MS-100 Research & Evidence-Based Practice 3 — Questions and Answers
Question 1: An administrator needs to research which Microsoft 365 audit log activities are retained for 90 days versus 1 year. What is the most accurate evidence source for this retention policy?
- Microsoft Purview compliance documentation on learn.microsoft.com (Correct answer)
- The audit log search results in Microsoft Purview portal
- Microsoft 365 Defender threat reports
- Exchange admin center mail flow rules
Correct answer: Microsoft Purview compliance documentation on learn.microsoft.com
Microsoft Purview documentation on learn.microsoft.com specifies exact audit log retention periods tied to subscription plans including E3 and E5 differences.
Question 2: When planning an Azure AD Conditional Access policy rollout, what evidence-based tool helps administrators simulate policy impact before going live?
- What If tool in Azure AD Conditional Access (Correct answer)
- Azure AD Audit Logs from previous weeks
- Microsoft 365 Compliance score dashboard
- Intune device compliance reports
Correct answer: What If tool in Azure AD Conditional Access
The What If tool in Azure AD Conditional Access simulates which policies would apply to a specific user, app, and sign-in condition, providing pre-deployment evidence.
Question 3: A security team wants evidence that their Microsoft 365 tenant configuration aligns with CIS Benchmarks. Which Microsoft tool generates a scored evidence-based assessment?
- Microsoft Secure Score in Microsoft 365 Defender (Correct answer)
- Azure AD Identity Protection risk reports
- Microsoft 365 admin center Setup wizard
- Message Center advisories
Correct answer: Microsoft Secure Score in Microsoft 365 Defender
Microsoft Secure Score provides an evidence-based scoring system aligned to industry benchmarks, showing current posture and recommended improvement actions.
Question 4: Before migrating mailboxes to Exchange Online, an admin wants evidence on the current on-premises Exchange organization's readiness. Which tool should be used?
- Microsoft 365 Hybrid Configuration Wizard and its prerequisite checker (Correct answer)
- Exchange Management Console migration wizard
- Azure AD Connect Health reports
- Microsoft 365 usage reports
Correct answer: Microsoft 365 Hybrid Configuration Wizard and its prerequisite checker
The Hybrid Configuration Wizard includes prerequisite validation that surfaces evidence of readiness gaps before hybrid deployment begins.
Question 5: An admin is evaluating whether their organization's current identity synchronization is healthy before enabling password writeback. Which dashboard provides the most direct evidence?
- Azure AD Connect Health dashboard in the Azure portal (Correct answer)
- Microsoft 365 admin center Active Users report
- On-premises Active Directory event logs only
- Microsoft 365 Service Health Dashboard
Correct answer: Azure AD Connect Health dashboard in the Azure portal
Azure AD Connect Health provides real-time monitoring of sync agent status, sync errors, and latency data as direct evidence of synchronization health.
Question 6: When researching which Microsoft 365 plan is required for using Azure AD Privileged Identity Management (PIM), what is the authoritative evidence source?
- Azure Active Directory pricing and licensing documentation (Correct answer)
- The Azure portal PIM blade UI prompts
- Microsoft Q&A community forum answers
- Microsoft 365 admin center license comparison tool
Correct answer: Azure Active Directory pricing and licensing documentation
Microsoft's Azure Active Directory pricing and licensing documentation explicitly states that PIM requires Azure AD Premium P2 or Microsoft 365 E5.
Question 7: An administrator is trying to determine root cause of recurring Azure AD user account lockouts. What evidence-based investigation step should come first?
- Review the Azure AD Sign-in logs filtered by 'Failure' status for the affected user (Correct answer)
- Reset the user's password immediately
- Disable the account temporarily and wait
- Check the Microsoft 365 Service Health dashboard for outages
Correct answer: Review the Azure AD Sign-in logs filtered by 'Failure' status for the affected user
Azure AD Sign-in logs provide per-user, per-attempt failure details including error codes, locations, and apps, making them the primary evidence source for lockout investigation.
An administrator needs to research which Microsoft 365 audit log activities are retained for 90 days versus 1 year.
What is the most accurate evidence source for this retention policy?