Courseiva

Microsoft 365 Administrator MS-102 (MS-102) — Questions 301–375

712 questions total · 10pages · All types, answers revealed

Page 4

Page 5 of 10

Page 6
301
MCQeasy

Your organization needs to implement a Microsoft Purview data classification solution that scans data in Microsoft 365, Azure SQL Database, and Amazon S3. Which Microsoft Purview feature should you use?

A.Microsoft Purview Data Loss Prevention
B.Microsoft Purview Information Protection sensitivity labels
C.Microsoft Purview eDiscovery
D.Microsoft Purview Data Map
AnswerD

Microsoft Purview Data Map is the unified metadata backbone that discovers, classifies, and maps data across Microsoft 365, Azure SQL Database, and Amazon S3. It satisfies the multi-source scanning requirement by providing a single catalogue spanning on-premises, multicloud, and SaaS sources.

Why this answer

Microsoft Purview Data Map is the foundational metadata and scanning service that discovers and classifies data across sources including Microsoft 365, Azure SQL Database, and Amazon S3. It registers sources, runs scans, applies classification rules, and builds the data estate catalog that other Purview solutions consume. Because the requirement spans multi-cloud and on-prem sources, the Data Map is the correct feature.

Exam trap

MS-102 often tests the confusion between Data Map (discovery/catalog) and Information Protection (labeling/enforcement), so candidates pick labels when the scenario is really about multi-source scanning.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention enforces policies on data in motion/use within supported workloads and does not scan Amazon S3 or build a cross-cloud catalog. Option B is wrong because sensitivity labels classify and protect content primarily in Microsoft 365 and supported apps, not arbitrary external sources like S3. Option C is wrong because eDiscovery is a legal/HR workflow for identifying and preserving content for litigation, not a data classification scanning engine.

302
MCQhard

A security analyst needs to create a custom detection rule in Microsoft Defender XDR that triggers when a device communicates with a new, unclassified IP address flagged by Microsoft threat intelligence as potentially malicious. The rule must run every hour and create an incident if the count of such communications exceeds 10 in a 24-hour window. Which type of rule should the analyst create?

A.custom detection rule using advanced hunting
B.scheduled alert rule in Microsoft Sentinel
C.An incident creation rule in Microsoft Defender for Cloud Apps
D.custom remediation action rule
AnswerA

Custom detection rules in Microsoft Defender XDR are built on advanced hunting queries written in Kusto Query Language (KQL). These queries can be scheduled to run periodically across the tenant's extended data schema, and when the query results meet defined thresholds, the rule generates an incident for investigation. This is the native mechanism for creating custom detections directly within the Defender XDR portal, making it the correct choice.

Why this answer

A custom detection rule using advanced hunting is the correct choice because Microsoft Defender XDR allows you to create custom detection rules based on Kusto Query Language (KQL) queries that run on a scheduled interval (e.g., every hour). This rule can query the `DeviceNetworkEvents` table to identify communications with IP addresses flagged as malicious by Microsoft threat intelligence, aggregate the count over a 24-hour sliding window, and trigger an incident when the threshold of 10 is exceeded. This directly meets the requirement for a scheduled, threshold-based detection within Defender XDR.

Exam trap

The trap here is that candidates often confuse the scope of Microsoft Defender XDR custom detections with Microsoft Sentinel scheduled alert rules, assuming any scheduled query must be in Sentinel, but Defender XDR's advanced hunting custom detections natively support scheduled queries and incident creation without requiring Sentinel.

How to eliminate wrong answers

Option B is wrong because a scheduled alert rule in Microsoft Sentinel is designed for Azure-based SIEM and SOAR capabilities, not for native custom detection within Microsoft Defender XDR; Sentinel operates on a different data ingestion pipeline and is not the correct tool for creating rules that run directly in the Defender XDR portal. Option C is wrong because an incident creation rule in Microsoft Defender for Cloud Apps focuses on app-level anomalies and cloud application behaviors, not on device-level network communications with IP addresses flagged by threat intelligence. Option D is wrong because a custom remediation action rule is used to define automated response actions (e.g., isolating a device or running a script) after a detection occurs, not to define the detection logic or scheduling itself.

303
MCQmedium

Your organization uses Microsoft Entra Connect Sync. You need to ensure that specific on-premises Active Directory groups are synchronized to Microsoft Entra ID. What should you configure?

A.Set the sync scope to 'Synchronize selected groups'
B.Configure attribute-based filtering in Microsoft Entra Connect
C.Create a security group in Microsoft Entra ID and add members
D.Use the Synchronization Service Manager to select groups
AnswerA

Selecting 'Synchronize selected groups' in Microsoft Entra Connect wizard (or via PowerShell) restricts synchronization to only the on-premises groups you explicitly choose, along with their members. This is the native group-based filtering (also called group scoping) feature, letting you sync, for example, only the 'Sales' group and its users while excluding all other objects. It directly controls what the sync engine copies from the on-premises connector to Microsoft Entra ID, making it the correct answer.

Why this answer

Microsoft Entra Connect Sync allows you to scope synchronization to specific groups by selecting 'Synchronize selected groups' in the Azure AD Connect configuration. This setting, available during installation or via the 'Customize synchronization options' task, restricts synchronization to only the on-premises Active Directory groups you explicitly choose, ensuring that only those groups are synced to Microsoft Entra ID.

Exam trap

The trap here is that candidates often confuse attribute-based filtering (Option B) with group-specific scoping, not realizing that attribute-based filtering applies to all object types and cannot be used to select individual groups for synchronization.

How to eliminate wrong answers

Option B is wrong because attribute-based filtering in Microsoft Entra Connect filters objects based on their attributes (e.g., department or country), not specifically for selecting which groups to synchronize; it is a broader filtering mechanism that can exclude objects but does not provide a group-specific selection. Option C is wrong because creating a security group in Microsoft Entra ID and adding members does not control which on-premises groups are synchronized; it creates a cloud-only group that is not linked to the on-premises synchronization process. Option D is wrong because the Synchronization Service Manager is used to manage synchronization operations (e.g., run profiles, connectors, and metaverse objects) but does not provide a configuration option to select specific groups for synchronization; group selection is done during the Azure AD Connect configuration wizard.

304
Multi-Selectmedium

Your company is implementing Microsoft Purview Information Protection to classify and protect sensitive documents. You need to ensure that all documents containing personally identifiable information (PII) are automatically labeled. Which TWO actions should you take? (Select TWO.)

Select 2 answers
A.Define a custom sensitive info type in Microsoft Purview that matches your organization's PII patterns.
B.Train users to manually apply a sensitivity label to documents containing PII.
C.Configure a sensitivity label to encrypt documents containing PII.
D.Create a retention label for documents containing PII.
E.Create an auto-labeling policy in Microsoft Purview that applies a sensitivity label to documents containing PII.
AnswersA, E

A custom sensitive info type defines the regex, keyword list and confidence level matching your organisation's specific PII formats, which built-in types may miss. Auto-labeling policies then reference this type, satisfying the requirement that all PII-containing documents are detected accurately.

Why this answer

Option A is correct because defining a custom sensitive information type in Microsoft Purview lets you match your organization's specific PII patterns (for example, using regular expressions, keywords, and confidence levels) so that the classification engine can reliably detect the PII unique to your environment. Option E is correct because an auto-labeling policy in Microsoft Purview is the mechanism that automatically applies a sensitivity label to documents that match sensitive information types, which is exactly what is required to label PII-containing documents without user intervention. Option B is incorrect because training users to apply labels manually does not provide the automatic labeling the scenario requires.

Option C is incorrect because configuring a sensitivity label to encrypt documents only defines the protection action of a label; by itself it does not automatically detect or label PII content. Option D is incorrect because a retention label governs how long content is kept or deleted, not how it is classified and protected for PII.

Exam trap

MS-102 often tests the pairing of a sensitive info type with an auto-labeling policy — candidates pick encryption or retention labels thinking those achieve automatic classification, but only auto-labeling policies apply sensitivity labels based on content detection.

305
MCQeasy

A user receives an email from an unknown sender with a .zip attachment. The attachment contains a potentially malicious executable file. Microsoft Defender for Office 365 is enabled. Which feature dynamically detonates the attachment in a sandbox environment and blocks it if malicious behavior is detected?

A.Safe Attachments
B.Safe Links
C.Anti-phishing
D.Anti-spam
AnswerA

Safe Attachments is the correct answer because it uses behavioral analysis, machine learning, and sandbox detonation to inspect email attachments such as a zip file. When a message contains a zip, Safe Attachments extracts the archive and detonates its contents in a controlled, isolated environment, monitoring for malicious actions like process injection, file writes, or network calls. This catches zero-day and polymorphic malware that signature-based scanners miss, and the email is held until analysis completes.

Why this answer

Safe Attachments is the correct feature because it specifically detonates email attachments in a dynamic sandbox environment, analyzing behavior in real time. If the .zip file contains a malicious executable, Safe Attachments will block the email before delivery, preventing the user from accessing the threat. This is distinct from other Defender for Office 365 features that focus on URLs, phishing content, or spam filtering.

Exam trap

The trap here is that candidates confuse Safe Attachments with Safe Links, assuming both handle attachments, but Safe Links only rewrites and checks URLs, not file payloads.

How to eliminate wrong answers

Option B is wrong because Safe Links protects against malicious URLs within emails or Office documents, not file attachments. Option C is wrong because Anti-phishing policies detect impersonation and spoofing attempts, not executable file analysis. Option D is wrong because Anti-spam policies filter bulk or junk email based on sender reputation and content, not dynamic file detonation.

306
MCQmedium

A compliance officer needs to automatically retain documents in a SharePoint Online document library for 7 years and then automatically delete them. The retention must be applied based on when the document is created. Which Microsoft Purview feature should be configured?

A.Data Lifecycle Management
B.Records Management
C.eDiscovery
D.Communication Compliance
AnswerA

Data Lifecycle Management in Microsoft Purview is the solution specifically built to automate retention and deletion based on configured policies. It uses retention labels and policies to apply rules like 'retain for 7 years then delete' triggered by content age or events. This lets you meet compliance obligations without manual intervention, making it the correct choice for automatically retaining documents.

Why this answer

Data Lifecycle Management (DLM) in Microsoft Purview allows you to create retention labels that automatically retain content for a specified period (e.g., 7 years) based on the date the document was created, and then trigger a disposal action such as deletion. This feature is designed specifically for managing the lifecycle of data in SharePoint Online, including automatic retention and deletion based on metadata like creation date.

Exam trap

The trap here is that candidates often confuse Records Management with Data Lifecycle Management, assuming that any retention policy must involve records, when in fact DLM handles automated retention and deletion without requiring the content to be declared a record.

How to eliminate wrong answers

Option B (Records Management) is wrong because Records Management is focused on declaring content as records (immutable, auditable) and applying retention that prevents deletion or modification, not on automatically deleting content after a set period. Option C (eDiscovery) is wrong because eDiscovery is used for searching, holding, and exporting content for legal or investigative purposes, not for automated retention and deletion policies. Option D (Communication Compliance) is wrong because Communication Compliance is designed to detect and remediate inappropriate communications (e.g., harassment, sensitive info) in Microsoft Teams, Exchange, and Yammer, not for managing document lifecycle retention or deletion.

307
MCQhard

You are hunting for malicious activity in Microsoft 365 Defender. The exhibit shows a KQL query. What is the query searching for?

A.PowerShell processes with standard command line arguments
B.Processes that created PowerShell processes
C.PowerShell processes that were downloaded from the internet
D.PowerShell processes with encoded command line arguments
AnswerD

The query filters process command lines for encoded arguments, a common obfuscation technique where Base64 hides malicious PowerShell payloads. Matching on encoded command line indicators surfaces this behaviour, satisfying the stem's hunt for malicious activity in Microsoft 365 Defender.

Why this answer

The KQL query filters PowerShell process creation events where the command line contains encoded command indicators such as '-enc', '-EncodedCommand', or Base64-looking strings. This pattern is a classic detection for obfuscated PowerShell used by attackers to hide malicious scripts from casual inspection and simple string-based defenses.

Exam trap

MS-102 often tests whether candidates can distinguish between detection logic based on command-line content versus process lineage or network behavior, causing them to pick the parent-process or download-origin option.

How to eliminate wrong answers

Option A is wrong because standard command line arguments would not match the encoded-command pattern the query targets. Option B is wrong because the query filters on PowerShell processes themselves, not on parent processes that spawned PowerShell. Option C is wrong because the query does not inspect network origin or download activity; it only examines the command line content of PowerShell executions.

308
Multi-Selectmedium

A security analyst is creating a custom detection rule in Microsoft 365 Defender Advanced Hunting. The rule should trigger when a device makes an outbound connection to a known malicious IP address, and within 10 minutes, a process with suspicious command-line arguments is started on the same device. Which two Advanced Hunting tables must be joined using a KQL query to create this detection?

Select 1 answer
A.DeviceNetworkEvents and DeviceProcessEvents.
B.DeviceEvents and DeviceLogonEvents.
C.DeviceProcessEvents and DeviceFileEvents.
D.DeviceNetworkEvents and DeviceRegistryEvents.
AnswersA

DeviceNetworkEvents supplies outbound connection records, including RemoteIP, while DeviceProcessEvents captures process starts with ProcessCommandLine. Joining both on DeviceId and aligning timestamps within the 10-minute window satisfies the correlation requirement, since no single table holds network and process-creation data together.

Why this answer

The detection rule correlates an outbound network connection to a known malicious IP with a subsequent process creation on the same device within 10 minutes. This requires joining DeviceNetworkEvents (for network connections) with DeviceProcessEvents (for process creation and command-line arguments). DeviceFileEvents is not needed because the rule does not involve file events.

Therefore, only Option A provides the necessary tables.

Exam trap

Candidates might think that file events or other tables are also required, but the scenario specifically pairs network events with process events on the same device within a time window. Joining DeviceProcessEvents with DeviceFileEvents would be irrelevant.

309
MCQmedium

Your company uses Microsoft Entra ID. You need to restrict access to a critical application to only users who are in a specific security group and are signing in from a trusted location. You configure a conditional access policy with the following conditions: users (the security group), cloud apps (the critical application), conditions (locations: trusted IP ranges). However, users in the security group are still able to access the app from untrusted locations. What is the most likely reason?

A.The policy is configured as a block policy but is overridden by another policy
B.The cloud app is not correctly assigned to the policy
C.The policy uses session controls instead of grant controls
D.The policy is in report-only mode
AnswerD

Report-only mode evaluates a Conditional Access policy and writes the results to the Identity Protection logs without enforcing any of its configured controls. For a block policy, report-only means the intended block is never applied, and access is allowed exactly as if the policy did not exist. This is the classic default misconfiguration that makes a block policy appear ineffective during testing.

Why this answer

When a Conditional Access policy is in report-only mode, it evaluates the conditions and logs the result but does not enforce any access controls (grant or block). This explains why users in the security group can still access the app from untrusted locations—the policy is not actively blocking or requiring MFA/location compliance. Report-only mode is commonly used for testing before enabling enforcement.

Exam trap

The trap here is that candidates often assume a Conditional Access policy automatically enforces its conditions once configured, overlooking the critical distinction between report-only mode (evaluation only) and on/enforce mode (evaluation + enforcement).

How to eliminate wrong answers

Option A is wrong because if the policy were a block policy, it would actively block access when conditions match; the issue here is that no enforcement occurs at all, not that another policy overrides it. Option B is wrong because the cloud app assignment is correctly configured per the scenario; if it were incorrect, the policy wouldn't apply to the app at all, but users are still accessing it, indicating the policy is not enforcing. Option C is wrong because session controls (e.g., sign-in frequency) do not prevent access from untrusted locations; only grant controls (e.g., require trusted location) can block or allow access based on location.

The core problem is that the policy is not enforcing any controls, which points to report-only mode.

