Topic 1 - Design and implement Microsoft 365 services Flashcards Preview

MS-100 - Microsoft 365 Identity and Services > Topic 1 - Design and implement Microsoft 365 services > Flashcards

Flashcards in Topic 1 - Design and implement Microsoft 365 services Deck (48)
Loading flashcards...
1

Your company has a Microsoft Office 365 tenant. You suspect that several Office 365 features were recently updated. You need to view a list of the features that were recently updated in the tenant. Solution: You use the View service requests option in the Microsoft 365 admin center. Does this meet the goal?

A. Yes

B. No

B. No

2

Your company has a Microsoft Office 365 tenant. You suspect that several Office 365 features were recently updated. You need to view a list of the features that were recently updated in the tenant. Solution: You use Dashboard in Security & Compliance. Does this meet the goal?

A. Yes

B. No

B. No

3

Your company has a Microsoft Office 365 tenant. You suspect that several Office 365 features were recently updated. You need to view a list of the features that were recently updated in the tenant. Solution: You use Message center in the Microsoft 365 admin center. Does this meet the goal?

A. Yes

B. No

A. Yes

4

Your company has a Microsoft Office 365 tenant. You suspect that several Office 365 features were recently updated. You need to view a list of the features that were recently updated in the tenant. Solution: You review the Security & Compliance report in the Microsoft 365 admin center. Does this meet the goal?

A. Yes

B. No

B. No

5

You recently migrated your on-premises email solution to Microsoft Exchange Online and are evaluating which licenses to purchase.
You want the members of two groups named IT and Managers to be able to use the features shown in the following table.

The IT group contains 50 users. The Managers group contains 200 users.
You need to recommend which licenses must be purchased for the planned solution. The solution must minimize licensing costs.
Which licenses should you recommend?

A. 250 Microsoft 365 E3 only

B. 50 Microsoft 365 E3 and 200 Microsoft 365 E5

C. 250 Microsoft 365 E5 only

D. 200 Microsoft 365 E3 and 50 Microsoft 365 E5

D. 200 Microsoft 365 E3 and 50 Microsoft 365 E5

6

You have a Microsoft 365 tenant that contains Microsoft Exchange Online.
You plan to enable calendar sharing with a partner organization named adatum.com. The partner organization also has a Microsoft 365 tenant.
You need to ensure that the calendar of every user is available to the users in adatum.com immediately.
What should you do?

A. From the Exchange admin center, create a sharing policy.

B. From the Exchange admin center, create a new organization relationship.

C. From the Microsoft 365 admin center, modify the Organization profile settings.

D. From the Microsoft 365 admin center, configure external site sharing.

B. From the Exchange admin center, create a new organization relationship.

7

Your company has a Microsoft Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com.
You purchase a domain named contoso.com from a registrar and add all the required DNS records.
You create a user account named User1. User1 is configured to sign in as user1@contoso.onmicrosoft.com.
You need to configure User1 to sign in as user1@contoso.com.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:

8

Your company has an on-premises Microsoft Exchange Server 2016 organization and a Microsoft 365 Enterprise subscription.
You plan to migrate mailboxes and groups to Exchange Online.
You start a new migration batch.
Users report slow performance when they use the on-premises Exchange Server organization.
You discover that the migration is causing the slow performance.
You need to reduce the impact of the mailbox migration on the end-users.
What should you do?

A. Create a mailbox rule.

B. Configure back pressure.

C. Modify the migration endpoint settings.

D. Create a throttling policy.

C. Modify the migration endpoint settings.


You can reduce the maximum number of concurrent mailbox migrations.

9

You have a Microsoft 365 subscription.
You need to prevent phishing email messages from being delivered to your organization.
What should you do?

