We will provide one year free update for you after purchase of our study material, thus you can get the newest questions and prepare well for the real test. Before purchase, you can try our free demo questions to check the basic information about our pdf torrent.

Pass Your MS-100 Exam Easily - Real MS-100 Practice Dump Updated May 22, 2022 [Q95-Q113]

Share

Pass Your MS-100 Exam Easily - Real MS-100 Practice Dump Updated May 22, 2022

2022 Realistic Verified Free Microsoft MS-100 Exam Questions

NEW QUESTION 95
You have a Microsoft 365 subscription that uses a default named contoso.com.
Three files were created on February 1, 2019, as shown in the following table.

On March 1, 2019, you create two retention labels named Label1 and label2.
The settings for Label1 are configured as shown in the Label1 exhibit. (Click theLabel1tab.) Label 1

The settings for Label2 are configured as shown in the Label1 exhibit. (Click theLabel2tab.) Label 2

You apply the retention labels to Exchange email, SharePoint sites, and OneDrive accounts.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE:Each correct selection is worth one point.

Answer:

Explanation:

Explanation

Box 1: No
Retention overrides deletion.
Box 2: No
Content in a document library will be moved to the first-stage Recycle Bin within 7 days of disposition, and then permanently deleted another 93 days after that. Thus 100 days in total.
Box 3: No
Items in an Exchange mailbox will be permanently deleted within 14 days of disposition.
References:
https://docs.microsoft.com/en-us/office365/securitycompliance/labels
https://docs.microsoft.com/en-us/office365/securitycompliance/disposition-reviews

 

NEW QUESTION 96
You have an on-premises Microsoft SharePoint Server 2016 environment.
You create a Microsoft 365 tenant.
You need to migrate some of the SharePoint sites to SharePoint Online. The solution must meet the following requirements:
Microsoft OneDrive sites must redirect users to online content.
Users must be able to follow both on-premises and cloud-based sites.
Users must have a single SharePoint profile for both on-premises and on the cloud.
When users search for a document by using keywords, the results must include online and on-premises results.
From the SharePoint Hybrid Configuration Wizard, you select the following features:
Hybrid business to business (B2B) sites
Hybrid OneDrive
Hybrid Search
Which two requirements are met by using the SharePoint Hybrid Configuration Wizard features? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  • A. Users must be able to follow both on-premises and cloud-based sites.
  • B. When users search for a document by using keywords, the results must include online and on-premises results.
  • C. Users must have a single SharePoint profile for both on-premises and on the cloud.
  • D. OneDrive sites must redirect users to online content.

Answer: B,D

Explanation:
Hybrid OneDrive - Choosing this option will redirect on-premises My Sites/OneDrive for Business sites to SharePoint Online OneDrive for Business in Office 365. Once the wizard completes, any click of the OneDrive link from on-premises will redirect to OneDrive for Business in the cloud. This meets the following requirement: OneDrive sites must redirect users to online content.
Cloud hybrid search - Choosing this option creates a cloud Search service application in SharePoint Server and connects the cloud Search service application to your Office 365 tenant. This meets the following requirement: When users search for a document by using keywords, the results must include online and on-premises results.
Reference:
https://docs.microsoft.com/en-us/sharepoint/hybrid/hybrid-picker-in-the-sharepoint-online-admin-center

 

NEW QUESTION 97
Your company has a Microsoft 365 subscription that has multi-factor authentication configured for all users.
Users that connect to Microsoft 365 services report that they are prompted for multi-factor authentication multiple times a day.
You need to reduce the number of times the users are prompted for multi-factor authentication on their company-owned devices. Your solution must ensure that users are still prompted for MFA.
What should you do?

  • A. Enable the multi-factor authentication trusted IPs setting, and then verify each device as a trusted device.
  • B. Enable the remember multi-factor authentication setting, and then join all client computers to Microsoft Azure Active Directory (Azure AD).
  • C. Enable the multi-factor authentication trusted IPs setting, and then join all client computers to Microsoft Azure Active Directory (Azure AD).
  • D. Enable the remember multi-factor authentication setting, and then verify each device as a trusted device.