310
Multi-Selectmedium

Your organization uses Microsoft 365 and wants to implement a passwordless authentication strategy. Which THREE methods are supported natively in Microsoft Entra ID for passwordless sign-in?

Select 3 answers
A.Smart cards (physical or virtual)
B.Microsoft Authenticator app (phone sign-in)
C.Temporary Access Pass
D.Certificate-based authentication
E.FIDO2 security keys
AnswersB, C, E

Microsoft Entra ID supports phone sign-in through the Microsoft Authenticator app as a native passwordless method, binding credentials to the device. Users approve a number match rather than entering a password, satisfying the passwordless sign-in requirement.

Why this answer

Microsoft Entra ID natively supports three passwordless authentication methods: Windows Hello, FIDO2 security keys, and the Microsoft Authenticator app (phone sign-in), so option B is correct because Authenticator phone sign-in lets users sign in by approving a notification with a biometric or PIN instead of a password. Option C is correct because Temporary Access Pass is a native passwordless method that issues a time-limited passcode used to register other passwordless methods or recover access. Option E is correct because FIDO2 security keys are native passwordless credentials that use WebAuthn for phishing-resistant sign-in.

Options A and D are not correct because smart cards and certificate-based authentication, while supported for authentication in Entra ID, are not classified as native passwordless sign-in methods in the passwordless authentication strategy.

Exam trap

A common trap is thinking that Temporary Access Pass is not a native passwordless method because it is often used for recovery, but it is indeed a supported native method in Entra ID. Candidates may also overlook it because it is limited in duration, but it is still considered passwordless.

311
MCQeasy

A security administrator wants to review email messages that were blocked due to a malware detection in Microsoft Defender for Office 365. Which report should they use?

A.Submissions report
B.Spoof intelligence report
C.Mailflow map report
D.Threat Protection Status report
AnswerD

The Threat Protection Status report aggregates detections across Exchange Online Protection and Defender for Office 365, including malware blocked by anti-malware policies. It satisfies the requirement to review blocked email messages by surfacing malware detections with details such as recipient, sender, and detection technology, enabling the administrator to investigate the specific blocked items.

Why this answer

The Threat Protection Status report in Microsoft Defender for Office 365 provides details on email messages blocked due to malware, phishing, or other threats. It includes data on detections by type and allows administrators to review blocked messages. The Submissions report is for user/admin submissions of suspicious email, the Spoof intelligence report covers spoofing, and the Mailflow map report visualizes mail flow, not blocked malware messages.

Exam trap

MS-102 often tests the specific purpose of each Defender for Office 365 report — candidates confuse the Submissions report (user-reported emails) with the Threat Protection Status report (system-detected threats), leading to wrong answers when asked about reviewing blocked malware messages.

How to eliminate wrong answers

Option A is wrong because the Submissions report tracks emails submitted by users or admins for analysis, not the overall blocked malware messages. Option B is wrong because the Spoof intelligence report focuses on spoofing detections and allow/block decisions for spoofed senders, not malware blocks. Option C is wrong because the Mailflow map report is a visual representation of mail flow through the organization, not a report of blocked malware messages.

312
MCQhard

Your organization is implementing Microsoft Defender for Cloud Apps. You need to configure anomaly detection policies to alert when a user downloads an unusually large number of files from SharePoint Online. Which data source should you connect to enable this detection?

A.API connector for custom apps
B.App connector for SharePoint Online
C.Microsoft 365 Defender portal
D.Microsoft Entra ID logs
AnswerB

The App connector for SharePoint Online is the correct data source because it uses the Office 365 Management Activity API to capture user-level file activities such as downloads, uploads, edits, and permissions changes from SharePoint. When enabled in Microsoft Defender for Cloud Apps, it continuously ingests these events, which are essential for anomaly detection scenarios like unusual mass downloading or impossible travel. This connector directly provides the file-level context that sign-in logs and management portals lack, making it the single authoritative source for this requirement.

Why this answer

To detect anomalous file downloads from SharePoint Online, Microsoft Defender for Cloud Apps requires direct integration with the service via an App connector. The App connector for SharePoint Online (option B) enables the collection of metadata and activity logs necessary for anomaly detection policies, such as the 'Unusual file download by a user' policy. Without this connector, Defender for Cloud Apps cannot monitor SharePoint Online activities.

Exam trap

The trap here is that candidates often confuse Microsoft 365 Defender portal (a viewing/management interface) with a data source, or assume that Microsoft Entra ID logs contain sufficient activity data for file-level anomaly detection, when in fact only the App connector provides the necessary SharePoint Online activity metadata.

How to eliminate wrong answers

Option A is wrong because the API connector for custom apps is designed for third-party or custom applications that are not natively supported, not for connecting to Microsoft cloud services like SharePoint Online. Option C is wrong because Microsoft 365 Defender portal is the unified interface for viewing alerts and incidents, not a data source that provides activity logs to Defender for Cloud Apps. Option D is wrong because Microsoft Entra ID logs contain sign-in and authentication events, not the granular file download activities from SharePoint Online that are required for anomaly detection.

313
MCQmedium

Your organization receives a data subject request (DSR) to export personal data of a user. Which Microsoft Purview solution should you use to search for and export the data?

A.Microsoft Purview retention policies
B.Microsoft Purview Audit
C.Microsoft Purview eDiscovery
D.Microsoft Purview Data Loss Prevention
AnswerC

Microsoft Purview eDiscovery supports searching across Microsoft 365 content and exporting results, matching the requirement to locate and export a user's personal data for a DSR. It provides the case-based search, hold and export capabilities that DSR fulfilment demands.

Why this answer

Microsoft Purview eDiscovery allows you to search for content across Microsoft 365 and export it, which is necessary to fulfill a data subject request (DSR) to export personal data. Option A is incorrect because retention policies are used to retain data for a specified period, not to export it. Option B is incorrect because audit logs track activities but do not provide content search or export capabilities.

Option D is incorrect because Data Loss Prevention (DLP) is designed to prevent data leaks, not to export data.

314
Multi-Selecthard

You are the Microsoft 365 administrator for a company that uses Microsoft 365 E5. The company has a Microsoft Entra tenant with hybrid identity synchronized from on-premises Active Directory using Microsoft Entra Connect. You need to implement self-service password reset (SSPR) so that users can reset their passwords from the Azure portal. The solution must ensure that password changes are written back to on-premises Active Directory. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Configure the on-premises Active Directory domain to use fine-grained password policies.
B.Enable password hash synchronization and seamless single sign-on.
C.Enable self-service password reset for all users in the Microsoft Entra admin center.
D.Configure Microsoft Entra Connect to use password hash synchronization.
E.Enable password writeback in Microsoft Entra Connect.
AnswersC, E

To allow users to reset their passwords, SSPR must be enabled and scoped to the appropriate users. Enabling SSPR in the Microsoft Entra admin center is a necessary step. Without it, users cannot initiate a password reset from the Azure portal. This action, combined with password writeback, meets the requirement.

Why this answer

Enabling SSPR in Microsoft Entra ID allows users to reset their passwords, and enabling password writeback in Microsoft Entra Connect ensures those new passwords are synchronized back to on-premises Active Directory. Together, these actions provide a seamless self-service password reset experience that keeps on-premises and cloud passwords in sync.

Exam trap

The trap here is assuming that password hash synchronization or seamless SSO enables writeback, when in fact writeback is a separate feature that must be explicitly enabled.

315
MCQhard

You are configuring a Microsoft Entra Conditional Access policy to require compliant devices for access to Microsoft 365 apps. You need to ensure that the policy applies to all users except those in the 'BreakGlass' group. The BreakGlass group contains emergency access accounts. What should you do?

A.Create a Conditional Access policy that includes the BreakGlass group and set the grant control to 'Block access'.
B.Create a Conditional Access policy that includes all users, excludes the BreakGlass group, and set the grant control to 'Require multi-factor authentication'.
C.Create a Conditional Access policy that includes all users and excludes the BreakGlass group, and set the grant control to 'Require device to be marked as compliant'.
D.Create a Conditional Access policy that includes all users and excludes the BreakGlass group, and set the session control to 'Use app enforced restrictions'.
AnswerC

Conditional Access policies allow you to include all users and then exclude specific groups, such as the BreakGlass group. This ensures that emergency access accounts are not blocked by the policy. Setting the grant control to require a compliant device enforces the device compliance requirement for all other users. This is the correct and recommended approach to avoid locking out emergency accounts.

Why this answer

To enforce device compliance while excluding emergency access accounts, create a Conditional Access policy that targets all users but excludes the BreakGlass group. Then set the grant control to require the device to be marked as compliant. This ensures that only compliant devices can access Microsoft 365 apps, while emergency accounts remain unaffected.

The other options either block emergency accounts, apply session restrictions instead of compliance, or require MFA instead of compliance.

Exam trap

The trap here is mixing up grant controls and session controls; requiring a compliant device is a grant control, not a session control like app enforced restrictions.

316
Multi-Selecthard

Which TWO components are part of Microsoft Defender XDR?

Select 2 answers
A.Microsoft Defender for Office 365
B.Microsoft Purview
C.Microsoft Defender for Endpoint
D.Microsoft Intune
E.Microsoft Sentinel
AnswersA, C

Microsoft Defender for Office 365 is one of the workload pillars composing Microsoft Defender XDR, feeding email, collaboration and phishing signals into the unified incident graph. Its native integration with Defender for Endpoint, Identity and Cloud Apps satisfies the stem's requirement for a constituent component of the suite.

Why this answer

Microsoft Defender XDR is a unified extended detection and response suite that natively correlates signals across Microsoft's first-party security workloads, and Microsoft Defender for Office 365 (option A) is one of its core pillars, delivering protection against phishing, malware, and business email compromise across Exchange Online, Teams, and SharePoint/OneDrive. Microsoft Defender for Endpoint (option C) is likewise a native Defender XDR component, providing endpoint detection and response, attack surface reduction, and automated investigation and remediation that feed into the unified incident queue. By contrast, Microsoft Purview (option B) is a separate compliance and data-governance solution family (information protection, DLP, eDiscovery), Microsoft Intune (option D) is the cloud-based endpoint management/MDM service in the Microsoft Intune family, and Microsoft Sentinel (option E) is a standalone cloud-native SIEM/SOAR product that integrates with Defender XDR but is not itself one of its constituent workloads.

Exam trap

MS-102 often tests whether candidates confuse Defender XDR components with adjacent Microsoft security and compliance products like Purview, Intune, and Sentinel.

317
Multi-Selecthard

A compliance officer needs to ensure that all documents containing a custom sensitive info type (Employee ID with pattern EMP-####) are automatically labeled with a retention label that retains the documents for 3 years. Which two Microsoft Purview components must be configured? (Choose two.)

Select 2 answers
A.sensitivity label
B.retention label
C.data loss prevention (DLP) policy
D.An auto-labeling policy for retention labels
AnswersB, D

A retention label defines the retention and deletion rules for content at a granular level, such as preserving documents for a specific number of days, years, or permanently. You can apply it manually to individual items or through auto-labeling policies, and it triggers a retention period that cannot be overridden by users. For the compliance officer's requirement to manage document retention, this is the direct and authoritative mechanism.

Why this answer

A retention label is required to specify the retention period (3 years) for the documents. An auto-labeling policy for retention labels is needed to automatically apply that retention label based on the detection of the custom sensitive info type (Employee ID pattern EMP-####). Together, these two components enable automatic classification and retention without manual user intervention.

Exam trap

The trap here is that candidates often confuse sensitivity labels with retention labels, or think a DLP policy can apply retention labels, but Microsoft Purview separates these functions: DLP controls data movement, while auto-labeling policies for retention labels handle automatic retention label assignment.

318
MCQmedium

The legal department is investigating a potential data breach involving a specific user. The compliance officer needs to place a hold on all content in the user's Exchange Online mailbox and OneDrive for Business to prevent deletion until the investigation is complete. Which Microsoft Purview solution should the officer use?

A.Content Search
B.eDiscovery (Standard)
C.eDiscovery (Premium)
D.Audit log
AnswerB

eDiscovery (Standard), also known as eDiscovery in the classic compliance center, is a case-based workflow that allows you to create a case and then place legal holds on specific content locations, including Exchange mailboxes, OneDrive for Business sites, SharePoint sites, and Teams. These holds preserve data in full fidelity, preventing users from permanently deleting or modifying content, even if retention policies are not configured. For a data breach investigation, creating an eDiscovery (Standard) case and applying a hold is the correct, cost-effective method to ensure the relevant content remains intact while you search and analyze it.

Why this answer

eDiscovery (Standard) allows you to place a hold on Exchange Online mailboxes and OneDrive for Business sites to preserve content from deletion during an investigation. This hold prevents users and automated processes from permanently deleting items, ensuring data integrity for legal or compliance reviews.

Exam trap

The trap here is that candidates often confuse the search-only capability of Content Search with the preservation functionality of eDiscovery (Standard), or mistakenly think eDiscovery (Premium) is required for holds, when in fact holds are a standard feature of eDiscovery (Standard).

How to eliminate wrong answers

Option A is wrong because Content Search is used to search for content across Microsoft 365 but cannot place a hold to preserve data; it only returns search results. Option C is wrong because eDiscovery (Premium) extends eDiscovery (Standard) with advanced analytics and review sets, but placing a hold is a core feature of eDiscovery (Standard) and does not require Premium. Option D is wrong because Audit log records user and admin activities for forensic analysis but does not prevent deletion of content; it only logs what happened.

319
MCQeasy

You are implementing Microsoft Entra Verified ID. Which identity verification method uses a decentralized identity standard?

A.Decentralized identifiers (DIDs)
B.SAML 2.0
C.OAuth 2.0
D.Federation with Azure AD
AnswerA

Decentralized identifiers (DIDs) are the core of Microsoft Entra Verified ID: they are W3C-standard, globally unique identifiers generated from a public/private key pair and resolvable without a central registry. In Entra Verified ID, issuers and verifiers anchor DIDs to ION (Sidetree on Bitcoin) or use did:web, and the key holder uses the private key to sign Verifiable Credentials. This gives the user a self-owned, portable identity that cannot be revoked or controlled by a single IdP, which is exactly what Verified ID is designed to provide.

Why this answer

Microsoft Entra Verified ID is built on open standards for decentralized identity, specifically using Decentralized Identifiers (DIDs) as defined by the W3C. DIDs enable verifiable, self-sovereign identity without relying on a central authority, which is the core requirement for a decentralized identity verification method. This allows users to control their own identifiers and present verifiable credentials that can be cryptographically verified.

Exam trap

The trap here is that candidates confuse decentralized identity with federation or token-based protocols (SAML, OAuth), which are centralized by design, and fail to recognize that DIDs are the specific W3C standard enabling self-sovereign identity in Verified ID.

How to eliminate wrong answers

Option B is wrong because SAML 2.0 is a centralized federation protocol that relies on a single identity provider (IdP) to assert identity, not a decentralized standard. Option C is wrong because OAuth 2.0 is an authorization framework for token-based access delegation, not an identity verification method or decentralized identity standard. Option D is wrong because federation with Azure AD is a centralized identity management approach that depends on a trusted authority (Azure AD) to manage identities, which contradicts the decentralized, user-controlled model of Verified ID.

320
Multi-Selectmedium

Your organization uses Microsoft Purview Compliance Manager to manage compliance activities. Which TWO actions can be performed directly from Compliance Manager?

Select 2 answers
A.Assign an improvement action to a user.
B.Upload evidence for an improvement action.
C.View and manage DLP alerts.
D.Create a retention policy for Exchange Online.
E.Create a sensitivity label.
AnswersA, B

Assigning an improvement action to a user is a core function inside Compliance Manager. Every improvement action has an owner field, and you can set that owner directly from the action's details page to assign responsibility. This ensures accountability for specific regulatory controls and enables tracking of implementation status within the compliance scoring workflow.