A. From the Exchange admin center, create an anti-malware policy.

B. From Security & Compliance, create a DLP policy.

C. From Security & Compliance, create a new threat management policy.

D. From the Exchange admin center, create a spam filter policy.

C. From Security & Compliance, create a new threat management policy.

References:
https://docs.microsoft.com/en-us/office365/securitycompliance/set-up-anti-phishing-policies

10

Your company has a Microsoft 365 subscription. All identities are managed in the cloud.
The company purchases a new domain name.
You need to ensure that all new mailboxes use the new domain as their primary email address.
What are two possible ways to achieve the goal? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

A. From Microsoft Exchange Online PowerShell, run the command. Update-EmailAddressPolicy policy

B. From the Exchange admin center, click mail flow, and then configure the email address policies.

C. From the Microsoft 365 admin center, click Setup, and then configure the domains.

D. From Microsoft Exchange Online PowerShell, run the command. Set-EmailAddressPolicy policy

E. From the Azure Active Directory admin center, configure the custom domain names.

B. From the Exchange admin center, click mail flow, and then configure the email address policies.

D. From Microsoft Exchange Online PowerShell, run the command. Set-EmailAddressPolicy policy

11

Your company has a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com that includes the users shown in the following table.

Group2 is a member of Group1.
You assign a Microsoft Office 365 Enterprise E3 license to Group1.
You need to identity how many Office 365 E3 licenses are assigned.
What should you identify?

A. 1

B. 2

C. 3

D. 4

C. 3

12

You have a Microsoft 365 subscription.
A new corporate security policy states that you must automatically send DLP incident reports to the users in the legal department.
You need to schedule the email delivery of the reports. The solution must ensure that the reports are sent as frequently as possible.
How frequently can you share the reports?

A. hourly

B. monthly

C. weekly

D. daily

Reveal Solution

C. weekly

13

Your company has a Microsoft 365 subscription.
You need to identify all the users in the subscription who are licensed for Microsoft Office 365 through a group membership. The solution must include the name of the group used to assign the license.
What should you use?

A. the Licenses blade in the Azure portal

B. Reports in the Microsoft 365 admin center

C. Active users in the Microsoft 365 admin center

D. Report in Security & Compliance

A. the Licenses blade in the Azure portal

14

Your company has a Microsoft 365 subscription.
You upload several archive PST files to Microsoft 365 by using the Security & Compliance admin center.
A month later, you attempt to run an import job for the PST files.
You discover that the PST files were deleted from Microsoft 365.
What is the most likely cause of the files being deleted? More than one answer choice may achieve the goal. Select the BEST answer.

A. The PST files were corrupted and deleted by Microsoft 365 security features.

B. PST files are deleted automatically from Microsoft 365 after 30 days.

C. The size of the PST files exceeded a storage quota and caused the files to be deleted.

D. Another administrator deleted the PST files.

B. PST files are deleted automatically from Microsoft 365 after 30 days.

15

Your company has a main office and 20 branch offices in North America and Europe. Each branch office connects to the main office by using a WAN link. All the offices connect to the Internet and resolve external host names by using the main office connections.
You plan to deploy Microsoft 365 and to implement a direct Internet connection in each office.
You need to recommend a change to the infrastructure to provide the quickest possible access to Microsoft 365 services.
What is the best recommendation to achieve the goal? More than one answer choice may achieve the goal. Select the BEST answer.

A. For all the client computers in the branch offices, modify the MTU setting by using a Group Policy object (GPO).

B. In each branch office, deploy a proxy server that has user authentication enabled.

C. In each branch office, deploy a firewall that has packet inspection enabled.

D. In each branch office, configure name resolution so that all external hosts are redirected to public DNS servers directly.

D. In each branch office, configure name resolution so that all external hosts are redirected to public DNS servers directly.

16

Your network contains an Active Directory forest named adatum.local. The forest contains 500 users and uses adatum.com as a UPN suffix.
You deploy a Microsoft 365 tenant.
You implement directory synchronization and sync only 50 support users.
You discover that five of the synchronized users have usernames that use a UPN suffix of onmicrosoft.com.
You need to ensure that all synchronized identities retain the UPN set in their on-premises user account.
What should you do?

A. From the Microsoft 365 admin center, add adatum.com as a custom domain name.

B. From Windows PowerShell, run the Set-ADDomain â€"AllowedDNSSuffixes adatum.com command.

C. From Active Directory Users and Computers, modify the UPN suffix of the five user accounts.

D. From the Microsoft 365 admin center, add adatum.local as a custom domain name.

C. From Active Directory Users and Computers, modify the UPN suffix of the five user accounts.

17

Your company has a Microsoft Office 365 subscription that contains the groups shown in the following table.

