Microsoft MS-102 Defender For Cloud Apps Connectors Policies Activity Logs Practice Test
MS-102 skills 3.4 | 28 original questions
This MS-102 practice set focuses on defender for cloud apps connectors policies activity logs and cloud app discovery through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.
Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.
Question 1
An incident review at Lucerne Publishing produces a single administrative requirement for the tenant administrator. A controlled pilot must demonstrate how to enable Defender for Cloud Apps visibility and governance for supported Microsoft 365 activity. The team must preserve a clear audit trail for the administrative decision. The control owner requires a review after 8 days and evidence from 13 representative cases. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: C
Why: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. It directly addresses the stated requirement.
Option review:
A: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. It directly addresses the stated requirement.
D: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Secure Score surfaces recommended security actions and scoring so administrators can prioritize improvements and track security posture progress. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q001: Connect Microsoft 365 to Microsoft Defender for Cloud Apps with the app connector – The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps.
Question 2
Trey Research is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The implementation review is focused on one outcome: troubleshoot missing Microsoft 365 activity in Defender for Cloud Apps after connector setup. The service desk has 25 related tickets from 3 business units, so the team wants a targeted fix. The team does not want to redesign unrelated workloads. Which option best satisfies the requirement?
Correct answer: D
Why: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. It directly addresses the stated requirement.
Option review:
A: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. It directly addresses the stated requirement.
E: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q002: Validate the app connector status and granted permissions – A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing.
Question 3
The operations team at Fourth Coffee needs to resolve an issue without granting broader permissions than necessary. The next migration wave is blocked until the team can enable Defender for Cloud Apps visibility and governance for supported Microsoft 365 activity. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The affected scope contains 42 users across 16 administrative groups. What should the administrator configure first?
Correct answer: E
Why: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. It directly addresses the stated requirement.
Option review:
A: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. It directly addresses the stated requirement.
Learning point: MS102-T18-Q003: Connect Microsoft 365 to Microsoft Defender for Cloud Apps with the app connector – The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps.
Question 4
During a tenant review at Fabrikam Health, the Microsoft 365 administrator identifies one unresolved requirement. The next migration wave is blocked until the team can troubleshoot missing Microsoft 365 activity in Defender for Cloud Apps after connector setup. The architecture board will reject a choice that solves a different problem from the one stated. The affected scope contains 59 users across 6 administrative groups. What should the administrator configure first?
Correct answer: A
Why: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. It directly addresses the stated requirement.
Option review:
A: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. It directly addresses the stated requirement.
B: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Secure Score recommendations provide context for remediation and progress tracking instead of requiring administrators to infer actions from raw alert counts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q004: Validate the app connector status and granted permissions – A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing.
Question 5
Correct answer: B
Why: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. It directly addresses the stated requirement.
Option review:
A: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. It directly addresses the stated requirement.
C: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Closing a change ticket is not proof of risk reduction; Defender Vulnerability Management should reflect improved exposure after telemetry updates. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q005: Connect Microsoft 365 to Microsoft Defender for Cloud Apps with the app connector – The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps.
Question 6
Lucerne Publishing is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The administrator is comparing native Microsoft controls after documenting a requirement to troubleshoot missing Microsoft 365 activity in Defender for Cloud Apps after connector setup. The control owner requires a review after 93 days and evidence from 9 representative cases. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which administrative choice should be recommended?
Correct answer: C
Why: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. It directly addresses the stated requirement.
Option review:
A: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Security Exposure Management helps connect exposure signals into attack paths and initiatives, supporting risk-based prioritization beyond isolated findings. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. It directly addresses the stated requirement.
D: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q006: Validate the app connector status and granted permissions – A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing.
Question 7
Trey Research is preparing a change requested by the security administrator. Before the tenant expands to another business unit, the administrator must detect a defined risky cloud activity pattern and notify the security team. The initial rollout covers 22 locations and approximately 190 managed identities or devices. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: D
Why: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. It directly addresses the stated requirement.
Option review:
A: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Remediation workflows let security teams request, track, and validate vulnerability fixes instead of treating recommendations as a static report. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. It directly addresses the stated requirement.
E: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q007: Create an activity policy in Defender for Cloud Apps with an alert – Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur.
Question 8
Southridge Video is preparing a change requested by the service desk lead. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to alert on suspicious cloud behavior or discovered application conditions rather than only static application configuration. The solution should use a native Microsoft control that matches the stated requirement. The service desk has 36 related tickets from 12 business units, so the team wants a targeted fix. What is the most appropriate next step?
