MS-102 Security & Compliance 5 — Questions and Answers
Question 1: An organization needs to ensure that only compliant devices can access Microsoft 365 resources. Which feature enforces device compliance as an access condition?
- Microsoft Defender for Endpoint
- Conditional Access with device compliance requirement (Correct answer)
- Intune App Protection Policy
- Azure AD MFA registration policy
Correct answer: Conditional Access with device compliance requirement
Conditional Access policies can require that devices meet Intune compliance requirements before granting access to Microsoft 365 resources.
Question 2: What happens to email messages that match a Microsoft Purview retention policy with a 'retain and delete' action after the retention period expires?
- They are permanently deleted immediately
- They are moved to the Recoverable Items folder and then purged (Correct answer)
- They are archived to an online archive mailbox
- They are held indefinitely until manually reviewed
Correct answer: They are moved to the Recoverable Items folder and then purged
When a retain-and-delete retention policy expires, items are moved to the Recoverable Items folder where they are purged after the deletion period.
Question 3: Which Microsoft Purview feature provides a workflow for requesting, approving, and auditing access to privileged administrative tasks?
- Privileged Access Management (PAM) (Correct answer)
- Azure AD Privileged Identity Management (PIM)
- Just-in-Time access
- Access Reviews
Correct answer: Privileged Access Management (PAM)
Privileged Access Management in Microsoft Purview enforces just-in-time, just-enough access for privileged tasks in Microsoft 365 through an approval workflow.
Question 4: An admin configures a Safe Attachments policy in Microsoft Defender for Office 365 with the 'Dynamic Delivery' action. What does this do?
- Blocks all attachments until manually reviewed
- Delivers the email body immediately while scanning the attachment in a sandbox, then re-attaches it (Correct answer)
- Quarantines the email and notifies the recipient
- Replaces attachments with a safe link to the file
Correct answer: Delivers the email body immediately while scanning the attachment in a sandbox, then re-attaches it
Dynamic Delivery allows the email body to reach the recipient immediately while the attachment is detonated in a sandbox, then delivered once deemed safe.
Question 5: A security team wants to create a custom detection rule that triggers an alert when a specific behavior pattern is observed. Which Microsoft 365 Defender feature supports this?
- Threat Analytics reports
- Custom detection rules via Advanced Hunting (Correct answer)
- Microsoft Secure Score actions
- Automated Investigation rules
Correct answer: Custom detection rules via Advanced Hunting
Custom detection rules in Microsoft 365 Defender are built on Advanced Hunting KQL queries and trigger alerts or actions when defined conditions are met.
Question 6: Which Microsoft Purview feature allows an admin to make a mailbox inactive while still preserving its content for compliance after an employee leaves?
- Litigation hold applied before license removal (Correct answer)
- Retention label on the mailbox
- Archive mailbox enablement
- eDiscovery hold
Correct answer: Litigation hold applied before license removal
Applying a litigation hold or In-Place hold before removing the user's license converts the mailbox to an inactive mailbox, preserving content indefinitely.
Question 7: An organization using Microsoft Purview wants to automatically apply a retention label to documents containing specific keywords. Which feature enables this?
- Auto-apply retention label policy using keyword query (Correct answer)
- Manual sensitivity label assignment
- DLP policy with block action
- Compliance Manager assessment
Correct answer: Auto-apply retention label policy using keyword query
Auto-apply retention label policies can use keyword queries, sensitive information types, or trainable classifiers to automatically label matching content.
An organization needs to ensure that only compliant devices can access Microsoft 365 resources.
Which feature enforces device compliance as an access condition?