Microsoft MS-102 Email Threat Investigation Attack Simulation And Restricted Entities Practice Test
MS-102 skills 3.2 | 28 original questions
This MS-102 practice set focuses on email threat investigation attack simulation and restricted entities through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.
Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.
Question 1
Wingtip Services is preparing a change requested by the hybrid identity engineer. The change advisory board wants the smallest supported control that can find affected messages, recipients, URLs, and delivery actions associated with an email threat. The team will validate the change with 21 pilot groups before expanding it to 30 users. The administrator must avoid granting unrelated tenant-wide privilege. What is the most appropriate next step?
Correct answer: D
Why: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. It directly addresses the stated requirement.
Option review:
A: Remediation workflows let security teams request, track, and validate vulnerability fixes instead of treating recommendations as a static report. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. It directly addresses the stated requirement.
E: Secure Score is a posture indicator, not a complete risk model; exposure, asset criticality, and exploitability should inform remediation priority. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q001: Use Threat Explorer or Real-time detections to investigate the malicious message campaign – Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats.
Question 2
During a tenant review at Contoso Retail, the compliance administrator identifies one unresolved requirement. Security and operations teams agree on the target state: prevent users from accessing confirmed malicious email while the incident is remediated. The solution should use a native Microsoft control that matches the stated requirement. The service desk has 47 related tickets from 11 business units, so the team wants a targeted fix. Which control should the team use?
Correct answer: E
Why: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. It directly addresses the stated requirement.
Option review:
A: Secure Score surfaces recommended security actions and scoring so administrators can prioritize improvements and track security posture progress. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Remediation workflows let security teams request, track, and validate vulnerability fixes instead of treating recommendations as a static report. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. It directly addresses the stated requirement.
Learning point: MS102-T15-Q002: Use quarantine and remediation actions for confirmed malicious messages – Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually.
Question 3
The operations team at Alpine Ski House needs to resolve an issue without granting broader permissions than necessary. The current workaround is too manual. The replacement should find affected messages, recipients, URLs, and delivery actions associated with an email threat. The team will validate the change with 24 pilot groups before expanding it to 64 users. The solution should use a native Microsoft control that matches the stated requirement. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: A
Why: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. It directly addresses the stated requirement.
Option review:
A: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. It directly addresses the stated requirement.
B: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Secure Score surfaces recommended security actions and scoring so administrators can prioritize improvements and track security posture progress. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q003: Use Threat Explorer or Real-time detections to investigate the malicious message campaign – Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats.
Question 4
Southridge Video is preparing a change requested by the security operations analyst. The service owner wants a supportable design that will prevent users from accessing confirmed malicious email while the incident is remediated. The administrator must avoid granting unrelated tenant-wide privilege. The affected scope contains 81 users across 14 administrative groups. Which option best satisfies the requirement?
Correct answer: B
Why: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. It directly addresses the stated requirement.
Option review:
A: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. It directly addresses the stated requirement.
C: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q004: Use quarantine and remediation actions for confirmed malicious messages – Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually.
Question 5
Consolidated Messenger is standardizing administration after several teams used inconsistent procedures. The change advisory board wants the smallest supported control that can find affected messages, recipients, URLs, and delivery actions associated with an email threat. The affected scope contains 7 users across 4 administrative groups. The design should minimize manual per-user administration where a scoped central control exists. Which administrative choice should be recommended?
Correct answer: C
Why: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. It directly addresses the stated requirement.
Option review:
A: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Severity alone can be insufficient; active exploitation signals and organizational exposure provide stronger prioritization context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. It directly addresses the stated requirement.
D: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q005: Use Threat Explorer or Real-time detections to investigate the malicious message campaign – Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats.
Question 6
Correct answer: D
Why: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. It directly addresses the stated requirement.
Option review:
A: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Secure Score recommendations provide context for remediation and progress tracking instead of requiring administrators to infer actions from raw alert counts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. It directly addresses the stated requirement.
E: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q006: Use quarantine and remediation actions for confirmed malicious messages – Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually.
Question 7
A quarterly control review at Woodgrove Bank identifies a gap that must be corrected before the next audit. A post-incident action item requires the tenant to find affected messages, recipients, URLs, and delivery actions associated with an email threat. The initial rollout covers 7 locations and approximately 410 managed identities or devices. The architecture board will reject a choice that solves a different problem from the one stated. Which option best satisfies the requirement?
