MS-102 Security & Compliance 4 — Questions and Answers
Question 1: Which Microsoft 365 feature allows an admin to query raw event data across endpoints, emails, and identities using Kusto Query Language (KQL)?
- Compliance Manager
- Advanced Hunting (Correct answer)
- Threat Analytics
- Content Search
Correct answer: Advanced Hunting
Advanced Hunting in Microsoft 365 Defender uses KQL to query up to 30 days of raw telemetry across all protected workloads.
Question 2: An admin wants to ensure that high-risk sign-ins require additional verification automatically. Which Azure AD feature should be configured?
- Multi-Factor Authentication per-user setting
- Identity Protection risk-based Conditional Access policy (Correct answer)
- Privileged Identity Management
- Access Reviews
Correct answer: Identity Protection risk-based Conditional Access policy
Azure AD Identity Protection can evaluate sign-in risk level and trigger Conditional Access policies requiring MFA or blocking access for high-risk logins.
Question 3: What is the function of Microsoft Purview Compliance Manager?
- Blocks sharing of sensitive data in real time
- Provides risk assessments and improvement actions for regulatory compliance (Correct answer)
- Monitors user communication for policy violations
- Manages sensitivity label deployment across the tenant
Correct answer: Provides risk assessments and improvement actions for regulatory compliance
Compliance Manager assesses the tenant against regulatory frameworks and provides a compliance score with actionable improvement recommendations.
Question 4: A Microsoft 365 admin receives an alert that a user account may be compromised. Which Microsoft 365 Defender action can directly force a password reset and revoke sessions?
- Quarantine the user's mailbox
- Remediate user via Identity investigation actions (Correct answer)
- Submit the user to Microsoft for analysis
- Apply a DLP policy to the user
Correct answer: Remediate user via Identity investigation actions
In Microsoft 365 Defender, identity investigation actions allow admins to force password resets and revoke active sessions for compromised accounts.
Question 5: Which Microsoft Purview capability monitors employee emails and Teams messages for policy violations such as harassment or regulatory misconduct?
- Insider Risk Management
- Information Barriers
- Communication Compliance (Correct answer)
- DLP policies
Correct answer: Communication Compliance
Communication Compliance reviews messages against configured policies to detect inappropriate language, sensitive data sharing, or regulatory violations.
Question 6: An admin needs to prevent external sharing of files labeled 'Confidential' in SharePoint. Which combination of features achieves this?
- Retention policy + eDiscovery hold
- Sensitivity label with encryption + DLP policy (Correct answer)
- Information Barriers + Communication Compliance
- MFA + Conditional Access
Correct answer: Sensitivity label with encryption + DLP policy
Sensitivity labels with encryption restrict who can access labeled files, while DLP policies can block external sharing of labeled content.
Question 7: Which Microsoft Defender for Office 365 plan 2 feature allows security teams to investigate the full email delivery path and all recipients of a malicious message?
- Safe Attachments policy
- Threat Explorer (Real-time detections) (Correct answer)
- Anti-phishing policy
- Mail flow rules
Correct answer: Threat Explorer (Real-time detections)
Threat Explorer in Defender for Office 365 Plan 2 shows detailed email flow, delivery actions, and all recipients, enabling thorough investigation of threats.
Which Microsoft 365 feature allows an admin to query raw event data across endpoints, emails, and identities using Kusto Query Language (KQL)?