Microsoft MS-102 Microsoft 365 Backup Protection And Restore Operations Practice Test

 

MS-102 skills 1.1 | 25 original questions

This MS-102 practice set focuses on microsoft 365 backup protection and restore operations through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.

Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.

Question 1

Blue Yonder Airlines has completed a pilot and must now choose the production administration approach. Audit evidence shows that the current process cannot reliably protect supported Microsoft 365 data so it can be restored after accidental deletion, overwrite, or ransomware impact. The architecture board will reject a choice that solves a different problem from the one stated. The service desk has 47 related tickets from 17 business units, so the team wants a targeted fix. What should the administrator configure first?

  1. Create a Microsoft 365 Backup protection policy
  2. Use a tenant administrator account for initial setup
  3. Review Network connectivity insights for the affected office
  4. Invite the partner as an external guest user
  5. Use Microsoft Graph PowerShell for scripted bulk user changes

Correct answer: A

Why: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. It directly addresses the stated requirement.

B: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Network connectivity insights correlate Microsoft 365 connectivity measurements with locations and recommendations, helping isolate network design issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q001: Create a Microsoft 365 Backup protection policy – Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads.

Question 2

During a tenant review at Wingtip Services, the Microsoft 365 administrator identifies one unresolved requirement. Administrators have confirmed the present design does not roll protected collaboration data back to a healthy prior point after a destructive incident. The initial rollout covers 7 locations and approximately 640 managed identities or devices. The change must be repeatable and supportable after the project team leaves. Which control should the team use?

  1. Use group-based licensing
  2. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account
  3. Use Microsoft Purview role groups for Purview responsibilities
  4. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  5. Review Security & privacy organization settings

Correct answer: B

Why: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. It directly addresses the stated requirement.

Option review:

A: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. It directly addresses the stated requirement.

C: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q002: Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account – Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points.

Question 3

Lucerne Publishing is preparing a change requested by the security administrator. The project board will approve the next step only if it can recover selected mailbox items without rolling back unrelated mailbox content. The initial rollout covers 20 locations and approximately 810 managed identities or devices. The architecture board will reject a choice that solves a different problem from the one stated. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Make the verified custom domain the default domain
  2. Use Microsoft 365 admin center update management to configure the update approach
  3. Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate
  4. Edit the Microsoft 365 contact instead of creating a licensed user
  5. Assign the least-privileged built-in Microsoft Entra role

Correct answer: C

Why: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. It directly addresses the stated requirement.

Option review:

A: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: The exam objective specifically targets configuring software update management through the Microsoft 365 admin center rather than updating clients one by one. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. It directly addresses the stated requirement.

D: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q003: Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate – Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback.

Question 4

VanArsdel Media is preparing a change requested by the security administrator. The organization is replacing a manual process. The replacement must confirm that the required users, sites, or mailboxes are covered by a protection policy while remaining centrally manageable. The affected scope contains 7 users across 10 administrative groups. The response must address the cause described in the scenario rather than simply suppressing the symptom. What should the administrator configure first?

  1. Use Microsoft Graph PowerShell for scripted bulk user changes
  2. Scope the delegated administrator to the administrative unit instead of the tenant
  3. Create a new Microsoft 365 tenant
  4. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  5. Configure Service health notifications

Correct answer: D

Why: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. It directly addresses the stated requirement.

Option review:

A: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. It directly addresses the stated requirement.

E: Service health notification settings allow admins to receive updates for selected services and issue types instead of relying only on manual dashboard checks. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q004: Verify the workload is protected before relying on Microsoft 365 Backup recovery – Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident.

Question 5

Blue Yonder Airlines is preparing a change requested by the tenant administrator. Before the tenant expands to another business unit, the administrator must recover content to a known healthy state rather than simply choosing the newest available snapshot. The initial rollout covers 23 locations and approximately 240 managed identities or devices. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which administrative choice should be recommended?

  1. Review Security & privacy organization settings
  2. Use Microsoft 365 usage reports
  3. Create and manage a shared mailbox
  4. Use Microsoft Defender Unified RBAC or the appropriate Defender role
  5. Select the restore point that predates the damaging event

Correct answer: E

Why: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. It directly addresses the stated requirement.