Correct answer: E
Why: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. It directly addresses the stated requirement.
Option review:
A: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Affected-device context helps scope remediation effort and identify whether critical or internet-exposed systems need accelerated treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. It directly addresses the stated requirement.
Learning point: MS102-T15-Q007: Use Threat Explorer or Real-time detections to investigate the malicious message campaign – Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats.
Question 8
Graphic Design Institute is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The current workaround is too manual. The replacement should prevent users from accessing confirmed malicious email while the incident is remediated. The service desk has 58 related tickets from 20 business units, so the team wants a targeted fix. The response must address the cause described in the scenario rather than simply suppressing the symptom. What is the most appropriate next step?
Correct answer: A
Why: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. It directly addresses the stated requirement.
Option review:
A: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. It directly addresses the stated requirement.
B: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Security Exposure Management helps connect exposure signals into attack paths and initiatives, supporting risk-based prioritization beyond isolated findings. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q008: Use quarantine and remediation actions for confirmed malicious messages – Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually.
Question 9
Blue Yonder Airlines is migrating a business process to Microsoft 365 and wants the narrowest supported solution. An internal assessment finds the control technically functional but unable to find affected messages, recipients, URLs, and delivery actions associated with an email threat. The affected scope contains 75 users across 10 administrative groups. The architecture board will reject a choice that solves a different problem from the one stated. What should the administrator configure first?
Correct answer: B
Why: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. It directly addresses the stated requirement.
Option review:
A: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. It directly addresses the stated requirement.
C: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q009: Use Threat Explorer or Real-time detections to investigate the malicious message campaign – Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats.
Question 10
Proseware Logistics has completed a pilot and must now choose the production administration approach. The support team has reproduced the issue and narrowed it to this requirement: prevent users from accessing confirmed malicious email while the incident is remediated. The affected scope contains 92 users across 23 administrative groups. The organization wants a reversible rollout with measurable verification before broad enforcement. Which approach most directly addresses the requirement?
Correct answer: C
Why: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. It directly addresses the stated requirement.
Option review:
A: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. It directly addresses the stated requirement.
D: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q010: Use quarantine and remediation actions for confirmed malicious messages – Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually.
Question 11
Correct answer: D
Why: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. It directly addresses the stated requirement.
Option review:
A: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. It directly addresses the stated requirement.
E: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q011: Create an Attack Simulation Training campaign – Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience.
Question 12
Tailspin Toys is preparing a change requested by the security administrator. Administrators have confirmed the present design does not use campaign evidence to improve security awareness rather than treating the simulation as a pass/fail event. The affected scope contains 35 users across 3 administrative groups. The administrator must avoid granting unrelated tenant-wide privilege. What is the most appropriate next step?
Correct answer: E
Why: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. It directly addresses the stated requirement.
Option review:
A: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Exposure initiatives organize related recommendations around measurable security objectives, making them better suited than isolated alerts for posture improvement programs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. It directly addresses the stated requirement.
Learning point: MS102-T15-Q012: Review simulation results to identify users or techniques that need additional training – Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design.
Question 13
Graphic Design Institute has completed a pilot and must now choose the production administration approach. The organization is replacing a manual process. The replacement must measure phishing susceptibility and deliver targeted training without sending a real malicious campaign while remaining centrally manageable. The affected scope contains 52 users across 16 administrative groups. The design should minimize manual per-user administration where a scoped central control exists. Which administrative choice should be recommended?
Correct answer: A
Why: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. It directly addresses the stated requirement.
Option review:
A: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. It directly addresses the stated requirement.
B: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Closing a change ticket is not proof of risk reduction; Defender Vulnerability Management should reflect improved exposure after telemetry updates. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q013: Create an Attack Simulation Training campaign – Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience.
Question 14
Wingtip Services is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The support team has reproduced the issue and narrowed it to this requirement: use campaign evidence to improve security awareness rather than treating the simulation as a pass/fail event. The initial rollout covers 6 locations and approximately 690 managed identities or devices. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which action should the administrator take?
Correct answer: B
Why: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. It directly addresses the stated requirement.
Option review:
A: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. It directly addresses the stated requirement.