Why this answer

Compliance Manager is a solution within Microsoft Purview that provides a centralized dashboard for managing compliance activities. It allows you to assign improvement actions to specific users to track responsibility and progress, and to upload evidence files directly to an improvement action to demonstrate compliance with a control. These are core, direct functions of the Compliance Manager interface.

Exam trap

The trap here is that candidates confuse the Microsoft Purview compliance portal's overall capabilities with the specific, limited set of actions that can be performed directly within the Compliance Manager solution, leading them to select actions that are available elsewhere in the portal but not inside Compliance Manager.

321
MCQmedium

Your organization uses Microsoft Defender for Identity. You receive an alert about a suspicious LDAP query from a domain controller. After investigating, you determine the query is legitimate. How should you prevent future alerts for this activity?

A.Create a suppression rule for that alert type and entity.
B.Create a custom detection rule to allow the LDAP query.
C.Disable the Defender for Identity sensor on the domain controller.
D.Change the alert severity to Low.
AnswerA

Suppression rules in Microsoft Defender for Identity silence matching alerts by type and entity, so the confirmed-benign LDAP query from that domain controller stops generating alerts. This satisfies the stem's requirement to prevent future alerts for legitimate activity.

Why this answer

Microsoft Defender for Identity suppression rules are the designed mechanism for silencing alerts that have been triaged as benign. A suppression rule scoped to the specific alert type (e.g., 'Suspicious LDAP query') and the specific entity (the domain controller or account) prevents future identical alerts from being raised without weakening detection for the rest of the environment. This preserves the integrity of the detection pipeline while eliminating noise from known-good activity.

Exam trap

MS-102 often tests the difference between suppressing a specific alert (scoped to alert type + entity) and disabling the sensor or detection entirely — candidates who pick the 'disable' option fail to recognize that suppression is the surgical, non-disruptive fix.

How to eliminate wrong answers

Option B is wrong because custom detection rules in Defender XDR are used to create new detections from advanced hunting queries, not to whitelist or allow existing activity — there is no 'allow' action that suppresses an existing Defender for Identity alert. Option C is wrong because disabling the Defender for Identity sensor on the domain controller stops all identity telemetry from that DC, creating a massive blind spot and defeating the purpose of the sensor rather than addressing a single noisy alert. Option D is wrong because lowering the severity of an alert does not prevent it from being generated or appearing in the incident queue — it merely changes its classification, so the analyst would still receive the same alert repeatedly.

322
MCQeasy

You need to integrate Microsoft Defender XDR with Microsoft Sentinel for centralized monitoring. Which data connector should you use?

A.Microsoft Defender for Cloud connector
B.Azure Security Center connector
C.Microsoft 365 Defender connector
D.Microsoft Defender XDR connector
AnswerD

The Microsoft Defender XDR connector is the native Microsoft Sentinel data connector that connects directly to Microsoft Defender XDR through its public API. It ingests incidents, alerts, and advanced hunting event tables from all Microsoft Defender workloads, automatically correlating signals from Endpoint, Identity, Office 365, and Cloud Apps into a Sentinel incident. This bidirectional sync allows incident updates in either portal to propagate to the other, which is exactly what is needed when integrating Microsoft Defender XDR with Microsoft Sentinel.

Why this answer

The Microsoft Defender XDR connector (option D) is the correct choice because it ingests signals from all Microsoft 365 Defender components—including Defender for Endpoint, Office 365, Identity, and Cloud Apps—into Microsoft Sentinel. This connector uses the Microsoft 365 Defender API to stream unified alerts and incidents, enabling centralized monitoring and correlation across the entire XDR stack.

Exam trap

The trap here is that candidates confuse the 'Microsoft 365 Defender connector' (which does not exist) with the 'Microsoft Defender XDR connector', or they mistakenly choose the Defender for Cloud connector thinking it covers all Microsoft security signals.

How to eliminate wrong answers

Option A is wrong because the Microsoft Defender for Cloud connector is designed to ingest security alerts and posture data from Azure, on-premises, and other cloud workloads, not from Microsoft 365 Defender's XDR components. Option B is wrong because the Azure Security Center connector is a legacy name that has been replaced by Microsoft Defender for Cloud; it does not provide the unified incident and alert stream from Microsoft 365 Defender. Option C is wrong because there is no connector named 'Microsoft 365 Defender connector'—the correct connector name is 'Microsoft Defender XDR connector', and the former would imply a different API endpoint or data type.

323
MCQhard

You are the security administrator for a multinational organization using Microsoft 365 E5. The organization has 10,000 users across three regions: North America, Europe, and Asia. You have deployed Microsoft Defender for Endpoint on all Windows devices and enabled Microsoft Defender for Office 365. Recently, a sophisticated phishing campaign targeted executives in Europe, using a custom domain that closely resembles your legitimate domain (e.g., contoso.com vs. contos0.com). The emails bypassed anti-spam and anti-phishing policies. You need to configure protection to block these impersonation attempts without affecting legitimate emails from the actual domain. You must also ensure that any similar future attempts using different variations are automatically detected. What should you do?

A.Create a Safe Links policy with a block action for URLs containing 'contos0.com'.
B.Enable mailbox intelligence in anti-phishing policies to detect unusual sender behavior.
C.Add the spoofed domain 'contos0.com' to the Tenant Allow/Block List in the Defender for Office 365 portal.
D.Configure an anti-phishing policy to protect against impersonation of your domain, enabling the 'Protect against impersonation of domains I own' setting and adding your legitimate domain to the list of domains to protect.
AnswerD

Domain impersonation protection in an anti-phishing policy uses the 'domains I own' setting, adding contoso.com so lookalike senders such as contos0.com are blocked while genuine mail passes. This satisfies the requirement to block variations without affecting legitimate domain traffic.

Why this answer

Anti-phishing policies in Microsoft Defender for Office 365 include a dedicated domain impersonation setting called 'Protect against impersonation of domains I own.' By enabling this and adding contoso.com to the protected domains list, Defender uses its impersonation detection engine to catch lookalike domains (contos0.com, contoso.co, etc.) using homoglyph, typo, and character-substitution analysis — not just exact string matches. This automatically generalizes to future variations without needing to enumerate each spoofed domain manually.

Exam trap

MS-102 often tests the difference between static block lists (Tenant Allow/Block List) and dynamic impersonation detection — candidates pick the block list because it feels concrete, but the exam requires the setting that automatically generalizes to new lookalike domains.

How to eliminate wrong answers

Option A is wrong because Safe Links only rewrites and detonates URLs at click time; it does not detect sender-domain impersonation, and blocking a literal string 'contos0.com' would not catch future variations like 'contos0.co' or 'c0ntoso.com'. Option B is wrong because mailbox intelligence detects anomalous sender behavior per-user (based on historical communication patterns), not domain lookalike impersonation, and it would not reliably catch a first-time spoofed domain targeting executives. Option C is wrong because the Tenant Allow/Block List is a static, exact-match list — it blocks only the specific entry 'contos0.com' and provides no automatic detection of new lookalike domains, which the question explicitly requires.

324
MCQmedium

A company has a Microsoft 365 tenant with domain contoso.com. They own an additional domain fabrikam.com and have already added and verified it with a TXT record. Now they need to configure email to be routed to Exchange Online for fabrikam.com. Which DNS record must they create?

A.MX record pointing to contoso-com.mail.protection.outlook.com
B.CNAME record for autodiscover
C.TXT record for SPF
D.SRV record for SIP
AnswerA

Creating an MX record for fabrikam.com that points to `contoso-com.mail.protection.outlook.com` correctly configures email routing to Exchange Online. The MX record is the fundamental DNS mechanism that directs sending mail servers to the correct destination for a domain's email. For Microsoft 365, all verified domains within a single tenant share the same Exchange Online mail routing infrastructure. The `contoso-com` prefix identifies the specific Microsoft 365 tenant's mail protection service, ensuring that email for fabrikam.com is routed to the correct Exchange Online instance.

Why this answer

To route email for fabrikam.com to Exchange Online, you must create an MX record that points to the Exchange Online mail exchanger. The correct target is contoso-com.mail.protection.outlook.com, where 'contoso-com' is the hashed version of the primary domain (contoso.com) used by Microsoft 365. This MX record tells the internet's mail servers to deliver messages addressed to @fabrikam.com into the tenant's Exchange Online environment.

Exam trap

The trap here is that candidates often think they need to create an MX record pointing to 'fabrikam-com.mail.protection.outlook.com' (using the added domain), but Microsoft 365 always uses the primary domain's hashed value in the MX target regardless of which domain's email is being routed.

How to eliminate wrong answers

Option B is wrong because a CNAME record for autodiscover is used to automatically configure Outlook clients with Exchange Online settings, not to route email delivery. Option C is wrong because a TXT record for SPF is used to authorize sending servers and prevent spoofing, not to direct inbound email flow. Option D is wrong because an SRV record for SIP is used for VoIP and unified communications (Skype for Business/Teams), not for email routing.

325
MCQeasy

A global administrator wants to track service health issues and configure notifications for service incidents. Which portal should they use to view the current health status and set up email notifications?

A.Microsoft 365 admin center
B.Azure portal
C.Microsoft 365 Defender portal
D.Microsoft Purview compliance portal
AnswerA

The Service Health page in the Microsoft 365 admin center (under Health > Service health) aggregates current and historical health status for all Microsoft 365 workloads, including incidents, advisories, and expected resolutions. From this page, a global administrator can filter by product or region, view detailed problem descriptions, and configure proactive email notifications using the 'Notify me about issues' option. This dashboard is the designated console for tracking Microsoft 365 service health and directly satisfies the requirement.

Why this answer

The Microsoft 365 admin center provides the Service Health dashboard under Health > Service Health, which displays the current status of all Microsoft 365 services and allows administrators to configure email notifications for service incidents. This is the designated portal for managing tenant-wide service health and notifications, aligning with the role of a global administrator.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 admin center with the Azure portal for service health, because Azure also has a Service Health blade, but it only covers Azure services, not Microsoft 365 services like Exchange Online or Teams.

How to eliminate wrong answers

Option B is wrong because the Azure portal is used for managing Azure services and resources, not for Microsoft 365 service health or email notifications; it lacks the Service Health dashboard for Microsoft 365. Option C is wrong because the Microsoft 365 Defender portal focuses on security threats, incidents, and alerts (e.g., from Microsoft Defender for Office 365), not on service health incidents or email notifications for service availability. Option D is wrong because the Microsoft Purview compliance portal is dedicated to data governance, compliance, and eDiscovery, not to tracking service health or configuring notifications for service incidents.

326
MCQmedium

Your organization uses Microsoft Entra ID P2 licensing. You need to ensure that when a user's risk level is detected as 'high' by Identity Protection, the user is automatically required to perform a password change during their next sign-in. Which conditional access policy configuration should you use?

A.Assign 'Sign-in risk policy' with session control 'Sign-in frequency'
B.Assign 'User risk policy' with grant 'Require password change'
C.Assign 'User risk policy' with grant 'Require multifactor authentication'
D.Assign 'User risk policy' with grant 'Block access'
AnswerB

When a user risk policy triggers a 'Require password change' grant, the user must change their password before accessing resources, which invalidates the compromised credential. This directly remediates the detected user risk because the attacker no longer knows the valid password, and is the only option listed that performs an actual password reset.

Why this answer

The 'User risk policy' in Microsoft Entra ID Conditional Access is specifically designed to respond to user-level risk detections from Identity Protection. When a user's risk level is 'high', the policy can enforce a 'Require password change' grant, which forces the user to change their password at next sign-in to remediate the compromised account. This aligns with the requirement to automatically trigger a password change based on user risk.

Exam trap

The trap here is confusing 'Sign-in risk policy' (which controls session behavior) with 'User risk policy' (which controls user-level remediation), leading candidates to incorrectly select Option A for a password change requirement.

How to eliminate wrong answers

Option A is wrong because 'Sign-in risk policy' targets sign-in sessions (e.g., impossible travel, anonymous IP) and uses session controls like 'Sign-in frequency' to reauthenticate, not to force a password change based on user risk. Option C is wrong because 'Require multifactor authentication' as a grant for a user risk policy would prompt for MFA but does not force a password change, which is required to remediate a high-risk user. Option D is wrong because 'Block access' would prevent the user from signing in entirely, not allow them to sign in and then change their password.

327
MCQeasy

Your organization uses Microsoft Entra ID to manage user identities. You need to ensure that users can sign in using their existing social media accounts, such as Google or Facebook. Which identity solution should you configure?

A.External identities
B.Microsoft Entra B2B collaboration
C.Managed identities
D.Microsoft Entra Identity Protection
AnswerA

External identities is the Microsoft Entra ID capability that encompasses all identities outside your own directory, including B2B collaboration and B2C. It directly supports social identity providers such as Google and Facebook, allowing users to authenticate with those credentials and then access organizational or consumer-facing applications. Because the scenario is about social identity providers for user sign-in, this is the correct answer.

Why this answer

External identities in Microsoft Entra ID allow you to configure identity providers such as Google and Facebook, enabling users to sign in with their existing social media accounts. This is achieved by setting up federation with OAuth 2.0 and OpenID Connect protocols, which is the correct solution for the scenario described.

Exam trap

The trap here is that candidates often confuse 'External identities' (which includes social identity providers) with 'B2B collaboration' (which is for guest users from other organizations), leading them to select B2B collaboration incorrectly.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra B2B collaboration is specifically for inviting external business partners (guests) from other Azure AD tenants or email domains, not for federating with social identity providers like Google or Facebook. Option C is wrong because managed identities are used to provide Azure resources with an automatically managed identity in Azure AD for authenticating to other Azure services, not for external user sign-in. Option D is wrong because Microsoft Entra Identity Protection is a risk-based security tool that detects and responds to identity threats, not a federation solution for social identity providers.

328
MCQmedium

A company has a Microsoft 365 E5 subscription. The security team requires that all guest users must have terms of use acceptance before accessing resources. Which Azure AD feature should be configured?

A.Azure AD Terms of Use
B.Conditional Access policy
C.Azure AD Identity Protection
D.Self-service password reset
AnswerA

Azure AD Terms of Use (now part of Microsoft Entra ID) is the correct feature because it lets an organization create a customizable legal document and require specific users or groups to accept it before accessing a resource. You author the ToU in the Entra admin center under Protection > Conditional Access > Terms of use, and the service tracks each user's acceptance, including the version accepted and the timestamp. Acceptance can then be enforced via a Conditional Access policy, but the ToU itself is a separate configuration object that independently fulfills the requirement to have terms users must accept.

Why this answer

Azure AD Terms of Use (ToU) is the correct feature because it allows administrators to present a document to guest users that they must accept before accessing resources. This directly meets the security team's requirement for mandatory terms of use acceptance. Conditional Access policies can enforce ToU acceptance, but the ToU document itself is created and managed under the Azure AD Terms of Use blade.

Exam trap

The trap here is that candidates often confuse the 'Terms of Use' feature with 'Conditional Access policies' because Conditional Access is the enforcement mechanism, but the question specifically asks which feature should be configured to have the terms of use document itself, not the policy that enforces it.

How to eliminate wrong answers

Option B (Conditional Access policy) is wrong because while a Conditional Access policy can enforce the requirement to accept Terms of Use, it is not the feature that creates or hosts the terms of use document; the Terms of Use feature is the prerequisite. Option C (Azure AD Identity Protection) is wrong because it is designed to detect and respond to identity-based risks (e.g., leaked credentials, sign-ins from anonymous IPs), not to enforce terms of use acceptance. Option D (Self-service password reset) is wrong because it allows users to reset their own passwords and does not involve presenting or accepting terms of use.

329
Multi-Selecthard

Your organization uses Microsoft Entra ID and has a hybrid identity configuration with Active Directory Federation Services (AD FS). You are migrating to cloud authentication using Pass-through Authentication (PTA). Which TWO components are required for a PTA deployment?

Select 2 answers
A.Service Bus endpoints in Azure
B.Password Hash Synchronization agent
C.Azure AD Connect Health agent
D.Seamless Single Sign-On
E.Pass-through Authentication Agent
AnswersA, E

The Pass-through Authentication (PTA) Agent does not directly receive authentication requests from Azure AD over an inbound connection. Instead, it establishes an outbound connection to Azure Service Bus endpoints, and Azure AD delivers password validation requests to the agent through this Service Bus relay. Without these endpoints being reachable, the PTA agent cannot receive or respond to authentication requests, so Service Bus endpoints are an essential part of the PTA architecture.

Why this answer

Pass-through Authentication (PTA) requires the PTA Agent to be installed on-premises to validate user passwords against Active Directory. It also uses Azure Service Bus endpoints to establish a secure, persistent connection between the on-premises agent and Microsoft Entra ID, enabling authentication requests to flow without storing passwords in the cloud.

Exam trap

The trap here is that candidates often confuse the required components for PTA with those for PHS or Seamless SSO, mistakenly including the Password Hash Synchronization agent or Seamless SSO as mandatory for PTA.

330
MCQeasy

Your company is implementing Microsoft Purview Audit (Standard). You need to search for activities performed by a specific user in Exchange Online. Which log should you query?

A.Unified audit log.
B.DLP incident reports.
C.Azure AD audit logs.
D.Mailbox audit logs only.
AnswerA

Purview Audit (Standard) writes Exchange Online activities to the unified audit log, which is the only searchable repository for user-level events in Microsoft 365. Querying it satisfies the requirement to find activities performed by a specific user, since mailbox audit records surface there rather than in transport or IIS logs.

Why this answer

Microsoft Purview Audit (Standard) stores all audit events — including Exchange Online user activities — in the Unified audit log, which is queried via the Microsoft Purview compliance portal or the Search-UnifiedAuditLog PowerShell cmdlet. To find activities performed by a specific user in Exchange Online, you search the Unified audit log and filter by the user's UPN and the relevant Exchange workloads/activities. This is the single centralized log for Purview Audit (Standard) across Microsoft 365 services.

Exam trap

MS-102 often tests the misconception that mailbox audit logs and the Unified audit log are separate query targets in Purview Audit (Standard) — in fact, Exchange Online activities are surfaced through the Unified audit log, and 'mailbox audit logs only' is a distractor that misrepresents the architecture.

How to eliminate wrong answers

Option B (DLP incident reports) is wrong because DLP incident reports only surface data-loss-prevention policy matches, not general user activity auditing. Option C (Azure AD audit logs) is wrong because Azure AD (Entra ID) audit logs capture identity and directory events (sign-ins, role changes, app consents), not Exchange Online mailbox activities. Option D (Mailbox audit logs only) is wrong because mailbox audit logs are the legacy per-mailbox auditing mechanism; in Purview Audit (Standard), mailbox activities are surfaced through the Unified audit log, and 'only' makes the option incorrect as a query target.

331
Matchingmedium

Match each Microsoft 365 compliance feature to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Prevents sensitive data from being shared

Searches and exports content for legal cases

Keeps or deletes content based on rules

Classifies and protects data

Records user and admin activities

Why these pairings

Correct matches: DLP prevents accidental sharing, eDiscovery searches for legal needs, and Sensitivity Labels classify/protect data. Common confusions include mixing DLP with retention policies and eDiscovery with automatic classification.

332
MCQhard

Your organization has deployed Microsoft Defender for Cloud Apps. You need to ensure that all external file sharing to untrusted domains is automatically blocked. The solution must not affect internal sharing. What should you configure?

A.Create an access policy in Microsoft Defender for Cloud Apps to block access from untrusted domains.
B.Create a file policy in Microsoft Defender for Cloud Apps with a governance action to remove external users.
C.Configure an app connector for the cloud app to enforce DLP policies.
D.Create a session policy in Microsoft Defender for Cloud Apps to monitor external sharing.
AnswerB

A file policy in Defender for Cloud Apps scans cloud app repositories for content, exposure, and sharing metadata, and can automatically apply governance actions when conditions are met. By configuring a condition that flags files shared with external domains or unauthorized collaborators, you can select the governance action "Remove external users" to directly strip external principals from the file's access control list (ACL). This is the appropriate mechanism because it is data-centric, works on both existing and new shares, and does not rely on user or session behavior.

Why this answer

A file policy in Microsoft Defender for Cloud Apps can be configured with a governance action to remove external users from shared files when sharing is detected with untrusted domains. This action automatically blocks external sharing without affecting internal sharing, as it targets only external collaborators from domains not on the trusted list.

Exam trap

The trap here is that candidates confuse access policies (which block user access to the app) with file policies (which govern sharing actions on files), leading them to select Option A instead of the correct file policy governance action.

How to eliminate wrong answers

Option A is wrong because access policies in Defender for Cloud Apps control real-time access based on user or device context, not file-sharing actions; they block access to the app itself, not external sharing events. Option C is wrong because configuring an app connector enables monitoring and control of a cloud app but does not by itself enforce DLP policies or block external sharing; it is a prerequisite for policies, not the policy itself. Option D is wrong because session policies monitor and control user sessions in real time (e.g., preventing download or copy), but they do not automatically block external file sharing to untrusted domains; they are designed for conditional access app control, not file governance.

333
MCQhard

Your organization has a hybrid identity setup with Azure AD Connect. You need to ensure that users can reset their passwords from the cloud and have the changes synchronized back to on-premises Active Directory. Which feature must you enable?

A.Password writeback.
B.Seamless single sign-on.
C.Pass-through authentication.
D.Password hash synchronization.
AnswerA

Password writeback is the only option that supports a bidirectional password flow: when a user performs a self-service password reset or changes their password in Azure AD, Azure AD Connect writes the new password back to the on-premises Active Directory. This requires Azure AD Premium licensing and must be explicitly enabled in Azure AD Connect, making it the correct feature for a hybrid identity organization that needs cloud-originated password changes reflected on-premises.

Why this answer

Password writeback is the Azure AD Connect feature that enables password changes performed in the cloud (e.g., via Azure AD SSPR) to be written back to on-premises Active Directory. This ensures the on-premises password stays synchronized with the cloud, which is required for hybrid identity scenarios where users reset passwords from the cloud.

Exam trap

The trap here is that candidates often confuse password hash synchronization (which only syncs one-way) with password writeback (which enables cloud-to-on-premises password changes), leading them to select password hash synchronization as the answer.

How to eliminate wrong answers

Option B (Seamless single sign-on) is wrong because it provides automatic sign-in for domain-joined devices on the corporate network, not password synchronization or writeback. Option C (Pass-through authentication) is wrong because it validates passwords directly against on-premises AD without storing password hashes in the cloud, and it does not support writing password changes back to on-premises AD. Option D (Password hash synchronization) is wrong because it only synchronizes password hashes from on-premises to Azure AD; it does not write password changes from the cloud back to on-premises AD.

334
Multi-Selecthard

You are designing a Microsoft Entra ID governance strategy. Which THREE features should you use to implement the principle of least privilege for administrative roles?

Select 3 answers
A.Microsoft Entra Lifecycle Workflows
B.Privileged Access Groups
C.Microsoft Entra Entitlement Management
D.Microsoft Entra Privileged Identity Management (PIM)
E.Microsoft Entra Access Reviews
AnswersB, D, E

Privileged Access Groups (PAG) are role-assignable Microsoft Entra ID groups that can be mapped to Azure AD roles, allowing group membership to control role eligibility. When PIM is enabled for these groups, admins receive just-in-time, time-bound activation, and dynamic membership rules can be used to add or remove users automatically based on attributes or lifecycle events. This combination makes PAG a modern, correct approach for admin role governance.

Why this answer

Privileged Access Groups (B) enable you to grant just-in-time or time-bound access to Azure AD roles and other resources by assigning users to a group that is eligible for role activation, directly supporting the principle of least privilege by limiting standing administrative access.

Exam trap

The trap here is that candidates often confuse Entitlement Management (which handles access packages for end users) with Privileged Access Groups (which specifically control administrative role activation), leading them to select Option C instead of B.

335
MCQmedium

Refer to the exhibit. You have a Conditional Access policy as shown. The exhibit shows the policy is in Report-only mode and that Microsoft Azure Management is included as the target cloud app. A Global Administrator reports that they are not prompted for MFA when accessing the Azure portal. Which is the most likely reason?

A.The Global Administrator role is not included in the policy.
B.The user is accessing from a trusted IP address.
C.The policy does not include the Azure portal as a target cloud app.
D.The policy is in Report-only mode.
AnswerD

Report-only mode evaluates the policy and logs its outcome without enforcing controls, so sign-ins proceed without an MFA prompt. The Global Administrator's experience confirms the policy is not yet switched to On, which is the enforcement state required to challenge users.

Why this answer

The policy is set to 'Report-only' mode, which means it evaluates sign-ins and logs results but does not enforce any controls like MFA. Even though the policy targets Microsoft Azure Management (which includes the Azure portal), the enforcement mode must be 'On' to require MFA. Since it is in Report-only mode, the Global Administrator is not prompted for MFA.

Exam trap

The trap is that candidates might assume that as long as a Conditional Access policy includes the correct cloud app (Microsoft Azure Management), it will enforce MFA. However, if the policy is in Report-only mode, it does not enforce any controls, regardless of the app targeting.

How to eliminate wrong answers

Option A is wrong because the policy targets 'All users', which includes Global Administrators; the role itself does not need to be listed separately. Option B is wrong because the exhibit shows no trusted IP address exclusion is configured; the policy applies to all locations. Option D is wrong because the exhibit shows the policy is set to 'On' (enabled), not 'Report-only' mode.

336
MCQeasy

Your organization needs to create a custom domain in Microsoft 365. You have added the domain 'contoso.com' to the tenant. What is the next step to verify domain ownership?

A.Create user accounts with the custom domain.
B.Configure the email exchange (MX) record.
C.Assign licenses to users with the custom domain.
D.Add a TXT record to the public DNS zone.
AnswerD

The correct approach is to add a TXT record to the public DNS zone. Microsoft provides a unique TXT value in the domain verification wizard, and placing it in your DNS zone demonstrates that you control the domain's DNS namespace. Once the TXT record propagates and Microsoft queries it successfully, the domain is marked verified, allowing subsequent configuration steps like setting up MX records and creating users.

Why this answer

After adding a custom domain to a Microsoft 365 tenant, the next mandatory step is to prove ownership of the domain by adding a specific TXT record provided by Microsoft to the domain's public DNS zone. Microsoft queries this TXT record to verify that you control the domain before allowing you to use it for services like email or user accounts. This verification step is required by Microsoft's domain onboarding process and must succeed before any other configuration can proceed.

Exam trap

The trap here is that candidates often confuse domain verification (TXT record) with domain configuration (MX record), mistakenly thinking that setting up email routing is the immediate next step after adding the domain.

How to eliminate wrong answers

Option A is wrong because creating user accounts with the custom domain requires the domain to be verified first; attempting to assign a non-verified domain to users will fail. Option B is wrong because configuring the MX record is part of setting up email routing after domain verification, not a step to prove ownership. Option C is wrong because assigning licenses to users with the custom domain also depends on the domain being verified; licenses cannot be applied to unverified domains.

337
MCQmedium

You are reviewing an ARM template that will be used to deploy a storage account for a Microsoft 365 migration project. The template includes 'supportsHttpsTrafficOnly': true. What is the primary benefit of this setting?

A.It enforces secure transfer (HTTPS) for all requests to the storage account.
B.It reduces latency by enabling CDN integration.
C.It enables geo-redundant storage.
D.It minimizes storage costs by reducing bandwidth usage.
AnswerA

The supportsHttpsTrafficOnly property (also known as enableHttpsTrafficOnly in ARM templates) blocks any HTTP request to the storage account, forcing clients to use TLS/HTTPS for all read, write, and management operations. This prevents data from being transmitted in cleartext, meeting security and compliance requirements such as PCI DSS and HIPAA. Without this flag, a misconfigured client could silently fall back to HTTP, exposing account keys and data in transit.

Why this answer

Setting 'supportsHttpsTrafficOnly' to true enforces secure transfer by requiring all requests to the storage account to use HTTPS (TLS). This ensures data in transit is encrypted, protecting against man-in-the-middle attacks and eavesdropping. It is a critical security control for compliance with standards like PCI-DSS and HIPAA.

Exam trap

The trap here is that candidates may confuse 'supportsHttpsTrafficOnly' with performance or redundancy features, but it is purely a security control for enforcing encrypted transport.

How to eliminate wrong answers

Option B is wrong because enabling HTTPS-only does not reduce latency or enable CDN integration; CDN integration is configured separately via Azure CDN profiles. Option C is wrong because geo-redundant storage (GRS) is controlled by the 'sku.name' property (e.g., Standard_GRS), not by the HTTPS setting. Option D is wrong because HTTPS-only does not minimize storage costs; bandwidth usage is unaffected by the protocol, and HTTPS may add slight overhead due to TLS handshake.

338
MCQmedium

Refer to the exhibit. You run the PowerShell command shown. The output shows no results. The user confirms they downloaded files from SharePoint last week. What is the most likely cause?

A.The UserIds parameter is misspelled.
B.The RecordType parameter is incorrect.
C.Audit logging is not enabled for the user.
D.The Operations parameter is incorrect.
AnswerC

The unified audit log contains no eligible events for this search if audit logging is not enabled for the user, even when every command parameter is correct. In Microsoft 365, user activities such as FileDownloaded are published to the audit log only when auditing is enabled at the tenant level and the user has the required license. Because the command itself is valid, the empty output indicates that audit events were never generated for this user, not that the syntax is flawed.

Why this answer

The PowerShell command shown is likely Search-UnifiedAuditLog, which queries the unified audit log. If the output is empty despite the user having downloaded files from SharePoint, the most likely cause is that audit logging (specifically, mailbox or SharePoint audit logging) is not enabled for that user or workload. Without audit logging turned on, no events are recorded, so the search returns nothing.

Exam trap

The trap is assuming that an empty audit log search means no activity occurred, when it often means audit logging was never enabled or the events have not yet been ingested.

How to eliminate wrong answers

Option A is wrong because a misspelled UserIds parameter would typically cause a syntax error or an error message, not a silent empty result, and the user ID is usually valid. Option B is wrong because RecordType for SharePoint file downloads would be SharePointFileOperation, and if it were incorrect, the command might return other record types or an error, but the scenario implies no results at all. Option D is wrong because an incorrect Operations parameter would filter out events, but the more fundamental issue is that no events exist because auditing is disabled.

339
MCQmedium

Your organization uses Microsoft Purview Records Management and has a file plan that categorizes records by department. You need to ensure that HR records are retained for seven years after employee termination, while finance records are retained for ten years after the end of the fiscal year. What is the most efficient way to implement this?

A.Create a single retention label with a trigger event and adjust the retention period using PowerShell.
B.Create two retention labels: one for HR with termination trigger and seven-year retention, and one for Finance with end-of-fiscal-year trigger and ten-year retention.
C.Define the retention settings in the file plan and apply them to both departments.
D.Create two retention policies, one for HR and one for Finance, each with the appropriate retention period.
AnswerB

Retention labels support event-based triggers, letting HR use a termination trigger and Finance an end-of-fiscal-year trigger, each with its own retention period. Two labels satisfy both departmental rules within one file plan, avoiding separate policies per department.

Why this answer

Retention labels in Microsoft Purview Records Management support event-based retention triggers, and each label can have its own retention period and trigger type. Creating one label for HR with a termination trigger and seven-year retention, and another for Finance with an end-of-fiscal-year trigger and ten-year retention, directly maps to the two distinct business requirements. Labels are the correct construct for file-plan-based records management because they can be published to specific locations and applied per-item.

Exam trap

MS-102 often tests the distinction between retention policies (location-wide, no event triggers) and retention labels (item-level, support event-based triggers) — candidates pick policies because they sound simpler, missing that event-based retention requires labels.

