Microsoft 365 Administrator - MS-102 Exam Practice Test
Question 1
HOTSPOT
You have a Microsoft 365 E5 subscription.
You need to meet the following requirements:
Automatically encrypt documents stored in Microsoft OneDrive and SharePoint.
Enable co-authoring for Microsoft Office documents encrypted by using a sensitivity label.
Which two settings should you use in the Microsoft Purview compliance portal? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 subscription.
You need to meet the following requirements:
Automatically encrypt documents stored in Microsoft OneDrive and SharePoint.
Enable co-authoring for Microsoft Office documents encrypted by using a sensitivity label.
Which two settings should you use in the Microsoft Purview compliance portal? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:

Box 1: Information protection
Automatically encrypt documents stored in Microsoft OneDrive and SharePoint.
How to integrate Microsoft Purview Information Protection with Defender for Cloud Apps Enable Microsoft Purview Information Protection All you have to do to integrate Microsoft Purview Information Protection with Defender for Cloud Apps is select a single checkbox. By enabling automatic scan, you enable searching for sensitivity labels from Microsoft Purview Information Protection on your Office 365 files without the need to create a policy. After you enable it, if you have files in your cloud environment that are labeled with sensitivity labels from Microsoft Purview Information Protection, you ' ll see them in Defender for Cloud Apps.
To enable Defender for Cloud Apps to scan files with content inspection enabled for sensitivity labels:
In the Microsoft Defender XDR portal, select Settings. Then choose Cloud Apps. Then go to Information Protection - > Microsoft Information Protection.
Note: Encryption of data at rest
Encryption at rest includes two components: BitLocker disk-level encryption and per-file encryption of customer content.
BitLocker is deployed for OneDrive for Business and SharePoint Online across the service. Per-file encryption is also in OneDrive for Business and SharePoint Online in Microsoft 365 multi-tenant and new dedicated environments that are built on multi-tenant technology.
Box 2: Settings
Enable co-authoring for Microsoft Office documents encrypted by using a sensitivity label.
1. Sign in to the Microsoft Purview compliance portal as a global admin for your tenant.
2. From the navigation pane, select Settings > Co-authoring for files with sensitivity files.
3. On the Co-authoring for files with sensitivity labels page, read the summary description, prerequisites, and what to expect.
4. Then select Turn on co-authoring for files with sensitivity labels, and Apply.
5. Wait 24 hours for this setting to replicate across your environment before you use this new feature for co- authoring.
Reference:
https://learn.microsoft.com/en-us/defender-cloud-apps/azip-integration
https://learn.microsoft.com/en-us/microsoft-365/compliance/sensitivity-labels-coauthoring
Question 2
You have a Microsoft 365 E5 subscription that contains two users named Admin1 and Admin2.
All users are assigned a Microsoft 365 Enterprise E5 license and auditing is turned on.
You create the audit retention policy shown in the exhibit. (Click the Exhibit tab.)

After Policy1 is created, the following actions are performed:
Admin1 creates a user named User1.
Admin2 creates a user named User2.
How long will the audit events for the creation of User1 and User2 be retained? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

All users are assigned a Microsoft 365 Enterprise E5 license and auditing is turned on.
You create the audit retention policy shown in the exhibit. (Click the Exhibit tab.)

After Policy1 is created, the following actions are performed:
Admin1 creates a user named User1.
Admin2 creates a user named User2.
How long will the audit events for the creation of User1 and User2 be retained? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/audit-log-retention-policies?view=o365-worldwide
Question 3
You have a Microsoft 365 E5 subscription.
You plan to create an anti-malware policy named Policy1.
You need to ensure that Policy1 can detect malicious email messages that were already delivered to a user ' s mailbox.
What should you do in the Microsoft Defender portal?
You plan to create an anti-malware policy named Policy1.
You need to ensure that Policy1 can detect malicious email messages that were already delivered to a user ' s mailbox.
What should you do in the Microsoft Defender portal?
Correct Answer: A
Question 4
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

Which users can create user objects, and which users can create Microsoft 365 groups? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