You have the licenses shown in the following table.

Another administrator removes User1 from Group1 and adds Group2 to Group1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

YES YES YES

18

Your company has on-premises servers and a Microsoft Azure Active Directory (Azure AD) tenant.
Several months ago, the Azure AD Connect Health agent was installed on all the servers.
You review the health status of all the servers regularly.
Recently, you attempted to view the health status of a server named Server1 and discovered that the server is NOT listed on the Azure Active Directory Connect
Servers list.
You suspect that another administrator removed Server1 from the list.
You need to ensure that you can view the health status of Server1.
What are two possible ways to achieve the goal? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

A. From Windows PowerShell, run the cmdlet. Register-AzureADConnectHealthSyncAgent

B. From Azure Cloud shell, run the Connect-AzureAD cmdlet.

C. From Server1, change the Azure AD Connect Health services Startup type to Automatic (Delayed Start).

D. From Server1, change the Azure AD Connect Health services Startup type to Automatic.

E. From Server1, reinstall the Azure AD Connect Health agent.

A. From Windows PowerShell, run the cmdlet. Register-AzureADConnectHealthSyncAgent

E. From Server1, reinstall the Azure AD Connect Health agent.

19

You have a Microsoft 365 subscription.
You suspect that several Microsoft Office 365 applications or services were recently updated.
You need to identify which applications or services were recently updated.
What are two possible ways to achieve the goal? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

A. From the Microsoft 365 admin center, review the Message center blade.

B. From the Office 365 Admin mobile app, review the messages.

C. From the Microsoft 365 admin center, review the Products blade.

D. From the Microsoft 365 admin center, review the Service health blade.

A. From the Microsoft 365 admin center, review the Message center blade.

B. From the Office 365 Admin mobile app, review the messages.

20

Your company has a Microsoft Office 365 tenant.
You suspect that several Office 365 features were recently updated.
You need to view a list of the features that were recently updated in the tenant.
Solution: You use Monitoring and reports from the Compliance admin center.
Does this meet the goal?

A. Yes

B. No

B. No

21

Your network contains an on-premises Active Directory domain named contoso.com that is synced to a Microsoft Azure Active Directory (Azure AD) tenant. The on-premises domain contains a server named Server1 that runs Windows Server 2016 and 200 client computers that run Windows 10.
Your company purchases a Microsoft 365 subscription.
On Server1, you create a file share named Share1. You extract the Microsoft Office Deployment Tool (ODT) to Share1.
You need to deploy Office 365 ProPlus, and the French language pack from Share1 to the Windows 10 computers.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:

22

Your network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).
You manage Windows 10 devices by using Microsoft System Center Configuration Manager (Current Branch).
You configure a pilot for co-management.
You add a new device named Device1 to the domain. You install the Configuration Manager client on Device1.
You need to ensure that you can manage Device1 by using Microsoft Intune and Configuration Manager.
Solution: You add Device1 to an Active Directory group.
Does this meet the goal?

A. Yes

B. No

A. Yes

23

Your network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).
You manage Windows 10 devices by using Microsoft System Center Configuration Manager (Current Branch).
You configure a pilot for co-management.
You add a new device named Device1 to the domain. You install the Configuration Manager client on Device1.
You need to ensure that you can manage Device1 by using Microsoft Intune and Configuration Manager.
Solution: Define a Configuration Manager device collection as the pilot collection. Add Device1 to the collection.
Does this meet the goal?

A. Yes

B. No

B. No

24

Your network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).
You manage Windows 10 devices by using Microsoft System Center Configuration Manager (Current Branch).
You configure a pilot for co-management.
You add a new device named Device1 to the domain. You install the Configuration Manager client on Device1.
You need to ensure that you can manage Device1 by using Microsoft Intune and Configuration Manager.
Solution: You create a device configuration profile from the Intune admin center.
Does this meet the goal?

