MS-101 Microsoft 365 Mobility and Security Exam Questions and Answers – Page 1

The latest MS-101 Microsoft 365 Mobility and Security certification actual real practice exam question and answer (Q&A) dumps are available free, which are helpful for you to pass the MS-101 Microsoft 365 Mobility and Security exam and earn MS-101 Microsoft 365 Mobility and Security certification.

Exam Question 21

You are deploying Microsoft Endpoint Manager.
You successfully enroll Windows 10 devices in Endpoint Manager.
When you try to enroll an iOS device in Endpoint Manager, you get an error.
You need to ensure that you can enroll the iOS device in Endpoint Manager.
Solution: You create the Mobility (MDM and MAM) settings.
Does this meet the goal?

A. Yes
B. No
Correct Answer:
B. No

Exam Question 22

Your network contains an Active Directory domain named contoso.com that is synced to Microsoft Azure Active Directory (Azure AD).
You manage Windows 10 devices by using Microsoft System Center Configuration Manager (Current Branch).
You configure pilot co-management.
You add a new device named Device1 to the domain. You install the Configuration Manager client on Device1.
You need to ensure that you can manage Device1 by using Microsoft Intune and Configuration Manager.
Solution: You add Device1 to a Configuration Manager device collection.
Does this meet the goal?

A. Yes
B. No
Correct Answer:
B. No

Exam Question 23

From the Microsoft Azure Active Directory (Azure AD) Identity Protection dashboard, you view the risk events shown in the exhibit. (Click the Exhibit tab.)
From the Microsoft Azure Active Directory (Azure AD) Identity Protection dashboard, you view the risk events shown in the exhibit.
You need to reduce the likelihood that the sign-ins are identified as risky.
What should you do?

A. From the Security & Compliance admin center, create a classification label.
B. From the Security & Compliance admin center, add the users to the Security Readers role group.
C. From the Azure Active Directory admin center, configure the trusted IPs for multi-factor authentication.
D. From the Conditional access blade in the Azure Active Directory admin center, create named locations.
Correct Answer:
D. From the Conditional access blade in the Azure Active Directory admin center, create named locations.

Exam Question 24

Your company has a Microsoft 365 E5 subscription.
Users in the research department work with sensitive data.
You need to prevent the research department users from accessing potentially unsafe websites by using hyperlinks embedded in email messages and documents. Users in other departments must not be restricted.
What should you do from the Security & Compliance admin center?

A. Create a data loss prevention (DLP) policy that has a Content is shared condition.
B. Modify the default safe links policy.
C. Create a data loss prevention (DLP) policy that has a Content contains condition.
D. Create a new safe links policy.
Correct Answer:
D. Create a new safe links policy.

Exam Question 25

You have a Microsoft 365 tenant.
You have a line-of-business application named App1 that users access by using the My Apps portal.
After some recent security breaches, you implement a conditional access policy for App1 that uses Conditional Access App Control.
You need to be alerted by email if impossible travel is detected for a user of App1. The solution must ensure that alerts are generated for App1 only.
What should you do?

A. From Microsoft Cloud App Security, create a Cloud Discovery anomaly detection policy.
B. From Microsoft Cloud App Security, modify the impossible travel alert policy.
C. From Microsoft Cloud App Security, create an app discovery policy.
D. From the Azure Active Directory admin center, modify the conditional access policy.
Correct Answer:
A. From Microsoft Cloud App Security, create a Cloud Discovery anomaly detection policy.

Exam Question 26

A user receives the following message when attempting to sign in to https://myapps.microsoft.com:

“Your sign-in was blocked. We’ve detected something unusual about this sign-in. For example, you might be signing in from a new location, device, or app. Before you can continue, we need to verify your identity. Please contact your admin.”

Which configuration prevents the users from signing in?

A. Microsoft Azure Active Directory (Azure AD) Identity Protection policies
B. Microsoft Azure Active Directory (Azure AD) conditional access policies
C. Endpoint Manager compliance policies
D. Security & Compliance data loss prevention (DLP) policies
Correct Answer:
B. Microsoft Azure Active Directory (Azure AD) conditional access policies

Exam Question 27

You have the Microsoft Azure Active Directory (Azure AD) users shown in the following table.

NameMember of
User1Group1
User2Group2

Your company uses Microsoft Intune.
Several devices are enrolled in Intune as shown in the following table.

NamePlatformBitLocker Drive Encryption (BitLocker)Member of
Device1Windows 10DisabledGroup3
Device2Windows 10DisabledGroup4

The device compliance policies in Intune are configured as shown in the following table.

NameRequire BitLockerAssigned to
Policy1Not configuredGroup3
Policy2RequireGroup4

You create a conditional access policy that has the following settings:

  • The Assignments settings are configured as follows:
    1. Users and groups: Group1
    2. Cloud apps: Microsoft Office 365 Exchange Online
    3. Conditions: Include All device state, exclude Device marked as compliant
  • Access controls is set to Block access.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

  • User1 can access Microsoft Exchange Online from Device1.
  • User1 can access Microsoft Exchange Online from Device2.
  • User2 can access Microsoft Exchange Online from Device2.

Correct Answer:

  • User1 can access Microsoft Exchange Online from Device1: Yes
  • User1 can access Microsoft Exchange Online from Device2: No
  • User2 can access Microsoft Exchange Online from Device2: No

Exam Question 28

You have several devices enrolled in Microsoft Intune.
You have a Microsoft Azure Active Directory (Azure AD) tenant that includes the users shown in the following table.

NameRoleMember of
User1Cloud device administratorGroupA
User2Intune administratorGroupB
User3NoneNone

The device limit restrictions in Intune are configured as shown in the following table.

PriorityNameDevice limitAssigned to
1Policy115GroupA
2Policy210GroupB
DefaultAll users5All users

You add User3 as a device enrollment manager in Intune.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

  • User1 can enroll a maximum of 10 devices in Intune.
  • User2 can enroll a maximum of 10 devices in Intune.
  • User3 can enroll an limited number of devices in Intune.

Correct Answer:

  • User1 can enroll a maximum of 10 devices in Intune: No
  • User2 can enroll a maximum of 10 devices in Intune: Yes
  • User3 can enroll an limited number of devices in Intune: No

Exam Question 29

Your company has a Microsoft 365 tenant.
You plan to allow users from the engineering department to enroll their mobile device in mobile device management (MDM).
The device type restrictions are configured as shown in the following table.

PriorityNameAllowed platformAssigned to
1iOSiOSMarketing
2AndroidAndroidEngineering
DefaultAll usersAll platformsAll users

The device limit restrictions are configured as shown in the following table.

PriorityNameDevice limitAssigned to
1Engineering15Engineering
2Wet Region5Engineering
DefaultAll users10All users

What is the effective configuration for the members of the Engineering group? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Device limit:

  • 5
  • 10
  • 15

Allowed platform:

  • Android only
  • iOS only
  • All platforms

Correct Answer:

  • Device limit: 15
  • Allowed platform: Android only

Exam Question 30

Your network contains an Active Directory domain named contoso.com. The domain contains 100 Windows 8.1 devices.
You plan to deploy a custom Windows 10 Enterprise image to the Windows 8.1 devices.
You need to recommend a Windows 10 deployment method.
What should you recommend?

A. a provisioning package
B. an in-place upgrade
C. wipe and load refresh
D. Windows Autopilot
Correct Answer:
B. an in-place upgrade