How to eliminate wrong answers

Option A is wrong because a single retention label cannot have two different trigger events and two different retention periods — a label has one retention configuration, so this cannot satisfy both HR and Finance requirements. Option C is wrong because the file plan is a container for organizing labels, not a place to define per-department retention settings; retention settings live on the labels themselves. Option D is wrong because retention policies apply uniformly to a location (e.g., all Exchange mailboxes) and do not support event-based triggers like employee termination or end-of-fiscal-year — those triggers require retention labels, not policies.

340
MCQeasy

Your organization needs to ensure that all emails containing credit card numbers are automatically encrypted before being sent to external recipients. Which Microsoft Purview solution should you configure?

A.Configure a DLP policy that uses the 'Encrypt email messages' action.
B.Create a sensitivity label that applies encryption and auto-labeling.
C.Set up a retention policy with encryption.
D.Implement a Communication Compliance policy.
AnswerA

DLP policies in Microsoft Purview can be configured with the action 'Encrypt email messages' to automatically apply IRM (Azure RMS) protection to any outbound email that matches a sensitive info type condition. This action uses the built-in encryption template and does not require a separate label to be defined. When an email triggers a DLP rule, the message is encrypted in transit and at rest, enforcing access controls before delivery.

Why this answer

A Microsoft Purview DLP policy can detect sensitive information types like credit card numbers (via the Credit Card Number SIT) and apply the 'Encrypt email messages' action, which uses Office 365 Message Encryption (OME) to encrypt the email before it leaves the organization. This directly satisfies the requirement to automatically encrypt emails containing credit card numbers sent to external recipients. DLP policies are evaluated at send time and can enforce encryption without user intervention.

Exam trap

MS-102 often tests the distinction between DLP and sensitivity labels; candidates pick sensitivity labels because they also encrypt, but DLP is the correct tool for automatic, content-based encryption of emails containing specific sensitive data.

How to eliminate wrong answers

Option B is wrong because sensitivity labels with auto-labeling can apply encryption, but they are primarily designed for classification and protection of content at rest and in transit; they do not automatically trigger based on sensitive content detection in the same way DLP does, and auto-labeling for email encryption based on SITs is less direct than a DLP rule. Option C is wrong because retention policies govern data lifecycle and deletion, not encryption. Option D is wrong because Communication Compliance policies are for detecting and reviewing inappropriate or risky communications (e.g., harassment, regulatory violations) and do not encrypt emails.

341
MCQmedium

A company must ensure that all outgoing emails containing credit card numbers are blocked from being sent to external recipients. When a user attempts to send such an email, it should be blocked immediately, and the user should see a policy tip explaining the rule. Which Microsoft Purview solution should the administrator configure?

A.Data Loss Prevention (DLP) policy
B.Sensitivity labels
C.Retention labels
D.Communication compliance
AnswerA

DLP policies inspect outbound email content in Exchange Online and block messages containing sensitive data such as credit card numbers, satisfying the immediate-blocking requirement. Policy tips display in Outlook, giving the sender the required explanation of why the message was stopped.

Why this answer

A Data Loss Prevention (DLP) policy is the correct solution because it is specifically designed to detect sensitive information, such as credit card numbers, in transit (email) and enforce real-time actions like blocking the message and displaying a policy tip to the user. DLP policies in Microsoft Purview can be configured with conditions that match credit card number patterns using built-in sensitive info types, and the action 'Block messages' with a policy tip notification is available for Exchange Online mail flow. This ensures immediate blocking and user notification without requiring any manual labeling or classification.

Exam trap

The trap here is that candidates often confuse sensitivity labels with DLP because both involve 'protection,' but sensitivity labels require manual or automatic classification and do not perform real-time content inspection or blocking of outbound emails based on sensitive data patterns.

How to eliminate wrong answers

Option B is wrong because sensitivity labels are used to classify and protect data at rest (e.g., documents and emails) by applying encryption or visual markings, but they do not natively detect credit card numbers in real-time during email transmission or enforce blocking with policy tips. Option C is wrong because retention labels are designed to manage data lifecycle and retention policies (e.g., how long to keep or delete data), not to inspect email content for sensitive information or block outbound messages. Option D is wrong because communication compliance is focused on monitoring and reviewing internal and external communications for policy violations (e.g., harassment or insider trading), but it does not provide real-time blocking of emails based on sensitive data patterns or display policy tips to users.

342
MCQmedium

Your organization, Contoso, has a Microsoft Entra ID tenant with 50,000 users. You are implementing a zero-trust security model. The following requirements must be met: 1) All access to SaaS applications must be restricted based on user, device, and location. 2) Users accessing from unmanaged devices must only be allowed browser-based access and must accept terms of use. 3) The IT team must be able to grant temporary access to the Global Administrator role for up to 8 hours. 4) All external users must have their access reviewed every 6 months. Which combination of Microsoft Entra features should you use?

A.Conditional access policies, entitlement management, Privileged Identity Management (PIM), and access reviews
B.Conditional access policies, Privileged Identity Management (PIM), access reviews, and terms of use
C.Conditional access policies, Microsoft Entra B2B, Privileged Identity Management (PIM), and access reviews
D.Conditional access policies, Identity Protection user risk policy, Privileged Identity Management (PIM), and access reviews
AnswerB

This combination fully meets the requirement: conditional access policies enforce device, location, and browser restrictions; terms of use require explicit consent from users on unmanaged devices before access is granted; PIM provides time-bound, just-in-time activation of administrative roles; and access reviews periodically recertify external and internal user access. Each component addresses a distinct control, and together they ensure both secure conditional access and ongoing governance.

Why this answer

It combines Conditional Access policies to enforce user, device, and location restrictions; Terms of Use to require acceptance for browser-based access from unmanaged devices; Privileged Identity Management (PIM) to grant time-limited Global Administrator access for up to 8 hours; and Access Reviews to ensure external users are reviewed every 6 months. This set directly addresses all four requirements without introducing unnecessary or conflicting features.

Exam trap

The trap here is that candidates often confuse Entitlement Management or B2B with the Terms of Use feature, but Terms of Use is a distinct Conditional Access grant control specifically designed to require user acceptance before accessing applications, which is essential for the unmanaged device browser-access requirement.

How to eliminate wrong answers

Option A is wrong because it includes Entitlement Management, which is used for managing resource access packages and guest user lifecycle, but it does not provide the Terms of Use functionality required for unmanaged device browser access. Option C is wrong because it includes Microsoft Entra B2B, which is for inviting external users and managing their identities, but it does not enforce Terms of Use acceptance for unmanaged devices; the requirement for browser-based access with Terms of Use is specifically met by the Terms of Use feature, not B2B. Option D is wrong because it includes Identity Protection user risk policy, which focuses on detecting and responding to risky user behavior (e.g., leaked credentials), but it does not enforce Terms of Use acceptance for unmanaged devices, which is a distinct requirement.

343
MCQmedium

A company wants to require that all users accessing a critical cloud application for the first time must accept a company terms of use before they are granted access. Which Conditional Access policy grant control should be added?

A.Require multi-factor authentication
B.Require device to be marked as compliant
C.Require terms of use
D.Require approved client app
AnswerC

The 'Require terms of use' grant control in Azure AD Conditional Access is the only listed option that directly presents a designated Azure AD Terms of Use document to the user at sign-in and requires an explicit Accept action before the session proceeds. Once the user accepts, Azure AD records the acceptance, and the conditional access policy can require reacceptance based on expiration or frequency. This matches the stated requirement precisely because access is gated on the user's affirmative acknowledgement of the terms.

Why this answer

The 'Require terms of use' grant control in a Conditional Access policy is specifically designed to force a user to accept a company's terms of use (TOU) before accessing a cloud application. When this control is enabled, Microsoft Entra ID presents the TOU document to the user on first access, and access is blocked until the user explicitly accepts the terms. This directly meets the requirement of requiring acceptance before granting access.

Exam trap

The trap here is that candidates often confuse 'terms of use' with a general compliance or security requirement, leading them to select 'Require device to be marked as compliant' (Option B) because they think device compliance implies policy acceptance, but Conditional Access grant controls are distinct and the terms of use control is the only one that enforces a user-facing acceptance workflow.

How to eliminate wrong answers

Option A is wrong because Require multi-factor authentication (MFA) enforces an additional authentication factor, not a legal or policy acceptance step; it does not present or require acceptance of a terms of use document. Option B is wrong because Require device to be marked as compliant checks device health and compliance status (e.g., via Intune or MDM), but does not involve any user-facing terms acceptance workflow. Option D is wrong because Require approved client app restricts access to specific client applications (e.g., Microsoft Outlook or Teams), but has no mechanism to display or enforce a terms of use acceptance.

344
MCQeasy

Your organization is planning to deploy Microsoft 365 Copilot. You need to ensure that all prerequisites are met. Which of the following is a mandatory prerequisite for enabling Microsoft 365 Copilot?

A.Microsoft Purview Data Loss Prevention policies.
B.Microsoft Entra ID P2 licenses.
C.An active Azure subscription.
D.Exchange Online Plan 2 licenses.
AnswerB

Microsoft Entra ID P2 licenses are not mandatory. While Copilot uses Entra ID for identity, only the free tier or P1 is sufficient. P2 is not a requirement.

Why this answer

None of the listed options are mandatory prerequisites for Microsoft 365 Copilot. The actual mandatory requirements are a qualifying Microsoft 365 license (E3, E5, or Business Premium) and the Microsoft 365 Copilot add-on license. Microsoft Entra ID P2 is not required; a basic Entra ID (free) is sufficient.

Purview DLP, an Azure subscription, and Exchange Online Plan 2 are also not mandatory.

Exam trap

The trap here is that candidates might assume Microsoft Entra ID P2 is required because Copilot relies on identity and security features, but in reality, a standard Entra ID (free) is sufficient. The actual mandatory prerequisites are a qualifying Microsoft 365 license and the Copilot add-on.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Loss Prevention policies are not a prerequisite for enabling Copilot; they are an optional compliance feature that can be applied after deployment to control data sharing. Option C is wrong because an active Azure subscription is not required for Microsoft 365 Copilot, which is a SaaS add-on to Microsoft 365 and does not depend on Azure infrastructure for its core functionality. Option D is wrong because Exchange Online Plan 2 licenses are not mandatory; Copilot works with Exchange Online Plan 1 or other mail-enabled plans as long as the user has a valid Microsoft 365 license that includes Exchange Online.

345
MCQhard

A security analyst is investigating a suspected credential theft attack where an attacker attempts to dump credentials from LSASS. Which Attack Surface Reduction (ASR) rule should the administrator enable to block this activity from untrusted processes?

A.Block credential stealing from the Windows local security authority subsystem (lsass.exe)
B.Block Office applications from creating child processes
C.Block executable files from running unless they meet a prevalence, age, or trusted list criterion
D.Block Adobe Reader from creating child processes
AnswerA

This Attack Surface Reduction rule is specifically engineered to prevent untrusted processes from reading the memory space of lsass.exe, the Windows Local Security Authority Subsystem. By blocking read access to LSASS, it directly thwarts credential-dumping techniques used by tools such as Mimikatz, which rely on extracting password hashes or plaintext credentials from that process's memory. This makes it the most targeted and effective rule for the described credential theft scenario.

Why this answer

The ASR rule 'Block credential stealing from the Windows local security authority subsystem (lsass.exe)' (GUID: 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2) is specifically designed to prevent untrusted processes from accessing LSASS memory and dumping credentials, such as with tools like Mimikatz. This directly addresses the described attack scenario of credential theft from LSASS, making it the correct choice.

Exam trap

The trap here is that candidates may confuse generic credential theft prevention rules (like Windows Defender Credential Guard) with ASR rules, or mistakenly think that blocking child processes (Option B or D) would stop LSASS dumping, when in fact the attack often involves a direct process handle to lsass.exe rather than spawning a child process.

How to eliminate wrong answers

Option B is wrong because 'Block Office applications from creating child processes' prevents Office apps (e.g., Word, Excel) from spawning child processes like PowerShell or cmd.exe, which is a common technique for lateral movement or payload execution, not specifically for dumping credentials from LSASS. Option C is wrong because 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' is a cloud-delivered protection rule that restricts unknown executables based on reputation, not a targeted ASR rule for LSASS credential theft. Option D is wrong because 'Block Adobe Reader from creating child processes' prevents Adobe Reader from launching other executables, which is a defense against PDF-based exploits, not a rule designed to block credential dumping from LSASS.

346
MCQmedium

An admin needs to bulk assign licenses to 200 users based on department. Which method is most efficient?

A.Use Azure AD PowerShell script
B.Use Azure admin center bulk operations
C.Use group-based licensing in Azure AD
D.Assign licenses one by one in admin center
AnswerC

Group-based licensing in Azure AD is the correct, scalable approach: you create or select a security group, assign the appropriate license SKUs to that group, and Azure automatically assigns the licenses to every member of the group—and to any users added later. This declarative method eliminates the need for per-user scripting or manual clicks, and it also auto-removes licenses when users leave the group, keeping license allocation aligned with membership. For 200 users, you simply add them to the group and Azure handles the rest, making it the most efficient and maintainable solution.

Why this answer

Group-based licensing in Azure AD is the most efficient method for bulk-assigning licenses to 200 users based on department because it automates license assignment and removal based on group membership. Once a user is added to or removed from a department-specific group, Azure AD automatically applies or revokes the corresponding license, eliminating manual intervention and ensuring consistency across large-scale deployments.

Exam trap

The trap here is that candidates often choose PowerShell (Option A) because they assume scripting is always the most efficient for bulk operations, but they overlook that group-based licensing is a fully automated, policy-driven solution that requires no ongoing script execution or manual triggers.

How to eliminate wrong answers

Option A is wrong because using an Azure AD PowerShell script, while automated, requires manual execution, maintenance, and error handling for 200 users, making it less efficient than a fully managed, policy-driven approach like group-based licensing. Option B is wrong because the Azure admin center bulk operations (e.g., CSV upload) are a one-time manual process that does not scale well for ongoing changes in department membership or license requirements. Option D is wrong because assigning licenses one by one in the admin center is highly inefficient and error-prone for 200 users, violating the principle of least effort and automation for bulk tasks.

347
MCQhard

A security administrator is configuring Microsoft Defender for Office 365 to protect against zero-day malware in attachments. The administrator wants to use dynamic delivery so that users can view the email body while the attachment is being analyzed. However, the administrator is concerned about false positives and wants to ensure that if a benign attachment is later found to be malicious, it is removed from the user's inbox. What should the administrator configure?

A.Configure a Safe Attachments policy with dynamic delivery and enable ZAP.
B.Configure a Safe Links policy with URL detonation.
C.Configure an anti-phishing policy with mailbox intelligence.
D.Configure an anti-malware policy with common attachments filter.
AnswerA

A Safe Attachments policy with dynamic delivery exposes the attachment to Microsoft's sandbox detonation environment while the message is delivered to the user's mailbox; a placeholder is used until the verdict is clean and the real attachment becomes available. Enabling zero-hour auto purge (ZAP) adds retroactive remediation so that if the system later identifies the message as malicious, it is automatically removed from the mailbox. This combination fulfills the requirement for both low-latency attachment delivery and post-delivery protection.

Why this answer

Safe Attachments policies with dynamic delivery allow users to view the email body while the attachment is being detonated in a sandbox. Zero-Hour Auto Purge (ZAP) then retroactively removes messages from the user’s inbox if a previously deemed benign attachment is later identified as malicious, addressing the false-positive concern.

Exam trap

The trap here is that candidates confuse Safe Attachments dynamic delivery with Safe Links URL detonation, or assume that anti-malware policies alone can retroactively remove malicious attachments, missing the critical ZAP integration for post-delivery remediation.