A. Yes

B. No

B. No

25

26

You have a Microsoft 365 subscription.
You configure a data loss prevention (DLP) policy.
You discover that users are incorrectly marking content as false positive and bypassing the DLP policy.
You need to prevent the users from bypassing the DLP policy.
What should you configure?

A. actions

B. exceptions

C. incident reports

D. user overrides

D. user overrides

27

In Microsoft 365, you configure a data loss prevention (DLP) policy named Policy1. Policy1 detects the sharing of United States (US) bank account numbers in email messages and attachments.
Policy1 is configured as shown in the exhibit. (Click the Exhibit tab.)

You need to ensure that internal users can email documents that contain US bank account numbers to external users who have an email suffix of contoso.com.
What should you configure?

A. an action

B. a group

C. a condition

D. an exception

A. an action

28

Your company uses on-premises Windows Server File Classification Infrastructure 9FCI). Some documents on the on-premises file servers are classifies as
Confidential.
You migrate the files from the on-premises file servers to Microsoft SharePoint Online.
You need to ensure that you can implement data loss prevention (DLP) policies for the uploaded files based on the Confidential classification.
What should you do first?

A. From the SharePoint admin center, create a managed property.

B. From the SharePoint admin center, configure hybrid search.

C. From the Security & Compliance Center PowerShell, run the cmdlet. New-DlpComplianceRule

D. From the Security & Compliance Center PowerShell, run the cmdlet. New-DataClassification

C. From the Security & Compliance Center PowerShell, run the cmdlet. New-DlpComplianceRule

29

You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com.
You have three applications App1, App2, App3. The Apps use files that have the same file extensions.
Your company uses Windows Information Protection (WIP). WIP has the following configurations:
✑ Windows Information Protection mode: Silent
✑ Protected apps: App1
✑ Exempt apps: App2
From App1, you create a file named File1.
What is the effect of the configurations? To answer, select the appropriate options in the answer area.
Hot Area:

30

Your company has 10 offices.
The network contains an Active Directory domain named contoso.com. The domain contains 500 client computers. Each office is configured as a separate subnet.
You discover that one of the offices has the following:
Computers that have several preinstalled applications

✑ Computers that use nonstandard computer names
✑ Computers that have Windows 10 preinstalled
✑ Computers that are in a workgroup
You must configure the computers to meet the following corporate requirements:
✑ All the computers must be joined to the domain.
✑ All the computers must have computer names that use a prefix of CONTOSO.
✑ All the computers must only have approved corporate applications installed.
You need to recommend a solution to redeploy the computers. The solution must minimize the deployment time.

A. a provisioning package

B. wipe and load refresh

C. Windows Autopilot

D. an in-place upgrade

A. a provisioning package

By using a Provisioning, IT administrators can create a self-contained package that contains all of the configuration, settings, and apps that need to be applied to a device.
Incorrect Answers:
C: With Windows Autopilot the user can set up pre-configure devices without the need consult their IT administrator.
D: Use the In-Place Upgrade option when you want to keep all (or at least most) existing applications.

31

You have a Microsoft 365 subscription.
You recently configured a Microsoft SharePoint Online tenant in the subscription.
You plan to create an alert policy.
You need to ensure that an alert is generated only when malware is detected in more than five documents stored in SharePoint Online during a period of 10 minutes.
What should you do first?

A. Enable Microsoft Office 365 Cloud App Security.

B. Deploy Windows Defender Advanced Threat Protection (Windows Defender ATP).

C. Enable Microsoft Office 365 Analytics.

B. Deploy Windows Defender Advanced Threat Protection (Windows Defender ATP).

32

From the Microsoft Azure Active Directory (Azure AD) Identity Protection dashboard, you view the risk events shown in the exhibit. (Click the Exhibit tab.)

You need to reduce the likelihood that the sign-ins are identified as risky.
What should you do?

A. From the Security & Compliance admin center, add the users to the Security Readers role group.

B. From the Conditional access blade in the Azure Active Directory admin center, create named locations.

C. From the Azure Active Directory admin center, configure the trusted IPs for multi-factor authentication.

D. From the Security & Compliance admin center, create a classification label.

B. From the Conditional access blade in the Azure Active Directory admin center, create named locations.

33

You have a Microsoft 365 subscription.
You have the devices shown in the following table.