Option review:

A: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Usage reports provide service-specific adoption and activity metrics rather than security incidents or licensing inventory alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. It directly addresses the stated requirement.

Learning point: MS102-T03-Q005: Select the restore point that predates the damaging event – Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy.

Question 6

Contoso Retail is standardizing administration after several teams used inconsistent procedures. Before the tenant expands to another business unit, the administrator must protect supported Microsoft 365 data so it can be restored after accidental deletion, overwrite, or ransomware impact. The initial rollout covers 13 locations and approximately 410 managed identities or devices. The administrator must avoid granting unrelated tenant-wide privilege. Which approach most directly addresses the requirement?

  1. Create a Microsoft 365 Backup protection policy
  2. Assign the least-privileged built-in Microsoft Entra role
  3. Require approval or MFA for PIM role activation
  4. Add the custom domain and verify ownership with DNS
  5. Prefer local internet egress for Microsoft 365 traffic where appropriate

Correct answer: A

Why: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. It directly addresses the stated requirement.

B: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft 365 network guidance favors direct, local egress and avoiding unnecessary hairpins for trusted Microsoft 365 traffic. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q006: Create a Microsoft 365 Backup protection policy – Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads.

Question 7

The tenant administrator at Tailspin Toys is designing the next phase of the Microsoft 365 rollout. The support team has reproduced the issue and narrowed it to this requirement: roll protected collaboration data back to a healthy prior point after a destructive incident. The control owner requires a review after 58 days and evidence from 3 representative cases. Existing workload settings should remain unchanged unless the requirement specifically depends on them. What is the most appropriate next step?

  1. Configure Service health notifications
  2. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account
  3. Create a member user in Microsoft Entra ID
  4. Review license assignment errors for the affected users or groups
  5. Create an administrative unit and assign a scoped role over it

Correct answer: B

Why: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. It directly addresses the stated requirement.

Option review:

A: Service health notification settings allow admins to receive updates for selected services and issue types instead of relying only on manual dashboard checks. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. It directly addresses the stated requirement.

C: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q007: Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account – Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points.

Question 8

The hybrid identity engineer at City Power & Light is designing the next phase of the Microsoft 365 rollout. An internal assessment finds the control technically functional but unable to recover selected mailbox items without rolling back unrelated mailbox content. The service desk has 75 related tickets from 16 business units, so the team wants a targeted fix. The organization wants a reversible rollout with measurable verification before broad enforcement. What should the administrator configure first?

  1. Use Microsoft Defender Unified RBAC or the appropriate Defender role
  2. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account
  3. Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate
  4. Configure the Organization profile in the Microsoft 365 admin center
  5. Review software update status in the Microsoft 365 admin center

Correct answer: C

Why: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. It directly addresses the stated requirement.

Option review:

A: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. It directly addresses the stated requirement.

D: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Central update monitoring is the appropriate way to identify update compliance and rollout problems across managed Microsoft 365 Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q008: Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate – Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback.

Question 9

The security operations analyst at Woodgrove Bank is designing the next phase of the Microsoft 365 rollout. The current workaround is too manual. The replacement should confirm that the required users, sites, or mailboxes are covered by a protection policy. The control owner requires a review after 92 days and evidence from 6 representative cases. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which approach most directly addresses the requirement?

  1. Prefer local internet egress for Microsoft 365 traffic where appropriate
  2. Create an organizational contact in the Microsoft 365 admin center
  3. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set
  4. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  5. Make the privileged role eligible in Microsoft Entra PIM

Correct answer: D

Why: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 network guidance favors direct, local egress and avoiding unnecessary hairpins for trusted Microsoft 365 traffic. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. It directly addresses the stated requirement.

E: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q009: Verify the workload is protected before relying on Microsoft 365 Backup recovery – Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident.

Question 10

An incident review at Fabrikam Health produces a single administrative requirement for the security administrator. A post-incident action item requires the tenant to recover content to a known healthy state rather than simply choosing the newest available snapshot. The service desk has 18 related tickets from 19 business units, so the team wants a targeted fix. The architecture board will reject a choice that solves a different problem from the one stated. Which control should the team use?

