Courseiva

Microsoft 365 Administrator MS-102 (MS-102) — Questions 601–675

712 questions total · 10pages · All types, answers revealed

Page 8

Page 9 of 10

Page 10
601
MCQmedium

A legal department needs to preserve all communications related to an ongoing lawsuit. They identify specific users and require that their mailbox items and OneDrive files are not altered or deleted. Which Microsoft Purview feature should be used?

A.Litigation Hold
B.Retention Policy
C.Data Loss Prevention (DLP)
D.eDiscovery
AnswerA

Litigation Hold is the correct mechanism because it places a preservation hold on an entire mailbox and OneDrive for Business site in-place, preventing items from being permanently deleted or altered. Every version of a document and every mailbox item, including deleted items and items edited by users, is retained in the Recoverable Items folder until the hold is released. Deletion by users, as well as cleanup by retention policies, is blocked for held content, ensuring all communications related to the legal matter remain discoverable in their original location.

Why this answer

Litigation Hold is the correct feature because it preserves all mailbox items and OneDrive files for specific users in their current state, preventing any alteration or deletion by users or automated processes. This is essential for legal holds where data must be immutable for eDiscovery purposes, and it applies at the user level rather than broadly across the organization.

Exam trap

The trap here is that candidates often confuse retention policies with litigation holds, thinking retention policies can preserve data indefinitely, but retention policies allow deletion after the retention period and do not block user-initiated edits or deletions during the policy's active duration.

How to eliminate wrong answers

Option B (Retention Policy) is wrong because retention policies are designed for managing data lifecycle and can delete or archive items after a specified period, but they do not prevent users from modifying or deleting content while the policy is active; litigation hold explicitly locks content. Option C (Data Loss Prevention) is wrong because DLP focuses on preventing sensitive data from being shared or leaked through rules and policies, not on preserving data from alteration or deletion. Option D (eDiscovery) is wrong because eDiscovery is a tool for searching, holding, and exporting data as part of legal investigations, but it is not a hold feature itself; litigation hold is the underlying mechanism that eDiscovery uses to preserve content.

602
MCQmedium

A company uses password hash synchronization with Microsoft Entra Connect. The security team wants to enable self-service password reset (SSPR) so that users can reset their own passwords, and the password changes must be written back to the on-premises Active Directory. Which additional configuration is required to achieve password writeback?

A.Configure SSPR to use federation with on-premises AD FS
B.Enable password hash synchronization in Microsoft Entra Connect
C.Install Microsoft Entra Connect with password writeback enabled
D.Set the SSPR property 'Password writeback' to 'Yes' in the Microsoft Entra admin center
AnswerC

To allow SSPR password changes to be written back, Microsoft Entra Connect must be installed or reconfigured with the 'Password writeback' optional feature checked. This action installs the writeback service on the sync server, which connects to the on-premises AD and enables the tenant to accept cloud-originated password resets. After enabling this component, the cloud-side SSPR property must also be set to 'Yes' to complete the configuration.

Why this answer

Password writeback requires the installation of Microsoft Entra Connect with the password writeback feature explicitly enabled during setup. This allows password changes initiated via SSPR to be written back to on-premises Active Directory. Option C is correct because it directly addresses the necessary infrastructure component.

Exam trap

The trap here is that candidates often confuse configuring the SSPR policy setting (Option D) with the actual installation requirement, assuming the admin center toggle alone enables writeback without realizing the Entra Connect component must be installed first.

How to eliminate wrong answers

Option A is wrong because federation with AD FS is not required for password writeback; SSPR with password hash synchronization works independently of federation. Option B is wrong because password hash synchronization is already in place per the scenario, but enabling it again does not enable writeback; writeback is a separate feature. Option D is wrong because setting the SSPR property 'Password writeback' to 'Yes' in the admin center only configures the SSPR policy; it does not install or enable the writeback service in Entra Connect, which is a prerequisite.

603
MCQhard

You manage a Microsoft 365 tenant for a company that uses Microsoft Defender for Office 365 Plan 2. The security team reports that several users clicked a link in a phishing email and entered credentials on a fake sign-in page. You must identify which users were compromised and remediate their accounts as quickly as possible. What should you do?

A.Use the Compromised users report in Microsoft 365 Defender to identify affected users, then select the users and choose to force a password reset and revoke their sessions.
B.Run the Get-MessageTraceV2 cmdlet in Exchange Online PowerShell for the phishing message and disable the accounts of every recipient.
C.Review the Attack simulation training report for the tenant and export the list of users who failed the simulation.
D.Open the Threat Explorer in Microsoft 365 Defender, filter by the sender address, and manually review the message trace for each recipient.
AnswerA

In tenants with Microsoft Defender for Office 365 Plan 2, the compromised users report surfaces users whose credentials were entered on a phishing page detected by the service. From the report, an administrator can confirm the users, then force a password reset and revoke active sessions to contain the compromise quickly.

Why this answer

The Compromised users report in Microsoft 365 Defender uses signals from Defender for Office 365 to detect when a user enters credentials on a phishing site. Because the tenant has Plan 2, the report is available and includes the affected users. From the report, the administrator can force a password reset and revoke sessions, which are the recommended containment actions.

Exam trap

The trap here is reaching for message trace or Threat Explorer, which show delivery and URL data but cannot reveal which recipients actually submitted credentials on the phishing page.

604
MCQmedium

A company with Azure AD Premium P2 licenses wants to enforce that all activations of the Global Administrator role require approval from a designated security group. The activation must also require a business justification and expire after 4 hours. Which Azure AD feature should the administrator configure?

A.Azure AD Identity Protection
B.Azure AD Privileged Identity Management (PIM)
C.Azure AD Conditional Access
D.Azure AD Multi-Factor Authentication
AnswerB

Azure AD Privileged Identity Management (PIM) provides just-in-time activation of Azure AD roles, implementing a request-and-approval workflow that aligns exactly with the stated requirement. Through PIM, you can require users to submit an activation request with justification, designate eligible approvers, and set a maximum activation duration. It also supports time-bound assignments, MFA enforcement on activation, and full auditing of every role activation, making it the definitive solution for controlling privileged access.

Why this answer

Azure AD Privileged Identity Management (PIM) provides time-bound and approval-based role activation. It allows you to require approval from a designated security group, mandate a business justification, and set a maximum activation duration (e.g., 4 hours) for privileged roles like Global Administrator. This directly matches all the requirements in the question.

Exam trap

The trap here is that candidates confuse Conditional Access (which controls sign-in conditions) with PIM (which controls role activation), leading them to select Option C because they think 'approval' is a conditional access policy, but PIM is the only feature that manages role activation workflows and expiration.

How to eliminate wrong answers

Option A is wrong because Azure AD Identity Protection is a risk-based tool that detects and responds to identity threats (e.g., leaked credentials, sign-in risks) but does not manage role activation, approval workflows, or activation duration. Option C is wrong because Azure AD Conditional Access enforces access policies based on conditions like location or device state, but it cannot control role activation approval or expiration; it applies to sign-in events, not role elevation. Option D is wrong because Azure AD Multi-Factor Authentication adds an extra verification step during authentication but does not provide approval workflows, business justification prompts, or time-bound role activation.

605
Drag & Dropmedium

Drag and drop the steps to configure role-based access control (RBAC) in Microsoft 365 Defender in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

RBAC roles are created/edited in Defender, permissions assigned, and then assigned to users/groups.

606
MCQmedium

A company uses Microsoft Entra ID P2 licenses. A security administrator needs to grant a user temporary elevation to the Global Administrator role for a specific task. The elevation should require approval from a designated group and be time-limited. Which Microsoft Entra feature should be configured?

A.Conditional Access
B.Privileged Identity Management
C.Identity Protection
D.Access Reviews
AnswerB

Privileged Identity Management (PIM) in Microsoft Entra ID P2 provides exactly this capability: it lets users activate time-boxed, just-in-time privileged roles through an approval workflow. A user who is made eligible for a role can submit an activation request, which is routed to designated approvers, and upon approval, the role is granted for a configurable duration. This matches the scenario of on-demand role elevation with approval and time constraints.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID P2 provides just-in-time (JIT) privileged access with time-bound activation, approval workflows, and audit logging. This directly meets the requirement for temporary elevation to Global Administrator with approval from a designated group and a time limit.

Exam trap

The trap here is that candidates confuse Privileged Identity Management with Conditional Access, thinking Conditional Access can enforce time-limited role elevation, but Conditional Access only controls authentication conditions, not role activation or approval workflows.

How to eliminate wrong answers

Option A is wrong because Conditional Access enforces policies based on signals like user location or device state at sign-in, but it does not provide time-limited role elevation with approval workflows. Option C is wrong because Identity Protection focuses on detecting and remediating identity-based risks (e.g., leaked credentials, impossible travel), not on managing privileged role assignments or approvals. Option D is wrong because Access Reviews are used to periodically review and certify existing group memberships or role assignments, not to grant temporary, on-demand elevation with approval.

607
Multi-Selecteasy

Your organization needs to manage guest access to Microsoft Teams. Which TWO methods can you use to control guest access?

Select 2 answers
A.Use sensitivity labels to restrict guest access.
B.Configure SharePoint Online external sharing settings.
C.Enable guest access in the Teams admin center.
D.Set conditional access policies for guest users.
E.Configure external collaboration settings in Microsoft Entra ID.
AnswersC, E

In the Microsoft Teams admin center, the Org-wide settings > Guest access section includes an 'Allow guest access in Microsoft Teams' toggle that must be set to On. This setting is the Teams-specific control that admits guest accounts into the team membership and lets them participate in channels and chats. Without this toggle enabled, guests cannot be added to a team even if Microsoft Entra ID allows B2B collaboration invitations. Thus, enabling guest access in the Teams admin center is a required step to support guest collaboration in Teams.

Why this answer

Enabling guest access in the Teams admin center is a required step to allow guest users to join Teams. Without this toggle enabled, guest access is blocked at the Teams level regardless of other settings. This setting works in conjunction with Microsoft Entra ID external collaboration settings to control guest access.

Exam trap

The trap here is that candidates often confuse the separate layers of control—Teams-specific settings (admin center) versus tenant-wide identity settings (Entra ID)—and may think that only one of these two correct options is needed, or that SharePoint settings (Option B) are sufficient for Teams guest access.

608
MCQeasy

You need to prevent users from registering security information for Microsoft Entra self-service password reset (SSPR) if they are not in a specific group. What should you configure?

A.Microsoft Entra Identity Protection user risk policy
B.Combined registration for SSPR and Microsoft Entra multifactor authentication
C.SSPR scope setting to require group membership
D.Conditional Access policy to block registration for non-group members
AnswerC

SSPR scope lets you target registration and reset to a single Microsoft Entra group, so users outside that group cannot register security information. This directly satisfies the requirement to restrict registration by group membership rather than disabling SSPR tenant-wide.

Why this answer

The SSPR scope setting in Microsoft Entra ID allows you to restrict self-service password reset registration and usage to a specific group of users. By configuring the scope to 'Selected' and choosing the group, only members of that group can register security information for SSPR. This directly prevents users outside the group from registering.

Exam trap

MS-102 often tests the confusion between SSPR scope settings and Conditional Access policies, leading candidates to choose Conditional Access for restricting SSPR registration.

How to eliminate wrong answers

Option A is wrong because Identity Protection user risk policies are used to detect and respond to risky sign-ins, not to control SSPR registration scope. Option B is wrong because combined registration for SSPR and MFA only simplifies the registration experience; it does not restrict who can register. Option D is wrong because Conditional Access policies control access to cloud apps based on conditions, but they do not govern SSPR registration scope; SSPR scope is configured separately in the Password reset blade.

609
MCQmedium

A company uses Microsoft Entra ID P2 licenses and wants to enforce multi-factor authentication (MFA) for all users when accessing corporate applications. However, a small group of break-glass accounts must be excluded from MFA requirements to ensure emergency access. The administrator creates a Conditional Access policy targeting all users. Which configuration should be applied to achieve the exclusion?

A.Set 'Grant' control to 'Require multi-factor authentication' and include all users including break-glass accounts.
B.Under 'Assignments' > 'Users and groups', select 'Exclude' and choose the security group containing break-glass accounts.
C.Under 'Session' controls, configure 'Sign-in frequency' with a value of 0 to disable MFA for break-glass accounts.
D.Create a separate policy for break-glass accounts that does not impose MFA and assign it a lower priority.
AnswerB

This is the correct approach because the 'Exclude' setting under 'Assignments' > 'Users and groups' removes the selected security group from the policy's scope entirely. By excluding the group that contains your break-glass accounts, the Conditional Access policy will require MFA for all other users, while the excluded accounts remain accessible for emergency use. This is the recommended pattern from Microsoft, as group-based exclusions are easy to audit and manage, and they ensure break-glass accounts are never subject to the MFA grant control.

Why this answer

Conditional Access policies in Microsoft Entra ID allow administrators to exclude specific users or groups from policy enforcement. By excluding the security group containing break-glass accounts under 'Assignments' > 'Users and groups', the MFA requirement is applied to all other users while ensuring emergency access accounts remain unblocked. This is the standard and recommended approach for handling break-glass accounts in a Conditional Access policy targeting all users.

Exam trap

The trap here is that candidates may confuse session controls (like sign-in frequency) with grant controls (like MFA requirement), or incorrectly assume that a lower-priority policy can override a higher-priority policy that includes the same users, when in fact exclusion is the only reliable method to bypass a policy targeting all users.

How to eliminate wrong answers

Option A is wrong because including break-glass accounts in the policy would force them to satisfy MFA, defeating their purpose as emergency access accounts that must bypass all authentication requirements. Option C is wrong because the 'Sign-in frequency' session control manages how often users must re-authenticate, not whether MFA is required; setting it to 0 disables the session control but does not exclude break-glass accounts from MFA enforcement. Option D is wrong because creating a separate policy with lower priority does not override the existing policy that targets all users; Conditional Access policies are evaluated cumulatively, and the break-glass accounts would still be subject to the MFA requirement unless explicitly excluded.

610
MCQeasy

An administrator adds the custom domain 'fabrikam.com' to a new Microsoft 365 tenant. After adding the domain, the status shows 'Pending verification'. Which type of DNS record must be added to the public DNS zone to complete domain ownership verification?

A.MX record
B.TXT record
C.CNAME record
D.SPF record
AnswerB

Microsoft 365 proves domain ownership by reading a unique TXT value from the domain's public DNS zone. The tenant compares the returned string against the supplied token, and only a matching TXT record moves the domain from Pending verification to verified.

Why this answer

To verify domain ownership in Microsoft 365, you must add a TXT record with a specific verification value provided by the Microsoft 365 admin center to the public DNS zone. This proves you control the domain because only the domain owner can modify DNS records. Other record types like MX, CNAME, or SPF are used for mail routing or service configuration, not for ownership verification.

Exam trap

The trap here is that candidates confuse the verification TXT record with other TXT-based records like SPF or DKIM, or assume any DNS record type can be used for verification, but Microsoft specifically requires a TXT record with a unique token for domain ownership proof.

