at sign-in and grants or blocks access accordingly. Intune compliance policies alone do not enforce access; they only determine compliance status.

Exam trap

The trap here is assuming that an Intune compliance policy alone can block access, when it only reports compliance and requires Conditional Access to enforce.

246
MCQeasy

Your organization uses Microsoft Defender for Office 365. A user reports receiving a phishing email that bypassed the built-in anti-phishing policy. You need to analyze the email headers to determine why it was not detected. What should you use?

A.Attack Simulator in Microsoft Defender for Office 365
B.Threat Explorer in Microsoft Defender for Office 365
C.Message trace in Exchange admin center
D.Quarantine page in Microsoft Defender for Office 365
AnswerB

Threat Explorer provides message trace, detection technology and delivery location per email, letting you determine which anti-phishing control failed and why. It is the Microsoft Defender for Office 365 tool built for investigating individual messages.

Why this answer

Threat Explorer (part of Microsoft 365 Defender's Email & Collaboration section) provides detailed email metadata, including full message headers, delivery action, and the specific policy or filter that processed the message. It lets administrators trace why a message was allowed, blocked, or delivered to junk, and it surfaces the anti-phishing verdict, spoof intelligence, and detection technology that evaluated the message. This is the correct tool for post-incident header analysis of a phishing message that bypassed filtering.

Exam trap

MS-102 often tests the distinction between tools that show message routing (Message trace) versus tools that show detection verdicts and headers (Threat Explorer) — candidates confuse the two because both are email investigation tools.

How to eliminate wrong answers

Option A is wrong because Attack Simulator is used to launch simulated phishing campaigns for user training and to measure click rates — it does not analyze real inbound email headers. Option C is wrong because Message trace in the Exchange admin center only shows the routing and delivery status of messages (sent, delivered, failed) and does not expose anti-phishing verdicts, header-level detection details, or the reason a message bypassed a policy. Option D is wrong because the Quarantine page only lists and manages messages that were already quarantined — a message that bypassed the filter and landed in the inbox would not appear there.

247
MCQhard

Your organization, Contoso Ltd., has a Microsoft 365 E5 tenant with Microsoft Entra ID P2. You have 10,000 users and 500 applications. You are planning to implement a comprehensive identity security strategy. Your requirements are: 1. All users must use phishing-resistant MFA for accessing business-critical applications. 2. Users accessing sensitive HR data must be required to use a compliant device. 3. Any authentication attempt from an anonymous IP address or from a country where Contoso has no business operations must be blocked. 4. All external collaboration must be governed by access reviews that require sponsor approval. 5. You need to monitor and respond to identity risks in real time. You need to design a solution using Microsoft Entra ID features. Which combination of features should you implement?

A.Deploy Microsoft Entra ID authentication strengths for phishing-resistant MFA. Create Conditional Access policies requiring compliant device for HR apps and blocking anonymous IPs and non-business countries. Use Microsoft Entra Identity Protection for risk detection and automated response. Implement entitlement management with connected organizations and access reviews requiring sponsor approval.
B.Configure Conditional Access policies with MFA and trusted locations. Use Identity Protection for risk monitoring. Set up access reviews with group owner approval.
C.Enable security defaults for all users. Use Microsoft Defender for Cloud Apps to block anonymous IPs. Configure Azure AD access reviews for external users.
D.Use certificate-based authentication for all users. Create Conditional Access policies for device compliance. Set up identity protection. Use self-service access reviews for external users.
AnswerA

Authentication strengths enforce phishing-resistant MFA, while Conditional Access applies compliant-device and location blocks. Identity Protection supplies real-time risk detection with automated remediation, and entitlement management with connected organisations plus sponsor-approved access reviews governs external collaboration, meeting all five stated requirements.

Why this answer

Option A correctly maps all requirements to Microsoft Entra ID features: authentication strengths for phishing-resistant MFA, Conditional Access for device compliance and location-based blocks, Identity Protection for risk monitoring and automated response, and entitlement management with access reviews for external collaboration governance. This combination leverages the full capabilities of Microsoft Entra ID P2 and E5 licenses.

Exam trap

MS-102 often tests the confusion between authentication methods (e.g., certificate-based) and authentication strengths, and between access reviews with group owner approval versus sponsor approval, leading candidates to choose incomplete solutions.

How to eliminate wrong answers

Option B is wrong because it uses MFA (not phishing-resistant) and trusted locations (which may not block all non-business countries), and access reviews with group owner approval do not require sponsor approval as specified. Option C is wrong because security defaults only provide basic MFA and do not support phishing-resistant methods or granular Conditional Access; Defender for Cloud Apps is not the primary tool for blocking anonymous IPs (Conditional Access is), and access reviews for external users lack sponsor approval. Option D is wrong because certificate-based authentication is not necessarily phishing-resistant (it can be if configured with strong factors, but authentication strengths is the correct feature), and self-service access reviews do not enforce sponsor approval.

248
MCQeasy

Your organization uses Microsoft 365 Business Premium. You need to ensure that when a user is assigned an Intune license, the device automatically enrolls in Microsoft Intune. What should you configure?

A.Configure Microsoft Entra ID device settings to enable MDM automatic enrollment
B.Create a device compliance policy to require enrollment
C.Create a device enrollment restriction in Intune to block personal devices
D.Deploy a device configuration profile with enrollment settings
AnswerA

In Microsoft Entra ID, under Device settings, the 'Enable automatic enrollment for MDM' option (also known as MDM user scope) directs the identity provider to register and enroll devices into the configured MDM authority, Intune, as part of the user sign-in flow. Because every user in the organization holds a Microsoft 365 Business Premium license that includes Intune, toggling this setting causes their devices to automatically enroll upon authentication and license assignment. This is the only option that actively triggers enrollment; the other options are post-enrollment or pre-enrollment controls that do not initiate the enrollment process.

Why this answer

Microsoft Entra ID (formerly Azure AD) device settings include an option to enable automatic MDM enrollment for users assigned an Intune license. When enabled, any device that signs in with a licensed user account will automatically enroll in Microsoft Intune, satisfying the requirement without additional configuration.

Exam trap

The trap here is that candidates often confuse device compliance policies or configuration profiles with the enrollment trigger, but only the Microsoft Entra ID device settings control the automatic MDM enrollment behavior.

How to eliminate wrong answers

Option B is wrong because a device compliance policy checks compliance after enrollment, it does not trigger automatic enrollment. Option C is wrong because enrollment restrictions control which devices can enroll (e.g., blocking personal devices), but they do not enable automatic enrollment. Option D is wrong because a device configuration profile applies settings to already enrolled devices, it does not initiate the enrollment process.

249
Multi-Selecthard

You are designing a Microsoft 365 tenant for a multinational organization. You need to ensure compliance with data residency requirements. Which THREE actions should you take?

Select 3 answers
A.Set data location preferences in the Microsoft 365 admin center.
B.Disable cross-region replication in Exchange Online.
C.Use compliance boundaries for eDiscovery.
D.Create data loss prevention policies for each region.
E.Configure Microsoft 365 Multi-Geo.
AnswersA, C, E

During initial tenant provisioning, the Microsoft 365 admin center's data location setting lets you choose the main geographic region (for example, Europe, Asia Pacific) where core Microsoft 365 data for the tenant will be stored at rest. This selection determines the primary residency for Exchange Online mailboxes, SharePoint/OneDrive content, and Teams data. Because the choice is made at tenant creation and is largely immutable for existing tenants, it must be aligned with the multinational's data-residency requirements before provisioning begins.

Why this answer

Setting data location preferences in the Microsoft 365 admin center (under Settings > Org Settings > Organization Information) allows you to specify the primary data residency region for your tenant. This ensures that core data at rest, such as Exchange Online mailboxes and SharePoint sites, is stored in the selected geographic location to meet compliance requirements.

Exam trap

The trap here is that candidates often confuse data residency (where data is stored) with data protection (DLP policies) or replication settings, leading them to select DLP policies or disabling replication instead of the correct Multi-Geo and compliance boundary options.

250
MCQeasy

A user reports that they cannot access their Microsoft 365 mailbox via Outlook on the web. Other users can access their mailboxes. What is the most likely cause?

A.The user's password has expired
B.The Exchange Online service is experiencing an outage
C.The user's browser cache needs to be cleared
D.The user does not have an Exchange Online license assigned
AnswerD

Exchange Online licenses are assigned per user through the Microsoft 365 admin center or Azure AD, and each user needs an active license with the Exchange Online service plan before a mailbox is provisioned. Without that license, the user remains able to authenticate to Microsoft 365 and use other services, but Outlook on the web will fail with a 'no mailbox' or 'license' error because Exchange does not find a recipient object. This exactly matches the reported scenario: one user cannot access their Exchange Online mailbox while other functionality may still work.

Why this answer

The most likely cause is that the user does not have an Exchange Online license assigned. Without a valid license, the user's mailbox is not provisioned, and Outlook on the Web (OWA) cannot access it. Other users can access their mailboxes because they have licenses, ruling out a service-wide issue.

Exam trap

The trap here is that candidates confuse authentication issues (password expired) with authorization or licensing issues, assuming that if a user can log in to the Microsoft 365 portal, they automatically have a mailbox.

How to eliminate wrong answers

Option A is wrong because an expired password would prevent authentication entirely, but the user would see a login prompt or password error, not a mailbox access issue after login. Option B is wrong because an Exchange Online outage would affect all users, not just one. Option C is wrong because clearing browser cache resolves display or rendering issues, not access to the mailbox itself; if the mailbox is unlicensed, no amount of cache clearing will help.

251
Multi-Selecthard

Which THREE features are included in Microsoft Defender for Office 365 Plan 2 but NOT in Plan 1? (Choose three.)

Select 3 answers
A.Anti-phishing policies
B.Safe Links
C.Automated Investigation and Response (AIR)
D.Threat Explorer
E.Attack Simulation Training
AnswersC, D, E

Automated Investigation and Response (AIR) is a premium Plan 2 capability that uses orchestration and automation to investigate alerts, analyze threat signals, and take recommended or automated remediation actions. It goes beyond passive detection by proactively resolving incidents without requiring continuous manual oversight, making it a key differentiator for Plan 2 licensing.

Why this answer

Automated Investigation and Response (AIR) (C) is exclusive to Defender for Office 365 Plan 2, as it uses automated playbooks to investigate and remediate threats, which Plan 1 does not include. Threat Explorer (D) is also a Plan 2-only feature, providing real-time and historical threat hunting and reporting capabilities that are absent from Plan 1. Attack Simulation Training (E) is likewise included only in Plan 2, enabling organizations to run simulated phishing and social engineering attacks to train users.

Anti-phishing policies (A) and Safe Links (B) are available in both Plan 1 and Plan 2, so they are not correct answers for features unique to Plan 2.

Exam trap

MS-102 often tests the boundary between P1 protection features and P2 investigation features, so candidates incorrectly include Safe Links or anti-phishing as P2 exclusives.

252
MCQmedium

A company wants to require MFA for all users when they access Office 365 from any network location that is not the company's trusted IP ranges. Which Conditional Access policy configuration should be applied?

