exam questions

Exam MS-101 All Questions

View all questions & answers for the MS-101 exam

Exam MS-101 topic 2 question 91 discussion

Actual exam question from Microsoft's MS-101
Question #: 91
Topic #: 2
[All MS-101 Questions]

You have a Microsoft 365 E5 subscription.
You need to identify which users accessed Microsoft Office 365 from anonymous IP addresses during the last seven days.
What should you do?

  • A. From the Defender for Cloud Apps admin center, select Users and accounts.
  • B. From the Microsoft 365 Defender, view the Threat tracker.
  • C. From the Microsoft 365 admin center, view the Security & compliance report.
  • D. From the Azure Active Directory admin center, view the Risky sign-ins report.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
allesglar
Highly Voted 3 years, 6 months ago
Selected Answer: D
There is no way to filter based on the IP in users and accounts of cloud app security. I believe the answer is D the there is also a 7 day filter for anonymous IPs.
upvoted 26 times
...
tagada
Highly Voted 3 years, 6 months ago
Selected Answer: D
i think correct answer is D.
upvoted 9 times
...
Amir1909
Most Recent 1 year, 4 months ago
D is correct
upvoted 1 times
...
BigDazza_111
1 year, 9 months ago
Selected Answer: A
Look under heading 'Activity from anonymous IP address' half way down page https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks#activity-from-anonymous-ip-address
upvoted 1 times
...
Jo696
2 years ago
Selected Answer: D
Always Azure AD, Risky sign in
upvoted 1 times
...
DilythiumCrystal
2 years, 3 months ago
That being said the use of users does not seem right as it is a policy that you set up to then see a threat detection from Cloudapps/Control/Policies/threat detections which has now been hidden somewhere in Defender
upvoted 1 times
...
DilythiumCrystal
2 years, 3 months ago
Correct Answer was A. https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy. However they have changed the portal so there is no way of knowing if it is still the case.
upvoted 1 times
...
KrisDeb
2 years, 8 months ago
Selected Answer: D
D, Risky sign-in
upvoted 2 times
...
Burki_71
2 years, 8 months ago
Selected Answer: D
I think D, Risky Sign-In
upvoted 1 times
...
mackzone
3 years ago
Came on exam 25-06-2022
upvoted 1 times
...
venwaik
3 years, 1 month ago
Selected Answer: D
Answer D. Came on exam 09-05-2022
upvoted 2 times
...
JamesM9
3 years, 3 months ago
Tested today - the criteria is met within the risky sign-ins report found within the Azure Active Directory. Therefore, the answer is D.
upvoted 1 times
...
ScottT
3 years, 3 months ago
Looking at Risk Detections in https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-investigate-risk . You can see reported Anonymous IP Addresses. This isn't strictly Risky Sign-ins but compared to the other answers it is in the right area. I go with D.
upvoted 2 times
...
edzio
3 years, 4 months ago
Selected Answer: D
D is correct
upvoted 2 times
...
Goena
3 years, 6 months ago
Correct answer is D.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...