How to eliminate wrong answers

Option B is wrong because Safe Links policies protect against malicious URLs, not attachments, and URL detonation does not handle attachment analysis or post-delivery removal. Option C is wrong because anti-phishing policies with mailbox intelligence focus on impersonation and phishing detection, not attachment scanning or zero-day malware. Option D is wrong because an anti-malware policy with common attachments filter only blocks predefined file types (e.g., .exe, .scr) and does not provide dynamic delivery or retroactive removal via ZAP.

348
MCQmedium

A compliance officer needs to prevent users from sharing confidential documents with external users outside the organization. The policy should block sharing via email attachments or sharing links from SharePoint Online. Which Microsoft Purview solution should be configured?

A.Sensitivity labels
B.Data Loss Prevention (DLP)
C.Retention policies
D.Information barriers
AnswerB

DLP policies are the correct technical control because they can identify sensitive information in messages and files and automatically block specific actions such as sending an external email or creating an external sharing link in SharePoint and OneDrive. When a rule is triggered, DLP can block the activity outright, show a policy tip, or require a user to justify an override, giving compliance officers a real-time enforcement mechanism. DLP works across Exchange, SharePoint, OneDrive, Teams, and endpoints, making it the only option listed that explicitly prevents the sharing of sensitive content.

Why this answer

Data Loss Prevention (DLP) in Microsoft Purview is designed to identify, monitor, and automatically protect sensitive information across Exchange Online, SharePoint Online, and OneDrive for Business. By creating a DLP policy with a rule that blocks sharing of confidential documents via email attachments or sharing links to external users, the compliance officer can enforce the required restriction. DLP policies can inspect content for sensitive data types (e.g., credit card numbers, custom confidential labels) and apply actions such as blocking the sharing action or sending a notification.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which apply protection) with DLP policies (which enforce actions like blocking), leading them to choose Option A, but labels alone cannot block sharing; they require a DLP policy to enforce the block action.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are used to classify and protect data by applying encryption, markings, or access restrictions, but they do not natively block sharing actions based on external user detection; DLP policies are required to enforce such blocking rules. Option C is wrong because retention policies are designed to preserve or delete content after a specified period, not to prevent real-time sharing of documents with external users. Option D is wrong because information barriers restrict communication and collaboration between specific internal groups or users (e.g., to avoid conflicts of interest), but they do not block sharing with external users outside the organization.

349
MCQmedium

A company uses Microsoft Entra ID P2 licenses. They want to block all authentication attempts from an internal app that uses legacy authentication protocols (POP3, IMAP, SMTP) because these protocols cannot enforce multi-factor authentication. Which Conditional Access policy setting should be used?

A.Grant access requiring multi-factor authentication
B.Block access for apps using legacy authentication
C.Require compliant device
D.Require approved client app
AnswerB

In a Conditional Access policy, the 'Client apps' condition includes 'Exchange ActiveSync clients' and 'Other clients'. Selecting these options explicitly targets protocols such as POP3, IMAP4, SMTP, and Exchange Web Services that rely on basic authentication instead of modern authentication. This blocks legacy authentication traffic while still allowing modern, MFA-capable clients, and it is the recommended way to enforce Microsoft's 'block legacy authentication' policy.

Why this answer

The scenario explicitly requires blocking authentication attempts from an internal app using legacy protocols (POP3, IMAP, SMTP) that cannot enforce multi-factor authentication. The 'Block access for apps using legacy authentication' Conditional Access setting targets client apps that use legacy authentication protocols, effectively preventing any authentication from those apps regardless of user or device compliance.

Exam trap

The trap here is that candidates often confuse 'Require MFA' (which still allows legacy apps to attempt authentication and fail silently) with 'Block legacy authentication' (which explicitly prevents the authentication attempt at the protocol level), leading them to choose Option A instead of B.

How to eliminate wrong answers

Option A is wrong because 'Grant access requiring multi-factor authentication' would still allow the legacy app to attempt authentication; legacy protocols cannot pass MFA claims, so the policy would either fail or be bypassed, not block the attempt. Option C is wrong because 'Require compliant device' only checks device health (e.g., Intune compliance) and does not address the protocol-level vulnerability of legacy authentication; the app could still authenticate from a compliant device using POP3/SMTP without MFA. Option D is wrong because 'Require approved client app' enforces the use of specific modern authentication apps (e.g., Microsoft Authenticator) but does not block legacy protocols; an approved client app could still use legacy authentication if not explicitly restricted.

350
MCQeasy

Your organization wants to use Microsoft Intune to manage devices. You need to ensure that only corporate-owned devices can enroll. What configuration should you use?

A.Use a conditional access policy to require device compliance.
B.Configure enrollment restrictions to block personally owned devices.
C.Set a compliance policy requiring devices to be marked as corporate.
D.Create a device type restriction for iOS and Android.
AnswerB

Enrollment restrictions in Microsoft Intune are administrative policies that govern the actual enrollment action, and they include an ownership-type setting. By configuring the 'Allow personally owned devices' restriction to 'Block' under the default or custom enrollment restriction, Intune will reject enrollment attempts from devices that are not marked as corporate-owned, while still permitting corporate-owned devices enrolled via methods such as Apple Business Manager or Windows Autopilot. This is the correct approach because it directly prevents the enrollment of personal devices without affecting corporate-enrolled assets.

Why this answer

Enrollment restrictions in Microsoft Intune allow you to block personally owned devices by setting the 'Allow personally owned devices' option to 'No' for the platform. This ensures that only corporate-owned devices, which are identified by their corporate enrollment token or IMEI/MEID numbers, can enroll. This is the direct and intended method to restrict enrollment to corporate-owned devices only.

Exam trap

The trap here is that candidates often confuse post-enrollment controls (like compliance policies or conditional access) with pre-enrollment restrictions, mistakenly thinking that requiring compliance or marking devices as corporate can block personal devices from enrolling, when in fact only enrollment restrictions can prevent the enrollment process itself.

How to eliminate wrong answers

Option A is wrong because a conditional access policy requiring device compliance does not prevent enrollment; it controls access to cloud apps after enrollment, and non-compliant devices can still enroll but then be blocked from accessing resources. Option C is wrong because a compliance policy requiring devices to be marked as corporate is not a pre-enrollment restriction; compliance policies are evaluated after enrollment and cannot block the enrollment process itself. Option D is wrong because a device type restriction for iOS and Android only blocks specific device models or platforms, not the ownership status (corporate vs. personal), so it cannot ensure that only corporate-owned devices enroll.

351
MCQeasy

You are a security administrator. You need to investigate a suspicious logon from an anonymous IP address. Which Microsoft Defender XDR data source should you query first?

A.Identity and authentication events
B.Cloud app events
C.Endpoint device events
D.Vulnerability and compliance events
E.Email & collaboration events
AnswerA

Identity and authentication events in Microsoft Defender XDR surface sign-in logs, including source IP, user agent and risk detections. Querying these first reveals whether the anonymous IP authenticated successfully and which account was targeted, directly addressing the suspicious logon scenario.

Why this answer

A suspicious logon from an anonymous IP address is an identity and authentication event. Microsoft Defender XDR's Identity and authentication events data source includes sign-in logs, authentication attempts, and related identity activities. Querying this source first will provide details such as the user account, IP address, location, and success/failure status, which are crucial for investigating the logon.

Exam trap

The trap is confusing identity events with cloud app events; logon attempts are identity events, while cloud app events are actions within apps after authentication.

How to eliminate wrong answers

Option B is wrong because cloud app events pertain to activities within cloud applications (e.g., Office 365), not raw logon events. Option C is wrong because endpoint device events focus on device processes and file activities, not authentication. Option D is wrong because vulnerability and compliance events relate to security posture, not logon attempts.

Option E is wrong because email and collaboration events cover email and Teams activities, not logon events.

352
MCQmedium

Contoso frequently collaborates with a partner company (Fabrikam) via B2B collaboration. Contoso uses Microsoft Entra ID P2 licenses and wants to require Fabrikam's guest users to authenticate using Contoso's MFA policies, ignoring any MFA claims from the Fabrikam home tenant. Fabrikam already has MFA enabled for its users. What configuration should Contoso make in their cross-tenant access settings?

A.Configure outbound access settings to require MFA for Fabrikam users
B.Configure inbound trust settings to uncheck 'Trust multi-factor authentication from Microsoft Entra tenants' for Fabrikam
C.Create a Conditional Access policy targeting all guest users from Fabrikam that requires MFA
D.Configure B2B direct connect for Fabrikam and require MFA
AnswerB

Unchecking inbound MFA trust for Fabrikam forces guest users to satisfy Contoso's own Conditional Access MFA requirements, rather than accepting MFA claims issued by Fabrikam's home tenant. This directly meets the stated constraint of ignoring Fabrikam's MFA claims, ensuring Contoso's authentication strength policies govern guest access.

Why this answer

Contoso wants to ignore MFA claims from Fabrikam's home tenant and enforce its own MFA policies on Fabrikam guest users. In cross-tenant access settings, the 'Trust multi-factor authentication from Microsoft Entra tenants' checkbox controls whether inbound MFA claims from the external tenant are accepted. By unchecking this for Fabrikam, Contoso ensures that Fabrikam's MFA claims are ignored, and Contoso's Conditional Access policies (including MFA requirements) apply to those guest users.

Exam trap

The trap here is that candidates often confuse inbound trust settings with outbound settings or Conditional Access policies, assuming that a Conditional Access policy alone can override MFA claims from the home tenant, when in fact the trust setting must be explicitly disabled to ignore those claims.

How to eliminate wrong answers

Option A is wrong because outbound access settings control how Contoso's users access Fabrikam resources, not how Fabrikam's guest users authenticate into Contoso. Option C is wrong because while a Conditional Access policy can require MFA for guest users, it does not override or ignore MFA claims from the home tenant; if the inbound trust setting trusts Fabrikam's MFA, the Conditional Access policy may not re-prompt for MFA. Option D is wrong because B2B direct connect is used for Teams Connect shared channels, not for standard B2B collaboration guest user access, and it does not provide the granular control over MFA trust needed here.

353
MCQeasy

Your organization needs to automatically detect and classify documents containing passport numbers in SharePoint Online. Which Microsoft Purview feature should you use?

A.eDiscovery (Premium).
B.Auto-labeling with sensitivity labels.
C.Data Lifecycle Management (DLM) policy.
D.Data Loss Prevention (DLP) policy.
AnswerB

Auto-labelling with sensitivity labels applies trainable classifiers and sensitive information types during scanning, so passport numbers are detected and classified without user input. This satisfies the requirement for automatic detection in SharePoint Online, unlike manual labelling or purely client-side classification.

Why this answer

Auto-labeling with sensitivity labels in Microsoft Purview can automatically detect sensitive content such as passport numbers using built-in or custom sensitive information types (SITs) and then apply a sensitivity label to the document. This is the only feature among the options designed to both detect and classify (label) content at scale in SharePoint Online. The label can then drive encryption, retention, and other protections.

Exam trap

MS-102 often tests the confusion between DLP (which takes protective actions like blocking) and auto-labeling (which classifies content with sensitivity labels); candidates frequently pick DLP when the requirement is to classify.

How to eliminate wrong answers

Option A is wrong because eDiscovery (Premium) is used for identifying, preserving, collecting, and reviewing content for legal or investigative purposes, not for automatically classifying documents with sensitivity labels. Option C is wrong because Data Lifecycle Management (DLM) policies govern retention and deletion of content, not detection and classification of sensitive data. Option D is wrong because DLP policies detect sensitive content and can block or warn on sharing, but they do not apply sensitivity labels to classify documents.

354
MCQmedium

You are the Microsoft 365 administrator for a company that has a Microsoft 365 E5 subscription. The company has a policy that all files stored in SharePoint Online and OneDrive for Business must be retained for seven years. You need to implement a retention solution that meets this requirement and ensures that users cannot permanently delete the files before the retention period expires. What should you do?

A.Create a retention policy in Microsoft Purview that retains content in SharePoint and OneDrive for seven years and locks the policy.
B.Configure a data loss prevention (DLP) policy that blocks deletion of files in SharePoint and OneDrive for seven years.
C.Create a retention policy that applies to all SharePoint sites and OneDrive accounts, set the retention period to seven years, and configure the policy to retain items even if users delete them.
D.Create a retention label that retains items for seven years and configure a retention label policy to publish the label to all SharePoint sites and OneDrive accounts.
AnswerC

A retention policy applied to all SharePoint sites and OneDrive accounts with a seven-year retention period ensures that items are retained even if users delete them. The policy preserves a copy in the Preservation Hold library, preventing permanent deletion. This meets the requirement that files must be retained for seven years and cannot be permanently deleted by users before the retention period expires.

Why this answer

A retention policy applied to all SharePoint sites and OneDrive accounts with a seven-year retention period ensures that items are retained even if users delete them. The policy preserves copies in the Preservation Hold library, preventing permanent deletion. This meets the requirement that files must be retained for seven years and cannot be permanently deleted by users before the retention period expires.

Exam trap

The trap here is confusing retention with DLP; DLP can block actions like sharing but cannot enforce retention, while retention policies preserve content even after deletion.

355
MCQeasy

An administrator has added a custom domain 'contoso.com' to their Microsoft 365 tenant and verified ownership. However, users are unable to receive emails sent to their custom domain. Which type of DNS record must the administrator add in the public DNS zone to route emails to Exchange Online?

A.TXT record
B.MX record
C.CNAME record
D.SPF record
AnswerB

An MX record specifies the mail exchanger accepting messages for contoso.com, directing inbound mail to Exchange Online's protection service. Without it, senders cannot locate a mail server, so users receive nothing despite verified domain ownership.

Why this answer

The MX (Mail Exchange) record is the DNS record type that directs email messages to a specific mail server. For Exchange Online, the MX record must point to the tenant's mail exchanger (e.g., contoso-com.mail.protection.outlook.com) with a priority value (typically 0). Without this record, sending mail servers cannot route inbound emails to the custom domain's mailbox store in Exchange Online.

Exam trap

The trap here is that candidates confuse the purpose of MX records with SPF or TXT records, thinking that SPF alone enables email delivery, when in fact MX records are the fundamental requirement for inbound mail routing.

How to eliminate wrong answers

Option A (TXT record) is wrong because TXT records hold arbitrary text data, such as SPF or DKIM keys, but they do not route email traffic. Option C (CNAME record) is wrong because CNAME records alias one domain to another and are not used for mail routing; MX records are the standard for mail exchange. Option D (SPF record) is wrong because SPF records authorize sending servers to prevent spoofing, but they do not direct inbound email delivery.

356
Multi-Selectmedium

You need to configure Microsoft Purview Data Loss Prevention (DLP) to prevent sensitive data from being shared via email. Which THREE elements can you use to define the policy?

Select 3 answers
A.Actions
B.Locations
C.Sensitivity labels
D.Exceptions
E.Conditions
AnswersA, B, E

Actions are a mandatory component of any Microsoft Purview DLP policy because they determine the enforcement response—such as blocking a SharePoint file share, applying encryption to an email, or displaying a policy tip—when a condition matches sensitive content. Without an action, the policy would only perform detection without any remediation or prevention, failing to satisfy data loss protection requirements. The action defines the resulting 'do you want to do' part of the rule, making it essential for the policy to be functional.

Why this answer

Actions are a required element in a Microsoft Purview DLP policy because they define what happens when sensitive data is detected—such as blocking the email, sending a notification, or applying encryption. Without specifying actions, the policy would have no enforcement mechanism to prevent data sharing.

Exam trap

The trap here is that candidates confuse sensitivity labels as a top-level policy element instead of recognizing they are merely a condition type, while exceptions are often mistakenly considered a separate core component rather than a refinement of conditions.

357
MCQmedium

Your organization uses Microsoft Defender for Office 365. You need to configure a policy that automatically redirects emails containing malicious attachments to a quarantine folder for admin review. What type of policy should you create?