Correct answer: E
Why: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. It directly addresses the stated requirement.
Option review:
A: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. It directly addresses the stated requirement.
Learning point: MS102-T18-Q008: Use an anomaly detection or app discovery policy when the requirement is behavior- or discovery-driven – Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios.
Question 9
Adventure Works is standardizing administration after several teams used inconsistent procedures. The organization is replacing a manual process. The replacement must detect a defined risky cloud activity pattern and notify the security team while remaining centrally manageable. The team will validate the change with 2 pilot groups before expanding it to 53 users. The architecture board will reject a choice that solves a different problem from the one stated. Which option best satisfies the requirement?
Correct answer: A
Why: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. It directly addresses the stated requirement.
Option review:
A: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. It directly addresses the stated requirement.
B: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q009: Create an activity policy in Defender for Cloud Apps with an alert – Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur.
Question 10
City Power & Light is standardizing administration after several teams used inconsistent procedures. The project board will approve the next step only if it can alert on suspicious cloud behavior or discovered application conditions rather than only static application configuration. The team will validate the change with 15 pilot groups before expanding it to 70 users. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which approach most directly addresses the requirement?
Correct answer: B
Why: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. It directly addresses the stated requirement.
Option review:
A: Severity alone can be insufficient; active exploitation signals and organizational exposure provide stronger prioritization context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. It directly addresses the stated requirement.
C: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Exposure initiatives organize related recommendations around measurable security objectives, making them better suited than isolated alerts for posture improvement programs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q010: Use an anomaly detection or app discovery policy when the requirement is behavior- or discovery-driven – Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios.
Question 11
Southridge Video is migrating a business process to Microsoft 365 and wants the narrowest supported solution. Security and operations teams agree on the target state: detect a defined risky cloud activity pattern and notify the security team. The administrator must avoid granting unrelated tenant-wide privilege. The affected scope contains 87 users across 5 administrative groups. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: C
Why: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. It directly addresses the stated requirement.
Option review:
A: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. It directly addresses the stated requirement.
D: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Severity alone can be insufficient; active exploitation signals and organizational exposure provide stronger prioritization context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q011: Create an activity policy in Defender for Cloud Apps with an alert – Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur.
Question 12
The operations team at Southridge Video needs to resolve an issue without granting broader permissions than necessary. A post-incident action item requires the tenant to alert on suspicious cloud behavior or discovered application conditions rather than only static application configuration. The service desk has 13 related tickets from 18 business units, so the team wants a targeted fix. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. What should the administrator configure first?
Correct answer: D
Why: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. It directly addresses the stated requirement.
Option review:
A: Affected-device context helps scope remediation effort and identify whether critical or internet-exposed systems need accelerated treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Secure Score is a posture indicator, not a complete risk model; exposure, asset criticality, and exploitability should inform remediation priority. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. It directly addresses the stated requirement.
E: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q012: Use an anomaly detection or app discovery policy when the requirement is behavior- or discovery-driven – Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios.
Question 13
An incident review at Trey Research produces a single administrative requirement for the Microsoft 365 administrator. The change advisory board wants the smallest supported control that can narrow a large cloud activity set to the events relevant to an investigation. The service desk has 30 related tickets from 8 business units, so the team wants a targeted fix. The architecture board will reject a choice that solves a different problem from the one stated. What is the most appropriate next step?
Correct answer: E
Why: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. It directly addresses the stated requirement.
Option review:
A: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Affected-device context helps scope remediation effort and identify whether critical or internet-exposed systems need accelerated treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. It directly addresses the stated requirement.
Learning point: MS102-T18-Q013: Filter the Defender for Cloud Apps activity log by user, IP address, activity, or application – The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior.
Question 14
During a tenant review at Wingtip Services, the Microsoft 365 administrator identifies one unresolved requirement. The existing configuration works for normal operations but fails the new requirement to understand whether the event is isolated or part of a broader risky pattern. The solution should use a native Microsoft control that matches the stated requirement. The team will validate the change with 21 pilot groups before expanding it to 47 users. Which action should the administrator take?
Correct answer: A
Why: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. It directly addresses the stated requirement.
Option review:
A: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. It directly addresses the stated requirement.
