Courseiva

Microsoft 365 Administrator MS-102 (MS-102) — Questions 451–525

712 questions total · 10pages · All types, answers revealed

Page 6

Page 7 of 10

Page 8
451
MCQmedium

Your organization is migrating from on-premises Active Directory to Microsoft Entra ID. You need to ensure that users can use their existing on-premises passwords to log in to cloud services, while maintaining password policy enforcement on-premises. Which feature should you implement?

A.Password Hash Synchronization (PHS)
B.Pass-through Authentication with Seamless SSO
C.Active Directory Federation Services (AD FS)
D.Install Azure AD Connect with default settings
AnswerB

Pass-through Authentication with Seamless SSO is not the best option because it uses lightweight agents on-premises to validate passwords directly against Active Directory in real time, rather than synchronizing any password hash to Entra ID. While PTA avoids storing password hashes in the cloud, it introduces a dependency on on-premises agent availability, requires agent high availability planning, and Seamless SSO only provides silent sign-in on domain-joined devices. For a simple migration to cloud authentication, PTA is operationally more complex than PHS and does not allow cloud-based sign-in if the on-premises directory becomes unreachable.

Why this answer

Pass-through Authentication (PTA) validates passwords directly against on-premises Active Directory, ensuring that on-premises password policies (complexity, expiration, lockout) are enforced for cloud sign-ins. PHS merely synchronizes password hashes to Entra ID and cannot enforce on-premises lockout or account state at authentication time.

Exam trap

The trap is that candidates may think PHS is sufficient because it uses the same password, but the requirement to maintain on-premises policy enforcement during logon points to PTA, not PHS. Seamless SSO is optional and not the deciding factor.

How to eliminate wrong answers

Option B is wrong because Pass-through Authentication with Seamless SSO validates passwords directly against on-premises Active Directory without storing password hashes in the cloud, but it does not maintain password policy enforcement on-premises in a way that differs from PHS—it still relies on on-premises policy, but the question specifically asks for a feature that ensures users can use existing passwords while maintaining on-premises policy enforcement, and PHS is the simplest and most direct solution. Option C is wrong because Active Directory Federation Services (AD FS) is a federation service that redirects authentication to on-premises servers, which adds complexity and requires high-availability infrastructure; it is not the simplest or most appropriate choice when the goal is to use existing passwords without additional federation overhead. Option D is wrong because installing Azure AD Connect with default settings does not automatically enable password synchronization; the default settings only synchronize directory objects, and you must explicitly select the Password Hash Synchronization option to achieve the described goal.

452
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You discover that a user is accessing a sanctioned cloud app from an unknown IP address. You want to require multi-factor authentication (MFA) for this access. What should you configure?

A.Create a file policy
B.Create an access policy
C.Create a session policy
D.Create an app discovery policy
AnswerB

A Microsoft Defender for Cloud Apps access policy evaluates session conditions such as the source IP address and can enforce step-up controls, including requiring MFA, for the sanctioned app. This satisfies the requirement to challenge access originating from the unknown IP address.

Why this answer

An access policy in Microsoft Defender for Cloud Apps can enforce conditional access controls, such as requiring multi-factor authentication (MFA), based on conditions like IP address. Option A is incorrect because file policies govern file sharing and cannot enforce MFA. Option C is incorrect because session policies monitor and control user activity in real time but do not directly enforce MFA.

Option D is incorrect because app discovery policies identify shadow IT and do not control access conditions.

453
MCQmedium

A compliance officer needs to retain all documents in a SharePoint Online site for 7 years and then automatically delete them. During the retention period, users must be able to edit the documents but not delete them. Which Microsoft Purview solution should the officer configure?

A.retention policy configured with a retention period of 7 years and an action to delete items automatically
B.retention label configured with a retention period and an action to delete after 7 years
C.data lifecycle management policy
D.An eDiscovery hold
AnswerA

A retention policy in Microsoft Purview applies at the container level, such as a SharePoint site or Exchange mailbox, and can be configured with a 7-year retention period followed by automatic deletion of items. This container-based scope ensures all documents in the site are covered without requiring per-item labels or manual classification. During the retention period, content is protected from permanent deletion by users, and after the 7 years the policy triggers an automatic purge, exactly matching the compliance officer's requirement.

Why this answer

A retention policy in Microsoft Purview can be applied at the site level to enforce a 7-year retention period with automatic deletion, while allowing users to edit documents during that time. The policy prevents deletion by users because the retention lock overrides user permissions, ensuring compliance with the requirement to block deletion but permit edits.

Exam trap

The trap here is that candidates confuse retention labels with retention policies, assuming labels can enforce site-wide deletion and edit permissions, but labels are item-level and require manual application or auto-labeling, whereas policies apply broadly and include the necessary deletion prevention.

How to eliminate wrong answers

Option B is wrong because a retention label requires manual or auto-classification and is typically applied to individual items, not an entire site, and it does not inherently prevent user deletion during the retention period unless combined with a retention policy. Option C is wrong because a data lifecycle management policy focuses on managing data across its lifecycle (e.g., archiving or moving to cold storage) but does not enforce a retention period with deletion prevention and automatic deletion in the same way as a retention policy. Option D is wrong because an eDiscovery hold preserves content for legal or investigative purposes but does not automatically delete items after a set period; it is designed for indefinite holds until released, not scheduled deletion.

454
MCQeasy

Your organization has a Microsoft 365 E5 tenant. You need to ensure that users are prompted to register for multifactor authentication (MFA) the first time they sign in. Which Microsoft Entra ID policy should you configure?

A.Enable Security defaults
B.Create a Conditional Access policy requiring MFA and enable Microsoft Entra ID Identity Protection to enforce MFA registration
C.Enable combined registration for SSPR and MFA
D.Configure MFA service settings per-user
AnswerB

This combined approach works because Identity Protection's MFA registration policy is a Conditional Access grant control that prompts users to register at their first interactive sign-in, before they can access protected apps. The separate Conditional Access policy requiring MFA for all cloud apps then enforces the actual MFA challenge at every subsequent sign-in, ensuring both registration and ongoing enforcement. This is the modern, recommended method, as it is customizable per user, group, or application and integrates seamlessly with the Conditional Access engine.

Why this answer

Combining a Conditional Access policy that requires MFA with Identity Protection's MFA registration policy ensures users are prompted to register for MFA at first sign-in. The MFA registration policy in Identity Protection specifically enforces that users must register their authentication methods before accessing applications, which triggers the registration prompt on initial authentication.

Exam trap

The trap here is that candidates often confuse the MFA registration policy in Identity Protection with a standard Conditional Access policy that requires MFA, but the registration policy specifically triggers the registration prompt, not the MFA challenge itself.

How to eliminate wrong answers

Option A is wrong because Security defaults is a baseline security feature that enforces MFA for all users but does not provide a granular registration prompt on first sign-in; it applies MFA automatically after registration, not a registration-only trigger. Option C is wrong because combined registration for SSPR and MFA only consolidates the user registration portal for both features; it does not enforce or prompt registration at sign-in. Option D is wrong because configuring MFA service settings per-user is a legacy method that requires manual enablement and does not automatically prompt users to register on first sign-in; it also lacks the integration with Identity Protection for registration enforcement.

455
MCQmedium

You need to configure Microsoft Entra ID to allow users to authenticate using their existing social media accounts. Which identity provider type should you add?

A.OpenID Connect identity provider
B.Google identity provider
C.Microsoft account identity provider
D.SAML/WS-Fed identity provider
AnswerB

Google identity provider is a first-class social identity provider in Microsoft Entra External Identities. You add it by navigating to External Identities > All identity providers > Google, supplying a client ID and client secret from the Google API Console, and then enabling it for B2B guest invitations or self-service sign-up user flows. This is the correct option because it directly configures Microsoft Entra ID to accept Google accounts for authentication.

Why this answer

To allow users to authenticate using their existing social media accounts, you need to add a Google identity provider in Microsoft Entra ID. Google is explicitly supported as a social identity provider (IdP) for B2B guest user scenarios, enabling users to sign in with their Gmail accounts. This is configured under External Identities > All identity providers, where you select Google and configure the OAuth 2.0 client ID and secret from the Google API Console.

Exam trap

The trap here is that candidates confuse the generic 'OpenID Connect identity provider' option with the pre-configured social providers, not realizing that Microsoft provides dedicated Google and Facebook identity providers for social authentication, while OpenID Connect is for custom OIDC-compliant IdPs.

How to eliminate wrong answers

Option A is wrong because OpenID Connect is a protocol, not a specific social identity provider; adding a generic OpenID Connect provider requires custom configuration and is not the pre-built option for social accounts like Google. Option C is wrong because Microsoft account is already a built-in identity provider in Entra ID for Microsoft personal accounts (e.g., Outlook.com), not for third-party social media accounts like Google or Facebook. Option D is wrong because SAML/WS-Fed identity providers are used for enterprise federation with on-premises or cloud directories (e.g., ADFS, Okta), not for consumer social media authentication.

456
MCQmedium

A company needs to migrate several shared mailboxes from on-premises Exchange 2016 to Exchange Online. The company plans to keep some user mailboxes on-premises for now. Which migration strategy should they use for the shared mailboxes?

A.Cutover migration
B.Staged migration
C.IMAP migration
D.Hybrid migration
AnswerD

Hybrid migration leverages the Mailbox Replication Service (MRSproxy) in an Exchange hybrid deployment to move mailbox objects, including shared mailboxes, between on-premises and Exchange Online with full coexistence. Because the hybrid configuration establishes synchronization and trusts between the two environments, the shared mailbox's attributes, permissions, and user object are migrated atomically, preserving its type as a shared mailbox in the cloud. This is the only method listed that natively supports moving shared mailboxes, making it the correct answer for the migration scenario.

Why this answer

A hybrid migration is the correct choice because it allows the coexistence of on-premises Exchange 2016 and Exchange Online mailboxes, enabling the selective migration of shared mailboxes while keeping some user mailboxes on-premises. This approach uses the Hybrid Configuration Wizard to establish a secure connection and synchronize directory objects via Azure AD Connect, supporting mailbox moves with the New-MoveRequest cmdlet.

Exam trap

The trap here is that candidates often choose cutover migration because it is simpler, but they overlook the requirement to keep some mailboxes on-premises, which cutover migration cannot accommodate.

How to eliminate wrong answers

Option A is wrong because cutover migration migrates all mailboxes in a single batch and requires all mailboxes to be moved to Exchange Online, which conflicts with the requirement to keep some user mailboxes on-premises. Option B is wrong because staged migration is designed for migrating user mailboxes from on-premises Exchange 2003 or 2007, not Exchange 2016, and it does not support shared mailboxes natively. Option C is wrong because IMAP migration only migrates email data (not calendar, contacts, or tasks) and does not preserve shared mailbox properties or enable coexistence; it is intended for non-Exchange systems.

457
MCQhard

A security analyst needs to create a custom detection rule in Microsoft Defender XDR that triggers when a user's device establishes a network connection to a known malicious IP address on a port commonly used by a specific malware. The rule must also include process information such as the filename of the process that initiated the connection. Which advanced hunting table should be the primary data source for this rule?

A.DeviceNetworkEvents
B.DeviceProcessEvents
C.DeviceFileEvents
D.IdentityLogonEvents
AnswerA

DeviceNetworkEvents is the correct table because it records each network connection initiated or received on a device, including actionable fields such as RemoteIP, RemotePort, Protocol, LocalIP, LocalPort, and InitiatingProcessId or InitiatingProcessFileName. A custom detection rule can directly target these columns to alert on inbound or outbound traffic to suspicious IPs or ports without needing to join other tables. This is the only listed table that natively contains network-specific endpoint data suitable for detecting network-based threats.

Why this answer

The DeviceNetworkEvents table in Microsoft Defender XDR captures network connection events, including source and destination IP addresses, ports, and the initiating process's filename and ID. This makes it the ideal primary data source for a custom detection rule that must trigger on a specific malicious IP and port combination while also providing process information.

Exam trap

The trap here is that candidates often confuse DeviceProcessEvents (which includes process command lines) as sufficient for network detection, overlooking that it lacks the network-specific fields (RemoteIP, RemotePort) required to match a malicious IP and port combination.

How to eliminate wrong answers

Option B (DeviceProcessEvents) is wrong because it logs process creation and termination events, not network connections; it lacks the destination IP and port fields needed for this rule. Option C (DeviceFileEvents) is wrong because it tracks file creation, modification, and deletion events, which are irrelevant to network connections. Option D (IdentityLogonEvents) is wrong because it captures authentication and logon events from Azure AD, not network-level activities on devices.

458
MCQeasy

You are configuring Microsoft Entra ID Protection. You want to automatically respond to a specific risk level by requiring the user to change their password. Which risk policy should you configure?

A.MFA registration policy
B.Sign-in risk policy
C.Session risk policy
D.User risk policy
AnswerD

User risk policy targets the user account itself, so its remediation action is a password change, satisfying the stem's requirement. Sign-in risk policy instead blocks or demands MFA at authentication, which cannot force a credential reset. Configuring user risk to High and allowing password change enforces the required response.

Why this answer

The user risk policy in Microsoft Entra ID Protection is designed to respond to user risk detections such as leaked credentials, and it can be configured to require a password change (password reset) when a specified user risk level is reached. This directly matches the requirement to automatically respond to a risk level by requiring a password change.

Exam trap

MS-102 often tests the confusion between user risk and sign-in risk policies — candidates must remember that password change is tied to user risk, while MFA is tied to sign-in risk.

How to eliminate wrong answers

Option A is wrong because the MFA registration policy is used to require users to register for MFA, not to respond to risk with a password change. Option B is wrong because the sign-in risk policy responds to sign-in risk by requiring MFA or blocking access, not by forcing a password change. Option C is wrong because there is no 'session risk policy' in Entra ID Protection — session controls are configured within Conditional Access, not as a standalone risk policy.

459
MCQeasy

You are a security administrator for a company that uses Microsoft Defender XDR. You need to investigate a suspicious email that was reported by a user. You want to see the full email details, including headers, attachments, and URLs. Where should you look?

A.Use the Threat analytics dashboard to find the email.
B.Go to the user entity page and view their email activity.
C.In the Microsoft Defender XDR portal, search for the email message ID or subject to open the email entity page.
D.Open the incident related to the email and view the alert details.
AnswerC

The email entity page in the Microsoft Defender XDR portal consolidates the full message, including headers, attachments and URLs, retrievable by message ID or subject. This gives the investigator the complete artefact set needed to assess the reported suspicious email.

Why this answer

The email entity page in the Microsoft Defender XDR portal allows you to search by message ID or subject to view full email details including headers, attachments, and URLs. Option A is incorrect because the Threat analytics dashboard provides information about threats and attack patterns, not individual email details. Option B is incorrect because the user entity page shows user activity and alerts, not email details.

Option D is incorrect because incident details provide alerts and evidence, but not the full email entity with headers and attachments.

460
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) to manage role activations. They have an Azure AD Premium P2 license. The security team wants to require that any activation of the Exchange Administrator role must be approved by a specific group named 'Exchange Approvers'. Additionally, activations must require a ticket number and expire after 6 hours. Which PIM configuration should the administrator modify?

A.Configure the 'Role settings' for the Exchange Administrator role to require approval and set the approvers group
B.Add the Exchange Administrator role to the 'Exchange Approvers' group's eligible assignments
C.Create a PIM alert for activations without a ticket number and set a 6-hour alert threshold
D.Define an access review for the Exchange Administrator role with a 6-hour review duration
AnswerA

In Azure AD PIM, role settings for the Exchange Administrator role live under 'Role settings' in PIM. Editing this configuration lets you toggle 'Require approval to activate' and specify one or more approver groups or users; you can also enforce justification and ticket-number fields. Setting the Exchange Approvers group as the approver group ensures that every activation request is first reviewed by the designated approvers before the role becomes active. This is the only option that actually enforces an approval gate at activation time.

