exam questions

Exam MS-100 All Questions

View all questions & answers for the MS-100 exam

Exam MS-100 topic 3 question 2 discussion

Actual exam question from Microsoft's MS-100
Question #: 2
Topic #: 3
[All MS-100 Questions]

Your company has a Microsoft 365 subscription.
You need to identify which users performed the following privileged administration tasks:
✑ Deleted a folder from the second-stage Recycle Bin if Microsoft SharePoint
✑ Opened a mailbox of which the user was not the owner

Reset a user password -

What should you use?

  • A. Microsoft Azure Active Directory (Azure AD) audit logs
  • B. Microsoft Azure Active Directory (Azure AD) sign-ins
  • C. Security & Compliance content search
  • D. Security & Compliance audit log search
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Tryggr
Highly Voted 4 years ago
D is the correct answer. "Because you can search for the following types of user and admin activity in Microsoft 365: User activity in SharePoint Online and OneDrive for Business Admin activity in Exchange Online (Exchange admin audit logging)" https://docs.microsoft.com/en-us/microsoft-365/compliance/search-the-audit-log-in-security-and-compliance?view=o365-worldwide https://docs.microsoft.com/en-us/microsoft-365/compliance/search-the-audit-log-in-security-and-compliance?view=o365-worldwide
upvoted 21 times
...
Agbantu
Highly Voted 4 years ago
Definitely D, Audit log search from the SCC (now compliance.microsoft.com)
upvoted 11 times
...
BigDazza_111
Most Recent 2 years, 1 month ago
Selected Answer: D
D 4 sure. Azure AD audit logs do not let you search SP online activities
upvoted 1 times
...
BigDazza_111
2 years, 2 months ago
Selected Answer: D
Audit logs in Azure display device and user athentication data. Not Activity logs.
upvoted 1 times
...
JCkD4Ni3L
2 years, 2 months ago
Selected Answer: D
Answer is D.
upvoted 1 times
...
bsaksham
2 years, 5 months ago
Selected Answer: D
No brainer
upvoted 1 times
...
ARZIMMADAR
2 years, 5 months ago
Absolute Joke. D is the correct answer
upvoted 1 times
...
Contactfornitish
2 years, 11 months ago
Selected Answer: D
A, are you joking? Deletion of files isn't privileged that way
upvoted 2 times
...
Contactfornitish
2 years, 11 months ago
Selected Answer: D
Been doing since a while
upvoted 3 times
...
Stiobhan
3 years, 1 month ago
1000% answer is D. Just ran exact audit on my tenant and all choices are there 😉
upvoted 3 times
...
jru24
3 years, 2 months ago
yes, I tested it. D is correct
upvoted 1 times
...
Wojer
3 years, 6 months ago
just test it and its D
upvoted 2 times
...
PDR
3 years, 6 months ago
also D
upvoted 1 times
...
tcmaggio
3 years, 6 months ago
Selected Answer: D
D for me.
upvoted 3 times
...
kaveri123
3 years, 6 months ago
Should be letter D. I made some test in my LAB and compare the two. Azure Audit logs only see who reset the password. Audits Logs > Filter the activity Security & Compliance > Audit has all the necessary options that mentioned on this questions (Passwords, Deleted Folder, Opened a mailbox)
upvoted 5 times
...
tcmaggio
3 years, 7 months ago
Selected Answer: D
I also vote D.
upvoted 5 times
...
Mavula
3 years, 7 months ago
So why don't they update this answer to be D?
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...