Skip to Content

Microsoft 365 Identity and Services MS-100 Exam Questions and Answers – 1

The latest Microsoft 365 Identity and Services MS-100 certification actual real practice exam question and answer (Q&A) dumps are available free, which are helpful for you to pass the Microsoft 365 Identity and Services MS-100 exam and earn Microsoft 365 Identity and Services MS-100 certification.

Question 81

Question

Your network contains an on-premises Active Directory forest named contoso.com. The forest contains the following domains:

  • Contoso.com
  • East.contoso.com

An Azure AD Connect server is deployed to contoso.com. Azure AD Connect syncs to an Azure Active Directory (Azure AD) tenant.
You deploy a new domain named west.contoso.com to the forest.
You need to ensure that west.contoso.com syncs to the Azure AD tenant.
Solution: You create an Azure DNS zone for west.contoso.com. On the on-premises DNS servers, you create a conditional forwarder for west.contoso.com.
Does this meet the goal?

A. Yes
B. No

Answer

B. No

Question 82

Question

You have a Microsoft 365 subscription that contains an Azure Active Directory (Azure AD) tenant named contoso.com.
Corporate policy states that user passwords must not include the word Contoso.
What should you do to implement the corporate policy?

A. From the Azure Active Directory admin center, configure the Password protection settings.
B. From the Microsoft 365 admin center, configure the Password policy settings.
C. From Azure AD Identity Protection, configure a sign-in risk policy.
D. From the Azure Active Directory admin center, create a conditional access policy.

Answer

A. From the Azure Active Directory admin center, configure the Password protection settings.

Question 83

Question

Your network contains an on-premises Active Directory forest named contoso.com. The forest contains the following domains:

  • Contoso.com
  • East.contoso.com

An Azure AD Connect server is deployed to contoso.com. Azure AD Connect syncs to an Azure Active Directory (Azure AD) tenant.
You deploy a new domain named west.contoso.com to the forest.
You need to ensure that west.contoso.com syncs to the Azure AD tenant.
Solution: You install a new Azure AD Connect server in west.contoso.com and set AD Connect to active mode.
Does this meet the goal?

A. Yes
B. No

Answer

A. Yes

Question 84

Question

Your network contains an on-premises Active Directory forest named contoso.com. The forest contains the following domains:

  • Contoso.com
  • East.contoso.com

An Azure AD Connect server is deployed to contoso.com. Azure AD Connect syncs to an Azure Active Directory (Azure AD) tenant.
You deploy a new domain named west.contoso.com to the forest.
You need to ensure that west.contoso.com syncs to the Azure AD tenant.
Solution: You install a new Azure AD Connect server in west.contoso.com and set AD Connect to staging mode.
Does this meet the goal?

A. Yes
B. No

Answer

B. No

Question 85

Question

You have a Microsoft 365 subscription that contains the domains shown in the following exhibit.

Which domain name suffixes can you use when you create users?

A. only Sub1.Contoso1919.onmicrosoft.com
B. only Contoso1919.onmicrosoft.com and Sub2.Contoso1919.onmicrosoft.com
C. only Contoso1919.onmicrosoft.com, Sub1.Contoso1919.onmicrosoft.com, and Sub2.Contoso1919.onmicrosoft.com
D. all the domains in the subscription

Answer

C. only Contoso1919.onmicrosoft.com, Sub1.Contoso1919.onmicrosoft.com, and Sub2.Contoso1919.onmicrosoft.com

Question 86

Question

You have a Microsoft 365 subscription that contains the users shown in the following table.

You plan to use Exchange Online to manage email for a DNS domain.
An administrator adds the DNS domain to the subscription.
The DNS domain has a status of incomplete setup.
You need to identify which user can complete the setup of the DNS domain. The solution must use the principle of least privilege.
Which user should you identify?

A. User1
B. User2
C. User3
D. User4

Answer

A. User1

Question 87

Question

Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the objects shown in the following table.

You configure Azure AD Connect to sync contoso.com to Azure Active Directory.
Which objects will sync to Azure AD?

A. Group1, User1, and User2
B. Group1 and User1 only
C. User1 and User2 only
D. Group1 only

Answer

B. Group1 and User1 only

Manage User Identity and Roles Testlet 2

Overview

Contoso, Ltd. is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York.

The offices have the users and devices shown in the following table.

Contoso recently purchased a Microsoft 365 E5 subscription.

Existing Environment

The network contains an Active directory forest named contoso.com and a Microsoft Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com.

You recently configured the forest to sync to the Azure AD tenant.

You add and then verify adatum.com as an additional domain name.

All servers run Windows Server 2016.

All desktop computers and laptops run Windows 10 Enterprise and are joined to contoso.com.

All the mobile devices in the Montreal and Seattle offices run Android. All the mobile devices in the New York office run iOS.

Contoso has the users shown in the following table.

Contoso has the groups shown in the following table.

Microsoft Office 365 licenses are assigned only to Group2.

The network also contains external users from a vendor company who have Microsoft accounts that use a suffix of @outlook.com.

Requirements

Planned Changes
Contoso plans to provide email addresses for all the users in the following domains:

  • East.adatum.com
  • Contoso.adatum.com
  • Humongousinsurance.com

Technical Requirements
Contoso identifies the following technical requirements:

  • All new users must be assigned Office 365 licenses automatically.
  • The principle of least privilege must be used whenever possible.

Security Requirements
Contoso identifies the following security requirements:

  • Vendors must be able to authenticate by using their Microsoft account when accessing Contoso resources.
  • User2 must be able to view reports and schedule the email delivery of security and compliance reports.
  • The members of Group1 must be required to answer a security question before changing their password.
  • User3 must be able to manage Office 365 connectors.
  • User4 must be able to reset User3 password.

Question 88

Question

You need to assign User2 the required roles to meet the security requirements.
Solution: From the Office 365 admin center, you assign User2 the Security Reader role. From the Exchange admin center, you assign User2 the Compliance Management role.
Does this meet the goal?

A. Yes
B. No

Answer

A. Yes

Question 89

Question

You need to assign User2 the required roles to meet the security requirements.
Solution: From the Office 365 admin center, you assign User2 the Security Administrator role. From the Exchange admin center, you add User2 to the View-Only Organization Management role.
Does this meet the goal?

A. Yes
B. No

Answer

B. No

Question 90

Question

You need to assign User2 the required roles to meet the security requirements.
Solution: From the Office 365 admin center, you assign User2 the Security Reader role. From the Exchange admin center, you assign User2 the Help Desk role.
Does this meet the goal?

A. Yes
B. No

Answer

B. No