Which users can create user objects, and which users can create Microsoft 365 groups? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
User objects
User2 only
Microsoft 365 groups
User1, User2, and User3
User2 only can create user objects because User2 has the User Administrator role. Microsoft's Microsoft Entra built-in role reference states that the User Administrator role includes the permission to create users and manage users. The Groups Administrator role is scoped to group management, not user object creation. The Teams Administrator role manages the Teams workload and does not grant general Microsoft Entra user creation rights.
For Microsoft 365 groups, the correct selection is User1, User2, and User3. Microsoft states that the Groups Administrator role can create and manage groups across workloads, including Teams, SharePoint, Yammer, and Outlook, so User1 qualifies. The User Administrator role includes the ability to create and manage all groups, so User2 qualifies. The Teams Administrator role also explicitly grants the ability to create and manage all Microsoft 365 groups, because Teams administration depends on Microsoft 365 group-backed teams.
Therefore, choose User2 only for user objects and User1, User2, and User3 for Microsoft 365 groups.
Question 5
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 subscription.
From the Microsoft Defender XDR, you create a role group named US eDiscovery Managers by copying the eDiscovery Manager role group.
You need to ensure that the users in the new role group can only perform content searches of mailbox content for users in the United States.
Solution: From the Microsoft Defender XDR, you modify the roles of the US eDiscovery Managers role group.
Does this meet the goal?
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 subscription.
From the Microsoft Defender XDR, you create a role group named US eDiscovery Managers by copying the eDiscovery Manager role group.
You need to ensure that the users in the new role group can only perform content searches of mailbox content for users in the United States.
Solution: From the Microsoft Defender XDR, you modify the roles of the US eDiscovery Managers role group.
Does this meet the goal?
Correct Answer: A
Question 6
You have a Microsoft 365 E5 subscription that contains the users shown in the following table:

You use Microsoft Entra ID Protection.
For the Users at risk detected alerts setting, you configure the following:
Recipient: Admin1
Alert on user risk level at or above: Medium
User1 signs in to Microsoft 365 services and is assigned the detected risk levels shown in the following table:

For each of the following statements, select Yes if the statement is true. Otherwise, select No.


You use Microsoft Entra ID Protection.
For the Users at risk detected alerts setting, you configure the following:
Recipient: Admin1
Alert on user risk level at or above: Medium
User1 signs in to Microsoft 365 services and is assigned the detected risk levels shown in the following table:

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Correct Answer:

Explanation:
Statement
Answer
By the end of the day, Admin1 has received two email alerts.
No
By the end of the day, Admin2 has received three email alerts.
Yes
By the end of the day, Admin3 has received three email alerts.
No
Microsoft Entra ID Protection sends Users at risk detected email alerts when a user's risk level reaches the configured threshold. Here, the threshold is Medium or above, so the 1:00 PM Low risk event does not generate an alert. The 2:00 PM Medium event generates one alert, the 3:00 PM Medium event generates another because Microsoft states that later risk detections can trigger additional emails even if the recalculated risk remains at the configured level, and the 4:00 PM High event generates a third alert because it is still above the configured threshold. Microsoft also states that extra emails are suppressed only within a five- second period; these events are one hour apart, so that suppression rule does not reduce the count.
Admin1 receives the alerts because Admin1 is explicitly configured as a recipient, but the statement says two alerts; the correct count is three, so it is No. Admin2 receives three alerts because Security Reader users are automatically included by default for ID Protection notifications when they have a valid email or alternate email. Admin3 does not receive the alerts because User Administrator is not one of the automatically included roles and is not configured as a recipient.
Question 7
You have a Microsoft 365 subscription that contains the users shown in the following table.

You need to configure group-based licensing to meet the following requirements:
To all users, deploy an Office 365 E3 license without the Power Automate license option.
To all users, deploy an Enterprise Mobility + Security E5 license.
To the users in the research department only, deploy a Power BI Pro license.
To the users in the marketing department only, deploy a Visio Plan 2 license.
What is the minimum number of deployment groups required?

