Courseiva

Microsoft 365 Administrator MS-102 (MS-102) — Questions 526–600

712 questions total · 10pages · All types, answers revealed

Page 7

Page 8 of 10

Page 9
526
Multi-Selectmedium

Which THREE features are part of Microsoft Defender XDR? (Select THREE.)

Select 3 answers
A.Microsoft Purview
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Office 365
D.Microsoft Sentinel
E.Microsoft Defender for Identity
AnswersB, C, E

Microsoft Defender for Endpoint contributes endpoint detection and response telemetry into the unified Microsoft Defender XDR portal, correlating device alerts with identity and email signals. It is one of the core workloads natively integrated into Microsoft Defender XDR, satisfying the stem's selection of three features.

Why this answer

Microsoft Defender XDR is a unified security solution that integrates signals from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, and others. The correct answers are B, C, and E. Option A (Microsoft Purview) is a data governance and compliance solution, not part of Defender XDR.

Option D (Microsoft Sentinel) is a separate cloud-native SIEM and SOAR solution.

527
MCQeasy

An administrator needs to add a custom domain 'contoso.org' to their Microsoft 365 tenant. They have already purchased the domain and have access to the DNS registrar. What is the first step the administrator should perform in the Microsoft 365 admin center?

A.Add a TXT record in the public DNS zone
B.Add the domain in the Microsoft 365 admin center
C.Configure email routing (MX record)
D.Create user accounts with the new domain
AnswerB

The first action is adding the custom domain in the Microsoft 365 admin center, which creates a domain object in Azure AD and marks it as unverified. This step generates the exact DNS records (including the unique TXT verification string) that you will need to prove ownership. Once the domain is added, you can retrieve and then add those records — but the addition in the admin center must happen first.

Why this answer

The first step to add a custom domain to a Microsoft 365 tenant is to initiate the domain addition process in the Microsoft 365 admin center. This triggers Microsoft to generate the unique verification TXT record that must be published in the public DNS zone. Without first adding the domain in the admin center, the administrator would not know the specific verification string required for the TXT record.

Exam trap

The trap here is that candidates often confuse the sequence of steps and think that adding a DNS record (like TXT or MX) is the first action, when in reality the domain must first be registered in the admin center to obtain the required verification token.

How to eliminate wrong answers

Option A is wrong because adding a TXT record in the public DNS zone is the second step, performed after the domain has been added in the admin center to obtain the unique verification value. Option C is wrong because configuring email routing (MX record) is a later step that occurs after domain verification is complete and the domain is set as the primary email domain. Option D is wrong because creating user accounts with the new domain requires the domain to first be verified and added to the tenant; otherwise, the domain is not recognized by Azure AD.

528
Multi-Selectmedium

Your organization is planning to migrate from on-premises Active Directory to Microsoft Entra ID using Azure AD Connect. You need to ensure that password synchronization is enabled. Which TWO components are required for password synchronization to work?

Select 2 answers
A.Azure AD Connect with password hash synchronization selected.
B.Active Directory Federation Services (AD FS).
C.Password Writeback enabled.
D.Microsoft Identity Manager (MIM).
E.Microsoft Entra ID service to process synchronization.
AnswersA, E

Azure AD Connect is the official Microsoft synchronization tool that connects on-premises Active Directory with Microsoft Entra ID. When password hash synchronization (PHS) is selected, Azure AD Connect retrieves a one-way hash (using MD5, SHA-256, and PBKDF2) of each user's on-premises password and securely transfers it to Entra ID. This allows users to authenticate to cloud services using the same password without any federation infrastructure, and it is the core mechanism that satisfies the migration requirement.

Why this answer

Azure AD Connect with password hash synchronization (PHS) selected is the component that hashes the on-premises Active Directory password and synchronizes it to Microsoft Entra ID. Option E is correct because the Microsoft Entra ID service must process the incoming password hashes and store them in the cloud directory, enabling authentication against Entra ID. Without both the local sync engine (Azure AD Connect) and the cloud-side service, password synchronization cannot function.

Exam trap

The trap here is that candidates often confuse Password Writeback (a separate feature for cloud-to-on-premises password changes) as a prerequisite for password synchronization, when in fact it is an optional add-on that is not required for the one-way sync of password hashes from on-premises to the cloud.

529
MCQhard

Your organization uses Microsoft Defender for Endpoint. You need to configure a rule that automatically isolates a device from the network when a specific threat is detected, but only if the device is in a specific device group. Which approach should you use?

A.Indicator of compromise (IoC)
B.Automation rule
C.Custom detection rule
D.Group policy in Intune
AnswerB

An automation rule in Microsoft 365 Defender allows you to define conditions based on alert or incident properties and then automatically run a series of actions, including Microsoft Defender for Endpoint's isolate device response action. By specifying a condition like 'Alert severity' or 'Threat category,' you can trigger device isolation without manual intervention. Automation rules are the appropriate mechanism because they combine trigger conditions with remediation actions like isolation.

Why this answer

Automation rules in Microsoft Defender for Endpoint allow you to define automated actions, such as isolating a device, based on specific conditions like threat severity and device group membership. This directly meets the requirement to isolate only devices in a specific group when a specific threat is detected, as automation rules support granular scoping by device group.

Exam trap

The trap here is that candidates often confuse automation rules with custom detection rules, thinking custom detection rules can also trigger automated actions, but only automation rules provide the device group scoping and direct remediation actions like isolation.

How to eliminate wrong answers

Option A is wrong because Indicators of Compromise (IoCs) are used to detect or block known malicious entities (e.g., file hashes, IPs, URLs) but do not trigger automated response actions like device isolation based on device group membership. Option C is wrong because Custom Detection Rules are for creating custom alerts based on advanced hunting queries, not for configuring automated remediation actions like isolation; they can trigger alerts but not directly execute device isolation. Option D is wrong because Group Policy in Intune is used for device configuration and compliance policies, not for real-time automated response to threat detections in Defender for Endpoint.

530
MCQmedium

A company is planning to deploy Microsoft Defender for Endpoint to its Windows 10 devices. The devices are managed by Microsoft Intune. The security team wants to ensure that the MDE sensor is installed automatically on new devices that are enrolled in Intune. Which method should the team use?

A.Manually install MDE on each device.
B.Use Group Policy to deploy the MDE installation package.
C.Deploy MDE using Microsoft Configuration Manager.
D.Create an Endpoint security policy in Intune to deploy MDE.
AnswerD

Creating an Endpoint security policy in Intune deploys the MDE sensor automatically during enrolment, satisfying the requirement that new Windows 10 devices receive it without manual intervention. This built-in connector pushes the onboarding package to Intune-managed devices, unlike configuration profiles or scripts, which need extra packaging and assignment.

Why this answer

The correct method is to create an Endpoint security policy in Intune specifically for Microsoft Defender for Endpoint. This policy type allows you to configure the MDE onboarding blob and automatically deploy the MDE sensor to Windows 10 devices enrolled in Intune. It is the native, cloud-based approach that ensures new devices receive the sensor without manual intervention or on-premises infrastructure.

Exam trap

MS-102 often tests the misconception that Group Policy or Configuration Manager are required for automatic deployment, when in fact Intune's native Endpoint security policies are the recommended method for cloud-managed devices.

How to eliminate wrong answers

Option A is wrong because manual installation does not scale, is error-prone, and fails to meet the requirement for automatic deployment to new devices. Option B is wrong because Group Policy is an on-premises Active Directory tool that cannot natively target Intune-enrolled devices without hybrid Azure AD join and even then lacks direct integration for MDE onboarding in modern management. Option C is wrong because Microsoft Configuration Manager requires additional infrastructure, is not automatically available for Intune-managed devices, and is unnecessary when Intune can handle the deployment directly.

531
MCQeasy

You are a security administrator for a company that uses Microsoft Defender XDR. You need to investigate an incident that involves multiple alerts across different workloads. Which feature in Microsoft Defender XDR should you use to view the full attack story and related entities?

A.Incident details page
B.Advanced hunting
C.Threat analytics
D.Incident queue
AnswerA

The incident details page in Microsoft Defender XDR aggregates all alerts, entities, and automated investigations related to an incident. It provides a visual attack story, showing the sequence of events and relationships between entities, which is exactly what you need to investigate the incident.

Why this answer

The incident details page in Microsoft Defender XDR is designed to provide a comprehensive view of an incident, including all related alerts, entities, and the attack story. This allows security administrators to understand the full scope and progression of the attack.

Exam trap

The trap here is confusing the incident queue with the incident details page; the queue only lists incidents, while the details page provides the full story.

532
MCQeasy

A company has an existing Microsoft 365 tenant with the verified custom domain 'contoso.com'. The administrator now wants to add a second custom domain, 'contoso-europe.com', to the same tenant. What is the first step the administrator should take?

A.Add the domain in the Microsoft 365 admin center.
B.Add a TXT verification record in the public DNS zone for 'contoso-europe.com'.
C.Add an MX record pointing to Exchange Online in the public DNS zone for 'contoso-europe.com'.
D.Contact Microsoft support to enable the domain addition feature.
AnswerA

Adding the domain in the Microsoft 365 admin center is the first step, which generates the required TXT or MX verification record. Only after DNS verification succeeds can the administrator create users, mailboxes and configure services for contoso-europe.com.

Why this answer

The first step to add a second custom domain to an existing Microsoft 365 tenant is to initiate the domain addition process in the Microsoft 365 admin center. This triggers the system to generate the unique TXT verification record that must be added to the public DNS zone to prove ownership of the domain. Without first adding the domain in the admin center, the administrator would not know the specific verification value required for the DNS record.

Exam trap

The trap here is that candidates often assume the first step is to create a DNS record (like TXT or MX) directly, but the correct sequence requires initiating the domain addition in the admin center first to obtain the necessary verification value.

How to eliminate wrong answers

Option B is wrong because adding a TXT verification record in the public DNS zone is the second step, not the first; the administrator must first add the domain in the admin center to obtain the unique verification string. Option C is wrong because adding an MX record pointing to Exchange Online is a post-verification step used to route email, and it is not required for domain ownership verification. Option D is wrong because Microsoft 365 allows domain addition without contacting support; the feature is enabled by default for all tenants with verified custom domains.

533
MCQmedium

A company uses Microsoft Entra ID P2 licenses. The security team wants to automatically require a password change for users with medium sign-in risk, but only when the sign-in originates from outside the corporate network. Users with high sign-in risk should be blocked entirely. A group of break-glass accounts must be excluded from all policies. Which feature should the administrator implement?

A.Conditional Access policies with sign-in risk and location conditions
B.Identity Protection risk policies
C.Privileged Identity Management (PIM)
D.Azure AD Identity Governance
AnswerA

Conditional Access policies are the actual enforcement layer for risk-based access controls in Microsoft Entra ID. The sign-in risk condition, calculated in real time by Identity Protection, can be combined with location conditions such as named locations or trusted IPs to require MFA, force a password change, or block access entirely. This is the correct approach because it directly applies risk and geographic context to the authentication request, and your P2 licenses include the required risk detection features.

Why this answer

Conditional Access policies in Microsoft Entra ID allow combining sign-in risk conditions with location conditions (e.g., 'Not trusted IPs' or 'All trusted locations' set to false) to target only sign-ins from outside the corporate network. The policy can be configured to require a password change for medium risk and block access for high risk, while excluding break-glass accounts via the 'Exclude' tab using a dedicated group.

Exam trap

The trap here is that candidates confuse Identity Protection risk policies (which lack location scoping) with Conditional Access policies (which support both risk and location conditions), leading them to select Option B despite its inability to meet the location requirement.

How to eliminate wrong answers

Option B is wrong because Identity Protection risk policies (user risk and sign-in risk policies) operate at the tenant level and cannot be scoped to location conditions like 'outside corporate network'; they apply globally to all sign-ins. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time role activation and approval workflows, not sign-in risk-based access controls or password change requirements. Option D is wrong because Azure AD Identity Governance focuses on access reviews, entitlement management, and lifecycle workflows, not real-time sign-in risk enforcement or location-based conditional access.

534
MCQhard

A company uses dynamic groups based on department attribute. A user moved from Sales to Marketing but the group membership did not update after 48 hours. What should the admin do first?

A.Delete and recreate the group
B.Run a PowerShell script to update membership
C.Wait another 24 hours
D.Manually refresh the dynamic group in Azure AD
AnswerD

In the Microsoft Entra admin center, navigate to Groups, open the specific dynamic group, and select the Manual Refresh (or Reprocess) action from the Dynamic membership rules pane to immediately trigger recalculation. This operation forces Microsoft Entra ID to re-run the membership query against current user attribute values, including the department field, and to add or remove members accordingly. This is the supported way to resolve stale dynamic group membership without recreating the group or using unsupported PowerShell commands.

Why this answer

Azure AD dynamic group membership evaluation is not instantaneous; it occurs on a periodic schedule. When a user's attribute changes, the admin can manually trigger a refresh by selecting 'Refresh' on the dynamic group's overview page in the Azure portal, which forces an immediate evaluation of the membership rules. This is the first troubleshooting step before waiting longer or using other methods.

Exam trap

The trap here is that candidates assume dynamic group membership updates are instantaneous or that PowerShell can force a refresh, when in fact the only supported manual trigger is through the Azure portal or Graph API, and waiting is not the first recommended action.

How to eliminate wrong answers

Option A is wrong because deleting and recreating the group would cause loss of group settings, assigned licenses, and policies, and is an unnecessary destructive action when a manual refresh can resolve the delay. Option B is wrong because there is no native PowerShell cmdlet to force a dynamic group membership refresh; the only supported method is through the Azure portal or Microsoft Graph API. Option C is wrong because waiting another 24 hours is not a proactive troubleshooting step; the admin should first attempt a manual refresh to expedite the evaluation.

535
Multi-Selectmedium

Which TWO actions can you perform using Microsoft Purview Data Loss Prevention (DLP) policies?

Select 2 answers
A.Set retention periods for documents containing credit card numbers.
B.Show a policy tip to users when they attempt to share sensitive data.
C.Block users from sharing sensitive information via email.
D.Add a watermark to sensitive documents.
E.Automatically encrypt sensitive files when shared.
AnswersB, C

Policy tips deliver real-time, in-context warnings within supported apps such as Outlook, Word and Teams when a user's action matches a DLP rule condition, satisfying the requirement to notify users attempting to share sensitive data. Enforcement occurs at the point of egress, letting users justify or override before the item leaves the tenant.

Why this answer

Option B is correct because Microsoft Purview DLP policies can display policy tips to users in supported apps (for example, Outlook, Word, Excel, and SharePoint) when their actions match a DLP rule, warning them before they share sensitive data. Option C is correct because DLP policies can enforce blocking actions, such as preventing users from sending emails containing sensitive information like credit card or Social Security numbers, via Exchange/Outlook and other workloads. Option A is not a DLP function; retention periods are configured with retention labels and retention policies in Microsoft Purview Data Lifecycle Management (or records management), not DLP.

Option D is not a DLP action; watermarks are applied through sensitivity labels with content marking (or Azure Information Protection), not DLP policies. Option E is not a DLP action; automatic encryption is achieved through sensitivity labels with encryption settings, not DLP, which focuses on detecting and restricting/blocking sharing rather than encrypting files.