How to eliminate wrong answers

Option A is wrong because MX records are used to specify mail exchange servers for email routing, not for domain ownership verification. Option C is wrong because CNAME records alias one domain name to another and are not used for verification; they are typically used for service-specific configurations like autodiscover. Option D is wrong because SPF records are a type of TXT record used to authorize sending servers for email authentication, but the verification process requires a specific TXT record with a unique token, not an SPF record.

611
MCQmedium

You are reviewing a Conditional Access policy in JSON format. The policy is applied to all users accessing Office 365 from trusted locations. What is the intended behavior of this policy?

A.Users are blocked if they are not using a compliant device
B.Users must provide MFA and use a compliant device
C.Users only need to provide MFA regardless of device
D.Users must provide MFA or use a compliant device
AnswerD

This is correct because the grant controls are structured with an OR operator, meaning at least one of the listed controls must be satisfied. Users can authenticate with MFA to gain access, or they can sign in from a device that is marked compliant, and either fulfilled control results in grant. The policy scope (users, apps, conditions, etc.) determines when this grant logic is applied, but the operator and control list express exactly an MFA-or-compliant-device requirement.

Why this answer

The policy grants access when users are in a trusted location and either provide MFA or use a compliant device. The 'OR' condition between MFA and device compliance means that satisfying either requirement is sufficient, not both. This is the standard behavior when multiple controls are assigned with 'Require one of the selected controls' in Conditional Access.

Exam trap

The trap here is that candidates often assume multiple grant controls always require all conditions (AND logic), but Conditional Access defaults to OR logic unless the policy explicitly specifies 'Require all the selected controls'.

How to eliminate wrong answers

Option A is wrong because the policy does not block users; it grants access with conditions, and trusted location users are not blocked if they fail device compliance as long as they provide MFA. Option B is wrong because the policy does not require both MFA and a compliant device; it uses an OR condition, so only one is needed. Option C is wrong because the policy does not grant access with MFA alone regardless of device; it also allows access with a compliant device without MFA, so device compliance is a separate path.

612
MCQmedium

You are the Microsoft 365 administrator for a company that uses Microsoft Entra ID P1 and Microsoft 365 E3. A new security policy requires that when users sign in from outside the corporate network, they must use Microsoft Entra multifactor authentication. However, users signing in from the corporate office network must not be prompted for MFA. The corporate office has a public IP address range of 203.0.113.0/24. You create a named location called 'Corporate Office' with this IP range. What should you do next to meet the requirement?

A.Create a conditional access policy that targets all users and all cloud apps, set the condition to exclude the 'Corporate Office' named location, and require multifactor authentication.
B.Create a conditional access policy that targets all users and all cloud apps, set the condition to include the 'Corporate Office' named location, and require multifactor authentication.
C.Configure the 'Corporate Office' named location as trusted and enable security defaults.
D.Enable Microsoft Entra multifactor authentication per user for all users, and configure the corporate IP range as trusted IPs in the MFA service settings.
AnswerA

This policy applies MFA to all users and cloud apps but excludes the trusted corporate IP range. Sign-ins from outside the corporate network will not match the exclusion and will trigger MFA, while sign-ins from the office IP range will be excluded and will not require MFA. This meets the requirement exactly.

Why this answer

A conditional access policy is the correct tool to enforce MFA based on network location. By excluding a named location containing the corporate IP range, the policy applies MFA only when users sign in from outside that range. This satisfies the security policy while avoiding unnecessary prompts for on-premises users.

Exam trap

The trap here is confusing the include and exclude conditions in conditional access, or thinking that trusted IPs in per-user MFA can achieve location-based enforcement.

613
MCQmedium

A company has a Microsoft 365 tenant that uses the default contoso.onmicrosoft.com domain. The IT team wants to add a new custom domain, contoso.com, and ensure that all existing users' primary email addresses automatically change to the new domain. They also want to prevent users from signing in with the onmicrosoft.com domain. What should the administrator do first?

A.Modify the default email address policy in Exchange Online to use contoso.com as the primary SMTP suffix.
B.Create a new mail-enabled security group for all users and assign the contoso.com SMTP address to the group.
C.Run the Set-MsolUserPrincipalName PowerShell cmdlet to change each user's UPN to contoso.com.
D.Add contoso.com as a custom domain in the Microsoft 365 admin center and verify ownership by adding a TXT record to the public DNS zone.
AnswerD

Adding and verifying the custom domain is the mandatory first step before it can be used for email addresses or sign-in. Verification proves domain ownership via a DNS TXT record. Until the domain is verified, you cannot assign it to users, set it as default, or change UPN suffixes. This action directly enables the subsequent steps of updating user principal names and email addresses.

Why this answer

Before any custom domain can be used in Microsoft 365, it must be added and verified in the admin center. Verification typically involves adding a TXT record to the domain's DNS. Only after verification can the domain be assigned to users, set as default, or used for sign-in.

Changing UPNs or email address policies requires the domain to exist first.

Exam trap

The trap here is assuming that changing a user's UPN or email address policy will automatically add and verify a new domain, but domain verification must occur first.

614
MCQmedium

A compliance officer needs to retain all email messages in a user's Exchange Online mailbox for 7 years after the message is sent or received, and then automatically delete them. The retention must be enforced regardless of user actions. Which Microsoft Purview solution should be used?

A.Litigation hold
B.Retention policy with Exchange location
C.Classification policy
D.In-place eDiscovery hold
AnswerB

A retention policy applied to the Exchange location enforces retention at the mailbox level, independent of user deletion or edits. Setting a seven-year retention period then deletion meets the requirement that messages be kept for seven years and removed automatically.

Why this answer

A retention policy with the Exchange location in Microsoft Purview allows you to define a retention period (e.g., 7 years) and then automatically delete messages after that period. It enforces the retention regardless of user actions because it operates at the service level, not relying on user cooperation. This meets the compliance officer's requirement for mandatory, time-based retention and deletion.

Exam trap

The trap here is that candidates often confuse Litigation hold (which preserves indefinitely) with a retention policy (which can both preserve and delete after a set time), leading them to select Litigation hold for time-based deletion scenarios.

How to eliminate wrong answers

Option A is wrong because Litigation hold preserves all mailbox content indefinitely until the hold is removed, but it does not automatically delete messages after a specific period; it is designed for legal preservation, not time-based retention with deletion. Option C is wrong because Classification policy (e.g., sensitivity labels) applies metadata and protection actions but does not enforce time-based retention or automatic deletion of email messages. Option D is wrong because In-place eDiscovery hold is a deprecated feature that preserves content for eDiscovery purposes without automatic deletion; it also does not support time-based retention policies.

615
MCQmedium

You are examining the default cross-tenant access policy for your Microsoft Entra ID tenant. Based on the exhibit, which statement is true?

A.Your users can use their Microsoft Authenticator app to sign in to partner tenants.
B.B2B direct connect is enabled for all external organizations.
C.External users must always reauthenticate even if their home tenant requires MFA.
D.Compliant device claims from external tenants are trusted.
AnswerC

With IsMfaAccepted set to $false in the inbound trust settings, the default cross-tenant access policy does not accept MFA claims from external IdPs. This means that even if a user from a partner tenant satisfied MFA in their home tenant, they must complete MFA again when accessing resources in your tenant. Your tenant's conditional access policies are enforced independently of the external tenant's MFA state, ensuring your organization's MFA requirements are always satisfied.

Why this answer

The default cross-tenant access policy in Microsoft Entra ID includes a setting that, when enabled, requires external users to satisfy MFA requirements from their home tenant. However, the exhibit shows that the 'Trust MFA from external tenants' option is not selected, meaning Entra ID will not accept MFA claims from the external user's home tenant. As a result, external users must always reauthenticate with MFA, even if their home tenant already enforced MFA.

Exam trap

The trap here is that candidates assume 'Trust MFA from external tenants' is enabled by default, but Microsoft deliberately leaves it disabled to enforce the resource tenant's own MFA policies, requiring external users to reauthenticate.

How to eliminate wrong answers

Option A is wrong because the Microsoft Authenticator app is a personal authentication method tied to the user's home tenant; cross-tenant access policies do not govern which authenticator app a user can use in partner tenants. Option B is wrong because B2B direct connect is not enabled by default for all external organizations; it must be explicitly configured in the cross-tenant access settings. Option D is wrong because compliant device claims from external tenants are not trusted by default; the 'Trust device compliance from external tenants' setting must be explicitly enabled in the cross-tenant access policy.

616
MCQmedium

An organization wants to delegate user creation to help desk staff without granting global admin rights. Which role should be assigned?

A.Global Administrator
B.Helpdesk Administrator
C.License Administrator
D.User Administrator
AnswerD

User Administrator is the built-in role that includes the permissions to create and manage users and groups, reset passwords for non-administrators, and assign/remove licenses, which aligns directly with typical help desk provisioning tasks. It is a least-privilege-appropriate choice because it does not grant access to tenant-wide settings or the ability to manage other administrators. This makes it the correct built-in role for delegating user creation and license management to a help desk.

Why this answer

The User Administrator role is the correct choice because it grants the specific permissions needed to create and manage users and groups, including resetting passwords, without the broad privileges of Global Administrator. This role aligns with the principle of least privilege for help desk staff who need to perform user creation tasks.

Exam trap

The trap here is that candidates often confuse Helpdesk Administrator with User Administrator because both can reset passwords, but only User Administrator can create users, which is the specific task required in the question.

How to eliminate wrong answers

Option A is wrong because Global Administrator has unrestricted access to all Azure AD and Microsoft 365 settings, which is excessive and violates security best practices for delegating user creation. Option B is wrong because Helpdesk Administrator can reset passwords and manage service requests but cannot create users or modify user attributes beyond password resets. Option C is wrong because License Administrator can only assign and manage licenses for users and groups, not create new user accounts.

617
Matchingmedium

Match each Microsoft 365 migration tool to its use case.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Migrate mailboxes from on-premises to Exchange Online

Migrate files from on-premises to SharePoint and OneDrive

Sync on-premises identities to Azure AD

Orchestrate large-scale migrations

Migrate data from Google Workspace

Why these pairings

Correct matches: Exchange Migration (cutover) migrates entire on-premises Exchange organization; SPMT migrates files and SharePoint content; Mover migrates files from cloud storage; Azure AD Connect synchronizes identities. Common confusions include mixing the purpose of Mover with Exchange migration and SPMT with identity synchronization.

618
MCQmedium

A company plans to enable Self-Service Password Reset (SSPR) for all users. The administrator needs to ensure that users are required to register at least two authentication methods before they can use SSPR. Which configuration setting should the administrator modify?

A.Set the 'Number of methods required to reset' to 2 in the SSPR authentication methods settings.
B.Enable combined registration for SSPR and Microsoft Entra ID Multi-Factor Authentication.
C.Configure a Conditional Access policy requiring MFA registration for SSPR.
D.Set the 'Number of questions required to register' to 2 in the security questions settings.
AnswerA

This setting directly enforces that users must register at least two methods to use SSPR.

Why this answer

The 'Number of methods required to reset' setting directly controls how many authentication methods a user must provide during the SSPR reset process. By setting this value to 2, the administrator ensures that users must register at least two methods (e.g., phone and email) before they can reset their password, as SSPR requires the registered methods to match the reset requirement.

Exam trap

The trap here is confusing the 'Number of methods required to reset' (which controls the reset process) with the 'Number of methods required to register' (which controls initial registration), leading candidates to mistakenly choose options that affect registration but not the reset requirement.

How to eliminate wrong answers

Option B is wrong because enabling combined registration for SSPR and Microsoft Entra ID Multi-Factor Authentication simplifies the registration process but does not enforce a minimum number of methods for SSPR usage. Option C is wrong because a Conditional Access policy requiring MFA registration for SSPR can mandate MFA registration but does not control the number of authentication methods needed for SSPR reset. Option D is wrong because the 'Number of questions required to register' setting applies only to security questions, which are a specific authentication method, and does not enforce the overall number of methods required for reset; also, security questions are not a recommended method for SSPR.

619
MCQeasy

An organization has just purchased Microsoft 365 Business Standard licenses. The administrator adds a new user through the admin center. By default, does the new user receive a welcome email with sign-in instructions?

A.Yes, always, regardless of how the user is created.
B.Yes, if the administrator does not clear the 'Send welcome email' checkbox during user creation.
C.No, the administrator must manually send the welcome email using a script.
D.No, welcome emails are only sent when using the 'Add multiple users' option.
AnswerB

Correct — when an administrator adds a user through the admin center, either individually or in bulk, the 'Send welcome email' checkbox appears on the 'Finish' or 'Settings' page and is checked by default. As long as that box remains checked during the creation process, Microsoft 365 automatically sends the welcome email to the user's designated email address with the temporary password and sign-in information. If the administrator unchecks the box, no email is sent and the admin must distribute credentials another way.

Why this answer

When an administrator adds a new user through the Microsoft 365 admin center, the default behavior is to send a welcome email containing the user's sign-in name and temporary password. The administrator can opt out by clearing the 'Send welcome email in email' checkbox during the creation process. Therefore, the user receives the email unless the administrator explicitly deselects that option.

Exam trap

The trap here is that candidates may assume the welcome email is always sent or never sent, overlooking the specific checkbox control that allows the administrator to suppress the email during user creation.

How to eliminate wrong answers

Option A is wrong because the welcome email is not always sent; it depends on the checkbox state during user creation, and if the user is created via other methods (e.g., PowerShell, bulk CSV import), the email may not be sent by default. Option C is wrong because the administrator does not need to manually send the email using a script; the admin center provides a built-in checkbox to control sending, and the email is sent automatically unless the checkbox is cleared. Option D is wrong because the welcome email is sent for single user creation as well, not only when using the 'Add multiple users' option; the checkbox exists in both single and bulk creation flows.

620
MCQeasy

Your organization uses Microsoft Defender for Office 365. You need to ensure that all email messages containing encrypted attachments are automatically scanned for malware before delivery. What should you configure?

A.Safe Attachments policy
B.Safe Links policy with URL scanning
C.Anti-malware policy
D.Anti-spam policy
AnswerA

Dynamic Delivery allows scanning encrypted attachments.

Why this answer

Safe Attachments policy can be configured to scan encrypted attachments. Option B is wrong because it is for scanning URLs in emails. Option C is wrong because the anti-malware policy handles malware detection but does not specifically address encrypted attachments.

Option D is wrong because the anti-spam policy is designed to filter spam, not to scan attachments for malware.

621
MCQmedium

Your organization uses Microsoft Defender for Office 365. Users report that legitimate emails from a specific partner domain are being moved to Junk Email folder. You verify that the partner's SPF, DKIM, and DMARC records are correctly configured. Which two actions should you take to resolve this issue?