You need to configure group-based licensing to meet the following requirements:
To all users, deploy an Office 365 E3 license without the Power Automate license option.
To all users, deploy an Enterprise Mobility + Security E5 license.
To the users in the research department only, deploy a Power BI Pro license.
To the users in the marketing department only, deploy a Visio Plan 2 license.
What is the minimum number of deployment groups required?
Correct Answer: D
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 8
You have a Microsoft 365 E5 subscription that contains a user named User1.
You have a Conditional Access policy applied to a cloud-based app named App1. App1 has Conditional Access App Control deployed.
You need to create a Microsoft Defender for Cloud Apps policy to block User1 from printing from App1.
You have a Conditional Access policy applied to a cloud-based app named App1. App1 has Conditional Access App Control deployed.
You need to create a Microsoft Defender for Cloud Apps policy to block User1 from printing from App1.
Correct Answer: B
Question 9
You have a Microsoft 365 E5 tenant that contains the devices shown in the following table.

You plan to implement attack surface reduction (ASR) rules. Which devices will support the ASR rules?

You plan to implement attack surface reduction (ASR) rules. Which devices will support the ASR rules?
Correct Answer: B
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 10
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the users shown in the following table.

The domain syncs to an Microsoft Entra tenant named contoso.com as shown in the exhibit. (Click the Exhibit tab.)

User2 fails to authenticate to Microsoft Entra ID when signing in as [email protected].
You need to ensure that User2 can access the resources in Microsoft Entra ID.
Solution: From the Microsoft Entra admin center, you assign User2 the Security Reader role. You instruct User2 to sign in as [email protected].
Does this meet the goal?
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the users shown in the following table.

The domain syncs to an Microsoft Entra tenant named contoso.com as shown in the exhibit. (Click the Exhibit tab.)

User2 fails to authenticate to Microsoft Entra ID when signing in as [email protected].
You need to ensure that User2 can access the resources in Microsoft Entra ID.
Solution: From the Microsoft Entra admin center, you assign User2 the Security Reader role. You instruct User2 to sign in as [email protected].
Does this meet the goal?
Correct Answer: A
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 11
You have a Microsoft 365 E5 subscription that uses Microsoft intune.
in the Microsoft Endpoint Manager admin center, you discover many stale and inactive devices, You enable device clean-up rules What can you configure as the minimum number of days before a device a removed automatically?
in the Microsoft Endpoint Manager admin center, you discover many stale and inactive devices, You enable device clean-up rules What can you configure as the minimum number of days before a device a removed automatically?
Correct Answer: B
Question 12
You have an Microsoft Entra ID (Microsoft Entra ID) tenant that contains a user named User1.
Your company purchases a Microsoft 365 subscription.
You need to ensure that User1 is assigned the required role to create file policies and manage alerts in the Cloud App Security admin center.
Solution: From the Microsoft Entra ID admin center, you assign the Compliance administrator role to User1.
Does this meet the goal?
Your company purchases a Microsoft 365 subscription.
You need to ensure that User1 is assigned the required role to create file policies and manage alerts in the Cloud App Security admin center.
Solution: From the Microsoft Entra ID admin center, you assign the Compliance administrator role to User1.
Does this meet the goal?
Correct Answer: B
Question 13
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 E5 subscription.
You create an account for a new security administrator named SecAdmin1.
You need to ensure that SecAdmin1 can manage Microsoft Defender for Office 365 settings and policies for Microsoft Teams, SharePoint, and OneDrive.
Solution: From the Microsoft 365 admin center, you assign SecAdmin1 the Exchange Administrator role.
Does this meet the goal?
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 E5 subscription.
You create an account for a new security administrator named SecAdmin1.
You need to ensure that SecAdmin1 can manage Microsoft Defender for Office 365 settings and policies for Microsoft Teams, SharePoint, and OneDrive.
Solution: From the Microsoft 365 admin center, you assign SecAdmin1 the Exchange Administrator role.
Does this meet the goal?
Correct Answer: A
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 14
You have a Microsoft 365 subscription.
You create a Microsoft Defender Threat Intelligence (Defender Tl) project named Project!
You need to add artifacts to Project 1
Which type of artifact can you add to Project1?
You create a Microsoft Defender Threat Intelligence (Defender Tl) project named Project!
You need to add artifacts to Project 1
Which type of artifact can you add to Project1?
Correct Answer: A