C: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Secure Score is a posture indicator, not a complete risk model; exposure, asset criticality, and exploitability should inform remediation priority. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q014: Review simulation results to identify users or techniques that need additional training – Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design.
Question 15
VanArsdel Media is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The implementation review is focused on one outcome: measure phishing susceptibility and deliver targeted training without sending a real malicious campaign. The team will validate the change with 19 pilot groups before expanding it to 86 users. The team does not want to redesign unrelated workloads. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: C
Why: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. It directly addresses the stated requirement.
Option review:
A: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. It directly addresses the stated requirement.
D: Remediation workflows let security teams request, track, and validate vulnerability fixes instead of treating recommendations as a static report. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q015: Create an Attack Simulation Training campaign – Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience.
Question 16
Alpine Ski House is preparing a change requested by the security operations analyst. The existing configuration works for normal operations but fails the new requirement to use campaign evidence to improve security awareness rather than treating the simulation as a pass/fail event. The solution should use a native Microsoft control that matches the stated requirement. The affected scope contains 12 users across 9 administrative groups. What should the administrator configure first?
Correct answer: D
Why: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. It directly addresses the stated requirement.
Option review:
A: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Secure Score surfaces recommended security actions and scoring so administrators can prioritize improvements and track security posture progress. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. It directly addresses the stated requirement.
E: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q016: Review simulation results to identify users or techniques that need additional training – Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design.
Question 17
During a tenant review at Humongous Insurance, the service desk lead identifies one unresolved requirement. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to measure phishing susceptibility and deliver targeted training without sending a real malicious campaign. The control owner requires a review after 29 days and evidence from 22 representative cases. The change must be repeatable and supportable after the project team leaves. Which administrative choice should be recommended?
Correct answer: E
Why: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. It directly addresses the stated requirement.
Option review:
A: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. It directly addresses the stated requirement.
Learning point: MS102-T15-Q017: Create an Attack Simulation Training campaign – Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience.
Question 18
Correct answer: A
Why: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. It directly addresses the stated requirement.
Option review:
A: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. It directly addresses the stated requirement.
B: Severity alone can be insufficient; active exploitation signals and organizational exposure provide stronger prioritization context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q018: Review simulation results to identify users or techniques that need additional training – Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design.
Question 19
The operations team at Adventure Works needs to resolve an issue without granting broader permissions than necessary. The project board will approve the next step only if it can measure phishing susceptibility and deliver targeted training without sending a real malicious campaign. The affected scope contains 63 users across 2 administrative groups. The team must preserve a clear audit trail for the administrative decision. Which approach most directly addresses the requirement?
Correct answer: B
Why: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. It directly addresses the stated requirement.
Option review:
A: Secure Score recommendations provide context for remediation and progress tracking instead of requiring administrators to infer actions from raw alert counts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. It directly addresses the stated requirement.
C: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Severity alone can be insufficient; active exploitation signals and organizational exposure provide stronger prioritization context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q019: Create an Attack Simulation Training campaign – Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience.
Question 20
Blue Yonder Airlines is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. An internal assessment finds the control technically functional but unable to determine why an account was restricted from sending messages after suspicious outbound activity. The control owner requires a review after 80 days and evidence from 15 representative cases. The change must be repeatable and supportable after the project team leaves. Which action should the administrator take?
Correct answer: C
Why: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. It directly addresses the stated requirement.
Option review:
A: Affected-device context helps scope remediation effort and identify whether critical or internet-exposed systems need accelerated treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. It directly addresses the stated requirement.
D: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Secure Score recommendations provide context for remediation and progress tracking instead of requiring administrators to infer actions from raw alert counts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q020: Review the restricted entities page for the blocked user – Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation.
Question 21
During a tenant review at Humongous Insurance, the messaging administrator identifies one unresolved requirement. Security and operations teams agree on the target state: restore mail sending only after the cause of abusive outbound activity has been remediated. The team must preserve a clear audit trail for the administrative decision. The team will validate the change with 5 pilot groups before expanding it to 6 users. Which approach most directly addresses the requirement?
Correct answer: D
Why: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. It directly addresses the stated requirement.
Option review:
A: Security Exposure Management helps connect exposure signals into attack paths and initiatives, supporting risk-based prioritization beyond isolated findings. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. It directly addresses the stated requirement.
