Free MS-102 Questions for Microsoft 365 Administrator MS-102 Exam as PDF & Practice Test Engine
You have a Microsoft 365 E5 subscription that contains two Microsoft SharePoint Online sites named Site1 and Site2.
You have the documents shown in the following table.

You create a data loss prevention (DLP) policy named DLP1 that has the advanced DLP rule as shown in the exhibit.


For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

You have the documents shown in the following table.

You create a data loss prevention (DLP) policy named DLP1 that has the advanced DLP rule as shown in the exhibit.


For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
NO
No
Yes
In the Content contains condition, Microsoft Purview DLP lets you combine conditions using logical operators:
"Any of these" = logical OR
"All of these" = logical AND
From the exhibit, the rule is effectively:
Group1 (All of these / AND)
Credit Card Number: 1 to 5 instances
SWIFT Code: 1 to 2 instances
OR
Group2 (Any of these)
Credit Card Number: 10 to Any instances
So the rule matches if:
(Credit Card is 1-5 AND SWIFT is 1-2) OR (Credit Card is #10).
Evaluate each document against the rule
Document1: Credit Card = 3, SWIFT = 3
Group1 requires SWIFT 1-2, but Document1 has 3 # Group1 = false
Group2 requires Credit Card #10, but Document1 has 3 # Group2 = false Result: DLP1 does NOT apply # No Document2: Credit Card = 7, SWIFT = 2 Group1 requires Credit Card 1-5, but Document2 has 7 # Group1 = false Group2 requires Credit Card #10, but Document2 has 7 # Group2 = false Result: DLP1 does NOT apply # No Document3: Credit Card = 15, SWIFT = 0 Group2 requires Credit Card #10, and Document3 has 15 # Group2 = true Result: DLP1 DOES apply # Yes
You have the Microsoft Defender XDR report schedules shown in the following exhibit.

You need to ensure that the report schedules generate reports as frequently as possible.
To what should you set the Frequency setting for each schedule? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


You need to ensure that the report schedules generate reports as frequently as possible.
To what should you set the Frequency setting for each schedule? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:

You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

Which users can create user objects, and which users can create Microsoft 365 groups? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


Which users can create user objects, and which users can create Microsoft 365 groups? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
User objects
User2 only
Microsoft 365 groups
User1, User2, and User3
User2 only can create user objects because User2 has the User Administrator role. Microsoft's Microsoft Entra built-in role reference states that the User Administrator role includes the permission to create users and manage users. The Groups Administrator role is scoped to group management, not user object creation. The Teams Administrator role manages the Teams workload and does not grant general Microsoft Entra user creation rights.
For Microsoft 365 groups, the correct selection is User1, User2, and User3. Microsoft states that the Groups Administrator role can create and manage groups across workloads, including Teams, SharePoint, Yammer, and Outlook, so User1 qualifies. The User Administrator role includes the ability to create and manage all groups, so User2 qualifies. The Teams Administrator role also explicitly grants the ability to create and manage all Microsoft 365 groups, because Teams administration depends on Microsoft 365 group-backed teams.
Therefore, choose User2 only for user objects and User1, User2, and User3 for Microsoft 365 groups.
You have a Microsoft 365 tenant.
Company policy requires that all Windows 10 devices meet the following minimum requirements:
Require complex passwords.
Require the encryption of data storage devices.
Have Microsoft Defender Antivirus real-time protection enabled.
You need to prevent devices that do not meet the requirements from accessing resources in the tenant.
Which two components should you create? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
Company policy requires that all Windows 10 devices meet the following minimum requirements:
Require complex passwords.
Require the encryption of data storage devices.
Have Microsoft Defender Antivirus real-time protection enabled.
You need to prevent devices that do not meet the requirements from accessing resources in the tenant.
Which two components should you create? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
Correct Answer: A,E
Vote an answer
Explanation: Only visible for ExamDiscuss members. You can sign-up / login (it's free).
HOTSPOT
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

You configure the Microsoft Authenticator authentication method policy to enable passwordless authentication as shown in the following exhibit.

Both User1 and User2 report that they are NOT prompted for passwordless sign-in in the Microsoft Authenticator app.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

You configure the Microsoft Authenticator authentication method policy to enable passwordless authentication as shown in the following exhibit.

Both User1 and User2 report that they are NOT prompted for passwordless sign-in in the Microsoft Authenticator app.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:

Box 1: Yes
User1 is member of Group1.
User1 has MFA registered method of Microsoft Authenticater app (push notification) The Microsoft Authenticator authentication method policy is configured for Group1, registration is optional, authentication method is any.
Note: Microsoft Authenticator can be used to sign in to any Microsoft Entra ID account without using a password. Microsoft Authenticator uses key-based authentication to enable a user credential that is tied to a device, where the device uses a PIN or biometric. Windows Hello for Business uses a similar technology.
This authentication technology can be used on any device platform, including mobile. This technology can also be used with any app or website that integrates with Microsoft Authentication Libraries.
Box 2: No
User2 is member of Group2.
The Microsoft Authenticator authentication method policy is configured for Group1, not for Group2.
Box 3: No
User3 is member of Group1.
User3 has no MFA method registered.
User3 must choose an authentication method.
Note: Enable passwordless phone sign-in authentication methods
Microsoft Entra ID lets you choose which authentication methods can be used during the sign-in process.
Users then register for the methods they ' d like to use.
Reference:
https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-phone
You have a Microsoft 365 E5 tenant that contains the devices shown in the following table.

You plan to implement attack surface reduction (ASR) rules. Which devices will support the ASR rules?

You plan to implement attack surface reduction (ASR) rules. Which devices will support the ASR rules?
Correct Answer: A
Vote an answer
Explanation: Only visible for ExamDiscuss members. You can sign-up / login (it's free).
You have a Microsoft 365 tenant.
You plan to manage incidents in the tenant by using the Microsoft 365 security center.
Which Microsoft service source will appear on the Incidents page of the Microsoft 365 security center?
You plan to manage incidents in the tenant by using the Microsoft 365 security center.
Which Microsoft service source will appear on the Incidents page of the Microsoft 365 security center?
Correct Answer: C
Vote an answer
Explanation: Only visible for ExamDiscuss members. You can sign-up / login (it's free).
Your network contains an on-premises Active Directory Domain Services (AD DS) domain. The domain contains 2,000 user accounts.
You have a Microsoft Entra tenant.
You need to sync the domain with the Microsoft Entra tenant. The solution must meet the following requirements:
. Minimize infrastructure requirements.
. Minimize single points of failure.
. Minimize administrative effort.
What should you use?
You have a Microsoft Entra tenant.
You need to sync the domain with the Microsoft Entra tenant. The solution must meet the following requirements:
. Minimize infrastructure requirements.
. Minimize single points of failure.
. Minimize administrative effort.
What should you use?
Correct Answer: A
Vote an answer
Explanation: Only visible for ExamDiscuss members. You can sign-up / login (it's free).
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

Which users can create user objects, and which users can create Microsoft 365 groups? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


Which users can create user objects, and which users can create Microsoft 365 groups? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:

You have a Microsoft 365 ES subscription.
You integrate Microsoft Defender for Endpoint with Microsoft Intune.
You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled In Intune.
Solution: You create an endpoint detection and response (EDR) policy.
Does this meet the goal?
You integrate Microsoft Defender for Endpoint with Microsoft Intune.
You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled In Intune.
Solution: You create an endpoint detection and response (EDR) policy.
Does this meet the goal?
Correct Answer: B
Vote an answer
You have a hybrid Microsoft Entra ID (Microsoft Entra ID) tenant and a Microsoft Endpoint Configuration Manager deployment.
You have the devices shown in the following table.

You plan to enable co-management.
You need to identify which devices support co-management without requiring the installation of additional software.
Which devices should you identify?
You have the devices shown in the following table.

You plan to enable co-management.
You need to identify which devices support co-management without requiring the installation of additional software.
Which devices should you identify?
Correct Answer: A
Vote an answer
You have an Microsoft Entra tenant and a Microsoft 365 E5 subscription. The tenant contains the users shown in the following table.

You plan to implement Microsoft Defender for Endpoint.
You verify that role-based access control (RBAC) is turned on in Microsoft Defender for Endpoint.
You need to identify which user can view security incidents from the Microsoft Defender XDR portal.
Which user should you identify?

You plan to implement Microsoft Defender for Endpoint.
You verify that role-based access control (RBAC) is turned on in Microsoft Defender for Endpoint.
You need to identify which user can view security incidents from the Microsoft Defender XDR portal.
Which user should you identify?
Correct Answer: A
Vote an answer
0
0
0
10