A.Safe Attachments policy.
B.Anti-malware policy.
C.Anti-spam policy.
D.Safe Links policy.
AnswerB

The anti-malware policy in Microsoft Defender for Office 365 is the correct place to configure how messages containing malware are handled. It uses heuristics and signature-based detection to identify malicious attachments, and when malware is found, the policy can be set to quarantine the entire message. This policy also allows admins to specify the quarantine retention period and enable/disable malware filters, making it the definitive control for malware-induced quarantine.

Why this answer

B is correct because the Anti-malware policy in Microsoft Defender for Office 365 is specifically designed to handle malware detected in email messages, including attachments. When configured, it can automatically redirect messages containing malicious attachments to a quarantine folder for admin review, providing a controlled remediation workflow.

Exam trap

Microsoft often tests the distinction between Anti-malware (for attachment malware) and Safe Attachments (for advanced sandbox analysis), leading candidates to mistakenly choose Safe Attachments when the core requirement is simply redirecting known malicious attachments to quarantine.

How to eliminate wrong answers

Option A is wrong because Safe Attachments policy focuses on scanning and detonating attachments in a sandbox environment before delivery, but its primary quarantine action is for messages with malicious attachments detected during that process, not for general malware redirection; the question's requirement for automatic redirection of emails containing malicious attachments is directly met by the Anti-malware policy. Option C is wrong because Anti-spam policy handles spam, phishing, and bulk mail, not malware or malicious attachments. Option D is wrong because Safe Links policy protects users from malicious URLs in messages and Office documents, not from malicious attachments.

358
MCQeasy

You are configuring Microsoft Entra ID for a new organization. The CIO wants to ensure that all external users who are invited to collaborate via Microsoft Entra B2B must go through an approval process before gaining access. Which setting should you configure?

A.Create a Conditional Access policy requiring approval for external users
B.Set 'External collaboration settings' to restrict invitations to specific admins
C.Enable guest self-service sign-up via user flows
D.Enable Identity Protection for guest users
AnswerB

Under Microsoft Entra ID, go to External Identities > External collaboration settings and configure 'Guest invite restrictions' to 'Only users assigned to specific admin roles can invite guest users' (or the Guest Inviter role). This restricts invitation capability to authorized administrators, so any external user must be vetted by an admin before the invitation is sent, effectively acting as a mandatory approval gate. This is the correct control because it directly governs who may initiate external invitations and prevents regular users from bypassing oversight.

Why this answer

The 'External collaboration settings' in Microsoft Entra ID allow you to restrict who can invite external users. By setting the invitation restriction to 'Only users assigned to specific admin roles can invite', you ensure that all B2B collaboration invitations must be initiated by authorized admins, effectively requiring an approval process before external users gain access.

Exam trap

The trap here is confusing post-authentication access controls (Conditional Access) with pre-invitation approval workflows (External collaboration settings), leading candidates to incorrectly select a Conditional Access policy.

How to eliminate wrong answers

Option A is wrong because Conditional Access policies control access after authentication (e.g., requiring MFA or device compliance), not the invitation or approval process for B2B guest users. Option C is wrong because enabling guest self-service sign-up via user flows allows external users to sign up without any admin approval, which directly contradicts the requirement for an approval process. Option D is wrong because Identity Protection for guest users monitors risk signals (e.g., leaked credentials) but does not control the invitation or approval workflow for B2B collaboration.

359
MCQmedium

Your company has a Microsoft Entra tenant with 5,000 users. You need to delegate the ability to reset user passwords to the helpdesk team, but only for users in the Sales department. What is the most efficient way to achieve this?

A.Create an administrative unit for Sales, add Sales users, then assign a custom role scoped to that administrative unit
B.Create a security group for Sales, then assign a custom role to the group
C.Create a custom role with password reset permissions and assign it to helpdesk
D.Add helpdesk users to the Global Administrator role
AnswerA

Administrative units scope role assignments to a defined subset of users, so a custom role granting password reset can be assigned to helpdesk over the Sales administrative unit only, avoiding tenant-wide permissions or per-user delegation.

Why this answer

Administrative units (AUs) in Microsoft Entra ID are containers specifically designed to scope administrative permissions to a subset of users, groups, or devices. By creating an AU for Sales, adding the Sales users to it, and assigning a custom role (such as Password Administrator or a custom role with microsoft.directory/users/password/update) scoped to that AU, the helpdesk team gains the ability to reset passwords only for Sales users. This is the most efficient and least-privilege approach because it uses built-in scoping mechanisms without needing to manage separate role assignments per user or create complex conditional access policies.

Exam trap

MS-102 often tests the misconception that security groups can be used to scope role assignments in Microsoft Entra ID, but role scoping requires administrative units or tenant-level assignment; security groups are for licensing and access management, not for scoping administrative roles.

How to eliminate wrong answers

Option B is wrong because security groups cannot be used as a scope for role assignments in Microsoft Entra ID; role assignments are scoped to the tenant, administrative units, or (for some roles) specific objects, not to security groups. Option C is wrong because a custom role assigned at the tenant level would grant password reset permissions for all users, not just Sales, violating the requirement to limit to the Sales department. Option D is wrong because Global Administrator is the highest-privilege role and grants full control over the entire tenant, which is excessive and violates the principle of least privilege.

360
MCQeasy

A company wants to receive alerts when a user account is used from an unauthorized location. They have Microsoft Defender for Cloud Apps (MDA). Which policy type should they create?

A.Create a session policy.
B.Create an app permissions policy.
C.Create a file policy.
D.Create an anomaly detection policy.
AnswerD

Anomaly detection policies in Microsoft Defender for Cloud Apps baseline normal user behaviour and alert on deviations such as impossible travel or unfamiliar sign-in locations. This directly satisfies the requirement to flag account use from unauthorised locations.

Why this answer

Anomaly detection policies in Microsoft Defender for Cloud Apps use machine learning and behavioral baselines to flag activities that deviate from a user's normal pattern — including logins from unfamiliar or unauthorized geographic locations. This is the correct policy type because the requirement is to detect unusual user behavior (impossible travel, atypical location) rather than to control sessions, permissions, or files. MDA's anomaly detection engine automatically surfaces alerts such as 'Activity from infrequent country' or 'Impossible travel' without needing a predefined rule.

Exam trap

MS-102 often tests the distinction between MDA policy types — candidates pick session or file policies because they sound security-relevant, but only anomaly detection policies are behavior-based and location-aware.

How to eliminate wrong answers

Option A is wrong because session policies are Conditional Access App Control policies that proxy and restrict user sessions in real time (e.g., block download, enforce DLP) — they do not generate location-based behavioral alerts. Option B is wrong because app permissions policies govern OAuth app consent and permission grants to third-party applications, not user login locations. Option C is wrong because file policies apply DLP or governance actions to files (e.g., quarantine, apply sensitivity labels) and have nothing to do with detecting logins from unauthorized locations.

361
MCQeasy

An organization has just purchased Microsoft 365 subscriptions and wants to add their custom domain 'fabrikam.com' to the tenant. Which record must they add to their DNS provider to verify domain ownership?

A.MX record
B.TXT record
C.CNAME record
D.SRV record
AnswerB

A TXT record is the standard method Microsoft 365 uses to verify domain ownership because it can hold an arbitrary text string. Microsoft gives you a unique verification token during the domain setup wizard; when you publish it as a TXT record, Microsoft queries your DNS zone and confirms the exact token exists. This proves you control the domain without affecting existing services, and you can remove the record after verification succeeds.

Why this answer

To verify domain ownership in Microsoft 365, you must add a TXT record provided by the Microsoft 365 admin center to your DNS hosting provider. This TXT record contains a unique verification string that Microsoft checks to confirm you control the domain. MX, CNAME, and SRV records are used for mail routing, service aliasing, and service location, respectively, but they do not serve the purpose of domain ownership verification.

Exam trap

The trap here is that candidates often confuse the TXT record used for verification with the MX record required for email routing, mistakenly thinking they can skip verification by adding an MX record directly.

How to eliminate wrong answers

Option A is wrong because an MX record is used to specify the mail exchange server for a domain, not to prove domain ownership; adding an MX record would only affect email routing. Option C is wrong because a CNAME record creates an alias from one domain name to another and is used for service redirection, not for domain verification. Option D is wrong because an SRV record defines the location (hostname and port) of specific services like SIP or LDAP, and it is not used for domain ownership validation.

362
MCQeasy

An administrator is onboarding a new custom domain for email in a Microsoft 365 tenant. Which step should be performed first?

A.Add the domain in the Microsoft 365 admin center
B.Verify domain ownership by adding a TXT record
C.Configure DNS records for Microsoft services
D.Set the domain as the primary email domain
AnswerA

The first step in onboarding a custom email domain is to add it in the Microsoft 365 admin center (Settings > Domains > Add domain). This action registers the domain with your tenant and generates the necessary verification token, allowing you to proceed to the next step of proving ownership. This must occur before any TXT record or DNS changes can be associated with the domain.

Why this answer

Before you can use a custom domain for email or any other service in Microsoft 365, you must first add the domain to the tenant in the Microsoft 365 admin center. This creates the domain object in Azure Active Directory and initiates the verification process. Only after the domain is added can you proceed to verify ownership and configure DNS records.

Exam trap

The trap here is that candidates often confuse the order of operations, thinking DNS verification (Option B) is the first step, but Microsoft 365 requires the domain to be added to the tenant first to generate the verification token.

How to eliminate wrong answers

Option B is wrong because verifying domain ownership by adding a TXT record is a subsequent step that cannot be performed until the domain has been added to the tenant. Option C is wrong because configuring DNS records for Microsoft services (e.g., MX, CNAME, TXT) is done after verification, not before. Option D is wrong because setting the domain as the primary email domain is a final step that requires the domain to be added, verified, and DNS records configured first.

363
MCQhard

Your organization uses Microsoft Entra ID with Privileged Identity Management (PIM) to manage administrative roles. You need to ensure that when a user activates the Global Administrator role, they must provide a justification and the activation is time-bound. Additionally, you want to require approval from the security team for this activation. What should you configure?

A.Configure an Identity Protection user risk policy for Global Administrators
B.Create an Access Review for Global Administrator role
C.Configure a Conditional Access policy requiring MFA for Global Administrator activation
D.Modify the PIM role settings for Global Administrator to require justification, set maximum activation duration, and require approval
AnswerD

Configuring the Global Administrator role's PIM settings directly satisfies every stated constraint: justification on activation, a maximum activation duration enforcing time-bound access, and approver selection for security team sign-off. These controls live in the role's activation settings within Microsoft Entra ID Privileged Identity Management, so no separate policy or access review is needed.

Why this answer

Privileged Identity Management (PIM) role settings allow you to enforce activation requirements such as justification, maximum activation duration, and approval. These settings are configured directly in the PIM role settings for the Global Administrator role, ensuring that every activation request is justified, time-bound, and requires approval from designated approvers (e.g., the security team).

Exam trap

The trap here is that candidates often confuse Conditional Access policies (which control authentication) with PIM role settings (which control role activation), leading them to select Option C even though Conditional Access cannot enforce approval workflows or activation duration limits.

How to eliminate wrong answers

Option A is wrong because Identity Protection user risk policies are designed to detect and respond to user account compromise risks (e.g., leaked credentials), not to control PIM role activation workflows. Option B is wrong because Access Reviews are used for periodic recertification of role assignments (e.g., confirming who still needs the role), not for enforcing activation-time requirements like justification, duration, or approval. Option C is wrong because Conditional Access policies can require MFA during sign-in, but they cannot enforce PIM-specific activation requirements such as justification, time-bound activation, or approval workflow; those are managed exclusively within PIM role settings.

364
MCQhard

Your organization uses Microsoft Purview Compliance Manager. You need to assign a control to a specific user for implementation. What should you do?

A.Assign the user the Compliance Manager role.
B.Edit the control and assign a new owner.
C.Create a DLP policy to enforce the control.
D.Modify the assessment to include the user.
AnswerB

Editing the control lets you set a new owner, which is exactly how Compliance Manager delegates implementation responsibility. Ownership assignment sits on the control itself, not on assessments or improvement actions, so reassigning the owner directly satisfies the requirement to make one named user accountable for that control.

Why this answer

In Microsoft Purview Compliance Manager, each control within an assessment has an 'Assigned to' field that designates the individual responsible for implementing and documenting that control. Editing the control and assigning a new owner is the correct way to delegate accountability for a specific control to a user. This assignment is purely for tracking and workflow purposes and does not grant any permissions to the user.

Exam trap

MS-102 often tests the confusion between assigning a role (which grants permissions) and assigning a control owner (which assigns accountability) — candidates incorrectly pick the role option thinking it delegates the control.

How to eliminate wrong answers

Option A is wrong because the Compliance Manager role grants access to the Compliance Manager solution itself, not ownership of a specific control; role assignment and control ownership are separate concepts. Option C is wrong because DLP policies enforce data-handling rules on content and have nothing to do with assigning control ownership in Compliance Manager. Option D is wrong because modifying the assessment changes the scope of controls being evaluated, not who is responsible for a particular control.

365
MCQeasy

An administrator adds the custom domain 'adatum.com' to a new Microsoft 365 tenant. In the Microsoft 365 admin center, the domain status shows 'Pending verification'. Which type of DNS record must the administrator add to the public DNS zone to complete the domain ownership verification?

A.TXT record
B.MX record
C.CNAME record
D.SPF record
AnswerA

Microsoft 365 generates a unique verification code and instructs you to add it as a TXT record in your domain's DNS. The service then queries DNS for that exact string; if found, it confirms you control the domain and can use it for Exchange Online, Teams, or SharePoint. TXT records are the standard mechanism for proving ownership because they can hold arbitrary text, which the verification token is.

Why this answer

To verify domain ownership in Microsoft 365, you must add a TXT record containing a unique verification string provided by the Microsoft 365 admin center to the public DNS zone. The DNS provider checks for this TXT record, and when found, Microsoft 365 confirms you control the domain. This is a standard domain verification method defined in RFC 1035 and used by many cloud services.

Exam trap

The trap here is that candidates confuse the TXT record used for domain verification with the TXT record used for SPF or DKIM, or assume an MX record is required because email is involved, but Microsoft 365 uses a dedicated verification TXT record separate from any email-related records.

How to eliminate wrong answers

Option B is wrong because an MX record routes email to a mail server, not for domain ownership verification; it is used later for mail flow configuration. Option C is wrong because a CNAME record aliases one domain to another and is not used for domain verification; it is typically used for services like autodiscover. Option D is wrong because an SPF record is a TXT record used for email authentication (anti-spoofing), not for domain ownership verification; it is configured after verification is complete.

366
MCQeasy

You run the PowerShell command shown in the exhibit for a Microsoft 365 tenant. The output shows DisplayName as 'Contoso', DefaultDomainName as 'contoso.onmicrosoft.com', and InitialDomain as 'contoso.onmicrosoft.com'. What does this indicate about the tenant?

A.The command requires global admin privileges.
B.The tenant is using the initial .onmicrosoft.com domain as the default domain.
C.The tenant has not been verified.
D.The tenant has a custom domain set as the default.
AnswerB

When DefaultDomainName and InitialDomain display the same .onmicrosoft.com address, it means Microsoft 365 is using the originally provisioned domain as the primary SMTP routing domain. This is the default state for a new tenant; the initial domain is always verified and cannot be removed, so no custom domain has been designated as default.

Why this answer

The output shows DefaultDomainName and InitialDomain both set to 'contoso.onmicrosoft.com', which means the tenant is using its initial Microsoft-provided domain as the default domain. The Get-MgDomain cmdlet retrieves domain objects, and the DefaultDomainName property indicates which domain is used by default for new users and services. Since no custom domain is set as default, the initial .onmicrosoft.com domain remains the default.

Exam trap

The trap here is that candidates may assume the DefaultDomainName property reflects a custom domain that has been set as default, but the output explicitly shows it is the initial .onmicrosoft.com domain, indicating no custom domain has been promoted to default.