  1. Create an administrative unit and assign a scoped role over it
  2. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  3. Open Health > Service health in the Microsoft 365 admin center
  4. Use Adoption Score for organization-level adoption insights
  5. Select the restore point that predates the damaging event

Correct answer: E

Why: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. It directly addresses the stated requirement.

Option review:

A: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Service health provides tenant-relevant advisories and incidents and should be checked before treating a widespread cloud problem as a local fault. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Adoption Score is designed to provide adoption-oriented insights and recommendations rather than raw service-health status. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. It directly addresses the stated requirement.

Learning point: MS102-T03-Q010: Select the restore point that predates the damaging event – Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy.

Question 11

During a tenant review at Datum Dynamics, the security administrator identifies one unresolved requirement. A production change is approved only if it can protect supported Microsoft 365 data so it can be restored after accidental deletion, overwrite, or ransomware impact. The organization wants a reversible rollout with measurable verification before broad enforcement. The service desk has 35 related tickets from 9 business units, so the team wants a targeted fix. What is the most appropriate next step?

  1. Create a Microsoft 365 Backup protection policy
  2. Review software update status in the Microsoft 365 admin center
  3. Create a Microsoft 365 Group for shared collaboration resources
  4. Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary
  5. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account

Correct answer: A

Why: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. It directly addresses the stated requirement.

B: Central update monitoring is the appropriate way to identify update compliance and rollout problems across managed Microsoft 365 Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q011: Create a Microsoft 365 Backup protection policy – Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads.

Question 12

Lucerne Publishing has completed a pilot and must now choose the production administration approach. The implementation review is focused on one outcome: roll protected collaboration data back to a healthy prior point after a destructive incident. The control owner requires a review after 52 days and evidence from 22 representative cases. The team does not want to redesign unrelated workloads. Which action should the administrator take?

  1. Make the privileged role eligible in Microsoft Entra PIM
  2. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account
  3. Use a tenant administrator account for initial setup
  4. Review Network connectivity insights for the affected office
  5. Invite the partner as an external guest user

Correct answer: B

Why: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. It directly addresses the stated requirement.

Option review:

A: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. It directly addresses the stated requirement.

C: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Network connectivity insights correlate Microsoft 365 connectivity measurements with locations and recommendations, helping isolate network design issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q012: Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account – Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points.

Question 13

Proseware Logistics is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. Security and operations teams agree on the target state: recover selected mailbox items without rolling back unrelated mailbox content. The architecture board will reject a choice that solves a different problem from the one stated. The control owner requires a review after 69 days and evidence from 12 representative cases. Which administrative choice should be recommended?

  1. Use Adoption Score for organization-level adoption insights
  2. Use group-based licensing
  3. Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate
  4. Use Microsoft Purview role groups for Purview responsibilities
  5. Verify the workload is protected before relying on Microsoft 365 Backup recovery

Correct answer: C

Why: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. It directly addresses the stated requirement.

Option review:

A: Adoption Score is designed to provide adoption-oriented insights and recommendations rather than raw service-health status. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. It directly addresses the stated requirement.

D: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q013: Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate – Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback.

Question 14

An incident review at Graphic Design Institute produces a single administrative requirement for the tenant administrator. A production change is approved only if it can confirm that the required users, sites, or mailboxes are covered by a protection policy. The architecture board will reject a choice that solves a different problem from the one stated. The affected scope contains 86 users across 2 administrative groups. Which control should the team use?

  1. Create a Microsoft 365 Backup protection policy
  2. Make the verified custom domain the default domain
  3. Use Microsoft 365 admin center update management to configure the update approach
  4. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  5. Edit the Microsoft 365 contact instead of creating a licensed user

Correct answer: D

Why: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: The exam objective specifically targets configuring software update management through the Microsoft 365 admin center rather than updating clients one by one. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. It directly addresses the stated requirement.

E: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q014: Verify the workload is protected before relying on Microsoft 365 Backup recovery – Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident.

