MS-102 Actual Exam Questions

Last updated on May 30, 2025.
Vendor:Microsoft
Exam Code:MS-102
Exam Name:Microsoft 365 Administrator
Exam Questions:383
Question #321 Topic 1

HOTSPOT
-

You have a Microsoft 365 E5 subscription that contains three users named User1, User2, and User3.

You use Microsoft Entra ID Protection.

You configure the Users at risk detected alerts setting to send an alert when a user risk level of low or above is detected.

Users are assigned the risk levels shown in the following table.



By the end of the day, how many alerts were generated for User1, and how many alerts were generated for User2 and User3? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Reveal Solution Hide Solution   Discussion   4

Correct Answer:

Question #322 Topic 1

You have a Microsoft 365 E5 subscription.

You plan to implement a data loss prevention (DLP) strategy by using Microsoft Purview.

You need to recommend a classification method for a DLP condition. The classification method must automatically recognize document types based on existing documents in Microsoft SharePoint Online.

What should you recommend?

  • A. sensitive information types (SITs)
  • B. sensitivity labels
  • C. trainable classifiers
  • D. exact data match (EDM) classifiers
Reveal Solution Hide Solution   Discussion   2

Correct Answer: C 🗳️

Community vote distribution
C (100%)

Question #323 Topic 1

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Endpoint.

You integrate Microsoft Defender for Endpoint with Microsoft Intune.

From Microsoft Defender Vulnerability Management, you review the top security recommendations and discover a recommendation to update Microsoft Edge (Chromium) to a later version.

You need to ensure that a security task is added to Intune to address the recommendation.

What should you do?

  • A. From the Microsoft Intune admin center, configure Windows Autopatch.
  • B. From the Microsoft Intune admin center, configure a security baseline.
  • C. From the Microsoft Defender portal, select Request remediation.
  • D. From the Microsoft Defender portal add an incident notification rule.
Reveal Solution Hide Solution   Discussion   2

Correct Answer: C 🗳️

Community vote distribution
C (100%)

Question #324 Topic 1

HOTSPOT
-

You have an Azure subscription.

You have a Microsoft 365 E5 subscription.

You are licensed to use Microsoft Defender XDR.

You need to monitor activities from suspicious IP addresses and unusual administrative activities in Azure.

What should you use to monitor the activities, and what should you use to integrate Azure with Microsoft Defender XDR? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Reveal Solution Hide Solution   Discussion   8

Correct Answer:

Question #325 Topic 1

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps.

The subscription contains users that have Windows 11 devices.

You need to use the Cloud Discovery snapshot report to analyze cloud app usage on the devices.

What should you do before generating a report?

  • A. Create an activity policy.
  • B. Deploy the Azure Monitor Agent on the devices.
  • C. Export traffic logs from firewalls and proxies.
  • D. Create an app discovery policy.
Reveal Solution Hide Solution   Discussion   3

Correct Answer: C 🗳️

Community vote distribution
C (100%)

Question #326 Topic 1

DRAG DROP
-

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps.

You need to configure Cloud Discovery to generate a report that identifies top potential risks and provides a workflow to mitigate and manage the risks.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Reveal Solution Hide Solution   Discussion   9

Correct Answer:

Question #327 Topic 1

HOTSPOT
-

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps.

You need to create a file policy named Policy1 that meets the following requirements:

• Inspects files in connected software as a service (SaaS) apps
• Inspects protected files

Which two settings should you configure? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Reveal Solution Hide Solution   Discussion   2

Correct Answer:

Question #328 Topic 1

You have a Microsoft 365 E5 subscription.

You plan to create an anti-malware policy named Policy1.

You need to ensure that Policy1 can detect malicious email messages that were already delivered to a user's mailbox.

What should you do in the Microsoft Defender portal?

  • A. Enable zero-hour auto purge (ZAP).
  • B. Enable enhanced filtering.
  • C. Configure a quarantine policy.
  • D. Modify the common attachments filter.
Reveal Solution Hide Solution   Discussion   4

Correct Answer: A 🗳️

Community vote distribution
A (83%)
B (17%)

Question #329 Topic 1

You have a Microsoft 365 E5 subscription.

You need to use Microsoft Defender for Cloud Apps to monitor user mailbox activities.

What should you do?

  • A. Create an activity policy.
  • B. Create an access policy.
  • C. Enable mailbox audit logging.
  • D. Create an app connector for Microsoft 365.
Reveal Solution Hide Solution   Discussion   15

Correct Answer: A 🗳️

Community vote distribution
A (39%)
C (39%)
D (22%)

Question #330 Topic 1

HOTSPOT
-

You have a Microsoft 365 E5 subscription that contains a user named User1. User1 has a Windows 11 device named Device1 that is onboarded to Microsoft Defender for Endpoint.

User1 reports that various files were deleted from Device1.

You need to create a filter to identify which service deleted the files.

Which settings should you configure, and which type of filter should you create in the Microsoft Defender portal? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Reveal Solution Hide Solution   Discussion   2

Correct Answer:

Previous Questions
file Viewing page 33 out of 39 pages.
Viewing questions 321-330 out of 383 questions
Next Questions
Browse atleast 50% to increase passing rate cup
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Loading ...