E: Affected-device context helps scope remediation effort and identify whether critical or internet-exposed systems need accelerated treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q021: Secure the compromised account before removing the sending restriction – Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account.
Question 22
The compliance administrator at Litware Financial is designing the next phase of the Microsoft 365 rollout. A post-incident action item requires the tenant to determine why an account was restricted from sending messages after suspicious outbound activity. The team will validate the change with 18 pilot groups before expanding it to 23 users. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: E
Why: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. It directly addresses the stated requirement.
Option review:
A: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Security Exposure Management helps connect exposure signals into attack paths and initiatives, supporting risk-based prioritization beyond isolated findings. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. It directly addresses the stated requirement.
Learning point: MS102-T15-Q022: Review the restricted entities page for the blocked user – Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation.
Question 23
Wingtip Services is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. Before the tenant expands to another business unit, the administrator must restore mail sending only after the cause of abusive outbound activity has been remediated. The service desk has 40 related tickets from 8 business units, so the team wants a targeted fix. The architecture board will reject a choice that solves a different problem from the one stated. What is the most appropriate next step?
Correct answer: A
Why: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. It directly addresses the stated requirement.
Option review:
A: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. It directly addresses the stated requirement.
B: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q023: Secure the compromised account before removing the sending restriction – Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account.
Question 24
The operations team at A. Datum Manufacturing needs to resolve an issue without granting broader permissions than necessary. An internal assessment finds the control technically functional but unable to determine why an account was restricted from sending messages after suspicious outbound activity. The affected scope contains 57 users across 21 administrative groups. The solution should use a native Microsoft control that matches the stated requirement. What is the most appropriate next step?
Correct answer: B
Why: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. It directly addresses the stated requirement.
Option review:
A: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. It directly addresses the stated requirement.
C: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q024: Review the restricted entities page for the blocked user – Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation.
Question 25
Fourth Coffee is standardizing administration after several teams used inconsistent procedures. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to restore mail sending only after the cause of abusive outbound activity has been remediated. The control owner requires a review after 74 days and evidence from 11 representative cases. The organization wants a reversible rollout with measurable verification before broad enforcement. Which administrative choice should be recommended?
Correct answer: C
Why: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. It directly addresses the stated requirement.
Option review:
A: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Exposure initiatives organize related recommendations around measurable security objectives, making them better suited than isolated alerts for posture improvement programs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. It directly addresses the stated requirement.
D: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q025: Secure the compromised account before removing the sending restriction – Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account.
Question 26
During a tenant review at Humongous Insurance, the compliance administrator identifies one unresolved requirement. Before the tenant expands to another business unit, the administrator must determine why an account was restricted from sending messages after suspicious outbound activity. The affected scope contains 91 users across 24 administrative groups. The change must be repeatable and supportable after the project team leaves. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: D
Why: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. It directly addresses the stated requirement.
Option review:
A: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Closing a change ticket is not proof of risk reduction; Defender Vulnerability Management should reflect improved exposure after telemetry updates. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. It directly addresses the stated requirement.
E: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q026: Review the restricted entities page for the blocked user – Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation.
Question 27
Wide World Importers is standardizing administration after several teams used inconsistent procedures. The existing configuration works for normal operations but fails the new requirement to restore mail sending only after the cause of abusive outbound activity has been remediated. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The initial rollout covers 14 locations and approximately 170 managed identities or devices. Which administrative choice should be recommended?
Correct answer: E
Why: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. It directly addresses the stated requirement.
Option review:
A: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Secure Score is a posture indicator, not a complete risk model; exposure, asset criticality, and exploitability should inform remediation priority. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. It directly addresses the stated requirement.
Learning point: MS102-T15-Q027: Secure the compromised account before removing the sending restriction – Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account.
Question 28
City Power & Light is preparing a change requested by the governance lead. The current workaround is too manual. The replacement should determine why an account was restricted from sending messages after suspicious outbound activity. The service desk has 34 related tickets from 4 business units, so the team wants a targeted fix. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which control should the team use?
Correct answer: A
Why: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. It directly addresses the stated requirement.
Option review:
A: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. It directly addresses the stated requirement.
B: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Remediation workflows let security teams request, track, and validate vulnerability fixes instead of treating recommendations as a static report. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T15-Q028: Review the restricted entities page for the blocked user – Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation.
Popular posts
Recent Posts