Why this answer

In Azure AD PIM, the 'Role settings' for a specific role (like Exchange Administrator) allow you to configure activation requirements, including requiring approval, specifying approvers (such as the 'Exchange Approvers' group), requiring a ticket number, and setting a maximum activation duration (e.g., 6 hours). This directly meets all the security team's requirements.

Exam trap

The trap here is confusing 'eligible assignments' (who can activate a role) with 'approvers' (who must approve activations), leading candidates to incorrectly select Option B.

How to eliminate wrong answers

Option B is wrong because adding the Exchange Administrator role to the 'Exchange Approvers' group's eligible assignments would make members of that group eligible to activate the role, not approve activations of the role. Option C is wrong because PIM alerts can notify about suspicious activities but cannot enforce a ticket number requirement or set a 6-hour activation duration; those are configured in role settings. Option D is wrong because access reviews are for periodic recertification of role assignments, not for controlling activation duration or requiring approval during activation.

461
MCQhard

You create a custom detection rule in Microsoft Defender XDR using the KQL query shown in the exhibit. The rule is intended to detect lateral movement via SMB. After deploying the rule, you notice that it generates many false positives from legitimate administrative activity. What is the most effective way to reduce false positives?

A.Filter for only inbound SMB connections
B.Remove the join with DeviceProcessEvents
C.Add a filter to exclude specific administrative accounts or IP ranges
D.Increase the time window of the query
AnswerC

Adding a filter to exclude specific administrative accounts or IP ranges is a targeted false-positive reduction technique that preserves the detection logic while eliminating known, legitimate activity. For example, a SecOps team might suppress alerts from their jump-box IPs or privileged service accounts that routinely perform SMB admin tasks, so the rule only fires on anomalies. However, exclusions must be kept narrow and periodically reviewed, or attackers could abuse a broad allowlist to evade detection.

Why this answer

Adding a filter to exclude specific administrative accounts or IP ranges is the most effective way to reduce false positives from legitimate administrative activity. Since the rule detects lateral movement via SMB, legitimate admins may perform similar actions. By excluding known admin accounts or trusted IP ranges, you can suppress alerts for benign activity while still detecting malicious lateral movement.

Exam trap

MS-102 often tests tuning of detection rules, and candidates may think that simply removing joins or changing time windows will reduce false positives. The trap is to overlook that targeted exclusions based on administrative context are the most effective and precise method.

How to eliminate wrong answers

Option A is wrong because filtering for only inbound SMB connections may not address the root cause; lateral movement can involve both inbound and outbound connections, and the false positives may still occur. Option B is wrong because removing the join with DeviceProcessEvents could reduce context and potentially miss correlated events, but it does not specifically target the false positives from administrative activity. Option D is wrong because increasing the time window may capture more events and potentially increase false positives, not reduce them.

462
MCQeasy

Your organization uses Microsoft Defender for Endpoint (MDE). A security analyst needs to investigate a file that was detected as malicious on several devices. The analyst wants to see the file's prevalence across the organization and other related events. Which feature in MDE should the analyst use?

A.File page
B.Alert page
C.Device page
D.Investigation page
AnswerA

The File page in Microsoft Defender for Endpoint is the authoritative location for examining a specific file's organizational footprint. It displays aggregated data on file prevalence across all onboarded devices, identifies every device where the file has been observed, and lists related events and alerts, enabling an analyst to assess the scope of a potential threat and investigate associated activity.

Why this answer

The File page in Microsoft Defender for Endpoint provides a comprehensive view of a specific file, including its prevalence across the organization, a list of devices where it was observed, and related events such as alerts and detections. This allows the security analyst to investigate the file's spread and associated incidents in one centralized location.

Exam trap

The trap here is that candidates often confuse the File page with the Alert page, thinking that alerts are the primary source for file prevalence data, but the File page is specifically designed to show file-level telemetry across the organization, not just alert-triggered events.

How to eliminate wrong answers

Option B (Alert page) is wrong because the Alert page focuses on a specific security incident or alert, not on the file's prevalence across multiple devices or related events. Option C (Device page) is wrong because the Device page shows details about a single device, such as its alerts and software inventory, but does not aggregate file prevalence across the organization. Option D (Investigation page) is wrong because the Investigation page is used for advanced hunting queries and manual investigations, not for a pre-built summary of a file's prevalence and related events.

463
Drag & Dropmedium

Drag and drop the steps to configure Microsoft 365 Groups expiration policy in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Groups expiration policy is set in the admin center with a duration, notification owner, and deletion behavior.

464
Multi-Selecthard

Your company uses Microsoft Entra ID with P2 licenses. You need to configure Privileged Identity Management (PIM) for Azure AD roles. Which THREE actions are possible with PIM?

Select 3 answers
A.Automatically assign a role to all users in a security group
B.Schedule start and end times for role assignments
C.Require Azure MFA during role activation
D.Require approval from a specified group before activating a role
E.Limit role activation to a specific device
AnswersB, C, D

PIM supports time-bound assignments by letting you configure specific start and end dates and times for both eligible and active role assignments. This allows an administrator to grant access for a defined project window or temporary scenario without leaving the role permanently active. The scheduling capability is a core part of managing just-in-time privileged access. After the end time, the assignment expires and no longer grants access.

Why this answer

PIM allows you to configure time-bound role assignments with specific start and end dates, enabling just-in-time access and reducing standing privileges. This is a core feature of PIM for Azure AD roles, supporting both eligible and active assignments with scheduled durations.

Exam trap

The trap here is that candidates may confuse PIM's role activation restrictions with Conditional Access policies, assuming device-based limitations are possible, when in fact PIM only supports MFA, approval, and time-bound settings for activation.

465
MCQhard

Your organization uses Microsoft Defender for Endpoint (Plan 2) and Microsoft Defender for Identity. A security analyst reports that several domain controllers are generating alerts for anomalous logon activity. You need to investigate the scope of the potential compromise across the entire environment, including endpoints, identities, and cloud apps. What is the most efficient approach?

A.Check each workload portal individually and correlate manually
B.Review the alerts in Microsoft Defender for Identity only
C.Review the alerts in Microsoft Defender for Endpoint only
D.Use the Microsoft Defender XDR portal to view the unified incident
AnswerD

Use the Microsoft Defender XDR portal (formerly Microsoft 365 Defender) to view the unified incident, which automatically correlates alerts from all workloads—endpoint, identity, email, and cloud apps—into a single incident with an attack story. This portal provides affected assets, related alerts, evidence, and automated investigation timelines, allowing analysts to see the entire attack chain in one place. It also supports incident management actions such as commenting, assigning, and running automated responses across the integrated workloads.

Why this answer

Microsoft Defender XDR provides a unified incident view that correlates alerts from all workloads. Option A is wrong because checking only endpoints misses identity and cloud app alerts. Option B is wrong because checking only identities misses endpoints.

Option C is wrong because using multiple portals is inefficient.

466
MCQmedium

Your organization uses Microsoft Defender XDR and Microsoft 365 E5 licenses. You need to ensure that when a user is determined to be compromised (e.g., due to a leaked credential), all active sessions are terminated and the user is required to re-authenticate with multi-factor authentication (MFA). You want to automate this process as much as possible. What should you do?

A.In Microsoft Defender for Cloud Apps, create a session policy with the 'Suspend user' governance action and configure it to revoke sessions and require re-authentication.
B.Disable the user account in Microsoft Entra ID.
C.Create a conditional access policy that requires MFA for all users.
D.Manually reset the user's password and sign out of all sessions.
AnswerA

Correct: Automatically terminates sessions and forces MFA re-authentication.

Why this answer

Microsoft Defender for Cloud Apps can create a session policy with the 'Suspend user' governance action, which integrates with Microsoft Entra ID to revoke all active sessions and require the user to re-authenticate with MFA. This automates the process of terminating sessions and enforcing re-authentication when a user is compromised. Option B is incorrect because disabling the user account terminates sessions but does not require MFA re-authentication for future access.

Option C is incorrect because a conditional access policy requiring MFA for all users does not terminate existing sessions; it only applies to new authentication requests. Option D is incorrect because manually resetting the password and signing out of sessions is not automated and does not leverage the capabilities of Microsoft Defender XDR and Microsoft 365 E5 licenses.

Exam trap

Candidates may confuse conditional access policies with session governance actions. Conditional access policies are evaluated at the time of sign-in and do not terminate existing sessions. MDCA's session policies, such as 'Suspend user', can enforce actions that revoke active sessions and prompt re-authentication.

467
MCQmedium

A compliance officer needs to prevent users from copying sensitive data (e.g., credit card numbers) from a finance application into personal email or documents. The solution must inspect the content in real-time and block the action if sensitive data is detected. Which Microsoft Purview feature should the officer configure?

A.Data Loss Prevention (DLP) policies
B.Sensitivity labels
C.Retention labels
D.eDiscovery
AnswerA

DLP policies are the correct choice because they perform real-time content inspection on endpoints and cloud apps, matching against sensitive information types (e.g., credit card numbers, PII) and then enforcing protective actions. A DLP policy can specifically block copy, paste, print, or transfer of that data to unauthorized destinations, and it can also trigger user notifications or incident reports. This is the only option that directly intercepts and prevents user copying actions at the point of resource access.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies are designed to inspect content in real-time as users attempt to copy, paste, or share sensitive data (e.g., credit card numbers) from applications like finance apps into personal email or documents. DLP uses deep content analysis via sensitive information types and policy tips to block the action before the data leaves the controlled environment, meeting the compliance officer's requirement for real-time blocking.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which protect data at rest) with DLP policies (which enforce real-time action blocking), leading them to select sensitivity labels because they think labeling alone prevents copying, but labels do not block user actions in real-time.

How to eliminate wrong answers

Option B is wrong because sensitivity labels classify and protect data at rest (e.g., encryption or visual markings) but do not perform real-time content inspection or block copy/paste actions; they require user or automated labeling after data is created. Option C is wrong because retention labels manage data lifecycle (retention and deletion) based on policies, not real-time content inspection or blocking of data exfiltration. Option D is wrong because eDiscovery is used for searching, preserving, and exporting data for legal or investigative purposes, not for preventing data loss in real-time.

468
MCQmedium

Your organization has 5,000 users and uses Microsoft 365 E3. You are planning to migrate from on-premises Exchange to Exchange Online. You have already synchronized identities using Microsoft Entra Connect. The CIO wants to ensure that users can continue to access their email if the internet connection to Microsoft 365 is temporarily lost. You need to recommend a solution that provides offline access while minimizing cost and administrative overhead. What should you recommend?

A.Configure Outlook to use Cached Exchange Mode.
B.Implement a hybrid deployment and keep some mailboxes on-premises.
C.Deploy a VPN to ensure connectivity.
D.Enable Exchange Online Archiving for all users.
AnswerA

Cached Exchange Mode (CEM) creates a local copy of the user's mailbox in an Offline Outlook Data (.ost) file, enabling full access to synced folders, messages, calendar items, and contacts even when the device is disconnected from the network. When connectivity is restored, the OST synchronizes incremental changes via HTTPS using autodiscover and MAPI over HTTP, making it the correct solution for maintaining productivity during network outages. It also ensures that changes are queued locally and then propagated to Exchange Online, providing a seamless online/offline experience.

Why this answer

Cached Exchange Mode (CEM) downloads a copy of the user's mailbox to a local .ost file, allowing full access to email, calendar, and contacts even when the internet connection to Microsoft 365 is temporarily lost. This meets the CIO's requirement for offline access with zero additional cost and no administrative overhead, as CEM is a built-in feature of Outlook that is already available with Microsoft 365 E3.

Exam trap

The trap here is that candidates often confuse 'offline access' with 'high availability' or 'redundancy,' leading them to choose a hybrid deployment (Option B) or a VPN (Option C), when the simplest and most cost-effective solution is a client-side caching feature already included in the subscription.

How to eliminate wrong answers

Option B is wrong because implementing a hybrid deployment with some mailboxes on-premises increases cost (additional on-premises servers, licensing, and maintenance) and administrative overhead, and does not guarantee offline access for users whose mailboxes are moved to Exchange Online. Option C is wrong because deploying a VPN does not provide offline email access; it only attempts to maintain connectivity, and if the internet is lost, the VPN connection also fails. Option D is wrong because Exchange Online Archiving is a cloud-based feature that stores archived email in the cloud, not locally, so it does not provide offline access and adds cost without solving the stated requirement.

469
MCQeasy

A compliance officer needs to automatically apply a retention label to all documents in SharePoint Online that contain the exact phrase 'Contract'. The label must retain the documents for 10 years. Which Microsoft Purview feature should the officer configure?

A.retention policy applied to the entire site
B.Data Loss Prevention (DLP) policy
C.An auto-apply retention label using a trainable classifier
D.An auto-apply retention label using a content query (KQL)
AnswerD

An auto-apply retention label using a content query (KQL) is the only option that directly satisfies the requirement. In Microsoft Purview, you create an auto-apply retention label policy, select "Apply label to content that matches a query," and enter a KQL expression such as "Contract" to match documents containing that exact phrase. The KQL query runs against the search index, automatically assigns the retention label to matching content, and enforces the configured retention period. This approach is rule-based and deterministic, precisely targeting the literal string "Contract" as specified.

Why this answer

An auto-apply retention label using a content query (KQL) allows you to define a specific keyword or phrase (e.g., 'Contract') to automatically label documents in SharePoint Online that contain that exact text. This meets the requirement to retain documents for 10 years by applying the label based on content matching, without needing a pre-trained classifier.

Exam trap

The trap here is that candidates often confuse auto-apply labels with trainable classifiers, thinking a machine learning model is needed for any content-based labeling, when in fact a simple KQL query is sufficient for exact phrase matching.

How to eliminate wrong answers

Option A is wrong because a retention policy applied to the entire site retains all content in the site, not just documents containing the exact phrase 'Contract', and it does not use a label—it applies retention settings directly without the granularity of label-based auto-application. Option B is wrong because a Data Loss Prevention (DLP) policy is designed to prevent data exfiltration or leakage by blocking or alerting on sensitive content, not to automatically apply retention labels for compliance purposes. Option C is wrong because a trainable classifier uses machine learning to identify patterns or categories (e.g., contracts in general), not an exact phrase match, and requires training and tuning, making it unsuitable for a simple keyword-based requirement.

470
MCQmedium

A security administrator wants to automatically isolate a device in Microsoft Defender for Endpoint whenever a high-severity alert is triggered. The isolation should occur without manual intervention. Which Microsoft Defender XDR feature should be configured?

A.Attack surface reduction rules
B.Automated investigation and response
C.Threat analytics
D.Vulnerability management
AnswerB

Automated investigation and response applies remediation actions automatically once a high-severity alert fires, so isolation occurs with no analyst involvement. This satisfies the stem's no-manual-intervention constraint, unlike custom detections or alert tuning, which identify or refine alerts but do not execute containment themselves.

Why this answer

Automated Investigation and Response (AIR) in Microsoft Defender XDR is designed to automatically respond to threats by running playbooks that can take remediation actions, such as isolating a device, without manual intervention. When a high-severity alert triggers, AIR evaluates the alert and, if configured, executes the isolation action as part of its automated response, meeting the requirement for zero-touch isolation.

Exam trap

The trap here is that candidates often confuse proactive prevention features (like ASR rules) with automated post-breach response capabilities, assuming any security feature that 'blocks' something can also isolate a device automatically.