Question 15

The identity administrator at Wide World Importers is designing the next phase of the Microsoft 365 rollout. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to recover content to a known healthy state rather than simply choosing the newest available snapshot. The control owner requires a review after 12 days and evidence from 15 representative cases. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Invite the partner as an external guest user
  2. Use Microsoft Graph PowerShell for scripted bulk user changes
  3. Scope the delegated administrator to the administrative unit instead of the tenant
  4. Create a new Microsoft 365 tenant
  5. Select the restore point that predates the damaging event

Correct answer: E

Why: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. It directly addresses the stated requirement.

Option review:

A: Microsoft Entra B2B guest collaboration is designed for external users who need controlled access while retaining their external identity context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft Graph PowerShell provides scriptable Microsoft 365 and Entra administration suitable for controlled bulk operations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: A tenant-wide role would exceed the requirement; administrative-unit scoping is designed for delegated management of a subset of directory objects. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. It directly addresses the stated requirement.

Learning point: MS102-T03-Q015: Select the restore point that predates the damaging event – Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy.

Question 16

  1. Datum Manufacturing has completed a pilot and must now choose the production administration approach. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to protect supported Microsoft 365 data so it can be restored after accidental deletion, overwrite, or ransomware impact. The initial rollout covers 5 locations and approximately 290 managed identities or devices. The solution should use a native Microsoft control that matches the stated requirement. Which Microsoft 365 or Microsoft Entra capability is the best fit?
  2. Create a Microsoft 365 Backup protection policy
  3. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  4. Review Security & privacy organization settings
  5. Use Microsoft 365 usage reports
  6. Create and manage a shared mailbox

Correct answer: A

Why: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. It directly addresses the stated requirement.

B: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Security & privacy settings in the Microsoft 365 admin center are designed for organization-wide configuration, not individual mailbox preferences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Usage reports provide service-specific adoption and activity metrics rather than security incidents or licensing inventory alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q016: Create a Microsoft 365 Backup protection policy – Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads.

Question 17

Trey Research is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The administrator is comparing native Microsoft controls after documenting a requirement to roll protected collaboration data back to a healthy prior point after a destructive incident. The team will validate the change with 18 pilot groups before expanding it to 46 users. The change must be repeatable and supportable after the project team leaves. Which action should the administrator take?

  1. Edit the Microsoft 365 contact instead of creating a licensed user
  2. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account
  3. Assign the least-privileged built-in Microsoft Entra role
  4. Require approval or MFA for PIM role activation
  5. Add the custom domain and verify ownership with DNS

Correct answer: B

Why: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. It directly addresses the stated requirement.

Option review:

A: Contacts are appropriate for non-sign-in recipients; creating a licensed user would add unnecessary identity and licensing overhead. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. It directly addresses the stated requirement.

C: Least-privilege role assignment limits standing administrative capability and reduces the impact of credential misuse. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: PIM activation settings can require safeguards such as approval, MFA, justification, or time limits for eligible role activations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q017: Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account – Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points.

Question 18

Southridge Video is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. A controlled pilot must demonstrate how to recover selected mailbox items without rolling back unrelated mailbox content. The change must be repeatable and supportable after the project team leaves. The initial rollout covers 8 locations and approximately 630 managed identities or devices. Which control should the team use?

  1. Create a new Microsoft 365 tenant
  2. Configure Service health notifications
  3. Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate
  4. Create a member user in Microsoft Entra ID
  5. Review license assignment errors for the affected users or groups

Correct answer: C

Why: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. It directly addresses the stated requirement.

Option review:

A: A new tenant provides the organizational and identity boundary required for an independent Microsoft 365 environment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Service health notification settings allow admins to receive updates for selected services and issue types instead of relying only on manual dashboard checks. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. It directly addresses the stated requirement.

D: Member users are the normal tenant identities for internal users and can be assigned licenses, groups, and roles as appropriate. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q018: Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate – Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback.

Question 19

Proseware Logistics has completed a pilot and must now choose the production administration approach. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to confirm that the required users, sites, or mailboxes are covered by a protection policy. The solution should use a native Microsoft control that matches the stated requirement. The initial rollout covers 21 locations and approximately 800 managed identities or devices. What is the most appropriate next step?

  1. Create and manage a shared mailbox
  2. Use Microsoft Defender Unified RBAC or the appropriate Defender role
  3. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account
  4. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  5. Configure the Organization profile in the Microsoft 365 admin center

Correct answer: D

Why: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. It directly addresses the stated requirement.

Option review:

A: A shared mailbox is intended for a common address accessed by multiple delegated users rather than a personal user mailbox. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Defender permissions should be managed with the supported Defender role model or unified RBAC so security duties can be scoped appropriately. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. It directly addresses the stated requirement.

E: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q019: Verify the workload is protected before relying on Microsoft 365 Backup recovery – Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident.

Question 20

Alpine Ski House is standardizing administration after several teams used inconsistent procedures. The project board will approve the next step only if it can recover content to a known healthy state rather than simply choosing the newest available snapshot. The initial rollout covers 11 locations and approximately 60 managed identities or devices. The team must preserve a clear audit trail for the administrative decision. Which approach most directly addresses the requirement?

  1. Add the custom domain and verify ownership with DNS
  2. Prefer local internet egress for Microsoft 365 traffic where appropriate
  3. Create an organizational contact in the Microsoft 365 admin center
  4. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set
  5. Select the restore point that predates the damaging event

Correct answer: E

Why: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 verifies custom-domain ownership by requiring the organization to publish the specified DNS record before the domain can be used fully. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 network guidance favors direct, local egress and avoiding unnecessary hairpins for trusted Microsoft 365 traffic. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: A contact represents an external recipient for addressing and directory purposes and does not need a Microsoft 365 sign-in identity. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. It directly addresses the stated requirement.

Learning point: MS102-T03-Q020: Select the restore point that predates the damaging event – Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy.

Question 21

A quarterly control review at Northwind Traders identifies a gap that must be corrected before the next audit. A production change is approved only if it can protect supported Microsoft 365 data so it can be restored after accidental deletion, overwrite, or ransomware impact. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The initial rollout covers 24 locations and approximately 230 managed identities or devices. What should the administrator configure first?

  1. Create a Microsoft 365 Backup protection policy
  2. Review license assignment errors for the affected users or groups
  3. Create an administrative unit and assign a scoped role over it
  4. Select the restore point that predates the damaging event
  5. Open Health > Service health in the Microsoft 365 admin center

Correct answer: A

Why: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. It directly addresses the stated requirement.

Option review:

A: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. It directly addresses the stated requirement.

B: License monitoring should include assignment state and errors, such as conflicting service plans or insufficient available licenses. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Administrative units provide a boundary for scoped Entra role assignments so a delegated admin does not automatically administer the whole tenant. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Service health provides tenant-relevant advisories and incidents and should be checked before treating a widespread cloud problem as a local fault. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q021: Create a Microsoft 365 Backup protection policy – Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads.

Question 22

The operations team at Woodgrove Bank needs to resolve an issue without granting broader permissions than necessary. The change advisory board wants the smallest supported control that can roll protected collaboration data back to a healthy prior point after a destructive incident. The service desk has 40 related tickets from 14 business units, so the team wants a targeted fix. The change must be repeatable and supportable after the project team leaves. Which action should the administrator take?

  1. Configure the Organization profile in the Microsoft 365 admin center
  2. Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account
  3. Review software update status in the Microsoft 365 admin center
  4. Create a Microsoft 365 Group for shared collaboration resources
  5. Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary

Correct answer: B

Why: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. It directly addresses the stated requirement.

Option review:

A: Organization profile settings are the appropriate place for tenant-wide company information rather than per-user properties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points. It directly addresses the stated requirement.

C: Central update monitoring is the appropriate way to identify update compliance and rollout problems across managed Microsoft 365 Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Microsoft 365 Groups provide a membership service that integrates with Microsoft 365 collaboration resources. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q022: Use Microsoft 365 Backup to restore a protected SharePoint site or OneDrive account – Microsoft 365 Backup supports high-fidelity restore operations for protected SharePoint and OneDrive content to selected restore points.

