exam questions

Exam MS-101 All Questions

View all questions & answers for the MS-101 exam

Exam MS-101 topic 3 question 89 discussion

Actual exam question from Microsoft's MS-101
Question #: 89
Topic #: 3
[All MS-101 Questions]

Your company has a Microsoft 365 subscription that uses an Azure Active Directory (Azure AD) tenant named contoso.com.
A user named User1 is a member of a dynamic group named Group1.
User1 reports that he cannot access documents shared to Group1.
You discover that User1 is no longer a member of Group1.
You suspect that an administrator made a change that caused User1 to be removed from Group1.
You need to identify which administrator made the change.
Which audit log activity should you search in the Security & Compliance admin center?

  • A. Azure AD group administration activities ג€" Removed member from group
  • B. User administration activities ג€" Updated user
  • C. Azure AD group administration activities ג€" Updated group
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
blaatlama
Highly Voted 5 years, 2 months ago
Wouldn't this be B since Group1 is a dynamic group? Therefore user attribute should have been changed, otherwise user1 would be added back in the group automatically..
upvoted 29 times
Boeroe
2 years, 9 months ago
Or the dynamic rule was changed and then answer C would be correct as this is a change of the group
upvoted 1 times
...
minajahan
5 years, 1 month ago
B is the correct answer! Security menu item from O365 Admin page -> Search menu from left panel -> choose User administration activities from Activities -> under that, choose "Updated user".
upvoted 26 times
airairo
3 years, 11 months ago
it got updated to https://compliance.microsoft.com/auditlogsearch
upvoted 3 times
...
...
...
mgmjtech
Highly Voted 4 years, 9 months ago
Finally got time to test this scenario out. I agree with Smoo. I can see two entries. One from the "Removed member from group". Which shows the user was removed but not who did it. On the Updated user entry, I can see the ID was updated/removed and the user that did it. You need to expand the entry to see more details under "ModifiedProperties". The answer is B.
upvoted 13 times
...
Contactfornitish
Most Recent 2 years, 9 months ago
Selected Answer: B
A. Can't be true since its a dynamic group and direct removal not possible B. Most likely scenario as change of attribute on basis of which dynamic group membership was evaluated if changed by an admin then user would be out C. Its still possible as one can change the group definition itself and new definition can be anything else to keep the user out but I would not chose this option in exam as if that's the case, many users would be impacted. If multiple choice, then I would chose B & C and if single choice then B
upvoted 6 times
...
RazielLycas
2 years, 9 months ago
mumbling about it I would say, if the query was changed, maybe more than one user would be removed so the "more" probable option is an user modification? but it's a speculation
upvoted 2 times
...
RazielLycas
2 years, 9 months ago
it miss too much info, if the query was changed it's C (maybe it's a multiple and statement query and user miss one) or the user itself was changed and it doesn't match the query anymore.. who knows
upvoted 3 times
...
L33D
2 years, 10 months ago
Selected Answer: B
B since Group1 is a dynamic group
upvoted 1 times
...
Zardu
3 years, 1 month ago
Just to really throw a wrench in all this...there is no "Security and Compliance" dashboard, there are two -- MS 365 Defender (Security) and Compliance. So old quesiton that isn't good anymore?
upvoted 1 times
...
TashaGirl
3 years, 1 month ago
Selected Answer: B
Activity - Updated user, user=admin who changed, item=affected user, click for details, scroll to ModifiedProperties to see what was changed. The next logged event for item (affected user) will be by "service principal_" activity = Removed member from group. Answer is B 100% - I am auditing this for our compliance on a daily basis.
upvoted 3 times
...
PDR
3 years, 4 months ago
agree with some others - can be B or C that could cause this, but as F_M says I would think most likely they are looking for B as it only mentions 1 user being effected. Perfectly feasible of course that the rule could have been changed to effect just one user, but without full info we have to take a best guess here
upvoted 1 times
...
FreddyLao
3 years, 4 months ago
C is the answer. just test in my environment. no recrd in update user audit log but record to show i changed the query in the dynamic group in update group so that the user was excluded from the group membership.
upvoted 3 times
JAPo123
3 years, 2 months ago
https://docs.microsoft.com/en-us/microsoft-365/compliance/search-the-audit-log-in-security-and-compliance?view=o365-worldwide#audited-activities Updated user --> Administrator changes one or more properties of a user account. For a list of the user properties that can be updated, see the "Update user attributes" section in Azure Active Directory Audit Report Events.
upvoted 1 times
...
...
F_M
3 years, 8 months ago
I think both B and C can be valid answers. By the way the question states that only one user can't access the group anymore so I would say that is more likely a change on the user properties. If the dynamic membership rule was change I expect that more than one user lost the access. With this specific question wording and answer set, I would go with B.
upvoted 1 times
...
LoremanReturns
3 years, 9 months ago
Tested in my lab. The correct answer is B. An administrator performed a change on User 1 attributes and broke the match with dynamic group membership. This action is audit under "User administration activities - Updated user"
upvoted 4 times
...
encxorblood
3 years, 10 months ago
For me is not clear. I can update the query for the dynamic group. Bu I can also edit a user property, location as a sample and user i also out of group. But I think she mean answer B.
upvoted 2 times
...
donathon
3 years, 11 months ago
C A: This is a dynamic group, after you create the group, you cannot change it from a dynamic group to a static group, you must re-create the group. Hence, the only way to remove the member is to either change the query or the user attributes (whatever that is) that will add the user to the group. It all depends on the query. B: While this can be an answer it cannot guarantee that the user is removed from the group. It all depends on how the group membership query is constructed which may or may not be based on the user attributes. C: This is the only way that the user can be removed from the group which is by modifying the query itself.
upvoted 4 times
JT19760106
3 years, 3 months ago
As you stated, you don't understand what user attributes are or how a dynamic query works. All you have to do is change the attribute(s) of the user that the dynamic query keys off of to have that user fall out of the group. Only one user was impacted so it's not likely that the group was updated.
upvoted 3 times
...
...
Fr3ddy
3 years, 11 months ago
I think answer C. This can help https://docs.microsoft.com/en-us/microsoft-365/compliance/search-the-audit-log-in-security-and-compliance?view=o365-worldwide#user-administration-activities
upvoted 1 times
...
BrianGold
3 years, 12 months ago
Part of the question states "You suspect that an administrator made a change that caused User1 to be removed from Group1" That is the key to which answer is correct. Therefore, I go with C.
upvoted 1 times
...
MSGrady
4 years, 1 month ago
B... When an attribute changes for a user or device, all dynamic group rules in the organization are processed for membership changes. Tested with an existing customer
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago