Summer Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

MS-102 Questions and Answers

Question # 6

You need to recommend a solution for the security administrator. The solution must meet the technical requirements.

What should you include in the recommendation?

A.

Microsoft Microsoft Entra ID (Microsoft Entra ID) Privileged Identity Management

B.

Microsoft Microsoft Entra ID (Microsoft Entra ID) Identity Protection

C.

Microsoft Microsoft Entra ID (Microsoft Entra ID) conditional access policies

D.

Microsoft Microsoft Entra ID (Microsoft Entra ID) authentication methods

Full Access
Question # 7

You need to meet the technical requirement for large-volume document retrieval. What should you create?

A.

a data loss prevention (DLP) policy from the Security & Compliance admin center

B.

an alert policy from the Security & Compliance admin center

C.

a file policy from Microsoft Cloud App Security

D.

an activity policy from Microsoft Cloud App Security

Full Access
Question # 8

You need to meet the technical requirement for the SharePoint administrator. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Question # 8

Full Access
Question # 9

You plan to implement the endpoint protection device configuration profiles to support the planned changes.

You need to identify which devices will be supported, and how many profiles you should implement.

What should you identify? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 9

Full Access
Question # 10

You need to configure Office on the web to meet the technical requirements.

What should you do?

A.

Assign the Global reader role to User1.

B.

Enable sensitivity labels for Office files in SharePoint Online and OneDrive.

C.

Configure an auto-labeling policy to apply the sensitivity labels.

D.

Assign the Office apps admin role to User1.

Full Access
Question # 11

You need to configure the information governance settings to meet the technical requirements.

Which type of policy should you configure, and how many policies should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 11

Full Access
Question # 12

You need to create the DLP policy to meet the technical requirements.

What should you configure first?

A.

sensitive info types

B.

the Insider risk management settings

C.

the event types

D.

the sensitivity labels

Full Access
Question # 13

You need to create the Safe Attachments policy to meet the technical requirements.

Which option should you select?

A.

Replace

B.

Enable redirect

C.

Block

D.

Dynamic Delivery

Full Access
Question # 14

You need to configure automatic enrollment in Intune. The solution must meet the technical requirements.

What should you configure, and to which group should you assign the configurations? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 14

Full Access
Question # 15

You create the planned DLP policies.

You need to configure notifications to meet the technical requirements.

What should you do?

A.

From the Microsoft 365 security center, configure an alert policy.

B.

From the Microsoft Endpoint Manager admin center, configure a custom notification.

C.

From the Microsoft 365 admin center, configure a Briefing email.

D.

From the Microsoft 365 compliance center, configure the Endpoint DLP settings.

Full Access
Question # 16

You need to configure the Office 365 service status notifications and limit access to the service and feature updates. The solution must meet the technical requirements.

What should you configure in the Microsoft 365 admin center? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 16

Full Access
Question # 17

You need to configure just in time access to meet the technical requirements.

What should you use?

A.

entitlement management

B.

Microsoft Entra Privileged Identity Management (PIM)

C.

access reviews

D.

Microsoft Entra ID Protection

Full Access
Question # 18

You need to ensure that the Microsoft 365 incidents and advisories are reviewed monthly.

Which users can review the incidents and advisories, and which blade should the users use? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 18

Full Access
Question # 19

You need to configure the compliance settings to meet the technical requirements.

What should you do in the Microsoft Endpoint Manager admin center?

A.

From Compliance policies, modify the Notifications settings.

B.

From Locations, create a new location for noncompliant devices.

C.

From Retire Noncompliant Devices, select Clear All Devices Retire State.

D.

Modify the Compliance policy settings.

Full Access
Question # 20

On which server should you use the Defender for identity sensor?

A.

Server1

B.

Server2

C.

Server3

D.

Server4

E.

Servers5

Full Access
Question # 21

You are evaluating the use of multi-factor authentication (MFA).

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 21

Full Access
Question # 22

You need to ensure that Admin4 can use SSPR.

