Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft 365 Certified:Administrator Expert

Domain 3Objective 2

Implement and Manage Email and Collaboration Protection by Using Microsoft Defender for Office 365 MS-102 Practice Questions (Page 2)

Part of the Manage security and threats by using Microsoft Defender XDR domain, which accounts for 30–35% of the MS-102 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~12–23 in this domain), expect 3–6 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
10concepts
30–35%of the exam

Questions 6–10

  1. 6foundation · easy

    In Microsoft Defender for Office 365, what is the purpose of the tenant allow/block list?

    Select an answer first
  2. 7foundation · easy

    Which component of a training campaign in Microsoft Defender for Office 365 specifies the users who will receive the training?

    Select an answer first
  3. 8expert · hard

    A company has a strict policy that all email from external senders must be scanned for malware and spam. They also have a line-of-business application that sends automated emails to users with attachments. These emails are being quarantined by the malware filter because the attachments are flagged as false positives. You need to allow these specific emails while maintaining the strict scanning policy for all other external email. What should you do?

    Select an answer first
  4. 9application · medium

    Contoso Pharmaceuticals uses Microsoft 365 and has a zero-trust policy that requires all inbound email containing executable attachments to be blocked. A security analyst reports that a user received a .zip file containing a .js file, which was delivered to the inbox. The anti-malware policy is set to the default action. You need to ensure that nested executable files inside archives are blocked and that the incident is investigated. What should you do?

    Select an answer first
  5. 10application · medium

    A multinational company uses Microsoft Defender for Office 365. The security team notices that a specific user's account is sending a high volume of spam to internal recipients. The user claims their account was compromised and has since changed their password. You need to stop the remaining spam flow while allowing the user to continue working. What should you do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “MS-102” is a trademark of its owner, used for identification only.