MS-102 Sample Questions & Answers
Handling security and threats through Defender XDR carries the most weight, alongside deploying the tenant and managing users, groups and roles, Entra identity sync and secure access, and compliance through Microsoft Purview.
Launch the full MS-102 simulator →Showing 9 of 19 free samples.
- Question 1Advanced
Implement and manage Microsoft Entra identity and access · Implement and manage secure access
Case Study: Weyland-Yutani Corporation
Company Background:
Weyland-Yutani Corporation is a multinational conglomerate with a significant investment in off-world colony development. They have 50,000 employees globally and a hybrid Active Directory environment. Their on-premises Active Directory (AD) is namedweyland.corpand they have a verified domainw-y.comin their Microsoft 365 E5 tenant. Identity synchronization is managed by Microsoft Entra Connect Sync, with Password Hash Synchronization enabled.Current Situation:
The corporation's security team has detected suspicious sign-in activity. Analysis of Microsoft Entra sign-in logs shows multiple failed login attempts from anonymous IP addresses targeting high-privilege accounts, followed by a successful sign-in from an unfamiliar location for one of the accounts. The successful sign-in occurred for a user who is a member of the 'Colony Admin' role-assignable security group. This group is used to grant administrative permissions to a critical Azure application.Security Requirements:
- Administrators must only be able to activate their privileged roles when needed, and for a limited duration.
- Activation of a privileged role must require justification and an optional approval workflow.
- High-risk sign-ins detected by Microsoft Entra ID Protection must automatically trigger a requirement for multi-factor authentication and force a password reset.
- Membership in the 'Colony Admin' group must be reviewed quarterly by the group owners.
Problem:
You are a Microsoft 365 administrator tasked with implementing a solution that meets all the security requirements to prevent a similar incident in the future. Which combination of services and configurations provides the most comprehensive solution?Show answer & explanation
Correct answer: B
This option correctly addresses all four security requirements. PIM for Groups provides just-in-time membership with justification and approval workflows (Reqs 1 & 2). The user risk policy in ID Protection enforces password resets for high-risk users (Req 3). Access Reviews for the group ensures quarterly validation of membership (Req 4). The sign-in risk policy in ID Protection (which can be configured alongside the user risk policy) can enforce MFA for high-risk sign-ins.
- Question 2Beginner
Deploy and manage a Microsoft 365 tenant · Implement and manage a Microsoft 365 tenant
A new Microsoft 365 administrator is reviewing the organization's network connectivity to Microsoft 365 services. In the Microsoft 365 admin center, they navigate to Health > Network connectivity. They observe a low network connectivity score for the Chicago office, with specific issues related to high TCP latency. The administrator needs to identify the recommended network egress point for optimal connectivity from the Chicago office. What should the administrator check in the Network connectivity tool?
Show answer & explanation
Correct answer: B
The Network connectivity tool in the Microsoft 365 admin center specifically identifies the 'Optimal service front door' for a given location. This is the closest entry point into Microsoft's global network. The tool compares the user's actual egress point to this optimal location and provides recommendations. High latency often indicates that traffic is not egressing from the network optimally.
- Question 3Intermediate
Manage compliance by using Microsoft Purview · Implement Microsoft Purview information protection and data lifecycle management
A manufacturing company uses Microsoft 365. The legal department requires that all email communications related to a specific project, codenamed 'Project Titan', be preserved for 10 years, regardless of user actions. The project involves members from multiple departments. The solution must ensure that the preserved data is discoverable. What is the most appropriate tool to meet this requirement?
Show answer & explanation
Correct answer: C
For legal matters like preserving data for a specific project or investigation, an eDiscovery case with a hold is the most appropriate tool. It allows you to place a hold on specific content locations (like mailboxes) based on keywords (like 'Project Titan'). This preserves the data in place for discovery and legal purposes, which directly aligns with the legal department's requirements.
- Question 4Advanced
Manage security and threats by using Microsoft Defender XDR · Review and respond to security reports and alerts generated by Microsoft Defender XDR
A consultant is reviewing a company's Microsoft Secure Score. They notice a significant number of points can be gained by implementing an improvement action titled 'Enable policy to block legacy authentication'. The company is concerned this will break an essential on-premises line-of-business application that uses SMTP AUTH to send email notifications. What is the recommended approach to implement the improvement action while maintaining application functionality?
Show answer & explanation
Correct answer: D
The best practice is to block legacy authentication broadly using Conditional Access. However, since Conditional Access policies do not apply to SMTP AUTH for Exchange Online, you must also manage this protocol at the service level. The correct method is to disable it tenant-wide and then create a specific Exchange Online authentication policy to re-enable SMTP AUTH only for the specific service account that needs it. This follows the principle of least privilege.
