Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

You are the Microsoft 365 administrator for a large enterprise. You need to ensure that only users with a valid business justification can access sensitive data stored in SharePoint Online. The solution must enforce access reviews and provide detailed reports for auditors. Which TWO actions should you take?

⚠ Common exam trap

A common mix-up: candidates confuse access control mechanisms like DLP or sensitivity labels with identity-based access reviews, failing to recognize that access reviews in Entra ID Governance enforce periodic attestation, while audit logging in Purview provides the detailed access reports for auditors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure access reviews in Microsoft Entra ID Governance for the SharePoint site.

Option A is correct because Microsoft Entra ID Governance access reviews are the native mechanism to periodically attest who still needs access to a SharePoint site, enforcing the requirement that only users with a valid business justification retain access. Option C is correct because enabling audit logging in Microsoft Purview captures SharePoint Online access and activity events, and the resulting audit log search and reports provide the detailed evidence auditors require. Option B is not correct because Defender for Cloud Apps session policies monitor and control sessions but do not enforce access reviews or produce the required auditor-facing access attestation reports. Option D is not correct because sensitivity labels with justification for label changes govern classification and labeling actions, not recurring access justification or review. Option E is not correct because a DLP policy prevents sharing of sensitive content but does not enforce access reviews or generate the detailed access reports for auditors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure access reviews in Microsoft Entra ID Governance for the SharePoint site.

    Why this is correct

    Configuring access reviews in Microsoft Entra ID Governance automates a recurring certification workflow in which site owners or designated reviewers must explicitly confirm each user's continued need to access the SharePoint site. Every approval response is logged with a timestamp and reviewer identity, generating the audit trail required by internal policy or external auditors. This directly satisfies the business-justification and periodic-attestation requirements because access is not simply recorded; it is actively revalidated on a fixed schedule.

  • ✗

    Deploy Microsoft Defender for Cloud Apps and create a session policy to monitor access.

    Why it's wrong here

    A Microsoft Defender for Cloud Apps session policy with conditional access app control can monitor live user sessions and even block high-risk actions like mass download or external sharing, but it only inspects activity while a session is happening. It does not introduce a recurring attestation cycle, nor does it require a reviewer to certify that a user's membership remains justified after the session ends. As a real-time security control it may reduce risk, but it fails the core requirement for periodic access reviews with documented business justification.

  • ✓

    Enable audit logging in Microsoft Purview and generate detailed access reports.

    Why this is correct

    Enabling Microsoft Purview audit logging does capture every access event on the SharePoint site, including permission changes, file views, and downloads, and these logs can be queried to produce detailed historical access reports for auditors. However, audit logs are purely passive: they record what happened but do not prompt an owner to periodically revalidate why a user still holds access. To meet a true attestation requirement, those reports must be paired with an active workflow such as Entra ID access reviews; on their own, audit logs only support the review process, not replace it.

  • ✗

    Apply a sensitivity label to the SharePoint site and require justification for label change.

    Why it's wrong here

    Applying a sensitivity label to the SharePoint site and requiring justification for any label change protects the content by classifying it and preventing users from casually downgrading its protection level. But the label is static once applied and does not evaluate the people inside the site's permission groups, nor does it generate a recurring membership review. It addresses data classification and protection, not identity attestation, so it leaves the periodic access-review and justification requirement completely unmet.

  • ✗

    Create a data loss prevention (DLP) policy to block unauthorized sharing.

    Why it's wrong here

    A data loss prevention (DLP) policy in Microsoft Purview inspects content and blocks sharing actions that violate rules, such as sending sensitive files outside the organization or to unauthorized domains. DLP evaluates outbound data movement and content patterns, but it cannot determine whether an existing member of the SharePoint site still has a legitimate business need to retain access. Therefore it mitigates data exfiltration risks but ignores the access review and business-justification requirement, making it an ineffective standalone answer.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.