Answer: D

Explanation:
The remember Multi-Factor Authentication feature for devices and browsers that are trusted by the user is a free feature for all Multi-Factor Authentication users. Users can bypass subsequent verifications for a specified number of days, after they've successfully signed-in to a device by using Multi-Factor Authentication. The feature enhances usability by minimizing the number of times a user has to perform two-step verification on the same device.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings

 

NEW QUESTION 98
You have a Microsoft 365 subscription. All users have client computers that run Windows 10 and have Microsoft 365 Apps for enterprise installed.
Some users in the research department work for extended periods of time without an Internet connection.
How many days can the research department users remain offline before they are prevented from editing Office documents?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A

Explanation:
After 30 days, Microsoft 365 Apps for enterprise will go into reduced functionality mode. When this happens, users will be able to open files but they won't be able to edit them.
As part of the installation process, Microsoft 365 Apps for enterprise communicates with the Office Licensing Service and the Activation and Validation Service to obtain and activate a product key. Each day, or each time the user logs on to their computer, the computer connects to the Activation and Validation Service to verify the license status and extend the product key. As long as the computer can connect to the Internet at least once every 30 days, Office remains fully functional. If the computer goes offline for more than 30 days, Office enters reduced functionality mode until the next time a connection can be made.
Reference:
https://docs.microsoft.com/en-us/deployoffice/overview-of-licensing-and-activation-in-office-365-proplus

 

NEW QUESTION 99
Your network contains two on-premises Active Directory forests named contoso.com and fabrikam.com.
Fabrikam.com contains one domain and five domain controllers. Contoso.com contains the domains shown in the following table.

You need to sync all the users from both the forests to a single Azure Active Directory (Azure AD) tenant by using Azure AD Connect.
What is the minimum number of Azure AD Connect sync servers required?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: C

Explanation:
Explanation/Reference:
You can have only one active Azure AD Connect server synchronizing accounts to a single Azure Active Directory (Azure AD) tenant. You can have 'backup' Azure AD Connect servers, but these must be running in
'staging' mode. Staging mode means the Azure AD Connect instance is not actively synchronizing users but is ready to be bought online if the active Azure AD Connect instance goes offline.
When you have multiple forests, all forests must be reachable by a single Azure AD Connect sync server. The server must be joined to a domain. If necessary, to reach all forests, you can place the server in a perimeter network (also known as DMZ, demilitarized zone, and screened subnet).
References:
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies#multiple-forests-single- azure-ad-tenant

 

NEW QUESTION 100
Your company has a Microsoft 365 subscription.
You upload several archive PST files to Microsoft 365 by using the Security & Compliance admin center.
A month later, you attempt to run an import job for the PST files.
You discover that the PST files were deleted from Microsoft 365.
What is the most likely cause of the files being deleted? More than one answer choice may achieve the
goal. Select the BEST answer.

  • A. The PST files were corrupted and deleted by Microsoft 365 security features.
  • B. Another administrator deleted the PST files.
  • C. PST files are deleted automatically from Microsoft 365 after 30 days.
  • D. The size of the PST files exceeded a storage quota and caused the files to be deleted.

Answer: C

Explanation:
Explanation/Reference:
References:
https://docs.microsoft.com/en-us/office365/securitycompliance/faqimporting-pst-files-to-office-365

 

NEW QUESTION 101
Your network contains an on-premises Active Directory domain.
Your company has a security policy that prevents additional software from being installed on domain controllers.
You need to monitor a domain controller by using Microsoft Azure Advanced Threat Protection (ATP).
What should you do? More than once choice may achieve the goal. Select the BEST answer.

  • A. Deploy an Azure ATP sensor, and then configure detections.
  • B. Deploy an Azure ATP sensor, and then configure port mirroring.
  • C. Deploy an Azure ATP standalone sensor, and then configure detections.
  • D. Deploy an Azure ATP standalone sensor, and then configure port mirroring.

