exam questions

Exam MS-101 All Questions

View all questions & answers for the MS-101 exam

Exam MS-101 topic 5 question 1 discussion

Actual exam question from Microsoft's MS-101
Question #: 1
Topic #: 5
[All MS-101 Questions]

You need to recommend a solution for the security administrator. The solution must meet the technical requirements.
What should you include in the recommendation?

  • A. Microsoft Azure Active Directory (Azure AD) Privileged Identity Management
  • B. Microsoft Azure Active Directory (Azure AD) Identity Protection
  • C. Microsoft Azure Active Directory (Azure AD) conditional access policies
  • D. Microsoft Azure Active Directory (Azure AD) authentication methods
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bouncy
Highly Voted 3 years, 1 month ago
Selected Answer: B
Requirement: high sign-in risk -> MFA. This is clearly an Identity Protection policy https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-policies
upvoted 7 times
schaedlerson
2 years, 11 months ago
B, i see it like you
upvoted 1 times
...
...
jonny_sins
Most Recent 1 year, 9 months ago
the answer is C. anyone who said B please reread the question and requirements from microsoft. B is accurate but C is a better answer
upvoted 2 times
...
gills
1 year, 10 months ago
I should be B and yet the RISK based conditions are not available in Conditional Policy. https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-configure-risk-policies#migrate-risk-policies-from-identity-protection-to-conditional-access
upvoted 1 times
...
shaden2000
2 years, 5 months ago
Selected Answer: B
Conditional is great but the admin requires a report. Identity protections provides the report and the resolve.
upvoted 2 times
...
ziziman
2 years, 7 months ago
Selected Answer: B
Identity Protection policies While Identity Protection also offers a user interface for creating 1) user risk policy and 2) sign-in risk policy, we highly recommend that 3) 'you use Azure AD Conditional Access to create risk-based policies for the following benefits': Rich set of conditions to control access: Conditional Access offers a rich set of conditions such as applications and locations for configuration. The risk conditions can be used in combination with other conditions to create policies that best enforce your organizational requirements. Multiple risk-based policies can be put in place to target different user groups or apply different access control for different risk levels. Conditional Access policies can be created through Microsoft Graph API and can be tested first in report-only mode. Manage all access policies in one place in Conditional Access.
upvoted 2 times
...
lusis987
2 years, 9 months ago
Identity protection The risk signals can trigger remediation efforts such as requiring: perform multifactor authentication, reset their password using self-service password reset, or block access until an administrator takes action.
upvoted 1 times
...
KemalM
2 years, 10 months ago
Selected Answer: C
It asks what you should include in your recommendation. Definitely you should recommend conditional access policy in order to require MFA for high sign-in risk
upvoted 3 times
bartdxxx
2 years, 2 months ago
where do you find sign-in risk in CA policies?
upvoted 1 times
...
jage01
2 years, 9 months ago
I'll go with C(CA) too, include all with the role Security administrators. With B, you have to know and target a specific user.
upvoted 1 times
jage01
2 years, 9 months ago
never mind, misread the question - was thinking the only the SA needs to login with MFA for high sign-in risk.
upvoted 1 times
...
...
DaDaDave
2 years, 7 months ago
Yes, but conditional access policies only do the enforcement, they also require a report from which the administrator will create the necessary policies Conditional access is under the umbrella of identity protection https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-security-overview
upvoted 2 times
...
...
RazielLycas
2 years, 10 months ago
Selected Answer: B
"based on that report" the policy probably will be a conditional access but the requirments is achieved with Identity protection, doesn't it?
upvoted 1 times
AK_1234
5 months, 2 weeks ago
Conditional is great but the admin requires a report. Identity protections provides the report and the resolve.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...