MS-100 Quality Control & Assurance 2 — Questions and Answers
Question 1: A Microsoft 365 administrator wants to verify that all user sign-ins are being audited. Which portal provides the Unified Audit Log for sign-in events?
- Microsoft Entra admin center
- Microsoft 365 compliance center (Correct answer)
- Microsoft 365 Defender portal
- Microsoft Intune admin center
Correct answer: Microsoft 365 compliance center
The Microsoft 365 compliance center (purview.microsoft.com) hosts the Unified Audit Log, which captures sign-in and other activities across Microsoft 365 services.
Question 2: Which PowerShell cmdlet is used to search the Unified Audit Log programmatically in Microsoft 365?
- Get-AuditLog
- Search-UnifiedAuditLog (Correct answer)
- Get-AdminAuditLogConfig
- Search-MailboxAuditLog
Correct answer: Search-UnifiedAuditLog
Search-UnifiedAuditLog is the Exchange Online PowerShell cmdlet used to query the Unified Audit Log with date ranges, record types, and user filters.
Question 3: An admin notices that audit log search is not returning results. What is the most likely cause?
- The tenant is on a trial license
- Unified Audit Log is not enabled for the tenant (Correct answer)
- The admin lacks the Global Administrator role
- Multi-factor authentication is not configured
Correct answer: Unified Audit Log is not enabled for the tenant
Unified Audit Logging must be explicitly enabled via the compliance center or PowerShell; new tenants may not have it on by default.
Question 4: How long are audit log records retained by default for Microsoft 365 E3 licensed tenants?
- 30 days
- 90 days (Correct answer)
- 180 days
- 1 year
Correct answer: 90 days
E3 tenants retain Unified Audit Log records for 90 days; E5 or add-on licenses extend retention to one year.
Question 5: A company needs to ensure that its Microsoft 365 configuration aligns with the CIS Benchmark. Which tool provides built-in policy assessments for this purpose?
- Microsoft Secure Score
- Microsoft Compliance Manager (Correct answer)
- Microsoft Defender for Cloud
- Azure Policy
Correct answer: Microsoft Compliance Manager
Compliance Manager in the Microsoft Purview compliance portal offers pre-built assessments including CIS Benchmarks to evaluate and track compliance posture.
Question 6: An administrator wants to receive an alert when a user is added to the Global Administrator role. Where should this alert be configured?
- Microsoft Entra Identity Protection
- Microsoft 365 compliance center alert policies (Correct answer)
- Microsoft Defender for Identity
- Azure Monitor
Correct answer: Microsoft 365 compliance center alert policies
Alert policies in the Microsoft 365 compliance center allow admins to create custom alerts for activities like role elevation detected in the audit log.
Question 7: Which report in the Microsoft 365 admin center shows the number of active users per service over a selected time period?
- Service health report
- Microsoft 365 usage report (Correct answer)
- Security baseline report
- Message trace report
Correct answer: Microsoft 365 usage report
The Microsoft 365 usage reports in the admin center provide breakdowns of active users per service (Exchange, Teams, SharePoint, etc.) over 7, 30, 90, or 180 days.
A Microsoft 365 administrator wants to verify that all user sign-ins are being audited.
Which portal provides the Unified Audit Log for sign-in events?