Microsoft MS-102 Defender For Office 365 Threat Policies Rules And Alert Policies Practice Test
MS-102 skills 3.2 | 30 original questions
This MS-102 practice set focuses on defender for office 365 threat policies rules and alert policies through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.
Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.
Question 1
Graphic Design Institute has completed a pilot and must now choose the production administration approach. An internal assessment finds the control technically functional but unable to protect users when they select URLs in supported email, Office, and collaboration content. The service desk has 66 related tickets from 22 business units, so the team wants a targeted fix. The solution should use a native Microsoft control that matches the stated requirement. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: D
Why: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. It directly addresses the stated requirement.
Option review:
A: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. It directly addresses the stated requirement.
E: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q001: Configure a Safe Links policy – Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats.
Question 2
Litware Financial is preparing a change requested by the compliance administrator. The implementation review is focused on one outcome: detonate or analyze suspicious attachments for unknown malware before users access them. The service desk has 83 related tickets from 12 business units, so the team wants a targeted fix. The team does not want to redesign unrelated workloads. What should the administrator configure first?
Correct answer: E
Why: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. It directly addresses the stated requirement.
Option review:
A: Closing a change ticket is not proof of risk reduction; Defender Vulnerability Management should reflect improved exposure after telemetry updates. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. It directly addresses the stated requirement.
Learning point: MS102-T14-Q002: Configure a Safe Attachments policy – Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection.
Question 3
Graphic Design Institute is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The support team has reproduced the issue and narrowed it to this requirement: apply a consistent set of Defender for Office 365 protections without individually tuning every policy. The service desk has 9 related tickets from 2 business units, so the team wants a targeted fix. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which administrative choice should be recommended?
Correct answer: A
Why: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. It directly addresses the stated requirement.
Option review:
A: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. It directly addresses the stated requirement.
B: Secure Score recommendations provide context for remediation and progress tracking instead of requiring administrators to infer actions from raw alert counts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Closing a change ticket is not proof of risk reduction; Defender Vulnerability Management should reflect improved exposure after telemetry updates. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q003: Use preset security policies when a standardized Microsoft-recommended protection baseline meets the requirement – Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines.
Question 4
During a tenant review at Proseware Logistics, the governance lead identifies one unresolved requirement. The organization is replacing a manual process. The replacement must protect users when they select URLs in supported email, Office, and collaboration content while remaining centrally manageable. The control owner requires a review after 26 days and evidence from 15 representative cases. The change must be repeatable and supportable after the project team leaves. What is the most appropriate next step?
Correct answer: B
Why: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. It directly addresses the stated requirement.
Option review:
A: Remediation workflows let security teams request, track, and validate vulnerability fixes instead of treating recommendations as a static report. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. It directly addresses the stated requirement.
C: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Secure Score recommendations provide context for remediation and progress tracking instead of requiring administrators to infer actions from raw alert counts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q004: Configure a Safe Links policy – Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats.
Question 5
A quarterly control review at Contoso Retail identifies a gap that must be corrected before the next audit. A post-incident action item requires the tenant to detonate or analyze suspicious attachments for unknown malware before users access them. The team will validate the change with 5 pilot groups before expanding it to 43 users. The design should minimize manual per-user administration where a scoped central control exists. Which option best satisfies the requirement?
Correct answer: C
Why: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. It directly addresses the stated requirement.
Option review:
A: Security Exposure Management helps connect exposure signals into attack paths and initiatives, supporting risk-based prioritization beyond isolated findings. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. It directly addresses the stated requirement.
D: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Remediation workflows let security teams request, track, and validate vulnerability fixes instead of treating recommendations as a static report. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q005: Configure a Safe Attachments policy – Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection.
Question 6
Northwind Traders is standardizing administration after several teams used inconsistent procedures. Administrators have confirmed the present design does not apply a consistent set of Defender for Office 365 protections without individually tuning every policy. The team will validate the change with 18 pilot groups before expanding it to 60 users. The team must preserve a clear audit trail for the administrative decision. Which action should the administrator take?
