MS-100 Professional Standards & Competencies 2 — Questions and Answers
Question 1: An admin needs to delegate the ability to reset user passwords without granting full Global Admin access. Which role should be assigned?
- Global Administrator
- Helpdesk Administrator (Correct answer)
- Security Reader
- Compliance Administrator
Correct answer: Helpdesk Administrator
The Helpdesk Administrator role allows password resets and service request management without full admin privileges.
Question 2: Your organization requires that all Microsoft 365 service health issues be tracked and communicated to stakeholders. Which admin center feature supports this?
- Microsoft Secure Score
- Service Health dashboard (Correct answer)
- Compliance Manager
- Message Center
Correct answer: Service Health dashboard
The Service Health dashboard in the Microsoft 365 admin center shows current and historical service incidents and advisories.
Question 3: A compliance officer needs read-only access to audit logs and reports in Microsoft 365. Which role is most appropriate?
- Security Administrator
- Global Reader (Correct answer)
- Compliance Data Administrator
- Reports Reader
Correct answer: Global Reader
The Global Reader role provides read-only access to all admin center features including audit logs and reports.
Question 4: Which Microsoft 365 feature allows an IT admin to create and enforce acceptable use policies for end users?
- Azure AD Terms of Use (Correct answer)
- Microsoft Purview DLP
- Conditional Access policies
- Intune Compliance policies
Correct answer: Azure AD Terms of Use
Azure AD Terms of Use requires users to accept a policy before accessing applications, enforcing acceptable use standards.
Question 5: An organization is being audited and needs to prove that administrative actions were logged. Which service provides this capability in Microsoft 365?
- Microsoft Defender for Cloud Apps
- Unified Audit Log in Microsoft Purview (Correct answer)
- Azure Monitor
- Microsoft Endpoint Manager
Correct answer: Unified Audit Log in Microsoft Purview
The Unified Audit Log in Microsoft Purview captures admin and user activities across Microsoft 365 services.
Question 6: Which best practice should be followed when a Microsoft 365 Global Administrator account is not actively being used for administration?
- Keep it signed in to avoid re-authentication delays
- Assign it a Microsoft 365 E3 license
- Use a separate cloud-only account with MFA and no productivity licenses (Correct answer)
- Link it to a shared mailbox
Correct answer: Use a separate cloud-only account with MFA and no productivity licenses
Global Admin accounts should be cloud-only, MFA-protected, and unlicensed to minimize attack surface when not in use.
Question 7: A Microsoft 365 admin wants to review which users have been assigned admin roles. Where should they navigate?
- Microsoft 365 admin center > Active users > Filter by role (Correct answer)
- Azure AD > Groups > Admin groups
- Microsoft Purview > Role groups
- Security & Compliance Center > Permissions
Correct answer: Microsoft 365 admin center > Active users > Filter by role
In the Microsoft 365 admin center, you can filter Active users by role to view all role assignments.
An admin needs to delegate the ability to reset user passwords without granting full Global Admin access.
Which role should be assigned?