Which tool should you use. and which action should you perform? To answer, select the appropriate options m the answer area.

NOTE: Each correct selection is worth one point.

Question # 22

Full Access
Question # 23

You need to configure Microsoft Entra Connect Sync to support the planned changes for the Montreal Users and Seattle Users OUs.

What should you do?

A.

From the Microsoft Microsoft Entra Connect Sync wizard, select Customize synchronization options.

B.

From PowerShell, run the Add-ADSyncConnectorAttnbuteinclusion cmdlet.

C.

From PowerShell, run the start-ADSyncSyncCycle cmdlet.

D.

From the Microsoft Microsoft Entra Connect Sync wizard, select Manage federation.

Full Access
Question # 24

You need to meet the technical requirements and planned changes for Intune.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 24

Full Access
Question # 25

You need to configure a conditional access policy to meet the compliance requirements.

You add Exchange Online as a cloud app.

Which two additional settings should you configure in Policy1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 25

Full Access
Question # 26

You need to meet the compliance requirements for the Windows 10 devices.

What should you create from the Intune admin center?

A.

a device compliance policy

B.

a device configuration profile

C.

an application policy

D.

an app configuration policy

Full Access
Question # 27

You need to meet the Intune requirements for the Windows 10 devices.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 27

Full Access
Question # 28

You need to ensure that the support technicians can meet the technical requirement for the Montreal office mobile devices.

What is the minimum of dedicated support technicians required?

A.

1

B.

4

C.

7

D.

31

Full Access
Question # 29

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory domain named contoso.com that is synced to Microsoft Microsoft Entra ID (Microsoft Entra ID).

You manage Windows 10 devices by using Microsoft System Center Configuration Manager (Current Branch).

You configure a pilot for co-management.

You add a new device named Device1 to the domain. You install the Configuration Manager client on Device1.

You need to ensure that you can manage Device1 by using Microsoft Intune and Configuration Manager.

Solution: Define a Configuration Manager device collection as the pilot collection. Add Device1 to the collection.

Does this meet the goal?

A.

Yes

B.

NO

Full Access
Question # 30

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory domain named contoso.com that is synced to Microsoft Microsoft Entra ID (Microsoft Entra ID).

You manage Windows 10 devices by using Microsoft System Center Configuration Manager (Current Branch).

You configure a pilot for co-management.

You add a new device named Device1 to the domain. You install the Configuration Manager client on Device1.

You need to ensure that you can manage Device1 by using Microsoft Intune and Configuration Manager.

Solution: You create a device configuration profile from the Device Management admin center.

Does this meet the goal?

A.

Yes

B.

No

Full Access
Question # 31

HOTSPOT

You create the Microsoft 365 tenant.

You implement Microsoft Entra Connect Sync as shown in the following exhibit.

Question # 31

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Question # 31

Full Access
Question # 32

You need to create the Microsoft Store for Business. Which user can create the store?

A.

User2

B.

User3

C.

User4

D.

User5

Full Access
Question # 33

As of March, how long will the computers in each office remain supported by Microsoft? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 33

Full Access
Question # 34

On which server should you install the Azure ATP sensor?

A.

Server 1

B.

Server 2

C.

Server 3

D.

Server 4

E.

Server 5

Full Access
Question # 35

You have a Microsoft 365 subscription.

You have the devices shown in the following table.

Question # 35

You plan to join the devices to Microsoft Entra ID (Microsoft Entra ID)

What should you do on each device to support Azure AU join? To answer, drag the appropriate actions to the collect devices, Each action may be used once, more than once, of not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 35

Full Access
Question # 36

You have a Microsoft 365 subscription that contains a user named User1.

User1 requires admin access to perform the following tasks:

Manage Microsoft Exchange Online settings.

Create Microsoft 365 groups.

You need to ensure that User1 only has admin access for eight hours and requires approval before the role assignment takes place.

What should you use?

A.

zure AD Identity Protection

B.

