exam questions

Exam MS-101 All Questions

View all questions & answers for the MS-101 exam

Exam MS-101 topic 3 question 35 discussion

Actual exam question from Microsoft's MS-101
Question #: 35
Topic #: 3
[All MS-101 Questions]

HOTSPOT -
You have a Microsoft 365 subscription.
Your network uses an IP address space of 51.40.15.0/24.
An Exchange Online administrator recently created a role named Role1 from a computer on the network.
You need to identify the name of the administrator by using an audit log search.
For which activities should you search and by which field should you filter in the audit log search? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
NikPat3125
Highly Voted 3 years, 11 months ago
Came in exam 27.07.2021
upvoted 28 times
Domza
3 years, 10 months ago
as always. thx for feedback
upvoted 7 times
...
...
gkp_br
Highly Voted 3 years, 10 months ago
Activities to search for: Show results for all activities Field to filter by: Item I tested on my tenant.
upvoted 24 times
RenegadeOrange
2 years, 9 months ago
Agree Item will show the name of the role which is the info you can search for when you filter the export.
upvoted 1 times
...
...
Sanjee31
Most Recent 2 years ago
in exam 28/6/2023
upvoted 2 times
...
den5_pepito83
2 years, 4 months ago
in exam 12.2.2023
upvoted 2 times
...
EsamiTopici
2 years, 4 months ago
Has anyone tested it?
upvoted 1 times
...
freeq
2 years, 6 months ago
Came on exam 30.12.2022
upvoted 1 times
...
AZalan
3 years, 2 months ago
"Show results from all activities" does not exist anymore. ( can someone else verify pls) But if you can use wildcard " * " which pulls all activities, and then you can filter by details or Activity
upvoted 2 times
...
JamesM9
3 years, 3 months ago
Show results for all Activities/Item.
upvoted 2 times
...
Glorence
3 years, 4 months ago
still valid, it was in my exam last Feb 5, 2022
upvoted 10 times
...
JT19760106
3 years, 5 months ago
Show results for all activities Filter by User 1) Tested and best option a) Show results for all activities b) Filter by Activity i) Activity will show "New-RoleGroup" command, but isn't an option in question ii) User is next helpful, but doesn't state you know the name of the admin(s) iii) Item is a GUID iv) Detail is blank v) IP Address is blacnk
upvoted 1 times
...
gan998
3 years, 9 months ago
I must be missing something here, why not filter by "user" once the search is made. The user field shows you which user did this lol..
upvoted 2 times
bk_apex
3 years, 9 months ago
I had the same thought but then I realized the question states "You need to identify the name of the administrator by using an audit log search." You can't filter on something you don't know! In this case you're using what you do know to find the user name in the logs.
upvoted 8 times
Glorence
3 years, 5 months ago
Agree! "You can't filter on something you don't know!" - make sense
upvoted 3 times
...
Turak64
3 years, 8 months ago
Another ambiguous question with not enough info to properly determine the answer. You have to presume you don't know the names of all the admins in your company, which is 1. unrealstic 2. depending on your access, you can find out what users have been assigned roles that would enable them to do this and then search by those names... In real life, you'd just send an email out or ask the person you're working with. Silly, silly, question that has no practical use.
upvoted 3 times
...
...
...
Dave12
3 years, 9 months ago
Came in the exam 22 09 2021
upvoted 11 times
...
Ahema
3 years, 10 months ago
Show results for all activities / details
upvoted 3 times
...
LoremanReturns
3 years, 11 months ago
Tested on my lab. You need to "Show results for all activities" because other options does not include the "New-TransportRule" operation. "Item" is empty, "Detail" is empty. "Users" is filled with the user who performed the action, "IP Address" is filled with the public IP of the client who performed the action (with also port 5547). So the right answer for me is "Show results for all activities" and "IP Address", matching these two information give you the user who performed the action.
upvoted 2 times
LoremanReturns
3 years, 11 months ago
My mistake i read "Rule" insted of "Role". Made the test in my lab by creating a new Role and i need to change my answers. "Item" is filled with the name of the newly created role. You can use this information to match the user who performed the action. The right answers are "Show results for all activities" and "Item".
upvoted 14 times
...
...
MyHawkeye
4 years ago
As per -- https://docs.microsoft.com/en-us/microsoft-365/compliance/search-the-audit-log-in-security-and-compliance?view=o365-worldwide -- searching the audit log is a two step process: - first, you can search by activities, date, users and object(file, folder or site) - second, you filter the results - again by date, user, activity, item or detail. The two questions relate to that process: 1. "Show results for all activities" seems the only valid option to me: - Role creation is not logged in "Exchange mailbox activities" or "Site administration activities" - As per @donathon "Role administration activities" only contains add/remove member 2. "Item" seems to be the best option to me: - "User" is what we are looking for, so we cannot filter for that - "IP address" is not available in the dialog (maybe in PowerShell, I don't know - but anyway, we know only the network range, not the exact IP of the administrators machine!) - "Detail" - I have no idea what would be shown here in relation to the question. To summarize - if I get this question in the exam, I will go for "Show results for all activities" and "Item".
upvoted 8 times
...
joyyyyyyyyyyyyy
4 years ago
what is the correct answers then?
upvoted 2 times
...
donathon
4 years ago
Show results for all activities and IP address. Exchange mailbox activities: Mailbox activities performed by the mailbox owner, a delegated user, or an administrator Site administration activities: Sharepoint activities. Role Role administration activities: Only has add\remove member. Hence the only option is to Show results for all activities. Did a search in SCC: Item: The object that was created or modified as a result of the corresponding activity. For example, the file that was viewed or modified or the user account that was updated. Not all activities have a value in this column. User: The user (or service account) who performed the action that triggered the event. Detail: Additional information about an activity. Again, not all activities have a value. IP address: The IP address of the device that was used when the activity was logged. The IP address is displayed in either an IPv4 or IPv6 address format. Conclusion: The only option here is by IP address. Detail is mostly blank. Item only shows what was changed. User is not useful as you don’t know who that user is.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...