Question 23

  1. Datum Manufacturing is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The support team has reproduced the issue and narrowed it to this requirement: recover selected mailbox items without rolling back unrelated mailbox content. The initial rollout covers 4 locations and approximately 570 managed identities or devices. The team must preserve a clear audit trail for the administrative decision. Which action should the administrator take?
  2. Use Microsoft Entra PowerShell or Microsoft Graph PowerShell with a validated input set
  3. Make the privileged role eligible in Microsoft Entra PIM
  4. Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate
  5. Use a tenant administrator account for initial setup
  6. Review Network connectivity insights for the affected office

Correct answer: C

Why: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. It directly addresses the stated requirement.

Option review:

A: PowerShell-based bulk administration is appropriate when the input set can be validated, logged, and processed consistently. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: PIM eligibility supports just-in-time role activation and reduces the time that privileged permissions are continuously active. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback. It directly addresses the stated requirement.

D: Initial tenant configuration requires an appropriately privileged tenant administrator rather than an ordinary workload user. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Network connectivity insights correlate Microsoft 365 connectivity measurements with locations and recommendations, helping isolate network design issues. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q023: Use Microsoft 365 Backup granular restore for Exchange mailbox items when appropriate – Microsoft 365 Backup supports mailbox-item recovery scenarios, allowing targeted recovery rather than an unnecessarily broad rollback.

Question 24

A quarterly control review at Wingtip Services identifies a gap that must be corrected before the next audit. Administrators have confirmed the present design does not confirm that the required users, sites, or mailboxes are covered by a protection policy. The initial rollout covers 17 locations and approximately 740 managed identities or devices. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Open Health > Service health in the Microsoft 365 admin center
  2. Use Adoption Score for organization-level adoption insights
  3. Use group-based licensing
  4. Verify the workload is protected before relying on Microsoft 365 Backup recovery
  5. Use Microsoft Purview role groups for Purview responsibilities

Correct answer: D

Why: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. It directly addresses the stated requirement.

Option review:

A: Service health provides tenant-relevant advisories and incidents and should be checked before treating a widespread cloud problem as a local fault. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Adoption Score is designed to provide adoption-oriented insights and recommendations rather than raw service-health status. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Group-based licensing applies product licenses to group members and adjusts assignments as membership changes, reducing per-user manual work. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident. It directly addresses the stated requirement.

E: Purview uses role groups to bundle compliance permissions, allowing administrators to receive only the capabilities needed for their duties. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T03-Q024: Verify the workload is protected before relying on Microsoft 365 Backup recovery – Backup recovery depends on the content being in the configured protection scope; assumptions about protection should be validated before an incident.

Question 25

Fourth Coffee is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The support team has reproduced the issue and narrowed it to this requirement: recover content to a known healthy state rather than simply choosing the newest available snapshot. The initial rollout covers 7 locations and approximately 910 managed identities or devices. The solution should use a native Microsoft control that matches the stated requirement. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use the workload-specific Microsoft 365 admin role when tenant-wide privilege is unnecessary
  2. Create a Microsoft 365 Backup protection policy
  3. Make the verified custom domain the default domain
  4. Use Microsoft 365 admin center update management to configure the update approach
  5. Select the restore point that predates the damaging event

Correct answer: E

Why: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. It directly addresses the stated requirement.

Option review:

A: Workload-specific admin roles provide narrower permissions than highly privileged tenant roles and better support least privilege. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Microsoft 365 Backup protection policies define protected content and establish recoverable restore points for supported workloads. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: After a custom domain is verified, setting it as the default causes new identities to use that domain suffix by default. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: The exam objective specifically targets configuring software update management through the Microsoft 365 admin center rather than updating clients one by one. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy. It directly addresses the stated requirement.

Learning point: MS102-T03-Q025: Select the restore point that predates the damaging event – Restore-point selection should align to when the unwanted deletion, encryption, or overwrite occurred so the recovered state is actually healthy.

Popular posts

img