Microsoft 365 Administrator - MS-102 Exam Practice Test
On which server should you install the Azure ATP sensor?
Correct Answer: C
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
You have a Microsoft 365 E5 subscription.
You plan to implement identity protection by configuring a sign-in risk policy and a user risk policy. Which type of risk is detected by each policy? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You plan to implement identity protection by configuring a sign-in risk policy and a user risk policy. Which type of risk is detected by each policy? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:

You have a Microsoft 365 E5 subscription that contains two groups named Group1 and Group2. You plan to configure a data loss prevention (DLP) strategy that meets the following requirements:
* Members of Group1 must be prevented from sharing documents that contain credit card numbers.
* Members of Group2 must be prevented from sharing documents that are classified as internal by Microsoft Purview Information Protection.
* The solution must minimize administrative effort
You need to create a DLP policy for each group.
Which condition should you add to each DLP policy rule for each group? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

* Members of Group1 must be prevented from sharing documents that contain credit card numbers.
* Members of Group2 must be prevented from sharing documents that are classified as internal by Microsoft Purview Information Protection.
* The solution must minimize administrative effort
You need to create a DLP policy for each group.
Which condition should you add to each DLP policy rule for each group? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:

You have a Microsoft J65 E5 subscription.
You integrate Microsoft Defender for Endpoint with Microsoft Intune.
You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune.
Solution: You configure a device configuration profile.
Does this meet the goal?
You integrate Microsoft Defender for Endpoint with Microsoft Intune.
You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune.
Solution: You configure a device configuration profile.
Does this meet the goal?
Correct Answer: A
Vote an answer
HOTSPOT
You have an Microsoft Entra tenant that contains the administrative units shown in the following table.

You have the following users:
A user named User1 that is assigned the Password Administrator for AU1 and AU2.
A user named User2 that is assigned the User Administrator for AU1.
A user named User3 that is assigned the User Administrator for the tenant.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

You have an Microsoft Entra tenant that contains the administrative units shown in the following table.

You have the following users:
A user named User1 that is assigned the Password Administrator for AU1 and AU2.
A user named User2 that is assigned the User Administrator for AU1.
A user named User3 that is assigned the User Administrator for the tenant.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:

Box 1: No
User1 is assigned the Password Administrator for AU1 and AU2.
User3 is in AU2. User3 is User Adminstrator.
Password administrators cannot reset User Administrators passwords.
Note: Password Administrator
Users with this role have limited ability to manage passwords. This role does not grant the ability to manage service requests or monitor service health. Whether a Password Administrator can reset a user ' s password depends on the role the user is assigned.

Box 2: Yes
Box 3: No
User1 is assigned the Password Administrator for AU1 and AU2.
User2 is in AU1. User2 is User Adminstrator.
Password administrators cannot reset User Administrators passwords.
Note: User Administrator
Can manage all aspects of users and groups, including resetting passwords for limited admins.
Reference:
https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#who-can-reset-passwords
https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference
You have a Microsoft 365 subscription that uses the following services:
* Microsoft Entra
* Exchange Online
* Microsoft Teams
* SharePoint Online.
You are planning a backup solution that will use Microsoft 365 Backup.
You need to recommend which Microsoft 365 services can be backed up and the longest retention period available.
What should you recommend? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

* Microsoft Entra
* Exchange Online
* Microsoft Teams
* SharePoint Online.
You are planning a backup solution that will use Microsoft 365 Backup.
You need to recommend which Microsoft 365 services can be backed up and the longest retention period available.
What should you recommend? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Services: Exchange Online and SharePoint Online only
Retention period: 1 year
The correct dropdown selection is Exchange Online and SharePoint Online only . Microsoft 365 Backup supports backup and recovery for OneDrive, SharePoint, and Exchange Online workloads. From the services listed in this question, Exchange Online and SharePoint Online are the only supported services.
Microsoft Entra is not a Microsoft 365 Backup workload because it is an identity and directory platform, not a content workload protected by Microsoft 365 Backup. Microsoft Teams is also not selected as a separate backup service. Teams files are stored in SharePoint or OneDrive, but Microsoft 365 Backup does not list
"Teams" as an independent backup workload. Microsoft's backup policy documentation also separates backup policy configuration into SharePoint, Exchange, and OneDrive tabs, reinforcing that those are the protected workload categories.
The longest available retention period is 1 year . Microsoft's Microsoft 365 Backup FAQ states that when backed-up OneDrive or Exchange content is removed from the backup policy or the user is deleted, the backup is retained for one year from the date the backup was created . Therefore, among the given retention choices, the correct maximum is 1 year , not 5 or 10 years.
You have a Microsoft 365 E5 tenant that has sensitivity label support enabled for Microsoft and SharePoint Online.
You need to enable unified labeling for Microsoft 365 groups.
Which cmdlet should you run?
You need to enable unified labeling for Microsoft 365 groups.
Which cmdlet should you run?
Correct Answer: A
Vote an answer
You are evaluating the use of multi-factor authentication (MFA).
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:

HOTSPOT
You have a Microsoft 365 subscription that contains a Microsoft 365 group named Group1. Group1 is configured as shown in the following exhibit.

An external user named User1 has an email address of [email protected].
You need to add User1 to Group1.
What should you do first, and which portal should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a Microsoft 365 subscription that contains a Microsoft 365 group named Group1. Group1 is configured as shown in the following exhibit.

An external user named User1 has an email address of [email protected].
You need to add User1 to Group1.
What should you do first, and which portal should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:

Box 1: Invite User1 to collaborate with your organization as a guest.
To manage guest users of a Microsoft 365 tenant via the Admin Center portal, go through the following steps.
Navigate with your Web browser to https://admin.microsoft.com.
On the left pane, click on "Users", then click "Guest Users".
On the "Guest Users" page, to create a new guest user, click on either the "Add a guest user" link on the top of the page or click on "Go to Microsoft Entra ID to add guest users" link at the bottom of the page. Both of these links will take you to the Microsoft Entra ID portal, which is located at https://aad.portal.azure.com.
On the "New user" page in the Microsoft Azure portal, you must choose to either "Create user" or "Invite user". If you choose the "Create user" option, this will create a new user in your organization, which will have a login address with format username@tenantdomain,dot,com. If you choose the "Invite user" option, this will invite a new guest user to collaborate with your organization. The user will be emailed an email invitation which they can accept in order to begin collaborating. For the purpose of creating a guest user, you must choose the "Invite user" option.
Box 2: The Microsoft Entra admin center
Microsoft Entra admin center unites Microsoft Entra ID with family of identity and access products Microsoft Entra admin center gives customers an entire toolset to secure access for everyone and everything in multicloud and multiplatform environments. The entire Microsoft Entra product family is available at this new admin center, including Microsoft Entra ID (Microsoft Entra ID) and Microsoft Entra Permissions Management, formerly known as CloudKnox.
Starting this month, waves of customers will begin to be automatically directed to entra.microsoft.com from Microsoft 365 in place of the Microsoft Entra admin center (aad.portal.azure.com).
Reference:
https://stefanos.cloud/kb/how-to-manage-microsoft-365-guest-users
https://m365admin.handsontek.net/microsoft-entra-admin-center-unites-azure-ad-with-family-of-identity-and- access-products
You have a Microsoft Entra tenant that contains the groups shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each cont ' d selection is worth one point.


Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each cont ' d selection is worth one point.

Correct Answer:

Explanation:
You can add a Microsoft Entra cloud user to: Group1, Group3, and Group4 only Group1: Microsoft 365 group with assigned membership type and security enabled.
Group3: Security group with assigned membership type and security enabled.
Group4: Security group with dynamic membership type and security enabled.
Group2 is not security enabled, so it cannot have security-related tasks assigned.
Group5 is sourced from Windows Server AD, which may limit direct cloud user additions.
You can add Group5 to: Group1, Group2, Group3, and Group4
Group5 can be added to other groups regardless of the membership type or source, as long as those groups (Group1, Group2, Group3, and Group4) are security-enabled and support such additions.
You have a Microsoft 365 E5 subscription.
You integrate Microsoft Defender for Endpoint with Microsoft Intune.
You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune.
Solution: You create a compliance policy.
Does this meet the goal?
You integrate Microsoft Defender for Endpoint with Microsoft Intune.
You need to ensure that devices automatically onboard to Defender for Endpoint when they are enrolled in Intune.
Solution: You create a compliance policy.
Does this meet the goal?
Correct Answer: A
Vote an answer
You have a Microsoft 365 subscription that contains the administrative units shown in the following table.

The groups contain the members shown in the following table.

The users are assigned the roles shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE; Each correct selection is worth one point.


The groups contain the members shown in the following table.

The users are assigned the roles shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE; Each correct selection is worth one point.

Correct Answer:

Explanation:

Youi network contains an Active Directory domain.
You have a Microsoft Entra tenant that has Security defaults disabled.
Microsoft Entra Connect Sync is configured for directory synchronization. Password hash synchronization and pass-through authentication are disabled.
You need to enable Microsoft Entra ID Protection to detect leaked credentials.
What should you do first?
You have a Microsoft Entra tenant that has Security defaults disabled.
Microsoft Entra Connect Sync is configured for directory synchronization. Password hash synchronization and pass-through authentication are disabled.
You need to enable Microsoft Entra ID Protection to detect leaked credentials.
What should you do first?
Correct Answer: B
Vote an answer
You have a Microsoft Microsoft Entra ID (Microsoft Entra ID) tenant named Contoso.com.
You create a Microsoft Defender for identity instance Contoso.
The tenant contains the users shown in the following table.

You need to modify the configuration of the Defender for identify sensors.
Solutions: You instruct User3 to modify the Defender for identity sensor configuration.
Does this meet the goal?
You create a Microsoft Defender for identity instance Contoso.
The tenant contains the users shown in the following table.

You need to modify the configuration of the Defender for identify sensors.
Solutions: You instruct User3 to modify the Defender for identity sensor configuration.
Does this meet the goal?
Correct Answer: B
Vote an answer