ExamGecko
Home Home / Microsoft / MS-102

Microsoft MS-102 Practice Test - Questions Answers, Page 17

Question list
Search
Search

List of questions

Search

Related questions











You have a Microsoft 365 E5 tenant.

The Microsoft Secure Score for the tenant is shown in the following exhibit.

You plan to enable Security defaults for Azure Active Directory (Azure AD).

Which three improvement actions will this affect?

A.

Require MFA for administrative roles.

A.

Require MFA for administrative roles.

Answers
B.

Ensure all users can complete multi-factor authentication for secure access

B.

Ensure all users can complete multi-factor authentication for secure access

Answers
C.

Enable policy to block legacy authentication

C.

Enable policy to block legacy authentication

Answers
D.

Enable self-service password reset

D.

Enable self-service password reset

Answers
E.

Use limited administrative roles

E.

Use limited administrative roles

Answers
Suggested answer: A, B, C

Explanation:

https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/concept-fundamentals-security-defaults

You have a Microsoft 365 E5 subscription.

You need to identify which users accessed Microsoft Office 365 from anonymous IP addresses during the last seven days.

What should you do?

A.

From the Cloud App Security admin center, select Users and accounts.

A.

From the Cloud App Security admin center, select Users and accounts.

Answers
B.

From the Microsoft 365 security center, view the Threat tracker.

B.

From the Microsoft 365 security center, view the Threat tracker.

Answers
C.

From the Microsoft 365 admin center, view the Security & compliance report.

C.

From the Microsoft 365 admin center, view the Security & compliance report.

Answers
D.

From the Azure Active Directory admin center, view the Risky sign-ins report.

D.

From the Azure Active Directory admin center, view the Risky sign-ins report.

Answers
Suggested answer: A

HOTSPOT

You have a Microsoft 365 tenant that contains 100 Windows 10 devices. The devices are managed by using Microsoft Endpoint Manager.

You plan to create two attack surface reduction (ASR) policies named ASR1 and ASR2. ASR1 will be used to configure Microsoft Defender Application Guard. ASR2 will be used to configure Microsoft Defender SmartScreen.

Which ASR profile type should you use for each policy? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 163
Correct answer: Question 163

Explanation:

https://docs.microsoft.com/en-us/mem/intune/protect/endpoint-security-asr-policy

HOTSPOT

You have a Microsoft 365 tenant that has Enable Security defaults set to No in Azure Active Directory (Azure AD).

The tenant has two Compliance Manager assessments as shown in the following table.

The SP800 assessment has the improvement actions shown in the following table.

You perform the following actions:

For the Data Protection Baseline assessment, change the Test status of Establish a threat intelligence program to Implemented.

Enable multi-factor authentication (MFA) for all users.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.


Question 164
Correct answer: Question 164

Explanation:

https://docs.microsoft.com/en-us/microsoft-365/compliance/compliance-manager-assessments?view=o365-worldwide#create-assessments

https://docs.microsoft.com/en-us/microsoft-365/compliance/compliance-score-calculation?view=o365-worldwide#action-types-and-points

You have a Microsoft 365 tenant.

Company policy requires that all Windows 10 devices meet the following minimum requirements:

Require complex passwords.

Require the encryption of data storage devices.

Have Microsoft Defender Antivirus real-time protection enabled.

You need to prevent devices that do not meet the requirements from accessing resources in the tenant.

Which two components should you create? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

a configuration policy

A.

a configuration policy

Answers
B.

a compliance policy

B.

a compliance policy

Answers
C.

a security baseline profile

C.

a security baseline profile

Answers
D.

a conditional access policy

D.

a conditional access policy

Answers
E.

a configuration profile

E.

a configuration profile

Answers
Suggested answer: B, D

Explanation:

https://docs.microsoft.com/en-us/mem/intune/protect/device-compliance-get-started

You have a Microsoft 365 E5 tenant.

You need to ensure that when a document containing a credit card number is added to the tenant, the document is encrypted.

Which policy should you use?

A.

a retention policy

A.

a retention policy

Answers
B.

a retention label policy

B.

a retention label policy

Answers
C.

an auto-labeling policy

C.

an auto-labeling policy

Answers
D.

an insider risk policy

D.

an insider risk policy

Answers
Suggested answer: C

Explanation:

https://docs.microsoft.com/en-us/microsoft-365/compliance/apply-sensitivity-label-automatically?view=o365-worldwide

DRAG DROP

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1.

You need to automatically label the documents on Site1 that contain credit card numbers.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.



Question 167
Correct answer: Question 167

Explanation:

https://docs.microsoft.com/en-us/microsoft-365/compliance/sensitivity-labels?view=o365-worldwide#what-label-policies-can-do

https://docs.microsoft.com/en-us/microsoft-365/compliance/apply-sensitivity-label-automatically?view=o365-worldwide

HOTSPOT

You have a Microsoft 365 tenant that contains the compliance policies shown in the following table.

The tenant contains the devices shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.


Question 168
Correct answer: Question 168

DRAG DROP

You have a Microsoft 365 subscription.

You have the devices shown in the following table.

You plan to join the devices to Azure Active Directory (Azure AD)

What should you do on each device to support Azure AU join? To answer, drag the appropriate actions to the collect devices, Each action may be used once, more than once, of not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.


Question 169
Correct answer: Question 169

HOTSPOT

Your on-premises network contains an Active Directory domain and a Microsoft Endpoint Configuration Manager site.

You have a Microsoft 365 E5 subscription that uses Microsoft Intune.

You use Azure AD Connect to sync user objects and group objects to Azure Directory (Azure AD) Password hash synchronization is disabled.

You plan to implement co-management.

You need to configure Azure AD Connect and the domain to support co-management.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 170
Correct answer: Question 170
Total 467 questions
Go to page: of 47