Exam trap

MS-102 often tests the specific actions DLP can take versus those it cannot, such as encryption or watermarking; candidates may incorrectly assume DLP can encrypt or watermark files.

536
MCQmedium

An organization uses Microsoft Entra ID P2 licenses. They want to implement a policy that forces users to perform multi-factor authentication (MFA) only when they sign in from an untrusted location. The trusted locations include the corporate office IP range. Which type of policy should they create?

A.Identity Protection user risk policy
B.Conditional Access policy
C.MFA registration policy
D.Authentication methods policy
AnswerB

A Conditional Access policy is the correct tool because it can include a location condition that references named locations or trusted/untrusted IP ranges. When a user attempts to sign in from a location that is not trusted, the policy's grant control can require MFA as an additional verification step. This matches the requirement to prompt for MFA only from untrusted locations, without affecting trusted network sign-ins.

Why this answer

Conditional Access policies in Microsoft Entra ID allow administrators to enforce MFA based on conditions like location. By configuring a policy that targets all users and cloud apps, with a condition excluding trusted IP ranges (corporate office), MFA is only triggered when sign-ins originate from untrusted locations. This is the precise mechanism for location-based MFA enforcement.

Exam trap

The trap here is confusing the purpose of Identity Protection policies (risk-based) with Conditional Access policies (condition-based), leading candidates to select A when the question explicitly requires location-based enforcement.

How to eliminate wrong answers

Option A is wrong because Identity Protection user risk policy evaluates user risk level (e.g., leaked credentials) and can force MFA or password change, but it does not filter by location or trusted IP ranges. Option C is wrong because MFA registration policy only enforces that users register for MFA, not when MFA is prompted based on location. Option D is wrong because Authentication methods policy defines which MFA methods are available (e.g., phone, app) but does not control the conditions under which MFA is required.

537
Multi-Selectmedium

You are configuring Microsoft Defender for Office 365. Which TWO actions should you take to protect users from phishing attacks that use impersonation?

Select 2 answers
A.Create a data loss prevention (DLP) policy to prevent sharing of credentials.
B.Configure anti-spam policies to increase the spam confidence level.
C.Configure anti-phishing policies to protect users from impersonation of custom domains.
D.Configure anti-phishing policies to protect users from impersonation of internal users.
E.Enable Safe Attachments for SharePoint, OneDrive, and Microsoft Teams.
AnswersC, D

In Defender for Office 365, an anti-phishing policy's impersonation settings let you specify custom domains to protect, and the service uses heuristics and machine learning to flag messages whose sending domain appears visually or logically similar to that protected domain. This mitigates attacks where an external sender uses a lookalike domain (e.g., typo-squatted or punycode variants) to trick users into thinking the mail originates from your organization. Because this is an identity-based detection, it is the correct policy category for the stated threat.

Why this answer

Option C is correct because anti-phishing policies in Microsoft Defender for Office 365 include impersonation settings that specifically protect against spoofing of custom domains the organization owns, using domain impersonation protection with actions like quarantining or moving messages to the Junk folder. Option D is also correct because the same anti-phishing policy provides user impersonation protection, which detects messages where the display name matches an internal user (such as executives or key staff) and applies the configured action. These two settings directly address phishing attacks that rely on impersonating trusted domains and internal users.

Option A is not correct because DLP policies govern sensitive information sharing, not impersonation-based phishing. Option B is not correct because raising the spam confidence level (SCL) affects bulk/spam filtering, not impersonation detection. Option E is not correct because Safe Attachments for SharePoint, OneDrive, and Teams protects against malicious files in those workloads, not impersonation phishing.

Exam trap

MS-102 often tests the confusion between anti-spam, anti-phishing, and Safe Attachments features, leading candidates to select spam confidence level adjustments or DLP instead of the specific impersonation settings in anti-phishing policies.

538
MCQmedium

Your organization uses Microsoft Defender XDR and Microsoft 365 E5 licenses. You are a security administrator. The security team wants to receive email notifications for high-severity incidents only. You need to configure the notification settings. What should you do?

A.In the Microsoft Defender XDR portal, go to Settings > Microsoft 365 Defender > Email notifications, and create a notification for high-severity incidents.
B.Create an incident response rule that sends an email when a high-severity incident is created.
C.Use the Microsoft Purview compliance portal to create an alert policy.
D.Configure a service health notification in the Microsoft 365 admin center.
AnswerA

Microsoft Defender XDR email notifications are configured under Settings > Microsoft 365 Defender > Email notifications, where you define the incident severity threshold. Creating a notification scoped to high severity delivers exactly the requested alerts, filtering out medium and low incidents.

Why this answer

In Microsoft Defender XDR, email notifications for incidents are configured under Settings > Microsoft 365 Defender > Email notifications. You can create a notification rule that specifies the severity level (e.g., high) and recipients. This directly fulfills the requirement to receive email notifications for high-severity incidents only.

Exam trap

MS-102 often tests the confusion between incident response rules (which automate actions) and email notification settings (which send emails), leading candidates to choose the wrong feature.

How to eliminate wrong answers

Option B is wrong because incident response rules are used to automate actions like assigning or tagging incidents, not to send email notifications; they cannot trigger emails. Option C is wrong because Microsoft Purview compliance portal alert policies are for compliance-related alerts (e.g., DLP, eDiscovery), not for Defender XDR incidents. Option D is wrong because service health notifications in the Microsoft 365 admin center inform about service outages and advisories, not security incidents.

539
Matchingmedium

Match each Microsoft 365 role to its administrative scope.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Full access to all admin features

Resets passwords for non-admins

Manages Exchange Online

Manages users and groups

Manages security policies

Why these pairings

These roles are part of Azure AD role-based access control. The correct matches are: Global Administrator (full access), User Administrator (users/groups), Exchange Administrator (Exchange settings). Common confusions include mixing Global and User Administrator scopes, or User and Exchange Administrator scopes.

540
MCQmedium

Your organization has a Microsoft 365 E5 tenant with 10,000 users. You need to ensure that when a user is detected as high-risk by Microsoft Entra ID Protection, the user is automatically blocked from accessing sensitive SharePoint sites. The solution should minimize administrative overhead. What should you do?

A.Create a Conditional Access policy targeting high-risk users, apply to SharePoint, and set 'Block access' or 'Use app enforced restrictions'.
B.Create a session policy in Microsoft Defender for Cloud Apps to block high-risk users from accessing SharePoint.
C.Configure a user risk policy in Microsoft Entra ID Protection to block sign-ins for high-risk users.
D.Deploy Microsoft Sentinel and create a custom analytics rule to trigger an automated response via Logic App.
AnswerA

Conditional Access policies natively consume Entra ID Protection risk signals. By selecting 'High risk' under User risk and assigning the SharePoint cloud app, you can enforce access controls directly: 'Block access' fully prevents access, while 'Use app enforced restrictions' applies SharePoint's built-in restricted-access user policy. This is the most straightforward, scenario-specific configuration for preventing high-risk users from reaching SharePoint.

Why this answer

A Conditional Access (CA) policy can directly target 'High risk' users (via Microsoft Entra ID Protection risk detection) and apply to SharePoint. By setting the grant control to 'Block access' or 'Use app enforced restrictions', you automatically block or restrict access to sensitive SharePoint sites without manual intervention, minimizing administrative overhead. This integrates natively with Microsoft 365 and requires no additional services or custom scripting.

Exam trap

The trap here is that candidates often confuse a user risk policy in Entra ID Protection (which blocks all sign-ins globally) with a Conditional Access policy (which can target specific applications like SharePoint), leading them to choose Option C instead of A.

How to eliminate wrong answers

Option B is wrong because a session policy in Microsoft Defender for Cloud Apps (MCAS) can only monitor or control access in real time after the user is already authenticated; it does not natively block access based on Entra ID Protection risk level without additional configuration, and it introduces extra overhead. Option C is wrong because a user risk policy in Microsoft Entra ID Protection blocks sign-ins globally (i.e., prevents authentication entirely), which is too broad and would block the user from all applications, not just sensitive SharePoint sites. Option D is wrong because deploying Microsoft Sentinel and creating a custom analytics rule with a Logic App is overly complex and introduces significant administrative overhead, violating the 'minimize administrative overhead' requirement; the native CA policy is simpler and more efficient.

541
Multi-Selectmedium

Which TWO actions can you perform using Microsoft Purview eDiscovery (Premium)? (Choose two.)

Select 2 answers
A.Place a legal hold on custodians' mailboxes and sites.
B.Export search results to a local computer for review.
C.Create and apply retention labels to documents.
D.Automatically delete emails older than a specified date.
E.Configure sensitivity labels to encrypt documents.
AnswersA, B

Custodial holds preserve mailbox and site content in place, satisfying the legal-hold requirement during an investigation. eDiscovery (Premium) adds custodian management and hold notifications beyond standard eDiscovery, keeping potentially relevant data immutable until the case closes.

Why this answer

Option A is correct because eDiscovery (Premium) supports placing legal holds on custodians, which preserves mailbox and site content (including Exchange mailboxes, SharePoint sites, and OneDrive accounts) to prevent spoliation during an investigation. Option B is correct because eDiscovery (Premium) allows you to export search results and review sets to a local computer for offline review, typically via the Export tool in the case. Option C is incorrect because retention labels are created and published through Microsoft Purview Records Management or Data Lifecycle Management, not through eDiscovery (Premium).

Option D is incorrect because automatic deletion of emails by age is handled by retention policies in Data Lifecycle Management, not eDiscovery (Premium). Option E is incorrect because sensitivity labels and encryption are configured through Microsoft Purview Information Protection, not eDiscovery (Premium).

542
Multi-Selectmedium

You are a Microsoft 365 Administrator for a company that is implementing a hybrid identity solution with Active Directory Federation Services (AD FS) for single sign-on (SSO). The company has recently acquired a subsidiary with its own on-premises Active Directory domain. You need to ensure that the identity lifecycle for users from the subsidiary is managed effectively through Microsoft Entra ID (formerly Azure AD) and that licensing is assigned efficiently. Which three of the following actions should you take? (Choose three.)

Select 3 answers
.Configure Microsoft Entra Connect to synchronize identities from the subsidiary’s Active Directory domain, and use group-based licensing to automatically assign Microsoft 365 licenses to synced users based on their department attribute.
.Create a new Microsoft Entra tenant for the subsidiary and configure cross-tenant synchronization to bring users into the main tenant.
.Use Microsoft Entra Connect to implement a filtered synchronization scope so that only users from the subsidiary’s sales department are synchronized initially.
.Configure Microsoft Entra cloud sync for the subsidiary domain to synchronize users, then assign licenses manually through PowerShell scripts to avoid any inheritance issues.
.Enable Microsoft Entra ID Governance’s Entitlement Management to create access packages that include Microsoft 365 licenses and automatically assign them to users based on their membership in dynamic groups.
.Configure password hash synchronization (PHS) for the subsidiary domain because AD FS cannot coexist with directory synchronization on separate domains.

Why this answer

Options A, C, and E are correct. A: Microsoft Entra Connect can synchronize identities from multiple on-premises AD forests into a single Microsoft Entra tenant, and group-based licensing allows automatic assignment of Microsoft 365 licenses based on directory attributes like department, ensuring efficient lifecycle management. C: Filtered synchronization scope (e.g., using OU or attribute filtering) lets you initially synchronize only a subset of users (like sales) to control the rollout and test the hybrid identity configuration.

E: Microsoft Entra ID Governance’s Entitlement Management can create access packages that include licenses and assign them via dynamic group membership, providing automated, policy-driven license assignment that integrates with identity lifecycle. B is incorrect because creating a separate tenant for the subsidiary would create administrative overhead and fragmentation; cross-tenant synchronization is not needed for multi-forest sync to a single tenant. D is incorrect because Microsoft Entra cloud sync is for simple sync scenarios and does not support AD FS; in a hybrid environment with AD FS, Microsoft Entra Connect is required.

F is incorrect because password hash synchronization is not required to coexist with AD FS; AD FS can be used together with directory synchronization from multiple domains, and PHS is an optional feature.

Exam trap

The trap here is that candidates often assume a separate tenant is required for an acquired subsidiary (Option B) or that cloud sync is equivalent to Entra Connect for AD FS scenarios (Option D), when in fact multi-forest sync with a single tenant and group-based licensing is the recommended approach for hybrid identity lifecycle management.

543
Multi-Selectmedium

A security administrator is configuring Microsoft Defender for Cloud Apps to protect against data exfiltration from SaaS apps. The administrator wants to create a policy that alerts when a user attempts to download more than 50 files from SharePoint Online within 5 minutes. Which two components must be configured to achieve this? (Choose two.)

Select 2 answers
A.File policy
B.Session policy
C.Activity policy
D.Conditional Access App Control
E.App connector for SharePoint Online
AnswersC, E

An activity policy in Microsoft Defender for Cloud Apps evaluates user activities against repeat-activity and threshold criteria, such as more than 50 downloads within 5 minutes. It satisfies the stem's alerting requirement by triggering on the defined SharePoint Online download pattern.

Why this answer

The correct answers are C (Activity policy) and E (App connector for SharePoint Online). An activity policy is needed to define the threshold (50 files in 5 minutes) and trigger an alert when exceeded. The app connector for SharePoint Online must be enabled to allow Defender for Cloud Apps to monitor SharePoint activity.

Option A (File policy) is incorrect because file policies govern file sharing and collaboration, not download counts. Option B (Session policy) is used for real-time session control, not alerting on activity counts. Option D (Conditional Access App Control) is used to enforce access policies, not for monitoring specific activities.

544
MCQeasy

Contoso uses Microsoft Entra ID P2. Users report that password reset self-service does not work. You verify that the users have the required license. What should you check next?

A.Ensure the users are in a group scoped for SSPR
B.Check that the users have registered for SSPR
C.Confirm the users have Microsoft Entra ID P1 licenses
D.Verify SSPR is enabled in Microsoft Entra ID
AnswerD

The correct first step is to open the Microsoft Entra admin center, go to Password reset > Properties, and verify that the 'Self-service password reset enabled' toggle is set to 'All' or 'Selected' instead of 'None'. By default, this setting is 'None', which disables the feature entirely even for users with P2 licenses and enrolled authentication methods. This matches the known requirement that SSPR must be explicitly enabled by an administrator. You should also confirm that the authentication methods under 'Authentication methods' are configured, but enabling the feature is the primary action needed.

Why this answer

The users already have the required Microsoft Entra ID P2 license, which includes SSPR functionality. However, SSPR must be explicitly enabled at the tenant level in Microsoft Entra ID under 'Password reset' settings before users can use the self-service password reset feature. Without this tenant-wide enablement, even licensed users cannot reset their passwords.

Exam trap

The trap here is that candidates often assume that having the correct license (P2) automatically enables SSPR, but Microsoft requires an explicit tenant-level toggle to activate the feature, and the question's phrasing 'does not work' points to the most fundamental missing configuration.

How to eliminate wrong answers

Option A is wrong because SSPR can be enabled for 'All users' or 'Selected' groups; scoping to a specific group is not required for SSPR to work—it is a configuration choice, not a prerequisite. Option B is wrong because user registration for SSPR is a step that occurs after SSPR is enabled; if SSPR is not enabled, users cannot register. Option C is wrong because the question states users already have the required license (Microsoft Entra ID P2), which includes all P1 features; checking for P1 licenses is redundant and irrelevant.

545
MCQmedium

The exhibit shows a DLP policy configuration. A user reports that they cannot share a document containing a credit card number from OneDrive for Business. However, the document was shared successfully last week. What is the most likely reason for the change?

A.The DLP policy was recently deployed or updated.
B.The DLP policy requires administrator override for sharing.
C.The DLP policy is applied only to SharePoint Online, not OneDrive.
D.The DLP policy does not include Microsoft Teams.
AnswerA

When a Microsoft Purview DLP policy with a Block external-sharing action is newly deployed or updated, the policy engine starts evaluating new sharing operations from that point forward. In this scenario the user's earlier successful share almost certainly occurred when no restrictive policy was active, and the current attempt to share another link is now being blocked by the newly enforced rule. This timing makes a recent deployment or update the most plausible explanation for a sudden change from permitted to blocked external sharing.

Why this answer

The most likely reason is that the DLP policy was recently deployed or updated. DLP policies in Microsoft 365 are evaluated in near real-time, and a newly deployed or modified policy will immediately enforce its rules on content sharing. Since the document was shared successfully last week, the policy change is the most plausible cause for the sudden block.

Exam trap

The trap here is that candidates may assume DLP policies are static and only apply to new content, but Microsoft 365 DLP policies are dynamic and can affect existing shares when deployed or updated.

How to eliminate wrong answers

Option B is wrong because DLP policies do not require an administrator override for sharing; they either block or allow sharing based on policy rules, and an override is an optional feature that must be explicitly configured. Option C is wrong because DLP policies in Microsoft 365 can be applied to both SharePoint Online and OneDrive for Business, and the exhibit shows a policy that includes OneDrive. Option D is wrong because the question is about sharing from OneDrive for Business, not Microsoft Teams, and the policy's inclusion of Teams is irrelevant to the reported issue.

546
MCQeasy

Your organization uses Microsoft Purview Communication Compliance to detect inappropriate messages in Microsoft Teams. You need to configure a policy that monitors for potential harassment based on a built-in classifier. The policy should alert designated reviewers when a match is found. What is the minimum configuration required?

A.Create a communication compliance policy, select the built-in harassment classifier, specify the users to monitor, and assign reviewers.
B.Create a retention policy for Teams messages, then create a communication compliance policy with the harassment classifier.
C.Create a DLP policy that blocks harassment, then configure communication compliance to review DLP alerts.
D.Apply a sensitivity label to all Teams messages, then create a communication compliance policy that scans for the label.
AnswerA

Creating a communication compliance policy is the sole configuration required to start detecting harassment. The built-in harassment classifier uses pre-trained machine learning models to flag potentially abusive or threatening language in Exchange, Teams, and Yammer messages. You must specify the users or groups whose messages are monitored, and assigning reviewers ensures the flagged messages are investigated and resolved. No additional components such as retention policies, DLP policies, or sensitivity labels are needed as prerequisites.

Why this answer

The minimum configuration to monitor for potential harassment using Communication Compliance is to create a communication compliance policy, select the built-in harassment classifier, specify the users to monitor, and assign reviewers. No retention policy, DLP policy, or sensitivity label is required.

547
MCQmedium

Your organization uses Microsoft Purview eDiscovery (Premium) for a legal investigation. You need to collect data from Microsoft Teams chat messages and channel conversations. The case manager wants to search for specific keywords and exclude irrelevant content. What should you do?

A.Use Content Search (Standard) with keyword queries.
B.Create a DLP policy to capture matching content.
C.Use Communication Compliance to review messages.
D.Create a collection in eDiscovery (Premium) with a KQL query to search Teams data.
AnswerD

Create a collection in eDiscovery (Premium) and use a KQL query to search Teams data; this is the correct approach because eDiscovery Premium natively indexes Teams chats, threads, meeting messages, and attachments, and supports advanced query filters for scoping. The collection ingests hits into a review set where you can analyze, tag, add to a hold, and export with metadata for litigation.

Why this answer

EDiscovery (Premium) collections allow searching Microsoft Teams chat messages and channel conversations using KQL queries with conditions to include specific keywords and exclude irrelevant content. Option A is incorrect because Content Search (Standard) is less powerful and lacks advanced filtering capabilities for Teams data. Option B is incorrect because DLP policies are designed for data loss prevention, not legal discovery.

Option C is incorrect because Communication Compliance is for monitoring communications, not for eDiscovery searches.

548
MCQhard

Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that automatically blocks downloads of files containing sensitive information from SharePoint Online to unmanaged devices. What type of policy should you create?

A.Session policy
B.Microsoft Purview Data Loss Prevention policy
C.Activity policy
D.File policy
AnswerA

Session policies apply real-time controls during a user session, including blocking downloads of files containing sensitive information from SharePoint Online to unmanaged devices. Access and activity policies cannot enforce this inline download restriction, so a session policy is required.

Why this answer

A session policy in Microsoft Defender for Cloud Apps is used to enforce real-time controls on user sessions, including blocking downloads of files with sensitive information from SharePoint Online to unmanaged devices. Session policies leverage Conditional Access App Control to proxy the session and apply DLP-like controls.

Exam trap

MS-102 often tests the distinction between session policies (real-time, proxy-based controls) and activity policies (alerting/governance) or Purview DLP policies (data-centric, not session-based).

How to eliminate wrong answers

Option B is wrong because a Microsoft Purview DLP policy can block sharing or downloading in some contexts, but for real-time session control with unmanaged devices, Defender for Cloud Apps session policies are the correct tool. Option C is wrong because an activity policy is used for alerting or governance actions based on user activities, not for real-time blocking of downloads. Option D is wrong because a file policy in Defender for Cloud Apps is used for malware detection and file labeling, not for blocking downloads based on sensitivity.

549
MCQeasy

Your company is using Microsoft 365 Business Premium. You want to ensure that all company-owned Windows 10 devices are automatically upgraded to Windows 11 when it becomes available through Windows Update. What should you configure?

A.Create a Windows 10 update ring policy in Intune that deploys quality updates.
B.Create a feature update policy for Windows 10 devices in Intune, targeting the Windows 11 version.
C.Create a device compliance policy in Intune that requires Windows 11.
D.Configure a Windows 11 readiness assessment in Microsoft Intune.
AnswerB

A feature update policy is the Intune-native mechanism to deploy a specific Windows feature update version, and by targeting the Windows 11 version, you instruct eligible Windows 10 devices to upgrade to Windows 11. This policy leverages Windows Update for Business to install the chosen feature update and then keeps devices on that version until you change the policy. Unlike an update ring or compliance policy, this is an actual remediation action that performs the in-place OS upgrade.

Why this answer

A feature update policy in Intune is specifically designed to upgrade Windows devices from one version to another, such as from Windows 10 to Windows 11. By targeting the Windows 11 version in this policy, you ensure that eligible Windows 10 devices automatically receive the upgrade when it becomes available via Windows Update. This is the correct mechanism for controlling OS version upgrades in a Microsoft 365 Business Premium environment.

Exam trap

The trap here is that candidates often confuse update ring policies (which handle quality updates and deferral settings) with feature update policies (which are required for OS version upgrades), leading them to select option A instead of B.

How to eliminate wrong answers

Option A is wrong because a Windows 10 update ring policy for quality updates only manages monthly cumulative and security patches, not feature upgrades like moving from Windows 10 to Windows 11. Option C is wrong because a device compliance policy enforces security and configuration requirements on devices that are already enrolled, but it cannot trigger an OS upgrade; it only reports non-compliance if the OS version does not match the policy. Option D is wrong because a Windows 11 readiness assessment in Intune only evaluates hardware compatibility and provides a report, but it does not configure or deploy the actual upgrade to devices.

550
MCQmedium

Your organization uses Microsoft Entra ID and has enabled Microsoft Entra Domain Services (Azure AD DS). You need to ensure that legacy applications that require NTLM authentication can still authenticate against the managed domain. What should you configure?

A.Configure Kerberos delegation
B.Disable NTLM v1 authentication on the managed domain
C.Enable NTLM v1 authentication on the managed domain
D.Enable password hash synchronization for the managed domain
AnswerC

Enabling NTLM v1 authentication on the Microsoft Entra Domain Services managed domain directly addresses the requirement for legacy applications. Microsoft Entra Domain Services typically prioritises more secure protocols like NTLM v2 and Kerberos. However, older applications often lack support for these newer versions and specifically mandate NTLM v1. Configuring the managed domain to support NTLM v1 allows these legacy applications to successfully authenticate, ensuring their continued operation within the environment.

Why this answer

Legacy applications that require NTLM authentication must have NTLM v1 enabled on the managed domain because Azure AD DS, by default, disables NTLM v1 for security reasons. Enabling NTLM v1 allows these older applications to authenticate against the managed domain using the NTLM protocol, which is necessary when Kerberos is not supported.

Exam trap

The trap here is that candidates often confuse enabling NTLM v1 with disabling it for security, or think that password hash synchronization alone enables NTLM authentication, but the key is that NTLM v1 must be explicitly enabled on the managed domain for legacy apps that require it.

How to eliminate wrong answers

Option A is wrong because Kerberos delegation is used for constrained or unconstrained delegation of Kerberos authentication, not for enabling NTLM authentication for legacy apps. Option B is wrong because disabling NTLM v1 would prevent legacy applications that require NTLM from authenticating, which is the opposite of what is needed. Option D is wrong because password hash synchronization is already required for Azure AD DS to function and does not control which authentication protocols are enabled on the managed domain.

551
MCQmedium

An organization is involved in a legal case and needs to preserve all emails in a user's mailbox, including future emails, without deleting or modifying them. The user must continue to work normally. Which Microsoft Purview feature should be applied to the user's mailbox?

A.Litigation Hold
B.Retention policy
C.Sensitivity label
D.Data Loss Prevention (DLP)
AnswerA

Litigation Hold is the correct choice because it preserves all mailbox content in its original state, including items that users edit or delete, by placing the entire mailbox on hold within the Recoverable Items folder. This in-place hold suspends the normal purging of deleted items and version tracking, allowing legal teams to review everything via eDiscovery without disrupting user workflows. Unlike other options, Litigation Hold is specifically designed to meet legal preservation obligations and can be applied to a user's entire mailbox or specific folders.

Why this answer

Litigation Hold (option A) is the correct feature because it preserves all mailbox content, including future emails, in its original state without allowing deletion or modification by users or automated processes. Unlike a retention policy, Litigation Hold places the entire mailbox on indefinite hold, ensuring that any item changed or deleted by the user is retained in the Recoverable Items folder, while the user continues to work normally. This meets the legal preservation requirement without disrupting daily operations.

Exam trap

Microsoft often tests the distinction between Litigation Hold and Retention Policy, where candidates mistakenly choose Retention Policy because they think it 'retains' data, but they miss that Retention Policy can delete data after a period, whereas Litigation Hold preserves everything indefinitely without deletion.

How to eliminate wrong answers

Option B (Retention policy) is wrong because retention policies are designed to manage data lifecycle by deleting or retaining items based on age or rules, not to preserve all content indefinitely for legal hold; they can delete items after a specified period, which violates the preservation requirement. Option C (Sensitivity label) is wrong because sensitivity labels classify and protect data based on sensitivity (e.g., encryption or marking), but they do not prevent deletion or modification of emails, nor do they preserve mailbox content for legal purposes. Option D (Data Loss Prevention (DLP)) is wrong because DLP policies detect and prevent accidental sharing of sensitive information (e.g., credit card numbers) but do not impose holds or preserve mailbox items; they focus on data exfiltration prevention, not legal preservation.

552
Multi-Selecthard

Which THREE actions can be taken by a Microsoft Purview Data Loss Prevention (DLP) policy in Exchange Online?

Select 3 answers
A.Block the email from being sent
B.Allow the sender to override the block
C.Block all emails from the sender
D.Notify the sender with a policy tip
E.Encrypt the email message
AnswersA, D, E

In Microsoft Purview Data Loss Prevention (DLP), a policy can be configured with an action to block the transmission of an email that contains sensitive information. When the condition is met, the DLP engine can prevent the message from leaving the sender's mailbox, either silently or with a policy tip, depending on the rule configuration. This is a primary enforcement mechanism to stop data exfiltration before it occurs, as the email is never delivered to the recipient.

Why this answer

DLP policies in Exchange Online can block sending, encrypt the message, and notify the sender with a policy tip. Justifying override is not an action; it's a user response. Blocking all emails is not granular; DLP actions are rule-based.

553
MCQmedium

A security administrator wants to automatically block malicious IP addresses from sending email to Exchange Online mailboxes. Which Microsoft Defender component should be configured?

A.Exchange Online Protection (EOP)
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Identity
D.Microsoft Defender for Cloud Apps
AnswerA

Exchange Online Protection (EOP) is the correct answer because its connection filtering feature evaluates the source IP address of every inbound SMTP connection against Microsoft's default and tenant-specific IP allow/block lists and real-time reputation data. Malicious IPs are rejected at the transport layer before the message is accepted, and admins can explicitly add IPs to the block list in the anti-spam policy to enforce a custom allow/deny set for inbound mail flow.

Why this answer

Exchange Online Protection (EOP) is the cloud-based email filtering service that protects Exchange Online mailboxes from spam, malware, and malicious IP addresses. It includes connection filtering, which can automatically block messages from specified IP addresses by using the default connection filter policy or custom IP Allow/Block lists. This makes EOP the correct component for blocking malicious IPs from sending email to Exchange Online.

Exam trap

The trap here is that candidates may confuse Microsoft Defender for Endpoint (which handles device-level threats) with email security, or assume that Defender for Cloud Apps (a CASB) can filter inbound email, when in fact only EOP provides the connection filtering and IP block list functionality for Exchange Online mail flow.

How to eliminate wrong answers

Option B (Microsoft Defender for Endpoint) is wrong because it focuses on endpoint detection and response (EDR) for devices, not email traffic filtering or IP-based blocking for Exchange Online. Option C (Microsoft Defender for Identity) is wrong because it monitors on-premises Active Directory for identity-based threats (e.g., lateral movement, privilege escalation), not inbound email from IP addresses. Option D (Microsoft Defender for Cloud Apps) is wrong because it provides cloud access security broker (CASB) capabilities for SaaS applications, including shadow IT discovery and app permissions, but does not directly block IP addresses from sending email to Exchange Online.

554
MCQmedium

Your organization uses Microsoft 365 Defender for Office 365. You need to ensure that phishing emails reported by users are automatically submitted for analysis in Microsoft Defender XDR. What should you configure?

A.Modify the anti-phishing policy to include user-reported submissions.
B.Use the Attack simulation training to collect user reports.
C.Enable Safe Attachments policy to automatically submit reported messages.
D.Configure the User-reported messages settings in the Microsoft 365 Defender portal.
AnswerD

Configuring the User-reported messages settings in the Microsoft 365 Defender portal is the correct approach because this setting controls the end-user reporting experience and how reported messages are submitted: to Microsoft for automated analysis, to a designated internal mailbox for manual triage, or to both. It also integrates with the Submission portal, enabling admins to view, analyze, and take action on user-reported messages. This is the sole central configuration point that governs user-reported submissions for analysis in Defender for Office 365.