B: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Secure Score surfaces recommended security actions and scoring so administrators can prioritize improvements and track security posture progress. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q014: Pivot from a suspicious activity-log event to the related user or app context – Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines.
Question 15
The tenant administrator at Proseware Logistics is designing the next phase of the Microsoft 365 rollout. Security and operations teams agree on the target state: narrow a large cloud activity set to the events relevant to an investigation. The response must address the cause described in the scenario rather than simply suppressing the symptom. The affected scope contains 64 users across 11 administrative groups. Which action should the administrator take?
Correct answer: B
Why: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. It directly addresses the stated requirement.
Option review:
A: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. It directly addresses the stated requirement.
C: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q015: Filter the Defender for Cloud Apps activity log by user, IP address, activity, or application – The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior.
Question 16
Fourth Coffee is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The implementation review is focused on one outcome: understand whether the event is isolated or part of a broader risky pattern. The initial rollout covers 24 locations and approximately 810 managed identities or devices. The team does not want to redesign unrelated workloads. Which action should the administrator take?
Correct answer: C
Why: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. It directly addresses the stated requirement.
Option review:
A: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. It directly addresses the stated requirement.
D: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q016: Pivot from a suspicious activity-log event to the related user or app context – Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines.
Question 17
A quarterly control review at Contoso Retail identifies a gap that must be corrected before the next audit. Before the tenant expands to another business unit, the administrator must narrow a large cloud activity set to the events relevant to an investigation. The control owner requires a review after 7 days and evidence from 14 representative cases. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which administrative choice should be recommended?
Correct answer: D
Why: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. It directly addresses the stated requirement.
Option review:
A: Secure Score recommendations provide context for remediation and progress tracking instead of requiring administrators to infer actions from raw alert counts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. It directly addresses the stated requirement.
E: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q017: Filter the Defender for Cloud Apps activity log by user, IP address, activity, or application – The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior.
Question 18
Alpine Ski House is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The implementation review is focused on one outcome: understand whether the event is isolated or part of a broader risky pattern. The team will validate the change with 4 pilot groups before expanding it to 24 users. The team does not want to redesign unrelated workloads. Which administrative choice should be recommended?
Correct answer: E
Why: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. It directly addresses the stated requirement.
Option review:
A: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Closing a change ticket is not proof of risk reduction; Defender Vulnerability Management should reflect improved exposure after telemetry updates. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Secure Score recommendations provide context for remediation and progress tracking instead of requiring administrators to infer actions from raw alert counts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. It directly addresses the stated requirement.
Learning point: MS102-T18-Q018: Pivot from a suspicious activity-log event to the related user or app context – Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines.
Question 19
Consolidated Messenger is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The administrator is comparing native Microsoft controls after documenting a requirement to discover unsanctioned cloud applications actually used by the organization. The affected scope contains 41 users across 17 administrative groups. The design should minimize manual per-user administration where a scoped central control exists. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: A
Why: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. It directly addresses the stated requirement.
Option review:
A: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. It directly addresses the stated requirement.
B: Security Exposure Management helps connect exposure signals into attack paths and initiatives, supporting risk-based prioritization beyond isolated findings. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q019: Use Cloud App Discovery data from supported endpoint or network traffic sources – Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list.
Question 20
Correct answer: B
Why: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. It directly addresses the stated requirement.
Option review:
A: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. It directly addresses the stated requirement.
C: Remediation workflows let security teams request, track, and validate vulnerability fixes instead of treating recommendations as a static report. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Security Exposure Management helps connect exposure signals into attack paths and initiatives, supporting risk-based prioritization beyond isolated findings. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q020: Integrate Defender for Endpoint signals with Cloud App Discovery when endpoints are the chosen visibility source – Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs.
Question 21
During a tenant review at VanArsdel Media, the security operations analyst identifies one unresolved requirement. The organization is replacing a manual process. The replacement must discover unsanctioned cloud applications actually used by the organization while remaining centrally manageable. The affected scope contains 75 users across 20 administrative groups. The team must preserve a clear audit trail for the administrative decision. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: C
Why: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. It directly addresses the stated requirement.
Option review:
A: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. It directly addresses the stated requirement.
D: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q021: Use Cloud App Discovery data from supported endpoint or network traffic sources – Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list.
Question 22
Alpine Ski House has completed a pilot and must now choose the production administration approach. The project board will approve the next step only if it can discover cloud app usage from managed endpoint network activity. The initial rollout covers 10 locations and approximately 920 managed identities or devices. The design should minimize manual per-user administration where a scoped central control exists. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: D
Why: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. It directly addresses the stated requirement.
