Courseiva
← Back to Microsoft 365 Administrator MS-102 questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise Microsoft 365 Administrator MS-102 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
MS-102
exam code
Microsoft
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related MS-102 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

Refer to the exhibit. You are reviewing the service principal for Microsoft Graph in your tenant. The passwordCredentials array is empty. What does this indicate?

Exhibit

Refer to the exhibit.

{
  "appId": "00000003-0000-0000-c000-000000000000",
  "displayName": "Microsoft Graph",
  "passwordCredentials": []
}
Question 2mediummultiple choice
Full question →

The exhibit shows a DLP policy configuration. A user reports that they cannot share a document containing a credit card number from OneDrive for Business. However, the document was shared successfully last week. What is the most likely reason for the change?

Exhibit

Refer to the exhibit.

```json
{
  "policy": {
    "name": "Data Loss Prevention Policy",
    "locations": [
      "ExchangeOnline",
      "SharePointOnline",
      "OneDriveForBusiness",
      "Teams"
    ],
    "rules": [
      {
        "name": "Credit Card Number Rule",
        "condition": {
          "sensitiveInformationTypes": [
            {
              "id": "Credit Card Number",
              "minCount": 1
            }
          ]
        },
        "actions": [
          {
            "type": "BlockAccess",
            "config": {
              "blockMessage": "Access blocked due to DLP policy"
            }
          }
        ]
      }
    ]
  }
}
```
Question 3easymultiple choice
Full question →

Refer to the exhibit. You run this PowerShell command in your Microsoft 365 tenant. What is the purpose of the command?

Exhibit

Refer to the exhibit.
```
Get-MsolUser -All | Where-Object {$_.isLicensed -eq $false} | Select-Object UserPrincipalName
```
Question 4mediummultiple choice
Full question →

The exhibit shows a KQL query used in Microsoft 365 Defender. The query returns no results for admin@contoso.com. What is the most likely reason?

Exhibit

Refer to the exhibit.

```kusto
IdentityInfo
| where UserPrincipalName == "admin@contoso.com"
| project UserPrincipalName, AssignedRoles, LastPasswordChangeDateTime
| where AssignedRoles contains "Global Administrator"
```
Question 5hardmultiple choice
Full question →

Refer to the exhibit. You run the KQL query and see that a device named 'WORKSTATION42' has made 1500 connections to a public IP address 203.0.113.55 in the last day. You suspect the device may be compromised. What should you do next to gain the most context?

Exhibit

{
  "exhibit_text": "You run the following KQL query in Microsoft Defender XDR Advanced Hunting:\n\n`DeviceNetworkEvents`\n`| where Timestamp > ago(1d)`\n`| where ActionType == "ConnectionSuccess"`\n`| where RemoteIPType == "Public"`\n`| summarize Count = count() by DeviceName, RemoteIP`\n`| where Count > 100`\n`| order by Count desc`\n\nThe query returns a list of devices that have made over 100 successful connections to public IPs in the last day. You need to investigate further."
Question 6mediummultiple choice
Full question →

Refer to the exhibit. An administrator runs the KQL query in Microsoft Defender for Endpoint. The result set is empty. What is the most likely reason?

Exhibit

Refer to the exhibit.

```kql
DeviceLogonEvents
| where Timestamp > ago(7d)
| where AccountName == "admin"
| project Timestamp, DeviceName, AccountName, IPAddress
| order by Timestamp desc
```
Question 7hardmultiple choice
Full question →

Refer to the exhibit. The Contoso tenant has a cross-tenant access policy configured for Fabrikam. Users from Fabrikam are unable to access resources in Contoso via B2B collaboration. What is the most likely reason?

Exhibit

Refer to the exhibit.

```powershell
Get-MgPolicyCrossTenantAccessPolicy

Id           : /policies/crossTenantAccessPolicy
DisplayName   : Default policy
DefaultPolicy : Microsoft.Graph.PowerShell.Models.MicrosoftGraphCrossTenantAccessPolicyDefault

(DefaultPolicy properties)
B2BCollaborationInbound : @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BCollaborationOutbound: @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BDirectConnectInbound : @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BDirectConnectOutbound: @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
OfficeSyncInbound        : @{AllowedTenants=}
OfficeSyncOutbound       : @{AllowedTenants=}
IsServiceDefault         : True

Get-MgPolicyCrossTenantAccessPolicyPartner -CrossTenantAccessPolicyId "/policies/crossTenantAccessPolicy"

Id                   : /policies/crossTenantAccessPolicy/partners/contoso.com
TenantId             : contoso.com
B2BCollaborationInbound : @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BCollaborationOutbound: @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BDirectConnectInbound : @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
B2BDirectConnectOutbound: @{AllowedIdentities=; AllowedApplications=; AllowedTenants=}
OfficeSyncInbound        : @{AllowedTenants=}
OfficeSyncOutbound       : @{AllowedTenants=}
IsServiceDefault         : False
AutomaticUserConsentSettings: @{InboundAllowed=; OutboundAllowed=}
```
Question 8hardmultiple choice
Full question →

Your organization uses Microsoft Defender for Endpoint (Plan 2) and Microsoft Defender for Identity. A user reports that their device is running slowly and exhibiting unusual network traffic. You investigate in Microsoft Defender XDR and see a high number of alerts for the device. You need to determine if the device is compromised and, if so, initiate an automated investigation. What should you do first?

