2026 New MS-101 Exam Dumps with PDF and VCE Free: https://www.2passeasy.com/dumps/MS-101/

Testking offers free demo for MS-101 exam. "Microsoft 365 Mobility and Security (beta)", also known as MS-101 exam, is a Microsoft Certification. This set of posts, Passing the Microsoft MS-101 exam, will help you answer those questions. The MS-101 Questions & Answers covers all the knowledge points of the real exam. 100% real Microsoft MS-101 exams and revised by experts!

Free MS-101 Demo Online For Microsoft Certifitcation:

NEW QUESTION 1
You need to recommend a solution for the security administrator. The solution must meet the technical
requirements.
What should you include in the recommendation?

  • A. Microsoft Azure Active Directory (Azure AD) Privileged Identity Management
  • B. Microsoft Azure Active Directory (Azure AD) Identity Protection
  • C. Microsoft Azure Active Directory (Azure AD) conditional access policies
  • D. Microsoft Azure Active Directory (Azure AD) authentication methods

Answer: C

Explanation:
References:
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/untrusted-networks

NEW QUESTION 2
HOTSPOT
You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com.
You have three applications named App1, App2, and App3 that have the same file format.
Your company uses Windows Information Protection (WIP). WIP has the following configurations: Windows Information Protection mode: Silent
Protected apps: App1 Exempt apps: App2
From App1, you create a file named File1.
What is the effect of the configurations? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
MS-101 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
MS-101 dumps exhibit

NEW QUESTION 3
You have a Microsoft 365 subscription.
You plan to enable Microsoft Azure Information Protection.
You need to ensure that only the members of a group named PilotUsers can protect content. What should you do?

  • A. Run the Add-AadrmRoleBasedAdministrator cmdlet.
  • B. Create an Azure Information Protection policy.
  • C. Configure the protection activation status for Azure Information Protection.
  • D. Run the Set-AadrmOnboardingControlPolicy cmdlet.

Answer: D

Explanation:
References:
https://docs.microsoft.com/en-us/azure/information-protection/activate-service

NEW QUESTION 4
HOTSPOT
You have several devices enrolled in Microsoft Intune.
You have a Microsoft Azure Active Directory (Azure AD) tenant that includes the users shown in the following table.
MS-101 dumps exhibit
The device type restrictions in Intune are configured as shown in the following table.
MS-101 dumps exhibit
You add User3 as a device enrollment manager in Intune.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
MS-101 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
MS-101 dumps exhibit

NEW QUESTION 5
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 subscription.
You need to prevent users from accessing your Microsoft SharePoint Online sites unless the users are connected to your on-premises network.
Solution: From the Azure Active Directory admin center, you create a trusted location and a conditional access policy.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

Explanation:
References:
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/location-condition https://techcommunity.microsoft.com/t5/Microsoft-SharePoint-Blog/Conditional-Access-in-SharePoint-Onlineand-OneDrive-for/ba-p/46678

NEW QUESTION 6
You deploy Microsoft Azure Information Protection.
You need to ensure that a security administrator named SecAdmin1 can always read and inspect data protected by Azure Rights Management (Azure RMS).
What should you do?

  • A. From the Security & Compliance admin center, add User1 to the eDiscovery Manager role group.
  • B. From the Azure Active Directory admin center, add User1 to the Security Reader role group.
  • C. From the Security & Compliance admin center, add User1 to the Compliance Administrator role group.
  • D. From Windows PowerShell, enable the super user feature and assign the role to SecAdmin1.

Answer: D

Explanation:
References:
https://docs.microsoft.com/en-us/azure/information-protection/configure-super-users

NEW QUESTION 7
HOTSPOT
From the Security & Compliance admin center, you create a retention policy named Policy1. You need to prevent all users from disabling the policy or reducing the retention period.
Which command should you run? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
MS-101 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
References:
https://docs.microsoft.com/en-us/powershell/module/exchange/policy-and-compliance-retention/set-retentioncompliancepolicy?view=exchange-pHYPERLINK "https://docs.microsoft.com/en-us/powershell/module/exchange/policy-and-compliance-retention/set-retentioncompliancepolicy?view=exchange-ps"s

NEW QUESTION 8
HOTSPOT
You have the Microsoft Azure Active Director (Azure AD) users shown in the following table.
MS-101 dumps exhibit
You create a conditional access policy that has the following settings:
• The Assignments settings are configured as follows:
• Users and groups: Group1
• Cloud apps: Microsoft Office 365 Exchange Online
• Conditions: Include All device state, exclude Device marked as compliant
• Access controls is set to Block access.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
MS-101 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
MS-101 dumps exhibit

NEW QUESTION 9
You need to meet the technical requirement for large-volume document retrieval. What should you create?

