exam questions

Exam MS-100 All Questions

View all questions & answers for the MS-100 exam

Exam MS-100 topic 3 question 12 discussion

Actual exam question from Microsoft's MS-100
Question #: 12
Topic #: 3
[All MS-100 Questions]

HOTSPOT -
You have a Microsoft Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.

Your company uses Windows Defender Advanced Threat Protection (ATP). Windows Defender ATP contains the roles shown in the following table.

Windows Defender ATP contains the device groups shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1:
Yes. User1 is in Group1 which is assigned to Role1. Device1 is in the device group named ATP1 which Group1 has access to. Role1 gives Group1 (and User1)
View Data Permission. This is enough to view Device1 in Windows Security Center.
Box 2:
Yes. User2 is in Group2 which is assigned to Role2. Role2 gives Group2 (and User2) View Data Permission. This is enough to sign in to Windows Security
Center.
Box 3:
Yes. User3 is in Group3 which is assigned the Windows ATP Administrator role. Someone with a Microsoft Defender ATP Global administrator role has unrestricted access to all machines, regardless of their machine group association and the Azure AD user groups assignments.
Reference:
https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/user-roles https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/rbac

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Couch
Highly Voted 5 years, 4 months ago
What is the point of the "View Data" permission by itself? If you can't login to the portal with just that permission (as the answer indicates), then what data can you actually view with that permission?
upvoted 18 times
jabbrwcky
5 years, 3 months ago
My thoughts exactly.
upvoted 2 times
itmp
4 years, 11 months ago
Tested and I can confirm: Creating a "ViewData only" role allows user access to ATP portal. (after about 3min) So Y/Y/Y
upvoted 19 times
...
...
...
[Removed]
Highly Voted 4 years, 9 months ago
Y - Y - Y Box 1: Yes. User1 is in Group1 which is assigned to Role1. Device1 is in the device group named ATP1 which Group1 has access to. Role1 gives Group1 (and User1) View Data Permission. This is enough to view Device1 in Windows Security Center. Box 2: Yes. User2 is in Group2 which is assigned to Role2. Role2 gives Group2 (and User2) View Data Permission. This is enough to sign in to Windows Security Center. Box 3: Yes. User3 is in Group3 which is assigned the Windows ATP Administrator role. Someone with a Microsoft Defender ATP Global administrator role has unrestricted access to all machines, regardless of their machine group association and the Azure AD user groups assignments. Reference: https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/userroles https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/rbac
upvoted 15 times
donathon
4 years, 7 months ago
Agree too
upvoted 3 times
...
...
donb21
Most Recent 2 years, 8 months ago
Answer is Y Y Y
upvoted 1 times
...
melatocaroca
3 years, 10 months ago
Y,Y,Y, Read-only access Users with read-only access can log in, view all alerts, and related information Reference: https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/basic-permissions?view=o365-worldwide
upvoted 1 times
...
lucidgreen
4 years, 2 months ago
Question 1: Yes. View Data Access and Alert investigation access. Assigned this device by Group 1. Question 2: Yes. View Data Access gives user the ability to log in to Windows Defender Security Center. Question 3: Yes. User 3 is an Administrator.
upvoted 2 times
...
RNG60FR
4 years, 3 months ago
MS-101 Exam Question ?
upvoted 7 times
imEmi
4 years, 2 months ago
It is.
upvoted 3 times
...
...
Rstilekar
4 years, 3 months ago
Tested and I can confirm: Creating a "ViewData only" and "Alerts investigting role" roles allows user access to ATP portal for user2. Question asks if USer2 can sign in to protection.office.com viz. Security portal. So answer is Yes. Overall So Y/Y/Y
upvoted 2 times
...
mkoprivnj
4 years, 4 months ago
Y, Y, Y for sure! ctfalci
upvoted 4 times
...
Carlos1787
4 years, 6 months ago
YNY is correct. the key is the device must be a part of a device group. See the Important at the end of the section https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/user-roles#create-roles-and-assign-the-role-to-an-azure-active-directory-group
upvoted 3 times
lucidgreen
4 years, 2 months ago
The second question doesn't ask if the user can view a device. It only asks if the user can log in. And the user can.
upvoted 1 times
...
...
STFN2019
4 years, 9 months ago
y n y no yes?
upvoted 1 times
...
Raj2020
4 years, 10 months ago
Tested in my Lab: View Data permission role is not allowed to login to Security center (MS Defender ATP)
upvoted 1 times
TonySuccess
4 years, 10 months ago
Thanks for confirming, i went YNY
upvoted 3 times
fgdsgfdsa
4 years, 8 months ago
Confirmed. Portal access is controlled separately https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/rbac https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/basic-permissions
upvoted 1 times
...
...
...
asdkjhbfc
4 years, 11 months ago
"view data" permission grants access to the portal https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/user-roles
upvoted 2 times
...
FcoGlezRoy
4 years, 11 months ago
Correct me if wrong, I think the answer is correct you can use event viewer or so to subscribe to remote events without login into the Windows Security Center: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/report-monitor-windows-defender-antivirus
upvoted 1 times
...
rogerthis1
5 years ago
How is the a MS-100 question, surely it must be MS-101?
upvoted 14 times
...
AlexanderSaad
5 years ago
Yes Yes Yes
upvoted 3 times
...
Goofer
5 years, 2 months ago
Y - Y - Y
upvoted 7 times
...
Zaada
5 years, 2 months ago
I feel like this is a wrong answer. How can you view the data if you don't have a permission to login at first place?
upvoted 3 times
zordss
5 years ago
exactly!
upvoted 2 times
ExamStudy101
3 years, 9 months ago
Maybe someone else can clarify but where exactly does it say you would not have sign in access for User2?
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago