MS-102 Actual Exam Questions

Last updated on May 30, 2025.
Vendor:Microsoft
Exam Code:MS-102
Exam Name:Microsoft 365 Administrator
Exam Questions:383
Question #71 Topic 1

You are reviewing alerts in the Microsoft 365 Defender portal.
How long are the alerts retained in the portal?

  • A. 30 days
  • B. 60 days
  • C. 3 months
  • D. 6 months
  • E. 12 months
Reveal Solution Hide Solution   Discussion   25
Community vote distribution
D (83%)
Other

Question #72 Topic 1

You have a Microsoft 365 E5 subscription.
From the Microsoft 365 Defender portal, you plan to export a detailed report of compromised users.
What is the longest time range that can be included in the report?

  • A. 1 day
  • B. 7 days
  • C. 30 days
  • D. 90 days
Reveal Solution Hide Solution   Discussion   41

Correct Answer: A 🗳️

Community vote distribution
A (56%)
C (36%)
8%

Question #73 Topic 1

HOTSPOT -
You have a Microsoft 365 subscription.
You deploy the anti-phishing policy shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Reveal Solution Hide Solution   Discussion   8

Correct Answer:

Question #74 Topic 1

HOTSPOT -
You use Microsoft Defender for Endpoint.
You have the Microsoft Defender for Endpoint device groups shown in the following table.

You plan to onboard computers to Microsoft Defender for Endpoint as shown in the following table.

To which device group will each computer be added? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Reveal Solution Hide Solution   Discussion   9

Correct Answer:

Question #75 Topic 1

DRAG DROP -
You have a Microsoft 365 subscription that uses Microsoft Defender for Office 365.
You need to configure policies to meet the following requirements:
Customize the common attachments filter.
Enable impersonation protection for sender domains.
Which type of policy should you configure for each requirement? To answer, drag the appropriate policy types to the correct requirements. Each policy type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Reveal Solution Hide Solution   Discussion   10

Correct Answer:

Question #76 Topic 1

You have an Azure AD tenant and a Microsoft 365 E5 subscription. The tenant contains the users shown in the following table.

You plan to implement Microsoft Defender for Endpoint.
You verify that role-based access control (RBAC) is turned on in Microsoft Defender for Endpoint.
You need to identify which user can view security incidents from the Microsoft 365 Defender portal.
Which user should you identify?

  • A. User1
  • B. User2
  • C. User3
  • D. User4
Reveal Solution Hide Solution   Discussion   17

Correct Answer: A 🗳️

Community vote distribution
A (70%)
C (30%)

Question #77 Topic 1

HOTSPOT -
You have a Microsoft 365 E5 subscription.
All company-owned Windows 11 devices are onboarded to Microsoft Defender for Endpoint.
You need to configure Defender for Endpoint to meet the following requirements:
Block a vulnerable app until the app is updated.
Block an application executable based on a file hash.
The solution must minimize administrative effort.
What should you configure for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Reveal Solution Hide Solution   Discussion   4

Correct Answer:

Question #78 Topic 1

HOTSPOT -
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint and contains the devices shown in the following table.

Defender for Endpoint has the device groups shown in the following table.

You create an incident email notification rule configured as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Reveal Solution Hide Solution   Discussion   12

Correct Answer:

Question #79 Topic 1

You have a Microsoft 365 tenant that contains two users named User1 and User2.
You create the alert policy shown in the following exhibit.

User2 runs a script that modifies a file in a Microsoft SharePoint library once every four minutes and runs for a period of two hours.
How many alerts will User1 receive?

  • A. 2
  • B. 5
  • C. 10
  • D. 25
  • E. 30
Reveal Solution Hide Solution   Discussion   19

Correct Answer: A 🗳️

Community vote distribution
A (70%)
D (28%)
3%

Question #80 Topic 1

Your company has 10,000 users who access all applications from an on-premises data center.
You plan to create a Microsoft 365 subscription and to migrate data to the cloud.
You plan to implement directory synchronization.
User accounts and group accounts must sync to Azure AD successfully.
You discover that several user accounts fail to sync to Azure AD.
You need to resolve the issue as quickly as possible.
What should you do?

  • A. From Active Directory Administrative Center, search for all the users, and then modify the properties of the user accounts.
  • B. Run idfix.exe, and then click Edit.
  • C. From Windows PowerShell, run the start-AdSyncSyncCycle -PolicyType Delta command.
  • D. Run idfix.exe, and then click Complete.
Reveal Solution Hide Solution   Discussion   3

Correct Answer: B 🗳️

Community vote distribution
B (100%)

Previous Questions
file Viewing page 8 out of 39 pages.
Viewing questions 71-80 out of 383 questions
Next Questions
Browse atleast 50% to increase passing rate cup
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Loading ...