exam questions

Exam MS-101 All Questions

View all questions & answers for the MS-101 exam

Exam MS-101 topic 3 question 49 discussion

Actual exam question from Microsoft's MS-101
Question #: 49
Topic #: 3
[All MS-101 Questions]

HOTSPOT -
You have a Microsoft 365 subscription that uses a default domain named contoso.com. The domain contains the users shown in the following table.

The domain contains the devices shown in the following table.

The domain contains conditional access policies that control access to a cloud app named App1. The policies are configured as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Note: Block access overrides Grant access
References:
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/plan-conditional-access

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PersonT
Highly Voted 4 years, 3 months ago
Yes,yes,no
upvoted 53 times
ALPHA_DELTA
4 years, 3 months ago
The policies only apply to members of Group1. If you are not a member of Group1, you get access, unless there is a policy that DOES apply to your group. No policy applies to the Compliant group, so User1 can access from any device. For User2, Policies 1 and 3 apply (Group2 is excluded from Policy2). Policy 1 blocks access to noncompliant devices and both allow access to compliant devices. Since Blocks beat out Allows, User2 can access from Device1 and not from Device2.
upvoted 7 times
IgorMatic
4 years, 3 months ago
great explanation.
upvoted 1 times
...
365admin
4 years, 2 months ago
User 1 belongs to a group named -group1 and not 'compliant'. User1 will be blocked on any device by Policy2. User2 will be allowed access on device1 and blocked on device2 by policy1 Hence answer will NO, YES,NO User2 will be blocked
upvoted 16 times
...
Domza
3 years, 10 months ago
Where do you see "Compliant Group:?
upvoted 4 times
...
...
...
King2
Highly Voted 4 years, 1 month ago
Box 1: Yes. User1 is in a group Group1, so policy1 applies. Policy1 excludes compliant devices and device1 is compliant. Therefore Policy1 does not apply. User1 can access App1 from Device1. Box 2: Yes. User2 is in Group1 so Policy1 applies first. Policy1 excludes compliant devices and Device1 is compliant. Therefore, Policy1 does not apply so we move on to Policy2. User2 is also in Group2. Policy2 excludes Group2. Therefore, Policy2 does not apply so we move on to Policy3. Policy3 applies to Group1 so Policy3 applies to User2. Policy3 applies to ‘All device states’ so Policy3 applies to Device1. Policy3 grants access. Therefore, User2 can access App1 using Device1. Box 3: No. User2 is in Group1 so Policy1 applies. Policy1 excludes compliant devices but Devices is non-compliant. Therefore, User2 cannot access App1 from Device2. Note that the in Exam 100, User1 is a member of compliant group. In Exam 101, User1 is a member of Group1. However Box1 will remain yes in both cases
upvoted 39 times
Bouncy
3 years, 1 month ago
Box1: only if you stop processing policies after the first match for whatever reason. Which is not how CA works, there's an OR operator between them and no priority. As lucidgreen explained: NYN
upvoted 7 times
...
lucidgreen
3 years, 11 months ago
Policy 2 says that anyone belonging to Group 1, except for those also belonging to Group 2, are blocked, regardless of device compliance. N, Y, N
upvoted 24 times
...
...
Feyenoord
Most Recent 2 years, 2 months ago
It's No, Yes, No Block will always win from Grant!
upvoted 2 times
...
Fala_Fel
2 years, 6 months ago
N Y N Exclude overrides Include Block overrides Grant No - User 1 will be blocked by Policy 2 Yes - Device 1 is excluded from Policy 1 so not blocked. Group 2 is excluded from Policy 2 so not blocked. User 2 is member of Group 1 as well so Policy 3 grants access No - User 2 on a non compliant device is blocked by Policy 1
upvoted 5 times
EsamiTopici
2 years, 5 months ago
Correct 100%!
upvoted 2 times
...
...
rnd3131
2 years, 10 months ago
i say n y n https://danielchronlund.com/2018/11/23/how-multiple-conditional-access-policies-are-applied/
upvoted 7 times
...
SaeedFarvardin
2 years, 10 months ago
100% Y / Y / N !!!
upvoted 4 times
SaeedFarvardin
2 years, 10 months ago