Question 9hardmultiple choice
Full question →

Refer to the exhibit. You are reviewing a Conditional Access policy in Microsoft Entra ID. What is the effect of this policy?

Exhibit

Refer to the exhibit.
```json
{
  "conditions": {
    "applications": {
      "includeApplications": ["Office365"]
    },
    "users": {
      "includeUsers": ["All"]
    },
    "platforms": {
      "includePlatforms": ["iOS", "Android"]
    }
  },
  "grantControls": {
    "builtInControls": ["mfa", "compliantDevice"]
  }
}
```
Question 10hardmultiple choice
Full question →

You are reviewing a Conditional Access policy in Microsoft Entra ID. The exhibit shows the policy configuration. You need to allow users to access Office 365 applications from personal devices that are not enrolled in Microsoft Intune. However, the policy currently blocks access because it requires a compliant device. Users are prompted for MFA but then blocked due to device compliance. What should you modify in the policy?

Exhibit

Refer to the exhibit.

```json
{
  "conditions": {
    "applications": {
      "includeApplications": ["Office365"]
    },
    "users": {
      "includeUsers": ["All"]
    },
    "locations": {
      "includeLocations": ["All"]
    }
  },
  "grantControls": {
    "builtInControls": ["mfa", "compliantDevice"]
  },
  "sessionControls": {
    "applicationEnforcedRestrictions": null,
    "cloudAppSecurity": {
      "cloudAppSecurityType": "monitorOnly"
    }
  }
}
```
Question 11mediummultiple choice
Full question →

You run the above PowerShell command on a Windows 10 device that is onboarded to Microsoft Defender for Endpoint. The device is reporting as healthy in the portal, but you suspect that some behavioral detection capabilities are turned off. Based on the output, which setting should you modify?

Exhibit

Refer to the exhibit.

```powershell
Get-MpPreference | Select-Object -Property DisableRealtimeMonitoring, DisableBehaviorMonitoring, DisableBlockAtFirstSeen
```

Output:
```
DisableRealtimeMonitoring : False
DisableBehaviorMonitoring : True
DisableBlockAtFirstSeen : False
```
Question 12easymultiple choice
Full question →

Refer to the exhibit. You deploy this configuration profile to Windows devices. What is the most likely outcome?

Network Topology
Microsoft Defender for Endpoint device configuration profile<!>Refer to the exhibit.```xml<DeviceConfiguration><DefenderForEndpoint><EnableAutomatedInvestigation>true</EnableAutomatedInvestigation><AlertSeverityForAutomatedInvestigation>Medium</AlertSeverityForAutomatedInvestigation><EmailNotification><Enabled>true</Enabled><Recipients>admin@contoso.com</Recipients></EmailNotification></DefenderForEndpoint></DeviceConfiguration>```
Question 13mediummultiple choice
Full question →

You are examining the default cross-tenant access policy for your Microsoft Entra ID tenant. Based on the exhibit, which statement is true?

Exhibit

Refer to the exhibit.

PowerShell Output:
Get-MgPolicyCrossTenantAccessPolicyDefault -Default

Id                                   : default
DisplayName                          : Default policy
IsServiceDefault                     : True
B2BCollaborationInbound              : @{Applications=; UsersAndGroups=; Organizations=}
B2BCollaborationOutbound             : @{Applications=; UsersAndGroups=; Organizations=}
B2BDirectConnectInbound              : @{Applications=; UsersAndGroups=; Organizations=}
B2BDirectConnectOutbound             : @{Applications=; UsersAndGroups=; Organizations=}
InboundTrust                          : @{IsMfaAccepted=$false; IsCompliantDeviceAccepted=$false; IsHybridAzureADJoinedDeviceAccepted=$false}
Question 14mediummultiple choice
Full question →

An administrator runs the Azure CLI command shown in the exhibit. What is the result of this command?

Network Topology
az ad app createdisplay-name "MyApp"sign-in-audience AzureADMultipleOrgskey-type Passwordpassword "P@ssw0rd"required-resource-accesses "[{\"resourceAppId\":\"00000003-0000-0000-c000-000000000000\"Refer to the exhibit.Azure CLI command:
Question 15hardmultiple choice
Full question →

You are reviewing directory settings for Microsoft 365 Groups. Based on the exhibit, which statement is true?

Exhibit

Refer to the exhibit.

PowerShell output:

Get-AzureADDirectorySetting | Select-Object *

Id                                   : 1234-...
DisplayName                          : Group.Unified
TemplateId                           : 62375ab9-...
Values                               : {[EnableGroupCreation, true], [GroupCreationAllowedGroupId, ], [UsageGuidelinesUrl, ], [ClassificationDescriptions, ], [DefaultClassification, ], [PrefixSuffixNamingRequirement, ], [CustomBlockedWordsList, ], [EnableMSStandardBlockedWords, false]}

These MS-102 practice questions are part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style MS-102 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.