Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Microsoft 365 Certified: Enterprise Administrator Expert MS-102 Questions and answers with ValidTests

Exam MS-102 All Questions
Exam MS-102 Premium Access

View all detail and faqs for the MS-102 exam

Viewing page 11 out of 12 pages
Viewing questions 151-165 out of questions
Questions # 151:

You have a Microsoft 365 E5 subscription that contains the security groups shown in the following table.

Question # 151

The subscription contains the users shown in the following table.

Question # 151

You have a Conditional Access policy that has the following settings:

• Assignments

o Users

■ Include: Group1

■ Exclude: Group2. Group3

o Target resources

■ Cloud apps

■ App1

■ Access controls

■ Grant

■ Block access

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 151

Options:

Questions # 152:

: 235

You have a Microsoft 365 tenant that is signed up for Microsoft Store for Business and contains a user named User1. You need to ensure that User1 can perform the following tasks in Microsoft Store for Business:

• Assign licenses to users.

• Procure apps from Microsoft Store.

• Manage private store availability for all items.

The solution must use the principle of least privilege.

Which Microsoft Store for Business role should you assign to User1?

Options:

A.

Basic Purchaser

B.

Device Guard signer

C.

Admin

D.

Purchaser

Questions # 153:

You configure a data loss prevention (DLP) policy named DLP1 as shown in the following exhibit.

Question # 153

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Question # 153

Options:

Questions # 154:

You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.

Question # 154

You plan to create 10 new users and configure group-based licensing to assign each user a Microsoft 365 E5 license.

To which group should you add the users, and which portal should you use to assign the license? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 154

Options:

Questions # 155:

You need to configure Microsoft Entra Connect Sync to support the planned changes for the Montreal Users and Seattle Users OUs.

What should you do?

Options:

A.

From PowerShell, run the Add-ADSyncConnectorAttributeInclusion cmdlet.

B.

From the Microsoft Entra Connect wizard, select Customize synchronization options.

C.

From PowerShell, run the Start-ADSyncSyncCycle cmdlet.

D.

From the Microsoft Entra Connect wizard, select Manage federation.

Questions # 156:

You have a Microsoft 365 subscription that includes Microsoft Intune and Microsoft Defender XDR.

All users have devices that run Windows 11.

From the Microsoft Defender portal, you review the Microsoft Secure Score recommendations. One of the top recommendations is to block all Microsoft Office applications from creating child processes.

You need to increase the secure score by addressing the recommendation.

What should you do?

Options:

A.

Create an attack surface reduction (ASR) policy.

B.

Configure an endpoint detection and response (EDR) policy.

C.

Create a policy for Office applications.

D.

Select Safe Documents for Office clients.

Questions # 157:

: 221

You have a Microsoft 365 E5 subscription.

Users have the devices shown in the following table.

Question # 157

On which devices can you manage apps by using app configuration policies in Microsoft Endpoint Manager?

Options:

A.

Device1, Device4, and Device6

B.

Device2, Device3, and Device5

C.

Device1, Device2, Device3, and Device6

D.

Device1, Device2, Device4, and Device5

Questions # 158:

You have a Microsoft 365 subscription that uses Microsoft Defender for Office 365.

A Built-in protection preset security policy is applied to the subscription.

Which two policy types will be applied by the Built-in protection policy? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

Options:

A.

Anti-malware

B.

Anti-phishing

C.

Safe Attachments

D.

Anti-spam

E.

Safe Links

Questions # 159:

You have a Microsoft 365 E5 subscription that contains the groups shown in the following exhibit.

Question # 159

To which groups can you assign Microsoft 365 E5 licenses?

Options:

A.

Group! and Group2 only

B.

Group2 and Group3 only

C.

Group3 and Group4 only

D.

Group 1, Group2. and Group3 only

E.

Group2, Group3, and Group4 only

Questions # 160:

You have a Microsoft 365 subscription.

You have the devices shown in the following table.

Question # 160

You plan to join the devices to Azure Active Directory (Azure AD)

What should you do on each device to support Azure AU join? To answer, drag the appropriate actions to the collect devices, Each action may be used once, more than once, of not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 160

Options:

Questions # 161:

Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the users shown in the following table.

Question # 161

The domain syncs to a Microsoft Entra tenant named contoso.com as shown in the exhibit. (Click the Exhibit tab.)

User2 fails to authenticate to the Microsoft Entra tenant when signing in as usef2@fabfikam.com

You need to ensure that User2 can access the resources in Microsoft Entra ID.

Solution: From the Microsoft Entra admin center, you add < abrlkam.com as a custom domain You insttud User2 to sign in as user2@fabrikam.com

Does this meet the goal?

Options:

A.

Yes

B.

No

Questions # 162:

: 223

Your company has digitally signed applications.

You need to ensure that Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) considers the digitally signed applications safe and never analyzes them.

What should you create in the Microsoft Defender Security Center?

Options:

A.

a custom detection rule

B.

an allowed/blocked list rule

C.

an alert suppression rule

D.

an indicator

Questions # 163:

Your network contains an Active Directory forest named Contoso. Local.

You have a Microsoft 365 subscription.

You plan to implement a directory synchronization solution that will use password hash synchronization.

From the Microsoft 365 admin center, you successfully verify the contoso.com domain name.

You need to prepare the environment for the planned directory synchronization solution.

What should you do first?

Options:

A.

From Active Directory Domains and Trusts, add contoso.com as a UPN suffix.

B.

From the Microsoft 365 admin center verify the Contoso. Local domain name.

C.

From the public DNS zone of contoso.com, add a new mail exchanger (MX) record.

D.

From Active Directory Users and Computers, modify the UPN suffix for all users.

Questions # 164:

HOTSPOT

You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

Question # 164

You plan to provide User4 with early access to Microsoft 365 feature and service updates.

You need to identify which Microsoft 365 setting must be configured, and which user can modify the setting. The solution must use the principle of least privilege.

What should you identify? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 164

Options:

Questions # 165:

You have a Microsoft 365 tenant that contains devices registered for mobile device management. The devices are configured as shown in the following table.

Question # 165

You plan to enable VPN access for the devices.

What is the minimum number of configuration policies required?

Options:

A.

3

B.

5

C.

4

D.

1

Viewing page 11 out of 12 pages
Viewing questions 151-165 out of questions