exclude compliant device so DEVICE1 can access independed of users in this case, think simple, ;O) like if useful!
upvoted 2 times
...
...
TimNov
3 years ago
Yes,Yes,No appears to make the most sense.
upvoted 1 times
...
VirtualJP
3 years, 6 months ago
I'm going with NNN, based upon the following deduction: Firstly, CA policies aren’t applied in any particular order. All policies apply and only the resultant matching controls are used. Additionally, with CA, Block always wins over Grant. And I believe on top of that, Exclusion always wins over Inclusion. User 1, Device 1 - ultimately Policy 2's criteria is met, so answer No User 2, Device 1 - ultimately Policy 2's criteria is met, so answer No User 2, Device 2 - ultimately Policy 1's criteria is met, so answer No
upvoted 1 times
VirtualJP
3 years, 6 months ago
Apologies and correction! User 1, Device 1 - ultimately Policy 2's criteria is met, so answer No User 2, Device 1 - ultimately Policy 3's criteria is met, so answer Yes User 2, Device 2 - ultimately Policy 1's criteria is met, so answer No
upvoted 12 times
...
...
us3r
3 years, 6 months ago
No (blocked from Policy1) Yes (Policy1 excluded, Policy2 excluded, Policy3 Grant access) No (Blocked by Policy1)
upvoted 4 times
edzio
3 years, 2 months ago
The first case - No (blocked from Policy2)
upvoted 4 times
...
...
allesglar
3 years, 7 months ago
No, No, No, answer is correct. I really do not understand how everyone is confused with the policies. There is no ranking in CA policies and every policy applies, also for user2 who gets blocked.
upvoted 4 times
allesglar
3 years, 7 months ago
N, Y, N policy2 does not apply to User2 because of the exlusion.
upvoted 4 times
...
...
Superciuk
3 years, 7 months ago
NO,No,No Block access overrides Grant access
upvoted 1 times
...
ZuluHulu
3 years, 8 months ago
General consensus is No, Yes, No. Admin please update answer.
upvoted 3 times
...
Velda
3 years, 8 months ago
Guys, i researched this question a lot. It may seems same as the question in MS-100: https://www.examtopics.com/discussions/microsoft/view/9613-exam-ms-100-topic-3-question-1-discussion/ But it's not the same question! Be careful, there's different group name for User1. In the MS-100 question User1 is member of group "Compliant" and in our question (MS-101) User1 is member of "Group1". So this is why answers are different too! In the MS-100 it's Y, Y, N. But correct answer for our question (MS-101) is N, Y, N because Policy2 will apply to User1!
upvoted 2 times
...
Chris_Rock
3 years, 10 months ago
agree with Goseu N,Y,N Group 1 policy 1 device is compliant -> so excempt from block access. Policy 2 any state -> block access so box 1 = NO
upvoted 4 times
...
larnyx
3 years, 10 months ago
CA policies aren’t applied in any particular order. All matching policys apply and the resulting access controls required by the policies will be merged! If both grant and block policies match, block will always win. No exceptions! Therefore, answer provided should be correct! both users belong to Group 1, and policy 2 blocks access.
upvoted 2 times
...
NikPat3125
4 years ago
Correct Answer is No,No,No. People forget that User 2 belongs to group1 as well. So What rules applies to User1 same rule applies to user2.
upvoted 5 times
lucidgreen
3 years, 11 months ago
Users in Group 2 are exempted from Policy 2. User 2 is exempt from Policy 2.
upvoted 2 times
klosinskil
3 years, 10 months ago
Exclude always wins over Include, so Group 2 is excluded rather than included
upvoted 1 times
...
...
...
donathon
4 years, 1 month ago
NYN Policy1: Ensures that device must be compliant, if the device is not compliant, the device will be blocked. Policy2: Excludes wins Includes and hence User 2 should be excluded for policy 2. User1 would be included which is block access. Policy3: Users who are in Group 1 will be granted access if Policy1 and 2 does not apply to them. Note: All policies of CA are applicable because there is no priority. N: User1 is blocked by policy2. Y: User2 is excluded from policy2 and granted access by policy3 and device is compliant and so excluded from policy1. N: Device2 is not compliant so blocked by Policy1.
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...