How to eliminate wrong answers

Option A is wrong because Attack Surface Reduction (ASR) rules are proactive policies that block specific behaviors (e.g., Office apps creating child processes) but do not perform post-breach automated isolation actions. Option C is wrong because Threat Analytics provides intelligence reports on active threats and vulnerabilities but does not execute any automated remediation or device isolation. Option D is wrong because Vulnerability Management identifies and prioritizes software vulnerabilities but lacks the capability to automatically isolate a device in response to an alert.

471
MCQmedium

Your organization uses Microsoft Entra ID. You want to enforce Multi-Factor Authentication (MFA) for all users. You have already configured Conditional Access policies. However, some users are still able to sign in without MFA. What should you check first?

A.Ensure all users have registered for MFA.
B.Verify that the Conditional Access policy is enabled.
C.Confirm that all users are included in the policy's user assignment.
D.Check if there are any exclusions configured.
AnswerC

The user assignment is the principal scope control in a Conditional Access policy. For MFA to apply to every user, the policy's 'Include' list must target 'All users' or a group containing all users. If some users are omitted, they will bypass the policy entirely regardless of other settings. Confirming this assignment is the critical diagnostic step.

Why this answer

The most common reason a Conditional Access policy fails to enforce MFA is that not all users are included in the policy's user assignment. If the policy targets only a subset of users (e.g., a test group), users outside that scope will bypass MFA entirely. The first troubleshooting step is to verify that the policy's 'Users and groups' assignment includes 'All users' or the specific groups covering all users.

Exam trap

The trap here is that candidates often jump to checking exclusions or MFA registration status first, overlooking the fundamental requirement that the policy must actually apply to the user via its assignment scope.

How to eliminate wrong answers

Option A is wrong because MFA registration is a prerequisite for MFA prompts, but even if users are registered, the Conditional Access policy must be correctly scoped to enforce MFA; unregistered users would simply be blocked or prompted to register, not allowed to sign in without MFA. Option B is wrong because if the policy were disabled, no users would be prompted for MFA, but the question states some users are still able to sign in without MFA, implying the policy is enabled but not applying to those users. Option D is wrong because checking exclusions is a valid step, but it is secondary to verifying that all users are included in the policy's assignment; exclusions only matter if users are already included.

472
MCQmedium

You are a security administrator for a company that uses Microsoft Defender XDR. You need to ensure that when a user clicks a malicious link in an email, the URL is automatically blocked and the user is prevented from accessing the site. Which Microsoft Defender XDR component should you configure?

A.Microsoft Defender for Endpoint web content filtering
B.Microsoft Defender for Cloud Apps conditional access app control
C.Microsoft Defender for Identity sign-in alerts
D.Microsoft Defender for Office 365 Safe Links policy
AnswerD

Safe Links in Microsoft Defender for Office 365 scans URLs in emails and documents, and blocks access to malicious sites at time of click. Configuring a Safe Links policy ensures that when a user clicks a malicious link, they are prevented from accessing the site, meeting the requirement.

Why this answer

Safe Links in Microsoft Defender for Office 365 is specifically designed to protect users from malicious URLs in emails and documents by scanning and blocking access at click time. Configuring a Safe Links policy ensures that users are prevented from accessing malicious sites when they click links.

Exam trap

The trap here is assuming that web content filtering or Conditional Access App Control can block email links, but they operate at different layers and do not scan email URLs.

473
Multi-Selecthard

Which TWO of the following are valid methods to enforce device compliance in a Conditional Access policy? (Select two.)

Select 2 answers
A.Require Microsoft Authenticator
B.Require session persistence
C.Require approved client app
D.Require Microsoft Entra hybrid joined device
E.Require device to be marked as compliant
AnswersD, E

Requiring Microsoft Entra hybrid joined device is a valid device compliance enforcement method because it checks that the device is joined to on-premises Active Directory and is synchronized or registered with Microsoft Entra ID (formerly Azure AD). This status confirms organizational ownership and management via Group Policy or SCCM/Intune hybrid scenarios, making it acceptable for Conditional Access device conditions. It is often used as an alternative when Intune MDM compliance is not deployed.

Why this answer

Requiring a Microsoft Entra hybrid joined device ensures the device is joined to both on-premises Active Directory and Microsoft Entra ID, which allows Conditional Access to enforce compliance based on the device's identity and configuration. Option E is correct because requiring the device to be marked as compliant relies on Microsoft Intune (or another MDM) to evaluate device health and policy adherence, and then Conditional Access blocks access if the device is not compliant.

Exam trap

The trap here is that candidates confuse authentication controls (like MFA or app restrictions) with device compliance controls, leading them to select 'Require approved client app' or 'Require Microsoft Authenticator' instead of the correct device-based grants.

474
MCQeasy

Your organization uses Microsoft Defender for Office 365. You need to ensure that emails containing malicious attachments are automatically removed from users' inboxes after detection. What should you configure?

A.Configure a Safe Links policy
B.Configure an anti-spam policy to delete the email
C.Configure a Safe Attachments policy
D.Use the attack simulation training to report the email
AnswerC

Safe Attachments detonates attachments in a sandbox and, when malware is detected, removes or replaces the message, satisfying the requirement for automatic post-detection removal from inboxes. Safe Links only rewrites URLs at click time, so it cannot remove malicious attachments already delivered.

Why this answer

Configure a Safe Attachments policy. Safe Attachments policies in Defender for Office 365 automatically scan email attachments for malicious content and can remove or quarantine emails with detected malware. Option A (Safe Links) protects against malicious URLs, not attachments.

Option B (anti-spam policy) handles spam, not malware in attachments. Option D (attack simulation training) is for phishing simulations, not automatic removal of malicious attachments.

475
MCQmedium

A company wants to block access to Exchange Online from devices that are not compliant with Intune compliance policies. Which Conditional Access grant control should be used?

A.Require device to be marked as compliant
B.Require MFA
C.Require approved client app
D.Require all conditions
AnswerA

This grant control checks a device's Intune compliance status before allowing access to Exchange Online. Non-compliant devices, such as unmanaged or jailbroken devices, are blocked even if the user's credentials are valid. It is the correct choice because it directly enforces the requirement that only devices meeting your organization's security policies can access the service.

Why this answer

To block access to Exchange Online from non-compliant devices, you need to enforce a Conditional Access policy that evaluates device compliance status. The 'Require device to be marked as compliant' grant control checks the device's compliance state reported by Microsoft Intune before granting access. If the device is not compliant, access to Exchange Online is blocked, ensuring only managed and compliant devices can connect.

Exam trap

The trap here is that candidates often confuse 'Require device to be marked as compliant' with 'Require approved client app' or 'Require MFA', thinking any of these can block non-compliant devices, but only the device compliance grant directly evaluates Intune compliance policies.

How to eliminate wrong answers

Option B is wrong because Require MFA only enforces multi-factor authentication, not device compliance; a non-compliant device could still access Exchange Online after MFA. Option C is wrong because Require approved client app restricts access to specific apps (e.g., Outlook mobile) but does not check device compliance; a non-compliant device could use an approved app. Option D is wrong because Require all conditions is not a valid grant control; it is a conceptual option that would require all other controls simultaneously, which is not a specific setting in Conditional Access.

476
MCQhard

A security analyst is using Microsoft 365 Defender Advanced Hunting to investigate a potential malware outbreak. The analyst needs to find all devices where a specific signed executable (known to be malicious) was created in the past 24 hours. Which Advanced Hunting table should be queried to detect the creation of the executable file?

A.DeviceFileEvents
B.DeviceProcessEvents
C.DeviceNetworkEvents
D.DeviceRegistryEvents
AnswerA

DeviceFileEvents is the correct table in Microsoft 365 Defender's advanced hunting schema for this scenario because it records file creation, modification, rename, and deletion events. Its columns include FileName, FolderPath, and Timestamp, allowing you to search for the malicious executable by its exact name and location on disk. Process, network, and registry tables do not provide this file-system telemetry.

Why this answer

The DeviceFileEvents table in Microsoft 365 Defender Advanced Hunting captures file creation, modification, and deletion events. Since the question specifically asks for detecting the creation of a signed executable file, this table provides the necessary data, including file name, path, and timestamp, to identify when and where the malicious executable was created.

Exam trap

The trap here is that candidates often confuse file creation with process execution, mistakenly selecting DeviceProcessEvents because they think of the executable running, but the question explicitly asks for the creation event, which is only captured in DeviceFileEvents.

How to eliminate wrong answers

Option B is wrong because DeviceProcessEvents logs process creation and execution events, not file creation; it would show the executable running but not its initial creation. Option C is wrong because DeviceNetworkEvents records network connections and communications, which are unrelated to local file creation. Option D is wrong because DeviceRegistryEvents tracks registry key modifications, not file system operations like file creation.

477
MCQeasy

An administrator wants to add a second custom domain, 'contoso-europe.com', to their existing Microsoft 365 tenant. The domain 'contoso.com' is already verified. What is the first step the administrator should take?

A.Add the domain in the Microsoft 365 admin center
B.Create a DNS TXT verification record
C.Update the UPN suffixes for users
D.Create a new Microsoft 365 tenant
AnswerA

Adding the domain in the Microsoft 365 admin center is the mandatory initial step. Navigate to Settings → Domains → Add domain, enter the domain name, and the wizard will present verification instructions and the exact TXT record you need. This action creates the domain object in the tenant and initiates the verification process, which is a prerequisite for later DNS and UPN configuration.

Why this answer

Before any DNS records can be created or users can be assigned the new domain, the domain must first be added to the tenant in the Microsoft 365 admin center (or via the Microsoft Graph/Exchange admin center). This step registers the domain in the tenant and generates the required verification TXT record values. Only after the domain is added can the administrator proceed to DNS verification and then configure services.

Exam trap

The trap is that candidates jump straight to DNS record creation because that feels like the 'technical' first step, but the exam expects you to know that the domain must be added to the tenant first so Microsoft can generate the unique verification token.

How to eliminate wrong answers

Option B is wrong because creating the DNS TXT record is the second step — you cannot know the exact TXT value (e.g., MS=msXXXXXXX) until the domain has been added to the tenant, which generates that value. Option C is wrong because updating UPN suffixes is a later step performed after the domain is verified and is used to assign user principal names to the new domain, not to initiate the add-domain workflow. Option D is wrong because creating a new tenant is unnecessary and would actually prevent the new domain from being associated with the existing tenant's users and services — a single tenant can host many verified domains.

478
MCQhard

Refer to the exhibit. A Conditional Access policy is created in Microsoft Entra ID. The policy targets the Office 365 app (which includes Exchange Online). You have 1000 users assigned. What is the immediate effect of this policy on users who are currently signed in?

A.All high-risk users are immediately blocked from accessing email.
B.No immediate effect; users will be blocked on their next sign-in attempt.
C.The policy is invalid because the Office 365 app does not support block.
D.Only users with a sign-in risk of high are blocked.
AnswerB

Conditional Access is an evaluation-time access control: when a user attempts to sign in, Azure AD checks the policy conditions—such as the assigned Office 365 app and the user-risk level—and then applies the Block grant control. Immediately after the policy is saved, there is no background task that scans and revokes existing sessions. The policy only takes effect on the next interactive or non-interactive sign-in attempt, at which point a high user-risk user will be denied access. This is why the policy has no immediate effect and the block occurs at the next sign-in.

Why this answer

Conditional Access policies in Microsoft Entra ID are evaluated at the time of sign-in. They do not terminate existing sessions. Therefore, users who are already signed in will not be affected until their next authentication attempt, at which point the policy's block action will be enforced.

Exam trap

Microsoft often tests the misconception that Conditional Access policies apply immediately to active sessions, when in fact they only take effect on the next sign-in attempt unless combined with session controls like sign-in frequency or continuous access evaluation.

How to eliminate wrong answers

Option A is wrong because the policy targets all users assigned, not only high-risk users; also, Conditional Access does not immediately terminate active sessions. Option C is wrong because the Office 365 app (which includes Exchange Online) fully supports the block grant control in Conditional Access policies. Option D is wrong because the policy does not specify a sign-in risk condition; it applies to all targeted users regardless of risk level.

479
MCQeasy

You are a security administrator. You need to ensure that email messages containing malicious attachments are automatically removed from all mailboxes in your organization after delivery. Which Microsoft Defender for Office 365 feature should you configure?

A.Safe Links
B.Zero-hour auto purge (ZAP)
C.Anti-phishing
D.Safe Attachments
AnswerB

Zero-hour auto purge retroactively removes delivered messages after Microsoft's detonation verdicts reclassify them as malicious, satisfying the requirement to delete threats post-delivery across all mailboxes. Unlike transport rules, which act only in transit, ZAP operates inside mailboxes, so it catches messages already sitting in inboxes when signatures update.

Why this answer

Zero-hour auto purge (ZAP) is the Defender for Office 365 feature that retroactively removes malicious messages from Exchange Online mailboxes after delivery. It works with Safe Attachments and Safe Links to detect threats post-delivery and automatically purge them, which is exactly what the administrator needs.

Exam trap

MS-102 often tests the confusion between Safe Attachments (detonation at delivery) and ZAP (retroactive purge after delivery) — candidates pick Safe Attachments when the question specifies 'after delivery.'

How to eliminate wrong answers

Option A is wrong because Safe Links rewrites and checks URLs at click time to block malicious links — it does not remove email messages containing malicious attachments from mailboxes. Option C is wrong because Anti-phishing policies detect and act on phishing emails at delivery time (or via impersonation protection), but they do not retroactively purge already-delivered messages. Option D is wrong because Safe Attachments detonates attachments in a sandbox to detect malware, but by itself it blocks or replaces the attachment at delivery; it is ZAP that performs the post-delivery purge of the entire message.

480
MCQmedium

Refer to the exhibit. You are configuring a session policy in Microsoft Defender for Cloud Apps. The policy must block downloads when both the app risk is high and the user risk is high. Based on the exhibit, which additional condition should you add to ensure the policy only applies to unsanctioned apps?

A.Add a condition for app risk score to be medium or low.
B.Add a condition for user risk score to be medium.
C.Add a condition for activity to include upload.
D.Add a condition for app tag to be 'unsanctioned'.
AnswerD

Adding a condition for app tag to be 'unsanctioned' explicitly scopes the session policy to only those applications that are marked as unsanctioned in the app catalog. This is the precise way to limit the policy's effect, because app tags are designed for this classification. It ensures that the existing download-blocking rule applies only to unsanctioned apps, fulfilling the stated requirement.

Why this answer

In Microsoft Defender for Cloud Apps session policies, to restrict the policy to unsanctioned apps, you must add a condition on the app tag. Unsanctioned apps are those that have been marked as unsanctioned in Cloud App Catalog. The condition 'app tag equals unsanctioned' ensures the policy only applies to those apps.

The other conditions (app risk score, user risk score, activity) do not filter by sanction status.

Exam trap

The trap is assuming that app risk score correlates with sanction status; candidates might choose app risk score instead of app tag, but they are independent attributes.

How to eliminate wrong answers

Option A is wrong because app risk score is a separate attribute from sanction status; an app can be high risk but sanctioned, or low risk but unsanctioned. Option B is wrong because user risk score is about the user, not the app's sanction status. Option C is wrong because activity type (upload/download) is about the action, not the app's sanction status.

481
MCQeasy

Your company has a hybrid identity configuration with Microsoft Entra Connect Sync. You need to enable password hash synchronization (PHS) for hybrid users. What is the prerequisite?