A.A: Include all users, exclude none, grant access require MFA with condition 'Location not in trusted locations'.
B.B: Include all users, exclude none, block access with condition 'Location not in trusted locations'.
C.C: Include all users, exclude trusted locations as a group, grant access require MFA.
D.D: Include all users, exclude all locations, grant access require MFA.
AnswerA

This policy correctly scopes the requirement: every user is in scope, and the location condition is evaluated during sign-in. When a user's IP address is not within a trusted location (i.e., an IP range you have designated as trusted), the grant control 'Require MFA' is enforced, prompting for multifactor authentication. When the user is in a trusted location, the condition is not satisfied and the policy does not apply, so MFA is not required—matching the business requirement exactly. The location condition acts as a filter, not an assignment, which is the intended design.

Why this answer

Ly configures a Conditional Access policy that targets all users and applies the 'Require MFA' grant control when the location condition is set to 'Any location' except the company's trusted IP ranges. This ensures MFA is enforced for all access attempts originating from outside the trusted network, meeting the requirement precisely.

Exam trap

The trap here is that candidates often confuse excluding a group (like 'All trusted users') with using the location condition to exclude trusted IP ranges, leading them to choose Option C, which incorrectly removes the location-based trigger entirely.

How to eliminate wrong answers

Option B is wrong because blocking access entirely for untrusted locations would prevent users from working remotely, which is not the requirement; the requirement is to require MFA, not block. Option C is wrong because excluding trusted locations as a group from the policy scope would mean the policy does not evaluate those locations at all, but the requirement is to apply MFA to all users when they are not in trusted locations, which is best handled by the location condition, not by excluding a group. Option D is wrong because excluding all locations would mean the policy never evaluates any location condition, effectively disabling the location-based trigger, so MFA would not be enforced based on network location.

253
MCQmedium

Your organization uses Microsoft 365 and has strict compliance requirements. The compliance officer has noticed that some users are able to access sensitive documents from unmanaged devices. You need to ensure that all access to sensitive data from unmanaged devices is blocked, while still allowing access from managed devices. The solution must be implemented using Microsoft Entra ID and Microsoft Intune. You have already deployed Microsoft Intune for mobile device management. What should you do?

A.Enable device compliance rules in Microsoft Entra ID and assign them to all users.
B.Create a device compliance policy in Microsoft Intune that requires a PIN and encryption.
C.Create an app protection policy in Microsoft Intune that requires managed apps to be used on unmanaged devices.
D.Create a conditional access policy in Microsoft Entra ID that requires device to be marked as compliant, and apply it to all cloud apps.
AnswerD

A conditional access policy requiring compliant devices blocks unmanaged devices while permitting Intune-managed ones, since compliance state is evaluated per device. Applying it to all cloud apps enforces this across Microsoft 365 workloads, satisfying the strict compliance requirement.

Why this answer

A Conditional Access policy that requires the device to be marked as compliant enforces that only Intune-managed, compliant devices can access cloud apps. This blocks unmanaged devices because they cannot satisfy the compliance requirement, while managed devices that meet the compliance policy are allowed. This directly satisfies the requirement to block unmanaged device access using Entra ID and Intune.

Exam trap

The trap is confusing app protection policies (which protect data but allow access) with device compliance Conditional Access (which blocks access from non-compliant/unmanaged devices).

How to eliminate wrong answers

Option A is wrong because device compliance rules alone do not enforce access; they must be referenced in a Conditional Access policy to have effect. Option B is wrong because a compliance policy defines what makes a device compliant but does not block access by itself. Option C is wrong because app protection policies (MAM) protect data within apps on unmanaged devices but do not block access to sensitive documents from unmanaged devices.

254
MCQmedium

A company uses Azure AD Connect with password hash synchronization. They want to allow users to reset their on-premises Active Directory passwords from the cloud Self-Service Password Reset (SSPR) portal. Which additional configuration is required in Azure AD Connect?

A.Enable password writeback
B.Enable self-service password reset in Azure AD
C.Configure Federation Services (AD FS)
D.Install Azure AD Application Proxy
AnswerA

Password writeback in Azure AD Connect is the component that synchronizes password changes from Azure AD back to on-premises Active Directory. With password hash sync, the cloud authentication works, but a cloud-initiated reset only updates the Azure AD password unless writeback is enabled. This feature requires Azure AD Premium and an on-premises service account with rights to update user passwords, ensuring the next sign-in with on-premises credentials uses the new password.

Why this answer

Password writeback is the specific feature in Azure AD Connect that enables password changes performed in the cloud (via SSPR) to be written back to the on-premises Active Directory. Without this feature enabled and configured, the SSPR portal can only reset cloud-only passwords, not synchronized on-premises passwords. Therefore, enabling password writeback is the additional configuration required beyond the existing password hash synchronization.

Exam trap

The trap here is that candidates often confuse enabling SSPR in Azure AD (a tenant-level setting) with the specific Azure AD Connect feature (password writeback) that is required to make SSPR work for synchronized users, leading them to select Option B instead of A.

How to eliminate wrong answers

Option B is wrong because enabling self-service password reset in Azure AD is a prerequisite for the SSPR portal itself, not the additional configuration required in Azure AD Connect to write the reset password back to on-premises AD. Option C is wrong because Federation Services (AD FS) is not required for password writeback; password writeback works with password hash synchronization and does not require federation. Option D is wrong because Azure AD Application Proxy is used for publishing on-premises web applications externally, not for password synchronization or writeback.

255
MCQmedium

A security analyst runs the above KQL query in Microsoft 365 Defender. The query returns an empty result set. Which is the most likely reason?

A.The time range is too wide and the query times out.
B.No antivirus detection events for files with 'ransomware' or 'encrypt' in the filename occurred in the last 7 days.
C.The 'has_any' operator is used incorrectly; it should be 'contains' for each condition.
D.The DeviceEvents table does not contain antivirus detection events.
AnswerB

The query returned zero rows because no antivirus detection events with a filename containing the exact term 'ransomware' or 'encrypt' were logged in the last 7 days. This is a valid, actionable result; it does not mean the query is flawed. To uncover broader suspicious activity, reduce reliance on the filename term match or use contains for substring matching, and consider expanding the time range or adding related tables like DeviceFileEvents.

Why this answer

The KQL query filters DeviceEvents for antivirus detection events where the filename contains 'ransomware' or 'encrypt' within the last 7 days. An empty result set simply means no such events matched the filter criteria during that period — this is a normal, expected outcome when no ransomware-like files were detected, not an error condition. The query syntax and table are valid; the absence of data is the answer.

Exam trap

MS-102 often tests whether candidates confuse an empty query result with a query error or misconfiguration, when in fact the absence of matching events is the correct interpretation.

How to eliminate wrong answers

Option A is wrong because a wide time range does not cause a timeout in Microsoft 365 Defender's advanced hunting — queries are limited by result count and execution time, but a 7-day window is well within limits and would not silently return empty. Option C is wrong because 'has_any' is a valid KQL operator that checks if any of the specified values appear in the field; it is not a syntax error, and 'contains' would be less efficient and semantically different. Option D is wrong because the DeviceEvents table does contain antivirus detection events (e.g., AntivirusDetection action types), so the table is the correct source.

256
Multi-Selecthard

Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that detects when a user shares a file containing sensitive data with an external domain. Which three components must you configure in the policy? (Choose three.)

Select 3 answers
A.A content inspection method (e.g., DLP)
B.A governance action (e.g., alert, block)
C.A filter to specify the sharing type (e.g., external)
D.A session control action
E.An access token condition
AnswersA, B, C

Content inspection, such as DLP, examines the file payload to confirm it actually contains sensitive data, satisfying the stem's sensitive-data condition. Sharing filters alone cannot determine content; inspection is what distinguishes a genuine sensitive-data exposure from an ordinary external share.

Why this answer

The correct components for a file policy in Microsoft Defender for Cloud Apps are: a filter to specify the scope (e.g., sharing with external users), a content inspection method (e.g., DLP) to detect sensitive data, and a governance action (e.g., alert or block). Option D is incorrect because session control actions are used in session policies, not file policies. Option E is incorrect because access token conditions are not a component of file policies.

257
MCQmedium

A security administrator wants to prevent Microsoft Office applications (Word, Excel, PowerPoint) from creating child processes, which is a common technique used by malware to execute malicious code. Which attack surface reduction (ASR) rule should be enabled?

A.Block all Office applications from creating child processes
B.Block executable files from running unless they meet a prevalence, age, or trusted list criteria
C.Block Office applications from creating executable content
D.Block Win32 API calls from Office macros
AnswerA

This Attack Surface Reduction (ASR) rule, identified by rule GUID 26190899-1602-49e8-8b27-eb1d0a1ce869, specifically targets the parent-child relationship where winword.exe, excel.exe, or powerpnt.exe attempts to launch any secondary executable. By blocking the creation of child processes such as cmd.exe, powershell.exe, or wscript.exe, it directly neutralizes the described macro-based attack chain before the payload can execute. This is the only option among these that was designed to stop exactly this process-spawn behavior.

Why this answer

The ASR rule 'Block all Office applications from creating child processes' (GUID: D4F940AB-401B-4EFC-AADC-AD5F3C50688A) specifically prevents Word, Excel, and PowerPoint from spawning child processes such as cmd.exe, PowerShell, or wscript.exe. This directly mitigates a common malware technique where Office macros or exploits launch malicious executables. The rule is part of Microsoft Defender for Endpoint's attack surface reduction capabilities and is designed to stop process injection and lateral movement without blocking legitimate Office functionality.

Exam trap

The trap here is that candidates confuse 'creating child processes' with 'creating executable content' or 'blocking Win32 API calls,' leading them to choose options that address file writes or macro restrictions rather than the specific process spawning behavior.

How to eliminate wrong answers

Option B is wrong because 'Block executable files from running unless they meet a prevalence, age, or trusted list criteria' is an ASR rule that targets executable files (e.g., .exe, .dll) based on reputation, not Office child process creation. Option C is wrong because 'Block Office applications from creating executable content' prevents Office apps from writing executable files (e.g., .exe, .scr) to disk, but does not block the spawning of child processes. Option D is wrong because 'Block Win32 API calls from Office macros' disables macros from calling Win32 APIs (e.g., via VBA), which is a different attack vector; it does not prevent Office apps from creating child processes through other means like OLE or DDE.

258
MCQhard

You are a security administrator for a company that uses Microsoft Defender XDR. The security team wants to identify all devices that have communicated with a specific malicious IP address over the past 30 days. They need to run an advanced hunting query. Which table should they query?

A.DeviceEvents
B.DeviceProcessEvents
C.DeviceNetworkEvents
D.DeviceFileEvents
AnswerC

DeviceNetworkEvents contains network connection events from devices, including remote IP addresses and ports. Querying this table allows you to filter by RemoteIP and time range to find devices that communicated with the malicious IP. This is the correct table for network communication history in Microsoft Defender XDR advanced hunting.

Why this answer

DeviceNetworkEvents is the dedicated table for network connection events in Microsoft Defender XDR advanced hunting. It includes fields like RemoteIP, LocalIP, and RemotePort, enabling precise filtering for communications with a specific malicious IP address.

Exam trap

The trap here is confusing general device event tables with the specialized network events table, leading to incomplete or inaccurate query results.

259
MCQhard

Your organization uses Microsoft 365 E5 licenses. You need to implement a secure score improvement plan. After reviewing the Secure Score, you notice a recommendation to 'Enable sign-in risk policy' in Microsoft Entra ID. However, you want to ensure that users who sign in from trusted locations are not challenged. What should you configure?