Microsoft Entra Verified ID

C.

Conditional Access

D.

Microsoft Entra ID Privileged Identity Management (PJM)

Full Access
Question # 37

You have a Microsoft 365 tenant.

You plan to implement Endpoint Protection device configuration profiles.

Which platform can you manage by using the profile?

A.

Ubuntu Linux

B.

macOS

C.

iOS

D.

Android

Full Access
Question # 38

HOTSPOT

Your network contains an on-premises Active Directory domain. The domain contains the servers shown in the following table.

Question # 38

You purchase a Microsoft 365 E5 subscription.

You need to implement Microsoft Entra Cloud Sync.

What should you install first and on which server? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 38

Full Access
Question # 39

You have a Microsoft 365 E5 subscription.

You onboard all devices to Microsoft Defender for Endpoint

You need to use Defender for Endpoint to block access to a malicious website at www.contoso.com.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct answer is worth one point.

A.

Create a web content filtering policy.

B.

Configure an enforcement scope.

C.

Enable Custom network indicators.

D.

Create an indicator.

E.

Enable automated investigation.

Full Access
Question # 40

You have a Microsoft 365 subscription that uses Microsoft Defender XDR

From Automatic remediation in the Microsoft Defender portal, you set Automation level to Semi - require approval for non-temp folders for the endpoints.

You need to identify the impact of the Automation level setting on the endpoints.

Which two actions will occur based on the remediation settings? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

A.

Devices will be remediated automatically if a threat is detected in the \windows\ folder.

B.

Devices will be remediated automatically if a threat is detected in the \program files (X86) \ " folder.

C.

Devices will be remediated automatically if a threat is detected in the \users\ " \downloads\ " folder.

D.

Devices will be remediated only after end-user approval.

Full Access
Question # 41

From the Security & Compliance admin center, you create a content export as shown in the exhibit. (Click the Exhibit tab.)

Question # 41

What will be excluded from the export?

A.

a 10-MB XLSX file

B.

a 5-MB MP3 file

C.

a 5-KB RTF file

D.

an 80-MB PPTX file

Full Access
Question # 42

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the users shown in the following table.

Question # 42

The domain syncs to an Microsoft Entra tenant named contoso.com as shown in the exhibit. (Click the Exhibit tab.)

Question # 42

User2 fails to authenticate to Microsoft Entra ID when signing in as user2@fabrikam.com.

You need to ensure that User2 can access the resources in Microsoft Entra ID.

Solution: From the Microsoft Entra admin center, you add fabrikam.com as a custom domain. You instruct User2 to sign in as user2@fabrikam.com.

Does this meet the goal?

A.

Yes

B.

No

Full Access
Question # 43

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint and Microsoft Intune.

All devices run Windows 11 and are Microsoft Entra joined.

You are alerted to a zero-day attack.

You need to identify which devices were affected by the attack and send a request to Intune administrators to update the affected devices.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

From Incidents & alerts, select the latest incident.

B.

From Vulnerability management, open the security recommendation.

C.

Select the affected devices and request remediation.

D.

From Threat analytics, view the list of vulnerable devices.

Full Access
Question # 44

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint.

You plan to perform device discovery and authenticated scans of network devices.

You install and register the network scanner on a device named Device1.

What should you do next?

A.

Connect Defender for Endpoint to Microsoft Intune.

B.

Apply for Microsoft Threat Experts - Targeted Attack Notifications.

C.

Create an assessment job.

D.

Download and run an onboarding package.

Full Access
Question # 45

You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

Question # 45

Which users can create user objects, and which users can create Microsoft 365 groups? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 45

Full Access
Question # 46

You have a Microsoft 365 E5 subscription.

On Monday, you create a new user named User1.

On Tuesday, User1 signs in for the first time and perform the following actions:

• Signs in to Microsoft Exchange Online from an anonymous IP address

• Signs in to Microsoft SharePoint Online from a device in New York City.