A.Pass-through authentication agent installed
B.Password writeback enabled
C.Hybrid Identity Administrator role in Microsoft Entra ID
D.Federation with AD FS
AnswerC

Configuring password hash synchronization requires changing tenant-level directory synchronization settings, which is protected by administrative roles. The Hybrid Identity Administrator role in Microsoft Entra ID grants permission to manage provisioning and synchronization, including enabling PHS. A Global Administrator can also perform this task, but Hybrid Identity Administrator is the least-privileged role that can, making it a necessary prerequisite.

Why this answer

The Hybrid Identity Administrator role in Microsoft Entra ID is required to enable password hash synchronization (PHS) because this role grants the necessary permissions to configure directory synchronization settings, including the PHS feature, within the Entra ID tenant. Without this role, the synchronization account used by Microsoft Entra Connect Sync cannot modify the tenant-level PHS toggle, even if the local service account has sufficient permissions on-premises.

Exam trap

The trap here is that candidates often confuse the on-premises administrative permissions (like Enterprise Admin) with the cloud role required to toggle the PHS feature, mistakenly thinking local AD permissions are sufficient, when in fact the Hybrid Identity Administrator role in Entra ID is the specific prerequisite for enabling PHS at the tenant level.

How to eliminate wrong answers

Option A is wrong because the Pass-through Authentication (PTA) agent is an alternative authentication method, not a prerequisite for PHS; PHS and PTA are mutually exclusive for the same user authentication flow, and PHS can be enabled without any PTA agent installed. Option B is wrong because password writeback enables password changes in the cloud to be written back to on-premises Active Directory, which is a separate feature used for self-service password reset (SSPR) and is not required for synchronizing password hashes from on-premises to the cloud. Option D is wrong because federation with AD FS is a different authentication model that bypasses PHS entirely; PHS can be enabled as a backup or standalone authentication method without any federation infrastructure.

482
MCQmedium

An administrator wants to configure automated investigation and response (AIR) in Microsoft 365 Defender so that when a high-severity malware alert is generated for a device from Microsoft Defender for Endpoint, the device is automatically isolated from the network without requiring a security analyst to approve the action. Which configuration step is required?

A.Set the automation level for device isolation to 'Semi - require approval for any remediation'
B.Set the automation level for device isolation to 'Full - remediate threats automatically'
C.Create a custom detection rule that automatically isolates the device
D.Enable 'Automated device isolation' in the Microsoft 365 Defender settings
AnswerB

Setting the automation level to 'Full - remediate threats automatically' lets Microsoft 365 Defender execute remediation actions such as device isolation without analyst approval. This satisfies the stem's requirement that isolation occur automatically when a high-severity malware alert is raised.

Why this answer

Setting the automation level for device isolation to 'Full - remediate threats automatically' in Microsoft Defender for Endpoint's automated investigation and response (AIR) configuration allows the system to automatically isolate a device when a high-severity malware alert is triggered, without requiring analyst approval. This automation level is specifically designed to execute remediation actions like device isolation immediately based on the alert's severity and the device's risk level.

Exam trap

The trap here is that candidates often confuse the 'Full' automation level with requiring approval for all actions, or they mistakenly think a separate toggle like 'Automated device isolation' exists, when in fact the automation level controls all remediation actions including isolation.

How to eliminate wrong answers

Option A is wrong because 'Semi - require approval for any remediation' means that any remediation action, including device isolation, will wait for a security analyst to manually approve it, which contradicts the requirement for automatic isolation without approval. Option C is wrong because creating a custom detection rule is not the standard or recommended method for configuring automated device isolation; AIR automation levels are the native mechanism to control automatic remediation actions. Option D is wrong because 'Automated device isolation' is not a standalone setting in Microsoft 365 Defender; the correct configuration is done through the automation level settings within the device group's AIR policies.

483
MCQmedium

Your company uses Microsoft Entra ID and has an app named App1 that requires permissions to read all user profiles. You need to grant admin consent for App1 to read profiles without requiring each user to consent. What should you do?

A.Create a Conditional Access policy that requires consent for App1.
B.Register a new application in App registrations and assign the required permissions.
C.From Microsoft Entra ID, go to Enterprise applications, select App1, and grant admin consent.
D.Configure the user consent settings to allow users to consent for themselves.
AnswerC

To grant admin consent for App1, navigate to Microsoft Entra ID > Enterprise applications, select App1, then choose Permissions and click the Grant admin consent button. This action applies the app's required permissions to the tenant on behalf of all users, eliminating the need for individual user consent. This is the direct, supported method in the administration center for an existing enterprise application.

Why this answer

Granting admin consent for an enterprise application in Microsoft Entra ID allows a tenant administrator to pre-approve permissions for all users, eliminating the need for individual user consent. This is done by navigating to Enterprise applications, selecting App1, and using the 'Grant admin consent' option, which sends an OAuth 2.0 authorization request with the required permissions (e.g., User.Read.All) on behalf of the entire organization.

Exam trap

The trap here is that candidates often confuse 'granting admin consent' with 'configuring user consent settings' or 'creating a new app registration', not realizing that admin consent is a specific action on the existing enterprise application's permissions blade.

How to eliminate wrong answers

Option A is wrong because Conditional Access policies control access conditions (e.g., location, device state) and cannot be used to grant or require consent for an application; consent is managed via application permissions and consent settings. Option B is wrong because registering a new application would create a separate app identity, not modify App1's existing permissions; the required permissions must be assigned to App1 itself, and admin consent must be granted for that specific app. Option D is wrong because configuring user consent settings to allow self-consent would require each user to individually consent, which contradicts the goal of granting admin consent to avoid user-by-user approval.

484
MCQmedium

An administrator recently added a custom domain 'tailspintoys.com' to their Microsoft 365 tenant and verified it. They now need to configure the domain so that all recipient email addresses for 'info@tailspintoys.com' are delivered to a shared mailbox in Exchange Online. The domain is currently set as internal relay. What should the administrator do first to route email for this domain to Exchange Online?

A.Update the MX record at the DNS registrar to point to Exchange Online
B.Change the domain type from 'Internal relay' to 'Authoritative' in Exchange admin center
C.Create the shared mailbox 'info@tailspintoys.com' in Exchange Online
D.Disable the internal relay option for the domain in the Microsoft 365 admin center
AnswerB

In the Exchange admin center, open Mail flow > Accepted domains, select the tailspintoys.com entry, and set its type to Authoritative. This tells Exchange Online that it is the only authorized mail system for that domain, so it will accept all inbound messages and attempt to deliver them to valid mailboxes in the organization, while generating non-delivery reports for unknown recipients. This is the required first configuration task because neither creating recipients nor updating MX records will make Exchange Online the owner of the address space until the accepted domain type is changed.

Why this answer

When a domain is set to 'Internal relay' in Exchange Online, the service expects to relay messages to an on-premises server for that domain. To have Exchange Online accept and deliver messages directly to a shared mailbox (or any hosted recipient), the domain must be changed to 'Authoritative'. This tells Exchange Online that it is the final destination for all recipients in that domain, enabling local delivery.

Exam trap

The trap here is that candidates often think updating the MX record (Option A) is the first step to route email to Exchange Online, but they overlook that the domain type must be changed to 'Authoritative' first; otherwise, Exchange Online will not deliver messages to cloud recipients even after the MX record is pointed correctly.

How to eliminate wrong answers

Option A is wrong because updating the MX record to point to Exchange Online is necessary for mail flow from the internet, but it does not change how Exchange Online treats the domain internally; if the domain remains 'Internal relay', Exchange Online will still attempt to relay messages for that domain to an on-premises server rather than delivering locally. Option C is wrong because creating the shared mailbox is a subsequent step; the domain must first be set to 'Authoritative' so that Exchange Online recognizes the recipient as local and can deliver to it. Option D is wrong because disabling the internal relay option in the Microsoft 365 admin center is not a valid action; the domain type is configured in the Exchange admin center, not the Microsoft 365 admin center, and simply removing the relay setting does not change the domain to authoritative.

485
MCQmedium

Your organization uses Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps. A user reports receiving a suspicious email with a link to a known phishing site. You need to prevent other users from clicking similar links in the future. What should you configure?

A.Use the attack simulation training to educate users
B.Create a Safe Attachments policy to block the attachment
C.Configure a spam filter policy to block the sender
D.Add the URL to the Tenant Allow/Block List in Microsoft 365 Defender
AnswerD

Tenant Allow/Block List entries for URLs are enforced by Defender for Office 365 at time-of-click, blocking the phishing link for every user in the tenant. This satisfies the requirement to stop others clicking similar links, unlike user-level junk or transport rules.

Why this answer

The Tenant Allow/Block List in Microsoft 365 Defender allows you to block specific URLs across the organization, preventing users from accessing known phishing sites. Option A is incorrect because attack simulation training is for user education, not blocking links. Option B is incorrect because Safe Attachments policies only handle email attachments, not URLs.

Option C is incorrect because spam filter policies manage spam classification, not specific URLs.

486
MCQmedium

A security administrator wants to automatically block a file that is detected as malware on one endpoint from being executed on all other endpoints in the organization. Which Microsoft Defender for Endpoint capability provides this?

A.Attack surface reduction rules
B.Network protection
C.Tamper protection
D.Automated investigation and remediation
AnswerD

Automated investigation and remediation (AIR) in Microsoft Defender for Endpoint directly matches the requirement: when malware is detected on one device, AIR automatically performs an investigation, and then can take response actions including blocking the file's hash and containing the threat across the entire organization. By leveraging cloud-based intelligence, AIR can propagate the block to all endpoints before the malware has a chance to spread or re-enter. This is the only option that provides a post-detection, automated, organization-wide file-blocking capability.

Why this answer

Automated investigation and remediation (AIR) in Microsoft Defender for Endpoint is designed to automatically respond to detected threats by containing or blocking malicious files across the organization. When malware is detected on one endpoint, AIR can trigger a remediation action (e.g., blocking the file hash) that is propagated to all other endpoints via the Microsoft Defender security center, preventing execution elsewhere.

Exam trap

The trap here is that candidates often confuse automated investigation and remediation with proactive controls like attack surface reduction rules, but AIR is specifically the reactive, automated response capability that can block a detected file across all endpoints.

How to eliminate wrong answers

Option A is wrong because attack surface reduction rules are proactive policies that reduce exploit entry points (e.g., blocking Office apps from creating child processes), not a reactive mechanism to block a file already detected as malware across endpoints. Option B is wrong because network protection blocks outbound connections to malicious IPs/domains using the Windows Filtering Platform, not the execution of a specific file hash on endpoints. Option C is wrong because tamper protection prevents unauthorized changes to security settings (e.g., disabling real-time protection), but does not automatically block a detected malware file from running on other machines.

487
MCQmedium

Refer to the exhibit. You are creating a custom role in Microsoft Entra ID for helpdesk staff. What can users assigned this role do?

A.Read user properties and reset passwords
B.Read security groups and reset passwords
C.Create new users and reset passwords
D.Read user properties and assign licenses
AnswerA

This option is correct because the exhibit's custom role permission list contains exactly two entries: 'Read user properties' and 'Reset passwords.' These permissions align precisely with the task of viewing a user's profile and resetting their password, with no extra administrative rights such as creating users or assigning licenses. Therefore, the role description 'Read user properties and reset passwords' accurately and completely reflects the configured permissions.

Why this answer

The custom role shown in the exhibit includes only the 'Users' > 'Basic' > 'Read' permission and the 'Authentication' > 'Passwords' > 'Reset password' permission. This combination allows helpdesk staff to read basic user properties (such as display name, user principal name, and job title) and reset user passwords. It does not grant write access to other user attributes, security groups, or license assignments.

Exam trap

The trap here is that candidates often assume 'reset password' implies full user management or that reading user properties automatically includes reading groups, but Microsoft Entra ID separates these into distinct permission scopes.

How to eliminate wrong answers

Option B is wrong because reading security groups requires the 'Groups' > 'Read' permission, which is not included in this custom role. Option C is wrong because creating new users requires the 'Users' > 'Create' permission, which is not granted here. Option D is wrong because assigning licenses requires the 'Users' > 'Assign license' permission, which is also absent from this role.

488
MCQhard

Your organization uses Microsoft 365 and has enabled Microsoft Entra ID P2 licenses. You need to configure automatic user provisioning for a third-party SaaS application that supports SCIM 2.0. What should you do first in the Microsoft Entra admin center?

A.Add the application from the gallery, then configure provisioning.
B.Configure provisioning in 'App registrations'.
C.Navigate to 'Enterprise applications' and create a new application.
D.Use the 'App registrations' blade to register the app.
AnswerA

This is the only correct sequence for a gallery application that supports SCIM provisioning. You must first add the application from the Azure AD gallery, which creates an enterprise application object with the vendor's prebuilt provisioning template. After it is added, you open the app's Provisioning blade, set the provisioning mode to Automatic, enter the SCIM endpoint URL and an authentication token supplied by the SaaS vendor, and then save and test the connection. This is the standard, supported workflow; provisioning settings and attribute mappings are made available only after the gallery app has been installed.

Why this answer

To configure automatic user provisioning for a third-party SaaS application that supports SCIM 2.0, you must first add the application from the Microsoft Entra gallery. This action creates an enterprise application object in your tenant, which is required to access the provisioning configuration blade. Only after adding the gallery application can you configure the provisioning settings, including the SCIM endpoint URL and token, to enable automated user lifecycle management.

Exam trap

The trap here is that candidates confuse 'App registrations' (for custom app development) with 'Enterprise applications' (for SaaS app provisioning), leading them to choose an option that registers an app instead of adding a gallery application.

How to eliminate wrong answers

Option B is wrong because 'App registrations' is used for custom-developed applications that use OAuth/OpenID Connect, not for provisioning configuration of gallery or non-gallery SaaS apps. Option C is wrong because 'Enterprise applications' does not have a 'create new application' option; you add applications from the gallery or create a non-gallery app via the 'New application' button, but the correct first step is specifically to add from the gallery. Option D is wrong because registering an app in 'App registrations' creates a service principal for a custom app, not the provisioning configuration for a third-party SaaS app that supports SCIM.

489
MCQeasy

A company uses hybrid identity with Azure AD Connect and password hash synchronization. They want to enable Self-Service Password Reset (SSPR) with password writeback so that users can reset their on-premises Active Directory passwords. Which Azure AD license is required?

A.Azure AD Free
B.Azure AD Premium P1
C.Azure AD Premium P2
D.Microsoft 365 E3
AnswerB

Premium P1 includes password writeback and SSPR with on-premises integration.

Why this answer

Azure AD Premium P1 is required for Self-Service Password Reset (SSPR) with password writeback. Password writeback is a premium feature that enables password changes in Azure AD to be written back to on-premises Active Directory via Azure AD Connect. Azure AD Free does not include SSPR with writeback, and Azure AD Premium P2 includes additional features like Identity Protection but is not necessary for this scenario.

Exam trap

The trap is that Microsoft 365 E3 includes Azure AD Premium P1, making it technically sufficient. However, the question asks for the specific Azure AD license, and the correct answer is Premium P1. Candidates may also incorrectly think Premium P2 is required for password writeback.

How to eliminate wrong answers

Option A is wrong because Azure AD Free does not include Self-Service Password Reset (SSPR) with password writeback; it only supports basic SSPR for cloud-only users without writeback. Option C is wrong because Azure AD Premium P2 includes all P1 features plus Identity Protection and Privileged Identity Management, but the extra capabilities are not required for password writeback; P1 is sufficient. Option D is wrong because Microsoft 365 E3 includes Azure AD Free, not Premium P1, and therefore does not support password writeback; a separate Azure AD Premium P1 license or an equivalent E5 plan is needed.