How to eliminate wrong answers

Option A is wrong because the Get-MgDomain cmdlet does not require global admin privileges; it can be run by any user with appropriate read permissions (e.g., Domain Reader or Global Reader). Option C is wrong because the presence of a DisplayName, DefaultDomainName, and InitialDomain in the output indicates the domain is verified and active; unverified domains would not appear in the domain list or would show a different status. Option D is wrong because the DefaultDomainName is 'contoso.onmicrosoft.com', not a custom domain; if a custom domain were set as default, that custom domain name would appear in the DefaultDomainName property.

367
MCQmedium

An organization is involved in litigation and needs to search for all communications containing a specific keyword across Exchange Online, SharePoint Online, and OneDrive for Business. The results must be preserved as evidence without allowing deletion. Which Microsoft Purview solution should the compliance officer use?

A.Data Loss Prevention
B.eDiscovery (Premium)
C.Communication Compliance
D.Retention Labels
AnswerB

eDiscovery (Premium) is the Microsoft 365 workload designed for legal discovery: it uses a single search index across Exchange Online, SharePoint Online, OneDrive, and Teams, allowing keywords, conditional operators, and custodian-based collection. It can place a legal hold on matched content, making it immutable and preserving all versions and metadata until released. Review sets then provide advanced analytics, redaction, tagging, and export for litigation workflows, so it directly answers the need to search and preserve.

Why this answer

eDiscovery (Premium) is the correct solution because it provides end-to-end workflow for identifying, preserving, collecting, reviewing, and exporting content across Exchange Online, SharePoint Online, and OneDrive for Business. It supports legal hold to preserve data in-place, preventing deletion or alteration, and can search all communications for specific keywords using advanced query capabilities.

Exam trap

The trap here is that candidates often confuse eDiscovery (Premium) with Retention Labels or Communication Compliance because all three involve content management, but only eDiscovery (Premium) provides the legal hold and cross-workload search capabilities required for litigation evidence preservation.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) is designed to prevent accidental sharing of sensitive data through policies and alerts, not to search, preserve, or hold content for litigation. Option C is wrong because Communication Compliance focuses on monitoring and detecting policy violations (e.g., harassment, insider trading) in communications, not on preserving evidence or placing legal holds. Option D is wrong because Retention Labels are used to classify and apply retention or deletion rules to content, but they do not provide the search, hold, or export capabilities required for litigation discovery.

368
MCQhard

A security analyst wants to automatically create a Microsoft Teams message in a dedicated security channel whenever a Microsoft 365 Defender incident with severity 'High' is created. Which automation approach should the analyst use?

A.Power Automate
B.Automation rules in Defender
C.Microsoft Graph API
D.Action Center
AnswerA

Power Automate flows offer a native trigger for Microsoft 365 Defender incidents, such as 'When an incident is created or updated,' and can then use the Microsoft Teams connector's 'Post message in a chat or channel' action to send a message to a specific channel. This low-code solution allows filtering by severity (e.g., High), supports adaptive cards for rich context, and can automatically execute without human intervention. It is the standard tool for integrating Defender incident generation with Teams notifications.

Why this answer

Power Automate is the correct choice because it provides a no-code/low-code workflow that can be triggered by Microsoft 365 Defender's 'When an incident is created or updated' connector, filter for severity 'High', and then post a message to a dedicated Teams channel via the 'Post a message in a chat or channel' action. This directly meets the requirement for automatic, event-driven notification without custom code.

Exam trap

The trap here is that candidates confuse 'automation rules' in Defender (which handle response actions like isolation) with external notification workflows, leading them to choose Option B instead of recognizing that Power Automate is the correct integration tool for sending Teams messages.

How to eliminate wrong answers

Option B is wrong because Automation rules in Defender are designed for automated response actions (e.g., isolating a device, blocking an IP) within the Defender portal itself, not for sending external notifications like Teams messages. Option C is wrong because while Microsoft Graph API can technically achieve this, it requires custom scripting, authentication setup, and manual polling or webhook configuration, making it less straightforward than Power Automate for a security analyst without developer resources. Option D is wrong because Action Center is a centralized interface for reviewing and approving pending remediation actions from Defender, not a tool for creating automated notifications or workflows.

369
MCQeasy

Your organization uses Microsoft Entra ID to manage user identities. You need to ensure that users can sign in using their existing social media accounts, such as Microsoft, Google, or Facebook. What should you configure?

A.Configure Conditional Access policies for social identity providers
B.Configure External Identities and add identity providers for social networks
C.Configure Microsoft Entra Connect to sync social account attributes
D.Configure self-service password reset (SSPR)
AnswerB

External Identities lets you federate with social providers such as Microsoft, Google, and Facebook, so users sign in with existing accounts rather than new Entra ID credentials. This directly satisfies the requirement for social media sign-in.

Why this answer

Microsoft Entra ID supports External Identities, which allow you to add social identity providers (Microsoft, Google, Facebook) as external authentication sources. This enables users to sign in with their existing social accounts by configuring federation with those providers using OAuth 2.0 or OpenID Connect protocols, without needing to create separate Entra ID accounts.

Exam trap

The trap here is that candidates often confuse Conditional Access policies with identity provider configuration, thinking policies can add or manage external authentication sources, when in fact Conditional Access only enforces rules on already-configured providers.

How to eliminate wrong answers

Option A is wrong because Conditional Access policies evaluate sign-in risks and enforce access controls after authentication, but they cannot add or configure social identity providers; they only work with already-configured identity providers. Option C is wrong because Microsoft Entra Connect is used to synchronize on-premises Active Directory objects to Entra ID, not to sync social account attributes—social identity providers are external and not synced via directory synchronization. Option D is wrong because self-service password reset (SSPR) allows users to reset their own passwords for their Entra ID accounts, but it does not enable sign-in with social media accounts; SSPR is unrelated to external identity provider configuration.

370
MCQmedium

Your organization uses Microsoft Defender for Identity (MDI) and Microsoft Defender for Cloud Apps. You receive an alert about a user account that is exhibiting suspicious behavior: unusual login times from an IP address that is not in the user's typical location. The alert recommends action. You need to determine if the account is compromised. What is the best next step?

A.Initiate an automated investigation in Microsoft Defender XDR
B.Configure a conditional access policy in Microsoft Entra ID to block the IP
C.Immediately disable the user account
D.Reset the user's password
AnswerA

Automated investigation in Microsoft Defender XDR correlates the MDI sign-in anomaly with related alerts and entity data, gathering evidence and recommending remediation. This satisfies the need to determine compromise quickly without manually pivoting across portals.

Why this answer

Initiating an automated investigation in Microsoft Defender XDR correlates signals across MDI, Defender for Cloud Apps, and other Microsoft 365 services to determine if the account is compromised. Option B is wrong because configuring a conditional access policy is a preventive measure, not an investigative step to confirm compromise. Option C is wrong because disabling the account immediately might be premature and could disrupt legitimate access without confirming the threat.

Option D is wrong because resetting the password alone does not investigate other potential malicious activity or identify the scope of compromise.

371
MCQmedium

Your organization has Microsoft 365 E5 and uses Microsoft Defender for Cloud Apps. You want to block downloads from an unsanctioned cloud app that is used by some employees. What should you configure?

A.Create a DLP policy to block sharing of sensitive data with the app.
B.Create a conditional access policy to require the use of managed apps.
C.Block the app by its IP addresses in the firewall.
D.Configure the app as unsanctioned in Defender for Cloud Apps and create a session policy to block downloads.
AnswerD

Marking the app unsanctioned alone only flags it in Cloud Discovery; the session policy is what enforces control. Conditional Access app control proxies the session, and the block-download action satisfies the requirement to prevent data leaving via that unsanctioned cloud app.

Why this answer

Marking the app as unsanctioned in Defender for Cloud Apps and creating a session policy allows blocking downloads from that app. Option A is incorrect because a DLP policy protects data but does not block app usage. Option B is incorrect because a conditional access policy can enforce controls like requiring managed apps, but it does not directly block downloads from an unsanctioned app.

Option C is incorrect because blocking by IP address is ineffective for cloud apps that use dynamic IP ranges.

372
MCQmedium

An organization wants to enforce that all administrators use a phishing-resistant authentication method (e.g., FIDO2 security keys or Windows Hello for Business) when accessing Microsoft 365 admin portals. Which Microsoft Entra ID feature should be used?

A.Conditional Access authentication strength
B.Security defaults
C.Per-user MFA
D.Identity Protection
AnswerA

Conditional Access authentication strength is the correct mechanism because it lets you create or use a built-in policy that requires a specific authentication strength, such as "Phishing-resistant MFA" (FIDO2 security keys, Windows Hello for Business, or certificate-based authentication). You apply this policy to a Conditional Access grant control scoped to the Administrator role, which forces every administrator to sign in using only a phishing-resistant method. This is more than just enabling MFA; it actively rejects weaker methods like SMS, voice call, OTP, or authenticator app verification codes, ensuring compliance with the stated requirement.

Why this answer

Conditional Access authentication strength allows administrators to define and enforce specific authentication methods, such as FIDO2 security keys or Windows Hello for Business, which are phishing-resistant. By creating a policy that targets admin roles and requires an authentication strength policy that mandates these methods, the organization can ensure that only phishing-resistant credentials are accepted when accessing Microsoft 365 admin portals. This granular control goes beyond simple MFA enforcement by specifying the exact authentication method required.

Exam trap

The trap here is that candidates often confuse the generic MFA enforcement of Security defaults or Per-user MFA with the ability to specify a particular authentication method, not realizing that only Conditional Access authentication strength provides the granularity to mandate phishing-resistant methods like FIDO2.

How to eliminate wrong answers

Option B is wrong because Security defaults enforces a baseline set of security policies, including requiring MFA for all users, but it does not allow customization to mandate a specific phishing-resistant method like FIDO2; it uses a generic MFA requirement that could be satisfied by less secure methods such as SMS or OTP. Option C is wrong because Per-user MFA enables or disables MFA on a per-user basis but cannot enforce a specific authentication method; it only requires the user to complete MFA using any method they have registered, including non-phishing-resistant ones. Option D is wrong because Identity Protection is a risk-based detection and remediation tool that identifies suspicious sign-ins and user risks, but it does not enforce specific authentication methods; it can trigger MFA via Conditional Access but cannot mandate a particular method like FIDO2.

373
MCQhard

A multinational company uses Microsoft Entra ID with Conditional Access policies. They have a policy that requires multi-factor authentication (MFA) for all users when accessing the company's custom SaaS application. However, users from the European branch are reporting that they are prompted for MFA every time, even though they have already authenticated via a compliant device. What is the most likely cause?

A.The user's device is not marked as compliant
B.The user has per-user MFA enabled
C.The Conditional Access policy has a session control that requires sign-in frequency
D.The policy includes a location condition that is not met
AnswerC

Sign-in frequency is a Conditional Access session control that configures how often a user must re-authenticate, regardless of whether their device is compliant. Once the configured time window expires, the session's refresh token is no longer valid for re-authentication, forcing the user to provide MFA again. This exactly matches the reported behavior—repeated MFA prompts on a compliant device—because the policy is not checking device health but enforcing token lifetime limits.

Why this answer

The Conditional Access policy includes a session control that requires sign-in frequency, which forces users to re-authenticate with MFA at a specified interval regardless of device compliance or previous authentication. Even if the device is compliant and the user has already authenticated, the sign-in frequency control overrides session persistence and prompts for MFA again based on the configured time period (e.g., every hour). This explains why European branch users are repeatedly prompted for MFA despite having authenticated via a compliant device.

Exam trap

The trap here is that candidates confuse device compliance with session persistence, assuming that a compliant device automatically prevents repeated MFA prompts, but Conditional Access session controls like sign-in frequency explicitly override that behavior.

How to eliminate wrong answers

Option A is wrong because if the device were not marked as compliant, the policy would block access or require additional controls, but the users are still able to access the application after MFA, indicating the device compliance condition is satisfied. Option B is wrong because per-user MFA is a legacy setting that applies globally to all applications and would not cause repeated prompts only for this specific SaaS application; it would also be overridden by Conditional Access policies. Option D is wrong because a location condition that is not met would typically block access or require additional authentication, not cause repeated MFA prompts after successful authentication from a compliant device.

374
MCQhard

A company wants to require approval for any activation of the Global Administrator role in Privileged Identity Management (PIM). The approvers are predefined as members of a security group named 'GA-Approvers'. Activations must require a business justification and expire after 4 hours. Which PIM configuration should the administrator modify to meet these requirements?

A.Edit the role settings of the Global Administrator role in PIM.
B.Create an access review for the Global Administrator role.
C.Configure Azure AD Identity Protection to require MFA for Global Administrator.
D.Assign the Global Administrator role directly to the users temporarily.
AnswerA

To require approval for Global Administrator activations, you must edit the role's settings in Azure AD Privileged Identity Management. On the Activation tab, set 'Require approval to activate' to Yes and select designated approvers. This setting governs every PIM activation request for that role, ensuring no one gains the role without an approver's consent. This is the correct control because it directly addresses the approval requirement.

Why this answer

The requirement to require approval, enforce a business justification, and set a 4-hour expiration for Global Administrator activations is configured in the role settings of the Global Administrator role within Privileged Identity Management (PIM). These settings control activation parameters such as approval requirements, justification, and maximum activation duration, which directly map to the stated needs.

Exam trap

The trap here is that candidates confuse PIM role settings (which control activation policies) with access reviews (which audit existing assignments) or Azure AD Identity Protection (which handles sign-in risk), leading them to select options that address different aspects of identity governance.

How to eliminate wrong answers

Option B is wrong because an access review is used to periodically review and confirm role assignments, not to configure activation approval, justification, or expiration settings. Option C is wrong because Azure AD Identity Protection's MFA requirement for Global Administrator enforces authentication at sign-in, not activation approval or duration within PIM. Option D is wrong because directly assigning the Global Administrator role bypasses PIM activation workflows entirely, removing the ability to require approval, justification, or expiration.

375
MCQeasy

A company has a hybrid identity setup. A new employee is created in on-premises AD but does not appear in Azure AD after sync. What should the admin check first?

A.Organizational unit filtering
B.DNS configuration
C.License assignment
D.Azure AD Connect synchronization status
AnswerD

Azure AD Connect synchronization status is the primary suspect when a newly created on-premises user does not appear in Microsoft 365. The synchronization service runs on a recurring schedule; if the last delta sync failed, the scheduler is paused, or the service itself is stopped, the new user will not be replicated to Azure AD. Verifying the sync cycle, checking the event logs for errors, and forcing a delta sync are the correct initial troubleshooting steps before examining any other configuration.

Why this answer

When a new user is created in on-premises Active Directory but does not appear in Azure AD after synchronization, the first troubleshooting step is to check the Azure AD Connect synchronization status. This is because Azure AD Connect is the service responsible for synchronizing objects from on-premises AD to Azure AD, and any sync failure, delay, or misconfiguration (such as a stopped sync cycle or filtering rules) would prevent the user from appearing. Checking the sync status via the Azure AD Connect wizard or the Synchronization Service Manager can immediately reveal whether the object was exported, skipped, or errored.

Exam trap

The trap here is that candidates often jump to license assignment (Option C) because they think a user must have a license to appear in Azure AD, but in reality, unlicensed users still appear in Azure AD after sync; the license only enables service access, not directory presence.

How to eliminate wrong answers

Option A is wrong because organizational unit (OU) filtering is a configuration within Azure AD Connect that controls which OUs are synchronized, but it is not the first thing to check; if the user's OU is excluded, the user would never sync, but the admin should first verify the sync status to see if the user is being processed at all. Option B is wrong because DNS configuration is unrelated to user synchronization; DNS is used for name resolution in network connectivity, but Azure AD Connect communicates over HTTPS and does not rely on DNS for object-level sync issues. Option C is wrong because license assignment is a post-sync step; a user must first appear in Azure AD before licenses can be assigned, so checking licenses would be premature and irrelevant if the user has not synced.

Page 4

Page 5 of 10

Page 6

All pages