Option review:
A: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. It directly addresses the stated requirement.
E: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q022: Integrate Defender for Endpoint signals with Cloud App Discovery when endpoints are the chosen visibility source – Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs.
Question 23
A quarterly control review at Trey Research identifies a gap that must be corrected before the next audit. The support team has reproduced the issue and narrowed it to this requirement: discover unsanctioned cloud applications actually used by the organization. The affected scope contains 18 users across 23 administrative groups. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: E
Why: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. It directly addresses the stated requirement.
Option review:
A: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Exposure initiatives organize related recommendations around measurable security objectives, making them better suited than isolated alerts for posture improvement programs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. It directly addresses the stated requirement.
Learning point: MS102-T18-Q023: Use Cloud App Discovery data from supported endpoint or network traffic sources – Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list.
Question 24
Coho Winery is standardizing administration after several teams used inconsistent procedures. An internal assessment finds the control technically functional but unable to decide how to govern a newly discovered cloud application based on risk and actual organizational use. The team will validate the change with 13 pilot groups before expanding it to 35 users. The organization wants a reversible rollout with measurable verification before broad enforcement. Which option best satisfies the requirement?
Correct answer: A
Why: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. It directly addresses the stated requirement.
Option review:
A: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. It directly addresses the stated requirement.
B: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Severity alone can be insufficient; active exploitation signals and organizational exposure provide stronger prioritization context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q024: Review the discovered app risk score and usage before sanctioning or unsanctioning it – Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar.
Question 25
A quarterly control review at Tailspin Toys identifies a gap that must be corrected before the next audit. An internal assessment finds the control technically functional but unable to communicate and enforce that a risky cloud app is not approved for organizational use. The control owner requires a review after 52 days and evidence from 3 representative cases. Existing workload settings should remain unchanged unless the requirement specifically depends on them. What is the most appropriate next step?
Correct answer: B
Why: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. It directly addresses the stated requirement.
Option review:
A: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. It directly addresses the stated requirement.
C: Secure Score is a posture indicator, not a complete risk model; exposure, asset criticality, and exploitability should inform remediation priority. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q025: Mark the risky discovered app as unsanctioned and use supported enforcement integration where appropriate – Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use.
Question 26
Proseware Logistics is standardizing administration after several teams used inconsistent procedures. The support team has reproduced the issue and narrowed it to this requirement: decide how to govern a newly discovered cloud application based on risk and actual organizational use. The team will validate the change with 16 pilot groups before expanding it to 69 users. The architecture board will reject a choice that solves a different problem from the one stated. What should the administrator configure first?
Correct answer: C
Why: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. It directly addresses the stated requirement.
Option review:
A: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. It directly addresses the stated requirement.
D: Affected-device context helps scope remediation effort and identify whether critical or internet-exposed systems need accelerated treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q026: Review the discovered app risk score and usage before sanctioning or unsanctioning it – Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar.
Question 27
The security operations analyst at Woodgrove Bank is designing the next phase of the Microsoft 365 rollout. A controlled pilot must demonstrate how to communicate and enforce that a risky cloud app is not approved for organizational use. The organization wants a reversible rollout with measurable verification before broad enforcement. The service desk has 86 related tickets from 6 business units, so the team wants a targeted fix. Which control should the team use?
Correct answer: D
Why: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. It directly addresses the stated requirement.
Option review:
A: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Secure Score surfaces recommended security actions and scoring so administrators can prioritize improvements and track security posture progress. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. It directly addresses the stated requirement.
E: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T18-Q027: Mark the risky discovered app as unsanctioned and use supported enforcement integration where appropriate – Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use.
Question 28
Fourth Coffee has completed a pilot and must now choose the production administration approach. An internal assessment finds the control technically functional but unable to decide how to govern a newly discovered cloud application based on risk and actual organizational use. The affected scope contains 12 users across 19 administrative groups. The administrator must avoid granting unrelated tenant-wide privilege. Which administrative choice should be recommended?
Correct answer: E
Why: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. It directly addresses the stated requirement.
Option review:
A: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. It directly addresses the stated requirement.
Learning point: MS102-T18-Q028: Review the discovered app risk score and usage before sanctioning or unsanctioning it – Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar.
Popular posts
Recent Posts