490
MCQhard

Your organization is implementing Microsoft Purview Communication Compliance to detect potential insider trading. You need to scan internal emails for specific patterns and assign reviewers from the legal team. What is the minimum number of policies required?

A.One policy with multiple conditions.
B.Three policies: one for patterns, one for reviewers, and one for storage.
C.Zero, as Communication Compliance does not support custom policies.
D.Two policies: one for each pattern.
AnswerA

A single Communication Compliance policy can combine multiple conditions, such as keyword or sensitive information type matches, to detect insider trading patterns across internal email. Reviewer assignment to the legal team is configured within that same policy, so no additional policies are needed to satisfy both the detection and review requirements.

Why this answer

A single Communication Compliance policy can contain multiple conditions (such as sensitive info types, keyword dictionaries, and trainable classifiers) and can define multiple reviewers or reviewer groups within the same policy. Since the requirement is to scan internal emails for specific patterns AND assign legal reviewers, both can be configured inside one policy, making one the minimum number required.

Exam trap

MS-102 often tests the misconception that each condition or reviewer group requires its own policy, when in fact Communication Compliance policies are designed to bundle multiple conditions and reviewers into a single policy.

How to eliminate wrong answers

Option B is wrong because reviewers and patterns are configured within the same policy — there is no separate 'storage' policy concept in Communication Compliance, and splitting patterns across policies is unnecessary. Option C is wrong because Communication Compliance fully supports custom policies with custom conditions and reviewers. Option D is wrong because multiple patterns can be combined as conditions inside a single policy; you do not need one policy per pattern.

491
MCQmedium

An organization wants to allow users to sign in to Microsoft 365 using their on-premises Active Directory credentials but does not want to synchronize password hashes to the cloud. They also want to eliminate the need for users to re-enter their credentials when accessing cloud resources from domain-joined devices. Which combination of authentication methods should they implement?

A.Pass-through Authentication (PTA) with Seamless Single Sign-On (SSO)
B.Federation with Active Directory Federation Services (AD FS)
C.Password Hash Sync (PHS) with Seamless SSO
D.Cloud-only authentication with MFA
AnswerA

Pass-through Authentication validates credentials directly against on-premises Active Directory, so no password hashes reach Microsoft Entra ID. Seamless SSO then issues a desktop SSO token from the domain-joined device, removing repeated credential prompts for cloud resources.

Why this answer

Pass-through Authentication (PTA) validates user passwords directly against on-premises Active Directory without storing password hashes in the cloud, satisfying the requirement to avoid hash synchronization. Seamless SSO eliminates the need for users to re-enter credentials on domain-joined devices by using Kerberos delegation to silently authenticate against Microsoft Entra ID, meeting both stated needs.

Exam trap

The trap here is that candidates often confuse Seamless SSO as being exclusive to Password Hash Sync, but it is also fully supported with Pass-through Authentication, and the key differentiator is the requirement to avoid password hash synchronization.

How to eliminate wrong answers

Option B (Federation with AD FS) is wrong because it requires deploying and maintaining additional federation infrastructure and does not inherently avoid password hash synchronization; AD FS still relies on password validation against on-premises AD but introduces complexity and potential single points of failure. Option C (PHS with Seamless SSO) is wrong because Password Hash Sync explicitly synchronizes password hashes to the cloud, which the organization wants to avoid. Option D (Cloud-only authentication with MFA) is wrong because it does not use on-premises Active Directory credentials at all, requiring users to have separate cloud identities and failing the requirement to authenticate against on-premises AD.

492
MCQeasy

Your organization is a small business with 200 users. You use Microsoft 365 Business Premium, which includes Microsoft Defender for Business (the small business version of Defender for Endpoint) and Microsoft Defender for Office 365 Plan 1. You want to protect against ransomware by blocking malicious processes and behaviors on endpoints. You also need to enable automated investigation and response for common threats. However, your IT team has limited security expertise and wants a simple configuration that provides out-of-the-box protection without custom policies. What should you do?

A.Configure Safe Attachments policies in Microsoft Defender for Office 365 to block ransomware attachments.
B.Enable the default security baseline in Microsoft Defender for Business, which includes attack surface reduction rules and automated investigation.
C.Create custom attack surface reduction rules in Microsoft Defender for Business to block ransomware behaviors.
D.Deploy a third-party endpoint detection and response (EDR) solution alongside Microsoft Defender for Business.
AnswerB

Enabling the default security baseline in Microsoft Defender for Business provides a preset collection of endpoint protection settings, including attack surface reduction rules, real-time antivirus, tamper protection, and automated investigation and remediation. This baseline is curated by Microsoft to balance security with usability, making it ideal for small businesses that lack dedicated security staff. It directly addresses ransomware behaviors by blocking common exploit techniques and automatically responding to alerts without manual configuration.

Why this answer

Microsoft Defender for Business includes a default security baseline that turns on recommended attack surface reduction (ASR) rules, next-generation antivirus, and automated investigation and response (AIR) out of the box. For a 200-user shop with limited security expertise, enabling this baseline delivers ransomware-blocking behavior rules and automated remediation without requiring custom policy authoring. This matches the requirement for simple, out-of-the-box protection.

Exam trap

MS-102 often tests the difference between email-layer protection (Safe Attachments) and endpoint behavior blocking (ASR/AIR) — candidates pick Safe Attachments because 'ransomware' appears in email, but the question specifies blocking malicious processes on endpoints.

How to eliminate wrong answers

Option A is wrong because Safe Attachments in Defender for Office 365 Plan 1 protects against malicious email attachments, not endpoint process behaviors — it does not block ransomware execution on endpoints, which is the stated requirement. Option C is wrong because creating custom ASR rules requires security expertise to tune rule IDs, exclusions, and audit-vs-block modes, contradicting the 'limited expertise, simple configuration' constraint; the default baseline already includes recommended ASR rules. Option D is wrong because deploying a third-party EDR alongside Defender for Business adds cost, complexity, and potential agent conflicts, and is unnecessary since Defender for Business already provides EDR and AIR capabilities.

493
MCQmedium

A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a user receives a phishing email and clicks a link to a known malicious domain. Which advanced hunting table should the analyst query to track the clicked URL?

A.EmailEvents
B.EmailUrlInfo
C.EmailAttachmentInfo
D.DeviceEvents
AnswerB

This table is the authoritative source in the email schema for URL information, including the original URL, domain, and the disposition (e.g., clicked, not clicked) associated with links in emails. It's directly structured for link-level analysis and is the correct starting point when building a custom detection for clicked URLs. You can join it with EmailEvents on NetworkMessageId to correlate click events with the email's delivery and recipient.

Why this answer

The EmailUrlInfo table in Advanced Hunting for Microsoft Defender XDR contains records of URLs that were present in emails, including the URL domain and whether the link was clicked. By joining EmailEvents with EmailUrlInfo on the NetworkMessageId, the analyst can identify when a user clicked a URL that leads to a known malicious domain, making it the correct table for tracking clicked URLs.

Exam trap

The trap here is that candidates often confuse EmailUrlInfo (which stores URL metadata and supports click tracking) with EmailEvents (which only contains email flow data), leading them to incorrectly select EmailEvents as the primary table for URL click analysis.

How to eliminate wrong answers

Option A is wrong because EmailEvents captures metadata about email delivery events (e.g., sender, recipient, delivery action) but does not include the specific URLs contained in the email or click actions. Option C is wrong because EmailAttachmentInfo tracks file attachments in emails, not URLs or link clicks. Option D is wrong because DeviceEvents logs system-level events on endpoints (e.g., process creation, registry changes) and does not contain email URL click data.

494
MCQeasy

An organization wants to prevent users from running executable files from the Windows Temp folder. Which Microsoft Defender for Endpoint capability should be configured?

A.Attack surface reduction rules
B.Network protection
C.Exploit protection
D.Controlled folder access
AnswerA

Attack surface reduction (ASR) rules are a Windows Defender Exploit Guard capability that can specifically block process creation from common temporary folders (such as %Temp% and %AppData%) using a predefined rule like 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' or the explicit temp-folder rule, preventing malware from launching from file paths where droppers commonly execute. ASR rules are client-side, configured via Microsoft Intune, Configuration Manager, or GPO, and operate before the executable is allowed to spawn by intercepting process creation in the kernel and user-mode. This makes ASR the correct choice because it directly restricts executable execution based on file location and reputation, rather than merely restricting network or data access.

Why this answer

Attack surface reduction (ASR) rules are a Microsoft Defender for Endpoint capability that can block executable files from running from specific locations, such as the Windows Temp folder. Rule GUID 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2 specifically targets this behavior by preventing executables and scripts from launching from temporary folders. This is the correct capability because ASR rules are designed to reduce the attack surface by controlling common malware entry points and persistence mechanisms.

Exam trap

The trap here is that candidates often confuse Controlled folder access (which protects files from modification) with execution control, or they mistakenly think Network protection can block local file execution because it sounds like a broad security measure.

How to eliminate wrong answers

Option B (Network protection) is wrong because it prevents users from accessing malicious websites or IP addresses, not from running local executable files from a folder. Option C (Exploit protection) is wrong because it applies mitigations to system processes and applications to prevent exploitation of vulnerabilities, such as heap spray or code injection, not to block execution from a specific folder path. Option D (Controlled folder access) is wrong because it protects folders from unauthorized changes by untrusted applications, such as ransomware encryption, but does not block the execution of executables from the Temp folder.

495
MCQhard

Your organization uses Microsoft Defender for Endpoint (Plan 2) and Microsoft Defender for Identity. A user reports that their device is running slowly and exhibiting unusual network traffic. You investigate in Microsoft Defender XDR and see a high number of alerts for the device. You need to determine if the device is compromised and, if so, initiate an automated investigation. What should you do first?

A.Isolate the device from the network immediately
B.Initiate a Live Response session to gather forensic data
C.Use the Microsoft Defender XDR portal to trigger an automated investigation on the device
D.Run a full antivirus scan from Microsoft Defender Antivirus
AnswerC

Triggering automated investigation from the Microsoft Defender XDR portal initiates the built-in response workflow, gathering evidence and applying remediation actions across the device. This directly addresses the requirement to determine compromise and start automated investigation.

Why this answer

Using the Microsoft Defender XDR portal to trigger an automated investigation leverages the full XDR capabilities to analyze the device and determine if it is compromised. Option A is incorrect because isolating the device is a containment action, not the first step to determine compromise. Option B is incorrect because Live Response is a manual forensic tool, not an automated investigation.

Option D is incorrect because running a full antivirus scan is not an automated investigation and may not detect advanced threats.

496
MCQhard

Refer to the exhibit. You run the KQL query and see that a device named 'WORKSTATION42' has made 1500 connections to a public IP address 203.0.113.55 in the last day. You suspect the device may be compromised. What should you do next to gain the most context?

A.Isolate the device immediately using Microsoft Defender for Endpoint
B.Expand the query to join with DeviceProcessEvents to see which process initiated the connections
C.Add the IP address to the Tenant Allow/Block List to block it
D.Create a Safe Links policy to block the IP address
AnswerB

Expanding the Advanced Hunting query with a join to DeviceProcessEvents is the correct next step because it lets you identify which executable initiated each connection. DeviceNetworkEvents already records InitiatingProcessId, but combining it with DeviceProcessEvents using DeviceId, Timestamp, and ProcessId enables you to see the full process details, command-line arguments, and parent process. This tells you whether the traffic is from a known legitimate application or an unknown/malicious process, giving you a foundation for a reasoned containment decision.

Why this answer

Expanding the query to join with DeviceProcessEvents will provide context on which process initiated the connections, helping determine if the activity is malicious or benign. This is the next logical step in an investigation before taking containment actions.

Exam trap

Candidates may jump to containment (isolate) or blocking, but the question asks for the next step to gain context, so investigation via additional queries is correct.

How to eliminate wrong answers

Option A is wrong because isolating the device immediately is a containment action that should be taken after sufficient evidence, not as a first step to gain context. Option C is wrong because adding the IP to the Tenant Allow/Block List is a mitigation that may be premature without understanding the process. Option D is wrong because Safe Links policies are for email URL protection, not for blocking IP addresses from endpoint connections.

497
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You need to generate alerts when a user downloads more than 100 files from SharePoint Online within 10 minutes. What should you configure?

A.Create an activity policy
B.Create an app discovery policy
C.Create a session policy
D.Create an OAuth app policy
AnswerA

Activity policies in Microsoft Defender for Cloud Apps evaluate user actions against thresholds and generate alerts or governance actions. Configuring one with a file-download criterion and a 100-file count within a 10-minute window detects the mass-download behaviour.

Why this answer

Activity policies in Microsoft Defender for Cloud Apps are designed to monitor user activities across connected apps and generate alerts when specific conditions are met, such as a user downloading more than 100 files from SharePoint Online within 10 minutes. This is a classic anomaly detection scenario that activity policies handle natively. The other policy types serve different purposes: app discovery for shadow IT, session policies for conditional access, and OAuth app policies for app permissions.

Exam trap

MS-102 often tests the confusion between activity policies (monitor user actions) and session policies (control access in real-time); candidates may pick session policy thinking it can alert on download volume, but session policies are for inline enforcement, not threshold-based alerting.

How to eliminate wrong answers

Option B is wrong because app discovery policies are used to identify unsanctioned cloud apps (shadow IT) based on traffic logs, not to monitor user file download activity. Option C is wrong because session policies control real-time session behavior (e.g., block download, require step-up authentication) but do not generate alerts based on activity thresholds. Option D is wrong because OAuth app policies govern the permissions and access of OAuth applications, not user activity patterns.

498
MCQhard

A security administrator wants to block executable files from running from writable system directories such as %TEMP% and %APPDATA% on Windows devices. Which attack surface reduction (ASR) rule should be enabled?

A.Block executable files from running unless they meet a prevalence, age, or trusted list criterion.
B.Block Office communication application from creating child processes.
C.Block credential stealing from the Windows local security authority subsystem (lsass.exe).
D.Block executable content from email client and webmail.
AnswerA

This is the correct Attack Surface Reduction (ASR) rule, GUID 01443614-cd74-433a-b99e-2ecdc07bfc25, which blocks executables that lack sufficient prevalence, age, or a trusted-list entry. It leverages cloud-delivered reputation checks and admin-defined trusted files to stop unknown binaries that commonly execute from writable system directories such as %TEMP%, %APPDATA%, and C:\Users\Public, where persistence mechanisms are often planted. This directly enforces the requirement to block executable files from running from writable system locations while still allowing known legitimate software.

Why this answer

The ASR rule 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' (GUID: 01443614-cd74-433a-b99e-2ecdc07bfc25) is designed specifically to block executables (e.g., .exe, .dll, .scr) from running from writable locations like %TEMP% and %APPDATA% unless they have sufficient global prevalence, are older than a certain age, or are on a trusted list. This directly addresses the administrator's requirement to prevent untrusted executables from executing from these directories.

Exam trap

The trap here is that candidates often confuse the 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' rule with the 'Block executable content from email client and webmail' rule, mistakenly thinking the latter covers all executable execution from writable directories when it only applies to email/webmail sources.

How to eliminate wrong answers

Option B is wrong because 'Block Office communication application from creating child processes' targets Microsoft Office communication apps (e.g., Outlook, Teams) from spawning child processes, which is a different attack vector (e.g., script-based attacks), not executable files from writable directories. Option C is wrong because 'Block credential stealing from the Windows local security authority subsystem (lsass.exe)' specifically protects LSASS from credential dumping via tools like Mimikatz, not from executables running in %TEMP% or %APPDATA%. Option D is wrong because 'Block executable content from email client and webmail' prevents executable attachments from being launched from email clients (e.g., Outlook, Gmail), which is a different entry point than local writable system directories.