  • A. a data loss prevention (DLP) policy from the Security & Compliance admin center
  • B. an alert policy from the Security & Compliance admin center
  • C. a file policy from Microsoft Cloud App Security
  • D. an activity policy from Microsoft Cloud App Security

Answer: D

Explanation:
References:
https://docs.microsoft.com/en-us/office365/securitycompliance/activity-policies-and-alerts

NEW QUESTION 10
You need to meet the compliance requirements for the Windows 10 devices. What should you create from the Intune admin center?

  • A. a device compliance policy
  • B. a device configuration profile
  • C. an application policy
  • D. an app configuration policy

Answer: D

NEW QUESTION 11
HOTSPOT
You need to configure a conditional access policy to meet the compliance requirements. You add Exchange Online as a cloud app.
Which two additional settings should you configure in Policy1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
MS-101 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
MS-101 dumps exhibit

NEW QUESTION 12
HOTSPOT
You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com.
A user named User1 has files on a Windows 10 device as shown in the following table.
MS-101 dumps exhibit
In Azure Information Protection, you create a label named Label1 that is configured to apply automatically. Label1 is configured as shown in the following exhibit.
MS-101 dumps exhibit
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
MS-101 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
References:
https://docs.microsoft.com/en-us/azure/information-protection/configure-policy-classification

NEW QUESTION 13
HOTSPOT
You have a document in Microsoft OneDrive that is encrypted by using Microsoft Azure Information Protection as shown in the following exhibit.
MS-101 dumps exhibit
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
MS-101 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
References:
https://docs.microsoft.com/en-us/azure/information-protection/configure-policy-protection

NEW QUESTION 14
From the Microsoft Azure Active Directory (Azure AD) Identity Protection dashboard, you view the risk events shown in the exhibit. (Click the Exhibit tab.)
MS-101 dumps exhibit
You need to reduce the likelihood that the sign-ins are identified at risky. What should you do?

  • A. From the Security & Compliance admin center, create a classification label.
  • B. From the Security & Compliance admin center, add the users to the Security Readers role group.
  • C. From the Azure Active Directory admin center, configure the trusted IPs for multi-factor authentication.
  • D. From the Conditional access blade in the Azure Active Directory admin center, create named locations.

Answer: D

Explanation:
References:
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/location-condition

NEW QUESTION 15
Your network contains an on-premises Active Directory domain named contoso.com. The domain contains 1,000 Windows 10 devices.
You perform a proof of concept (PoC) deployment of Windows Defender Advanced Threat Protection (ATP) for 10 test devices. During the onboarding process, you configure Windows Defender ATP- related data to be stored in the United States.
You plan to onboard all the devices to Windows Defender ATP. You need to store the Windows Defender ATP data in Europe. What should you first?

  • A. Create a workspace.
  • B. Onboard a new device.
  • C. Delete the workspace.
  • D. Offboard the test devices.

Answer: D

NEW QUESTION 16
HOTSPOT
You need to meet the technical requirement for the SharePoint administrator. What should you do?
To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
MS-101 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
References:
https://docs.microsoft.com/en-us/office365/securitycompliance/search-the-audit-log-in-security-and-compliance#step-3-filter-the-search-results

NEW QUESTION 17
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are deploying Microsoft Intune.
You successfully enroll Windows 10 devices in Intune.
When you try to enroll an iOS device in Intune, you get an error. You need to ensure that you can enroll the iOS device in Intune.
Solution: You add your user account as a device enrollment manager. Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

NEW QUESTION 18
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals- Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).
You manage Windows 10 devices by using Microsoft System Center Configuration Manager (Current Branch).
You configure pilot co-management
You add a new device named Device 1 to the domain. You install the Configuration Manager client on Device1.
You need to ensure that you can manage Device1 by using Microsoft Intune and Configuration Manager.
Solution: You unjoin Device1 from the Active Directory domain. Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

NEW QUESTION 19
Your company has 10 offices.
The network contains an Active Directory domain named contoso.com. The domain contains 500 client computers. Each office is configured as a separate subnet.
You discover that one of the offices has the following:
•Computers that have several preinstalled applications
•Computers that use nonstandard computer names
•Computers that have Windows 10 preinstalled
•Computers that are in a workgroup
You must configure the computers to meet the following corporate requirements:
•All the computers must be joined to the domain.
•All the computers must have computer names that use a prefix of CONTOSO.
•All the computers must only have approved corporate applications installed.
You need to recommend a solution to redeploy the computers. The solution must minimize the deployment time.
What should you recommend?

