exam questions

Exam MS-102 All Questions

View all questions & answers for the MS-102 exam

Exam MS-102 topic 1 question 14 discussion

Actual exam question from Microsoft's MS-102
Question #: 14
Topic #: 1
[All MS-102 Questions]

You have a new Microsoft 365 E5 tenant.
You need to enable an alert policy that will be triggered when an elevation of Microsoft Exchange Online administrative privileges is detected.
What should you do first?

  • A. Enable auditing.
  • B. Enable Microsoft 365 usage analytics.
  • C. Create an Insider risk management policy.
  • D. Create a communication compliance policy.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Nilz76
Highly Voted 1 year, 8 months ago
Selected Answer: A
A. Enable auditing The first step you should take is to Enable auditing. In order to monitor and get alerted on specific activities such as elevation of administrative privileges, auditing needs to be enabled in your Microsoft 365 environment. Auditing will record events such as changes in permissions and other administrative activities, which can then be monitored through alert policies to notify administrators when specific events occur.
upvoted 19 times
...
anonavia
Highly Voted 1 year, 10 months ago
Selected Answer: A
-A When an elevation of Microsoft Exchange Online administrative privileges is detected in your Microsoft 365 E5 tenant, you should first enable auditing.
upvoted 6 times
...
FemiA55
Most Recent 7 months, 3 weeks ago
A. Enable auditing.
upvoted 2 times
...
MR_Eliot
10 months ago
Selected Answer: A
Only A makes senses, but is is also enabled by default!
upvoted 2 times
...
[Removed]
12 months ago
Was in Exam 27-6-24
upvoted 4 times
norbe01
9 months, 4 weeks ago
By any chances, you mentioned in all comments which ones was at the exam? :)
upvoted 2 times
...
...
rus123
1 year, 1 month ago
Option C
upvoted 1 times
...
mikl
1 year, 1 month ago
Selected Answer: A
To enable an alert policy in a new Microsoft 365 E5 tenant that will be triggered by the elevation of Microsoft Exchange Online administrative privileges, the first step you should take is: A. Enable auditing. Auditing must be enabled to track and record actions within the tenant, which allows for the creation of alert policies based on those audit logs1. Once auditing is enabled, you can create alert policies in the Microsoft Purview compliance portal or the Microsoft Defender portal to monitor activities such as assigning admin privileges in Exchange Online1
upvoted 1 times
...
SecAzO365
1 year, 5 months ago
Selected Answer: C
So if Auditing is enabled by default, why shouldn't you then choose for C? https://learn.microsoft.com/en-us/purview/insider-risk-management-policies Insider risk management policies determine which users are in-scope and which types of risk indicators are configured for alerts. You can quickly create a security policy that applies to all users in your organization or define individual users or groups for management in a policy.
upvoted 4 times
...
SecAzO365
1 year, 5 months ago
So if Auditing is enabled by default, why shouldn't you then choose for C? https://learn.microsoft.com/en-us/purview/insider-risk-management-policies Insider risk management policies determine which users are in-scope and which types of risk indicators are configured for alerts. You can quickly create a security policy that applies to all users in your organization or define individual users or groups for management in a policy.
upvoted 1 times
...
benpatto
1 year, 6 months ago
Selected Answer: A
Gotta be A. The others don't really matter in this situation. Anything alert related would have an alert policy setup specifically, so auditing is the only reliable option. Power of deduction is a great thing xD
upvoted 2 times
...
osxzvkwpfcfxobqjby
1 year, 10 months ago
- A But, question makes no sense. Audit is enabled by default. All other options are less obvious. https://learn.microsoft.com/en-us/purview/audit-solutions-overview#audit-standard
upvoted 3 times
GLLimaBR
1 year, 4 months ago
Hello. I believe the answer below will help you with this question: "Audit logging is turned on by default for Microsoft 365 organizations. However, when setting up a new Microsoft 365 organization, you should verify the auditing status for your organization. For instructions, see the Verify the auditing status for your organization section in this article." https://learn.microsoft.com/en-us/purview/audit-log-enable-disable
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...