A.Modify the Anti-Spam policy to increase the spam threshold.
B.Review the Anti-Phishing policy's spoof intelligence settings.
C.Configure the Outbound spam filter policy.
D.Disable the Spam filter for the affected users.
E.Add the partner domain to the Tenant Allow/Block List as an allowed domain.
AnswerB, E

Spoof intelligence settings can flag the partner domain as intra-organisation or impersonating a trusted sender, overriding correct SPF, DKIM and DMARC. Reviewing them identifies why legitimate mail is treated as spoofed and routed to Junk Email.

Why this answer

Legitimate emails from a partner domain are being moved to Junk Email folder despite correct SPF, DKIM, and DMARC records. This typically indicates that the emails are being misclassified as spoofed or phishing. Reviewing the Anti-Phishing policy's spoof intelligence settings (Option B) allows you to check if the partner domain is being incorrectly treated as a spoof sender and adjust the settings accordingly.

Additionally, adding the partner domain to the Tenant Allow/Block List as an allowed domain (Option E) explicitly permits emails from that domain, overriding any false positive filtering. Option A (increasing spam threshold) may reduce spam filtering effectiveness and does not address the root cause. Option C (Outbound spam filter policy) affects outgoing emails, not inbound.

Option D (disabling spam filter) is too aggressive and removes protection for the affected users. Therefore, the correct actions are B and E.

622
MCQhard

You have a Microsoft 365 E5 tenant with Microsoft Defender for Cloud Apps. You need to discover unsanctioned cloud apps used by users. What should you configure?

A.Conditional Access App Control
B.Microsoft Purview Data Loss Prevention
C.Microsoft Defender for Endpoint App Control
D.Microsoft Defender for Cloud Apps Cloud Discovery
AnswerD

Microsoft Defender for Cloud Apps Cloud Discovery parses your network traffic logs, either uploaded manually or forwarded via integrated proxies and Defender for Endpoint, to identify and score the cloud apps your users access. It compares traffic against a catalog of over 31,000 apps and even detects unknown apps heuristically, enabling you to mark them as sanctioned or unsanctioned. This is the correct tool for discovering the full landscape of apps in your environment.

Why this answer

Microsoft Defender for Cloud Apps Cloud Discovery is the correct feature for identifying unsanctioned cloud apps used in your environment. It analyzes traffic logs from your network or endpoints to discover all cloud app usage, categorizes them by risk, and allows you to sanction or unsanction them. This directly fulfills the requirement to discover unsanctioned cloud apps.

Exam trap

The trap here is that candidates confuse Conditional Access App Control (a policy enforcement mechanism for sanctioned apps) with Cloud Discovery (the actual discovery and risk assessment feature), leading them to select Option A instead of the correct answer.

How to eliminate wrong answers

Option A is wrong because Conditional Access App Control is a session-level policy enforcement feature that works with sanctioned apps to control access and data exfiltration, not a discovery tool for finding unsanctioned apps. Option B is wrong because Microsoft Purview Data Loss Prevention (DLP) is designed to prevent sensitive data from being shared or leaked, not to discover or inventory cloud app usage. Option C is wrong because Microsoft Defender for Endpoint App Control (Windows Defender Application Control) is a host-based security feature that controls which executables can run on Windows devices, not a cloud app discovery mechanism.

623
Multi-Selecthard

Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that detects when a user signs in from an unknown IP address and then downloads a large number of files. Which THREE components should you configure?

Select 3 answers
A.IP address range category
B.Scope (users and groups)
C.Anomaly detection policy template
D.Session policy
E.Alert settings
AnswersB, C, E

The Scope (users and groups) component is a mandatory and correct part of an anomaly detection policy in Microsoft Defender for Cloud Apps. It defines the set of users or groups whose activity is monitored and evaluated against the detection template. For example, you can scope the policy to only your global administrators or a specific group of high-privilege users, which reduces false positives and focuses on the accounts that matter most. Without a defined scope, the policy cannot determine whose activities are subject to anomaly analysis.

Why this answer

The policy must be scoped to specific users or groups to ensure that the anomaly detection rule (unknown IP followed by mass download) applies only to the intended set of accounts. Without scoping, the policy would evaluate all users, which may generate excessive noise or miss targeted monitoring. In Microsoft Defender for Cloud Apps, the Scope (users and groups) setting is a required component when creating an anomaly detection policy to define which identities are monitored.

Exam trap

The trap here is that candidates often confuse the IP address range category (Option A) as a required component for defining unknown IPs in an anomaly detection policy, when in fact the policy automatically uses the organization's configured IP ranges and does not require a separate category to be selected during policy creation.

624
MCQmedium

The exhibit shows a KQL query used in Microsoft 365 Defender. The query returns no results for admin@contoso.com. What is the most likely reason?

A.The user does not have the Global Administrator role.
B.The KQL query syntax is invalid.
C.The role name in the query is misspelled.
D.Microsoft Defender for Identity is not enabled for the tenant.
AnswerD

IdentityInfo is not derived from the Microsoft Graph or role directory alone; it is continuously synchronized by Microsoft Defender for Identity (MDI) sensors from on-premises Active Directory and Azure AD. MDI enriches identities with role, group, and resource access data. When MDI is not onboarded or properly licensed, the IdentityInfo table remains empty or contains only incomplete data, so any query filtering it returns no rows. This is the root cause consistent with an empty result set and a valid query, making it the only correct answer here.

Why this answer

The KQL query uses the `IdentityLogonEvents` table, which is populated by Microsoft Defender for Identity (MDI). If MDI is not enabled for the tenant, this table contains no data, so the query returns no results regardless of the user's role or query syntax. The query itself is syntactically correct and the role name 'GlobalAdministrator' is valid, but without MDI being provisioned, the table is empty.

Exam trap

The trap here is that candidates often assume a query returning no results must have a syntax error or a misspelled value, when in fact the underlying data source (Defender for Identity) may not be provisioned, causing the table to be empty.

How to eliminate wrong answers

Option A is wrong because the query filters on the `AccountUpn` field, not on administrative roles; even if the user lacks the Global Administrator role, the query would still return logon events for that user if MDI were enabled. Option B is wrong because the KQL syntax is valid: it correctly uses the `where` operator with a string comparison and a logical `and` to filter on `ActionType`. Option C is wrong because 'GlobalAdministrator' is the correct role name as stored in the `AccountSid` or related fields in Defender for Identity; a misspelling would cause a syntax error or no match, but the query returns no results for a valid user, indicating the data source itself is missing.

625
MCQhard

A user with an E5 license is unable to use Azure Information Protection (AIP). The admin confirms the license is assigned. What is the most likely cause?

A.AIP requires an additional subscription
B.AIP client is not installed
C.AIP service plan is disabled in the license
D.User account is blocked
AnswerC

The most likely cause is that the 'Azure Information Protection' service plan is disabled in the user's license assignment. In Microsoft 365, an administrator can toggle individual service plans on or off within a license while keeping the overall license assigned; disabling this plan blocks all AIP-related functionality without affecting other services. To confirm, check the user's license details in Microsoft 365 admin center under Users > Active Users > Licenses, or use PowerShell with Get-MgUserLicenseDetail to inspect the service plan status.

Why this answer

Even with an E5 license assigned, the Azure Information Protection (AIP) service plan must be explicitly enabled for the user. By default, some service plans within an E5 license may be disabled, and the AIP service plan (commonly labeled as 'Azure Information Protection' or 'Information Protection for Office 365') must be toggled on in the user's license settings in the Microsoft 365 admin center. Without this, the user cannot activate AIP features regardless of license assignment.

Exam trap

The trap here is that candidates assume an E5 license automatically grants full access to all included features, but Microsoft requires each service plan to be individually enabled, and the exam tests this granular licensing behavior.

How to eliminate wrong answers

Option A is wrong because E5 already includes AIP; no additional subscription is needed. Option B is wrong because the AIP client is only required for on-premises labeling or unified labeling client scenarios, but the core AIP service (e.g., protection, labeling in Office apps) works via the cloud service plan. Option D is wrong because a blocked user account would prevent all access, not just AIP, and the question states the user is unable to use AIP specifically, not that they are blocked from all services.

626
MCQeasy

Refer to the exhibit. You deploy this configuration profile to Windows devices. What is the most likely outcome?

A.Automated investigation will be triggered for alerts with severity Medium and above, and email notifications will be sent to admin@contoso.com.
B.Automated investigation will be triggered only for alerts with severity High, and email notifications will be sent to all admins.
C.Automated investigation will be disabled, and email notifications will be sent to admin@contoso.com.
D.Automated investigation will be triggered for all alerts regardless of severity, and no email notifications will be sent.
AnswerA

This configuration profile is correctly interpreted because it explicitly sets the automated investigation severity threshold to 'Medium and above', meaning alerts classified as Medium, High, or Critical will trigger an automated investigation. Additionally, email notifications are enabled and addressed specifically to admin@contoso.com, not to all administrators, which matches the 'To' field in the policy. The combination of an inclusive severity threshold and a targeted recipient list is exactly what the deployment produces.

Why this answer

The configuration profile sets the automated investigation action to 'Medium or higher' and specifies a single email recipient (admin@contoso.com). This means Defender for Endpoint will trigger automated investigations for alerts with severity Medium, High, or Critical, and send email notifications only to the listed address, not to all admins.

Exam trap

The trap here is that candidates often confuse the severity filter with a binary on/off toggle, or assume that specifying a single email recipient sends notifications to all admins by default, when in fact the recipient list is explicitly defined.

How to eliminate wrong answers

Option B is wrong because the profile sets the severity threshold to 'Medium or higher', not 'High' only, and notifications are sent to the specified address, not all admins. Option C is wrong because automated investigation is not disabled; the profile explicitly enables it with a severity filter. Option D is wrong because the profile restricts automated investigation to alerts of Medium severity and above, not all alerts, and it does specify email notifications to admin@contoso.com.

627
Multi-Selecthard

Your organization uses Microsoft Entra ID and has strict security requirements. You need to implement a Zero Trust security model. Which THREE of the following are foundational principles of Zero Trust that should be implemented?

Select 3 answers
A.Assume trust based on location
B.Segment access
C.Use least privilege access
D.Assume breach
E.Verify explicitly
AnswersC, D, E

Least privilege access enforces just-in-time and just-enough-access (JEA), limiting standing permissions so users receive only the rights needed for a task. This directly satisfies the Zero Trust principle of assuming breach, since compromised accounts cannot move laterally across Microsoft Entra ID resources without elevated rights.

Why this answer

Option E (Verify explicitly) is correct because Zero Trust requires that every access request be authenticated and authorized based on all available data points, including user identity, device health, location, and resource sensitivity, rather than granting implicit trust. Option C (Use least privilege access) is correct because Zero Trust mandates just-in-time and just-enough-access (JIT/JEA), risk-based adaptive policies, and data protection to limit each user's access to only what is needed for the task. Option D (Assume breach) is correct because Zero Trust operates on the assumption that the network is already compromised, so organizations must minimize blast radius, segment access, verify end-to-end encryption, and use analytics to detect and respond to threats.

Option A (Assume trust based on location) does not belong because Zero Trust explicitly rejects implicit trust from network location such as a corporate LAN or VPN, which is a core tenet of the traditional perimeter model. Option B (Segment access) is a related implementation tactic rather than one of the three foundational principles, which Microsoft defines as Verify explicitly, Use least privilege access, and Assume breach.

Exam trap

Microsoft often tests the distinction between security best practices (like segmentation) and the specific foundational principles of Zero Trust, causing candidates to select 'Segment access' because it sounds correct, but it is not one of the three core pillars defined by Microsoft.

628
MCQmedium

A security administrator needs to implement a just-in-time (JIT) privileged access solution for the Global Administrator role. Users must request activation and provide a business justification. The request must be approved by a separate group of approvers, and the role activation should expire after 4 hours. Which Microsoft Entra feature should be configured?

A.Conditional Access
B.Privileged Identity Management (PIM)
C.Azure AD Roles (default role settings)
D.Identity Protection
AnswerB

Microsoft Entra Privileged Identity Management provides eligible role assignment, approval workflows, business justification prompts and time-bound activation. Configuring the Global Administrator role as eligible with a four-hour maximum duration and designated approvers satisfies every stated requirement.

Why this answer

Privileged Identity Management (PIM) is the Microsoft Entra feature specifically designed for just-in-time (JIT) privileged access. It allows you to configure role activation with approval workflows, require a business justification, set a maximum activation duration (e.g., 4 hours), and designate specific approvers. This directly matches all requirements in the question.

Exam trap

The trap here is that candidates often confuse Conditional Access (which controls access to apps) with PIM (which controls privileged role activation), or they assume default role settings can enforce JIT activation without realizing that PIM is the only feature that provides time-bound, approval-based role elevation.

How to eliminate wrong answers

Option A is wrong because Conditional Access enforces access policies based on signals like user location or device state, but it does not provide JIT role activation, approval workflows, or time-bound role elevation. Option C is wrong because Azure AD Roles (default role settings) only define static role assignments and permissions; they lack the ability to require activation requests, business justification, or approval from a separate group. Option D is wrong because Identity Protection focuses on detecting and remediating identity risks (e.g., leaked credentials, anomalous sign-ins) and does not manage privileged role activation or approval processes.

629
MCQmedium

A compliance officer wants to automatically apply a 'Confidential' sensitivity label to documents in SharePoint Online that contain credit card numbers. The label should be applied when the documents are created or modified. Which Microsoft Purview feature should be configured?

A.Create an auto-labeling policy for sensitivity labels
B.Create a retention label policy
C.Create a Data Loss Prevention (DLP) policy
D.Configure a default sensitivity label
AnswerA

Auto-labeling policies for sensitivity labels scan content in Microsoft 365 using sensitive information types and pattern matching to detect data such as personal, financial, or health information. When a match occurs, the policy automatically applies a configured sensitivity label—like 'Confidential'—directly to the file or email. This is the only mechanism here that both analyzes content and applies a sensitivity label, satisfying the compliance officer's requirement. Additionally, auto-labeling policies can run in simulation mode to tune detection before full enforcement.

Why this answer

Auto-labeling policies for sensitivity labels in Microsoft Purview can automatically apply a sensitivity label to documents in SharePoint Online based on sensitive information types, such as credit card numbers. This policy scans documents when they are created or modified and applies the label without user intervention, meeting the compliance officer's requirement.

Exam trap

The trap here is that candidates often confuse a DLP policy's ability to detect sensitive data with the ability to automatically apply a sensitivity label, but DLP policies only trigger alerts or block actions, not label documents.

How to eliminate wrong answers

Option B is wrong because retention label policies are designed to manage data retention and deletion, not to apply sensitivity labels for classification or protection. Option C is wrong because a Data Loss Prevention (DLP) policy can detect and block sharing of sensitive data but cannot automatically apply a sensitivity label to documents. Option D is wrong because configuring a default sensitivity label applies the label to new documents automatically but does not scan for specific content like credit card numbers, nor does it trigger on modification.

630
MCQmedium

A company is planning to migrate from on-premises Exchange to Exchange Online and needs to ensure that mail flow can coexist between the two environments during the transition. Which tool should the administrator use to configure this hybrid deployment?

A.Azure AD Connect
B.Exchange Hybrid Configuration Wizard
C.Microsoft 365 Admin Center
D.Exchange Admin Center
AnswerB

The Exchange Hybrid Configuration Wizard automates creation of the hybrid configuration, including connectors, accepted domains, OAuth and the free/busy sharing needed for coexistence. It is the supported tool for establishing mail flow between on-premises Exchange and Exchange Online during migration.

Why this answer

The Exchange Hybrid Configuration Wizard (HCW) is the correct tool because it automates the configuration of coexistence features between on-premises Exchange and Exchange Online, including mail flow routing, free/busy sharing, and OAuth authentication. It generates the necessary connectors and settings to support a hybrid deployment, ensuring seamless mail flow during migration.

Exam trap

The trap here is that candidates often confuse Azure AD Connect's directory synchronization role with hybrid mail flow configuration, assuming it handles all hybrid setup, when in fact it only syncs objects and does not configure Exchange-specific routing or coexistence.

How to eliminate wrong answers

Option A is wrong because Azure AD Connect synchronizes directory objects (users, groups) but does not configure mail flow or hybrid coexistence settings between Exchange environments. Option C is wrong because the Microsoft 365 Admin Center provides high-level tenant management and licensing but lacks the granular Exchange-specific hybrid configuration capabilities. Option D is wrong because the Exchange Admin Center (EAC) in Exchange Online or on-premises can manage individual connectors and settings but does not provide the guided, automated workflow of the HCW for establishing a full hybrid deployment.

631
MCQeasy

A new administrator needs to automatically assign Microsoft 365 E5 licenses to all users in the Sales department. The Sales department is identified by the 'department' attribute in Azure AD. Which licensing method should the administrator use to minimize manual effort?

A.Manual license assignment per user
B.Group-based licensing using a dynamic group
C.PowerShell script to assign licenses
D.Bulk license assignment via CSV file
AnswerB

Dynamic groups evaluate the 'department' attribute through membership rules, so users added to Sales are licensed automatically without manual intervention. Group-based licensing then assigns the E5 licence and removes it when users leave, satisfying the requirement to minimise ongoing administrative effort.

Why this answer

Group-based licensing using a dynamic group is the correct method because it automatically assigns Microsoft 365 E5 licenses to all users in the Sales department based on the 'department' attribute in Azure AD. Dynamic groups evaluate membership rules in real time, so when a user's department attribute is set to 'Sales', the license is assigned without manual intervention. This minimizes administrative effort by eliminating the need for per-user or batch operations.

Exam trap

The trap here is that candidates often choose PowerShell scripting (Option C) thinking it is the most automated method, but they overlook that group-based licensing provides true zero-touch, attribute-driven automation without requiring custom code or scheduled tasks.

How to eliminate wrong answers

Option A is wrong because manual license assignment per user requires an administrator to individually assign licenses to each Sales department user, which is labor-intensive and does not scale. Option C is wrong because a PowerShell script, while automatable, still requires manual execution or scheduling and does not provide real-time, attribute-based automatic assignment like group-based licensing does. Option D is wrong because bulk license assignment via CSV file is a one-time operation that does not automatically handle new users or attribute changes, requiring repeated manual exports and imports.

632
MCQeasy

You need to configure Microsoft Defender for Cloud Apps to detect anomalous user behavior such as impossible travel. Which type of policy should you create?

A.Access policy
B.Session policy
C.Anomaly detection policy
D.File policy
AnswerC

Anomaly detection policies in Microsoft Defender for Cloud Apps baseline each user's normal activity and raise alerts on deviations such as impossible travel, satisfying the requirement to detect anomalous behaviour. Unlike activity policies, which trigger on predefined matching criteria, they use behavioural analytics, so no manual rule logic is needed.

Why this answer

Anomaly detection policy. In Microsoft Defender for Cloud Apps, anomaly detection policies are specifically designed to identify unusual user behaviors, such as impossible travel (login from geographically distant locations within a short time), unusual activity patterns, and other security anomalies. Option A (Access policy) is incorrect because it enforces access controls based on conditions like location or device, rather than detecting anomalies.

Option B (Session policy) is incorrect as it monitors and controls real-time application sessions, not anomaly detection. Option D (File policy) is incorrect because it focuses on data protection by applying rules to files stored in cloud apps.

633
MCQeasy

A security administrator needs a single console to investigate and respond to a complex incident involving alerts from endpoints, email, and identities. Which Microsoft portal should they use?

A.Microsoft 365 Defender portal
B.Microsoft Sentinel
C.Microsoft Defender for Cloud
D.Microsoft 365 compliance center
AnswerA

Microsoft 365 Defender portal unifies signals from Defender for Endpoint, Defender for Office 365, and Microsoft Entra ID Protection into one incident view, enabling cross-domain investigation and response. This single console satisfies the requirement to correlate endpoint, email, and identity alerts for a complex incident.

Why this answer

The Microsoft 365 Defender portal (security.microsoft.com) is the correct choice because it provides a unified incident management console that correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Defender for Identity. This allows the security administrator to investigate and respond to a complex incident spanning endpoints, email, and identities from a single pane of glass, leveraging automated investigation and response (AIR) capabilities.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with the Microsoft 365 Defender portal (an XDR console), assuming that any security investigation must go through a SIEM, but the question specifically asks for the single console that natively correlates alerts from endpoints, email, and identities without additional data ingestion setup.

How to eliminate wrong answers

Option B is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR platform that ingests logs from multiple sources, but it is not the single console designed for native XDR incident correlation across Microsoft 365 Defender workloads; it requires additional configuration and data connectors to unify alerts from endpoints, email, and identities. Option C is wrong because Microsoft Defender for Cloud is focused on securing cloud workloads (IaaS, PaaS, and data services) and does not natively integrate email and identity alerts from Microsoft 365 Defender. Option D is wrong because the Microsoft 365 compliance center is designed for data governance, eDiscovery, and compliance management, not for real-time security incident investigation and response.

634
MCQmedium

Your organization uses Microsoft Entra ID for identity management. You need to ensure that users can sign in using their Google Workspace credentials without creating external identities. What should you configure?

A.Enable Microsoft Entra Verified ID for Google Workspace users
B.Configure Google as a social identity provider in Microsoft Entra External ID
C.Configure Microsoft Entra B2B collaboration with Google Workspace
D.Configure SAML/WS-Fed identity provider federation with Google Workspace
AnswerD

Configuring SAML/WS-Fed identity provider federation is the correct approach because Microsoft Entra ID supports direct federation with Google Workspace by exchanging metadata and establishing a trust relationship. This allows Google Workspace users to authenticate with their existing corporate credentials and gain SSO access to Entra ID-integrated apps and resources. It provides a true federation experience where Google is treated as an external IdP within the Entra tenant.

Why this answer

Configuring SAML/WS-Fed identity provider federation with Google Workspace allows users to sign in using their Google Workspace credentials directly, without creating external identities. This federation establishes a trust relationship between Microsoft Entra ID and Google Workspace as an identity provider, enabling seamless authentication for users who already have Google accounts.

Exam trap

The trap here is that candidates often confuse social identity provider configuration (Option B) with enterprise federation, but social IdPs are designed for consumer scenarios and create external identities, whereas SAML/WS-Fed federation preserves the user's existing identity without creating new objects in the directory.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Verified ID is a decentralized identity solution using verifiable credentials, not designed for federating with Google Workspace for sign-in. Option B is wrong because configuring Google as a social identity provider in Microsoft Entra External ID is intended for consumer-facing applications and creates external identities, not for enterprise users with existing Google Workspace accounts. Option C is wrong because Microsoft Entra B2B collaboration creates external guest user objects in the directory, which contradicts the requirement to avoid creating external identities.

635
MCQeasy

A compliance officer wants to prevent users from sending emails that contain personally identifiable information (PII), such as social security numbers, to external recipients. If a user attempts to send such an email from Outlook, the email should be blocked and a policy tip explaining the block should be displayed. Which Microsoft Purview solution should the officer configure?

A.Microsoft Purview Data Loss Prevention (DLP) policy
B.Microsoft Purview Information Protection sensitivity label
C.Microsoft Purview Records Management retention label
D.Microsoft Purview eDiscovery case
AnswerA

A Microsoft Purview Data Loss Prevention (DLP) policy is exactly designed for this scenario: when applied to Exchange Online, it inspects outbound messages in transit against sensitive info types (such as social security numbers or credit card numbers) and can take corrective actions like blocking the message before it leaves the organization, optionally allowing an end-user override with justification and a policy tip in Outlook. This combination of content inspection, transport-level enforcement, and real-time user notification makes it the correct choice for preventing users from sending emails with specific sensitive data.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies are specifically designed to detect and block sensitive information, such as PII (e.g., social security numbers), in transit. When a DLP rule matches, it can block the email and display a policy tip in Outlook, informing the user why the message was blocked. This meets the compliance officer's requirement to prevent external sending of PII with real-time user notification.

Exam trap

The trap here is that candidates confuse sensitivity labels (which apply protection at rest) with DLP policies (which enforce actions on data in motion), leading them to choose Option B because they associate labels with 'protecting' PII, but labels do not block outbound email or trigger policy tips.

How to eliminate wrong answers

Option B is wrong because sensitivity labels classify and protect data at rest (e.g., encryption, visual markings) but do not natively block outbound email based on content inspection or display policy tips in Outlook. Option C is wrong because retention labels manage data lifecycle (retention and deletion) and are not designed to inspect or block email content in transit. Option D is wrong because eDiscovery cases are used for legal hold, search, and export of content, not for real-time prevention of email sending or policy tip enforcement.

636
MCQhard

You are a Microsoft 365 administrator. Users report that they cannot create Microsoft Teams meetings using the Teams desktop client. They receive an error: 'Meeting creation is disabled by your IT administrator.' You need to enable meeting creation. You check the Teams admin center and find that meeting policies are set to 'Off' for 'Allow private meeting scheduling'. However, after changing it to 'On', users still get the error. What is the most likely cause?

A.The user does not have an OAuth 2.0 token.
B.The global meeting policy is overriding the user-level policy.
C.The user's mailbox is still on-premises and not migrated to Exchange Online.
D.The user does not have a Microsoft Teams license assigned.
AnswerC

Teams meeting schedules are stored in the user's Exchange calendar. When the user mailbox remains on-premises in a hybrid deployment, the Teams meeting policy is ineffective because the online meeting workspace is controlled by Exchange on-premises, not by Exchange Online. Only after the mailbox is migrated to Exchange Online will Teams be able to provision the meeting workspace and enforce the assigned meeting policy.

Why this answer

The error persists because the user's mailbox is still on-premises and not migrated to Exchange Online. Microsoft Teams relies on Exchange Online for scheduling features, including private meeting creation. Even with the meeting policy set to 'On', if the mailbox is on-premises, the Teams client cannot communicate with Exchange Online to create the meeting, resulting in the error.

Exam trap

The trap here is that candidates often assume changing the meeting policy in the Teams admin center is sufficient, overlooking the critical dependency on Exchange Online for Teams calendar features, which is a common misconfiguration in hybrid environments.

How to eliminate wrong answers

Option A is wrong because OAuth 2.0 tokens are used for authentication and authorization, not for enabling or disabling meeting creation; the error is policy-related, not token-related. Option B is wrong because the global meeting policy only applies if no user-level policy is assigned; if a user-level policy is explicitly set to 'On', it should override the global policy, so this would not cause the error. Option D is wrong because if the user lacked a Teams license, they would not be able to access the Teams desktop client at all, or would see a different error about licensing, not a specific meeting creation disabled error.

637
MCQeasy

Your company is deploying Microsoft 365 for a new subsidiary with 500 users. You need to configure the initial tenant with a custom domain (contoso.com) and verify ownership. What is the first step you must perform?

A.Delegate the contoso.com zone to Microsoft 365 DNS servers.
B.Create user accounts with the custom domain before verification.
C.Add a TXT record provided by Microsoft 365 to the contoso.com DNS zone.
D.Set contoso.com as the default domain in the Microsoft 365 admin center.
AnswerC

Adding the TXT record provided by the Microsoft 365 domain setup wizard is the correct verification method. The wizard generates a unique TXT record value that you must publish in the public DNS zone of contoso.com; Microsoft 365 then queries the DNS to confirm the record exists and matches, proving your control over the domain. This TXT record is a one-time verification token and is separate from any SPF or DKIM TXT records. Once Microsoft 365 detects the record, the domain status changes to 'Verified' and you can proceed with configuring services and creating users.

Why this answer

To verify ownership of a custom domain in Microsoft 365, you must prove you control the domain's DNS zone. Microsoft provides a unique TXT record value that you add to the public DNS zone of contoso.com. Once the TXT record propagates, Microsoft queries it and confirms ownership, allowing you to proceed with domain configuration.

Exam trap

The trap here is that candidates may confuse the order of operations, thinking they can set the domain as default or create users first, but Microsoft 365 strictly requires domain ownership verification before any domain-based configuration can proceed.

How to eliminate wrong answers

Option A is wrong because delegating the entire contoso.com zone to Microsoft 365 DNS servers is not the first step; delegation is optional and only performed after domain verification if you want Microsoft to manage your DNS records. Option B is wrong because you cannot create user accounts with a custom domain before the domain is verified; Microsoft 365 will reject the domain until ownership is proven. Option D is wrong because setting contoso.com as the default domain requires the domain to already be verified; attempting to set it before verification will fail.

638
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that alerts when a user downloads more than 10 files from SharePoint Online within 10 minutes. This activity should be considered anomalous. Which type of policy should you create?

A.Cloud Discovery policy
B.Activity policy
C.Session policy
D.App discovery policy
AnswerB

Activity policies in Microsoft Defender for Cloud Apps evaluate user activity against thresholds and anomaly detection, so a rule triggering when more than ten SharePoint Online downloads occur within ten minutes matches this policy type.

Why this answer

An Activity policy in Defender for Cloud Apps triggers alerts based on user activities such as file downloads, and supports thresholds and time windows. To alert when a user downloads more than 10 files from SharePoint Online within 10 minutes, you configure an Activity policy with the 'Download file' activity, a threshold of 10, and a 10-minute window. This matches the requirement exactly.

Exam trap

MS-102 often tests whether candidates confuse Activity policies (threshold-based alerts on user actions) with Session policies (real-time access control) or Cloud Discovery policies (shadow IT visibility).

How to eliminate wrong answers

Option A is wrong because a Cloud Discovery policy governs shadow IT discovery from traffic logs, not user activity thresholds. Option C is wrong because a Session policy controls real-time session actions (block, protect, proxy) via Conditional Access App Control, not alerting on download counts. Option D is wrong because App discovery policy is another name for Cloud Discovery, focused on identifying unsanctioned apps.

639
MCQmedium

An administrator runs the Azure CLI command shown in the exhibit. What is the result of this command?

A.A new application registration is created with requested permissions to Graph
B.An existing application registration is updated
C.The application is configured with single-tenant sign-in audience
D.An admin consent is granted for the Microsoft Graph permissions
AnswerA

The Azure CLI command uses the `az ad app create` verb, which always creates a brand-new application registration object in the directory rather than touching an existing one. The `--required-resource-accesses` parameter supplies the Microsoft Graph permissions the new app needs, so the operation registers the app and declares its required scopes in one step. This is purely a creation action, and the requested permissions are merely declared, not approved.

Why this answer

The Azure CLI command `az ad app create --display-name 'MyApp' --required-resource-accesses '[{"resourceAppId":"00000003-0000-0000-c000-000000000000","resourceAccess":[{"id":"e1fe6dd8-ba31-4d61-89e7-88639da4923c","type":"Scope"}]}]'` creates a new application registration in Microsoft Entra ID. The `--required-resource-accesses` parameter specifies the Microsoft Graph (resourceAppId `00000003-0000-0000-c000-000000000000`) and the permission with ID `e1fe6dd8-ba31-4d61-89e7-88639da4923c` (which corresponds to the `User.Read` delegated permission). This registers the app with requested permissions to Microsoft Graph, but does not grant admin consent or configure sign-in audience.

Exam trap

The trap here is that candidates confuse requesting permissions (which happens during app registration) with granting admin consent (a separate administrative action), leading them to incorrectly select Option D.

How to eliminate wrong answers

Option B is wrong because the `az ad app create` command always creates a new application registration; it does not update an existing one (use `az ad app update` for updates). Option C is wrong because the command does not include any parameter to set the sign-in audience (e.g., `--sign-in-audience`); by default, the audience is set to `AzureADMyOrg` (single-tenant), but the command itself does not configure it—the default applies. Option D is wrong because the command only requests permissions; admin consent requires a separate step, such as using `az ad app permission admin-consent` or the Microsoft Entra admin center.

640
MCQeasy

A company wants to prevent their Microsoft 365 tenant from allowing external users to be invited by default. Only specific administrators should be able to invite guests. Which setting should be changed?

A.External Identities – External collaboration settings
B.Conditional Access policy to block external users
C.Tenant restrictions
D.B2B direct connect
AnswerA

In Entra ID (Azure AD), navigate to External Identities > External collaboration settings and change the Guest invite settings to 'Only users assigned to specific admin roles can invite guests' (or 'No one can invite guests'). This is the administrative toggle that directly restricts who can issue B2B invitations, so it is the correct control to prevent the tenant from broadcasting external-user invitation privileges.

Why this answer

The correct setting is under External Identities – External collaboration settings, specifically the 'Guest invite settings' option. By default, this is set to 'Anyone in the organization can invite guest users including guests and non-admins'. Changing it to 'Only users assigned to specific admin roles can invite guest users' restricts guest invitations to designated administrators, meeting the requirement to prevent default external user invitations.

Exam trap

The trap here is that candidates often confuse 'blocking external users' via Conditional Access (Option B) with controlling the invitation process, but Conditional Access only applies after the user is already in the directory, not to the invitation permission itself.

How to eliminate wrong answers

Option B is wrong because Conditional Access policies control access conditions (like location or device compliance) after a user is already in the tenant, not the ability to invite external users. Option C is wrong because Tenant restrictions control inbound/outbound access to external tenants via HTTP headers, not the invitation process within the same tenant. Option D is wrong because B2B direct connect is a feature for Teams Connect shared channels that allows external users to access resources without being invited as guests; it does not control guest invitation settings.

641
Drag & Dropmedium

Drag and drop the steps to configure Data Loss Prevention (DLP) policies in Microsoft Purview in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

DLP policies are created in Purview, conditions and actions defined, and then deployed after testing.

642
Multi-Selecthard

You are a security administrator for Fabrikam, Inc. The company uses Microsoft Defender XDR with Microsoft Defender for Identity, Microsoft Defender for Endpoint, and Microsoft Defender for Cloud Apps onboarded. An analyst is investigating a suspected pass-the-hash attack against a domain controller. The analyst needs to correlate identity signals with device and cloud app activity in the unified incident. You must identify which Defender XDR capabilities the analyst can use to pivot from an identity alert to related device and cloud activity. (Choose two.)

Select 2 answers
A.Run Advanced Hunting queries against the IdentityLogonEvents and DeviceLogonEvents tables in the Microsoft 365 Defender portal.
B.Use the incident graph in the Microsoft 365 Defender portal to expand the alert and view related entities such as accounts, devices, and IP addresses.
C.Use the Microsoft Defender for Endpoint device timeline to review process creation events on the targeted domain controller.
D.Use the Microsoft Defender for Cloud Apps activity log to review file downloads from sanctioned cloud applications.
E.Use the Microsoft Defender for Identity health alerts page to review sensor configuration issues on the domain controllers.
AnswersA, B

Advanced Hunting exposes Kusto tables from all onboarded Defender workloads, including IdentityLogonEvents for Defender for Identity and DeviceLogonEvents for Defender for Endpoint. Joining these tables allows the analyst to correlate identity logon anomalies with device logon activity and identify lateral movement associated with a pass-the-hash attack.

Why this answer

Cross-domain correlation in Microsoft Defender XDR is achieved through the unified incident graph and through Advanced Hunting across the Kusto tables exposed by each onboarded workload. The graph links accounts, devices, IP addresses, and cloud apps, while Advanced Hunting allows joining IdentityLogonEvents with DeviceLogonEvents to trace pass-the-hash lateral movement. Health alerts, cloud app activity logs, and device timelines each cover only one domain.

Exam trap

The trap here is treating single-workload consoles or health pages as if they provide unified cross-domain correlation, when only the incident graph and Advanced Hunting span all onboarded workloads.

643
MCQmedium

A compliance officer needs to prevent users from sending emails that contain sensitive information, such as social security numbers, to external recipients. If a user attempts to send such an email, the action should be blocked and a policy tip should be displayed to the user. Which Microsoft Purview solution should the officer configure?

A.Data Loss Prevention (DLP) policy
B.sensitivity label with encryption
C.Information Rights Management (IRM)
D.retention label with deletion
AnswerA

A DLP policy in Microsoft Purview integrates with Exchange Online to inspect email content in transit and at the client. It uses sensitive information types (e.g., U.S. Social Security Number) as conditions and can apply an action to 'Block the message' from being sent, optionally allowing the sender to override with a business justification. At the same time, policy tips are displayed in Outlook, Outlook on the web, and Mail for iOS/Android during composition, providing real-time guidance before the message leaves the client. This is the only option that actually prevents the email from being sent and educates the sender.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft Purview is designed to inspect email content for sensitive information (e.g., social security numbers) and can block the message while displaying a policy tip to the user. This matches the requirement exactly, as DLP policies enforce actions on data in transit (email) with user notifications.

Exam trap

The trap here is that candidates confuse sensitivity labels (which protect data at rest) with DLP (which protects data in motion), leading them to choose Option B because they think encryption prevents sending, but encryption does not block the email or show a policy tip at the point of sending.

How to eliminate wrong answers

Option B (sensitivity label with encryption) is wrong because sensitivity labels primarily classify and protect data at rest (e.g., files in SharePoint) and can apply encryption, but they do not natively block outbound email in real-time or display policy tips during send. Option C (Information Rights Management) is wrong because IRM protects content after delivery by restricting actions like forwarding or printing, but it does not inspect or block emails before they are sent based on sensitive data patterns. Option D (retention label with deletion) is wrong because retention labels manage data lifecycle (e.g., how long to keep or when to delete) and have no capability to scan outbound email content or block transmission.

644
Multi-Selecthard

A Microsoft Purview auto-labeling policy for sensitivity labels is matching too many SharePoint documents after simulation. Which two changes would most directly reduce false positives before enabling automatic labeling? (Choose two.)

Select 2 answers
A.Increase the confidence level or instance-count requirement for the sensitive information type
B.Add supporting keyword or contextual conditions to the auto-labeling rule
C.Turn on automatic labeling immediately and wait for users to report problems
D.Replace the sensitivity label with a retention label
AnswersA, B

Raising the confidence level or instance-count threshold in the sensitive information type (SIT) increases the probability that the detected pattern is a genuine match rather than an isolated or coincidental string. Confidence reflects the match strength of the classification engine, and instance count requires multiple occurrences in the same item, both of which reduce false positives in an auto-labeling policy.

Why this answer

Increasing the confidence level or instance-count requirement for the sensitive information type (SIT) directly reduces false positives by raising the threshold for what qualifies as a match. A higher confidence level means the classification engine requires stronger evidence (e.g., more keywords or a closer proximity to a pattern), while a higher instance count requires the sensitive data to appear multiple times in the document. Both adjustments make the auto-labeling rule more selective, ensuring only documents with a high likelihood of containing the specified sensitive content are labeled.

Exam trap

The trap here is that candidates may think immediate enforcement (Option C) is the fastest way to fix false positives, but Microsoft explicitly recommends using simulation mode to tune rules before enabling automatic labeling, and waiting for user reports is not a valid tuning strategy.

645
MCQhard

Contoso is a multinational company with 50,000 users. They have a Microsoft 365 E5 subscription and use Microsoft Entra ID for identity. They recently deployed Microsoft Copilot for Microsoft 365 to 10,000 users. The security team wants to ensure that Copilot responses do not expose sensitive information. They also need to monitor Copilot usage for unusual activity. The company uses Microsoft Purview Information Protection and Microsoft Defender for Cloud Apps. You need to configure the environment to meet these requirements. Which action should you take?

A.Create a Microsoft Purview DLP policy that includes Copilot as a location.
B.Configure a Conditional Access policy to restrict Copilot to managed devices.
C.Enable session monitoring in Microsoft Defender for Cloud Apps for Copilot.
D.Create sensitivity labels and auto-labeling policies for Copilot.
AnswerA

Correct: A Microsoft Purview DLP policy that includes Copilot as a location is the right control because it directly inspects both the prompts users enter and the responses Copilot generates for sensitive content—such as credit card numbers, health records, or confidential intellectual property. When matched, the policy can block the interaction or apply a restrictive action, preventing sensitive data from being exposed through AI conversations. This is the only option that combines content inspection with enforcement specifically for Copilot data flows.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies can include Microsoft Copilot for Microsoft 365 as a location, allowing the security team to detect and prevent sensitive information from being exposed in Copilot responses. This directly addresses the requirement to ensure Copilot responses do not expose sensitive data by scanning and blocking content based on sensitivity labels or sensitive info types.

Exam trap

The trap here is that candidates often confuse monitoring (Defender for Cloud Apps session monitoring) with prevention (DLP), or assume that sensitivity labels alone can block sensitive data in Copilot responses without a DLP policy explicitly targeting Copilot as a location.

How to eliminate wrong answers

Option B is wrong because Conditional Access policies restrict access based on device compliance or location, but they do not prevent sensitive information from appearing in Copilot responses; they only control who can access Copilot, not what data is exposed. Option C is wrong because session monitoring in Microsoft Defender for Cloud Apps provides visibility into user sessions and can detect anomalous behavior, but it does not proactively block sensitive data in Copilot responses; it is more about monitoring usage for unusual activity, which is a separate requirement. Option D is wrong because creating sensitivity labels and auto-labeling policies for Copilot helps classify and protect data, but without a DLP policy that includes Copilot as a location, the labels alone do not enforce blocking or warning actions when sensitive data is shared via Copilot responses.

646
MCQeasy

You need to configure self-service password reset (SSPR) for users in Microsoft Entra ID. Which license is required?

A.Microsoft 365 F3
B.Microsoft 365 E3
C.Microsoft Entra ID P1
D.Microsoft Entra ID Free
AnswerC

Correct. Microsoft Entra ID P1 is the specific license that provides SSPR functionality.

Why this answer

Self-service password reset (SSPR) requires a Microsoft Entra ID P1 or P2 license. Both Microsoft 365 F3 and Microsoft 365 E3 include Microsoft Entra ID P1 licenses, which support SSPR. However, the question directly asks which license is required for SSPR, and the correct answer is the standalone Microsoft Entra ID P1 license.

While F3 and E3 include this license, they are suite licenses and not the specific license component being asked for.

Exam trap

The trap is that candidates may incorrectly assume Microsoft 365 E3 and F3 only include Entra ID Free, but in fact they include Entra ID P1, which supports SSPR. This can lead candidates to dismiss these options, but the correct answer is still the specific Entra ID P1 license.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 F3 includes only Azure AD Free, which does not support SSPR. Option B is wrong because Microsoft 365 E3 also includes only Azure AD Free, lacking the premium SSPR capability. Option D is wrong because Microsoft Entra ID Free explicitly excludes SSPR; SSPR requires at least a P1 license.

647
MCQmedium

A company adds and verifies the custom domain 'contoso.com' in their Microsoft 365 tenant. However, emails sent to new users at user@contoso.com bounce back. The existing MX record for contoso.com points to the on-premises mail server. What is the most likely cause of the bounce?

A.The domain verification failed and needs to be repeated
B.The MX record must be updated to point to Exchange Online
C.Users must be added to the domain in the admin center
D.The SPF record is missing or misconfigured
AnswerB

The MX record is the DNS instruction that tells sending mail servers where to deliver messages for your domain. When you add a verified custom domain to Microsoft 365, you must change this record from your previous email provider to the Exchange Online endpoint (for example, contoso-com.mail.protection.outlook.com). If you leave the old MX value in place, inbound mail continues to route to the legacy mail server, which has no mailbox for the recipient, causing the bounce. Correcting the MX record is the precise fix for bounced incoming mail after domain provisioning.

Why this answer

B is correct because the MX record for contoso.com still points to the on-premises mail server. When a user is created in Exchange Online with the domain contoso.com, inbound email is routed according to the MX record. Since the MX record directs mail to the on-premises server, which does not have a mailbox for the new user, the message bounces.

To deliver mail to Exchange Online, the MX record must be updated to point to Exchange Online (e.g., contoso-com.mail.protection.outlook.com).

Exam trap

The trap here is that candidates often confuse domain verification (a one-time DNS check) with ongoing mail routing (MX record), leading them to think verification failure is the cause, when in fact the MX record is the direct culprit.

How to eliminate wrong answers

Option A is wrong because domain verification is a one-time DNS TXT record check; once verified, it remains valid and does not cause email bounces for new users. Option C is wrong because users are already added to the domain in the admin center (the question states 'adds and verifies the custom domain'), and adding users does not affect mail routing. Option D is wrong because a missing or misconfigured SPF record can cause email to be rejected or marked as spam, but it does not cause a bounce due to the MX record pointing to the wrong server; the immediate cause is the MX record destination.

648
MCQhard

You are a security administrator for a large enterprise with 10,000 users. The company uses Microsoft 365 E5 licenses, which include Microsoft Defender XDR. The company has recently experienced a series of ransomware attacks where attackers gained initial access through phishing emails, then moved laterally using compromised credentials, and finally deployed ransomware on file servers. The CISO wants to implement a comprehensive defense strategy that reduces the attack surface and automates response. The requirements are: 1) Prevent phishing emails from reaching users, especially those targeting executives. 2) Detect and block lateral movement using compromised credentials. 3) Automatically contain compromised devices during an incident. 4) Provide a unified incident view across email, endpoints, and identities. You need to recommend a solution that meets all requirements with minimal manual effort. What should you do?

A.Configure Microsoft Defender XDR by enabling Defender for Office 365 with anti-phish and impersonation protection, Defender for Identity, and Defender for Endpoint with automated investigation and response.
B.Use Microsoft Purview to classify and protect sensitive data, and configure data loss prevention policies to block ransomware.
C.Deploy Microsoft Sentinel and create analytics rules to detect phishing, lateral movement, and ransomware. Configure automated playbooks to contain devices.
D.Upgrade to Microsoft Entra ID P2 and enable Identity Protection for risky sign-ins and user risk. Use Conditional Access to block access from compromised devices.
AnswerA

This is the correct approach because Microsoft Defender XDR unifies email, identity, and endpoint signals into a single incident pipeline. Defender for Office 365's anti-phishing and impersonation protection blocks malicious messages at the transport layer, Defender for Identity detects Kerberoasting, pass-the-hash, and other lateral movement techniques using Active Directory signals, and Defender for Endpoint's automated investigation and response can isolate endpoints and remediate ransomware artifacts. Correlating these alerts in the XDR incident view lets you see the full attack chain and contain it before broad encryption occurs.

Why this answer

Option A is correct because it leverages the native Microsoft Defender XDR suite, which directly addresses all four requirements: Defender for Office 365 with anti-phish and impersonation protection prevents phishing emails (requirement 1); Defender for Identity detects lateral movement using compromised credentials by monitoring on-premises Active Directory signals (requirement 2); Defender for Endpoint with automated investigation and response automatically contains compromised devices (requirement 3); and the integrated Defender XDR portal provides a unified incident view across email, endpoints, and identities (requirement 4). This solution requires minimal manual effort because the components are natively integrated and automation is built-in.

Exam trap

MS-102 often tests the misconception that Microsoft Sentinel or Purview alone can provide comprehensive XDR capabilities, when in fact Defender XDR is the integrated solution that natively meets prevention, detection, and automated response requirements with minimal manual effort.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview focuses on data classification, protection, and DLP, which are reactive data-centric controls and do not prevent phishing emails, detect lateral movement, or automatically contain devices. Option C is wrong because Microsoft Sentinel is a SIEM/SOAR solution that requires custom analytics rules and playbooks, which demands significant manual configuration and tuning, and it does not natively provide the integrated prevention and automated containment across email, endpoints, and identities that Defender XDR offers out-of-the-box. Option D is wrong because Entra ID P2 and Identity Protection only address identity risks (risky sign-ins and users) and Conditional Access can block access but does not prevent phishing emails, detect lateral movement on-premises, or automatically contain compromised devices.

649
Multi-Selectmedium

You are a security administrator for a company that uses Microsoft Defender XDR. You need to configure alert policies to notify the security team when specific activities occur. You want to receive notifications for alerts related to malicious file detection and suspicious sign-in attempts. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Set up a Microsoft Sentinel playbook.
B.Create a data loss prevention (DLP) policy.
C.Configure email notifications for the alert policy.
D.Create an alert policy in Microsoft 365 Defender with the appropriate detection sources.
E.Enable audit logging in Microsoft Purview compliance portal.
AnswersC, D

Configuring email notifications for the alert policy ensures that the security team is notified when the specified alerts are triggered. This step is essential to actually receive the notifications for malicious file detection and suspicious sign-in attempts, as the policy alone does not send emails.

Why this answer

To receive notifications for specific alerts in Microsoft Defender XDR, you must create an alert policy that includes the relevant detection sources and then configure email notifications for that policy. These two actions together ensure the security team is alerted about malicious files and suspicious sign-ins.

Exam trap

The trap here is thinking that enabling audit logging or creating DLP policies will generate the required alerts, when they serve different purposes.

650
MCQmedium

Refer to the exhibit. What is the effect of this session policy?

A.Allows viewing but blocks downloading files on managed devices
B.Blocks all access to SharePoint and OneDrive from unmanaged native clients only
C.Blocks upload of files to SharePoint Online and OneDrive from unmanaged devices
D.Blocks download of files from SharePoint Online and OneDrive on unmanaged devices
AnswerD

This session policy is configured for SharePoint Online and OneDrive to block the download action when access comes from an unmanaged device. It allows other actions like viewing, editing, and uploading, so user productivity is maintained while sensitive files cannot be saved locally on non-compliant devices. The restriction is enforced across both browser and native client access methods.

Why this answer

The session policy shown in the exhibit is configured to block downloads from SharePoint Online and OneDrive for unmanaged devices. This is achieved by applying a conditional access policy that targets unmanaged devices and restricts the download action specifically, while still allowing view-only access. The correct answer is D because the policy explicitly blocks the download of files, not uploads or all access.

Exam trap

The trap here is that candidates often confuse 'block downloads' with 'block all access' or 'block uploads,' leading them to select options B or C instead of recognizing that the policy specifically targets the download action only.

How to eliminate wrong answers

Option A is wrong because the policy blocks downloads on unmanaged devices, not managed devices; managed devices are typically allowed full access. Option B is wrong because the policy does not block all access to SharePoint and OneDrive; it only blocks downloads, and it applies to unmanaged devices, not just native clients. Option C is wrong because the policy blocks downloads, not uploads; uploads are still permitted on unmanaged devices.

651
Multi-Selecteasy

Which TWO tools can be used to manage Microsoft 365 tenant settings and configurations?

Select 2 answers
A.Microsoft 365 admin center
B.Exchange admin center (EAC)
C.SharePoint admin center
D.Microsoft 365 PowerShell
E.Microsoft Intune admin center
AnswersA, D

The Microsoft 365 admin center is the primary web-based portal for tenant-wide administration. It provides centralized access to user and group management, license assignment, billing, service health, and security settings. As the main entry point for global admins, it can also delegate to specialized consoles for individual workloads, making it a correct answer for managing the tenant as a whole.

Why this answer

The Microsoft 365 admin center is the primary web-based portal for managing tenant-wide settings such as user licensing, domain management, service health, and security policies. It provides a unified dashboard for configuring core tenant configurations without requiring role-specific consoles.

Exam trap

The trap here is that candidates often confuse role-specific admin centers (like EAC or SharePoint admin center) with the tenant-wide Microsoft 365 admin center, assuming any admin center can manage all tenant settings, whereas each is scoped to its own service.

652
MCQeasy

Your organization uses Microsoft Defender XDR. You need to configure automatic attack disruption for SaaS applications. Which Microsoft 365 security solution provides this capability?

A.Microsoft Defender for Identity
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Office 365
D.Microsoft Defender for Endpoint
AnswerB

Microsoft Defender for Cloud Apps delivers automatic attack disruption for SaaS apps by correlating signals from Microsoft Entra ID and Defender XDR to identify compromised sessions or malicious OAuth apps, then containing the threat mid-attack. This satisfies the stem's requirement for a Microsoft 365 security solution providing SaaS-specific disruption.

Why this answer

Microsoft Defender for Cloud Apps (Option B) provides automatic attack disruption for SaaS applications by using risk indicators and automation to stop attacks in real time. Option A (Microsoft Defender for Identity) focuses on on-premises Active Directory and identity threats, not SaaS apps. Option C (Microsoft Defender for Office 365) protects email and collaboration tools.

Option D (Microsoft Defender for Endpoint) secures endpoints like desktops and servers. Therefore, only option B delivers the required capability.

Exam trap

Candidates often confuse Microsoft Defender for Cloud Apps with other Defender products. Remember that automatic attack disruption for SaaS is unique to Defender for Cloud Apps.

653
Multi-Selecthard

You are configuring Microsoft Defender for Identity. Which THREE capabilities does it provide?

Select 3 answers
A.Scanning of email attachments for malware.
B.Detection of compromised accounts through behavioral analytics.
C.Detection of reconnaissance activities such as LDAP enumeration.
D.Creation of data loss prevention (DLP) policies.
E.Detection of lateral movement between domain-joined machines.
AnswersB, C, E

Detection of compromised accounts through behavioral analytics is a core Defender for Identity feature. It establishes baselines for users and machines, then uses machine learning to flag anomalies such as impossible travel, unusual logon hours, or abnormal service usage. Once an account's behavior deviates from its profile, the sensor raises an alert, enabling investigation and remediation of the compromise.

Why this answer

Options B, C, and E are correct because Microsoft Defender for Identity provides detection of compromised accounts through behavioral analytics (B), detection of reconnaissance activities such as LDAP enumeration (C), and detection of lateral movement between domain-joined machines (E). Option A is incorrect because scanning email attachments for malware is a feature of Microsoft Defender for Office 365, not Defender for Identity. Option D is incorrect because creation of data loss prevention (DLP) policies is a feature of Microsoft Purview, not Defender for Identity.

654
Multi-Selecteasy

Which TWO features are part of Microsoft Purview Communication Compliance?

Select 2 answers
A.Restricting communication between specific groups.
B.Applying retention labels to communications.
C.Policy tips to notify users of policy violations.
D.Detection of inappropriate or offensive language in emails.
E.Automatic encryption of sensitive communications.
AnswersC, D

Policy tips are a native Communication Compliance capability, surfacing real-time notifications to users within Outlook and Teams when their messages match a configured policy. This directly satisfies the stem's requirement for a feature belonging to Communication Compliance, distinguishing it from unrelated Microsoft Purview solutions such as Data Loss Prevention or Insider Risk Management.

Why this answer

Option C is correct because Communication Compliance policies can display policy tips to users in supported clients (for example, Outlook and Teams) to warn them in real time when their message may violate an organizational policy, helping deter risky communications. Option D is correct because Communication Compliance uses trainable classifiers and built-in sensitive information types to detect inappropriate or offensive language, harassment, threats, and other policy-violating content in emails and other communications. Option A is not a Communication Compliance feature; restricting communication between specific groups is handled by Exchange transport rules or information barriers.

Option B is not part of Communication Compliance; retention labels are applied through Microsoft Purview Data Lifecycle Management and Records Management. Option E is not part of Communication Compliance; automatic encryption of sensitive communications is provided by sensitivity labels with encryption or Exchange data loss prevention/transport rules.

655
Multi-Selecteasy

Your company uses Microsoft Entra ID for identity management. You are planning to implement Conditional Access policies. Which TWO components are required to create a Conditional Access policy?

Select 2 answers
A.MFA registration status
B.Identity Protection risk policies
C.Azure AD roles
D.Assignments (users, groups, cloud apps, conditions)
E.Access controls (grant or block, session controls)
AnswersD, E

Assignments constitute the first mandatory component of a Conditional Access policy and define the target scope. They include Users, Groups, Cloud apps or actions, and Conditions such as device state, location, client app, and sign-in risk. This section determines who and what the policy applies to, and without it the policy would have no subject to evaluate.

Why this answer

A Conditional Access policy in Microsoft Entra ID requires two core components: Assignments and Access controls. Assignments define the scope of the policy by specifying users, groups, cloud apps, and conditions (e.g., location, device state). Access controls determine the enforcement action, such as granting access (optionally requiring MFA or compliant device) or blocking access, along with session controls like app-enforced restrictions.

Without both components, the policy cannot be created.

Exam trap

The trap here is that candidates confuse optional conditions or integrated features (like MFA registration status or Identity Protection risk) with the mandatory structural components of Assignments and Access controls, leading them to select distractors that are valid policy elements but not required for creation.

656
Matchingmedium

Match each Microsoft 365 networking port to its protocol.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

HTTPS

SMTP

SMTP (submission)

IMAP

IMAP over SSL

Why these pairings

Common Microsoft 365 networking ports: 443 (HTTPS), 587 (SMTP submission), 993 (IMAP SSL), 995 (POP3 SSL). Be careful not to confuse port numbers with different protocols.

657
MCQeasy

A company has recently signed up for Microsoft 365 Business Premium. They want to change the default domain from onmicrosoft.com to a custom domain they own. Which step must be completed first before the custom domain can be used for user email addresses?

A.Add the custom domain in the Microsoft 365 admin center
B.Verify domain ownership by adding a TXT record to the domain's DNS
C.Create user accounts with the new domain as their primary email
D.Configure email exchange records (MX)
AnswerA

Adding the custom domain in the Microsoft 365 admin center is the mandatory first step to associate your existing DNS namespace with your tenant. From Domains > Add domain, you enter the domain name, which triggers Microsoft's verification wizard and generates the exact DNS records you must publish. Until this addition is completed, no downstream tasks like verification or user provisioning can begin.

Why this answer

Before a custom domain can be used for user email addresses in Microsoft 365, the domain must first be added to the tenant in the Microsoft 365 admin center. This step creates a domain object in Azure AD that allows Microsoft to associate the domain with your tenant and prepare for ownership verification. Without adding the domain first, subsequent steps like DNS verification or user creation cannot proceed because the system has no record of the domain.

Exam trap

The trap here is that candidates often confuse the order of operations, assuming DNS verification (Option B) is the first step, but Microsoft 365 requires the domain to be added to the tenant as a prerequisite before any DNS records can be validated.

How to eliminate wrong answers

Option B is wrong because verifying domain ownership by adding a TXT record is a required step, but it must occur after the domain is added in the admin center; you cannot verify a domain that hasn't been registered in the tenant. Option C is wrong because creating user accounts with the new domain as their primary email is a later step that requires the domain to be both added and verified first. Option D is wrong because configuring MX records is part of the final DNS configuration for mail routing, which depends on the domain being verified and the tenant ready to accept mail.

658
MCQmedium

You are investigating a phishing campaign targeting your organization. In Microsoft Defender XDR, you run a KQL query in Advanced Hunting to find all email messages that contain a specific phishing URL. Which table should you query?

A.EmailUrlInfo
B.EmailAttachmentInfo
C.UrlClickEvents
D.EmailEvents
AnswerA

In Advanced hunting, EmailUrlInfo is the table that stores URL entities extracted from email messages, with each record tied to a specific email via NetworkMessageId. When investigating a phishing campaign, you use this table to search for messages containing a malicious URL or to pivot from a known email to all its embedded links. It also includes the URL's disposition (e.g., Phish) from Microsoft's threat reputation systems, making it the correct source for email-level URL information.

Why this answer

The EmailUrlInfo table in Advanced Hunting stores URL information extracted from email messages, including the specific URLs found in the body or attachments. To find all email messages containing a specific phishing URL, you must query this table because it directly maps URLs to their associated email identifiers (e.g., NetworkMessageId).

Exam trap

The trap here is that candidates confuse UrlClickEvents (which tracks user interaction after delivery) with EmailUrlInfo (which captures URL presence in the email itself), leading them to choose the wrong table for identifying messages containing a URL.

