Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

MS-102 Microsoft 365 Administrator Exam Free Practice Exam Questions (2026 Updated)

Prepare effectively for your Microsoft MS-102 Microsoft 365 Administrator Exam certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 3 / 4
Total 585 questions

You need to meet the technical requirement for log analysis.

What is the minimum number of data sources and log collectors you should create from Microsoft Cloud App Security? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Which report should the New York office auditors view?

A.

DLP policy matches

B.

DLP false positives and overrides

C.

DLP incidents

D.

Top Senders and Recipients

You need to meet the requirement for the legal department.

Which three actions should you perform in sequence from the Security & Compliance admin center? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You need to protect the U.S. PII data to meet the technical requirements.

What should you create?

A.

a data loss prevention (DLP) policy that contains a domain exception

B.

a Security & Compliance retention policy that detects content containing sensitive data

C.

a Security & Compliance alert policy that contains an activity

D.

a data loss prevention (DLP) policy that contains a user override

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint site named Sitel. Site! contains the files shown in the following table.

You have a data loss prevention (DLP) policy named DLP1 that has the advanced DLP rules shown in the following table.

You apply DLP1 to Site1.

Which policy tip is displayed for each file? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

You have an Microsoft Entra tenant and a Microsoft 365 E5 subscription. The tenant contains the users shown in the following table.

You plan to implement Microsoft Defender for Endpoint.

You verify that role-based access control (RBAC) is turned on in Microsoft Defender for Endpoint.

You need to identify which user can view security incidents from the Microsoft Defender XDR portal.

Which user should you identify?

A.

User1

B.

User2

C.

User3

D.

User4

You have a Microsoft 365 subscription that uses Microsoft Defender for Office 365.

You need to configure policies to meet the following requirements:

Customize the common attachments filter.

Enable impersonation protection for sender domains.

Which type of policy should you configure for each requirement? To answer, drag the appropriate policy types to the correct requirements. Each policy type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

HOTSPOT

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint site named Site1 and a data loss prevention (DLP) policy named DLP1. DLP1 contains the rules shown in the following table.

Site1 contains the files shown in the following table.

Which policy tips are shown for each file? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 tenant that connects to Microsoft Defender for Endpoint.

You have devices enrolled in Microsoft Intune as shown in the following table.

You plan to use risk levels in Microsoft Defender for Endpoint to identify whether a device is compliant. Noncompliant devices must be blocked from accessing corporate resources.

You need to identify which devices can be onboarded to Microsoft Defender for Endpoint, and which Endpoint security policies must be configured.

What should you identify? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 subscription.

You need to recommend a solution for monitoring and reporting application access. The solution must meet the following requirements:

• Support KQL for querying data.

• Retain report data for at least one year.

What should you include in the recommendation?

A.

a security report in Microsoft Defender XDR

B.

End point analytics

C.

Microsoft 365 usage analytics

D.

Azure Monitor workbooks

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Endpoint. The subscription contains the devices shown in

You need to create the Endpoint security policies shown in the following table.

To which device can you apply each policy? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Your network contains an on-premises Active Directory domain named adatum.com that syncs to Microsoft Entra ID by using the Microsoft Entra Connect Sync Express Settings. Password write back is disabled.

You create a user named User1 and enter Pass in the Password field as shown in the following exhibit.

The Microsoft Entra ID password policy is configured as shown in the following exhibit.

Password policy

Set the password policy for all users in your organization.

Days before passwords expire 90

Days before a user is notified about 14

expiration

You confirm that User1 is synced to Microsoft Entra ID.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the users shown in the following table.

You have a Microsoft Entra tenant that syncs with contoso.com by using Microsoft Entra Connect Sync. Microsoft Entra Connect Sync is configured as shown in the exhibit. (Click the Exhibit tab.)

The Microsoft Entra tenant contains a cloud-only group named Group1 as shown in the following table.

You perform the following tasks at 10 AM:

• In contoso.com. you move User1 to 0U2.

• In the Microsoft Entra tenant, you delete User2.

• In contoso.com. you create a computer account named Comp1 in 0U1 and update the description of Comp1.

For each of the following statements, select Yes if the statement is true. Otherwise, select

No.

NOTE: Each correct selection is worth one point.

You have a Microsoft Entra tenant that contains the groups shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each cont ' d selection is worth one point.

You have a Microsoft 365 E5 subscription that contains a user named User1. You create an anti-phishing policy named Policy! that has the following settings:

• Include these users, groups and domains: User1

• Phishing email threshold: 3 - More Aggressive

User1 receives the email messages shown in the following table.

Which messages are phishing email?

A.

Mail4 only

B.

Mail3 and Mail4 only

C.

Mail2, Mail3, and Mail4 only

D.

Mail1, Mail2, Mail3, and Mail4

You have a Microsoft 365 subscription that uses an Microsoft Entra tenant named contoso.com. The tenant contains the users shown in the following table.

From the Sign-ins blade of the Microsoft Entra admin center for which users can User1 and User2 view the sign-ins? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint.

All the devices in your organization are onboarded to Microsoft Defender for Endpoint.

You need to ensure that an alert is generated if malicious activity was detected on a device during the last 24 hours.

What should you do?

A.

From the Microsoft Purview compliance portal, create a data loss prevention (DLP) policy.

B.

From Alerts queue, create a suppression rule and assign an alert.

C.

From Advanced hunting, create a query and a detection rule.

D.

From the Microsoft Purview compliance portal, create an audit log search.

You have a Microsoft 365 Enterprise E5 subscription.

You add a cloud-based app named App1 to the Microsoft Entra ID enterprise applications list.

You need to ensure that two-step verification is enforced for all user accounts the next time they connect to App1.

Which three settings should you configure from the policy? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 subscription that contains a user named User1

You create a retention label named Retention1 that is published to all locations.

You need to ensure that User1 can label email messages by using Retention1 as soon as possible.

Which cmdlet should you run in Microsoft Exchange Online PowerShell?

A.

Start-MpScan

B.

Start-Process

C.

Start-ManagedFolderAsslstant

D.

Start-AppBackgroundTask

You have a Microsoft 365 E5 tenant.

You plan to deploy a monitoring solution that meets the following requirements:

Captures Microsoft Teams channel messages that contain threatening or violent language.

Alerts a reviewer when a threatening or violent message is identified.

What should you include in the solution?

A.

Data Subject Requests (DSRs)

B.

Insider risk management policies

C.

Communication compliance policies

D.

Audit log retention policies

Page: 3 / 4
Total 585 questions
Copyright © 2014-2026 Solution2Pass. All Rights Reserved