You need to onboard the devices to Windows Defender Advanced Threat Protection (ATP). The solution must avoid installing software on the devices whenever possible.
Which onboarding method should you use for each operating system? To answer, drag the appropriate methods to the correct operating systems. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Select and Place:

34

You have a Microsoft 365 subscription.
You need to implement Windows Defender Advanced Threat Protection (ATP) for all the supported devices enrolled devices enrolled on mobile device management (MDM).
What should you include in the device configuration profile? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

35

You have a Microsoft 365 tenant.
You have a line-of-business application named App1 that users access by using the My Apps portal.
After some recent security breaches, you implement a conditional access policy for App1 that uses Conditional Access App Control.
You need to be alerted by email if impossible travel is detected for a user of App1. The solution must ensure that alerts are generated for App1 only.
What should you do?

A. From Microsoft Cloud App Security, modify the impossible travel alert policy.

B. From Microsoft Cloud App Security, create a Cloud Discovery anomaly detection policy.

C. From the Azure Active Directory admin center, modify the conditional access policy.

D. From Microsoft Cloud App Security, create an app discovery policy.

B. From Microsoft Cloud App Security, create a Cloud Discovery anomaly detection policy.

36

Your network contains an on-premises Active Directory domain.
Your company has a security policy that prevents additional software from being installed on domain controllers.
You need to monitor a domain controller by using Microsoft Azure Advanced Threat Protection (ATP).
What should you do? More than once choice may achieve the goal. Select the BEST answer.

A. Deploy an Azure ATP standalone sensor, and then configure port mirroring.

B. Deploy an Azure ATP standalone sensor, and then configure detections.

C. Deploy an Azure ATP sensor, and then configure detections.

D. Deploy an Azure ATP sensor, and then configure port mirroring.

D. Deploy an Azure ATP sensor, and then configure port mirroring.

37

Your network contains an on-premises Active Directory domain named contoso.com. The domain contains 1,000 Windows 10 devices.
You perform a proof of concept (PoC) deployment of Windows Defender Advanced Threat Protection (ATP) for 10 test devices. During the onboarding process, you configure Windows Defender ATP-related data to be stored in the United States.
You plan to onboard all the devices to Windows Defender ATP data in Europe.
What should you do first?

A. Create a workspace

B. Offboard the test devices

C. Delete the workspace

D. Onboard a new device

B. Offboard the test devices

38

You implement Microsoft Azure Advanced Threat Protection (Azure ATP).
You have an Azure ATP sensor configured as shown in the following exhibit.

Updates -

How long after the Azure ATP cloud service is updated will the sensor update?

A. 1 hour

B. 7 days

C. 48 hours

D. 12 hours

E. 24 hours

E. 24 hours

39

Your company has a Microsoft 365 E3 subscription.
All devices run Windows 10 Pro and are joined to Microsoft Azure Active Directory (Azure AD).
You need to change the edition of Windows 10 to Enterprise the next time users sign in to their computer. The solution must minimize downtime for the users.
What should you use?

A. Subscription Activation

B. Windows Update

C. Windows Autopilot

D. an in-place upgrade

C. Windows Autopilot

40

41

15 / Android

42

Your network contains an Active Directory domain named contoso.com. The domain contains 1000 Windows 8.1 devices.
You plan to deploy a custom Windows 10 Enterprise image to the Windows 8.1 devices.
You need to recommend a Windows 10 deployment method.
What should you recommend?

A. Wipe and load refresh

B. Windows Autopilot

C. a provisioning package

D. an in-place upgrade

D. an in-place upgrade

43

You use Microsoft System Center Configuration manager (Current Branch) to manage devices.
Your company uses the following types of devices:
✑ Windows 10
✑ Windows 8.1
✑ Android
✑ iOS
Which devices can be managed by using co-management?

A. Windows 10 and Windows 8.1 only

B. Windows 10, Android, and iOS only

C. Windows 10 only

D. Windows 10, Windows 8.1, Android, and iOS

D. Windows 10, Windows 8.1, Android, and iOS

44

45

46

47

48