  • A. a provisioning package
  • B. wipe and load refresh
  • C. Windows Autopilot
  • D. an in-place upgrade

Answer: A

Explanation:
References:
https://docs.microsoft.com/en-us/windows/deployment/windows-10-deployment-scenarios https://docs.microsoft.com/en-us/windows/deployment/windows-autopilot/windows-autopilot

NEW QUESTION 20
HOTSPOT
You have a Microsoft 365 subscription that uses a default domain named contoso.com. The domain contains the users shown in the following table.
MS-101 dumps exhibit
The domain contains the devices shown in the following table.
MS-101 dumps exhibit
The domain contains conditional access policies that control access to a cloud app named App1. The policies are configured as shown in the following table.
MS-101 dumps exhibit
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
MS-101 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
References:
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/plan-conditional-access

NEW QUESTION 21
HOTSPOT
You have a Microsoft 365 subscription that contains all the user data.
You plan to create the retention policy shown in the Locations exhibit. (Click the Locations tab.)
MS-101 dumps exhibit
You configure the Advanced retention settings as shown in the Retention exhibit. (Click the Retention tab.)
MS-101 dumps exhibit
The locations specified in the policy include the groups shown in the following table.
MS-101 dumps exhibit
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
MS-101 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
References:
https://docs.microsoft.com/en-us/office365/securitycompliance/retention-policies

NEW QUESTION 22
HOTSPOT
You have a Microsoft Azure Activity Directory (Azure AD) tenant contains the users shown in the following table.
MS-101 dumps exhibit
Group3 is a member of Group1.
Your company uses Windows Defender Advanced Threat Protection (ATP). Windows Defender ATP contains the roles shown in the following table.
MS-101 dumps exhibit
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
MS-101 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
References:
https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-HYPERLINK "https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/user-roles-windows-defender-advanced-threat-protection"defender-atp/user-roles-windows-defender-advanced-threat-protection

NEW QUESTION 23
You create a new Microsoft 365 subscription and assign Microsoft 365 E3 licenses to 100 users. From the Security & Compliance admin center, you enable auditing.
You are planning the auditing strategy.
Which three activities will be audited by default? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

  • A. An administrator creates a new Microsoft SharePoint site collection.
  • B. An administrator creates a new mail flow rule.
  • C. A user shares a Microsoft SharePoint folder with an external user.
  • D. A user delegates permissions to their mailbox.
  • E. A user purges messages from their mailbox.

Answer: ABC

Explanation:
References:
https://docs.microsoft.com/en-us/office365/securitycompliance/search-the-audit-log-in-security-andcompliance?redirectSourcePath=%25HYPERLINK "https://docs.microsoft.com/en-us/office365/securitycompliance/search-the-audit-log-in-security-andcompliance?redirectSourcePath=%2farticle%2f0d4d0f35-390b-4518-800e-0c7ec95e946c"2farticle%252f0d4d0f35-390b-4518-800e-0c7ec95e946c

NEW QUESTION 24
HOTSPOT
Your network contains an Active Directory domain named contoso.com. All client devices run Windows 10 and are joined to the domain.
You update the Windows 10 devices by using Windows Update for Business.
What is the maximum amount of time you can defer Windows 10 updates? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
MS-101 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
References:
https://docs.microsoft.com/en-us/windows/deployment/update/waas-manage-updates-wufb

NEW QUESTION 25
You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com. You have a Microsoft 365 subscription.
You need to ensure that users can manage the configuration settings for all the Windows 10 devices in your organization.
What should you configure?

  • A. the Enrollment restrictions
  • B. the mobile device management (MDM) authority
  • C. the Exchange on-premises access settings
  • D. the Windows enrollment settings

Answer: B

Explanation:
References:
https://docs.microsoft.com/en-us/intune/mdm-authority-set

NEW QUESTION 26
......

P.S. prep-labs.com now are offering 100% pass ensure MS-101 dumps! All MS-101 exam questions have been updated with correct answers: https://www.prep-labs.com/dumps/MS-101/ (146 New Questions)