• Establishes Remote Desktop connections to hosts in Berlin and Hong Kong, and then signs in to SharePoint Online from the Remote Desktop connections

Which types of sign-in risks will Microsoft Entra ID Protection detect for User1?

A.

anonymous IP address only

B.

anonymous IP address and atypical travel

C.

anonymous IP address, atypical travel, and unfamiliar sign-in properties

D.

unfamiliar sign-in properties and atypical travel only

E.

anonymous IP address and unfamiliar sign-in properties only

Full Access
Question # 47

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it as a result, these questions will not appear in the review screen.

Your network contains an Active Directory domain.

You deploy an Microsoft Entra tenant.

Another administrator configures the domain to synchronize to Microsoft Entra ID.

You discover that 10 user accounts in an organizational unit (OU) are NOT synchronized to Microsoft Entra ID. All the other user accounts synchronized successfully.

You review Microsoft Entra Connect Health and discover that all the user account synchronizations completed successfully.

You need to ensure that the 10 user accounts are synchronized to Microsoft Entra ID.

Solution: From Microsoft Entra Connect Sync, you modify the filtering settings.

Does this meet the goal?

A.

Yes

B.

No

Full Access
Question # 48

You have a Microsoft 365 E5 subscription.

You need to create a Conditional Access policy named Policy1 that will enforce the use of phishing-resistant multifactor authentication (MFA) when a user attempts to register or join devices to a Microsoft Entra tenant.

How should you configure Policy1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 48

Full Access
Question # 49

You have a Microsoft 365 E5 tenant that contains 500 Windows 10 devices. The devices are enrolled in Microsoft intune.

You plan to use Endpoint analytics to identify hardware issues.

You need to enable Window health monitoring on the devices to support Endpoint analytics

What should you do?

A.

Configure the Endpoint analytics baseline regression threshold.

B.

Create a configuration profile.

C.

Create a Windows 10 Security Baseline profile

D.

Create a compliance policy.

Full Access
Question # 50

Your network contains an on-premises Active Directory Domain Services (AD DS) forest.

You have a Microsoft Entra tenant.

You implement Microsoft Entra Connect Sync.

The synchronization fails to complete.

You review the logs and discover the following error message:

“We found an issue with the service account that is used to run Microsoft Entra Connect Sync.”

You need to ensure that the synchronization completes successfully. The solution must minimize administrative effort.

What should you do?

A.

From PowerShell, run the Repair-AADCloudSyncToolsAccount cmdlet.

B.

From PowerShell, run the Set-ADSyncScheduler cmdlet.

C.

From Active Directory Users and Computers, reset the password of the ADSync service account.

D.

From the Microsoft Entra admin center, reset the password of the Microsoft Entra Connect Sync account.

Full Access
Question # 51

You have a Microsoft 365 subscription that contains an Microsoft Entra tenant named contoso.com. The tenant includes a user named User1.

You enable Microsoft Entra ID Protection.

You need to ensure that User1 can review the list in Microsoft Entra ID Protection of users flagged for risk. The solution must use the principle of least privilege.

To which role should you add User1?

A.

Security Reader

B.

Global Administrator

C.

Owner

D.

User Administrator

Full Access
Question # 52

You have a Microsoft 365 subscription that uses a third-party multifactor authentication (MFA) product.

While reviewing Microsoft Secure Score, you discover that there are no points listed for the Ensure multifactor authentication is enabled for all users recommendation.

You need to ensure that you receive all the points for the recommendation. The solution must minimize administrative effort.

What should you do?

A.

Configure a data connector.

B.

Modify the recommendation tags.

C.

Deploy a Microsoft Defender for Identity sensor.

D.

Modify the status of the recommendation.

Full Access
Question # 53

You have a Microsoft 365 E5 subscription that contains two Microsoft SharePoint Online sites named Site1 and Site2.

You have the documents shown in the following table.

Question # 53

You create a data loss prevention (DLP) policy named DLP1 that has the advanced DLP rule as shown in the exhibit.

