exam questions

Exam MS-101 All Questions

View all questions & answers for the MS-101 exam

Exam MS-101 topic 2 question 98 discussion

Actual exam question from Microsoft's MS-101
Question #: 98
Topic #: 2
[All MS-101 Questions]

You have a Microsoft 365 E5 subscription that contains the devices shown in the following table.

You need to configure an incident email notification rule that will be triggered when an alert occurs only on a Windows 10 device. The solution must minimize administrative effort.
What should you do first?

  • A. From the Microsoft 365 admin center, create a mail-enabled security group.
  • B. From the Microsoft 365 Defender portal, create a device group.
  • C. From the Microsoft Endpoint Manager admin center, create a device category.
  • D. From the Azure Active Directory admin center, create a dynamic device group.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
agnesmandriva
2 years, 2 months ago
Selected Answer: D
"The solution must minimize administrative effort" so D I think.
upvoted 3 times
...
RiTh73
2 years, 2 months ago
Selected Answer: D
D is Correct. Create a dynamic group to query all those devices with Windows 10 first.
upvoted 2 times
...
Meebler
2 years, 2 months ago
B is a more specific solution for this particular use case. The Microsoft 365 Defender portal is specifically designed for threat protection, and creating a device group in this portal allows you to better focus on security and threat management. On the other hand, creating a dynamic device group in the Azure Active Directory admin center is a more general solution that could be used for a wider range of scenarios. B is also easier to use for this specific scenario. Creating a device group in the Microsoft 365 Defender portal is a simple and straightforward process, and you can quickly filter devices based on specific criteria such as operating system version, device type, etc. This can help you create a more targeted device group that meets your needs. Overall, while D is also a valid choice for creating a device group, B is a better option for this specific scenario because it is a more specific and easier-to-use solution that is designed specifically for threat protection.
upvoted 2 times
...
Y2
2 years, 3 months ago
Selected Answer: D
The solution must minimize administrative effort!!
upvoted 1 times
...
bac0n
2 years, 5 months ago
Selected Answer: B
I know the dynamic device group sounds like the best answer, but this is asking about Defender for Endpoint and Device Groups are king. In Defender for Endpoint you can configure device groups to contain only PCs of a certain OS, IE Windows 10, like the question asks, and Email notifications are configured directly in Defender for Endpoint; this is not asking about an alert policy. The answer is 100% B.
upvoted 4 times
Fala_Fel
2 years, 4 months ago
Agree Ans is B - device groups in 365 Defender by Win OS already have a setting there to select, and you would create the email notification rule in 365 Defender as well. So B minimises admin effort.
upvoted 1 times
...
...
DaDaDave
2 years, 6 months ago
Selected Answer: D
D is correct since it will only be needed to be configured once, minimizing administrative effort, dynamic groups can be generated from either endpoint manager or azure AD portal pyramidhead further explains
upvoted 2 times
...
Mayank71291
2 years, 7 months ago
Selected Answer: B
In the navigation pane, select Settings > Endpoints > Permissions > Device groups. Click Add device group. Enter the group name and automation settings and specify the matching rule that determines which devices belong to the group.
upvoted 3 times
...
pyramidhead
2 years, 7 months ago
Answer is D. Key is "The solution must minimize administrative effort". https://learn.microsoft.com/en-us/mem/intune/enrollment/device-group-mapping "To enable automatic grouping, you must create a dynamic group using attribute-based rules in Azure AD. For instructions, see Using attributes to create advanced rules in the Azure AD documentation. Create an advanced rule for your group using the deviceCategory attribute and the category name you created in Step 1 of this article. For example, to create a rule that automatically groups devices belonging in the HR category, use the following rule syntax: device.deviceCategory -eq "HR"
upvoted 3 times
...
rolia
2 years, 7 months ago
Selected Answer: C
Endpoint.microsoft.com -> Groups -> Dynamic Device Group Answer seems to be C
upvoted 1 times
...
RenegadeOrange
2 years, 7 months ago
Selected Answer: B
Correct. You create an rule for alert notifications and in that you select the device group so you have to create the device group first. Settings > Endpoints > General > Email notifications. https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-email-notifications?view=o365-worldwide Settings > Endpoints > Permissions > Device groups https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/machine-groups?view=o365-worldwide
upvoted 4 times
...
Gloomer
2 years, 7 months ago
Selected Answer: D
To minimize the effort required, a dynamic device group is the correct choice. The easiest way to target windows 10.
upvoted 1 times
...
reastman66
2 years, 8 months ago
I guess it could be B but when creating the Incident notification it only asks for the basic information and then an email address. I think the correct answer is A.
upvoted 1 times
...
rjoihsoh
2 years, 10 months ago
seems correct - https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-email-notifications?view=o365-worldwide
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago