[2024] Valid MS-101 test answers & Microsoft MS-101 exam pdf
Verified MS-101 dumps Q&As - Pass Guarantee or Full Refund
NEW QUESTION # 38
Your company has a Microsoft 365 subscription.
You need to configure Microsoft 365 to meet the following requirements:
Malware found in email attachments must be quarantined for 20 days.
The email address of senders to your company must be verified.
Which two options should you configure in the Security & Compliance admin center? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 39
You have three devices enrolled in Microsoft Intune as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 40
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure Active Directory (Azure AD) tenant that contains a user named User1.
Your company purchases a Microsoft 365 subscription.
You need to ensure that User1 is assigned the required role to create file policies and manage alerts in the Cloud App Security admin center.
Solution: From the Azure Active Directory admin center, you assign the Security administrator role to User1.
Does this meet the goal?
- A. No
- B. Yes
Answer: B
Explanation:
Explanation/Reference:
References:
https://docs.microsoft.com/en-us/cloud-app-security/manage-admins
NEW QUESTION # 41
You have a Microsoft 365 subscription.
You plan to enable Microsoft Azure Information Protection.
You need to ensure that only the members of a group named PilotUsers can protect content What should you do?
- A. From the AAORM PowerShell module, run the Add-AadrmRoleBasedAdministrator cmdlet.
- B. From the AADRM PowerShell module, run the set-AadrmonboardingControlPolicy cmdlet.
- C. From Azure Information Protection, configure the protection activation status.
- D. From Azure Information Protection, create a policy.
Answer: D
Explanation:
Reference:
https://blogs.technet.microsoft.com/kemckinn/2018/05/17/creating-labels-for-azure-information-protection/
NEW QUESTION # 42
You need to meet the technical requirement for the SharePoint administrator. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
References:
https://docs.microsoft.com/en-us/office365/securitycompliance/search-the-audit-log-in-security-and-compliance#
NEW QUESTION # 43
You have a Microsoft 365 subscription.
You have a user named User1.
You need to ensure that User1 can place a litigation hold on all mailbox content.
Which role should you assign to User1?
- A. Compliance Management from the Exchange admin center
- B. Information Protection administrator from the Azure Active Directory admin center
- C. User management administrator from the Microsoft 365 admin center
- D. eDiscovery Manager from the Security & Compliance admin center
Answer: D
Explanation:
Section: [none]
Explanation/Reference:
References:
https://docs.microsoft.com/en-us/Exchange/permissions/feature-permissions/policy-and-compliance- permissions?view=exchserver-2019
NEW QUESTION # 44
From the Microsoft Azure Active Directory (Azure AD) Identity Protection dashboard, you view the risk events shown in the exhibit. (Click the Exhibit tab.)
You need to reduce the likelihood that the sign-ins are identified at risky.
What should you do?
- A. From the Azure Active Directory admin center, configure the trusted IPs for multi-factor authentication.
- B. From the Conditional access blade in the Azure Active Directory admin center, create named locations.
- C. From the Security & Compliance admin center, create a classification label.
- D. From the Security & Compliance admin center, add the users to the Security Readers role group.
Answer: B
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/location-condition
NEW QUESTION # 45
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).
You manage Windows 10 devices by using Microsoft System Center Configuration Manager (Current Branch).
You configure pilot co-management.
You add a new device named Device1 to the domain. You install the Configuration Manager client on Device1.
You need to ensure that you can manage Device1 by using Microsoft Intune and Configuration Manager.
Solution: You create a device configuration profile from the Device Management admin center.
Does this meet the goal?
- A. Yes
- B. No
Answer: B
Explanation:
Section: [none]
NEW QUESTION # 46
Your company uses Microsoft Cloud App Security.
You plan to integrate Cloud App Security and security information and event management (SIEM).
You need to deploy a SIEM agent on a server that runs Windows Server 2016.
What should you do? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
References:
https://docs.microsoft.com/en-us/office365/securitycompliance/integrate-your-siem-server-with-office-365-cas
NEW QUESTION # 47
You have a Microsoft 365 ES tenant.
You have the alerts shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
NEW QUESTION # 48
You have a Microsoft 365 E5 tenant.
You create a retention label named Retention1 as shown in the following exhibit.
When users attempt to apply Retention1, the label is unavailable.
You need to ensure that Retention1 is available to all the users.
What should you do?
- A. Modify the Business function/department setting for Retention 1.
- B. Use a file plan CSV template to import Retention1.
- C. Create a new label policy
- D. Modify the Authority type setting for Retention!
Answer: C
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/create-apply-retention-labels?view=o365-worldwide
NEW QUESTION # 49
Your company purchases a cloud app named App1.
You need to ensure that you can use Microsoft Cloud App Security to block downloads in App1. App1 supports session controls.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation
Graphical user interface, text, application Description automatically generated
Reference:
https://docs.microsoft.com/en-us/cloud-app-security/getting-started-with-cloud-app-security
NEW QUESTION # 50
You need to meet the technical requirement for the SharePoint administrator. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
References:
https://docs.microsoft.com/en-us/office365/securitycompliance/search-the-audit-log-in-security-and-compliance#
NEW QUESTION # 51
You have a Microsoft 365 tenet named Contoso.com. the tenant contains the users shown in the following table.
You have an eDiscovery case shown in the follow table.
For each of the following statements select yes of the statements is true. Otherwise, select NO.
NOTE: each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 52
Your network contains an Active Directory domain named contoso.com. The domain contains 100 Windows 8.1 devices. You plan to deploy a custom Windows 10 Enterprise image to the Windows 8.1 devices. You need to recommend a Windows 10 deployment method. What should you recommend?
- A. Windows Autopilot
- B. an in place upgrade
- C. a provisiong package
- D. wipe and load refresh
Answer: D
Explanation:
https://docs.microsoft.com/en-us/windows/deployment/deploy-windows-mdt/upgrade-to-windows-10-with-the-microsoft-deployment-toolkit In-place upgrade differs from computer refresh in that you cannot use a custom image to perform the in-place upgrade. In this article we will add a default Windows 10 image to the production deployment share specifically to perform an in-place upgrade. https://docs.microsoft.com/en-us/windows/deployment/deploy-windows-mdt/refresh-a-windows-7-computer-with-windows-10 To complete a computer refresh you will: Back up data and settings locally, in a backup folder. Wipe the partition, except for the backup folder. Apply the new operating system image. Install other applications. Restore data and settings.
NEW QUESTION # 53
You have a Microsoft 365 tenant.
You have a line-of-business application named App1 that users access by using the My Apps portal.
After some recent security breaches, you implement a conditional access policy for App1 that uses Conditional Access App Control.
You need to be alerted by email if impossible travel is detected for a user of App1. The solution must ensure that alerts are generated for App1 only.
What should you do?
- A. From Microsoft Cloud App Security, modify the impossible travel alert policy.
- B. From the Azure Active Directory admin center, modify the conditional access policy.
- C. From Microsoft Cloud App Security, create an app discovery policy.
- D. From Microsoft Cloud App Security, create a Cloud Discovery anomaly detection policy.
Answer: D
Explanation:
Explanation/Reference:
References:
https://docs.microsoft.com/en-us/cloud-app-security/cloud-discovery-anomaly-detection-policy
NEW QUESTION # 54
You need to configure a conditional access policy to meet the compliance requirements.
You add Exchange Online as a cloud app.
Which two additional settings should you configure in Policy1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 55
You have retention policies in Microsoft 365 as shown in the following table.
Policy1 is configured as shown in the Policy1exhibit. (Click the Policy1 lab.)
Policy2 is configured as shown in the Policy2 exhibit. (Click the Policy2 tab.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
NEW QUESTION # 56
You have a new Microsoft 365 subscription.
A user named User1 has a mailbox in Microsoft Exchange Online.
You need to log any changes to the mailbox folder permissions of User1.
Which command should you run? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
To enable auditing for a single mailbox (in this example, belonging to Holly Sharp), use this PowerShell command: Set-Mailbox username -AuditEnabled $true References:
https://support.microsoft.com/en-us/help/4026501/office-auditing-in-office-365-for-admins
https://docs.microsoft.com/en-us/powershell/module/exchange/mailboxes/set-mailbox?view=exchange-ps
NEW QUESTION # 57
You have a Microsoft 365 tenant.
You plan to implement Endpoint Protection device configuration profiles.
Which platform can you manage by using the profile?
- A. iOS
- B. Window 10
- C. Android
- D. CentOS Linux
Answer: B
Explanation:
Reference:
https://docs.microsoft.com/en-us/mem/intune/protect/endpoint-protection-configure
NEW QUESTION # 58
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).
You manage Windows 10 devices by using Microsoft System Center Configuration Manager (Current Branch).
You configure pilot co-management.
You add a new device named Device1 to the domain. You install the Configuration Manager client on Device1.
You need to ensure that you can manage Device1 by using Microsoft Intune and Configuration Manager.
Solution: You add Device1 to an Active Directory group.
Does this meet the goal?
- A. No
- B. Yes
Answer: B
Explanation:
Explanation
References:
https://www.scconfigmgr.com/2017/11/30/how-to-setup-co-management-part-6/
NEW QUESTION # 59
You have a Microsoft Office 365 subscription.
You need to delegate eDiscovery tasks as shown in the following table.
The solution must follow the principle of the least privilege.
To which role group should you assign each user? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
References:
https://docs.microsoft.com/en-us/office365/securitycompliance/assign-ediscovery-permissions
NEW QUESTION # 60
......
MS-101 Exam Questions – Valid MS-101 Dumps Pdf: https://prepaway.testkingpass.com/MS-101-testking-dumps.html