MS-102 Actual Exam Questions

Last updated on May 30, 2025.
Vendor:Microsoft
Exam Code:MS-102
Exam Name:Microsoft 365 Administrator
Exam Questions:383
Question #291 Topic 1

You have a Microsoft 365 E5 subscription.

You create a data loss prevention (DLP) policy named DLP1.

You need to ensure that endpoint rule actions are available in the advanced DLP rules for DLP1.

To which location should you apply DLP1?

  • A. Instances
  • B. OneDrive accounts
  • C. On-premises repositories
  • D. Devices
Reveal Solution Hide Solution   Discussion   6

Correct Answer: D 🗳️

Community vote distribution
D (100%)

Question #292 Topic 1

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.

All the devices in your organization are onboarded to Microsoft Defender for Endpoint.

You need to ensure that an alert is generated if malicious activity was detected on a device during the last 24 hours.

What should you do?

  • A. From the Microsoft Defender portal, create an alert suppression rule and assign an alert.
  • B. From the Microsoft Purview compliance portal, create an audit log search.
  • C. From the Microsoft Purview compliance portal, create a data loss prevention (DLP) policy.
  • D. From the Microsoft Defender portal, create an Advanced hunting query and a detection rule.
Reveal Solution Hide Solution   Discussion   3

Correct Answer: D 🗳️

Community vote distribution
D (83%)
A (17%)

Question #293 Topic 1

You have a Microsoft 365 E5 subscription that contains a domain named contoso.com.

You deploy a new Microsoft Defender for Office 365 anti-phishing policy named Policy1 that has user impersonation protection enabled for a user named user1@contoso.com.

You discover that Policy1 blocks email messages from a regular contact named user1@fabnkam.com.

You need to ensure that the messages are delivered successfully.

What should you do for Policy1?

  • A. Select Enable domains to protect.
  • B. Configure the Phishing email threshold setting.
  • C. Configure which users to protect.
  • D. Select Enable mailbox intelligence.
Reveal Solution Hide Solution   Discussion   2

Correct Answer: D 🗳️

Community vote distribution
D (100%)

Question #294 Topic 1

HOTSPOT
-

You have a Microsoft 365 E5 subscription.

You have devices onboarded to Microsoft Defender for Endpoint as shown in the following table.



You create the device groups shown in the following table.



IP address indicators are defined as shown in the following table.



For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Reveal Solution Hide Solution   Discussion   4

Correct Answer:

Question #295 Topic 1

Your company has a Microsoft Entra tenant named contoso.com and a Microsoft 365 subscription.

All users use Windows 10 devices to access Microsoft Office 365 apps.

All the devices are in a workgroup.

You plan to implement password less sign-in to contoso.com.

You need to recommend changes to the infrastructure for the planned implementation.

What should you include in the recommendation?

  • A. Join all the devices to contoso.com.
  • B. Deploy Microsoft Entra Application Proxy.
  • C. Deploy the Microsoft Entra Connect provisioning agent.
  • D. Deploy the Microsoft Authenticator app.
Reveal Solution Hide Solution   Discussion   5

Correct Answer: A 🗳️

Community vote distribution
A (80%)
D (20%)

Question #296 Topic 1

You have a Microsoft 365 E5 subscription.

You plan to implement an authentication policy that will user FIDO2 security key as a user authentication method.

You need to ensure that during enrollment, each FIDO2 security key is verified by using the FIDO Alliance Metadata Service.

Which setting should you enable?

  • A. Allow self-service setup
  • B. Restrict specific keys
  • C. Enforce attestation
  • D. Enforce key restrictions
Reveal Solution Hide Solution   Discussion   2

Correct Answer: C 🗳️

Community vote distribution
C (100%)

Question #297 Topic 1

HOTSPOT
-

You have a Microsoft 365 E5 subscription.

You are investigating a suspicious email message that generated alerts in the Microsoft Defender portal.

You need to examine the email message header and submit the message to Microsoft for review.

Which two settings should you use? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Reveal Solution Hide Solution   Discussion   6

Correct Answer:

Question #298 Topic 1

You have a Microsoft 365 E5 subscription.

You create the users shown in the following table.



You plan to use Microsoft Entra ID Protection.

Which users will be added automatically to the User at risk detected alerts list?

  • A. Admin1 only
  • B. Admin2 only
  • C. Admin1 and Admin2 only
  • D. Admin1 and Admin3 only
  • E. Admin1, Admin2, and Admin3
Reveal Solution Hide Solution   Discussion   4

Correct Answer: D 🗳️

Community vote distribution
D (92%)
8%

Question #299 Topic 1

HOTSPOT
-

You have a Microsoft 365 E5 subscription that contains the users shown in the following table.



The subscription contains the groups shown in the following table.



Which users and groups can you delete? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Reveal Solution Hide Solution   Discussion   10

Correct Answer:

Question #300 Topic 1

You have a Microsoft 365 E5 subscription.

You create a user named Admin1.

You need to ensure that Admin1 can view Endpoint security policies from the Microsoft Defender portal. The solution must follow the principle of least privilege.

Which Microsoft Entra role should you assign to Admin1?

  • A. Cloud Device Administrator
  • B. Security Reader
  • C. Global Reader
  • D. Security Administrator
  • E. Security Operator
Reveal Solution Hide Solution   Discussion   1

Correct Answer: B 🗳️

Community vote distribution
B (100%)

Previous Questions
file Viewing page 30 out of 39 pages.
Viewing questions 291-300 out of 383 questions
Next Questions
Browse atleast 50% to increase passing rate cup
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Loading ...