499
Multi-Selecteasy

A company is deploying Microsoft Defender for Office 365 to protect against advanced threats. Which two features are available only in Defender for Office 365 Plan 2 and not in Plan 1? (Choose two.)

Select 2 answers
A.Automated Investigation & Response
B.Anti-phishing
C.Safe Attachments
D.Safe Links
E.Threat Explorer
AnswersA, E

Automated Investigation and Response orchestrates multi-stage remediation across mailboxes, triggered automatically when alerts fire. It is licensed exclusively with Defender for Office 365 Plan 2; Plan 1 provides only manual investigation and basic alerting, so this feature satisfies the Plan 2-only constraint.

Why this answer

Options A and E are correct. Automated Investigation & Response (AIR) and Threat Explorer are only available in Defender for Office 365 Plan 2. Anti-phishing, Safe Attachments, and Safe Links are available in both Plan 1 and Plan 2.

500
MCQmedium

Your company has a Microsoft 365 E5 subscription. You need to prevent users from sharing files containing credit card numbers with external users. What should you configure?

A.A retention policy for SharePoint sites.
B.An information barrier policy.
C.A sensitivity label with encryption.
D.A DLP policy that blocks sharing of content with sensitive info type.
AnswerD

A DLP policy that blocks sharing of content matching a sensitive information type directly enforces the credit card number constraint, since Microsoft Purview's built-in credit card sensitive info type detects those patterns and blocks external sharing in Microsoft 365 E5.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft 365 can detect sensitive information types such as credit card numbers and block sharing with external users. DLP policies are designed to prevent accidental or intentional sharing of sensitive data across Exchange, SharePoint, OneDrive, and Teams, making it the correct control for this requirement.

Exam trap

MS-102 often tests the distinction between DLP (which blocks sharing based on content inspection) and sensitivity labels (which classify and protect but do not automatically block sharing based on content), so candidates who pick sensitivity labels miss the requirement for automatic blocking.

How to eliminate wrong answers

Option A is wrong because a retention policy governs how long content is kept or deleted, not whether it can be shared externally. Option B is wrong because information barrier policies prevent specific users or groups from communicating with each other, not from sharing files containing sensitive data with external users. Option C is wrong because a sensitivity label with encryption protects content but does not automatically block sharing based on the presence of credit card numbers; it requires user action or auto-labeling, and encryption alone does not prevent external sharing if the user chooses to share.

501
MCQhard

A security analyst needs to create a custom detection rule in Microsoft 365 Defender that triggers when a suspicious PowerShell process (e.g., using -EncodedCommand) is detected on a device, and within 5 minutes, an outbound network connection to a known malicious IP address occurs. Which two advanced hunting tables must be joined?

A.DeviceProcessEvents and DeviceNetworkEvents
B.DeviceEvents and DeviceFileCertificateInfo
C.IdentityLogonEvents and CloudAppEvents
D.EmailEvents and EmailAttachmentInfo
AnswerA

DeviceProcessEvents records the creation of processes with full command-line arguments, capturing activities such as launching PowerShell or other executables. DeviceNetworkEvents logs network connections to remote endpoints, including destination IPs and ports. By joining these tables on DeviceId within a time window, an analyst can identify a specific process making an outbound connection, which is exactly the pattern needed for this custom detection.

Why this answer

The custom detection rule requires correlating a suspicious PowerShell process event with a subsequent outbound network connection to a malicious IP within a 5-minute window. DeviceProcessEvents contains process creation data (e.g., command line, process name) for detecting encoded PowerShell commands, while DeviceNetworkEvents logs network connections (destination IP, port, protocol). Joining these two tables on DeviceId and a time range allows the rule to identify the sequence of a process event followed by a network event from the same device.

Exam trap

The trap here is that candidates may confuse the purpose of DeviceEvents (which covers broader system events like driver loads or registry changes) with DeviceProcessEvents, or mistakenly think cloud or email tables are relevant to endpoint-based process and network correlation.

How to eliminate wrong answers

Option B is wrong because DeviceEvents and DeviceFileCertificateInfo are used for tracking system-level events (e.g., driver loading, registry changes) and file certificate information, not for correlating process execution with network connections. Option C is wrong because IdentityLogonEvents and CloudAppEvents track user authentication and cloud application activity, not device-level process or network events. Option D is wrong because EmailEvents and EmailAttachmentInfo are focused on email delivery and attachment metadata, which are irrelevant to detecting PowerShell process behavior and outbound network connections on endpoints.

502
MCQmedium

A company uses Azure AD Conditional Access to enforce MFA for all cloud apps. They have some users who are physically located in countries that are considered high-risk by the security team. The team wants to require device compliance (as defined by Intune) for sign-ins from those specific countries, while still requiring MFA from all other locations. How should the administrator configure the Conditional Access policy?

A.Create two Conditional Access policies: one for the high-risk countries requiring MFA and device compliance, and another for all other locations requiring only MFA
B.Create a single Conditional Access policy that includes both conditions (locations) and grant controls (MFA and device compliance) with an 'OR' operator
C.Use Azure AD Identity Protection to automatically evaluate location risk, and let Conditional Access apply the same policy to all users
D.Configure a single Conditional Access policy with multiple location conditions and multiple grant controls using an 'AND' operator
AnswerA

A Conditional Access policy applies one set of grant controls to all users who match its conditions; it cannot vary those controls (e.g., MFA vs. MFA + device compliance) depending on which location matched. By creating two policies with distinct named locations — one for the specified high-risk countries and one for all other locations (with those countries excluded) — you ensure that users in the high-risk countries only match the first policy and must satisfy both MFA and device compliance, while users elsewhere match only the second policy and are only challenged with MFA. This design respects the logic that each policy is evaluated independently and grants are additive when multiple policies apply.

Why this answer

Conditional Access policies are evaluated independently, and each policy can target specific conditions with distinct grant controls. By creating two separate policies—one for high-risk countries requiring both MFA and device compliance, and another for all other locations requiring only MFA—the administrator can enforce the exact requirements per location group. This approach avoids conflicts and ensures that users in high-risk countries are subject to stricter controls while others are not.

Exam trap

The trap here is that candidates often think a single policy can combine multiple location conditions with an 'AND' operator, but Conditional Access treats multiple locations within one policy as an 'OR' condition, making it impossible to enforce different grant controls for different location groups in one policy.

How to eliminate wrong answers

Option B is wrong because using an 'OR' operator between grant controls (MFA OR device compliance) would allow sign-ins that meet either requirement, not both; the requirement is to enforce both MFA and device compliance for high-risk countries. Option C is wrong because Azure AD Identity Protection evaluates sign-in risk (e.g., anonymous IP, leaked credentials) not geographic location risk; it cannot be used to enforce device compliance based on country. Option D is wrong because a single policy with multiple location conditions using an 'AND' operator would require a user to be in all specified locations simultaneously, which is impossible; Conditional Access evaluates location conditions with an 'OR' logic within a single policy, not 'AND'.

503
MCQhard

Refer to the exhibit. You are analyzing a KQL query in Microsoft Defender XDR Advanced Hunting. The query returns a list of devices where PowerShell or cmd.exe with encoded commands executed more than 5 times in the last 7 days. The security team suspects that one of the devices is compromised due to excessive use of encoded commands. However, a legitimate administrative script uses encoded commands regularly. How can you refine the query to reduce false positives while still detecting potentially malicious activity?

A.Increase the Count threshold to 10.
B.Add a filter to exclude processes signed by a trusted certificate or running under specific service accounts.
C.Remove cmd.exe from the FileName filter.
D.Change the time range to 1 day instead of 7 days.
AnswerB

Add a filter such as `where Process.Signer != 'Microsoft Corporation'` or `where AccountName !in ('svc_backup', 'svc_monitoring')` to exclude processes from known trusted sources. Many legitimate automation scripts are signed by an internal certificate authority or run under dedicated service accounts, so these allowlist-style filters reduce noise without hiding unknown or unsigned binaries. This is the correct approach because it preserves detection of suspicious, unsigned processes that lack a trustworthy signer and are not expected to run under service accounts. It targets the actual root cause: the alert currently flags benign, trusted execution as suspicious.

Why this answer

Adding a filter to exclude processes signed by a trusted certificate or running under specific service accounts directly addresses the legitimate administrative script that uses encoded commands. This refinement reduces false positives by allowing trusted, signed executables or known service accounts to bypass detection, while still flagging unsigned or anomalous encoded command executions that are more likely malicious. In Microsoft Defender XDR Advanced Hunting, you can use the `SigningCertificate` or `InitiatingProcessAccountName` fields in the KQL query to implement this exclusion.

Exam trap

The trap here is that candidates often choose to increase the count threshold (Option A) thinking it will reduce false positives, but this is a blunt instrument that also reduces true positives, whereas the correct approach is to use contextual filters like certificate or account exclusions to surgically remove known-good activity.

How to eliminate wrong answers

Option A is wrong because simply increasing the count threshold to 10 does not differentiate between legitimate and malicious use; it only reduces sensitivity, potentially missing real threats while still including false positives from the trusted script. Option C is wrong because removing cmd.exe from the FileName filter ignores that cmd.exe can also be used with encoded commands in attacks (e.g., Base64-encoded payloads), and the legitimate script may use PowerShell, not cmd.exe, so this would not address the false positive from PowerShell. Option D is wrong because changing the time range to 1 day instead of 7 days reduces the observation window, which may cause you to miss malicious activity that occurs over a longer period and does not solve the core issue of distinguishing legitimate from malicious encoded command usage.

504
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You need to generate a report of all external users who have shared sensitive files from SharePoint Online. Which feature should you use?

A.OAuth app policies
B.Activity log
C.App permissions report
D.Cloud Discovery
AnswerB

The Defender for Cloud Apps activity log provides a comprehensive audit trail of user operations across connected cloud apps, including file-specific actions such as 'share file externally' and 'download file.' It supports granular filtering by user, IP address, device, and activity type, and you can specifically filter for activities where the target of the sharing is an external user. This makes it the definitive data source for investigating user file sharing, as it records both the actor and the action in near real-time. Alerts from these activities can also be routed to Microsoft Sentinel.

Why this answer

The Activity log in Microsoft Defender for Cloud Apps captures detailed records of user activities across connected apps, including file-sharing events in SharePoint Online. By filtering the log for external users and sensitive file types, you can generate a precise report of external sharing activities. This is the correct feature because it directly records the specific actions needed for the report.

Exam trap

The trap here is that candidates often confuse the Activity log (which records user actions) with the App permissions report (which lists app-level permissions), leading them to select Option C when they need to track individual user sharing events.

How to eliminate wrong answers

Option A is wrong because OAuth app policies govern third-party app permissions and consent, not user file-sharing activities. Option C is wrong because the App permissions report lists permissions granted to apps, not individual user actions like sharing files. Option D is wrong because Cloud Discovery analyzes shadow IT usage and traffic patterns, not specific file-sharing events in SharePoint Online.

505
MCQeasy

You are implementing Microsoft Entra Verified ID. Which technology does it use to create decentralized digital identities?

A.Decentralized Identifiers (DIDs)
B.OpenID Connect
C.OAuth 2.0
D.Security Assertion Markup Language (SAML)
AnswerA

Decentralized Identifiers (DIDs) are the foundation of Microsoft Entra Verified ID. They are a W3C standard for globally unique identifiers that are cryptographically verifiable and do not require a central registration authority. DIDs enable the issuer, holder, and verifier to interact via verifiable credentials, with the DID document containing public keys and service endpoints used to establish trust. The core is that DIDs provide a decentralized, self-sovereign identity layer, not merely an authentication protocol.

Why this answer

Microsoft Entra Verified ID uses Decentralized Identifiers (DIDs) as the core technology to create decentralized digital identities. DIDs are globally unique identifiers that are cryptographically verifiable and do not rely on a centralized registry, enabling self-sovereign identity scenarios where users control their own identity data.

Exam trap

The trap here is that candidates confuse authentication/authorization protocols (OpenID Connect, OAuth 2.0, SAML) with the underlying decentralized identity infrastructure (DIDs), mistakenly thinking these protocols are used to create the identity itself rather than to secure access to it.

How to eliminate wrong answers

Option B is wrong because OpenID Connect is an authentication protocol built on top of OAuth 2.0, used for verifying user identity via ID tokens, not for creating decentralized identifiers. Option C is wrong because OAuth 2.0 is an authorization framework that issues access tokens, not a technology for generating decentralized digital identities. Option D is wrong because SAML is an XML-based federated identity standard for single sign-on (SSO) that relies on a centralized identity provider, not a decentralized identity model.

506
Multi-Selecthard

You are investigating an incident in Microsoft Defender XDR. The incident involves multiple alerts from different sources. Which THREE actions should you take during the investigation?

Select 3 answers
A.Review the incident timeline to understand the sequence of events.
B.Delete all emails related to the incident from all mailboxes.
C.Use advanced hunting to query for related activities across devices and identities.
D.Isolate affected devices from the network using Microsoft Defender for Endpoint.
E.Reset the passwords of all user accounts involved.
AnswersA, C, D

Reviewing the incident timeline is the critical first step in an XDR investigation because it presents a chronological, correlated view of all alerts, user activities, and device events associated with the incident. This lets you reconstruct the attack chain from initial access to lateral movement and data exfiltration, identify which entities are truly affected, and establish what evidence must be preserved. Without this context, any containment or remediation action may be premature or miss the root cause.

Why this answer

Option A is correct because reviewing the incident timeline in Microsoft Defender XDR lets you correlate the multiple alerts from different sources into a chronological sequence, revealing the initial access, lateral movement, and impact so you can scope the incident accurately. Option C is correct because advanced hunting uses Kusto Query Language (KQL) against the unified schema (DeviceEvents, IdentityLogonEvents, EmailEvents, etc.) to pivot beyond the original alerts and uncover related activity across devices and identities that the incident view may not surface. Option D is correct because isolating affected devices via Microsoft Defender for Endpoint (through the device page or the 'Isolate device' action) contains the threat, prevents further lateral movement or command-and-control communication, and preserves forensic evidence while investigation continues.

Option B is not appropriate as a standard investigation step because bulk-deleting emails destroys evidence and is a remediation action (soft delete/hard delete via Purview) that should only follow confirmed scope, not precede it. Option E is also not a default investigation action because mass password resets can disrupt business operations and lock out users; credential remediation should be targeted based on confirmed compromise rather than applied to all involved accounts.

Exam trap

MS-102 often tests the distinction between investigation actions (timeline, hunting, isolation) and remediation actions (deleting emails, resetting passwords), so candidates must recognize that remediation should follow investigation, not replace it.

507
MCQmedium

A security administrator wants to monitor and control user downloads from a third-party SaaS application (e.g., Box) in real time. The administrator needs to apply session-level policies to block downloads based on risk. Which Microsoft 365 Defender feature should be used?

A.Cloud Discovery
B.Conditional Access App Control
C.App Connectors
D.Anomaly Detection Policies
AnswerB

Conditional Access App Control is the session-control engine in Microsoft Defender for Cloud Apps, integrated directly with Azure AD Conditional Access. When a user signs in, Azure AD routes the session through the Defender for Cloud Apps reverse proxy, allowing identity-aware policies to inspect the user's actions in real time and enforce constraints such as block download, monitor only, or require protection. This makes it the correct choice for monitoring and controlling user downloads from a third-party SaaS application at the individual session level.

Why this answer

Conditional Access App Control (CAAC) is the correct feature because it enables real-time session-level monitoring and control of user activities within third-party SaaS applications like Box. By integrating with Microsoft Defender for Cloud Apps, CAAC can apply policies to block downloads based on risk signals such as user location, device compliance, or anomalous behavior, all within the user's active session.