Question # 53

Question # 53

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 53

Full Access
Question # 54

You have the Microsoft Defender XDR report schedules shown in the following exhibit.

Question # 54

You need to ensure that the report schedules generate reports as frequently as possible.

To what should you set the Frequency setting for each schedule? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 54

Full Access
Question # 55

You have a Microsoft 365 subscription.

You need to add additional domains with the onmicrosoft.com suffix to the subscription. The additional domains must be assignable as email addresses for users.

What is the maximum number of onmicrosoft.com domains the subscription can contain?

A.

1

B.

2

C.

5

D.

10

Full Access
Question # 56

HOTSPOT

You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.

Question # 56

All the groups are deleted.

Which groups can be restored, and what is the retention period? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 56

Full Access
Question # 57

You have a Microsoft 365 ES tenant.

You have the alerts shown in the following exhibit.

Question # 57

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Question # 57

Full Access
Question # 58

You have a Microsoft 365 subscription.

You need to receive a notification each time a user in the service desk department grants Full Access permissions for a user mailbox.

What should you configure?

A.

a data loss prevention (DLP) policy

B.

an alert policy

C.

an audit search

D.

an insider risk management policy

Full Access
Question # 59

HOTSPOT

You have a Microsoft 365 E5 subscription.

You need to meet the following requirements:

Automatically encrypt documents stored in Microsoft OneDrive and SharePoint.

Enable co-authoring for Microsoft Office documents encrypted by using a sensitivity label.

Which two settings should you use in the Microsoft Purview compliance portal? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Question # 59

Full Access
Question # 60

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an on-premises Active Directory domain. The domain contains domain controllers that run Windows Server 2019. The functional level of the forest and the domain is Windows Server 2012 R2.

The domain contains 100 computers that run Windows 10 and a member server named Server1 that runs Windows Server 2012 R2.

You plan to use Server1 to manage the domain and to configure Windows 10 Group Policy settings.

You install the Group Policy Management Console (GPMC) on Server1.

You need to configure the Windows Update for Business Group Policy settings on Server1.

Solution: You raise the forest functional level to Windows Server 2016. You copy the Group Policy Administrative Templates from a Windows 10 computer to the Netlogon share on all the domain controllers.

Does this meet the goal?

A.

yes

B.

No

Full Access
Question # 61

You have a Microsoft 365 E5 subscription. The subscription contains a Microsoft SharePoint Online site named Site1. Site1 contains the following files:

• File.docx

• ImportantFile.docx

• Filejmportant.docx

From Microsoft Defender Cloud Apps, you create a file policy named Policy1 that has the filter shown in the following exhibit.

Question # 61

To which files will Policy1 apply?

A.

File.docx, ImportantFile.docx, and Filejmportant.docx

B.

Filejmportant.docx only

C.

ImportantFile.docx and Filejmportant.docx only

D.

File.docx only

E.

ImportantFile.docx only

Full Access
Question # 62

You have three devices enrolled in Microsoft Endpoint Manager as shown in the following table.

Question # 62

The device compliance policies in Endpoint Manager are configured as shown in the following table.

Question # 62

The device compliance policies have the assignments shown in the following table.

Question # 62

For each of the following statements, select Yes if the statement Is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 62

Full Access
Question # 63

Your company has a Microsoft 365 subscription.

you implement sensitivity Doris for your company.

You need to automatically protect email messages that contain the word Confidential m the subject line.

What should you create?

A.

a sharing policy from the Exchange admin center

B.

a mail flow rule from the Exchange admin center

C.

a message Dace from the Microsoft 365 security center

D.

a data loss prevention (DLP) policy from the Microsoft 365 compliance center

Full Access
Question # 64

You have a Microsoft 365 E5 subscription.

You need to ensure that an alert is generated when an app is registered in Microsoft Entra and is assigned the Directory.Readwrite.ALL Microsoft Graph permission.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 64

Full Access