How to eliminate wrong answers

Option B is wrong because EmailAttachmentInfo stores metadata about email attachments (e.g., file names, hashes) but does not contain URL data. Option C is wrong because UrlClickEvents logs user clicks on URLs in emails or documents, not the presence of URLs in the email itself. Option D is wrong because EmailEvents contains high-level email delivery and flow data (e.g., sender, recipient, delivery status) but does not include the actual URL content.

659
MCQmedium

Your organization uses Microsoft Entra Conditional Access. You need to block access from countries where your company does not operate. The list of blocked countries changes frequently. What is the most efficient way to manage this?

A.Enable Microsoft Entra multifactor authentication for all users from blocked countries
B.Create a Conditional Access policy that blocks all locations except the allowed countries
C.Use IP ranges in Conditional Access to block specific country IPs
D.Create Named Locations for blocked countries and use them in Conditional Access
AnswerD

Named Locations let you define country-based restrictions once and reference them across Conditional Access policies, so frequent updates to the blocked-country list require editing only the location definition rather than every policy. This directly satisfies the stem's changing-list constraint, avoiding repeated policy reconfiguration as countries are added or removed.

Why this answer

Named Locations in Microsoft Entra Conditional Access allow you to define countries by IP ranges and then use those locations in a policy to block access. This is the most efficient approach because you can update the list of blocked countries in the Named Locations configuration without modifying the Conditional Access policy itself, which is ideal when the list changes frequently.

Exam trap

The trap here is that candidates often think using IP ranges directly in the policy (Option C) is more precise, but they overlook the administrative overhead of maintaining those ranges manually, whereas Named Locations with country selection provide a simpler and more scalable solution for frequently changing country lists.

How to eliminate wrong answers

Option A is wrong because enabling MFA for users from blocked countries does not block access; it only adds an authentication challenge, which is not a block action and does not meet the requirement to prevent access. Option B is wrong because creating a policy that blocks all locations except allowed countries is inefficient when the list of blocked countries changes frequently, as you would need to constantly update the allowed list, and it is easier to manage a list of blocked countries directly. Option C is wrong because using IP ranges in Conditional Access to block specific country IPs is impractical and inefficient; you would need to manually gather and maintain a list of all IP ranges for each blocked country, which is error-prone and does not leverage the built-in country-based location detection that Named Locations provide.

660
Multi-Selecthard

A company wants to enable self-service password reset (SSPR) for all users. Which two configurations are mandatory to allow users to reset their own passwords? (Choose two.)

Select 2 answers
A.A: Enable SSPR for 'All' users.
B.B: Select at least one authentication method (e.g., mobile phone or email).
C.C: Configure a custom helpdesk URL.
D.D: Enforce registration after 30 days.
AnswersA, B

SSPR must be explicitly enabled and scoped in the Microsoft Entra admin center before any user can attempt a password reset. Setting the scope to 'All' guarantees that every user in the directory, regardless of group membership, is eligible for self-service resets; selecting 'None' or a specific group would disable the feature for all or limit it to only those users. Until this toggle is turned on, all other SSPR configuration settings—including authentication methods and registration policies—are effectively dormant and cannot validate or issue password resets.

Why this answer

Enabling SSPR for 'All' users is a mandatory configuration that ensures every user in the tenant is licensed and permitted to use self-service password reset. Without this setting, SSPR would not be activated for the intended user population, even if authentication methods are configured.

Exam trap

The trap here is that candidates often confuse optional configurations (like custom helpdesk URL or registration enforcement) with mandatory prerequisites, leading them to select those instead of the required scope and authentication method settings.

661
MCQmedium

A security administrator needs to block outbound network connections from a compromised Windows device to a known malicious IP address. The solution should be configured in Microsoft Defender for Endpoint and must work at the network layer, not relying on a user-installed client. Which feature should the administrator enable?

A.Attack surface reduction (ASR) rules
B.Custom detection rules (advanced hunting)
C.Network protection
D.Web protection (web threat protection)
AnswerC

Network protection in Microsoft Defender for Endpoint works at the network layer and is specifically designed to block outbound connections to malicious domains, IP addresses, and URLs. It intercepts traffic from applications and the OS, inspecting connections against Microsoft's cloud-based threat intelligence feed, and if a match is found, the connection is dropped and a warning is shown to the user. In the context of a compromised Windows device, this provides the necessary automatic blocking of outbound callbacks to attacker-controlled infrastructure. It can also be deployed in block mode or audit mode, and when enabled it leverages the Windows Filtering Platform rather than only DNS-based filtering, so direct IP connections are covered.

Why this answer

Network protection, is correct because it is a Microsoft Defender for Endpoint feature that blocks outbound connections to malicious IP addresses and domains at the network layer, using the Windows Filtering Platform (WFP) to enforce policies without requiring a user-installed client. This ensures the block applies system-wide, even if the device is compromised, as it operates before the TCP/IP stack processes the connection.

Exam trap

The trap here is that candidates often confuse Network protection with Web protection, mistakenly thinking Web protection can block IP-based outbound connections, when in fact Web protection only filters HTTP/HTTPS traffic based on URL reputation and does not operate at the network layer for arbitrary IP addresses.

How to eliminate wrong answers

Option A is wrong because Attack surface reduction (ASR) rules are designed to block specific behaviors (e.g., script execution, Office macro abuse) at the endpoint, not to block outbound network connections to a specific IP address. Option B is wrong because Custom detection rules (advanced hunting) only create alerts based on queries against telemetry data; they do not actively block network traffic. Option D is wrong because Web protection (web threat protection) focuses on blocking malicious URLs and web content based on reputation, not on blocking outbound connections to a known malicious IP address at the network layer.

662
MCQhard

Your organization has a Microsoft 365 E5 subscription and uses Microsoft Entra ID. You are implementing Privileged Identity Management (PIM) to manage access to Azure AD roles. You need to ensure that when a user activates a privileged role, the activation request must be approved by their manager and must include a ticket number. What should you configure?

A.Create an access review for the role
B.Modify the role settings in PIM to require approval and justification with ticket number
C.Configure an access package in Entitlement Management
D.Use Conditional Access policy with session controls
AnswerB

In Privileged Identity Management (PIM), you can modify the role's settings to require approval for activation and mandate that the user supply a justification, which can include the support ticket number before the role becomes active. This enforcement is embedded directly in the activation workflow, so the request is routed to designated approvers and the ticket reference is captured. Because the scenario asks for exactly this type of activation-time control, changing the PIM role settings is the correct solution.

Why this answer

PIM role settings allow you to configure activation requirements, including requiring approval and mandating a justification field. By enabling 'Require approval to activate' and configuring the approver as the user's manager, and by setting 'Require ticket information on activation', you enforce that every activation request includes a ticket number and is routed to the manager for approval.

Exam trap

The trap here is that candidates confuse Entitlement Management access packages (which also support approval workflows) with PIM role settings, but only PIM role settings allow you to require a ticket number and specify the manager as the approver for Azure AD role activation.

How to eliminate wrong answers

Option A is wrong because access reviews are used for periodic recertification of role assignments, not for controlling the activation process itself. Option C is wrong because Entitlement Management access packages manage resource access through catalogs and policies, but they do not enforce manager approval and ticket number requirements for Azure AD role activation—that is a PIM role settings feature. Option D is wrong because Conditional Access policies control authentication and session behavior, not the approval workflow or justification requirements for PIM role activation.

663
MCQmedium

Refer to the exhibit. You run the PowerShell commands shown. The output displays 10 mailboxes with various RecipientTypeDetails, including UserMailbox, SharedMailbox, and RoomMailbox. You need to ensure that only user mailboxes are returned. What should you modify?

A.Use the -Properties parameter to specify additional attributes
B.Change RecipientTypeDetails to RecipientType in the Select-Object
C.Add the parameter -Filter "RecipientTypeDetails -eq 'UserMailbox'"
D.Remove the -ShowProgress parameter
AnswerC

Adding the -Filter parameter with the OData query "RecipientTypeDetails -eq 'UserMailbox'" is the correct approach because it performs server-side filtering on the Get-Recipient cmdlet, returning only objects classified as user mailboxes. RecipientTypeDetails is a filterable property that distinguishes between mailbox types such as UserMailbox, SharedMailbox, RoomMailbox, and EquipmentMailbox. This ensures that the command returns exactly the intended result set, excluding all other recipient types, and is more efficient than pulling all recipients and filtering locally.

Why this answer

The Get-Mailbox cmdlet returns all mailbox types by default. To filter only user mailboxes, you must use the -Filter parameter with the condition 'RecipientTypeDetails -eq 'UserMailbox''. This ensures that only mailboxes with RecipientTypeDetails set to UserMailbox are returned, excluding shared, room, and other mailbox types.

Exam trap

The trap here is that candidates often assume RecipientTypeDetails is a property that can be filtered by simply selecting it in Select-Object, but Select-Object only controls output columns, not which objects are retrieved; filtering must be done at the query level with -Filter.

How to eliminate wrong answers

Option A is wrong because the -Properties parameter is used to specify additional attributes to return in the output, not to filter results; it does not limit which mailboxes are retrieved. Option B is wrong because RecipientType is a broader classification that does not differentiate between user, shared, or room mailboxes; changing to RecipientType would not filter to only user mailboxes. Option D is wrong because the -ShowProgress parameter controls whether progress is displayed during command execution and has no effect on the filtering of mailbox types.

664
MCQhard

Your company is required to retain all emails sent to and from executives for 7 years due to regulatory compliance. You need to implement this with minimal administrative overhead. What should you use?

A.Create a Microsoft Purview retention policy for the executive mailboxes
B.Configure Exchange journaling to export to an external system
C.Place each executive mailbox on Litigation Hold
D.Enable the archive mailbox for each executive
AnswerA

A Microsoft Purview retention policy applies a seven-year retention period to the executives' mailboxes tenant-wide, with no per-item or per-user manual work. This meets the regulatory requirement with minimal administrative overhead compared with litigation holds or labels.

Why this answer

A Microsoft Purview retention policy applied to the executive mailboxes retains all emails for 7 years with minimal administrative overhead. It is a centralized, policy-based solution that does not require per-mailbox configuration or external systems. This meets the regulatory requirement efficiently.

Exam trap

MS-102 often tests the difference between retention policies, retention labels, and Litigation Hold; candidates may incorrectly choose Litigation Hold or journaling when the requirement is a simple retention policy with minimal overhead.

How to eliminate wrong answers

Option B is wrong because Exchange journaling requires an external system to store and manage the journaled emails, increasing administrative overhead and complexity. Option C is wrong because Litigation Hold is designed for legal holds, not for regulatory retention, and it must be applied per mailbox, increasing overhead. Option D is wrong because enabling an archive mailbox only provides additional storage; it does not enforce a 7-year retention period.

665
MCQeasy

You need to implement a solution that allows users to classify documents containing personal data as 'Highly Confidential' and automatically encrypt them when shared via email. What should you configure?

A.A sensitivity label with auto-labeling and encryption.
B.A retention label with a disposition action.
C.An information barrier policy.
D.A DLP policy with an action to block sharing.
AnswerA

Sensitivity labels in Microsoft Purview can be configured to automatically apply encryption when content matches specified conditions, such as credit card numbers or confidential keywords. This auto-labeling can occur at rest or during document creation, and the encryption enforces permissions that protect data both inside and outside the organization. Because the requirement is to classify and encrypt, this is the only option that directly fulfills both actions.

Why this answer

A sensitivity label with auto-labeling and encryption is correct because sensitivity labels in Microsoft Purview Information Protection can be configured to automatically classify documents based on sensitive data types (e.g., personal data) and apply encryption to protect the content when shared via email. The auto-labeling feature uses conditions like pattern matching for personally identifiable information (PII) to assign the 'Highly Confidential' label, and the encryption action ensures the document is protected with Rights Management Services (RMS) policies, preventing unauthorized access even if the email is forwarded.

Exam trap

The trap here is that candidates often confuse DLP policies with sensitivity labels, thinking that DLP's block action achieves the same result as classification and encryption, but DLP only prevents sharing without applying persistent protection or classification metadata.

How to eliminate wrong answers

Option B is wrong because retention labels are designed to manage data lifecycle and retention/disposition actions (e.g., delete or retain), not to classify or encrypt content based on sensitivity or personal data. Option C is wrong because information barrier policies restrict communication and collaboration between specific groups (e.g., preventing HR from chatting with Finance), but they do not classify documents or apply encryption based on content. Option D is wrong because a DLP policy with an action to block sharing can prevent the email from being sent, but it does not automatically classify the document as 'Highly Confidential' or encrypt it; DLP policies typically block or notify, not apply encryption or sensitivity labels.

666
MCQhard

Refer to the exhibit. You are reviewing the service principal for Microsoft Graph in your tenant. The passwordCredentials array is empty. What does this indicate?

A.The service principal is using federated credentials.
B.The service principal uses certificate-based authentication.
C.The Microsoft Graph application is disabled.
D.No client secret is configured for the service principal.
AnswerD

A `passwordCredentials` array with no entries in the service principal means there are no password credential objects, and therefore no client secret is configured for that service principal. Client secrets are created and stored in this property as `passwordCredentials` objects, so an empty array is the expected representation when a secret has never been created, has expired, or has been deliberately removed. Without a client secret, app-only authentication would need another credential such as a certificate or managed identity, but the displayed data directly supports only the no-client-secret conclusion.

Why this answer

The passwordCredentials array being empty indicates that no client secret (password) has been configured for the service principal. Client secrets are one method of authentication for service principals, and their absence means that this particular authentication method is not set up. This does not imply the service principal is disabled or that other authentication methods like certificates or federated credentials are in use.

Exam trap

Microsoft often tests the misconception that an empty passwordCredentials array means the service principal is disabled or that no authentication is possible, when in fact other authentication methods like certificates or federated credentials may still be configured.

How to eliminate wrong answers

Option A is wrong because federated credentials are stored in the federatedIdentityCredentials array, not in passwordCredentials; an empty passwordCredentials array does not indicate federated credentials are being used. Option B is wrong because certificate-based authentication is indicated by the keyCredentials array, not passwordCredentials; an empty passwordCredentials array does not imply certificates are configured. Option C is wrong because the Microsoft Graph application being disabled is a separate property (accountEnabled) and is not indicated by the passwordCredentials array being empty.

667
MCQhard

Your company has a Microsoft 365 E5 subscription and uses Microsoft Entra ID. You have configured Microsoft Entra Identity Governance. You need to create an access review for all guest users in the tenant to ensure their access is still required. The review should be recurring every 90 days and should auto-remove guests if they are not approved. What should you configure?

A.Configure a Conditional Access policy to block guests after 90 days
B.Create an access review for all guest users with a recurrence of 90 days and auto-apply results
C.Configure PIM settings for guest users
D.Create an access package in entitlement management for guest users
AnswerB

Create an access review scoped to 'All guest users' and set the recurrence to 90 days; under 'Results' enable 'Auto apply results to resources' and 'If reviewers don't respond, remove access.' When each review instance completes, the service automatically removes the guest's assignments and, if you also enable the additional setting, can block sign-in and remove the B2B guest object from the directory. This is the identity governance feature designed for certified, recurring recertification of external identities.