Exam trap

The trap here is that candidates often confuse App Connectors (API-based control) with Conditional Access App Control (proxy-based session control), mistakenly thinking API integration can enforce real-time download blocks when it only provides retrospective or policy-based actions on stored data.

How to eliminate wrong answers

Option A is wrong because Cloud Discovery is a tool for identifying shadow IT and assessing cloud app usage from traffic logs, not for applying real-time session-level download controls. Option C is wrong because App Connectors provide API-based visibility and control for data at rest (e.g., file scanning) but cannot enforce session-level policies in real time. Option D is wrong because Anomaly Detection Policies identify suspicious activities after they occur (e.g., impossible travel) and trigger alerts, not block downloads in real time within a session.

508
Multi-Selectmedium

Your organization is planning to migrate from on-premises Exchange to Exchange Online. You need to choose a migration strategy. Which TWO statements about migration methods are correct?

Select 2 answers
A.A hybrid migration requires that you do not synchronize on-premises Active Directory with Microsoft Entra ID.
B.A minimal hybrid deployment allows you to manage mailboxes in both on-premises and Exchange Online.
C.A staged migration can be used to migrate mailboxes from Exchange 2019 to Exchange Online.
D.A cutover migration is suitable for organizations with fewer than 2000 mailboxes.
E.An IMAP migration migrates email, contacts, and calendar data.
AnswersB, D

A minimal hybrid deployment deliberately configures just enough coexistence to support mailbox management across both environments. Even at this baseline, the Hybrid Configuration Wizard creates a management relationship so administrators can view and move mailboxes from the on-premises Exchange admin center or the Exchange Online admin center, and mail flow works between the two. This makes it a valid and lightweight method for both coexistence and migration, so the statement is correct.

Why this answer

A minimal hybrid deployment uses Azure AD Connect to synchronize on-premises Active Directory with Microsoft Entra ID, enabling centralized management of mailboxes across both environments. This allows administrators to manage on-premises and Exchange Online mailboxes from a single Exchange admin center, making option B correct.

Exam trap

The trap here is that candidates often confuse 'minimal hybrid' with 'no synchronization,' but Microsoft requires directory synchronization for any hybrid deployment, and they may also incorrectly assume IMAP migration can handle calendar and contact data, which it cannot.

509
MCQhard

You are configuring Microsoft Defender for Office 365 to protect against business email compromise (BEC) attacks. Which policy setting should you enable to analyze email sender behavior and detect impersonation attempts?

A.Safe Attachments policy - Dynamic Delivery
B.Anti-phishing policy - Impersonation protection
C.Safe Links policy - URL scan
D.Anti-malware policy - Malware filter
AnswerB

Impersonation protection within the anti-phishing policy uses mailbox intelligence and spoof detection to model sender behaviour and flag messages impersonating internal users or trusted domains. This satisfies the requirement to analyse sender behaviour and detect business email compromise impersonation attempts.

Why this answer

Anti-phishing policies in Microsoft Defender for Office 365 include impersonation protection settings that analyze sender behavior and detect attempts to impersonate users, domains, or trusted senders. Enabling impersonation protection specifically addresses BEC by using mailbox intelligence and spoof intelligence to identify anomalous sender patterns.

Exam trap

MS-102 often tests the difference between Safe Attachments, Safe Links, anti-malware, and anti-phishing, and candidates may incorrectly associate BEC detection with attachment scanning rather than impersonation protection.

How to eliminate wrong answers

Option A is wrong because Safe Attachments with Dynamic Delivery focuses on detonating attachments in a sandbox and delivering the email without the attachment until scanning completes; it does not analyze sender behavior. Option C is wrong because Safe Links URL scanning protects against malicious URLs, not sender impersonation. Option D is wrong because anti-malware policies filter known malware signatures and do not detect impersonation or BEC tactics.

510
MCQhard

A company uses Microsoft Entra ID Governance to automate the lifecycle of user access. They want to automatically remove a user's group membership for a critical application 30 days after the user's employment end date is captured from the HR system. Which feature should be configured to meet this requirement?

A.Access Reviews
B.Entitlement management
C.Lifecycle Workflows
D.Privileged Identity Management
AnswerC

Lifecycle Workflows are the correct answer because they are designed to automate identity lifecycle events using HR data from sources like Workday or SuccessFactors. When an HR event such as termination occurs, a workflow triggers tasks that can directly remove group memberships without human intervention. This approach specifically addresses the requirement to automate removal based on an HR attribute date.

Why this answer

Lifecycle Workflows (LCW) in Microsoft Entra ID Governance are specifically designed to automate joiner, mover, and leaver processes triggered by HR data. A 'leaver' workflow can be configured to remove group memberships a defined number of days after the employee's employment end date is captured from the HR system, meeting the 30-day requirement precisely.

Exam trap

The trap here is confusing Lifecycle Workflows (which handle HR-triggered automated actions with delays) with Entitlement management (which manages access packages and requests but lacks native HR event-driven scheduling).

How to eliminate wrong answers

Option A is wrong because Access Reviews are periodic attestation processes that require manual or scheduled approval to confirm access, not automated time-based removal triggered by an HR event. Option B is wrong because Entitlement management manages access packages and requests but does not natively support a delay-based removal triggered by an HR employment end date; it relies on access reviews or expiration policies that are not tied to HR lifecycle events. Option D is wrong because Privileged Identity Management (PIM) provides just-in-time activation and approval for privileged roles, not automated removal of standard group memberships based on an HR-driven schedule.

511
MCQhard

Your organization is a financial services company with 5,000 users. You use Microsoft Defender XDR, including Defender for Endpoint Plan 2, Defender for Identity, Defender for Office 365 Plan 2, and Defender for Cloud Apps. You have recently deployed Microsoft Copilot for Security to assist your security operations center (SOC) analysts. A high-severity incident is generated: 'A user named jdoe accessed a malicious IP address from their device, and then logged into Azure Portal from an anonymous IP address. Defender for Identity detected a suspicious Kerberos ticket request from the same user's domain controller. The SOC analysts are overwhelmed with alerts and need to quickly understand the full scope of the incident, including related alerts, impacted assets, and recommended actions. They also want to use natural language to ask questions about the incident. What should you do to enable the analysts to efficiently investigate this incident?

A.Train the analysts to use Advanced Hunting to query across all data sources and build custom KQL queries to correlate the alerts.
B.Create custom detection rules in Microsoft Defender XDR to generate more specific alerts for similar activity.
C.Use Microsoft Copilot for Security integrated with Microsoft Defender XDR to get a natural language summary of the incident, ask follow-up questions, and receive recommended actions.
D.Configure automated investigation and remediation to automatically contain the threat and then review the results.
AnswerC

Copilot for Security embedded in Defender XDR correlates the incident's alerts, entities and Defender for Identity signals, then answers natural-language questions and surfaces recommended actions. This directly satisfies the analysts' need to rapidly scope the incident across products without manual triage.

Why this answer

Microsoft Copilot for Security integrated with Microsoft Defender XDR provides natural language summaries of incidents, allows follow-up questions, and offers recommended actions. This directly addresses the SOC analysts' need to quickly understand the full scope and use natural language, reducing investigation time.

Exam trap

MS-102 often tests the misconception that Advanced Hunting or automated investigation alone can provide natural language summaries, but only Copilot for Security offers that capability.

How to eliminate wrong answers

Option A is wrong because Advanced Hunting with KQL requires manual query writing and expertise, which is time-consuming and does not provide natural language interaction. Option B is wrong because custom detection rules generate more alerts, which would increase the noise rather than help investigate the existing incident. Option D is wrong because automated investigation and remediation can contain threats but does not provide natural language summaries or recommended actions for analysts to understand the incident scope.

512
MCQhard

You are a compliance administrator for Contoso Ltd. The company uses Microsoft Purview Information Protection with sensitivity labels. A new regulation requires that all documents labeled 'Highly Confidential' must be encrypted and only accessible by members of the 'Legal' group, even when shared externally. You have published a label named 'Highly Confidential' with encryption settings. You need to ensure that the label enforces these requirements when applied to documents in Office apps. What should you configure in the label's encryption settings?

A.Assign permissions to the 'Legal' group with 'Viewer' role, and clear the option 'Let users assign permissions'.
B.Assign permissions to the 'Legal' group with 'Viewer' role and set 'Do not forward' for the content.
C.Assign permissions to the 'Legal' group with 'Viewer' role and enable 'Let users assign permissions'.
D.Assign permissions to the 'Legal' group with 'Co-Author' role and set an expiration date for the content.
AnswerA

Assigning Viewer permissions to the Legal group ensures that only members of that group can read the content, and clearing 'Let users assign permissions' prevents users from altering the permissions when applying the label. This enforces the encryption and access restriction required by the regulation, ensuring that only Legal can access the documents.

Why this answer

To enforce that only the Legal group can access documents labeled 'Highly Confidential', the encryption settings must assign permissions exclusively to that group and prevent users from changing those permissions. Assigning Viewer role limits access to read-only for Legal, and disabling user assignment ensures the label's protection cannot be overridden. This meets the regulatory requirement for encryption and access control.

Exam trap

The trap here is assuming that any permission assignment to the Legal group automatically excludes others, when in fact user-assigned permissions could allow broader access if not disabled.

513
Multi-Selecthard

Which THREE components are required to implement auto-labeling for sensitivity labels in Microsoft 365?

Select 3 answers
A.A sensitivity label configured for auto-labeling.
B.A DLP policy for the same sensitive info type.
C.A sensitive info type or trainable classifier.
D.An auto-labeling policy that specifies the label and locations.
E.An information barrier policy.
AnswersA, C, D

Auto-labelling requires a sensitivity label whose settings define what the policy applies; without a label configured for auto-labelling there is nothing for the policy to assign. It satisfies the stem's requirement as the mandatory label component of the three-part configuration.

Why this answer

Auto-labeling in Microsoft 365 requires three core components. Option A is correct because a sensitivity label must be configured for auto-labeling (i.e., its auto-labeling setting enabled) so it can be applied automatically to matching content. Option C is correct because the auto-labeling policy must reference a sensitive info type (such as a built-in SIT or a custom SIT) or a trainable classifier to detect the content to label.

Option D is correct because an auto-labeling policy is the container that binds the label to the detection rules and specifies the workloads/locations (Exchange, SharePoint, OneDrive) where labeling runs. Option B is not required: a DLP policy is a separate data loss prevention control and is not a prerequisite for auto-labeling, even if it uses the same sensitive info type. Option E is not required: information barrier policies restrict communication between groups and are unrelated to sensitivity label auto-labeling.

Exam trap

MS-102 often tests the components of auto-labeling and confuses it with DLP; candidates might incorrectly include a DLP policy as a requirement, but auto-labeling policies are separate and do not require DLP.

514
MCQmedium

Your organization uses Microsoft Purview Data Lifecycle Management. You need to review the disposition of content that has reached the end of its retention period. What should you configure?

A.Create a DLP policy to notify administrators.
B.Place the content on an eDiscovery hold.
C.Enable disposition review in the retention policy or label.
D.Create a retention label with a retention period.
AnswerC

Disposition review lets reviewers examine content at the end of its retention period before permanent deletion, satisfying the requirement to review disposition. Configuring it on the retention policy or label routes expired items to a review queue in Microsoft Purview, where reviewers approve destruction or extend retention.

Why this answer

Disposition review is a feature in Microsoft Purview Data Lifecycle Management that allows you to review content before it is permanently deleted at the end of its retention period. To enable it, you must configure the retention policy or retention label to trigger a disposition review. This ensures that content is not automatically deleted without human oversight, which is often required for regulatory or legal reasons.

Exam trap

MS-102 often tests the difference between retention and disposition; candidates may think that setting a retention period automatically triggers review, but disposition review must be explicitly enabled.

How to eliminate wrong answers

Option A is wrong because DLP policies are for preventing data loss, not for managing retention disposition. Option B is wrong because an eDiscovery hold preserves content indefinitely, which is the opposite of disposition review. Option D is wrong because creating a retention label with a retention period alone does not enable disposition review; you must specifically enable the disposition review option on the label or policy.

515
MCQhard

Your organization has Microsoft 365 E5 licenses and uses Microsoft Defender for Office 365. You need to ensure that users are warned before clicking on malicious URLs in email messages, even if the URL is clicked after the email is delivered. Which policy should you configure?

A.Anti-malware policy
B.Safe Attachments policy
C.Safe Links policy
D.Anti-phishing policy
AnswerC

Safe Links rewrites URLs and checks them at click time, so users are warned or blocked even after delivery. This satisfies the requirement to protect clicks occurring post-delivery, unlike Safe Attachments, which detonates attachments, or anti-phishing policies, which act on delivery.

Why this answer

Safe Links policy is correct because it provides time-of-click protection, which scans URLs in email messages at the moment the user clicks them, even after delivery. This ensures users are warned or blocked from accessing malicious URLs that may have been benign at the time of delivery but later weaponized. Anti-malware, Safe Attachments, and Anti-phishing policies do not offer this post-delivery click-time verification.

Exam trap

The trap here is that candidates often confuse Safe Attachments (which handles files) with Safe Links (which handles URLs), or assume that Anti-phishing policies cover all link-based threats, but only Safe Links provides the specific time-of-click protection described in the question.

How to eliminate wrong answers

Option A is wrong because Anti-malware policy focuses on detecting and removing malware in email attachments and messages at the time of delivery, not on URL click-time protection. Option B is wrong because Safe Attachments policy specifically handles email attachments by detonating them in a sandbox environment, not URLs embedded in messages. Option D is wrong because Anti-phishing policy protects against impersonation and phishing attempts using spoofing intelligence and impersonation detection, but it does not provide click-time URL scanning or warning for malicious links.

516
MCQhard

You are the compliance administrator for Contoso Ltd., a multinational corporation with 10,000 users. The company uses Microsoft 365 E5 licenses and has deployed Microsoft Purview. The legal department requires that all email communications related to ongoing litigation be preserved for the duration of the case. You have identified the custodians and relevant keywords. You need to ensure that all relevant emails are preserved, regardless of whether users delete them. Additionally, you need to allow authorized reviewers to search and export the preserved emails without affecting the original data. Finally, you must ensure that the preservation is lifted automatically when the case is closed. What should you do?

A.Create an eDiscovery (Premium) case, add custodians, place them on hold, and use the case to search and export. Close the case to release the hold.
B.Configure a DLP policy to protect sensitive data and preserve the emails.
C.Create a retention label with a preservation action and publish it to the entire organization.
D.Place an in-place hold on all mailboxes using the Exchange admin center.
AnswerA

eDiscovery (Premium) is the correct solution because it provides a centralized case object that ties together custodians, holds, searches, and exports. Adding custodians places them on hold, ensuring their data is preserved across Exchange, SharePoint, and OneDrive for Business, while the case interface enables targeted searching and exporting. Closing the case (with release hold option) cleanly removes the holds, and the case record preserves an audit trail of the investigation.

Why this answer

eDiscovery (Premium) cases in Microsoft Purview are purpose-built for litigation workflows: they let you add custodians, place them on legal hold, run targeted searches, and export results without altering the source data. Closing the case automatically releases the custodian holds, which satisfies the requirement that preservation be lifted when the case ends. This is the only option that combines custodian-scoped preservation, reviewer search/export, and automatic hold release in one workflow.

Exam trap

MS-102 often tests the distinction between retention labels, DLP, and eDiscovery holds, tricking candidates into choosing a retention label because it sounds like 'preservation' when the scenario actually requires case-based legal hold with automatic release.