Why this answer

The User-reported messages settings in the Microsoft 365 Defender portal allow you to configure how user-reported phishing emails are handled. By enabling automatic submission to Microsoft for analysis, you ensure that reported messages are sent directly to the Microsoft security team for threat intelligence and policy tuning. This is the correct setting because it specifically controls the submission behavior for user-reported messages in Defender for Office 365.

Exam trap

The trap here is that candidates often confuse the anti-phishing policy (which handles detection settings) with the User-reported messages settings (which handles submission of user-reported emails), leading them to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because the anti-phishing policy controls protection settings like spoof intelligence and impersonation detection, not the submission of user-reported messages for analysis. Option B is wrong because Attack simulation training is used to create and manage simulated phishing campaigns, not to automatically submit real user-reported emails to Microsoft. Option C is wrong because Safe Attachments policy handles the scanning of email attachments in a sandbox environment, not the submission of user-reported messages for analysis.

555
MCQeasy

Your company has a Microsoft 365 E5 tenant. You need to ensure that all external emails are marked with a warning banner at the top of the email body. What should you configure?

A.A Safe Attachments policy in Microsoft Defender for Office 365.
B.External email tagging in the Microsoft 365 Defender portal.
C.A DLP policy with a sensitive information type.
D.A mail flow rule (transport rule) to add a disclaimer.
AnswerD

A mail flow rule (transport rule) in Exchange Online can apply a disclaimer to emails that meet specified conditions, such as being sent from an external sender. This rule can append a customized HTML banner to the message header or footer, which is exactly the visual warning required. This is the correct method for adding a disclaimer to external emails.

Why this answer

A mail flow rule (transport rule) in Exchange Online can be configured to prepend a disclaimer (warning banner) to the body of all external emails. This is the only mechanism that directly modifies the email body content for inbound or outbound messages based on sender/recipient criteria, such as when the sender is external to the organization.

Exam trap

The trap here is that candidates confuse 'external email tagging' (which adds a header or subject prefix) with adding a visible banner inside the email body, leading them to choose Option B instead of the correct mail flow rule.

How to eliminate wrong answers

Option A is wrong because Safe Attachments policies in Microsoft Defender for Office 365 are designed to detect and block malicious attachments, not to add visual warning banners to email bodies. Option B is wrong because External email tagging in the Microsoft 365 Defender portal adds an external tag to the email subject line or as a header, not a banner within the email body. Option C is wrong because a DLP policy with a sensitive information type is used to detect and protect sensitive data (e.g., credit card numbers) and can apply actions like blocking or notifying, but it cannot add a custom warning banner to the top of the email body.

556
MCQhard

Your company is planning to adopt Microsoft Copilot for Microsoft 365. The security team is concerned about data leakage. What must you implement to ensure that Copilot respects your organization's sensitivity labels and data classification?

A.Use Microsoft Defender for Cloud Apps to control Copilot
B.Configure Data Loss Prevention (DLP) policies
C.Deploy Microsoft Purview Information Protection with sensitivity labels
D.Enable Customer Lockbox
AnswerC

Deploying Microsoft Purview Information Protection with sensitivity labels is correct because Copilot respects these labels as the core data classification signal across files, emails, SharePoint sites, and Teams messages. When a label is applied, Copilot inherits the label's encryption and permission settings, and it either restricts content from being used in a prompt or adds the appropriate label/visual markings to its generated output. This gives organizations a direct way to ensure Copilot does not leak sensitive or confidential information, fulfilling the label-aware protection requirement.

Why this answer

Microsoft Purview Information Protection with sensitivity labels is the correct answer because Copilot for Microsoft 365 uses these labels to enforce data governance at the content level. When a sensitivity label is applied to a document or email, Copilot respects that label's encryption, marking, and access restrictions, preventing the model from generating responses that leak classified data. This is the foundational mechanism for ensuring Copilot adheres to your organization's data classification policies.

Exam trap

The trap here is that candidates often confuse DLP policies (which monitor and block data in transit or at rest) with sensitivity labels (which define and enforce data classification at the content level), leading them to choose DLP as the solution for controlling Copilot's behavior.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps is a CASB (Cloud Access Security Broker) that provides visibility and control over cloud app usage, but it does not directly enforce sensitivity labels within Copilot's processing pipeline. Option B is wrong because Data Loss Prevention (DLP) policies detect and prevent sharing of sensitive data after it is created, but they do not control how Copilot accesses or uses labeled content at the time of generation. Option D is wrong because Customer Lockbox provides a control mechanism for Microsoft support personnel to access your data, but it has no role in governing how Copilot respects sensitivity labels or classification.

557
MCQeasy

Your organization is deploying Microsoft 365 for a multinational company. You need to ensure users in different regions authenticate against the nearest Microsoft Entra ID endpoint for performance. What should you configure?

A.Add the appropriate regional subdomain (e.g., us.contoso.com) as a custom domain.
B.No additional configuration is required; Microsoft Entra ID automatically routes to the nearest endpoint.
C.Create a conditional access policy to route authentication to the nearest region.
D.Configure a traffic manager profile in Azure to route authentication requests.
AnswerB

No additional configuration is required because Microsoft Entra ID operates a globally distributed set of authentication front ends that are automatically selected through Microsoft's internal load balancing and DNS infrastructure. When a user signs in, their client resolves the Microsoft-managed login endpoint and is directed to the closest available regional service while the request is then handled consistently with the tenant's home instance. This routing is intrinsic to the platform and designed to optimize latency and resilience for multinational organizations without any tenant-side setup.

Why this answer

Microsoft Entra ID (formerly Azure AD) uses a global anycast network to automatically route authentication requests to the nearest available endpoint based on DNS resolution and network latency. No additional configuration is required because Entra ID's infrastructure is designed to provide optimal performance globally without manual traffic management.

Exam trap

The trap here is that candidates often overthink performance optimization and assume manual configuration (like custom domains or traffic managers) is needed, when Microsoft Entra ID's built-in anycast routing automatically handles regional proximity without any tenant-side setup.

How to eliminate wrong answers

Option A is wrong because adding a regional subdomain as a custom domain does not affect authentication routing; custom domains are used for user principal name (UPN) suffixes and email addresses, not for directing traffic to regional endpoints. Option C is wrong because Conditional Access policies control access based on conditions like location or device state, not the physical routing of authentication traffic to a nearest region. Option D is wrong because Azure Traffic Manager is used for load-balancing traffic to custom endpoints (e.g., web apps), but Microsoft Entra ID's authentication endpoints are managed by Microsoft and cannot be redirected via a Traffic Manager profile.

558
MCQmedium

An organization has registered the domain contoso.com and added it to their Microsoft 365 tenant. What is the next step to use this domain for user email addresses?

A.Add a DNS TXT record provided by Microsoft to the domain registrar
B.Create user accounts with the new domain
C.Configure Exchange Online connectors
D.Set up MX records for email routing
AnswerA

Domain ownership verification in Microsoft 365 is performed by adding the exact TXT record—containing a unique verification string generated in the Microsoft 365 admin center—to the domain's public DNS zone at the registrar. Microsoft periodically queries the TXT record for that domain; when the value matches, the domain is marked as verified and becomes an accepted domain. This must complete successfully before any user accounts, mail routing, or other service records can be associated with the custom domain.

Why this answer

After adding a custom domain to Microsoft 365, the domain's ownership must be verified by adding a specific DNS TXT record provided by Microsoft at the domain registrar. This verification proves you control the domain and is a prerequisite before you can assign user email addresses or configure other DNS records like MX. Without this step, Microsoft 365 will not trust the domain for email routing.

Exam trap

The trap here is that candidates often confuse domain verification (TXT record) with mail routing (MX record) and assume MX records are the immediate next step, but Microsoft 365 requires ownership proof before any DNS-based services can be configured.

How to eliminate wrong answers

Option B is wrong because creating user accounts with the new domain before verification will fail; Microsoft 365 rejects unverified domains for user creation. Option C is wrong because configuring Exchange Online connectors is an advanced step for hybrid or third-party mail flow, not the immediate next step after adding a domain. Option D is wrong because setting up MX records for email routing is done after domain verification, as MX records are used to direct incoming mail and require a verified domain to function correctly.

559
MCQeasy

An administrator needs to configure the default anti-spam policy for all users in the Microsoft 365 Defender portal. Where should the administrator navigate to find these settings?

A.Email & collaboration > Policies & rules > Threat policies > Anti-spam
B.Email & collaboration > Policies & rules > Threat policies > Anti-phishing
C.Email & collaboration > Policies & rules > Threat policies > Anti-malware
D.Email & collaboration > Policies & rules > Threat policies > Safe Attachments
AnswerA

The Anti-spam section in the Microsoft 365 Defender portal (Email & collaboration > Policies & rules > Threat policies) is the proper location to manage the default anti-spam policy, which applies to all recipients. This is where you configure the spam filter policy (e.g., 'Default' policy), connection filter policy, and outbound spam filter settings, including bulk email thresholds, spam actions, and allow/block lists. It directly addresses unwanted bulk email and spam.

Why this answer

The default anti-spam policy is configured under Email & collaboration > Policies & rules > Threat policies > Anti-spam in the Microsoft 365 Defender portal. This is the correct location because anti-spam settings, including the default policy that applies to all users, are managed specifically within the Anti-spam section of Threat policies. The other options address different threat protection areas (anti-phishing, anti-malware, Safe Attachments) that do not contain spam filtering configurations.

Exam trap

The trap here is that candidates often confuse the Anti-spam policy with Anti-phishing or Anti-malware policies because all are under Threat policies, but each addresses a distinct security layer, and the question specifically asks for spam configuration.

How to eliminate wrong answers

Option B is wrong because Anti-phishing policies handle protection against phishing attacks, not spam filtering, and include settings like impersonation protection and spoof intelligence. Option C is wrong because Anti-malware policies manage malware detection and quarantine actions for malicious files, not spam classification. Option D is wrong because Safe Attachments policies are part of Microsoft Defender for Office 365 and focus on scanning email attachments in a sandbox environment, not on spam filtering.

560
MCQmedium

You are the Microsoft 365 administrator for a multinational company. The company has deployed Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps. Recently, the security team detected that a user's credentials were compromised and used to access SharePoint Online from an unusual location. You need to investigate the incident and determine the full scope of the breach. The solution must use Microsoft 365 Defender to correlate events. What should you do first?

A.Use the Microsoft Purview compliance portal to search for the user's activity in audit logs.
B.Use advanced hunting in Microsoft 365 Defender portal to query for events related to the user across workloads.
C.Use Microsoft Defender for Cloud Apps to investigate the user's activity log.
D.Use Microsoft Sentinel to query the user's events from the workspace.
AnswerB

Advanced hunting in the Microsoft 365 Defender portal (now Microsoft Defender XDR) is a KQL-based, unified query interface that spans email, identity, endpoints, and cloud apps. It lets you join schema tables such as EmailEvents, IdentityLogonEvents, and CloudAppEvents to correlate a user's actions across a single incident, enabling detection of lateral movement or exfiltration. This is the correct first step because it uses the native, integrated signal of Defender XDR without additional licensing or setup.

Why this answer

Advanced hunting in the Microsoft 365 Defender portal allows you to query raw, cross-workload telemetry (e.g., from Identity, Exchange Online, SharePoint Online, and Defender for Cloud Apps) in a single Kusto Query Language (KQL) query. This is the most efficient first step to correlate events such as sign-ins, mailbox access, file downloads, and app sessions related to the compromised user, enabling you to determine the full scope of the breach across all Microsoft 365 services.

Exam trap

The trap here is that candidates often default to the audit log (Option A) because it is familiar from compliance scenarios, but the question explicitly requires correlation across workloads using Microsoft 365 Defender, which is only possible with advanced hunting's cross-table queries.

How to eliminate wrong answers

Option A is wrong because the Microsoft Purview compliance portal audit log search provides a limited, filtered view of audit records and does not natively correlate events across workloads like Identity, Defender for Cloud Apps, or advanced threat signals; it also lacks the raw telemetry and cross-query capabilities of advanced hunting. Option C is wrong because Microsoft Defender for Cloud Apps activity logs are scoped to cloud app sessions and do not include identity, mailbox, or endpoint events from other Defender workloads, making it insufficient for a full cross-workload investigation. Option D is wrong because Microsoft Sentinel is a separate SIEM that requires additional licensing, configuration, and data ingestion from Microsoft 365 Defender; it is not the first tool to use when the goal is to correlate events within the Microsoft 365 Defender portal itself.

561
Multi-Selecthard

Your company uses Microsoft Defender for Endpoint and wants to perform a live response on a device. Which THREE prerequisites must be met?

Select 3 answers
A.The user must be assigned a role that includes live response permissions
B.The device must be running a supported operating system (e.g., Windows 10 or newer)
C.The device must be managed by Microsoft Intune
D.The device must have Microsoft Defender Antivirus as the primary antivirus solution
E.The device must be onboarded to Microsoft Defender for Endpoint
AnswersA, B, E

Initiating a live response session is gated by role-based access control (RBAC). The user must be assigned an Azure AD role such as Security Operator, or a custom Defender for Endpoint role with the 'Live response' permission, and must have the device in their assigned scope; without this, the Start session button is unavailable even for an onboarded, supported device.

Why this answer

Live response in Microsoft Defender for Endpoint requires the user to be assigned a role that includes specific live response permissions, such as 'Live response' or 'Live response advanced' under the Microsoft 365 Defender role-based access control (RBAC). Without these permissions, the user cannot initiate a live response session, regardless of other configurations.

Exam trap

The trap here is that candidates often assume Intune management is required for live response, but Microsoft only requires the device to be onboarded to Defender for Endpoint and running a supported OS, with the user having the correct RBAC permissions.

562
MCQmedium

A compliance officer needs to prevent users from accidentally sharing documents containing credit card numbers with external users via email. The block should occur at the time the user attempts to send the email. Which Microsoft Purview feature should be configured?

A.Communication compliance
B.Data Loss Prevention (DLP)
C.Records management
D.Insider risk management
AnswerB

Data Loss Prevention (DLP) policies in Microsoft 365 enforce real-time protection by inspecting email messages for sensitive info types (e.g., credit card numbers, Social Security numbers) and applying actions such as blocking the message from leaving the organization, with optional user override and notification. These policies are integrated with Exchange Online transport rules, allowing them to evaluate outbound mail before delivery. DLP is the correct choice because it directly addresses the requirement to prevent accidental sharing through proactive, policy-based blocking.

Why this answer

Data Loss Prevention (DLP) is the correct feature because it is specifically designed to inspect email content in transit for sensitive data patterns, such as credit card numbers, and enforce policy actions like blocking the message at the transport layer. In Microsoft Purview, DLP policies can be configured to scan Exchange Online messages in real time using sensitive information types (e.g., Credit Card Number) and apply a block action with an optional policy tip to the user before the email leaves the outbound queue.