A.Configure named locations in Microsoft Entra ID for trusted IPs.
B.Enable the 'Sign-in risk' policy in Identity Protection and set 'Exclude trusted locations'.
C.Enable the 'Require MFA for all users' conditional access policy.
D.Create a conditional access policy that targets sign-in risk: medium and above, require MFA, and exclude trusted named locations.
AnswerD

This policy applies the 'Grant' control 'Require MFA' only when the 'Sign-in risk' condition is evaluated as medium or higher, and it explicitly excludes users who sign in from a named location marked as trusted. When a sign-in originates from an excluded trusted location, the policy is not evaluated, allowing seamless access without MFA. For risky sign-ins coming from any other IP, the policy triggers MFA, thereby satisfying the requirement to require MFA for medium+ risk while exempting trusted locations.

Why this answer

It creates a Conditional Access policy that targets sign-in risk at medium and above, requiring MFA, while excluding trusted named locations. This ensures users from trusted IPs are not challenged, directly addressing the requirement to avoid unnecessary prompts for trusted sign-ins while still enforcing risk-based policies.

Exam trap

The trap here is that candidates confuse Identity Protection's risk policies with Conditional Access policies, assuming exclusions are set directly in Identity Protection rather than through Conditional Access, leading them to select Option B.

How to eliminate wrong answers

Option A is wrong because configuring named locations alone does not enforce a sign-in risk policy; it only defines trusted IPs, which must be referenced in a Conditional Access policy to have effect. Option B is wrong because the 'Sign-in risk' policy in Identity Protection does not have an 'Exclude trusted locations' setting; exclusions are handled via Conditional Access policies, not within Identity Protection itself. Option C is wrong because 'Require MFA for all users' is a blanket policy that does not consider sign-in risk or trusted locations, so it would challenge users from trusted locations unnecessarily.

260
MCQmedium

Your organization has a Microsoft 365 tenant configured with a custom domain. You need to verify domain ownership using a TXT record. Where in the Microsoft 365 admin center would you initiate this process?

A.Settings > Domains
B.Setup > Org-wide settings
C.Users > Active Users
D.Admin centers > Azure Active Directory
AnswerA

Settings > Domains is the correct location in the Microsoft 365 admin center for adding, verifying, and managing custom domains. From this blade, you can initiate domain verification via a DNS TXT record or MX record, designate a primary domain, set the domain for services like Exchange Online, and monitor domain health. This is the unified domain management interface that most administrators use for day-to-day domain lifecycle tasks.

Why this answer

To verify domain ownership in Microsoft 365, you must add a TXT record provided by Microsoft to your domain's DNS zone. The process is initiated in the Microsoft 365 admin center under Settings > Domains, where you select the domain and click 'Start setup' to receive the verification TXT record value. This is the only location in the admin center that directly manages domain verification and DNS record validation for custom domains.

Exam trap

The trap here is that candidates may confuse domain verification with other domain-related tasks (like setting up email routing or managing user accounts) and select Setup > Org-wide settings or Users > Active Users, but only Settings > Domains provides the guided wizard for adding and verifying a custom domain via TXT records.

How to eliminate wrong answers

Option B is wrong because Setup > Org-wide settings contains organization-wide configuration options like security policies, profiles, and external sharing settings, but does not include domain management or DNS verification tasks. Option C is wrong because Users > Active Users is for managing user accounts, licenses, and permissions, not for domain ownership verification which is a DNS-level process. Option D is wrong because Admin centers > Azure Active Directory opens the Azure AD portal, which can manage custom domains but is not the primary or recommended path in the Microsoft 365 admin center for initiating TXT record verification; the correct path is Settings > Domains within the M365 admin center itself.

261
MCQmedium

A company uses Microsoft Entra ID P2 licenses and wants to block all authentication attempts from an internal legacy application that uses POP3 and SMTP protocols. The application cannot be updated and must be blocked from accessing Exchange Online. Which Conditional Access policy setting should the administrator configure?

A.Under 'Grant', select 'Block access'
B.Under 'Conditions' > 'Client apps', configure to block 'Exchange ActiveSync clients and other clients'
C.Under 'Conditions' > 'Device platforms', select 'Android' and 'iOS' and block them
D.Under 'Conditions' > 'Locations', select 'All trusted locations' and block
AnswerB

The 'Client apps' condition in Entra ID Conditional Access directly matches the authentication protocol used by the client. By selecting 'Exchange ActiveSync clients' and 'Other clients' (which cover POP3, IMAP, SMTP, and other non-modern authentication), you can explicitly block those legacy protocols while allowing modern, MFA-capable clients to continue. This is the precise and least disruptive way to enforce the security requirement.

Why this answer

The legacy application uses POP3 and SMTP, which are non-modern authentication protocols. In Conditional Access, the 'Client apps' condition includes a setting to block 'Exchange ActiveSync clients and other clients', which specifically targets legacy authentication protocols like POP3, SMTP, and IMAP. This allows the administrator to block all authentication attempts from such clients without affecting modern authentication flows.

Exam trap

The trap here is that candidates often confuse 'Client apps' with device or location conditions, mistakenly thinking that blocking a device platform or location will stop legacy protocol traffic, when in fact legacy authentication bypasses those controls entirely because it does not use modern token-based authentication.

How to eliminate wrong answers

Option A is wrong because 'Block access' under 'Grant' is a coarse control that blocks all access for the targeted users or apps, but it does not specifically target legacy protocols like POP3/SMTP; it would block all authentication methods, including modern ones, which is not the requirement. Option C is wrong because 'Device platforms' controls access based on the operating system (e.g., Android, iOS), not the authentication protocol; blocking Android and iOS would not affect a legacy application running on a server or desktop using POP3/SMTP. Option D is wrong because 'Locations' controls access based on network location (e.g., trusted IP ranges), not the authentication protocol; blocking trusted locations would not block the legacy application if it originates from an untrusted location, and it does not address the protocol-specific requirement.

262
Multi-Selectmedium

A security analyst is creating a custom detection rule in Microsoft 365 Defender Advanced Hunting. The rule should trigger when a user receives a phishing email containing a malicious URL and then clicks that URL within 10 minutes. Which two Advanced Hunting tables must be joined in the KQL query?

Select 2 answers
A.EmailEvents and UrlClickEvents
B.EmailEvents and DeviceProcessEvents
C.EmailUrlInfo and UrlClickEvents
D.EmailAttachmentInfo and UrlClickEvents
AnswersA, C

EmailEvents tracks email delivery metadata only, such as sender, recipient, subject, delivery action, and message ID, but it does not enumerate the URLs contained in the message body. UrlClickEvents references the clicked URL but does not include the email's NetworkMessageId unless the URL was part of a Safe Links click from an email, and even then you need URL information to correlate. Without the URL-to-email mapping that EmailUrlInfo provides, joining EmailEvents to UrlClickEvents is not straightforward and would require a separate enrichment step, so this pairing is incorrect for URL-click detection.

Why this answer

The rule requires detecting when a user receives a phishing email with a malicious URL and then clicks that URL within 10 minutes. Two separate joins can accomplish this:

**EmailEvents and UrlClickEvents**: EmailEvents contains metadata about email delivery (including NetworkMessageId), and UrlClickEvents records user clicks on URLs in Microsoft Defender for Office 365 Safe Links. Joining these tables on NetworkMessageId (and optionally URL hash) allows correlating the email receipt with the click event, enabling the time-based trigger.

**EmailUrlInfo and UrlClickEvents**: EmailUrlInfo provides details on URLs found within emails (including the URL and its verdict), and UrlClickEvents logs clicks. Joining on the URL hash (SHA256) directly correlates the email-delivered URL with the user's click, also enabling the time-based trigger.

Both pairs are valid and commonly used depending on the specific data needed. Option B (DeviceProcessEvents) is irrelevant as it deals with process execution, not email or URL clicks. Option D (EmailAttachmentInfo) pertains to attachments, not URLs.

Exam trap

Candidates often assume that only one combination is correct, but both EmailEvents+UrlClickEvents (via NetworkMessageId) and EmailUrlInfo+UrlClickEvents (via UrlHash) are valid ways to link the email to the click. The trick is recognizing that EmailEvents is indeed needed when using that path, and EmailUrlInfo is not required if you directly join on NetworkMessageId.

263
MCQhard

Your organization uses Microsoft Entra ID and has a custom role that grants 'microsoft.directory/applications/credentials/update' permission. A security audit reveals that a user assigned this role has modified credentials for an application. You need to prevent such actions while allowing other application updates. What should you do?

A.Assign the user the built-in Application Administrator role instead.
B.Enable multi-factor authentication for the user.
C.Remove the user from the custom role and assign them another role with fewer permissions.
D.Create a custom role that excludes the 'microsoft.directory/applications/credentials/update' permission and assign it to the user.
AnswerD

Creating a custom role that omits the 'microsoft.directory/applications/credentials/update' permission ensures the user cannot change application secrets, certificates, or passwords, while still allowing other application management actions. Custom roles in Microsoft Entra ID allow you to compose a permission set from the available permissions, enabling you to exclude sensitive operations. Assigning this custom role to the user satisfies the requirement to prevent credential updates without over-restricting other updates.

Why this answer

The custom role currently includes the 'microsoft.directory/applications/credentials/update' permission, which allows modifying application credentials. To prevent credential updates while still permitting other application updates, you must create a new custom role that explicitly excludes this permission and assign it to the user. This approach preserves granular control without granting unnecessary privileges, unlike built-in roles that would either over-scope or under-scope permissions.

Exam trap

The trap here is that candidates may think removing the user from the custom role and assigning a different role (Option C) is the simplest fix, but that would likely revoke all application update permissions, failing the requirement to allow other updates.

How to eliminate wrong answers

Option A is wrong because assigning the built-in Application Administrator role grants broader permissions, including the ability to update credentials, which does not solve the problem. Option B is wrong because enabling multi-factor authentication enhances security but does not restrict the user's existing permissions to modify credentials. Option C is wrong because removing the user from the custom role and assigning another role with fewer permissions would likely remove all application update capabilities, which is too restrictive and does not allow other application updates.

264
Matchingmedium

Match each Microsoft 365 Defender portal component to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Protects email and collaboration tools

Protects devices from threats

Protects on-premises Active Directory

Protects cloud applications

Unified threat protection dashboard

Why these pairings

The correct matches are Incidents with 'collection of related alerts', Alerts with 'individual notifications', and Hunting with 'proactive search'. The definitions for Threat Analytics and Secure Score are swapped in options C and D.

265
MCQhard

You are a security administrator for a company that uses Microsoft Defender XDR. You need to configure automated investigation and response (AIR) in Microsoft Defender for Endpoint to automatically remediate threats. You want to ensure that when a high-severity alert is triggered, the device is isolated and the malicious file is quarantined without manual intervention. Which setting should you configure?

A.Automation level in Microsoft Defender for Endpoint settings
B.Advanced hunting custom detection rules
C.Attack surface reduction rules
D.Alert notification rules in Microsoft 365 Defender
AnswerA

The automation level setting in Microsoft Defender for Endpoint determines how automated investigations and response actions are taken. Setting it to 'Full - remediate threats automatically' allows the system to automatically isolate devices and quarantine files upon high-severity alerts, achieving the required no-manual-intervention remediation.

Why this answer

The automation level setting in Microsoft Defender for Endpoint controls whether automated investigations automatically remediate threats. Setting it to full automation enables the system to isolate devices and quarantine files without human intervention when high-severity alerts occur, meeting the requirement.

Exam trap

The trap here is assuming that custom detection rules or alert notifications can perform remediation, but they only detect or notify, not act.