Correct answer: D
Why: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. It directly addresses the stated requirement.
Option review:
A: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. It directly addresses the stated requirement.
E: Security Exposure Management helps connect exposure signals into attack paths and initiatives, supporting risk-based prioritization beyond isolated findings. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q006: Use preset security policies when a standardized Microsoft-recommended protection baseline meets the requirement – Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines.
Question 7
During a tenant review at Blue Yonder Airlines, the hybrid identity engineer identifies one unresolved requirement. The change advisory board wants the smallest supported control that can protect users when they select URLs in supported email, Office, and collaboration content. The affected scope contains 77 users across 8 administrative groups. The design should minimize manual per-user administration where a scoped central control exists. Which action should the administrator take?
Correct answer: E
Why: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. It directly addresses the stated requirement.
Option review:
A: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. It directly addresses the stated requirement.
Learning point: MS102-T14-Q007: Configure a Safe Links policy – Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats.
Question 8
Fourth Coffee is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The administrator is comparing native Microsoft controls after documenting a requirement to detonate or analyze suspicious attachments for unknown malware before users access them. The control owner requires a review after 94 days and evidence from 21 representative cases. The architecture board will reject a choice that solves a different problem from the one stated. Which action should the administrator take?
Correct answer: A
Why: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. It directly addresses the stated requirement.
Option review:
A: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. It directly addresses the stated requirement.
B: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Severity alone can be insufficient; active exploitation signals and organizational exposure provide stronger prioritization context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q008: Configure a Safe Attachments policy – Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection.
Question 9
Woodgrove Bank is preparing a change requested by the security administrator. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to apply a consistent set of Defender for Office 365 protections without individually tuning every policy. The team will validate the change with 11 pilot groups before expanding it to 20 users. The solution should use a native Microsoft control that matches the stated requirement. Which option best satisfies the requirement?
Correct answer: B
Why: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. It directly addresses the stated requirement.
Option review:
A: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. It directly addresses the stated requirement.
C: Exposure initiatives organize related recommendations around measurable security objectives, making them better suited than isolated alerts for posture improvement programs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q009: Use preset security policies when a standardized Microsoft-recommended protection baseline meets the requirement – Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines.
Question 10
Lucerne Publishing has completed a pilot and must now choose the production administration approach. The service owner wants a supportable design that will protect users when they select URLs in supported email, Office, and collaboration content. The response must address the cause described in the scenario rather than simply suppressing the symptom. The initial rollout covers 24 locations and approximately 370 managed identities or devices. Which action should the administrator take?
Correct answer: C
Why: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. It directly addresses the stated requirement.
Option review:
A: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Affected-device context helps scope remediation effort and identify whether critical or internet-exposed systems need accelerated treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. It directly addresses the stated requirement.
D: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q010: Configure a Safe Links policy – Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats.
Question 11
The operations team at Humongous Insurance needs to resolve an issue without granting broader permissions than necessary. Audit evidence shows that the current process cannot reliably detonate or analyze suspicious attachments for unknown malware before users access them. The architecture board will reject a choice that solves a different problem from the one stated. The affected scope contains 54 users across 14 administrative groups. Which approach most directly addresses the requirement?
Correct answer: D
Why: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. It directly addresses the stated requirement.
Option review:
A: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Secure Score is a posture indicator, not a complete risk model; exposure, asset criticality, and exploitability should inform remediation priority. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. It directly addresses the stated requirement.
E: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q011: Configure a Safe Attachments policy – Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection.
Question 12
Wide World Importers is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to apply a consistent set of Defender for Office 365 protections without individually tuning every policy. The organization wants a reversible rollout with measurable verification before broad enforcement. The service desk has 71 related tickets from 4 business units, so the team wants a targeted fix. Which action should the administrator take?
Correct answer: E
Why: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. It directly addresses the stated requirement.
Option review:
A: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. It directly addresses the stated requirement.
Learning point: MS102-T14-Q012: Use preset security policies when a standardized Microsoft-recommended protection baseline meets the requirement – Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines.
