Microsoft MS-102 Übungsprüfungen
Zuletzt aktualisiert am 26.04.2025- Prüfungscode: MS-102
- Prüfungsname: Microsoft 365 Administrator
- Zertifizierungsanbieter: Microsoft
- Zuletzt aktualisiert am: 26.04.2025
HOTSPOT
You have a Microsoft 365 E5 subscription.
All corporate Windows 11 devices are managed by using Microsoft Intune and onboarded to Microsoft Defender for Endpoint.
You need to meet the following requirements:
• View an assessment of the device configurations against the Center for Internet Security (CIS) vl.0.0 benchmark.
• Protect a folder named C:Folder1 from being accessed by untrusted applications on the devices.
What should you do? To answer, select the appropriate options in the answer area.
Topic 1, Contoso, Ltd
Overview
Contoso, Ltd. is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York.
The company has the employees and devices shown in the following table.
Contoso recently purchased a Microsoft 365 ES subscription.
Existing Environment
Requirement
The network contains an on-premises Active Directory forest named contoso.com.
The forest contains the servers shown in the following table.
All servers run Windows Server 2016. All desktops and laptops are Windows 10 Enterprise and are joined to the domain.
The mobile devices of the users in the Montreal and Seattle offices run Android. The mobile devices of the users in the New York office run iOS.
The domain is synced to Azure Active Directory (Azure AD) and includes the users shown in the following table.
The domain also includes a group named Group1.
Planned Changes
Contoso plans to implement the following changes:
• Implement Microsoft 365.
• Manage devices by using Microsoft Intune.
• Implement Azure Advanced Threat Protection (ATP).
• Every September, apply the latest feature updates to all Windows computers. Every March, apply the latest feature updates to the computers in the New York office only.
Technical Requirements
Contoso identifies the following technical requirements:
• When a Windows 10 device is joined to Azure AD, the device must enroll in Intune automaticity.
• Dedicated support technicians must enroll all the Montreal office mobile devices in Intune.
• User1 must be able to enroll all the New York office mobile devices in Intune.
• Azure ATP sensors must be installed and must NOT use port mirroring.
• Whenever possible, the principle of least privilege must be used.
• A Microsoft Store for Business must be created.
Compliance Requirements
Contoso identifies the following compliance requirements:
• Ensure that the users in Group1 can only access Microsoft Exchange Online from devices that are enrolled in Intune and configured in accordance with the corporate policy.
• Configure Windows Information Protection (W1P) for the Windows 10 devices.
HOTSPOT
You need to configure a conditional access policy to meet the compliance requirements.
You add Exchange Online as a cloud app.
Which two additional settings should you configure in Policy1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
You have a Microsoft 365 E3 subscription that uses Microsoft Defender for Endpoint Plan 1.
Which two Defender for Endpoint features are available to the subscription? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
- A . advanced hunting
- B . security reports
- C . digital certificate assessment
- D . device discovery
- E . attack surface reduction (ASR)
You plan to use Azure Sentinel and Microsoft Cloud App Security. You need to connect Cloud App Security to Azure Sentinel.
What should you do in the Cloud App Security admin center?
- A . From Automatic log upload, add a log collector.
- B . From Automatic log upload, add a data source.
- C . From Connected apps, add an app connector.
- D . From Security extension, add a SIEM agent.
HOTSPOT
You have a Microsoft 365 E5 subscription.
From Azure AD Privileged Identity Management (PIM), you configure Role settings for the Global Administrator role as shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.
HOTSPOT
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
You add the following assignment for the User Administrator role:
Scope type: Directory
Selected members: Group1
Assignment type: Active
Assignment starts: Mar 15, 2023
Assignment ends: Aug 15, 2023
You add the following assignment for the Exchange Administrator role:
Scope type: Directory
Selected members: Group2
Assignment type: Eligible
Assignment starts: Jun 15, 2023
Assignment ends: Oct 15, 2023
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
HOTSPOT
You have a Microsoft 365 E5 subscription that contains 200 Android devices enrolled in Microsoft Intune.
You create an Android app protection policy named Policy! that is targeted to all Microsoft apps and assigned to all users.
Policy! has the Data protection settings shown in the following exhibit.
Use the drop-down menus to select ‚he answer choice that completes each statement based on the information presented in the graphic.
HOTSPOT
You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users
shown in the following table.
You integrate Microsoft Intune and contoso.com as shown in the following exhibit.
You purchase a Windows 10 device named Device1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
You have a Microsoft 365 E5 subscription that uses Microsoft intune in the Microsoft Endpoint Manager admin center, you discover many stale and inactive devices. You enable device clean-up rules
What can you configure as the minimum number of days before a device a removed automatically?
- A . 10
- B . 30
- C . 45
- D . 90
You have a Microsoft 365 E5 subscription that uses Microsoft intune in the Microsoft Endpoint Manager admin center, you discover many stale and inactive devices. You enable device clean-up rules
What can you configure as the minimum number of days before a device a removed automatically?
- A . 10
- B . 30
- C . 45
- D . 90