266
MCQeasy

An administrator wants to verify ownership of a custom domain 'adatum.com' in their Microsoft 365 tenant. They have already added the domain and received the TXT record value. However, the administrator's DNS hosting provider does not support adding a TXT record. Which alternative record type can be used for domain verification?

A.record
B.MX record
C.SRV record
D.NS record
AnswerB

Microsoft 365 permits two common verification methods: a TXT record containing 'MS=msXXXXXX' or an MX record pointing to 'msXXXXXX.adatum.com'. The MX verification record is a valid alternative that works by having you create a mail exchanger record with the exact verification token as the mail host. This record is non-authoritative and does not affect mail routing because it points to a Microsoft verification endpoint that only checks for the token. Once the token is confirmed, the MX record can be safely removed.

Why this answer

When a DNS hosting provider does not support TXT records, Microsoft 365 allows the use of an MX record as an alternative for domain verification. The administrator creates an MX record with a specific subdomain (e.g., 'adatum-com.mail.protection.outlook.com') and a custom priority value provided in the TXT record value, which Microsoft's verification system checks to confirm domain ownership. This method is supported because MX records are widely available and can carry the necessary verification data in their format.

Exam trap

The trap here is that candidates may assume only TXT records can verify domain ownership, overlooking that Microsoft 365 explicitly supports MX records as an alternative when TXT records are unavailable, which is a common scenario in restrictive DNS environments.

How to eliminate wrong answers

Option A is wrong because 'A record' maps a domain to an IPv4 address and cannot carry the verification string required by Microsoft 365; it is not a supported alternative for domain verification. Option C is wrong because 'SRV record' specifies the location of services (like SIP or LDAP) and is not used for domain ownership verification in Microsoft 365. Option D is wrong because 'NS record' delegates a domain to a set of name servers and does not support embedding a verification token; it would change the domain's authoritative servers rather than prove ownership.

267
MCQmedium

An organization plans to automatically assign Microsoft 365 E3 licenses to all users in the 'Finance' department. The Finance department is identified by the 'Department' attribute in Azure AD. Which method should the administrator use to minimize manual effort?

A.Group-based licensing using a dynamic group with the rule 'user.department -eq "Finance"'
B.Manual assignment using PowerShell
C.Bulk assignment using a CSV file
D.Self-service licensing portal
AnswerA

In this solution, Azure AD group-based licensing is combined with a dynamic group whose membership rule filters users where user.department equals 'Finance'. As new Finance employees are created, they automatically become group members based on their department attribute, and Azure AD evaluates membership to provision the Microsoft 365 E3 license within minutes. If a user's department changes, membership is recalculated and the license is automatically removed, providing fully automatic, attribute-driven lifecycle management.

Why this answer

Dynamic group licensing in Azure AD uses attribute-based membership rules, so a rule like 'user.department -eq "Finance"' automatically adds all Finance users to the group. Assigning the Microsoft 365 E3 license to that group means every current and future Finance user receives the license without manual intervention, which is the lowest-effort, most scalable approach.

Exam trap

The trap is choosing a one-time bulk method (CSV or PowerShell) when the requirement is ongoing automation — dynamic group licensing is the only option that handles future users automatically.

How to eliminate wrong answers

Option B is wrong because manual PowerShell assignment requires scripting and re-running whenever users join or leave Finance, which is not minimal effort. Option C is wrong because bulk CSV assignment is a one-time operation that does not automatically handle future users. Option D is wrong because a self-service portal shifts the work to users and does not guarantee correct license assignment.

268
MCQhard

Your organization, Fabrikam Inc., uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Microsoft Teams. You have a DLP policy that blocks sharing of credit card numbers in Teams messages. Recently, users have reported that they cannot share legitimate credit card numbers for business purposes, even with customers. You need to allow users to override the block for legitimate sharing, but require them to provide a business justification. What should you configure?

A.Create a second DLP policy with a lower priority that allows credit card sharing, and assign it to a security group containing authorized users.
B.Add the users to an exempt group in the DLP policy so they are not blocked.
C.Configure the DLP policy to show a policy tip that allows users to override the block with a business justification, and enable audit logging for overrides.
D.Configure the DLP policy to allow overrides without justification, and monitor usage.
AnswerC

Enabling the override with justification in the policy tip satisfies the requirement to permit legitimate sharing while capturing a reason. The policy tip appears in Teams, letting users proceed after entering a business justification, and audit logging records each override for later review and compliance reporting.

Why this answer

DLP policy tips in Microsoft Teams can be configured to allow users to override a block, and the override can require a business justification that is captured in the audit log. This preserves the protective control while providing a documented exception path for legitimate business scenarios like sharing a customer's own credit card number. Enabling audit logging ensures the override and justification are recorded for compliance review.

Exam trap

MS-102 often tests the confusion between exempting users from a DLP policy (removing all protection) and configuring a policy tip with override (preserving protection while allowing documented exceptions) — candidates pick the exemption path thinking it is more granular when it is actually broader.

How to eliminate wrong answers

Option A is wrong because creating a second lower-priority allow policy does not provide a per-incident override with justification — it silently permits sharing for an entire group, removing the control rather than creating a documented exception. Option B is wrong because exempting users from the DLP policy removes all protection for them, which is broader than needed and defeats the purpose of the policy. Option D is wrong because allowing overrides without requiring justification removes the accountability and audit trail that compliance requires; the question explicitly states users must provide a business justification.

269
MCQhard

A security analyst has identified a new malware sample with SHA256 hash 'abc123...'. They need to immediately block this file from executing on any managed endpoint across the organization. Which Microsoft Defender for Endpoint capability should they use?

A.Attack surface reduction rules
B.Indicators (IoC)
C.Automated investigation and response
D.Threat analytics
AnswerB

Indicators of compromise (IoC) in Microsoft 365 Defender for Endpoint let administrators explicitly define block actions for known malicious artifacts, including file SHA-256 hashes, IP addresses, URLs, and domains. After the analyst obtains the malware sample's exact hash, they can create a file indicator (with action 'Block and remediate') so that Defender blocks execution across managed endpoints. This is the only option here that directly provides granular, hash-based allow/block control rather than relying on behavioral heuristics or post-detection response.

Why this answer

Indicators of Compromise (IoC) in Microsoft Defender for Endpoint allow security analysts to create custom indicators (such as file hashes, IPs, or URLs) that are immediately enforced across all managed endpoints. This capability enables blocking execution of a specific SHA256 hash at the kernel level via the Microsoft Defender Antivirus driver, providing near-instant protection without requiring a signature update or policy change.

Exam trap

The trap here is that candidates confuse Indicators (IoC) with Attack Surface Reduction rules, mistakenly thinking ASR rules can block specific file hashes, when in fact ASR rules only block behavioral patterns and cannot target individual file hashes.

How to eliminate wrong answers

Option A is wrong because Attack Surface Reduction (ASR) rules are policy-based rules that target specific behaviors (e.g., blocking Office apps from creating child processes), not individual file hashes; they cannot block a single SHA256 hash on demand. Option C is wrong because Automated Investigation and Response (AIR) is a post-breach remediation workflow that triggers after detection, not a proactive blocking mechanism for a known IoC. Option D is wrong because Threat Analytics is a reporting and intelligence feature that provides threat summaries and mitigations, not a direct enforcement action to block file execution.

270
MCQmedium

You have a Microsoft 365 E5 tenant. Users report that they cannot access the Microsoft 365 admin center (https://admin.microsoft.com). You verify that they have the Global Administrator role assigned. You check the sign-in logs in Microsoft Entra ID and see that the sign-in was blocked by a Conditional Access policy. The policy requires MFA and a compliant device. The users are using personal devices that are not enrolled. What should you do to allow access while maintaining security?

A.Disable the Conditional Access policy.
B.Ask users to enroll their personal devices in Microsoft Intune.
C.Remove the Global Administrator role from the users and assign a lower privilege role.
D.Modify the Conditional Access policy to exclude the Microsoft 365 admin center from the device compliance requirement, but keep MFA.
AnswerD

Modifying the Conditional Access policy to exclude the Microsoft 365 admin center from the device compliance requirement, while keeping MFA, is a least-privilege approach. This allows administrators to sign in to the admin center from any device using MFA as a compensating control, but still enforces device compliance for all other cloud apps. This balances security and usability by scoping the exception only to the app that is causing the issue.

Why this answer

It allows users to access the Microsoft 365 admin center by removing the device compliance requirement for that specific cloud app while still enforcing MFA. This maintains security through MFA and avoids blocking access for users on personal, unenrolled devices. Disabling the policy entirely or requiring enrollment would either weaken security or be impractical for personal devices.

Exam trap

The trap here is that candidates may think removing the Global Administrator role (Option C) will bypass the Conditional Access policy, but Conditional Access policies apply to all users regardless of role unless explicitly excluded, and the policy's grant controls are evaluated before role-based access is considered.

How to eliminate wrong answers

Option A is wrong because disabling the Conditional Access policy entirely would remove all security controls (MFA and device compliance) for the admin center, exposing the tenant to unauthorized access. Option B is wrong because asking users to enroll personal devices in Intune may not be feasible or desired for personal devices, and it does not address the immediate access issue without policy modification. Option C is wrong because removing the Global Administrator role does not resolve the Conditional Access block; the policy applies to all users regardless of role, and the users need admin privileges to perform their duties.

271
MCQmedium

Your company uses Microsoft Intune for mobile device management. You need to ensure that only compliant devices can access corporate email in Microsoft 365. Which Microsoft Entra ID feature should you combine with Intune compliance policies?

A.Conditional Access
B.Microsoft Entra Application Proxy
C.Microsoft Entra Identity Protection
D.Microsoft Entra Privileged Identity Management
AnswerA

Conditional Access is the correct answer because it evaluates signals like device compliance before granting access. In Intune, compliance policies assess device health, and Conditional Access policies can require those devices to be marked compliant, blocking or allowing access based on that state. This direct integration makes it the tool that checks device compliance from Intune for MDM-managed devices.

Why this answer

Conditional Access is the correct answer because it is the Microsoft Entra ID feature that enforces access controls based on signals such as device compliance. When combined with Intune compliance policies, Conditional Access can block or allow access to corporate email in Microsoft 365 based on whether the device is marked as compliant by Intune. This integration ensures that only devices meeting your organization's security requirements can access corporate resources.

Exam trap

The trap here is that candidates often confuse Identity Protection (which handles risk-based access) with Conditional Access (which enforces policies like device compliance), leading them to select Option C instead of A.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra Application Proxy provides secure remote access to on-premises web applications, not device compliance enforcement for cloud services. Option C is wrong because Microsoft Entra Identity Protection detects and responds to identity-based risks (e.g., leaked credentials, sign-ins from anonymous IPs), but it does not evaluate device compliance status. Option D is wrong because Microsoft Entra Privileged Identity Management manages, controls, and monitors access to privileged roles in Microsoft Entra ID, not device compliance or access policies for corporate email.

272
MCQeasy

Your company uses Microsoft Entra ID. You need to ensure that when users are assigned privileged roles, they must activate the role and provide a justification. The solution must minimize the number of standing assignments. What should you implement?

A.Conditional Access policy requiring MFA for all users assigned to privileged roles.
B.Microsoft Entra ID Protection risk policies for privileged users.
C.Microsoft Entra Privileged Identity Management (PIM) with eligible assignments and activation requirements.
D.Microsoft Entra ID Governance access reviews for privileged roles.
AnswerC

PIM allows you to assign users as eligible for privileged roles. When they need the role, they must activate it, optionally providing justification and passing MFA. This minimizes standing access and meets the requirement. It is the correct solution for just-in-time privileged access.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) provides just-in-time privileged access. By configuring eligible assignments, users must activate roles when needed, and you can require justification and MFA. This minimizes standing access.