How to eliminate wrong answers

Option B is wrong because DLP policies detect and protect sensitive information in motion or at rest but do not place mailboxes on legal hold or provide case-based search and export for litigation. Option C is wrong because retention labels apply retention or preservation actions based on label policy scope and do not automatically release holds when a specific legal case closes, nor do they provide eDiscovery search/export tooling. Option D is wrong because Exchange in-place holds (or the newer Litigation Hold) preserve mailbox content but are not tied to a case lifecycle, so they must be manually removed and do not offer the case-scoped custodian management and review workflow required.

517
MCQeasy

Your organization uses Microsoft Defender for Office 365. You need to ensure that malicious links in email messages are blocked at the time of click by checking the link reputation in real time. What should you enable?

A.Anti-spam policy.
B.Safe Attachments policy.
C.Safe Links policy.
D.Anti-phishing policy.
AnswerC

A Safe Links policy in Microsoft Defender for Office 365 rewrites URLs and verifies link reputation at click time, blocking malicious destinations in real time. This satisfies the time-of-click requirement, unlike Safe Attachments, which detonates attachments rather than evaluating links.

Why this answer

Safe Links policy in Defender for Office 365 provides real-time link reputation checking at the time of click. It rewrites URLs and checks them against a dynamic list of known malicious links when users click them. Option A is incorrect because anti-spam policies filter spam emails, not malicious links.

Option B is incorrect because Safe Attachments scans email attachments for malware, not links. Option D is incorrect because anti-phishing policies protect against phishing attempts but do not perform real-time link checking.

518
MCQhard

Your company, Fabrikam Inc., uses Microsoft Entra ID with hybrid identity. You have an on-premises Active Directory and use Microsoft Entra Connect Sync to synchronize users. You need to configure Microsoft Entra ID Protection to detect leaked credentials and risky sign-ins. Additionally, you must ensure that when a user is detected as high risk, their access is automatically blocked and they are required to change their password. You also need to enable password writeback so that password changes are written back to on-premises AD. You have the following options: A. Enable Identity Protection, configure user risk policy to require password change, and enable password writeback in Microsoft Entra Connect. B. Enable Identity Protection, configure sign-in risk policy to block access, and enable password hash sync. C. Configure Conditional Access policy to require MFA for all users, and enable seamless SSO. D. Deploy Microsoft Defender for Identity and configure automatic remediation. Which option should you choose?

A.Enable Identity Protection, configure user risk policy to require password change, enable password writeback
B.Enable Identity Protection, configure sign-in risk policy to block access, enable password hash sync
C.Deploy Microsoft Defender for Identity, configure automatic remediation
D.Configure Conditional Access policy to require MFA, enable seamless SSO
AnswerA

This option is correct because it combines user risk detection in Microsoft Entra ID Protection with a user risk policy that automatically requires a secure password change when an account is flagged as compromised. Password writeback is essential in a hybrid environment to propagate the new password to on-premises Active Directory. This workflow directly remediates the risk and meets all stated requirements.

Why this answer

It directly addresses all requirements: enabling Identity Protection allows detection of leaked credentials and risky sign-ins; configuring the user risk policy to require a password change automatically blocks high-risk users until they change their password; and enabling password writeback in Microsoft Entra Connect ensures that password changes performed in the cloud are written back to on-premises Active Directory, maintaining hybrid identity synchronization.

Exam trap

The trap here is that candidates often confuse sign-in risk policies (which block access) with user risk policies (which can require a password change), and they may overlook that password writeback must be explicitly enabled in Microsoft Entra Connect, not just password hash sync.

How to eliminate wrong answers

Option B is wrong because configuring a sign-in risk policy to block access does not require the user to change their password—it only blocks the sign-in attempt, and enabling password hash sync alone does not enable password writeback, which is necessary for on-premises password changes. Option C is wrong because deploying Microsoft Defender for Identity focuses on detecting on-premises attacks and does not natively provide user risk policies for leaked credentials or automatic password change enforcement in Entra ID Protection. Option D is wrong because configuring a Conditional Access policy to require MFA does not detect leaked credentials or risky sign-ins, and enabling seamless SSO does not provide password writeback or automatic blocking with password change for high-risk users.

519
MCQmedium

Your organization uses Microsoft Defender for Endpoint. A user reports that their device is not receiving security updates. You need to ensure that the device is properly onboarded to Defender for Endpoint. Which log should you check first?

A.Event Viewer Application logs
B.System logs
C.Microsoft Defender for Endpoint client logs
D.Windows Update logs
AnswerC

The Microsoft Defender for Endpoint client logs are the authoritative source for troubleshooting onboarding and update issues. These logs, located in C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Logs, include files like MicrosoftDefenderATPOnboarding.log and MicrosoftDefenderATPUpdate.log that record sensor registration, machine ID assignment, and signature update failures. If an onboarding attempt is failing, the client log will contain the specific error code and allow verification of the correct log collection.

Why this answer

The Microsoft Defender for Endpoint client logs (option C) are the primary source for troubleshooting onboarding issues because they contain detailed records of the client's registration, communication with the cloud service, and policy application. If a device is not receiving security updates, it often indicates a failure in the onboarding process or a connectivity problem, which these logs directly capture. Checking these logs first allows you to verify the device's enrollment status and identify any errors in the initial connection or certificate exchange.

Exam trap

The trap here is that candidates often confuse 'security updates' with Windows Update logs (option D), but the question specifically targets Defender for Endpoint onboarding, which requires checking the client's own logs to confirm registration and communication with the cloud service.

How to eliminate wrong answers

Option A is wrong because Event Viewer Application logs record application-level events, not the specific onboarding or communication status of the Defender for Endpoint sensor. Option B is wrong because System logs focus on driver and hardware events, not the client-to-cloud registration process required for onboarding. Option D is wrong because Windows Update logs track update installation and download failures, but they do not indicate whether the device is properly enrolled in Defender for Endpoint; a device can be fully onboarded yet still have update issues unrelated to the security service.

520
MCQmedium

Your organization uses Microsoft Defender for Cloud Apps. You discover that a user is downloading large amounts of data from SharePoint Online to an unmanaged device. You need to automatically block the download and alert the security team. What should you configure?

A.Session policy
B.Access policy
C.File policy
D.Anomaly detection policy
AnswerA

Session policies apply real-time, in-session controls through Conditional Access app control, blocking downloads to unmanaged devices and raising alerts. This satisfies the requirement to automatically prevent the SharePoint Online download while notifying the security team.

Why this answer

A session policy in Defender for Cloud Apps applies real-time controls during a user session, including the ability to block downloads to unmanaged devices and trigger alerts. This is the correct control for stopping an active data exfiltration attempt from SharePoint Online.

Exam trap

The trap is confusing file policies (which scan content) with session policies (which enforce real-time controls), or picking anomaly detection which only alerts and does not block.

How to eliminate wrong answers

Option B is wrong because access policies control whether a user can sign in to an app at all, not what they can do once inside a session. Option C is wrong because file policies scan and classify files at rest or on upload, but they do not block real-time downloads in a session. Option D is wrong because anomaly detection policies flag unusual behavior (e.g., mass download) but do not enforce a block — they generate alerts only.

521
MCQmedium

An administrator who is not a Global Administrator needs to manage just-in-time privileged access to Azure resources using Microsoft Entra Privileged Identity Management (PIM). Which built-in role must be assigned to the administrator to allow PIM management for Azure resources?

A.Privileged Role Administrator
B.User Administrator
C.Security Administrator
D.Application Administrator
AnswerA

Privileged Role Administrator is the correct choice because this role is explicitly delegated to manage just-in-time access and governance in Microsoft Entra PIM. It can configure PIM settings for both Microsoft Entra roles and Azure resources, approve activation requests, and create eligible or active assignments for other roles. This is the least-privileged built-in role that can perform these tasks without requiring Global Administrator.

Why this answer

The Privileged Role Administrator role is the only built-in role that grants permissions to manage all aspects of Privileged Identity Management (PIM) for Azure resources, including configuring just-in-time access, managing role assignments, and approving activation requests. This role is specifically designed for administrators who need to oversee PIM without requiring Global Administrator privileges, as it provides full control over PIM policies and role settings across Azure AD and Azure resources.

Exam trap

The trap here is that candidates often confuse the Privileged Role Administrator role with the Global Administrator role, assuming only Global Admins can manage PIM, but Microsoft specifically designed the Privileged Role Administrator to delegate PIM management without granting full tenant-wide administrative control.

How to eliminate wrong answers

Option B (User Administrator) is wrong because it can manage user accounts and groups but lacks permissions to configure PIM role settings, activation policies, or approve requests for Azure resource roles. Option C (Security Administrator) is wrong because it focuses on security features like conditional access and identity protection, not on managing PIM role assignments or just-in-time access policies. Option D (Application Administrator) is wrong because it is limited to managing enterprise applications and app registrations, with no ability to manage PIM role configurations or privileged access workflows.

522
MCQhard

Your company is migrating from on-premises Exchange to Exchange Online. You have configured a hybrid deployment. During testing, you notice that free/busy information is not being shared between on-premises and cloud users. All other hybrid features work. What is the most likely cause?

A.The organization relationship between the on-premises and cloud tenants is missing or misconfigured.
B.Azure AD Connect has not been configured with the correct synchronization scope.
C.The on-premises firewall is blocking traffic to the Exchange Online endpoints.
D.OAuth authentication is not configured between on-premises and Exchange Online.
AnswerA

In Exchange hybrid deployments, free/busy sharing depends on a specific organization relationship between the on-premises Exchange organization and the Exchange Online tenant. This relationship defines the federated trust, sharing domain, and the availability service endpoints, so if it is missing or misconfigured, the Availability service cannot resolve cross-premises calendar requests even though mail routing remains functional. The organization relationship is the control plane for calendaring, not for transport, so its absence presents exactly the symptom described: messages flow but free/busy fails. Verify the relationship's sharing domain and the Autodiscover URLs to restore availability.

Why this answer

The organization relationship defines the trust and sharing settings between on-premises Exchange and Exchange Online tenants, specifically for free/busy information. Since all other hybrid features (e.g., mail flow, mailbox moves) work, the issue is isolated to the organization relationship, which must be configured on both sides to enable cross-premises calendar availability queries.

Exam trap

The trap here is that candidates assume OAuth is required for all hybrid features, but Microsoft specifically decouples free/busy sharing from OAuth in hybrid scenarios, making the organization relationship the primary culprit when only calendar availability fails.

How to eliminate wrong answers

Option B is wrong because Azure AD Connect synchronization scope controls identity and attribute sync (e.g., users, groups), not free/busy sharing; incorrect scope would cause missing or mismatched user objects, not a failure of free/busy queries specifically. Option C is wrong because firewall blocks would affect all hybrid traffic (e.g., SMTP, Autodiscover, EWS), not just free/busy; since other features work, a firewall issue is unlikely. Option D is wrong because OAuth authentication is required for modern hybrid features like archive access and eDiscovery, but free/busy sharing can function with legacy organization relationship settings using the AvailabilityAddressSpace or IntraOrganizationConnector; OAuth is not strictly necessary for basic free/busy.

523
MCQhard

You are a security administrator for a company that uses Microsoft Defender XDR. You need to integrate Microsoft Defender XDR with Microsoft Sentinel to create a unified incident view. You want to ensure that incidents from Defender XDR are automatically created in Sentinel. What should you do?

A.In Microsoft Defender XDR settings, enable the Microsoft Sentinel integration and select the Sentinel workspace
B.Enable the Microsoft Defender XDR connector in Microsoft Sentinel and turn on incident creation
C.Configure a custom detection rule in Defender XDR that calls the Microsoft Sentinel API
D.Install the Microsoft Sentinel solution for Microsoft Defender XDR from the Content Hub
AnswerB

To integrate Defender XDR with Sentinel and have incidents automatically created in Sentinel, you must enable the Microsoft Defender XDR data connector in Sentinel and specifically turn on the option to create incidents from Defender XDR alerts. This establishes the bi-directional synchronization and ensures incidents appear in both portals.

Why this answer

Enabling the Microsoft Defender XDR connector in Microsoft Sentinel and turning on incident creation is the correct method to ensure incidents from Defender XDR are automatically created in Sentinel. This provides a unified incident view and enables Sentinel's SOAR capabilities on Defender XDR incidents.

Exam trap

The trap here is assuming that installing a solution or configuring settings in Defender XDR is sufficient, but the incident creation toggle is specifically in the Sentinel data connector configuration.

524
MCQhard

Your organization uses Microsoft Entra ID P2 and has a hybrid identity environment with Microsoft Entra Connect Sync. You need to implement a solution that automatically remediates risky user sign-ins by requiring a password change when Microsoft Entra ID Protection detects a leaked credential. You also want to minimize help desk calls. Which configuration should you use?

A.Configure a user risk policy in Microsoft Entra ID Protection to require a secure password change for high user risk, and enable self-service password reset (SSPR) so users can remediate themselves.
B.Create a Conditional Access policy that requires multifactor authentication for all users and enable risk detections in Microsoft Entra ID Protection.
C.Enable Microsoft Entra Connect Health and configure alert notifications for synchronization errors, then instruct users to change their passwords when alerts are received.
D.Configure a sign-in risk policy to block access for medium and high sign-in risk, and enable Microsoft Entra Password Protection with a custom banned password list.
AnswerA

A user risk policy set to require a secure password change for high-risk users responds to leaked credentials by forcing a password reset. Enabling SSPR allows users to complete the remediation without help desk involvement, satisfying both the security and the minimize-help-desk-calls requirements. This is the intended use of Identity Protection user risk policies.

Why this answer

Microsoft Entra ID Protection detects leaked credentials and raises user risk. A user risk policy configured to require a secure password change for high user risk enforces remediation, and enabling SSPR lets users reset their own passwords. This combination automatically addresses the risk and reduces help desk dependency, which is exactly what the scenario requires.

Exam trap

The trap here is confusing sign-in risk policies with user risk policies; leaked credentials raise user risk, not sign-in risk, so a sign-in risk policy will not force a password change.

525
MCQeasy

An admin needs to provide a vendor with temporary access to a SharePoint site. What should the admin create?

A.Guest user in Azure AD
B.Anonymous sharing link
C.Security group
D.New user in your domain
AnswerA

A guest user in Azure AD represents an external collaborator through B2B collaboration, allowing the vendor to authenticate with their own corporate identity while you grant them tailored access to resources. This creates a distinct external identity in your directory that can be assigned to apps, groups, and sites, and access can be revoked or expired using access reviews or by removing the guest account. Because it is identity-based, every action is auditable under a specific guest account, making it the correct and secure way to provide temporary access.

Why this answer

A is correct because creating a guest user in Azure AD is the proper method to grant external users access to SharePoint Online resources with controlled permissions. Guest users are invited via Azure AD B2B collaboration, which allows the admin to assign specific SharePoint site permissions while maintaining oversight and the ability to revoke access. This approach ensures the vendor has a distinct identity for auditing and conditional access policies.

Exam trap

The trap here is that candidates often confuse anonymous sharing links (which are easy to create) with proper external user management, overlooking the need for identity-based access control and auditability required for vendor access.

How to eliminate wrong answers

Option B is wrong because an anonymous sharing link provides unrestricted access to anyone with the link, bypassing authentication and auditing, which violates the requirement for temporary, controlled vendor access. Option C is wrong because a security group is used to manage permissions for existing users within the organization, not to invite external vendors; it cannot create an external identity. Option D is wrong because creating a new user in your domain would require the vendor to have a mailbox and identity within your on-premises or cloud directory, which is unnecessary and introduces administrative overhead for temporary access.

Page 6

Page 7 of 10

Page 8

All pages