Exam trap

The trap here is that candidates often confuse Communication compliance (which also monitors email) with DLP, but Communication compliance is a reactive auditing tool for policy violations, not a proactive, inline blocking mechanism for sensitive data.

How to eliminate wrong answers

Option A is wrong because Communication compliance is designed to detect and remediate inappropriate or policy-violating communications (e.g., harassment, insider trading) after they are sent, not to block outbound emails containing sensitive data in real time. Option C is wrong because Records management focuses on classifying, retaining, and disposing of records based on regulatory requirements, not on inspecting or blocking email content during transmission. Option D is wrong because Insider risk management uses analytics to identify risky user activities (e.g., data exfiltration patterns) over time, but it does not provide inline blocking of email messages at the moment of sending.

563
MCQeasy

An administrator wants to restrict which users in the organization can create Microsoft 365 groups. The requirement is that only members of the IT department (identified by the department attribute in Azure AD) should be able to create groups. Which configuration should the administrator use?

A.Azure AD > Groups > Group settings > Group creation settings.
B.Azure AD Identity Governance > Access reviews.
C.Azure AD > Groups > Naming policy.
D.Microsoft 365 admin center > Groups > Add group.
AnswerA

This is correct because Azure AD's Groups > Group settings > General blade contains a group creation setting that lets you restrict who can create Microsoft 365 groups. The 'Group settings' pane includes an option to restrict user ability to create groups to a specific security group. When enabled, only members of that designated security group are allowed to create new Microsoft 365 groups across Azure AD, Teams, and other connected services. This directly addresses the requirement to restrict which users in the organization can create Microsoft 365 groups.

Why this answer

The Azure AD 'Group settings' blade includes a 'Group creation settings' option that allows administrators to restrict group creation to specific security groups. By configuring this setting, the administrator can limit group creation to only members of the IT department, identified by the department attribute in Azure AD, by placing those users into a designated security group.

Exam trap

The trap here is that candidates often confuse the 'Naming policy' (which controls group names) with the 'Group creation settings' (which controls who can create groups), or they mistakenly think that Access Reviews can enforce creation restrictions when it only reviews existing access.

How to eliminate wrong answers

Option B is wrong because Azure AD Identity Governance > Access reviews is used for periodic review and certification of access to groups, applications, and roles, not for controlling who can create groups. Option C is wrong because Azure AD > Groups > Naming policy enforces naming conventions and blocked words for groups, but does not restrict which users can create groups. Option D is wrong because the Microsoft 365 admin center > Groups > Add group is a manual creation interface for administrators and does not provide a tenant-wide policy to restrict group creation to specific users or departments.

564
MCQmedium

You are a security administrator for a company that uses Microsoft Defender XDR. A security incident involving a compromised user account has been escalated. You need to identify all devices where the compromised user account signed in within the last 7 days. Which Microsoft Defender XDR feature should you use?

A.Incident queue filtered by the user's email address
B.Device inventory filtered by the user's primary email
C.Advanced hunting with the IdentityLogonEvents table
D.Microsoft Defender for Cloud Apps activity log
AnswerC

The IdentityLogonEvents table in advanced hunting contains sign-in events from Microsoft Defender for Identity, providing details such as the user account, device name, and timestamp. Querying this table for the compromised user over the last 7 days will list all devices where that account signed in, directly answering the requirement.

Why this answer

Advanced hunting with the IdentityLogonEvents table provides a comprehensive view of sign-in events across devices, including those from Defender for Identity. By querying this table for the compromised user and a 7-day timeframe, you can accurately list all devices where the account signed in, enabling effective incident response.

Exam trap

The trap here is assuming that incident queue or device inventory can provide a complete list of sign-in events, but they lack the granular logon data needed for this investigation.

565
MCQhard

Your company uses Microsoft Entra ID with hybrid joined devices. You need to enforce multi-factor authentication (MFA) for all cloud app access but want to exclude specific locations (trusted IPs). What is the most efficient way to implement this?

A.Use Microsoft Intune to enforce MFA for all corporate devices
B.Enable per-user MFA and exclude trusted IPs in the MFA service settings
C.Configure a user risk policy in Microsoft Entra ID Protection to require MFA when risk is medium or higher
D.Create a Conditional Access policy targeting all cloud apps, requiring MFA, with a condition to exclude trusted IPs
AnswerD

Conditional Access evaluates sign-ins against user, app and location conditions, so a single policy requiring MFA for all cloud apps with trusted IPs excluded satisfies both requirements without per-app configuration or legacy per-user MFA settings.

Why this answer

A Conditional Access policy scoped to 'All cloud apps' with a grant control of 'Require multi-factor authentication' and a location condition excluding trusted IPs is the most efficient and granular way to meet the requirement. Conditional Access is the modern, recommended policy engine in Entra ID and supports named locations (trusted IPs) as a first-class condition, so trusted locations bypass MFA while all other access is challenged. This satisfies both the enforcement and exclusion requirements in a single policy.

Exam trap

MS-102 often tests the confusion between per-user MFA (legacy, limited) and Conditional Access (modern, granular) — candidates who pick per-user MFA miss that CA is the recommended and more capable solution.

How to eliminate wrong answers

Option A is wrong because Intune compliance policies control device configuration and can feed into Conditional Access, but Intune alone does not enforce MFA for cloud app access. Option B is wrong because per-user MFA is the legacy approach — while it does support trusted IP exclusion, it is being deprecated in favor of Conditional Access and lacks the granularity and reporting of CA policies. Option C is wrong because a user risk policy in Entra ID Protection only triggers MFA when risk is medium or high; it does not enforce MFA for all cloud app access regardless of risk, so it fails the 'all cloud app access' requirement.

566
Multi-Selecteasy

Your company is planning to use Microsoft 365 Copilot for Microsoft 365. Which THREE prerequisites are required for Copilot to function? (Choose three.)

Select 3 answers
A.Microsoft Entra ID (formerly Azure AD)
B.Microsoft Sentinel for security monitoring
C.Microsoft Intune for mobile device management
D.A Copilot for Microsoft 365 license assigned to each user
E.An active Microsoft 365 subscription (E3, E5, Business Premium, etc.)
AnswersA, D, E

Microsoft Entra ID is the identity and authentication backbone for Microsoft 365 Copilot. When a user sends a prompt, Copilot uses the Entra ID token to authenticate the user and to determine which resources the user can access through Microsoft Graph. Without Entra ID, there is no verified user identity, no conditional access enforcement, and no way to apply tenant policies to Copilot interactions, so this is a mandatory prerequisite rather than an optional component.

Why this answer

Microsoft Entra ID (formerly Azure AD) is required because Copilot for Microsoft 365 relies on Entra ID for authentication, identity management, and policy enforcement. Without Entra ID, Copilot cannot verify user identities, apply conditional access policies, or access Microsoft Graph to retrieve user and organizational data.

Exam trap

The trap here is that candidates confuse optional security or management services (Sentinel, Intune) with mandatory infrastructure (Entra ID), leading them to select non-essential components as prerequisites.

567
MCQmedium

A compliance officer needs to prevent users from sharing documents labeled 'Confidential' via email with external recipients. If a user attempts to send such an email, the action should be blocked and a policy tip displayed. Which Microsoft Purview feature should be configured?

A.Retention labels
B.Data Loss Prevention (DLP) policy
C.Sensitivity labels
D.Information barriers
AnswerB

DLP policies are the correct control because they inspect message content and context in transit and can match sensitive information types or sensitivity labels. With a rule, DLP can block or warn when email is shared with external users, and can even block the send action entirely while allowing an override with justification. This makes DLP the only option that directly enforces a sharing restriction based on content classification.

Why this answer

A Data Loss Prevention (DLP) policy is the correct Microsoft Purview feature because it is specifically designed to inspect email content and attachments for sensitive information, such as documents labeled 'Confidential', and enforce actions like blocking the email and displaying a policy tip to the user. DLP policies can be configured with conditions that detect sensitivity labels and apply protective actions, including blocking external sharing and notifying users via policy tips.

Exam trap

Microsoft often tests the misconception that sensitivity labels alone can enforce blocking actions, but in reality, sensitivity labels only apply classification and protection (e.g., encryption) and must be combined with a DLP policy to inspect and block outbound email based on those labels.

How to eliminate wrong answers

Option A is wrong because retention labels are used to manage data lifecycle (retain or delete content) and do not have the capability to block email transmission or display policy tips. Option C is wrong because sensitivity labels classify and protect data (e.g., encryption, marking) but do not directly enforce real-time blocking of email sharing with external recipients; DLP policies are required to inspect and block outbound email based on those labels. Option D is wrong because information barriers restrict communication and collaboration between specific groups of users within an organization, not between internal and external recipients, and cannot block email based on document labels or display policy tips.

568
MCQhard

Your organization uses Microsoft 365 E5 with Microsoft Entra ID P2. You have a hybrid identity environment with Microsoft Entra Connect Sync. You need to ensure that when a user is disabled in on-premises Active Directory, their Microsoft 365 access is blocked within 5 minutes, and any active refresh tokens are invalidated. You have already configured password hash synchronization. What should you do?

A.Enable Microsoft Entra Password Protection and configure a custom banned password list.
B.Configure Microsoft Entra Connect Sync to synchronize the 'accountEnabled' attribute and enable Continuous Access Evaluation (CAE) in Microsoft Entra ID.
C.Enable 'Enable password hash synchronization' and set the 'User must change password at next logon' flag in on-premises Active Directory.
D.Configure Microsoft Entra Connect Sync to synchronize the 'accountEnabled' attribute and enable 'Enable soft match' on the connector.
AnswerB

Synchronizing accountEnabled ensures the disabled state propagates to Microsoft Entra ID. Enabling CAE allows token revocation events, such as account disablement, to be enforced near real-time, invalidating refresh tokens within minutes. This combination meets the 5-minute blocking requirement.

Why this answer

Synchronizing the accountEnabled attribute from on-premises Active Directory ensures that disabled accounts are reflected in Microsoft Entra ID. Enabling Continuous Access Evaluation (CAE) allows Microsoft 365 services to respond to critical events like account disablement in near real-time, invalidating refresh tokens within minutes. Together, they meet the 5-minute blocking requirement.

Exam trap

The trap here is thinking that password hash synchronization alone propagates account disablement or that setting a password change flag blocks access; in reality, account status synchronization and CAE are required for timely token revocation.

569
MCQeasy

Your organization uses Microsoft Entra ID and requires that all guest users must have a mobile phone number registered for authentication. You need to enforce this requirement. What should you configure?

A.Create a Terms of Use policy that guests must accept.
B.Configure a Conditional Access policy requiring multifactor authentication for guest users.
C.Configure the Authentication methods policy to require mobile phone registration for guests.
D.Create an access review for guest users in Identity Governance.
AnswerC

The Authentication methods policy is the admin-level control that defines which verification methods are available and required for users, including guests. By enabling and configuring the Phone (mobile) method for guest users, you can mandate that guests register a mobile phone number before accessing resources. This directly satisfies the stated requirement.

Why this answer

The Authentication methods policy in Microsoft Entra ID allows you to define which authentication methods are available to users, including guest users. By configuring this policy to require mobile phone registration, you enforce that all guest users must register a mobile phone number for authentication, directly addressing the requirement.

Exam trap

The trap here is that candidates confuse requiring multifactor authentication (MFA) with requiring a specific authentication method (mobile phone), but MFA can be satisfied by other methods like email OTP or authenticator app, whereas the Authentication methods policy directly mandates registration of a mobile phone number.

How to eliminate wrong answers

Option A is wrong because a Terms of Use policy requires users to accept terms but does not enforce registration of a mobile phone number for authentication. Option B is wrong because a Conditional Access policy requiring multifactor authentication (MFA) for guest users enforces MFA at sign-in but does not specifically require the registration of a mobile phone number; MFA can be satisfied by other methods like email OTP or authenticator app. Option D is wrong because an access review in Identity Governance is used to review and attest to guest user access rights periodically, not to enforce authentication method registration.

570
Matchingmedium

Match each Microsoft 365 service to its primary purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Email and calendar

Document management and collaboration

Chat, meetings, and collaboration

Personal cloud storage

Enterprise social networking

Why these pairings

The correct matches associate Exchange Online with email and calendaring, SharePoint Online with document management and collaboration, Microsoft Teams with chat and meetings, and OneDrive for Business with personal cloud storage. Common confusions include misassigning Exchange's purpose to OneDrive or OneDrive's purpose to SharePoint.

571
MCQmedium

Your organization uses Microsoft Entra ID and has an application that requires the 'User.Read.All' permission. You need to grant this permission to the application but ensure that only an administrator can consent, not users. What should you do?

A.Grant admin consent for the application from the Enterprise applications blade.
B.Enable user consent for this application in the enterprise application settings.
C.Configure the user consent settings to allow user consent for low-risk permissions.
D.Set the 'Consent and permissions' settings to block user consent.
AnswerA

Granting admin consent from the Enterprise applications blade (by selecting the application, then clicking 'Grant admin consent' under Security/Permissions) authorizes the app's requested permissions for every user in the tenant. This is the only effective solution because the application likely requests high-risk permissions, such as Graph API application permissions, that must be consented to by a tenant administrator, not an end user. Once admin consent is granted, the application's status changes to 'Granted' and users can access it without being prompted for consent.

Why this answer

Granting admin consent from the Enterprise applications blade explicitly authorizes the application to access the 'User.Read.All' permission without requiring individual user consent. This is the only way to satisfy the requirement that only an administrator can consent, as admin consent bypasses user consent policies entirely and applies tenant-wide.

Exam trap

The trap here is that candidates often confuse blocking user consent (Option D) with granting admin consent, thinking that blocking users automatically grants the permission, but blocking only prevents consent without actually authorizing the application.

How to eliminate wrong answers

Option B is wrong because enabling user consent for this application would allow any user to consent to the 'User.Read.All' permission, which directly contradicts the requirement that only an administrator can consent. Option C is wrong because configuring user consent for low-risk permissions does not apply to 'User.Read.All', which is a high-risk permission (it allows reading all user profiles); users would still be blocked from consenting, but the requirement is to grant the permission, not just block users. Option D is wrong because blocking user consent entirely prevents users from consenting but does not grant the required permission to the application; admin consent must still be explicitly performed.

572
Multi-Selectmedium

Which TWO permissions are required for a custom role to manage Conditional Access policies in Microsoft Entra ID?

Select 2 answers
A.microsoft.directory/conditionalAccessPolicies/allProperties/read
B.microsoft.directory/conditionalAccessPolicies/read
C.microsoft.directory/conditionalAccessPolicies/delete
D.microsoft.directory/conditionalAccessPolicies/update
E.microsoft.directory/conditionalAccessPolicies/create
AnswersB, D

The read permission is the foundational access required to view Conditional Access policies and their current configuration. Without it, an administrator cannot even see the policies that need management, making it an indispensable part of the minimal permission set. Together with update, it covers the two core operations needed for policy management: seeing the policy and changing it.