Other options do not provide activation workflows or justification requirements.

Exam trap

The trap here is assuming that Conditional Access or access reviews can enforce just-in-time role activation with justification, which they cannot.

273
MCQhard

A company uses Microsoft Entra ID P2 licenses and wants to implement just-in-time (JIT) privileged access for administrators. Security requirements state that Global Administrator role members must request approval and provide a business justification before their role activation expires after 4 hours. Which Microsoft Entra feature should be configured?

A.Conditional Access
B.Privileged Identity Management (PIM)
C.Identity Protection
D.Self-Service Password Reset (SSPR)
AnswerB

Privileged Identity Management (PIM) in Microsoft Entra ID P2 provides just-in-time (JIT) activation of Azure AD roles, allowing eligible members to request elevated access with a defined start time, duration, and justification. Administrators can configure PIM to require approval from designated approvers before the role becomes active, ensuring every privileged activation is audited and time-boxed. This directly fulfills the scenario’s requirement for managed, approval-based, and time-limited privileged role activation. No other Entra ID feature combines role assignment, approval workflow, and expiration in this way.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID provides just-in-time (JIT) privileged access, requiring approval and a business justification for role activation, with configurable maximum activation durations (e.g., 4 hours). This directly meets the security requirement for Global Administrator role members to request approval and provide justification before activation expires after 4 hours.

Exam trap

The trap here is that candidates often confuse Conditional Access with PIM because both involve 'access control,' but Conditional Access cannot enforce time-bound role activation with approval and justification workflows.

How to eliminate wrong answers

Option A is wrong because Conditional Access enforces access policies based on signals like location or device compliance, but it does not provide time-bound role activation with approval workflows or business justification. Option C is wrong because Identity Protection detects and remediates identity-based risks (e.g., compromised accounts) but does not manage privileged role activation or approval processes. Option D is wrong because Self-Service Password Reset (SSPR) allows users to reset their own passwords without administrator intervention, and it has no capability to control privileged role activation with approval and expiration.

274
MCQeasy

You are a Microsoft 365 administrator for a small business with 50 users. The company uses Microsoft 365 Business Premium. You need to ensure that all users have multi-factor authentication (MFA) enabled. The company does not have any custom conditional access policies. You want to implement MFA as quickly as possible with minimal configuration. What should you do?

A.Enable security defaults in the Microsoft Entra admin center.
B.Configure MFA registration campaign for all users.
C.Enable per-user MFA for each user.
D.Create a conditional access policy that requires MFA for all users.
AnswerA

Security defaults in the Microsoft Entra admin center enforces MFA for every user, blocks legacy authentication, and requires users to complete MFA registration on first sign-in — all with a single toggle and no conditional access policy creation. For a small business without granular exclusion requirements, this is the fastest and most minimal-configuration path to satisfy the scenario. Microsoft recommends security defaults for tenants that do not have Microsoft Entra ID P1/P2 licenses, and even with Business Premium it provides immediate baseline protection without policy dependencies.

Why this answer

Security defaults provide a pre-configured set of security policies, including requiring MFA for all users, that can be enabled with a single toggle in the Microsoft Entra admin center. This is the fastest and simplest method for a small business with no existing conditional access policies, as it requires minimal configuration and immediately enforces MFA for every user.

Exam trap

The trap here is that candidates often confuse the MFA registration campaign (which only prompts registration) with actual MFA enforcement, or they overcomplicate the solution by choosing per-user MFA or a custom conditional access policy when security defaults are the fastest and simplest answer for a tenant with no existing policies.

How to eliminate wrong answers

Option B is wrong because the MFA registration campaign is a feature that nudges users to register for MFA but does not enforce MFA at sign-in; it only prompts registration, leaving authentication unprotected until users voluntarily comply. Option C is wrong because per-user MFA is a legacy method that requires manually enabling MFA for each of the 50 users individually, which is time-consuming and does not leverage the modern, policy-based approach of security defaults. Option D is wrong because creating a conditional access policy requires additional configuration steps (e.g., excluding break-glass accounts, defining conditions) and is not the fastest option; security defaults are designed for organizations without existing policies to achieve MFA enforcement instantly.

275
MCQmedium

A company plans to enable Self-Service Password Reset (SSPR) for all users. The administrator must ensure that users are required to register at least two authentication methods: one from the 'mobile app' category and one from the 'phone call' category. Which combination of methods should the administrator select in the SSPR registration settings?

A.Mobile app notification and office phone
B.Mobile app notification and mobile app code
C.Office phone and mobile phone
D.Mobile phone and email
AnswerA

Selecting Mobile app notification satisfies the mobile app authentication method category, while Office phone is classified under the phone call category. This combination fulfills the SSPR policy requirement of having two methods from different categories, ensuring users can verify identity via either the Microsoft Authenticator push notification or a call to their office landline. It also aligns with best practices for SSPR availability by providing diverse verification options.

Why this answer

The SSPR registration policy requires users to select at least two distinct authentication methods from the allowed list. By choosing 'Mobile app notification' (from the mobile app category) and 'Office phone' (from the phone call category), the administrator satisfies the requirement of one method from each specified category. The 'Office phone' option is classified under the 'phone call' category in Microsoft Entra ID SSPR settings.

Exam trap

The trap here is that candidates often assume 'Mobile phone' and 'Office phone' are different categories, but both are classified under the 'phone call' category in SSPR, so selecting both does not satisfy the requirement for a method from the 'mobile app' category.

How to eliminate wrong answers

Option B is wrong because both 'Mobile app notification' and 'Mobile app code' belong to the same 'mobile app' category, failing the requirement to have one method from the 'phone call' category. Option C is wrong because 'Office phone' and 'Mobile phone' are both in the 'phone call' category, not covering the 'mobile app' category. Option D is wrong because 'Mobile phone' is in the 'phone call' category and 'Email' is a separate category (not 'mobile app' or 'phone call'), so it does not include a method from the 'mobile app' category.

276
MCQmedium

You are the Microsoft 365 administrator for a company that has a Microsoft 365 E5 tenant. The security team requires that all administrative actions performed in the Microsoft 365 admin center and Microsoft Entra admin center be retained for seven years. You need to configure the appropriate audit log retention. What should you do?

A.Enable a Microsoft Entra diagnostic setting to export audit logs to an Azure Log Analytics workspace with a seven-year retention period.
B.Assign Microsoft 365 E5 Compliance licenses to all administrators and rely on the default retention.
C.In the Microsoft Purview compliance portal, create an audit retention policy that applies to the admin activities and set the retention period to seven years.
D.In the Microsoft 365 admin center, change the default audit log retention period to seven years.
AnswerC

Audit retention policies in Microsoft Purview allow you to retain specific audit records for a custom duration, up to 10 years, independent of the default tenant retention. Applying the policy to admin activities ensures those events are kept for seven years, meeting the security team's requirement without affecting other workloads.

Why this answer

To retain audit records for longer than the default period, you must create an audit retention policy in Microsoft Purview. This policy can target specific activities, such as admin actions, and set a custom retention duration up to 10 years. Changing default settings or relying on licenses alone does not extend retention.

Exam trap

The trap here is assuming that Microsoft 365 E5 licensing automatically provides extended audit retention or that a simple toggle in the admin center can change it.

277
MCQhard

Your company has deployed Microsoft Defender for Endpoint on all Windows devices. You are investigating an alert for a suspicious PowerShell command that was blocked by Attack Surface Reduction (ASR) rules. The alert shows the command was executed from a script embedded in a Word document. You need to identify the ASR rule that blocked this activity. Which rule is most likely responsible?

A.Block Office applications from creating child processes
B.Block Office applications from making Win32 API calls
C.Block Office applications from injecting code into other processes
D.Block Office applications from creating executable content
AnswerA

This ASR rule is specifically designed to block Office applications from spawning child processes, such as when Word launches PowerShell via a malicious macro. In this attack chain, the macro directly invokes PowerShell as a new process, so blocking child process creation breaks the execution chain at the critical point. Other ASR rules target different stages like API calls or code injection, but the core action here is the creation of the child process.

Why this answer

The ASR rule 'Block Office applications from creating child processes' is designed to stop Office apps (Word, Excel, PowerPoint) from spawning processes like powershell.exe, cmd.exe, or wscript.exe. A malicious macro in a Word document that launches PowerShell is the textbook trigger for this rule, which is why it is the most likely blocker.

Exam trap

The trap is conflating ASR rules that all mention 'Office applications' — candidates must distinguish child-process creation from API calls, code injection, and executable content creation.

How to eliminate wrong answers

Option B is wrong because 'Block Office applications from making Win32 API calls' targets direct API invocation from Office processes, not the spawning of a child PowerShell process. Option C is wrong because 'Block Office applications from injecting code into other processes' addresses process injection (e.g., via CreateRemoteThread), which is a different technique than launching a child process. Option D is wrong because 'Block Office applications from creating executable content' focuses on writing executable files to disk from Office, not on executing a script interpreter as a child process.

278
MCQmedium

Your organization uses Microsoft 365 E5 licenses for all users. You need to configure role-based access control (RBAC) so that helpdesk staff can reset passwords and manage licenses, but cannot modify user principal names (UPNs) or delete users. Which role assignment should you use?

A.License Administrator
B.Helpdesk Administrator
C.Password Administrator
D.User Administrator
AnswerB

Helpdesk Administrator is the correct choice because Microsoft Entra ID grants this role the combined abilities to reset passwords for non-administrator users and to manage license assignments by including the License Administrator permission as part of its delegated scope. Critically, it explicitly excludes the more privileged User Administrator capabilities such as deleting users or modifying user principal names (UPNs), which aligns exactly with the stated restrictions. This makes Helpdesk Administrator the least-privileged built-in role that satisfies both required tasks without permitting the prohibited actions.

Why this answer

The Helpdesk Administrator role is correct because it grants the specific permissions needed to reset passwords and manage licenses, while explicitly preventing modifications to user principal names (UPNs) and user deletions. This role is designed for tier-1 support staff who require these capabilities without elevated user management rights.

Exam trap

The trap here is that candidates often confuse the Helpdesk Administrator role with the User Administrator role, assuming the latter is required for license management, but User Administrator includes dangerous permissions like UPN modification and user deletion that are explicitly prohibited in the question.

How to eliminate wrong answers

Option A is wrong because the License Administrator role can only manage license assignments and cannot reset passwords, failing the password reset requirement. Option C is wrong because the Password Administrator role can only reset passwords and cannot manage licenses, failing the license management requirement. Option D is wrong because the User Administrator role can modify UPNs and delete users, which violates the restriction against those actions.

279
MCQmedium

A compliance officer needs to prevent users from sending emails that contain social security numbers to external recipients. When a user attempts to send such an email from Outlook, the email should be blocked and a policy tip should be displayed explaining why the email was blocked. Which Microsoft Purview solution should the officer configure?