Question 13
An incident review at Blue Yonder Airlines produces a single administrative requirement for the tenant administrator. A controlled pilot must demonstrate how to protect users when they select URLs in supported email, Office, and collaboration content. The administrator must avoid granting unrelated tenant-wide privilege. The team will validate the change with 17 pilot groups before expanding it to 88 users. Which approach most directly addresses the requirement?
Correct answer: A
Why: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. It directly addresses the stated requirement.
Option review:
A: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. It directly addresses the stated requirement.
B: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Secure Score surfaces recommended security actions and scoring so administrators can prioritize improvements and track security posture progress. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q013: Configure a Safe Links policy – Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats.
Question 14
The operations team at Wide World Importers needs to resolve an issue without granting broader permissions than necessary. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to detonate or analyze suspicious attachments for unknown malware before users access them. The response must address the cause described in the scenario rather than simply suppressing the symptom. The control owner requires a review after 14 days and evidence from 7 representative cases. What is the most appropriate next step?
Correct answer: B
Why: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. It directly addresses the stated requirement.
Option review:
A: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. It directly addresses the stated requirement.
C: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q014: Configure a Safe Attachments policy – Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection.
Question 15
Correct answer: C
Why: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. It directly addresses the stated requirement.
Option review:
A: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. It directly addresses the stated requirement.
D: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q015: Use preset security policies when a standardized Microsoft-recommended protection baseline meets the requirement – Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines.
Question 16
The operations team at Lucerne Publishing needs to resolve an issue without granting broader permissions than necessary. The implementation review is focused on one outcome: generate alerts when defined email or collaboration security activity meets the policy criteria. The service desk has 48 related tickets from 10 business units, so the team wants a targeted fix. The team does not want to redesign unrelated workloads. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: D
Why: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. It directly addresses the stated requirement.
Option review:
A: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Closing a change ticket is not proof of risk reduction; Defender Vulnerability Management should reflect improved exposure after telemetry updates. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. It directly addresses the stated requirement.
E: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q016: Create a Microsoft Defender for Office 365 alert policy – Alert policies define the conditions and notification behavior for security events that should create administrator alerts.
Question 17
Wingtip Services is preparing a change requested by the hybrid identity engineer. The organization is replacing a manual process. The replacement must reduce noisy notifications while preserving the underlying protective control while remaining centrally manageable. The affected scope contains 65 users across 23 administrative groups. Existing workload settings should remain unchanged unless the requirement specifically depends on them. What should the administrator configure first?
Correct answer: E
Why: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. It directly addresses the stated requirement.
Option review:
A: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Secure Score recommendations provide context for remediation and progress tracking instead of requiring administrators to infer actions from raw alert counts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. It directly addresses the stated requirement.
Learning point: MS102-T14-Q017: Tune alert policy thresholds or recipients instead of weakening threat protection – Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself.
Question 18
Woodgrove Bank is standardizing administration after several teams used inconsistent procedures. Before the tenant expands to another business unit, the administrator must generate alerts when defined email or collaboration security activity meets the policy criteria. The initial rollout covers 13 locations and approximately 820 managed identities or devices. The solution should use a native Microsoft control that matches the stated requirement. Which control should the team use?
Correct answer: A
Why: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. It directly addresses the stated requirement.
Option review:
A: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. It directly addresses the stated requirement.
B: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Remediation workflows let security teams request, track, and validate vulnerability fixes instead of treating recommendations as a static report. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q018: Create a Microsoft Defender for Office 365 alert policy – Alert policies define the conditions and notification behavior for security events that should create administrator alerts.
Question 19
The operations team at Woodgrove Bank needs to resolve an issue without granting broader permissions than necessary. Security and operations teams agree on the target state: reduce noisy notifications while preserving the underlying protective control. The response must address the cause described in the scenario rather than simply suppressing the symptom. The affected scope contains 8 users across 3 administrative groups. What is the most appropriate next step?
Correct answer: B
Why: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. It directly addresses the stated requirement.
Option review:
A: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. It directly addresses the stated requirement.
C: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Security Exposure Management helps connect exposure signals into attack paths and initiatives, supporting risk-based prioritization beyond isolated findings. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q019: Tune alert policy thresholds or recipients instead of weakening threat protection – Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself.
Question 20
An incident review at Tailspin Toys produces a single administrative requirement for the security administrator. An internal assessment finds the control technically functional but unable to generate alerts when defined email or collaboration security activity meets the policy criteria. The team will validate the change with 16 pilot groups before expanding it to 25 users. The organization wants a reversible rollout with measurable verification before broad enforcement. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: C
Why: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. It directly addresses the stated requirement.
Option review:
A: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. It directly addresses the stated requirement.
D: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q020: Create a Microsoft Defender for Office 365 alert policy – Alert policies define the conditions and notification behavior for security events that should create administrator alerts.
Question 21
Graphic Design Institute is standardizing administration after several teams used inconsistent procedures. A production change is approved only if it can reduce noisy notifications while preserving the underlying protective control. The change must be repeatable and supportable after the project team leaves. The control owner requires a review after 42 days and evidence from 6 representative cases. Which action should the administrator take?
Correct answer: D
Why: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. It directly addresses the stated requirement.
Option review:
A: Severity alone can be insufficient; active exploitation signals and organizational exposure provide stronger prioritization context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. It directly addresses the stated requirement.
E: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q021: Tune alert policy thresholds or recipients instead of weakening threat protection – Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself.
Question 22
Alpine Ski House has completed a pilot and must now choose the production administration approach. An internal assessment finds the control technically functional but unable to generate alerts when defined email or collaboration security activity meets the policy criteria. The team will validate the change with 19 pilot groups before expanding it to 59 users. The change must be repeatable and supportable after the project team leaves. What is the most appropriate next step?
Correct answer: E
Why: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. It directly addresses the stated requirement.
Option review:
A: Exposure initiatives organize related recommendations around measurable security objectives, making them better suited than isolated alerts for posture improvement programs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Severity alone can be insufficient; active exploitation signals and organizational exposure provide stronger prioritization context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. It directly addresses the stated requirement.
Learning point: MS102-T14-Q022: Create a Microsoft Defender for Office 365 alert policy – Alert policies define the conditions and notification behavior for security events that should create administrator alerts.
Question 23
Proseware Logistics has completed a pilot and must now choose the production administration approach. An internal assessment finds the control technically functional but unable to reduce noisy notifications while preserving the underlying protective control. The control owner requires a review after 76 days and evidence from 9 representative cases. The organization wants a reversible rollout with measurable verification before broad enforcement. Which administrative choice should be recommended?
Correct answer: A
Why: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. It directly addresses the stated requirement.
Option review:
A: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. It directly addresses the stated requirement.
B: Affected-device context helps scope remediation effort and identify whether critical or internet-exposed systems need accelerated treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Exposure initiatives organize related recommendations around measurable security objectives, making them better suited than isolated alerts for posture improvement programs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q023: Tune alert policy thresholds or recipients instead of weakening threat protection – Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself.
Question 24
Alpine Ski House has completed a pilot and must now choose the production administration approach. The current workaround is too manual. The replacement should generate alerts when defined email or collaboration security activity meets the policy criteria. The control owner requires a review after 93 days and evidence from 22 representative cases. The change must be repeatable and supportable after the project team leaves. Which control should the team use?
Correct answer: B
Why: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. It directly addresses the stated requirement.
Option review:
A: Secure Score is a posture indicator, not a complete risk model; exposure, asset criticality, and exploitability should inform remediation priority. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. It directly addresses the stated requirement.
C: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Affected-device context helps scope remediation effort and identify whether critical or internet-exposed systems need accelerated treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q024: Create a Microsoft Defender for Office 365 alert policy – Alert policies define the conditions and notification behavior for security events that should create administrator alerts.
Question 25
Contoso Retail is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The service owner wants a supportable design that will reduce noisy notifications while preserving the underlying protective control. The response must address the cause described in the scenario rather than simply suppressing the symptom. The initial rollout covers 12 locations and approximately 190 managed identities or devices. Which control should the team use?
Correct answer: C
Why: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. It directly addresses the stated requirement.
Option review:
A: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. It directly addresses the stated requirement.
D: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Secure Score is a posture indicator, not a complete risk model; exposure, asset criticality, and exploitability should inform remediation priority. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q025: Tune alert policy thresholds or recipients instead of weakening threat protection – Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself.
Question 26
The service desk lead at Fabrikam Health is designing the next phase of the Microsoft 365 rollout. Before the tenant expands to another business unit, the administrator must generate alerts when defined email or collaboration security activity meets the policy criteria. The control owner requires a review after 36 days and evidence from 2 representative cases. The design should minimize manual per-user administration where a scoped central control exists. Which administrative choice should be recommended?
Correct answer: D
Why: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. It directly addresses the stated requirement.
Option review:
A: Secure Score surfaces recommended security actions and scoring so administrators can prioritize improvements and track security posture progress. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. It directly addresses the stated requirement.
E: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q026: Create a Microsoft Defender for Office 365 alert policy – Alert policies define the conditions and notification behavior for security events that should create administrator alerts.
Question 27
A quarterly control review at Contoso Retail identifies a gap that must be corrected before the next audit. The existing configuration works for normal operations but fails the new requirement to reduce noisy notifications while preserving the underlying protective control. The team must preserve a clear audit trail for the administrative decision. The affected scope contains 53 users across 15 administrative groups. Which action should the administrator take?
Correct answer: E
Why: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. It directly addresses the stated requirement.
Option review:
A: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Secure Score surfaces recommended security actions and scoring so administrators can prioritize improvements and track security posture progress. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. It directly addresses the stated requirement.
Learning point: MS102-T14-Q027: Tune alert policy thresholds or recipients instead of weakening threat protection – Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself.
Question 28
A quarterly control review at Northwind Traders identifies a gap that must be corrected before the next audit. The service owner wants a supportable design that will generate alerts when defined email or collaboration security activity meets the policy criteria. The administrator must avoid granting unrelated tenant-wide privilege. The team will validate the change with 5 pilot groups before expanding it to 70 users. Which option best satisfies the requirement?
Correct answer: A
Why: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. It directly addresses the stated requirement.
Option review:
A: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. It directly addresses the stated requirement.
B: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q028: Create a Microsoft Defender for Office 365 alert policy – Alert policies define the conditions and notification behavior for security events that should create administrator alerts.
Question 29
An incident review at Woodgrove Bank produces a single administrative requirement for the governance lead. An internal assessment finds the control technically functional but unable to reduce noisy notifications while preserving the underlying protective control. The control owner requires a review after 87 days and evidence from 18 representative cases. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. What is the most appropriate next step?
Correct answer: B
Why: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. It directly addresses the stated requirement.
Option review:
A: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. It directly addresses the stated requirement.
C: Closing a change ticket is not proof of risk reduction; Defender Vulnerability Management should reflect improved exposure after telemetry updates. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q029: Tune alert policy thresholds or recipients instead of weakening threat protection – Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself.
Question 30
Tailspin Toys has completed a pilot and must now choose the production administration approach. The service owner wants a supportable design that will generate alerts when defined email or collaboration security activity meets the policy criteria. The solution should use a native Microsoft control that matches the stated requirement. The control owner requires a review after 13 days and evidence from 8 representative cases. Which administrative choice should be recommended?
Correct answer: C
Why: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. It directly addresses the stated requirement.
Option review:
A: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Secure Score recommendations provide context for remediation and progress tracking instead of requiring administrators to infer actions from raw alert counts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. It directly addresses the stated requirement.
D: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T14-Q030: Create a Microsoft Defender for Office 365 alert policy – Alert policies define the conditions and notification behavior for security events that should create administrator alerts.
Popular posts
Recent Posts