Why this answer

To manage Conditional Access policies in Microsoft Entra ID, a custom role requires both the read and update permissions. The 'read' permission (option B) is necessary to view existing policies, while the 'update' permission (option D) is required to modify or configure policy settings. Without both, the role cannot effectively manage policies, as management implies the ability to change them.

Exam trap

The trap here is that candidates often assume 'create' or 'delete' permissions are needed for management, but Microsoft defines 'manage' as the combination of read and update, not full CRUD access.

573
Multi-Selectmedium

A compliance officer needs to ensure that all documents uploaded to SharePoint Online that contain passport numbers are automatically labeled with a 'Highly Confidential' sensitivity label. Which two Microsoft Purview features must be configured together to achieve this? (Choose two.)

Select 2 answers
A.Auto-labeling policy for SharePoint Online
B.Data Loss Prevention (DLP) policy
C.Retention label policy
D.Sensitive info type (passport number)
AnswersA, D

An auto-labeling policy for SharePoint Online is the correct mechanism because it automatically applies a sensitivity label to documents when they match specified conditions, such as containing a passport number via a sensitive info type. This policy can run in simulation mode to assess coverage and then enforce labeling on all existing and new files in a site, ensuring consistent classification without manual user action. This directly satisfies the compliance requirement for labeling every uploaded document.

Why this answer

An auto-labeling policy in Microsoft Purview can automatically apply a sensitivity label to documents containing sensitive information, such as passport numbers, when they are uploaded to SharePoint Online. This policy uses conditions based on sensitive info types to trigger the labeling action without user intervention.

Exam trap

The trap here is that candidates often confuse DLP policies with auto-labeling policies, but DLP does not apply sensitivity labels—it only monitors and blocks data sharing, while auto-labeling is the correct feature for automatic label assignment.

574
MCQeasy

A company wants to use Azure AD Identity Protection features such as user risk policies and sign-in risk policies to automatically respond to risky behavior. Which Azure AD license is required to enable these capabilities?

A.Azure AD Free
B.Azure AD Premium P1
C.Azure AD Premium P2
D.Microsoft 365 E3
AnswerC

Azure AD Premium P2 is the correct license because it includes Identity Protection, which continuously analyzes user and sign-in risk, and adds risk conditions to Conditional Access so you can enforce policies such as requiring a password change when user risk is high. Along with Privileged Identity Management and entitlement management, P2 gives you both the detection and the automated remediation capabilities. This is the only Azure AD edition listed that supports user-risk-based policies natively.

Why this answer

Azure AD Identity Protection features like user risk policies and sign-in risk policies require Azure AD Premium P2. This is because P2 includes Identity Protection, which provides risk-based conditional access policies that automatically respond to detected risks. Azure AD Premium P1 supports Conditional Access but lacks the risk detection and automated remediation capabilities of Identity Protection.

Exam trap

The trap here is that candidates often confuse Azure AD Premium P1 with P2, assuming Conditional Access alone enables risk policies, but P1 lacks the risk detection engine (Identity Protection) required for automated risk-based responses.

How to eliminate wrong answers

Option A is wrong because Azure AD Free provides no Conditional Access or Identity Protection capabilities, only basic directory services. Option B is wrong because Azure AD Premium P1 includes Conditional Access but not Identity Protection; it cannot evaluate user or sign-in risk levels or enforce risk-based policies. Option D is wrong because Microsoft 365 E3 includes Azure AD Premium P1, not P2, and therefore lacks Identity Protection features such as risk policies.

575
MCQmedium

Your organization uses Microsoft Entra ID. You need to ensure that users can only access company resources from trusted networks. Which Conditional Access condition should you configure?

A.Sign-in risk
B.Device platforms
C.Client apps
D.Locations
AnswerD

The locations condition is specifically designed to evaluate the network origin of a sign-in request, using named locations that can be defined either as trusted IP address ranges or as countries/regions. This includes the trusted IPs feature in Microsoft Entra ID, which lets you mark corporate office ranges as trusted to bypass MFA or to block access from any other location. Because the organization needs to ensure access based on network location, this is the correct condition to configure in Conditional Access.

Why this answer

The Locations condition in a Conditional Access policy allows you to define trusted network locations using named locations (IP ranges or country/region). By configuring a policy that grants access only from these trusted locations, you ensure users can only access company resources from networks you have explicitly approved, such as corporate offices or VPN egress IPs.

Exam trap

The trap here is that candidates often confuse 'network location' with 'device compliance' or 'sign-in risk,' leading them to select Device platforms or Sign-in risk instead of the correct Locations condition.

How to eliminate wrong answers

Option A is wrong because Sign-in risk is a condition that detects the likelihood that a sign-in attempt is not legitimate based on real-time risk signals (e.g., anonymous IP, atypical travel), not the network location of the user. Option B is wrong because Device platforms condition restricts access based on the operating system of the device (e.g., Windows, iOS, Android), not the network from which the request originates. Option C is wrong because Client apps condition controls access based on the application type (e.g., browser, mobile app, legacy authentication), not the network location.

576
MCQeasy

A company has purchased 1000 Microsoft 365 E5 licenses and wants to automatically assign licenses to users based on their department attribute, which is synchronized from on-premises Active Directory. The department attribute is stored in Azure AD. Which automated method should the administrator use to achieve this?

A.Group-based licensing with dynamic groups
B.scheduled PowerShell script that runs daily
C.Manual license assignment via the Microsoft 365 admin center
D.Bulk assign licenses using the admin center import feature
AnswerA

Dynamic groups in Azure AD use membership rules based on user attributes such as department or location. When a user satisfies the rule, they are automatically added to the group, and licenses assigned to the group are provisioned to that user without manual intervention. If the user no longer meets the rule, they are removed and the license is automatically revoked. This built-in, identity-driven approach scales effortlessly to 1000 users and handles future changes in membership automatically.

Why this answer

Group-based licensing with dynamic groups is the correct method because it allows automatic license assignment based on user attributes like department, which is synchronized from on-premises Active Directory via Azure AD Connect. Dynamic groups evaluate membership rules in Azure AD, and when a user's department attribute matches the rule, the group-based licensing policy automatically assigns or removes the Microsoft 365 E5 license without manual intervention.

Exam trap

The trap here is that candidates often choose a scheduled PowerShell script (Option B) thinking it is more flexible or reliable, but they overlook that group-based licensing is the native, fully automated, and supported method for attribute-driven license assignment in Azure AD.

How to eliminate wrong answers

Option B is wrong because a scheduled PowerShell script that runs daily introduces latency (up to 24 hours) and requires ongoing maintenance, whereas group-based licensing provides near-real-time assignment and revocation. Option C is wrong because manual license assignment via the Microsoft 365 admin center is not automated and does not scale to 1000 users based on a dynamic attribute. Option D is wrong because bulk assign licenses using the admin center import feature is a one-time, static assignment based on a CSV file, not an automated method that responds to changes in the department attribute.

577
Multi-Selectmedium

A compliance administrator needs to automatically apply a retention label to documents in a SharePoint Online site that contain the keyword 'Project Alpha'. The label should retain the documents for 5 years and then delete them. Which two Microsoft Purview features must be configured to achieve this? (Choose two.)

Select 2 answers
A.Trainable classifiers
B.Auto-labeling policy for SharePoint Online
C.Document Fingerprinting
D.Sensitive info type with a keyword dictionary (e.g., 'Project Alpha')
AnswersB, D

Auto-labeling policy for SharePoint Online is the correct feature because it uses conditions (like sensitive info types or trainable classifiers) to automatically apply a retention label to matching documents. To satisfy the requirement, you configure the policy with a sensitive info type that includes a keyword dictionary for 'Project Alpha', and assign the 2-year retention label. This policy runs continuously and can target all or specific SharePoint sites, providing the required automatic labeling.

Why this answer

An auto-labeling policy for SharePoint Online (option B) is required because it can automatically apply a retention label to documents based on conditions such as the presence of specific keywords. The sensitive info type with a keyword dictionary (option D) defines the condition by creating a custom sensitive information type that matches the exact phrase 'Project Alpha', which the auto-labeling policy then uses to trigger the label application.

Exam trap

The trap here is that candidates often confuse trainable classifiers with keyword-based sensitive info types, assuming machine learning is needed for any content detection, when in fact a simple keyword dictionary is sufficient and more appropriate for fixed terms.

578
Multi-Selecthard

Which THREE are valid Microsoft Entra ID license plans that include Identity Protection?

Select 3 answers
A.Microsoft Entra ID P1
B.Microsoft 365 E3
C.Microsoft 365 E5 Security
D.Microsoft 365 E5
E.Microsoft Entra ID P2
AnswersC, D, E

Microsoft 365 E5 Security is an add-on subscription that brings Microsoft Entra ID P2 to an existing Microsoft 365 tenant, enabling Identity Protection with risk policies, user risk, and sign-in risk assessments. Since it explicitly grants P2 entitlements, it is a valid license plan for this question.

Why this answer

Microsoft Entra ID Identity Protection is a premium feature that requires either a Microsoft Entra ID P2 license or inclusion in a suite like Microsoft 365 E5 or Microsoft 365 E5 Security. Option C (Microsoft 365 E5 Security) is correct because it includes Microsoft Entra ID P2, which provides full Identity Protection capabilities including risk-based conditional access and user risk policies.

Exam trap

The trap here is that candidates often assume Microsoft 365 E3 includes all security features of E5, but E3 only provides Entra ID P1, which lacks Identity Protection's risk detection and remediation capabilities.

579
MCQeasy

An administrator runs the PowerShell command shown in the exhibit. What is the immediate effect on the user?

A.The user is disabled after 90 days of inactivity.
B.The user is blocked from signing in immediately.
C.The user is deleted after 90 days of inactivity.
D.The user's password is reset.
AnswerB

The command sets the user account's sign-in block attribute (such as AccountEnabled to $false or BlockCredential to $true) synchronously. As soon as the cmdlet completes, Azure AD revokes the user's ability to obtain tokens and authenticate for interactive or service-based sign-ins. This is a real-time, at-scale action commonly used for immediate access termination.

Why this answer

The PowerShell command `Set-MgUser -UserId user@domain.com -BlockCredential $true` immediately blocks the user from signing in by setting the `BlockCredential` property to true. This prevents any new authentication attempts, effectively locking the account without changing the password or deleting the user.

Exam trap

The trap here is that candidates confuse `BlockCredential` with disabling the account or setting an inactivity policy, but the command only blocks sign-in immediately without any time-based or deletion behavior.

How to eliminate wrong answers

Option A is wrong because the command does not set any inactivity-based disablement; that would require a different cmdlet like `Set-MgUser` with `-SignInActivity` or a conditional access policy. Option C is wrong because the command does not delete the user; deletion requires `Remove-MgUser`. Option D is wrong because the command does not reset the password; password reset requires `Update-MgUserPassword` or the admin portal.

580
MCQeasy

A company has just signed up for Microsoft 365 Business Standard without adding a custom domain. An administrator needs to create the first user accounts. What will be the default email address format for these new users?

A.username@contoso.com
B.username@onmicrosoft.com
C.username@<tenantname>.onmicrosoft.com
D.username@microsoftonline.com
AnswerC

When the tenant is provisioned, Microsoft creates a unique initial domain in the format <tenantname>.onmicrosoft.com, which is automatically registered and verified. New users are assigned the user principal name and email address using this domain by default, because no custom domains have been added yet. This domain remains the default until a custom domain is added and set as primary. Therefore, username@<tenantname>.onmicrosoft.com is the correct email suffix after signing up for Microsoft 365 Business Standard.

Why this answer

When a Microsoft 365 tenant is created without adding a custom domain, the default domain is the `<tenantname>.onmicrosoft.com` domain. New user accounts are automatically assigned an email address in the format `username@<tenantname>.onmicrosoft.com`, as this is the initial domain provisioned for the tenant. Option C correctly reflects this default behavior.

Exam trap

The trap here is that candidates often confuse the default `onmicrosoft.com` domain with the generic `microsoftonline.com` domain used for Azure AD authentication, or assume a custom domain like `contoso.com` is automatically assigned, leading them to select A or D instead of recognizing the tenant-specific subdomain format.

How to eliminate wrong answers

Option A is wrong because `contoso.com` is a custom domain that must be explicitly added and verified in the tenant; it is not the default domain when no custom domain is configured. Option B is wrong because `onmicrosoft.com` is a Microsoft-owned domain used for services like Outlook, but the tenant-specific subdomain (e.g., `contoso.onmicrosoft.com`) is required; a bare `@onmicrosoft.com` address is not valid for a tenant. Option D is wrong because `microsoftonline.com` is the domain used for Azure AD authentication endpoints (e.g., login.microsoftonline.com), not for user email addresses.

581
MCQhard

You are a Microsoft 365 administrator. Your tenant has a Microsoft Entra ID P2 license. You need to create a dynamic group for all users whose department is 'Engineering' and who are located in the United States. Which rule syntax should you use?

A.user.department -eq "Engineering" and user.country -eq "US"
B.user.department -eq "Engineering" And user.country -eq "United States"
C.user.department -eq "Engineering" and user.country -eq "United States"
D.user.department -eq "Engineering" AND user.country -eq "United States"
AnswerC

This expression is correct because it uses all lowercase operators ('and'), which are required by the dynamic membership rule parser, and matches the exact stored values: the department attribute string 'Engineering' and the country attribute display name 'United States'. The rule accurately targets users who meet both conditions simultaneously.

Why this answer

Dynamic group rules in Microsoft Entra ID require the use of lowercase 'and' as the logical operator, and the country attribute value must match the display name 'United States' as stored in the directory. The rule syntax must follow the property -operator 'value' format exactly, with no capitalization of 'and'.

Exam trap

The trap here is that candidates often confuse the country attribute value with the two-letter ISO code 'US' or incorrectly capitalize the logical operator 'and', leading them to choose options that would fail validation or produce incorrect membership results.

How to eliminate wrong answers

Option A is wrong because it uses 'US' as the country value, but Microsoft Entra ID stores the country attribute as the full display name 'United States', not the two-letter ISO code. Option B is wrong because it capitalizes 'And' as 'And', but dynamic group rules require the logical operator to be all lowercase 'and'. Option D is wrong because it capitalizes 'AND' as 'AND', but the rule syntax mandates the lowercase 'and' operator.

582
Multi-Selectmedium

You are the Microsoft 365 administrator for a company with a Microsoft 365 E3 tenant. The security team requires that you reduce the attack surface for email by blocking auto-forwarding to external domains and by ensuring that any email sent from an external sender that spoofs your custom domain is rejected. You must implement the controls natively in Microsoft 365 Defender. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Create an outbound anti-spam policy and set the Automatic forwarding rule to Off, then apply the policy to all recipients.
B.Create an anti-phishing policy and enable the mailbox intelligence setting for all users.
C.Configure the anti-phishing policy's Spoof intelligence by adding your custom domain as an allowed sender so that internal spoofing is permitted.
D.Ensure the default anti-phishing policy's anti-spoofing protection is enabled and that no allowed sender entry exists for your custom domain in the Tenant Allow/Block List.
E.Add your custom domain to the Domain impersonation section of the anti-phishing policy and set the action to Quarantine the message.
AnswersA, D

The outbound anti-spam policy contains the Automatic forwarding setting that controls whether users can auto-forward email to external domains. Setting it to Off blocks this exfiltration path, and applying the policy to all recipients ensures the control is tenant-wide. This directly addresses the requirement to prevent automatic external forwarding.

Why this answer

Blocking external auto-forwarding is done through the Automatic forwarding setting in an outbound anti-spam policy applied to all recipients. Rejecting spoofed mail that claims to be from your own domain relies on the anti-spoofing intelligence built into the default anti-phishing policy, which acts on your accepted domains, provided no allow entry in the Tenant Allow/Block List overrides the verdict.

Exam trap

The trap here is mixing up domain impersonation, which targets lookalike domains, with anti-spoofing intelligence, which handles exact spoofs of domains you own.

583
MCQhard

Your organization has deployed Microsoft Defender for Cloud Apps. You want to detect anomalous behavior such as impossible travel for users accessing cloud apps. You need to configure the appropriate policy. Which policy type should you create?

A.App discovery policy
B.Activity policy
C.Session policy
D.File policy
AnswerB

Activity policies evaluate user activity events against behavioural baselines, so impossible travel and other anomalies trigger alerts or governance actions. They operate on the activity log rather than file content, matching the requirement to detect anomalous cloud app access.

Why this answer

Activity policies in Microsoft Defender for Cloud Apps are designed to monitor user activity across cloud apps and trigger alerts or governance actions on anomalous behavior, including impossible travel, suspicious IP addresses, and unusual file downloads. Creating an activity policy with the 'Impossible travel' template directly detects the scenario described. This is the correct policy type for behavioral anomaly detection.

Exam trap

MS-102 often tests the confusion between activity policies (behavioral anomaly detection) and session policies (real-time access control), so candidates pick session policy when the question mentions 'anomalous behavior'.

How to eliminate wrong answers

Option A is wrong because app discovery policies identify shadow IT and unsanctioned cloud apps from traffic logs — they don't detect user behavior anomalies like impossible travel. Option C is wrong because session policies apply conditional access and real-time session controls (e.g., block download) for sanctioned apps, not anomaly detection. Option D is wrong because file policies scan and classify files for DLP or malware, not user travel anomalies.

584
MCQmedium

A company uses Azure AD Identity Protection. The security team wants to automatically block users from signing in when the user risk level is 'High'. Which policy should they configure?

A.Conditional Access policy with user risk condition
B.Sign-in risk policy
C.User risk policy
D.MFA registration policy
AnswerC

The User risk policy in Microsoft Entra ID Protection allows you to automatically respond when the system detects that a user account is likely compromised—based on signals such as leaked credentials, password spray, or anomalous user behavior—and is rated with a user risk level of High. It can be configured to 'Block access' directly at the policy level, providing the exact mechanism needed for this scenario. Separately, it can also require a secure password change or MFA, but with the condition 'User risk High' and the control 'Block access', it matches the required behavior precisely.

Why this answer

The User risk policy in Azure AD Identity Protection is specifically designed to automatically block sign-ins when the user risk level is 'High'. This policy evaluates the probability that a user's identity has been compromised based on signals like leaked credentials or anomalous behavior, and can enforce actions such as blocking access or requiring password change. Option C is correct because it directly targets user risk, not sign-in risk or other conditions.

Exam trap

The trap here is that candidates often confuse the User risk policy with the Sign-in risk policy, or think a Conditional Access policy with user risk condition is the only way to block based on user risk, but the exam expects the dedicated Identity Protection policy as the direct answer.

How to eliminate wrong answers

Option A is wrong because a Conditional Access policy with a user risk condition can also block sign-ins based on user risk, but the question asks for the specific policy to configure in Identity Protection, and the User risk policy is the dedicated, simpler policy for this purpose without requiring additional Conditional Access configuration. Option B is wrong because the Sign-in risk policy targets the risk level of individual sign-in sessions (e.g., anonymous IP, atypical travel), not the overall user risk level. Option D is wrong because the MFA registration policy enforces registration for Azure AD Multi-Factor Authentication, not blocking sign-ins based on user risk.

585
MCQmedium

A company wants to automatically assign Microsoft 365 E5 licenses to all users in the Sales department. The department is identified by the department attribute in Microsoft Entra ID. The administrator needs to configure a method where licenses are assigned based on group membership, and the group membership is automatically updated based on user attributes. Which licensing approach should the administrator use?

A.Per-user licensing with a PowerShell script.
B.Group-based licensing with a dynamic group that uses the department attribute.
C.Subscription-based licensing via the Microsoft 365 admin center.
D.Group-based licensing with an assigned group that must be manually updated.
AnswerB

With Azure AD group-based licensing, you can attach Microsoft 365 E5 licenses to a dynamic security group whose membership rule is based on the department attribute. When a user's department changes, Azure AD automatically updates group membership and then applies or removes the E5 license without manual scripting. This directly satisfies the requirement for automatic license assignment to all users in a given department.

Why this answer

Group-based licensing in Microsoft Entra ID allows automatic license assignment based on group membership, and a dynamic group can automatically update its membership using the department attribute rule (e.g., `user.department -eq "Sales"`). This meets the requirement for both automated license assignment and attribute-driven membership updates without manual intervention.

Exam trap

The trap here is that candidates may confuse group-based licensing with assigned groups (Option D) and overlook the dynamic group requirement, assuming any group-based licensing approach automatically updates membership, when in fact only dynamic groups provide attribute-driven automatic membership updates.

How to eliminate wrong answers

Option A is wrong because per-user licensing with a PowerShell script requires manual execution or scheduled automation, and does not provide real-time, attribute-driven automatic membership updates; it also lacks the native integration of group-based licensing. Option C is wrong because subscription-based licensing via the Microsoft 365 admin center refers to managing subscription quantities, not assigning licenses to individual users based on attributes or group membership. Option D is wrong because group-based licensing with an assigned group requires manual updates to group membership, which contradicts the requirement for automatic membership updates based on the department attribute.

586
MCQmedium

Your organization uses Microsoft Entra ID and has a Conditional Access policy that requires compliant devices for access to corporate resources. You need to ensure that iOS devices are compliant before accessing Exchange Online. Which Microsoft Intune policy should you configure?

A.Device configuration policy
B.Device compliance policy
C.App protection policy
D.Enrollment restrictions
AnswerB

A device compliance policy defines the platform-specific rules, such as iOS version and encryption requirements, that Intune evaluates to mark a device compliant. Conditional Access then grants Exchange Online access only to compliant devices, satisfying the stated requirement.

Why this answer

A Device Compliance policy in Microsoft Intune defines the rules a device must meet (OS version, encryption, jailbreak/root detection, password requirements) to be marked compliant. Conditional Access then uses that compliance state as a grant control, so iOS devices must satisfy the compliance policy before accessing Exchange Online. This is the correct policy type to enforce device health for Conditional Access.

Exam trap

MS-102 often tests the distinction between compliance policies (device health for Conditional Access) and configuration policies (settings delivery) — candidates pick configuration because it sounds like it 'configures' compliance, but only a compliance policy feeds the CA grant control.

How to eliminate wrong answers

Option A is wrong because a Device Configuration policy pushes settings to devices (Wi-Fi, VPN, restrictions) but does not evaluate or report compliance status to Conditional Access. Option C is wrong because an App Protection policy (MAM) protects app data on unmanaged or BYOD devices and does not make the device itself compliant. Option D is wrong because Enrollment Restrictions control which devices/users can enroll and which platforms are allowed, not whether an enrolled device meets compliance requirements.

587
Multi-Selecthard

You are implementing Microsoft Defender for Office 365. You need to configure anti-phishing policies to protect against user impersonation. Which THREE settings should you configure?

Select 3 answers
A.Enable impersonation protection for domains you own.
B.Enable mailbox intelligence to detect impersonation based on user behavior.
C.Set the bulk email threshold.
D.Enable impersonation protection for users who are defined as protected users.
E.Configure spoof intelligence to allow or block senders.
AnswersA, B, D

Enabling impersonation protection for domains you own directly instructs Defender for Office 365 to inspect messages where the sender address visually mimics any domain associated with your tenant. In the anti-phishing policy, toggling on this setting and optionally listing additional domains subjects such forged domain messages to the configured action (quarantine, redirect, or mailbox rule). Because the requirement centers on defending against attackers who abuse your own domain as the sender, this is the primary and correct configuration to implement.

Why this answer

Enabling impersonation protection for domains you own allows Defender for Office 365 to detect and act on attempts to spoof your organization's domain in the From address. This setting ensures that emails claiming to be from your domain are inspected for impersonation patterns, such as lookalike domains or display name spoofing, and can be automatically quarantined or have safety tips applied.

Exam trap

The trap here is that candidates confuse anti-phishing settings with anti-spam or spoof intelligence settings, mistakenly selecting bulk email threshold or spoof intelligence when the question explicitly targets user impersonation protection.

588
MCQmedium

A security administrator wants to configure Automated Investigation and Response (AIR) in Microsoft 365 Defender to automatically isolate a device when a high-severity alert for malware is detected. Which step is required?

A.A: Create an automation rule in Microsoft Sentinel.
B.B: Create a custom detection rule in advanced hunting.
C.C: Configure the device to be part of a device group and enable automation level.
D.D: Enable auto-removal of malware from devices.
AnswerC

To actually turn on AIR, you place the device into a device group in Microsoft 365 Defender (under Endpoints > Device groups) and select an automation level such as 'Full - remediate threats automatically' or 'Automatic - investigate threats automatically.' The device group's automation level decides whether AIR runs automatically and what actions (isolation, file removal, etc.) can be taken without approval. Without a proper device group with the desired automation level, AIR's automatic actions remain disabled or require manual approval.

Why this answer

To enable Automated Investigation and Response (AIR) in Microsoft Defender for Endpoint, the device must be added to a device group, and the automation level for that group must be set to 'Full – remediate threats automatically' or a similar level. This configuration allows Defender to automatically isolate a device when a high-severity malware alert is triggered, as part of the built-in AIR playbooks.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel automation rules (which are for cross-source orchestration) with the device group automation settings in Microsoft Defender for Endpoint, leading them to pick Option A instead of the correct device group configuration.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel automation rules are used for orchestration and response across multiple data sources, not for configuring device-level automated isolation in Microsoft Defender for Endpoint. Option B is wrong because custom detection rules in advanced hunting are for creating custom alerts based on KQL queries, not for enabling automated response actions like device isolation. Option D is wrong because 'auto-removal of malware' is not a configurable setting in Defender for Endpoint; remediation actions are controlled via automation levels and device groups, not a separate toggle.

589
MCQhard

You are reviewing directory settings for Microsoft 365 Groups. Based on the exhibit, which statement is true?

A.Only users in a specific security group can create Microsoft 365 Groups
B.A naming policy is enforced for new groups
C.Groups must have a classification label
D.All users in the tenant can create Microsoft 365 Groups
AnswerD

The EnableGroupCreation directory setting is set to true, which is the master switch that permits group creation in the tenant. Because GroupCreationAllowedGroupId is also empty, there is no security-group scoping override. As a result, every user in the organization can create Microsoft 365 Groups.

Why this answer

The exhibit shows that under 'Group creation settings,' the option 'Set which users can create Microsoft 365 Groups' is configured to 'Everyone.' This means all users in the tenant are permitted to create groups, regardless of membership in any security group. Therefore, option D is correct because the setting explicitly allows all users to create Microsoft 365 Groups.

Exam trap

The trap here is that candidates often assume a naming policy or classification label is always enforced for Microsoft 365 Groups, but the exhibit clearly shows no such configuration, and the question tests the ability to read the actual directory settings rather than relying on default assumptions.

How to eliminate wrong answers

Option A is wrong because the exhibit shows 'Everyone' is selected, not a specific security group; if a security group were required, the setting would show 'Selected security group' with a group specified. Option B is wrong because the exhibit does not display any naming policy configuration; a naming policy would be visible under 'Naming policy' settings, which are not shown or enabled here. Option C is wrong because the exhibit does not indicate that a classification label is required; classification labels are optional and must be explicitly configured in the 'Classification' settings, which are absent from the exhibit.

590
MCQhard

An organization with Microsoft Entra ID P2 licenses needs to enforce that all users accessing the Azure portal must use FIDO2 security keys for multi-factor authentication. Which configuration should be implemented?

A.Create a Conditional Access policy that requires MFA and select FIDO2 as the authentication strength in the grant controls
B.Create a Conditional Access policy that requires MFA and set the grant control to require a specific device platform
C.Configure an authentication strength policy that requires FIDO2 and assign it to a Conditional Access policy
D.Configure an authentication methods policy that allows only FIDO2 security keys
AnswerC

This is correct because Microsoft Entra ID authentication strengths let you define exactly which authentication methods are acceptable for a sign-in. To require FIDO2 security keys, you create a custom authentication strength that includes only the FIDO2 security key method, then assign that strength to a Conditional Access policy's 'Require authentication strength' grant control. This enforces the method at sign-in time, ensuring that users must authenticate with a FIDO2 security key to access the protected resource.

Why this answer

In Microsoft Entra ID, authentication strengths allow you to define a specific set of authentication methods (e.g., FIDO2 security keys) and then assign that strength to a Conditional Access policy. This ensures that only FIDO2 security keys are accepted for MFA when accessing the Azure portal, meeting the requirement precisely.

Exam trap

The trap here is that candidates often confuse the direct selection of an authentication method in Conditional Access grant controls with the correct two-step process of first defining an authentication strength policy and then assigning it to a Conditional Access policy.

How to eliminate wrong answers

Option A is wrong because selecting FIDO2 as the authentication strength in the grant controls of a Conditional Access policy is not a valid configuration; authentication strengths are defined separately and then referenced by the policy, not selected directly in grant controls. Option B is wrong because requiring a specific device platform (e.g., Windows) does not enforce the use of FIDO2 security keys; it only restricts the device type, not the authentication method. Option D is wrong because configuring an authentication methods policy to allow only FIDO2 security keys would block all other methods globally, but it does not integrate with Conditional Access to target specific apps like the Azure portal; it applies to all sign-ins, which is too broad and not the intended enforcement mechanism.

591
Multi-Selectmedium

Your organization uses Microsoft Entra ID. You need to enable users to reset their own passwords without administrator intervention. Which TWO components must be configured?

Select 2 answers
A.Microsoft Entra self-service password reset (SSPR)
B.Microsoft Entra Identity Protection
C.Conditional Access policies
D.Microsoft Entra Privileged Identity Management
E.Authentication methods registration
AnswersA, E

Microsoft Entra self-service password reset (SSPR) is the license-enabled feature that must be explicitly toggled on and configured for users to reset or change their own passwords without administrator intervention. The 'Enable self-service password reset' setting must be set to 'Selected' or 'All' (or via group assignment), and the reset process is governed by policies and authentication requirements. Its purpose is exactly the requested capability: allow users to self-reset when locked out or expired.

Why this answer

Microsoft Entra self-service password reset (SSPR) is the core feature that allows users to reset their own passwords without administrator intervention. It must be enabled and configured at the tenant level, and it relies on users having registered authentication methods to verify their identity during the reset process.