Answer: A

Explanation:
Explanation
If you're installing on a domain controller, you don't need a standalone ATP sensor. You need to configure the detections to detect application installations. With an ATP sensor (non-standalone), you don't need to configure port mirroring.
Reference:
https://docs.microsoft.com/en-us/azure-advanced-threat-protection/install-atp-step5
https://docs.microsoft.com/en-us/azure-advanced-threat-protection/atp-capacity-planning#choosing-the-right-sen

 

NEW QUESTION 102
Your company has a Microsoft Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com.
You purchase a domain named contoso.com from a registrar and add all the required DNS records.
You create a user account named User1. User1 is configured to sign in as [email protected].
You need to configure User1 to sign in as [email protected].
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

Explanation

The first step is to add the contoso.com domain to Office 365. You do this by adding a custom domain. When you add a custom domain to office 365, you can use the domain as your email address or to sign in to Office
365.
The second step is to verify the custom domain. This is to prove that you own the domain. You can verify the custom domain by adding a DNS record to the domain DNS zone.
When you have added and verified the domain, you can configure the user accounts to use it. To configure User1 to sign in as [email protected], you need to change the username of User1. In Office 365, the username is composed of two parts. The first part is the actual username (User1) and the second part is the domain. You need to modify the username of User1 by selecting the contoso.com domain from the dropdown list of domains. The dropdown list of domains contains the <domain>.onmicrosoft.com domain and any custom domains that have been added.
Reference:
https://docs.microsoft.com/en-us/office365/admin/setup/add-domain?view=o365-worldwide

 

NEW QUESTION 103
You have a Microsoft 365 subscription and a DNS domain. The domain is hosted by a third-party DNS service.
You plan to add the domain to the subscription.
You need to use Microsoft Exchange Online to send and receive emails for the domain.
Which type of DNS record should you add to the DNS zone of the domain for each task? To answer, drag the appropriate records to the correct tasks. Each record may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider?view=o365-worldwide

 

NEW QUESTION 104
Your company has a Microsoft 365 subscription.
You need to identify which users performed the following privileged administration tasks:
* Deleted a folder from the second-stage Recycle Bin if Microsoft SharePoint
* Opened a mailbox of which the user was not the owner
* Reset a user password
What should you use?

  • A. Security & Compliance audit log search
  • B. Microsoft Azure Active Directory (Azure AD) audit logs
  • C. Microsoft Azure Active Directory (Azure AD) sign-ins
  • D. Security & Compliance content search

Answer: B

Explanation:
Explanation
References:
https://docs.microsoft.com/en-us/azure/azure-monitor/platform/activity-logs-overview

 

NEW QUESTION 105
Please wait while the virtual machine loads. Once loaded, you may proceed to the lab section. This may take a few minutes, and the wait time will not be deducted from your overall test time.
When the Next button is available, click it to access the lab section. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design.
Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn't matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
You may now click next to proceed to the lab.
Lab information
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Microsoft 365 Username:[email protected]
Microsoft 365 Password:m3t^We$Z7&xy
If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support purposes only:
Lab Instance:11440873

Your organization recently purchased a projector that can be moved easily between conference rooms.
You need to ensure that any user in the organization can add the projector to a Microsoft Outlook meeting request. The solution must ensure that a user named Lee Gu must approve all meeting requests.
To answer, sign in to the Microsoft 365 portal.

Answer:

Explanation:
See explanation below.
Explanation
You need to create a resource mailbox in Exchange.
1. Go to the Exchange Admin Center.
2. In the left navigation pane, select Recipients.
3. Click the Resources link.
4. Click the plus (+) icon and select 'Equipment Mailbox'.
5. Give the mailbox a name such as 'Projector1'.
6. Enter the name projector1 in the email address field.
7. Click the Save button to create the equipment mailbox.
8. In the resource mailbox list, select the new mailbox and click the Edit icon (pencil icon).
9. Select 'Booking Delegates' in the menu list.
10. Select the option, "Select delegates who can accept or decline booking requests".
11. Click the plus (+) icon and add Lee Gu as a delegate.
12. Click the Save button to save the changes.

 

NEW QUESTION 106
Your company has a Microsoft 365 subscription that has multi-factor authentication configured for all users.
Users that connect to Microsoft 365 services report that they are prompted for multi-factor authentication multiple times a day.
You need to reduce the number of times the users are prompted for multi-factor authentication on their company-owned devices. Your solution must ensure that users are still prompted for MFA.
What should you do?

  • A. Enable the multi-factor authentication trusted IPs setting, and then verify each device as a trusted device.
  • B. Enable the remember multi-factor authentication setting, and then join all client computers to Microsoft Azure Active Directory (Azure AD).
  • C. Enable the multi-factor authentication trusted IPs setting, and then join all client computers to Microsoft Azure Active Directory (Azure AD).
  • D. Enable the remember multi-factor authentication setting, and then verify each device as a trusted device.

Answer: D

Explanation:
Section: [none]
Explanation:
The remember Multi-Factor Authentication feature for devices and browsers that are trusted by the user is a free feature for all Multi-Factor Authentication users. Users can bypass subsequent verifications for a specified number of days, after they've successfully signed-in to a device by using Multi-Factor Authentication. The feature enhances usability by minimizing the number of times a user has to perform two-step verification on the same device.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings

 

NEW QUESTION 107
Your network contains an on-premises Active Directory domain. The domain contains a server named Server1. Server1 has a share named Share1 that contains the files shown in the following table.

You have a hybrid deployment of Microsoft 365.
You create a Microsoft SharePoint site collection named Col lection1.
You plan to migrate Share1 to a document library in Collection1
You configure the SharePoint Migration Tool as shown in the exhibit. (Click the Exhibit tab.) For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

References:
https://docs.microsoft.com/en-us/sharepointmigration/spmt-settings

 

NEW QUESTION 108
Your network contains an on-premises Active Directory domain.
You have a Microsoft 365 subscription.
You implement a directory synchronization solution that uses pass-through authentication.
You configure Microsoft Azure Active Directory (Azure AD) smart lockout as shown in the following exhibit.

You discover that Active Directory users can use the passwords in the custom banned passwords list.
You need to ensure that banned passwords are effective for all users.
Which three actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. From Custom banned passwords, modify the Enforce custom list setting.
  • B. From a domain controller, install the Microsoft AAD Application Proxy connector.
  • C. From all the domain controllers, install the Azure AD Password Protection DC Agent.
  • D. From a domain controller, install the Azure AD Password Protection Proxy.
  • E. From Password protection for Windows Server Active Directory, modify the Mode setting.
  • F. From Active Directory, modify the Default Domain Policy.

Answer: A,C,D

 

NEW QUESTION 109
You have several Microsoft SharePoint document libraries in your on-premises environment.
You have a Microsoft 365 tenant that has directory synchronization implemented.
You plan to move all the document libraries to SharePoint Online.
You need to recommend a migration strategy for the document libraries.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

Explanation

The SharePoint Migration Tool lets you migrate content to SharePoint Online and OneDrive from the following locations:
* SharePoint Server 2013
* SharePoint Server 2010
* Network and local file shares
The first step is to create new SharePoint sites in SharePoint online. These sites will host the document libraries which will host the migrated content.
The second step is to create the document libraries in the SharePoint sites to host the migrated content.
The final step is to use the SharePoint Migration Tool to migrate the content.
Reference:
https://docs.microsoft.com/en-us/sharepointmigration/how-to-use-the-sharepoint-migration-tool

 

NEW QUESTION 110
Your company has an Azure Active Directory (Azure AD) tenant named contoso.com that contains 10,000 users.
The company has a Microsoft 365 subscription.
You enable Azure Multi-Factor Authentication (MFA) for all the users in contoso.com.
You run the following query. search "SigninLogs" | where ResultDescription == "User did not pass the MFA challenge." The query returns blank results.
You need to ensure that the query returns the expected results.
What should you do?

  • A. From the Security & Compliance admin center, enable Office 365 Analytics.
  • B. From the Security & Compliance admin center, turn on auditing.
  • C. From the Azure Active Directory admin center, configure the diagnostics settings to send logs to an Azure Log Analytics workplace.
  • D. From the Azure Active Directory admin center, configure the diagnostics settings to archive logs to an Azure Storage account.

Answer: C

Explanation:
You can now send audit logs to Azure Log Analytics. This gives you much easier reporting on audit events and the ability to perform queries such as the one in this question.
References:
https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/howto-integrate-activity-logs-with-log-analytics

 

NEW QUESTION 111
You have a Microsoft 365 subscription that uses an Azure Active Directory (Azure AD) tenant named contoso.com.
A temporary employee at your company uses an email address of [email protected].
You need to ensure that the temporary employee can sign in to contoso.com by using the [email protected] account.
What should you do?

  • A. From the Microsoft 365 admin center, create a new contact.
  • B. From the Azure Active Directory admin center, create a new guest user.
  • C. From the Microsoft 365 admin center, create a new user.
  • D. From the Azure Active Directory admin center, create a new user.

Answer: B

Explanation:
Section: [none]
Explanation:
You can invite guest users to the directory, to a group, or to an application. After you invite a user through any of these methods, the invited user's account is added to Azure Active Directory (Azure AD), with a user type of Guest. The guest user must then redeem their invitation to access resources. An invitation of a user does not expire.
The invitation will include a link to create a Microsoft account. The user can then authenticate using their Microsoft account. In this question, the external vendor already has a Microsoft account ([email protected]) so he can authenticate using that.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/b2b/add-users-administrator

 

NEW QUESTION 112
You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com that includes a user named User1.
You enable multi-factor authentication for contoso.com and configure the following two fraud alert settings:
* Set Allow users to submit fraud alerts: On
* Automatically block users who report fraud: On
You need to instruct the users in your organization to use the fraud reporting features correctly.
What should you tell the users to do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

Code to report fraud during initial greeting: When users receive a phone call to perform two-step verification, they normally press # to confirm their sign-in. To report fraud, the user enters a code before pressing #. This code is 0 by default, but you can customize it.
Block user when fraud is reported: If a user reports fraud, their account is blocked for 90 days or until an administrator unblocks their account. An administrator can review sign-ins by using the sign-in report, and take appropriate action to prevent future fraud. An administrator can then unblock the user's account.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings#fraud-alert

 

NEW QUESTION 113
......


Microsoft MS-100: Preparation Process

The Microsoft Learning Platform offers a wide range of resources to help the candidates prepare for the Microsoft MS-100 exam. The students who do not have a training budget can use free online tools while those who can afford to go through the instructor-led training also have the opportunity.

  • Free Online Training

    This training tool offers a series of learning modules that the applicants can explore. For the Microsoft MS-100 exam, they can use the following learning paths:

    • Protect Identity & Access with Azure AD
    • Manage Identity & Access in Azure AD
    • Microsoft 365: Modernize Your Enterprise Deployments with Windows 10 & Microsoft 365 Apps
    • Stay Current with Windows 10 & Microsoft 365 Apps
    • Managing Your Enterprise Deployment with Microsoft 365

    Each of these learning paths has different modules that highlight the topics of the exam. Using these resources will help improve your performance and equip you with the skills required to get certified.

  • Instructor-Led Training

    The Microsoft 365 Identity & Services training course covers three core elements of the Microsoft 365 enterprise administration, including Microsoft 365 Tenant & Service Management, Microsoft 365 Identity Management, and Office 365 Management. Each aspect of the exam content is treated in detail within the course to help the candidates develop the practical skills as well as knowledge required to ace the test. The instructor-led training can be taken in a classroom or online.

 

MS-100 Real Exam Questions and Answers FREE: https://easypass.examsreviews.com/MS-100-pass4sure-exam-review.html