- Question 5Beginner
Deploy and manage a Microsoft 365 tenant · Manage users and groups
During a tenant-to-tenant migration, an administrator needs to invite a large number of users from the source tenant (
source.com) as guests into the destination tenant (dest.com). To streamline the process, the administrator wants to use the bulk invite feature in Microsoft Entra ID. The PowerShell command to initiate this isNew-AzureADMSInvitation. Which file format is required to upload the user information for the bulk invite?Invite-User -InvitedUserEmailAddress -InviteRedirectUrl -SendInvitationMessage $true -InvitedUserDisplayNameWait, the question is asking about bulk invites, not a single user invite. Let me re-evaluate the question and cmdlet. The PowerShell cmdlet for bulk operations is different. The portal uses a specific file format. The question is about the file format for the portal's bulk invite feature.
Let me correct the question context. The administrator is using the Microsoft Entra admin center's bulk user invite feature. What is the required format for the file containing the user data to be uploaded?
Show answer & explanation
Correct answer: D
The bulk invite feature in the Microsoft Entra admin center requires a .CSV file. The portal provides a template that specifies the required columns, such as the guest's email address, the redirect URL after they accept the invitation, and a custom invitation message.
- Question 6Intermediate
Manage compliance by using Microsoft Purview · Implement Microsoft Purview data loss prevention (DLP)
A retail company is concerned about accidental oversharing of sensitive data by employees using Microsoft Teams chat and channels. They need to implement a policy that blocks messages containing credit card numbers from being shared with external users, but only generates a warning for internal sharing. Which Microsoft Purview solution should be configured to meet this requirement?
Show answer & explanation
Correct answer: B
Microsoft Purview Data Loss Prevention (DLP) policies are designed to identify sensitive information and prevent its inappropriate sharing. A DLP policy can be configured to detect credit card numbers (a built-in sensitive information type), scoped to Microsoft Teams, and have rules that apply different actions (block vs. warn) based on whether the recipient is internal or external to the organization.
- Question 7Intermediate
Deploy and manage a Microsoft 365 tenant · Manage roles and role groups
An administrator is managing a Microsoft 365 tenant and needs to delegate permissions to a regional IT team to manage users and licenses only for employees in the 'Europe' department. The administrator wants to avoid assigning a highly privileged built-in role like User Administrator, which has a tenant-wide scope. Which Microsoft Entra feature should be used to achieve this scoped delegation?
┌────────────────── Tenant (Global) ──────────────────┐ │ │ │ ┌─── US Users ───┐ ┌─── Europe Users ───┐ │ │ │ │ │ │ │ │ │ [User1, User2] │ │ [User3, User4] │ │ │ └─────────────────┘ └────────────────────┘ │ │ │ │ [Regional IT Team] needs access to │ │ manage ONLY Europe Users. │ │ │ └─────────────────────────────────────────────────────┘Show answer & explanation
Correct answer: C
Administrative Units (AUs) are the designated feature in Microsoft Entra ID for creating subdivisions within a tenant to delegate administrative permissions with a restricted scope. The administrator can create an AU for 'Europe', add the relevant users and the regional IT team to it, and then assign a role like User Administrator to the IT team scoped only to that AU.
- Question 8Intermediate
Manage security and threats by using Microsoft Defender XDR · Implement and manage Microsoft Defender for Cloud Apps
An organization has configured Microsoft Defender for Cloud Apps. A security analyst is investigating an alert indicating that a user has downloaded an unusually large amount of data from SharePoint Online. The analyst needs to review the specific files that were downloaded. Where in the Microsoft 365 Defender portal should the analyst look for this detailed information?
Show answer & explanation
Correct answer: C
The Activity log in Microsoft Defender for Cloud Apps provides a detailed audit trail of user activities in connected cloud applications. For a large download from SharePoint, the analyst can filter the Activity log by the user, the application (SharePoint Online), and the activity type (File Downloaded) to see the specific files, their paths, and other relevant metadata.
- Question 9Intermediate
Deploy and manage a Microsoft 365 tenant · Implement and manage a Microsoft 365 tenant
A law firm has just enabled Microsoft 365 Backup for their SharePoint Online environment. A paralegal accidentally deletes a critical client folder containing hundreds of documents. The deletion happened 12 hours ago. The firm needs to restore the folder to its original location with the highest possible fidelity. Which statement is true regarding the restoration process?
Show answer & explanation
Correct answer: D
Microsoft 365 Backup provides high-speed, point-in-time restore capabilities. It allows an administrator to restore an entire SharePoint site, including its contents like the deleted folder, to a specific point in the past. This process restores the content to its original location without overwriting changes made to other files after the chosen restore point, ensuring high fidelity.
Ready for the real thing?
The full MS-102 simulator has every exam-style question, timed mode, and instant scoring.