A.Data Loss Prevention (DLP) policy
B.Sensitivity labels
C.Communication compliance
D.eDiscovery
AnswerA

DLP policies in Exchange Online are the correct mechanism because they inspect email content in transit against sensitive information types (e.g., credit card numbers, social security numbers) and can trigger a real-time block action, such as rejecting or quarantining the message before it reaches the recipient. DLP also surfaces policy tips in Outlook to notify users that their message violates a policy, giving them a chance to modify or resend it. This proactive, content-aware enforcement is exactly what the compliance officer needs.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft Purview is designed to detect sensitive information, such as social security numbers, in emails and enforce actions like blocking the message and displaying a policy tip. This meets the compliance officer's requirement to prevent external sending of sensitive data while providing user notification.

Exam trap

Microsoft often tests the distinction between DLP (which can block and notify in real-time) and sensitivity labels (which apply protection but do not block sending based on content detection), leading candidates to confuse classification with enforcement.

How to eliminate wrong answers

Option B is wrong because sensitivity labels classify and protect data through encryption and visual markings but do not natively block outbound emails based on content detection or display policy tips. Option C is wrong because communication compliance focuses on monitoring and reviewing internal/external communications for policy violations (e.g., harassment or insider trading) rather than real-time blocking of specific sensitive data patterns. Option D is wrong because eDiscovery is used for searching and exporting content for legal or investigative purposes, not for preventing data exfiltration or enforcing real-time email restrictions.

280
MCQeasy

A user reports they cannot access Microsoft Teams. They see a message: 'Your account is not enabled for Teams.' You verify the user has a valid Microsoft 365 E3 license assigned. What is the most likely cause?

A.The user does not have the correct Microsoft Entra ID role.
B.The user is not assigned a valid license.
C.The Teams service plan is disabled in the user's license.
D.The user is not a global administrator.
AnswerC

Microsoft 365 license assignments include per-service-plan toggles, and when the Teams service plan is disabled for a user, Teams will not launch even though the user still appears as licensed. The user can have a fully valid E3 license with Exchange Online, SharePoint Online, and other plans active, but if the Teams plan is unchecked, the Teams client cannot authenticate or access the service. Enabling the Teams service plan on the user's license assignment is the required corrective action.

Why this answer

The error 'Your account is not enabled for Teams' indicates that the Teams service plan is disabled within the user's assigned Microsoft 365 E3 license. Even with a valid license, each service plan (e.g., Teams, Exchange Online, SharePoint) can be individually toggled on or off via the Microsoft 365 admin center or PowerShell. Since the user has a valid license but cannot access Teams, the most likely cause is that the Teams service plan has been explicitly disabled.

Exam trap

The trap here is that candidates often assume a valid license automatically enables all included services, but Microsoft 365 allows granular control over service plans, so a license assignment does not guarantee Teams is enabled.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID roles (e.g., Global Administrator, Teams Administrator) control administrative permissions, not the ability to use Teams as an end user; a user without any admin role can still access Teams if the service plan is enabled. Option B is wrong because the scenario explicitly states the user has a valid Microsoft 365 E3 license assigned, so the issue is not a missing license. Option D is wrong because being a Global Administrator is not required to use Teams; the error message is about service enablement, not administrative privileges.

281
MCQmedium

Your organization recently deployed Microsoft Defender for Office 365. Users report that some legitimate external emails are being quarantined as phishing attempts. You need to reduce false positives without compromising security. What should you do?

A.Increase the Spam Confidence Level (SCL) threshold to 9
B.Disable the anti-phishing policy and use a custom mail flow rule
C.Add the sender domains to the allowed senders list in the anti-phishing policy
D.Change the spam filtering action to 'Move message to Junk Email folder' instead of quarantine
AnswerC

The correct approach is to add the legitimate sender domains to the allowed senders list within the anti-phishing policy in Microsoft Defender for Office 365. Doing so instructs the impersonation detection engine to trust those specific domains, thereby preventing legitimate messages from being flagged as impersonation attempts while still applying malware scanning, spam filtering, and spoof intelligence to those messages. This is a targeted exception that does not weaken global security, making it the recommended and effective way to reduce phishing false positives for trusted domains.

Why this answer

Adding the sender domains to the allowed senders list in the anti-phishing policy explicitly whitelists those domains for phishing checks, reducing false positives while still scanning for other threats. This approach preserves security by not lowering the overall spam filtering threshold or disabling protections, and it targets only the specific domains that are being incorrectly flagged.

Exam trap

The trap here is that candidates often confuse the anti-phishing policy's allowed senders list with the tenant-level allowed/blocked list in the anti-spam policy, or they mistakenly think changing the action to junk email reduces false positives when it only changes the delivery outcome, not the detection logic.

How to eliminate wrong answers

Option A is wrong because increasing the SCL threshold to 9 would make the filter less sensitive, allowing more spam and phishing to reach users, which compromises security. Option B is wrong because disabling the anti-phishing policy removes critical protection against sophisticated phishing attacks, and a custom mail flow rule cannot replicate the advanced heuristics and impersonation detection of the built-in policy. Option D is wrong because changing the action to 'Move message to Junk Email folder' instead of quarantine still applies the same false-positive classification; it only changes the delivery location, not the underlying detection logic, so legitimate emails would still be incorrectly categorized.

282
MCQmedium

You are a compliance administrator for Fabrikam Inc. The company uses Microsoft Purview Information Barriers. You need to prevent users in the Sales department from communicating with users in the Research department in Microsoft Teams. However, both departments must be able to communicate with the Legal department. What should you do first?

A.Create a DLP policy that blocks Teams messages between Sales and Research.
B.Create an information barrier segment for each department and define blocked and allowed communication policies between them.
C.Assign sensitivity labels to users in Sales and Research to prevent collaboration.
D.Configure a Teams messaging policy that disables chat for the Sales and Research departments.
AnswerB

Information barriers use segments to group users and policies to define allowed or blocked communication between segments. You must first create segments for Sales, Research, and Legal, then define policies that block Sales-Research and allow Sales-Legal and Research-Legal. This is the foundational step to enforce the restriction.

Why this answer

Information barriers are the correct feature to restrict communication between specific groups in Microsoft Teams. The first step is to create segments for each department, then define policies that specify which segments can communicate. This allows blocking Sales-Research while permitting both to communicate with Legal.

Exam trap

The trap here is assuming DLP or Teams messaging policies can enforce ethical walls, when information barriers are the purpose-built solution.

283
MCQhard

Your organization uses Microsoft Entra ID P2 and Microsoft Defender for Cloud Apps. You need to protect a custom SaaS application that uses SAML-based SSO. The application does not support Conditional Access. You want to enforce session controls such as blocking downloads of sensitive files. What should you implement?

A.Deploy Microsoft Defender for Cloud Apps Conditional Access App Control and route the application through Defender for Cloud Apps.
B.Implement a reverse proxy from a third-party vendor.
C.Create a custom application registration and set app roles.
D.Configure the application to use Microsoft Entra ID as the identity provider and enable Conditional Access policies.
AnswerA

Microsoft Defender for Cloud Apps Conditional Access App Control (ACAC) is correct because it functions as a session-level reverse proxy that intercepts the user's session after authentication, enabling real-time controls like blocking downloads, preventing paste, and redacting sensitive data. By routing the application through Defender for Cloud Apps, you can target it with a Conditional Access policy using the 'Use Conditional Access App Control' session control, which works even for third-party SaaS apps that lack native Conditional Access support. This provides the exact session-level enforcement and visibility needed.

Why this answer

Microsoft Defender for Cloud Apps Conditional Access App Control acts as a reverse proxy that can enforce session policies—such as blocking downloads of sensitive files—on any SAML-based SaaS application, even if the application itself does not support Conditional Access. By routing the application's traffic through Defender for Cloud Apps, you can apply granular session controls at the proxy layer without modifying the application.

Exam trap

The trap here is that candidates often assume that enabling Entra ID as the identity provider and applying Conditional Access policies is sufficient, but they overlook that the application must support Conditional Access (i.e., be capable of enforcing the resulting controls) for those policies to work; when the app does not, a proxy-based solution like Defender for Cloud Apps App Control is required.

How to eliminate wrong answers

Option B is wrong because while a third-party reverse proxy could theoretically provide similar controls, the question specifically asks for a solution within the Microsoft ecosystem (Entra ID P2 and Defender for Cloud Apps), and Microsoft's own solution is the recommended and integrated approach. Option C is wrong because creating a custom application registration and setting app roles only manages authentication and authorization within Entra ID, but does not provide session-level controls like blocking file downloads. Option D is wrong because the application does not support Conditional Access, so configuring it to use Entra ID as the identity provider and enabling Conditional Access policies would have no effect—Conditional Access requires the application to be capable of interpreting and enforcing the resulting claims or tokens.

284
MCQeasy

You are a compliance administrator. You need to search for emails that contain trade secrets sent by a specific user in the last month. The search must include all mailboxes. What should you use?

A.eDiscovery (Premium) case.
B.Data Loss Prevention reports.
C.Audit log search.
D.Content search in Microsoft Purview.
AnswerD

Content search in Microsoft Purview is the correct tool because it performs a full-text query across all Exchange Online mailboxes using a KQL query. You can combine keywords such as "confidential" with date filters like "sent >= 01/01/2024" to find messages containing the specified text, and you can include inactive mailboxes and public folders. It directly meets the requirement to search for specific keywords inside emails, not merely metadata about them.

Why this answer

Content search in Microsoft Purview allows searching across all mailboxes for specific keywords and date ranges, making it the appropriate tool to find emails containing trade secrets from a specific user in the last month. Option D is correct. Option A is wrong because eDiscovery (Premium) is designed for complex legal workflows and not for basic content search.

Option B is wrong because Audit log search tracks user and admin activities, not email content. Option C is wrong because Data Loss Prevention (DLP) reports show policy matches and alerts, but do not allow searching across mailbox content for specific keywords.

285
Drag & Dropmedium

Drag and drop the steps to deploy Microsoft Defender for Office 365 policies in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Defender for Office 365 policies are created in the Defender portal, configured with threat protection settings, and applied to recipients.

286
Multi-Selecthard

Your organization uses Microsoft Sentinel for security operations. You need to ensure that Sentinel can ingest logs from Microsoft 365 Defender (XDR) and Microsoft Entra ID. Which THREE data connectors should you enable? (Choose three.)

Select 3 answers
A.Microsoft Defender for Endpoint
B.Microsoft Purview Information Protection
C.Microsoft Entra ID (formerly Azure AD)
D.Microsoft Intune
E.Microsoft Defender for Office 365 (formerly Office 365 ATP)
AnswersA, C, E

The Microsoft Defender for Endpoint connector is a built-in Sentinel data source that directly ingests endpoint detection and response telemetry, including tables such as DeviceLogonEvents, DeviceProcessEvents, and DeviceNetworkEvents. These raw Advanced Hunting events enable detections for malware, lateral movement, and other endpoint attacks. Without this connector, endpoint visibility would rely on manual log forwarding or third-party agents.

Why this answer

Microsoft Defender for Endpoint is a correct data connector because it ingests endpoint detection and response (EDR) logs from Windows, macOS, and Linux devices into Microsoft Sentinel. This integration allows security operations to correlate endpoint alerts with other signals, enabling advanced hunting and automated incident response across the Microsoft 365 Defender ecosystem.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Information Protection or Intune as security log sources, when in fact they are governance and management tools without native data connectors for Sentinel's security log ingestion.

287
MCQhard

Your company uses Microsoft Defender XDR and Microsoft Defender for Cloud Apps. You have discovered that a user's credentials were compromised and used to access a SaaS application from an unusual location. You need to automatically suspend the user's access to all cloud apps and require a password reset. The suspension should be immediate upon detection. What should you do?