Exam trap

The trap here is that candidates often confuse optional security features like Identity Protection or Conditional Access as prerequisites for SSPR, when in fact only SSPR enablement and authentication method registration are strictly required.

592
MCQeasy

A compliance officer needs to ensure that any email sent from the organization that contains personally identifiable information (PII) such as social security numbers is automatically encrypted when the recipient is outside the organization. Which Microsoft Purview solution should the officer configure?

A.Sensitivity labels with auto-labeling
B.Data Loss Prevention (DLP) policy with encryption action
C.Office 365 Message Encryption (OME) configuration
D.Retention policy and labels
AnswerB

Microsoft Purview DLP policies are the correct solution because they operate on outbound email in transit within Exchange Online, scanning message body and attachments for sensitive data types. When a match occurs, the policy can automatically apply encryption as a protective action (via OME) and even show a policy tip or notify the sender, exactly meeting the requirement to ensure any email containing sensitive data is secured at send.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft Purview can be configured with an 'Encrypt email messages' action that automatically applies Office 365 Message Encryption (OME) to emails containing sensitive information types (e.g., Social Security Number) when sent to external recipients. This meets the compliance requirement for automatic encryption based on content detection, without requiring user intervention or manual label application.

Exam trap

The trap here is that candidates confuse the underlying encryption technology (OME) with the policy that triggers it, leading them to select OME configuration (Option C) instead of the DLP policy that actually detects PII and enforces the encryption action.

How to eliminate wrong answers

Option A is wrong because sensitivity labels with auto-labeling can apply classification and protection, but they are designed for persistent labeling across documents and emails, not specifically to trigger encryption based on PII detection at the point of sending; auto-labeling for emails requires Exchange mail flow rules or DLP policies to enforce encryption. Option C is wrong because Office 365 Message Encryption (OME) is the underlying encryption technology, not a policy or configuration that automatically detects PII and triggers encryption; OME must be invoked by a DLP policy or mail flow rule. Option D is wrong because retention policies and labels manage data lifecycle and deletion, not real-time content inspection or encryption of outbound emails.

593
MCQhard

A security administrator wants to prevent malware from using Office macros to spawn malicious processes. Specifically, they want to block Excel, Word, and PowerPoint from creating child processes. Which Microsoft Defender for Endpoint capability should be configured?

A.Threat & Vulnerability Management
B.Attack Surface Reduction (ASR) rules
C.Web Protection
D.Network Protection
AnswerB

Attack Surface Reduction (ASR) rules are the correct control because they specifically target common attack techniques, including the rule 'Block Office applications from creating child processes.' This rule, identified by GUID e6db97e8-5c6a-4b3f-b3a4-6c3e2f3d4e5f (actual GUID: d4f6c3e7-4c1a-4f2b-9a5b-9d3f2a1c6b4e), uses behavior-based monitoring to prevent Office executables like WINWORD.EXE or EXCEL.EXE from launching other processes such as PowerShell or cmd.exe. This directly stops macro malware from executing its payload, including zero-day variants that no signature would catch.

Why this answer

Attack Surface Reduction (ASR) rules are a Microsoft Defender for Endpoint capability specifically designed to block common malware behaviors, such as Office applications (Excel, Word, PowerPoint) from creating child processes. This rule (GUID: 26190899-1602-49e8-8b27-eb1d0a1ce869) prevents macros from spawning cmd.exe, powershell.exe, or other executables, directly addressing the administrator's requirement.

Exam trap

The trap here is that candidates often confuse Attack Surface Reduction rules with other Defender for Endpoint capabilities like Network Protection or Web Protection, mistakenly thinking that blocking network traffic is equivalent to blocking local process creation, when ASR rules are the only option that directly controls child process spawning from Office apps.

How to eliminate wrong answers

Option A is wrong because Threat & Vulnerability Management (TVM) identifies, prioritizes, and remediates vulnerabilities in software and configurations, but it does not enforce runtime behavioral blocks like preventing child process creation. Option C is wrong because Web Protection blocks access to malicious URLs, IPs, and web content, but it does not control local process spawning from Office macros. Option D is wrong because Network Protection blocks outbound connections to malicious domains or IPs at the network layer, but it does not prevent local child process creation from Office applications.

594
Multi-Selectmedium

Which TWO roles can manage user licenses without being able to create users?

Select 2 answers
A.License Administrator
B.Billing Administrator
C.Global Administrator
D.User Administrator
E.Helpdesk Administrator
AnswersA, B

The License Administrator role is specifically scoped to assign, modify, and remove Microsoft 365 licenses for users, and to manage license quotas on subscriptions. It cannot create or delete user accounts, reset passwords, or perform other user management tasks, which makes it a least-privilege fit for the requirement to manage user licenses without additional user provisioning capabilities.

Why this answer

The License Administrator role in Microsoft 365 is specifically designed to allow users to manage licenses assigned to users and groups without having permissions to create new user accounts. This role grants access to the Microsoft 365 admin center's Billing > Licenses section and the Azure AD Licenses blade, enabling license assignment, removal, and consumption monitoring, but it explicitly excludes user creation or deletion capabilities.

Exam trap

The trap here is that candidates often confuse the License Administrator with the User Administrator, assuming that license management inherently includes user creation, but Microsoft explicitly separates these permissions to enforce least-privilege access.

595
MCQmedium

You are a Microsoft 365 administrator for a company that uses Microsoft Defender for Cloud Apps. The security team wants to detect when users download a large number of files from SharePoint Online in a short period, which could indicate data exfiltration. You need to create a policy to alert on this activity. What should you do?

A.Set up an anomaly detection policy for unusual file access.
B.Create an activity policy with a filter for 'Download file' and a threshold for the number of files.
C.Configure a session policy to block downloads from SharePoint Online.
D.Create a file policy with a filter for file name and a threshold for file size.
AnswerB

Activity policies in Microsoft Defender for Cloud Apps monitor user activities across connected apps. By filtering for 'Download file' and setting a threshold on the number of files within a time window, you can detect mass download behavior indicative of exfiltration. This directly addresses the requirement.

Why this answer

Activity policies in Microsoft Defender for Cloud Apps are designed to monitor user activities and can be configured with filters and thresholds to detect specific behaviors like mass file downloads. This provides the precise alerting needed for potential data exfiltration.

Exam trap

The trap here is assuming that file policies or session policies can detect download volume, but only activity policies track user actions with customizable thresholds.

596
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to deploy a custom Line-of-Business (LOB) app to a group of devices. The app is not in the Microsoft Store. What is the recommended method to deploy the app?

A.Add the app as a Microsoft Store app (business) in Intune.
B.Use Group Policy to deploy the app via a network share.
C.Publish the app to the Microsoft Store for Business and assign it.
D.Upload the app package to Intune as a Line-of-Business app and assign it to the device group.
AnswerD

Upload the app package to Intune as a Line-of-Business app and assign it to the device group. This is the standard Intune method for side-loading a custom internal application: you navigate to Apps > All Apps > Add, choose the 'Line-of-business app' type, upload the MSI or APPX installable package, and then configure the assignment as Required to an Azure AD device group. Intune stores the package in Azure and handles download and installation on each enrolled Windows 10 device, making it the correct native deployment mechanism for a custom LOB application.

Why this answer

Intune natively supports deploying custom Line-of-Business (LOB) apps by uploading the app package (e.g., .msi, .exe, .appx) directly into the Intune console and assigning it to a device group. This method is the recommended approach for apps not available in the Microsoft Store, as it leverages Intune's mobile device management (MDM) capabilities to push the app to Windows 10 devices without requiring external infrastructure like Group Policy or the Microsoft Store for Business.

Exam trap

The trap here is that candidates may confuse the Microsoft Store for Business (now Microsoft Store) as a viable publishing platform for custom LOB apps, not realizing that the store only accepts apps that meet Microsoft's submission requirements and is not designed for internal, proprietary applications.

How to eliminate wrong answers

Option A is wrong because adding the app as a Microsoft Store app (business) in Intune is intended for apps that are already available in the Microsoft Store for Business, not for custom LOB apps that are not in the store. Option B is wrong because Group Policy deployment via a network share is a traditional on-premises method that does not integrate with Intune's cloud-based MDM, and it requires devices to be domain-joined and connected to the corporate network, which is not recommended for modern, cloud-managed environments. Option C is wrong because publishing a custom LOB app to the Microsoft Store for Business is not supported; the store only accepts apps that meet specific submission criteria and are not intended for internal, proprietary line-of-business applications.

597
MCQmedium

A junior administrator needs permission to view sign-in logs, audit logs, and security recommendations in the Microsoft Entra admin center, but must not be able to reset passwords, modify settings, or manage roles. Which built-in Microsoft Entra role should the administrator assign?

A.Global Reader
B.Security Reader
C.Reports Reader
D.Security Administrator
AnswerB

Security Reader is the correct built-in role because it provides read-only access to security-related signals, including Entra ID sign-in logs, audit logs, and identity risk events. It does not allow any modification of security settings or password resets, so the junior administrator can inspect sign-in activity while remaining unable to alter configurations. This aligns precisely with the least-privilege principle for a view-only task.

Why this answer

The Security Reader role grants read-only access to security-related data, including sign-in logs, audit logs, and security recommendations, without permitting any write operations such as password resets, setting modifications, or role management. This aligns precisely with the junior administrator's required permissions.

Exam trap

The trap here is that candidates often confuse the Security Reader role with the Security Administrator role, mistakenly assuming that viewing security recommendations requires write permissions, or they overlook the legacy Reports Reader role which does not cover all required log types.

How to eliminate wrong answers

Option A is wrong because the Global Reader role provides read-only access to all aspects of Microsoft Entra ID, including settings and configurations, which is broader than the required scope and could inadvertently expose sensitive configuration data. Option C is wrong because the Reports Reader role is a legacy role that only allows viewing reports in the Azure portal, not the full set of sign-in logs, audit logs, and security recommendations in the Microsoft Entra admin center. Option D is wrong because the Security Administrator role has write permissions that include the ability to modify security policies, reset passwords, and manage roles, which exceeds the junior administrator's required restrictions.

598
Multi-Selecteasy

Your company is implementing Microsoft Purview Data Loss Prevention (DLP) to protect credit card numbers in emails. Which THREE actions can a DLP policy take when a match is found?

Select 3 answers
A.Delete the email from the recipient's inbox.
B.Encrypt the email automatically.
C.Allow the user to override the block with a business justification.
D.Send a notification to the user with a policy tip.
E.Block the email from being sent.
AnswersC, D, E

Permits the sender to bypass the block by supplying a business justification, satisfying the need for a documented exception path. The override is recorded for audit, balancing strict credit card protection against legitimate business email flow.

Why this answer

Option C is correct because Microsoft Purview DLP policies can be configured with user override capabilities, allowing users to provide a business justification to bypass a block action when a sensitive information match is detected. Option D is correct because DLP policies can display policy tips to users in supported workloads like Outlook, notifying them that their email contains sensitive content and explaining the policy that triggered the match. Option E is correct because blocking the email from being sent is a core DLP enforcement action that prevents the message containing credit card numbers from leaving the organization.

Option A is incorrect because DLP policies do not retroactively delete emails from a recipient's inbox; they act at send time or at rest through retention/retention labels, not as a DLP match action. Option B is incorrect because DLP policies do not automatically encrypt emails as a match action; encryption is handled through sensitivity labels, Azure Information Protection, or Exchange mail flow rules, not DLP policy actions.

Exam trap

MS-102 often tests the specific actions DLP can take versus those it cannot, such as encryption or deletion; candidates may incorrectly assume DLP can encrypt or delete emails.

599
MCQhard

An administrator deployed the above Intune device configuration policy for Microsoft Defender for Endpoint on Windows 10 devices. Users report that some potentially unwanted applications (PUA) are still being installed. What is the most likely cause?

A.The cloud timeout value is too low, causing PUA detection to fail.
B.The PUAProtection setting is in AuditMode and not blocking PUAs.
C.Cloud-delivered protection is set to High level, which does not affect PUAs.
D.Real-time monitoring is disabled.
AnswerB

The PUAProtection setting in AuditMode instructs Microsoft Defender Antivirus to detect potentially unwanted applications and record them in the event log without taking any blocking action. Because AuditMode is only logging findings, users can still install and run PUAs, making this setting the direct cause of the observed behavior. To actually block PUAs, PUAProtection must be set to Enable or Block mode.

Why this answer

The PUAProtection setting in the Defender for Endpoint Intune policy has three modes: Off, AuditMode, and Enabled (Block). AuditMode only logs detections without blocking, so PUAs continue to install. To actually block PUAs, the setting must be set to 'Enabled' (Block), not AuditMode.

Exam trap

The trap is that AuditMode sounds like it still takes action (auditing implies monitoring), so candidates assume PUAs are being detected and blocked — but AuditMode is explicitly non-blocking, which is the exact symptom described.

How to eliminate wrong answers

Option A is wrong because cloud timeout values govern how long the endpoint waits for a cloud protection verdict before falling back to local decision — they do not cause PUA detection to fail outright, and PUA blocking is a separate policy setting. Option C is wrong because cloud-delivered protection level (High/Normal/Zero-tolerance) affects the aggressiveness of cloud-based malware blocking, not PUA enforcement; PUA blocking is controlled by the dedicated PUAProtection setting. Option D is wrong because real-time monitoring being disabled would broadly weaken all protection, but the question specifically describes PUAs still installing despite a policy — the direct cause is the PUAProtection mode, not real-time monitoring.

600
MCQhard

Your organization uses Microsoft Entra ID Governance. You need to implement an access review for all users who have access to a critical application. The review must be recurring every quarter and require reviewers to provide a justification for their decisions. Which access review settings should you configure?

A.Frequency: Quarterly, Justification required: No
B.Frequency: Quarterly, Justification required: Yes
C.Frequency: Annually, Justification required: Yes
D.Frequency: Monthly, Justification required: Yes
AnswerB

This combination is correct because it satisfies both core requirements: the access review recurrence is set to Quarterly, matching the mandated cadence, and 'Justification required' is enabled. In Microsoft Entra ID Governance, enabling justification forces reviewers to enter a rationale for each approval or denial, which is captured in the review logs and used for compliance evidence. This exactly aligns with the organization's attestation policy.

Why this answer

The requirement specifies a quarterly recurring access review with mandatory justification. In Microsoft Entra ID Governance, the 'Frequency' setting controls the recurrence interval (e.g., Quarterly), and the 'Justification required' toggle enforces that reviewers must provide a reason for their decision. Setting 'Justification required' to 'Yes' ensures compliance with audit and governance policies.

Exam trap

The trap here is that candidates may focus solely on the frequency requirement and overlook the justification requirement, selecting Option A because it matches 'Quarterly' but ignores the mandatory justification setting.

How to eliminate wrong answers

Option A is wrong because it sets 'Justification required' to 'No', which violates the explicit requirement that reviewers must provide justification. Option C is wrong because it sets 'Frequency' to 'Annually', which does not meet the quarterly recurrence requirement. Option D is wrong because it sets 'Frequency' to 'Monthly', which is more frequent than required and could introduce unnecessary overhead, but more importantly, it does not match the specified quarterly interval.

Page 7

Page 8 of 10

Page 9

All pages