MS-102 Security & Compliance 2 — Questions and Answers
Question 1: An admin needs to ensure sensitive data leaving Microsoft 365 via email is blocked automatically. Which solution should they configure?
- Microsoft Defender for Endpoint
- Data Loss Prevention (DLP) policy (Correct answer)
- Azure AD Conditional Access
- Microsoft Secure Score
Correct answer: Data Loss Prevention (DLP) policy
DLP policies in Microsoft 365 detect and prevent the sharing of sensitive information through email and other channels.
Question 2: Which Microsoft 365 Defender portal feature provides a unified view of incidents across endpoints, email, and identities?
- Microsoft Secure Score
- Threat Analytics
- Incidents & Alerts queue (Correct answer)
- Attack Simulator
Correct answer: Incidents & Alerts queue
The Incidents & Alerts queue in Microsoft 365 Defender correlates alerts across all workloads into unified incidents.
Question 3: A company wants to classify emails containing credit card numbers automatically. Which Microsoft Purview feature provides built-in sensitive information types for this?
- Sensitivity labels
- Retention policies
- Sensitive information types (SITs) (Correct answer)
- Communication compliance
Correct answer: Sensitive information types (SITs)
Sensitive information types use pattern matching and confidence levels to detect data like credit card numbers automatically.
Question 4: What is the purpose of Microsoft Defender for Office 365 Safe Links?
- Blocks malicious email attachments at delivery
- Rewrites and scans URLs at click-time to protect against malicious links (Correct answer)
- Scans OneDrive files for malware
- Enforces MFA for email access
Correct answer: Rewrites and scans URLs at click-time to protect against malicious links
Safe Links rewrites URLs in emails and Office documents and checks them in real time when a user clicks, blocking known malicious destinations.
Question 5: An administrator needs to review all content searches and eDiscovery cases in Microsoft Purview. Which role group must they be a member of?
- Compliance Administrator
- eDiscovery Manager (Correct answer)
- Global Reader
- Security Operator
Correct answer: eDiscovery Manager
The eDiscovery Manager role group allows members to create and manage eDiscovery cases and run content searches in Microsoft Purview.
Question 6: Which feature in Microsoft Purview allows organizations to place a legal hold on a user's mailbox to preserve all content indefinitely?
- Retention label
- Litigation hold (Correct answer)
- MRM policy
- Inactive mailbox
Correct answer: Litigation hold
Litigation hold preserves all mailbox content for an indefinitely period, preventing deletion or modification of items.
Question 7: A security admin wants to automatically investigate and remediate alerts without manual intervention in Microsoft 365 Defender. Which capability supports this?
- Threat Analytics
- Automated Investigation and Remediation (AIR) (Correct answer)
- Advanced Hunting
- Attack Surface Reduction
Correct answer: Automated Investigation and Remediation (AIR)
AIR in Microsoft 365 Defender automatically investigates alerts and takes remediation actions based on configured settings.
An admin needs to ensure sensitive data leaving Microsoft 365 via email is blocked automatically.
Which solution should they configure?