Why this answer

Creating an access review for all guest users with a recurrence of 90 days and auto-apply results directly meets the requirement: it reviews guest access every 90 days and automatically removes guests who are not approved. Access reviews in Microsoft Entra ID Governance allow you to scope reviews to guest users, set recurrence, and enable auto-apply to enforce removal without manual intervention.

Exam trap

The trap here is that candidates confuse Conditional Access policies (which block access but do not remove accounts) with access reviews (which can automatically remove guest accounts), or they mistakenly think PIM or access packages can perform tenant-wide recurring guest reviews with auto-removal.

How to eliminate wrong answers

Option A is wrong because a Conditional Access policy controls access conditions (e.g., blocking sign-ins after 90 days) but does not perform recurring reviews or automatically remove guest accounts; it only blocks authentication, leaving the guest object and its assignments intact. Option C is wrong because PIM (Privileged Identity Management) settings manage just-in-time privileged role activation and approval, not recurring access reviews for all guest users or auto-removal of unapproved guests. Option D is wrong because creating an access package in entitlement management manages resource access through requests and approvals, but it does not provide a recurring review cycle with auto-removal for all guest users; access packages are for specific resource catalogs, not tenant-wide guest review.

668
MCQmedium

A security analyst needs to search for devices that have been communicating with a known malicious command-and-control server over the past 7 days. The analyst wants to identify the process that initiated the connection. Which advanced hunting query would be most efficient?

A.DeviceNetworkEvents | where RemoteIP == 'malicious IP' and Timestamp > ago(7d) | project DeviceName, InitiatingProcessFileName, Timestamp
B.DeviceProcessEvents | where ProcessId in (select ProcessId from DeviceNetworkEvents where RemoteIP == 'malicious IP' and Timestamp > ago(7d)) | project DeviceName, ProcessFileName, Timestamp
C.DeviceNetworkEvents | where Timestamp > ago(7d) | join DeviceProcessEvents on ProcessId | where RemoteIP == 'malicious IP' | project DeviceName, ProcessFileName, Timestamp
D.IdentityLogonEvents | where IPAddress == 'malicious IP' | project DeviceName, Timestamp
AnswerA

This is the correct query because DeviceNetworkEvents is the Microsoft 365 Defender table that logs outbound network connections, and it natively includes the InitiatingProcessFileName field. Filtering on RemoteIP and a 7-day Timestamp window directly narrows to the relevant events, then projecting the three required columns gives the answer without any additional joins or subqueries.

Why this answer

DeviceNetworkEvents contains network connection data including the remote IP and the initiating process details. Filtering by RemoteIP and Timestamp directly retrieves the required information without unnecessary joins or subqueries, making it the most efficient query for identifying the process that initiated the connection to a known malicious C2 server.

Exam trap

The trap here is that candidates may choose Option C thinking a join is necessary to get process details, but DeviceNetworkEvents already includes the initiating process name, making the join redundant and inefficient.

How to eliminate wrong answers

Option B is wrong because it uses a subquery on DeviceNetworkEvents to get ProcessIds, but DeviceProcessEvents does not contain network connection data; it focuses on process creation events, so it cannot directly identify processes that initiated network connections. Option C is wrong because it performs a join on ProcessId after filtering by Timestamp, which is inefficient and may return incorrect results if ProcessId is not unique across tables; it also filters RemoteIP after the join, processing more data than necessary. Option D is wrong because IdentityLogonEvents tracks authentication events, not network connections, and IPAddress in this table refers to the logon source IP, not the destination IP of a C2 server.

669
Multi-Selectmedium

A security administrator needs to block unsanctioned cloud apps in real time using a reverse proxy. Which two Microsoft Defender for Cloud Apps components must be configured?

Select 2 answers
A.Cloud Discovery
B.Conditional Access App Control
C.App governance
D.Session control policies
AnswersB, D

Conditional Access App Control is the reverse proxy component of Microsoft Defender for Cloud Apps that, when integrated with Azure AD Conditional Access, intercepts user sessions to cloud apps in real time. It enables granular controls such as blocking access entirely, preventing downloads, or masking sensitive data, making it the correct infrastructure for real-time blocking of unsanctioned cloud apps.

Why this answer

Conditional Access App Control (B) is the reverse proxy component in Microsoft Defender for Cloud Apps that enforces real-time session-level monitoring and control of cloud app access. Session control policies (D) are the specific policy objects that define the actions (e.g., block download, block access) applied through that reverse proxy. Together, they enable blocking unsanctioned cloud apps in real time by intercepting user traffic via the reverse proxy architecture.

Exam trap

The trap here is that candidates confuse Cloud Discovery (which only detects unsanctioned apps via log analysis) with the real-time blocking capability, or they assume App governance provides reverse proxy controls when it actually focuses on OAuth app permissions and lifecycle management.

670
Multi-Selectmedium

Your organization uses Microsoft Defender XDR. You need to configure automatic response actions for a high-severity incident. Which TWO options are available in the Microsoft Defender XDR automated investigation and response capabilities?

Select 2 answers
A.Create a mailbox rule to delete suspicious emails
B.Isolate a device from the network
C.Collect an investigation package from a device
D.Delegate mailbox permissions
E.Reset user passwords
AnswersB, C

Isolating a device from the network is a containment action Microsoft Defender XDR can execute automatically during automated investigation and response. It satisfies the stem's requirement for an available automatic response action, restricting lateral movement without deleting the device.

Why this answer

Option B (Isolate a device from the network) is correct because Microsoft Defender XDR automated investigation and response (AIR) can automatically contain a compromised endpoint by isolating it from the network, blocking most network traffic while preserving the Defender for Endpoint connection for remediation. Option C (Collect an investigation package from a device) is correct because AIR can automatically gather forensic data from an endpoint into an investigation package, which includes running processes, network connections, scheduled tasks, and other artifacts for analyst review. Option A (Create a mailbox rule to delete suspicious emails) is not an AIR response action; mailbox-level remediation in Defender XDR is performed through actions like soft delete, hard delete, or moving messages to Junk/Deleted Items, not by creating custom mailbox rules.

Option D (Delegate mailbox permissions) is an Exchange administrative task unrelated to automated incident response. Option E (Reset user passwords) is not an automated response action provided by Defender XDR AIR; password resets are handled through identity management tools such as Microsoft Entra ID, not as a Defender XDR automated remediation.

Exam trap

MS-102 often tests the specific automated response actions available in Defender XDR, and candidates may incorrectly assume that identity-related actions like password resets are included.

671
Multi-Selectmedium

Administrators want to enforce multi-factor authentication (MFA) for all users when accessing cloud applications from untrusted networks. They plan to use Azure AD Conditional Access with named locations. Which two components must be configured to meet this requirement? (Select two.)

Select 2 answers
A.location policy
B.named location for the corporate network
C.Conditional Access policy targeting all cloud apps
D.Conditional Access policy targeting MFA registration
AnswersB, C

A named location defines the corporate network as a trusted IP range, letting the policy distinguish trusted from untrusted access. Without it, Conditional Access cannot evaluate whether a session originates inside or outside the office, so the MFA condition cannot be scoped correctly.

Why this answer

Option B is correct because a named location must be defined to represent the trusted corporate network, allowing the Conditional Access policy to distinguish trusted from untrusted networks and apply MFA only when users connect from outside that location. Option C is correct because a Conditional Access policy scoped to all cloud apps is required to enforce the MFA requirement across every cloud application users access. Together, the named location and the Conditional Access policy targeting all cloud apps satisfy the scenario's requirement to enforce MFA from untrusted networks.

Option A is not a valid Azure AD component; location-based conditions are configured within a Conditional Access policy using named locations, not as a standalone 'location policy.' Option D is incorrect because a policy targeting MFA registration addresses the registration experience for authentication methods, not the enforcement of MFA when accessing cloud applications.

Exam trap

The trap here is that candidates often confuse 'named location' with 'location policy' (Option A) or mistakenly think that targeting MFA registration (Option D) is sufficient to enforce MFA during access, when in fact registration policies only handle the enrollment flow, not the authentication challenge at sign-in.

672
MCQeasy

After adding a custom domain name to a Microsoft 365 tenant, what is the first step the administrator must complete before users can sign in using the custom domain?

A.Add the domain as an accepted domain in Exchange Online
B.Set the custom domain as the default domain for new users
C.Verify domain ownership by adding a DNS TXT record
D.Create user accounts with usernames ending with the custom domain
AnswerC

The first mandatory step after adding a custom domain is to prove you control it by publishing a DNS TXT record containing the unique token Microsoft provides in the domain setup wizard. Microsoft validates the TXT record at the domain's DNS provider, and until this succeeds, the domain shows 'Not verified' in the Microsoft 365 admin center. Only after this verification can you proceed with configuring the domain for email or user accounts.

Why this answer

Before a custom domain can be used for user sign-ins or email routing in Microsoft 365, the administrator must prove ownership of the domain. This is done by adding a specific DNS TXT record provided by the Microsoft 365 domain setup wizard. Until the TXT record is verified, the domain remains unverified and cannot be used for any Microsoft 365 services.

Exam trap

The trap here is that candidates often confuse the order of operations, thinking they can add the domain to Exchange Online or create users first, but Microsoft 365 strictly enforces domain verification as the prerequisite for all subsequent domain-related configurations.

How to eliminate wrong answers

Option A is wrong because adding the domain as an accepted domain in Exchange Online is a later step that requires the domain to already be verified; you cannot add an unverified domain as an accepted domain. Option B is wrong because setting the custom domain as the default domain for new users also requires the domain to be verified first; the system will not allow an unverified domain to be set as default. Option D is wrong because creating user accounts with usernames ending with the custom domain is only possible after the domain is verified; the Microsoft 365 authentication system will reject unverified domains during user creation.

673
MCQmedium

Your organization has a hybrid identity deployment with Microsoft Entra Connect. You have synchronized all on-premises Active Directory users to Microsoft Entra ID. You need to enable Microsoft Entra ID Password Protection to automatically block weak passwords. You have installed the Password Protection proxy on a server and registered it. You also need to enforce the password protection policy for on-premises users. What additional step is required?

A.Install the Password Protection DC agent on each domain controller.
B.Install the Password Protection proxy on all domain controllers.
C.Enable the password filter in the Microsoft Entra Connect configuration.
D.Configure a Group Policy to require password complexity.
AnswerA

The DC agent is the enforcement engine for Password Protection in a hybrid environment. It must be installed on every domain controller because it hosts the password filter DLL that intercepts and validates password changes against the banned password list. Without it, a password change processed by a DC lacking the agent would bypass the policy entirely, so placing it on each DC is the required configuration.

Why this answer

The Password Protection DC agent is required on each domain controller to intercept and validate password changes against the Microsoft Entra ID Password Protection policy. Without this agent, the proxy server alone cannot enforce the policy for on-premises users, as the DC agent is the component that applies the password filter during password change operations.

Exam trap

The trap here is that candidates often assume the proxy server alone enforces the policy, but the proxy only facilitates communication, while the DC agent is the enforcement point on each domain controller.

How to eliminate wrong answers

Option B is wrong because the Password Protection proxy is not installed on domain controllers; it is installed on a separate server to communicate with Microsoft Entra ID, while the DC agent is installed on domain controllers to enforce the policy. Option C is wrong because Microsoft Entra Connect does not include a password filter for on-premises password protection; the password filter is part of the DC agent, not the Connect configuration. Option D is wrong because configuring a Group Policy for password complexity does not enable Microsoft Entra ID Password Protection; it only enforces local Windows password policies, which are separate from the cloud-based weak password detection.

674
MCQmedium

You are a security administrator. You need to configure a policy that automatically blocks sign-ins from anonymous IP addresses for all users in your Microsoft 365 tenant. Which policy should you configure in Microsoft Entra ID?

A.Password protection policy
B.Conditional Access policy with user risk condition
C.Conditional Access policy with sign-in risk condition
D.Identity Protection user risk policy
AnswerC

A Conditional Access policy with the sign-in risk condition evaluates Microsoft Entra ID Protection signals and blocks sign-ins assessed as risky, including anonymous IP usage. Applying it to all users satisfies the requirement to automatically block anonymous-IP sign-ins tenant-wide.

Why this answer

Anonymous IP address sign-ins are a sign-in risk detection in Microsoft Entra ID Protection. To automatically block them for all users, you configure a Conditional Access policy that targets All users and uses the sign-in risk condition set to High (or the specific 'Anonymous IP address' risk), with the access control set to Block. Sign-in risk evaluates the authentication attempt itself, which is exactly what anonymous IP represents.

Exam trap

MS-102 often tests the distinction between sign-in risk (real-time authentication signals like anonymous IP) and user risk (compromised credential indicators), causing candidates to pick the wrong condition.

How to eliminate wrong answers

Option A is wrong because password protection policies enforce banned password lists and lockout, not sign-in risk blocking. Option B is wrong because user risk condition targets compromised credentials (leaked credentials) rather than the anonymous IP sign-in signal. Option D is wrong because Identity Protection user risk policies remediate compromised accounts via password change, not anonymous IP blocking, and sign-in risk is enforced through Conditional Access.

675
MCQmedium

Your organization uses Microsoft 365 and wants to ensure that only compliant devices can access Exchange Online. You have Microsoft Intune for device management. What should you configure?

A.Configure devices to be Azure AD Joined
B.Create a Conditional Access policy with 'Require device to be marked as compliant'
C.Create an app protection policy in Intune
D.Create a device compliance policy in Intune
AnswerB

A Conditional Access policy requiring device compliance integrates with Microsoft Intune’s compliance policies to block non-compliant devices from Exchange Online access. This satisfies the stem’s requirement that only compliant devices connect, because Intune evaluates device health (e.g., encryption, jailbreak status) and reports the result to Microsoft Entra ID, which enforces the access grant during authentication.

Why this answer

To enforce that only compliant devices can access Exchange Online, you need a Conditional Access policy that includes the 'Require device to be marked as compliant' grant control. This policy evaluates the device compliance status reported by Intune and blocks or grants access accordingly. Without this Conditional Access policy, even compliant devices are not forced to meet compliance requirements before accessing Exchange Online.

Exam trap

The trap here is that candidates often confuse creating a device compliance policy (which only defines rules) with the Conditional Access policy that actually enforces those rules, leading them to select Option D instead of B.

How to eliminate wrong answers

Option A is wrong because Azure AD Join alone does not enforce compliance; it only registers the device in Azure AD, and without a Conditional Access policy, any joined device can access Exchange Online regardless of compliance. Option C is wrong because an app protection policy (MAM) manages data protection at the app level without requiring device enrollment or compliance, and it does not block access from non-compliant devices. Option D is wrong because a device compliance policy defines the compliance rules (e.g., encryption, OS version) but does not enforce access control; it is the Conditional Access policy that uses the compliance status to grant or deny access.

Page 8

Page 9 of 10

Page 10

All pages