A.In Microsoft Defender for Cloud Apps, create a session policy that uses the 'Suspend user' governance action and configure it to require password reset.
B.Create a playbook in Microsoft Sentinel that disables the user account in Microsoft Entra ID.
C.Set up a conditional access policy in Microsoft Entra ID to block all access from unusual locations.
D.Configure an automated investigation rule in Microsoft Defender XDR to reset the user's password.
AnswerA

Correct: Cloud Apps can suspend user and trigger password reset via integration with Entra ID.

Why this answer

Microsoft Defender for Cloud Apps allows you to create a session policy with the 'Suspend user' governance action, which can automatically suspend the user's access to all cloud apps upon detection of anomalous activity. Additionally, you can configure the policy to require a password reset, ensuring immediate remediation. Option B is wrong because a Microsoft Sentinel playbook can disable the user account but does not inherently force a password reset, and the response may not be immediate due to playbook execution delays.

Option C is wrong because a conditional access policy in Microsoft Entra ID can block access from unusual locations but does not suspend the user or require a password reset. Option D is wrong because Microsoft Defender XDR automated investigation rules cannot reset passwords; that action is not available in Defender XDR.

288
MCQmedium

You are a security administrator for Northwind Traders. You use Microsoft Defender XDR. You need to identify all devices that have communicated with a specific IP address associated with a known threat in the last 30 days. You want to use advanced hunting to find this information. Which table should you query?

A.DeviceNetworkEvents
B.DeviceFileEvents
C.DeviceEvents
D.DeviceLogonEvents
AnswerA

The DeviceNetworkEvents table in advanced hunting contains information about network connections initiated by or involving devices, including remote IP addresses. Querying this table allows you to filter for the specific IP address and the time range, returning the devices that communicated with it. This directly answers the requirement.

Why this answer

Advanced hunting in Microsoft Defender XDR includes the DeviceNetworkEvents table, which logs network connections and associated remote IP addresses. To find devices that communicated with a specific IP, you query DeviceNetworkEvents, filter by the RemoteIP column for the threat IP, and restrict the Timestamp to the last 30 days. This yields the required device list.

Exam trap

The trap here is assuming that DeviceEvents captures all network activity, when it primarily records process, file, and registry events.

289
MCQhard

You are troubleshooting why a user cannot access a SharePoint Online site. The user is assigned a Conditional Access policy that requires compliant device, and the device is enrolled in Microsoft Intune but shows as non-compliant. What is the most likely cause?

A.The device is non-compliant due to missing security updates
B.The device is not enrolled in Microsoft Intune
C.The Conditional Access policy is not applied to SharePoint Online
D.The user does not have an Intune license
AnswerA

The device is non-compliant because Microsoft Intune compliance policies evaluate security update installation as a required health condition. Missing security updates cause the compliance state to become 'non-compliant', which triggers the Conditional Access policy's 'Require device to be marked as compliant' grant control and blocks access to SharePoint Online. The user's license and the policy's application scope are irrelevant because the failure is specifically the device's compliance state.

Why this answer

The user's device is enrolled in Intune but marked as non-compliant, which directly blocks access because the Conditional Access policy requires a compliant device. The most common reason for non-compliance is missing security updates, as Intune evaluates compliance based on configured policies such as required patch levels, encryption status, or threat detection. Since the device is enrolled, the issue is not enrollment or licensing, but a specific compliance rule violation.

Exam trap

The trap here is that candidates may assume the device is not enrolled or the policy is misconfigured, but the question explicitly confirms enrollment and policy application, forcing you to focus on the compliance state itself.

How to eliminate wrong answers

Option B is wrong because the scenario explicitly states the device is enrolled in Microsoft Intune, so non-enrollment is not the cause. Option C is wrong because the Conditional Access policy is applied to SharePoint Online (as stated in the question), and the user is being blocked, indicating the policy is active. Option D is wrong because the user must have an Intune license to enroll the device and have it evaluated for compliance; without a license, the device would not appear in Intune at all.

290
MCQeasy

A compliance officer needs to identify documents in SharePoint Online that contain confidential business information by using a machine learning model. Which Microsoft Purview solution should be configured?

A.A: Data Lifecycle Management
B.B: Information Protection (trainable classifiers)
C.C: eDiscovery
D.D: Communication Compliance
AnswerB

Information Protection's trainable classifiers are machine learning models that learn to recognize specific content patterns from seed documents and then automatically classify SharePoint documents. Once trained, these classifiers can drive sensitivity labels, retention labels, or communication compliance policies, enabling automatic identification without manual scanning. This is the correct approach because the compliance officer needs to identify documents based on content, and trainable classifiers are purpose-built for that.

Why this answer

Trainable classifiers in Microsoft Purview Information Protection use machine learning models to identify documents containing sensitive or confidential business information based on content patterns and context. Unlike simple keyword matching, trainable classifiers learn from sample documents to accurately detect specific types of confidential data, such as intellectual property or financial reports, in SharePoint Online.

Exam trap

The trap here is that candidates often confuse trainable classifiers with simple keyword-based sensitivity labels or DLP policies, but the question specifically requires a machine learning model, which only trainable classifiers provide.

How to eliminate wrong answers

Option A is wrong because Data Lifecycle Management focuses on retention and deletion policies for data governance, not on identifying confidential content via machine learning. Option C is wrong because eDiscovery is designed for legal discovery and search of content for litigation or investigation, not for proactive classification using ML models. Option D is wrong because Communication Compliance monitors communications (e.g., email, Teams) for policy violations like harassment or insider trading, not for identifying confidential business documents in SharePoint.

291
MCQeasy

You need to grant a vendor access to a specific SharePoint Online site for a limited time. The vendor does not have an account in your Microsoft Entra ID. What should you use?

A.Create a user account via Microsoft Entra Connect
B.Configure self-service sign-up user flow
C.Assign the vendor a guest user account with no expiration
D.Use Microsoft Entra B2B collaboration and set an expiration for the guest user
AnswerD

Microsoft Entra B2B collaboration is the intended mechanism for inviting external vendors, because it creates a guest user identity that can be scoped to specific resources such as a SharePoint site. Combined with the guest user expiration policy in Entra ID, you can specify a fixed number of days before the account becomes inactive, enforcing time-bound access without any manual offboarding. This approach aligns with zero-trust principles and ensures the vendor's access automatically expires after the engagement.

Why this answer

Microsoft Entra B2B collaboration allows you to invite external users (vendors) as guest users to access your organization's resources, including SharePoint Online sites, without requiring them to have an existing account in your tenant. You can configure an expiration policy for the guest user account to automatically remove access after a specified period, meeting the requirement for limited-time access.

Exam trap

The trap here is that candidates often confuse B2B collaboration with creating a new user account (Option A) or assume that self-service sign-up (Option B) is appropriate for a single vendor, when in fact B2B collaboration is the correct method for granting external users time-limited access without managing their identities.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Connect is used to synchronize on-premises Active Directory identities to Microsoft Entra ID, not to create accounts for external vendors who do not have an existing identity in your organization. Option B is wrong because self-service sign-up user flow is designed for customers or partners to create their own accounts in your tenant for app registration or B2C scenarios, not for granting a specific vendor access to a SharePoint site with controlled expiration. Option C is wrong because assigning a guest user account with no expiration does not meet the requirement for limited-time access; it would grant permanent access unless manually removed, which is not automated or policy-driven.

292
MCQmedium

Your organization is deploying Microsoft 365 and needs to ensure that all new users are automatically assigned a Microsoft 365 Business Basic license. You want to use a group-based licensing strategy with an Azure AD security group. What should you do first?

A.Configure directory synchronization and create the group in on-premises Active Directory.
B.Create a dynamic Azure AD group with a rule for user attributes and enable self-service group management.
C.Assign the license directly to each user via the Microsoft 365 admin center.
D.Create a new Azure AD security group and assign the license to the group.
AnswerD

Creating a new Azure AD security group and assigning the license to that group is the definitive group-based licensing model. Once the license is assigned to the group, all current members immediately receive it, and any users added later are automatically provisioned without an admin step. Because group membership controls the license assignment, this method scales efficiently and provides a clean audit trail, which is exactly why Microsoft recommends it for bulk user licensing.

Why this answer

Group-based licensing in Azure AD requires you to first create a security group (which can be cloud-only or synced) and then assign the Microsoft 365 Business Basic license directly to that group. Once the license is assigned to the group, all members automatically receive the license, including new users added to the group. This approach centralizes license management and ensures automatic assignment without manual intervention.

Exam trap

The trap here is that candidates often think they must first configure directory synchronization (Option A) or create a dynamic group (Option B) before assigning a license to a group, but the correct first step is simply to create a security group and assign the license to it, as group-based licensing works with any Azure AD security group, including cloud-only static groups.

How to eliminate wrong answers

Option A is wrong because directory synchronization and creating the group in on-premises Active Directory is not the first step; you can use a cloud-only Azure AD security group without requiring on-premises sync, and the question does not specify a hybrid environment. Option B is wrong because creating a dynamic group with a user attribute rule and enabling self-service group management is not the first step; while dynamic groups can be used for licensing, the initial requirement is to create a security group and assign the license to it, not to configure dynamic membership or self-service. Option C is wrong because assigning licenses directly to each user via the Microsoft 365 admin center is a manual, per-user approach that contradicts the group-based licensing strategy specified in the question.

293
MCQmedium

A compliance officer needs to automatically apply a sensitivity label named 'Confidential' to documents stored in SharePoint Online whenever the documents contain social security numbers. Users must be prevented from removing the label. Which configuration should the officer implement?

A.Create a retention label with auto-labeling based on sensitive info types
B.Create a sensitivity label with auto-labeling and set 'Require justification to remove the label'
C.Use Microsoft Information Protection (MIP) unified labeling client to apply labels
D.Configure Data Loss Prevention (DLP) policy to apply the label
AnswerB

Sensitivity labels with auto-labeling can apply the label automatically based on sensitive info types. However, to prevent users from removing the label, you must configure advanced protection settings (e.g., require justification to remove the label) rather than just 'Mark content as mandatory', which only requires a label to be present. Despite the inaccurate setting name, the correct concept is using sensitivity labels with appropriate protection settings.

Why this answer

Sensitivity labels support auto-labeling based on sensitive info types (e.g., social security numbers). To prevent users from removing the label, configure the label policy setting 'Require justification to remove a label or lower classification label'. Option B correctly combines auto-labeling with this protection setting.

Retention labels (A) manage lifecycle, the MIP unified labeling client (C) is outdated, and DLP policies (D) can apply labels but do not inherently prevent label removal.

Exam trap

The trap is confusing 'Mark content as mandatory' (which requires a label but does not prevent removal) with the protection setting that restricts removal, such as 'Require justification to remove a label or lower classification label'. The correct answer uses sensitivity label auto-labeling with that protective setting.

How to eliminate wrong answers

Option A is wrong because retention labels are designed for data retention and deletion policies, not for classification or protection; they cannot apply sensitivity labels or prevent removal. Option C is wrong because the MIP unified labeling client is a legacy tool for on-premises or hybrid scenarios, not for cloud-native auto-labeling in SharePoint Online; it also does not enforce mandatory labeling. Option D is wrong because DLP policies can detect sensitive data and trigger actions like blocking or notification, but they cannot directly apply sensitivity labels; they rely on labels already being present.

294
MCQeasy

A newly hired administrator needs to manage user accounts, licenses, and reset passwords. Which portal should they access?

A.Microsoft 365 admin center
B.Microsoft Entra admin center
C.Microsoft 365 Defender
D.Azure Active Directory admin center
AnswerA

The Microsoft 365 admin center is the designated operational hub for managing Microsoft 365 user accounts, including creating new users, resetting passwords, adding users from a CSV, and assigning or revoking Microsoft 365 subscription licenses. It provides a service-aware view of all M365 workloads and is the primary portal for common administrative tasks like user lifecycle management and billing. While identity data resides in Microsoft Entra ID, the M365 admin center is the intended interface for day-to-day account administration.

Why this answer

The Microsoft 365 admin center (admin.microsoft.com) is the primary portal for day-to-day user administration tasks such as creating and managing user accounts, assigning licenses, and resetting passwords. It provides a unified interface for these common identity and license management operations within a Microsoft 365 tenant.

Exam trap

The trap here is that candidates often confuse the Microsoft Entra admin center (formerly Azure AD) with the Microsoft 365 admin center, thinking that all user management must be done in the identity portal, but the exam tests that routine user tasks like license assignment and password resets are performed in the Microsoft 365 admin center.

How to eliminate wrong answers

Option B (Microsoft Entra admin center) is wrong because it is focused on identity and access management (IAM) configuration, including conditional access policies, enterprise apps, and security defaults, not on routine user license assignment or password resets for end users. Option C (Microsoft 365 Defender) is wrong because it is a security operations portal for threat detection, investigation, and response (e.g., incident management, advanced hunting), not for user account or license management. Option D (Azure Active Directory admin center) is wrong because it is the legacy portal for Azure AD directory-level settings and bulk operations; while it can manage users, the Microsoft 365 admin center is the correct modern portal for license and password management in a Microsoft 365 context, and the Azure AD portal is now rebranded as Microsoft Entra admin center.

295
MCQhard

Your company uses Microsoft Entra ID and has enabled Microsoft Entra ID Protection. You notice that a user's sign-in was blocked due to a medium user risk. However, the user claims the sign-in was legitimate. What should you do to allow future sign-ins without lowering security?

A.Create a conditional access policy to bypass MFA for this user
B.Suppress the alert in Microsoft Defender XDR
C.Use the Microsoft Entra ID Protection reports to confirm the user as safe
D.Dismiss the risk in the Risky users report
AnswerC

Using the Microsoft Entra ID Protection reports to confirm the user as safe is the correct manual remediation action when investigation shows the risk detection is a false positive or the account is validated as legitimate. Selecting 'Confirm user safe' on the Risky users report dismisses the risk, resets the user's risk level, and removes the user from the risky users list, allowing sign-ins to proceed normally without requiring a password reset. This action should be performed only after verifying the user's identity and activity, as it is a permanent dismissal that prevents risk-based conditional access policies from challenging the user in the future.

Why this answer

When a user claims a blocked sign-in was legitimate, the proper action is to confirm the user as safe in the Microsoft Entra ID Protection reports. This action updates the risk state to 'confirmed safe', which resets the user's risk level and allows future sign-ins without lowering security. It also provides feedback to the risk detection algorithm to improve accuracy.

Exam trap

The trap here is confusing 'dismissing the risk' (which only closes the alert) with 'confirming the user as safe' (which actively resets the risk state and provides feedback), leading candidates to incorrectly choose Option D.

How to eliminate wrong answers

Option A is wrong because creating a conditional access policy to bypass MFA for this user would lower security by removing a critical authentication requirement, and it does not address the underlying risk detection. Option B is wrong because suppressing the alert in Microsoft Defender XDR only hides the notification; it does not resolve the risk state or prevent future blocks. Option D is wrong because dismissing the risk in the Risky users report simply closes the alert without confirming the sign-in as legitimate, which could allow the same risk to trigger again and does not provide feedback to the risk engine.

296
Multi-Selecthard

Your company is deploying Microsoft 365 Copilot for all users. You need to ensure that Copilot responses are grounded only in organizational data that users already have permission to access. Additionally, you must comply with data residency requirements in the European Union. Which THREE actions should you take?

Select 3 answers
A.Apply sensitivity labels to restrict Copilot from accessing specific files.
B.Set the data residency preference for Microsoft 365 Copilot to the European Union in the admin center.
C.Configure Microsoft 365 Copilot to respect existing user permissions via Microsoft Entra ID.
D.Block Copilot for all users outside the EU using conditional access policies.
E.Enable Copilot caching in Microsoft Purview to control data storage locations.
AnswersA, B, C

Sensitivity labels in Microsoft Purview can be configured with encryption or permissions settings that explicitly exclude the Copilot service principal, preventing Copilot from retrieving labeled content. For example, applying a label with 'Do Not Forward' or custom conditional access grants ensures Copilot only returns data when the user has the corresponding decryption rights. This provides granular control at the file level, allowing specific documents or emails to be hidden from Copilot-generated responses while other content remains accessible.

Why this answer

Sensitivity labels can be configured to block Copilot from accessing files with specific labels, ensuring that Copilot responses are grounded only in organizational data that users already have permission to access. This is done by using Microsoft Purview Information Protection to define label-based restrictions that Copilot respects, preventing it from surfacing content from labeled files even if the user has direct access.

Exam trap

The trap here is that candidates may confuse conditional access policies (which control access) with data residency controls (which control data storage and processing location), and may incorrectly think caching in Purview is a real feature for data residency, when in fact Microsoft 365 Copilot does not use Purview caching for this purpose.

297
MCQhard

A security administrator needs to block users from running portable executable files (e.g., .exe, .scr) that were downloaded from the internet on Windows devices. Which Attack Surface Reduction (ASR) rule should the administrator enable to meet this requirement?

A.Block executable files from running unless they meet a prevalence, age, or trusted list criterion
B.Block credential stealing from the Windows local security authority subsystem (lsass.exe)
C.Block Adobe Reader from creating child processes
D.Block persistence through WMI event subscription
AnswerA

This correct ASR rule (GUID: 01443614-cd74-433a-b99e-2ecdc07bfc25) evaluates every executable launched against Microsoft's cloud reputation service, checking prevalence, age, and any tenant-configured trusted list. Files that are unknown, new, or untrusted are blocked at the point of execution, which directly addresses the requirement to block users from running portable executables like .exe and .scr downloads. Because it operates on the executable itself, it is the only option that matches the stated intent.

Why this answer

The ASR rule 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' (GUID: 01443614-cd74-433a-b99e-2ecdc07bfc25) specifically targets executable files (e.g., .exe, .scr) that have been downloaded from the internet by checking their Mark-of-the-Web (MoTW) attribute. When enabled, this rule prevents execution of such files unless they meet criteria like high prevalence, sufficient age, or inclusion in a trusted list, directly addressing the requirement to block internet-downloaded portable executables.

Exam trap

The trap here is that candidates often confuse ASR rules focused on execution control (like blocking downloaded executables) with rules that block specific attack techniques (like credential theft or persistence), leading them to select a rule that addresses a different threat vector entirely.

How to eliminate wrong answers

Option B is wrong because the ASR rule 'Block credential stealing from the Windows local security authority subsystem (lsass.exe)' (GUID: 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2) protects against credential theft via LSASS access, not against running internet-downloaded executables. Option C is wrong because the ASR rule 'Block Adobe Reader from creating child processes' (GUID: 7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c) only restricts Adobe Reader from spawning child processes, which is unrelated to blocking execution of downloaded .exe or .scr files. Option D is wrong because the ASR rule 'Block persistence through WMI event subscription' (GUID: e6db77e5-3df2-4cf1-b95a-636979351e5b) targets WMI-based persistence techniques, not the execution of internet-downloaded portable executables.

298
MCQeasy

An organization wants to receive email notifications for all service health incidents. Which role must an administrator have to configure service health notifications in the Microsoft 365 admin center?

A.Global Administrator
B.Service Support Administrator
C.Helpdesk Administrator
D.Billing Administrator
AnswerA

Global Administrator holds the highest-level role in Microsoft 365 and inherits every permission, including the ability to view the Service Health dashboard and configure email notifications for service health incidents. Under 'Service Health' in the Microsoft 365 admin center, a Global Administrator can select 'Edit preferences' to subscribe to incident email alerts for all services. No other role has the necessary write permission to change those notification preferences, so only this role fully satisfies the requirement.

Why this answer

Only the Global Administrator role has the necessary permissions to access and modify the Service Health section in the Microsoft 365 admin center, including configuring email notifications for service health incidents. This is because the Global Administrator role is the highest privileged role and is required to manage tenant-wide settings such as service health alerts, which are not delegated to lower-level administrative roles.

Exam trap

The trap here is that candidates often assume the Service Support Administrator role, which can view service health, can also configure notifications, but Microsoft deliberately restricts write access to the Global Administrator role to prevent unauthorized changes to critical alerting infrastructure.

How to eliminate wrong answers

Option B (Service Support Administrator) is wrong because this role can only view service health and manage support tickets, but cannot configure notification settings for service health incidents. Option C (Helpdesk Administrator) is wrong because this role is limited to password resets, user management, and basic support tasks, and does not have permission to access or modify service health notification configurations. Option D (Billing Administrator) is wrong because this role is restricted to managing billing accounts, invoices, and payment methods, and has no access to service health or notification settings.

299
MCQhard

Your organization uses Microsoft Entra ID with P2 licenses. You need to identify and remediate users who are at risk due to leaked credentials or anomalous sign-in activity. You want to automate the response to high-risk users by requiring a password change. Which feature should you use?

A.Microsoft Entra Identity Protection
B.Microsoft Defender for Cloud Apps
C.Microsoft Entra Identity Governance
D.Microsoft Entra Privileged Identity Management (PIM)
AnswerA

Identity Protection detects leaked credentials and anomalous sign-in behaviour via its risk detections, then applies risk-based Conditional Access policies. A policy requiring password change for high-risk users automates remediation, satisfying the P2-licensed requirement to identify and respond to risky users.

Why this answer

Microsoft Entra Identity Protection provides risk-based conditional access policies that can automatically require a password change for high-risk users. Option B is wrong because Microsoft Defender for Cloud Apps focuses on cloud application security, not identity risk. Option C is wrong because Microsoft Entra Identity Governance handles access reviews and entitlement management.

Option D is wrong because Microsoft Entra Privileged Identity Management (PIM) manages privileged roles, not user risk.

300
MCQmedium

Refer to the exhibit. You run the Get-RetentionCompliancePolicy cmdlet and see the output. Your organization wants to retain all ProjectX documents for 10 years and then allow users to delete them. However, users complain that documents are being deleted automatically. What is the issue?

A.The retention action is set to Delete instead of NoAction.
B.The policy is disabled, so it should not be enforcing.
C.The mode is set to Enable, which means the policy is in test mode.
D.The retention trigger is set to DateCreated, which is incorrect.
AnswerB

The policy is disabled, so it should not be causing automatic deletion. This is the correct identification of the issue as stated.

Why this answer

The policy is disabled (Enabled: False), so it is not enforcing any retention or deletion actions. However, users are complaining that documents are being deleted automatically, which cannot be caused by this disabled policy. The issue is likely another policy or process.

Option A is incorrect because even if the retention action is 'Delete', it has no effect since the policy is disabled. Option C is incorrect because Mode 'Enable' means the policy is active when enabled, but since it is disabled, mode is irrelevant. Option D is incorrect because 'DateCreated' is a valid retention trigger.

Page 3

Page 4 of 10

Page 5

All pages