Certification Provider: Microsoft
Exam Name: Microsoft 365 Mobility and Security
Exam Code: MS-101
Official Exam Time: 150 mins
Number of questions in the Official Exam: 40-60 Q&As
Latest update time in our database: September 27,2023
MS-101 Official Exam Topics:
  • Topic1 : Plan and implement device services (35-40%)
  • Topic2 : Plan co-management between Endpoint Configuration Manager and Intune / Plan and implement configuration profiles for iOS and Android
  • Topic3 : Plan and implement device security and compliance by using Microsoft Endpoint Manager / Plan and implement device compliance policies
  • Topic4 : Implement and manage security baselines / Plan and configure conditional access policies for device compliance
  • Topic5 : Plan and implement application deployment / Publish public and private applications by using Microsoft Endpoint Manager
  • Topic6 : Plan for Windows client deployment and management / Plan and implement additional Windows client security features
  • Topic7 : Plan and implement device enrollment / Plan and implement device registration to Azure AD
  • Topic8 : Review and respond to the Microsoft 365 Secure Score / Review and respond to issues identified in Microsoft Defender for Office 365, including threats, investigations, and campaigns
  • Topic9 : Configure Microsoft Defender for Endpoint settings / Review and respond to risks on devices
  • Topic10 : Configure Cloud App Discovery / Manage Microsoft 365 Compliance (30-35%)
  • Topic11 : Plan and implement information protection / Optimize label usage by using Content Explorer, Activity Explorer, and label reports
  • Topic12 : Plan and implement DLP for workloads / Retrieve and interpret audit logs for workloads
  • Topic13 : Specify a Content Search based on requirements /

What should you first?

Your network contains an on-premises Active Directory domain named contoso.com. The domain contains 1,000 Windows 10 devices.

You perform a proof of concept (PoC) deployment of Windows Defender Advanced Threat Protection (ATP) for 10 test devices. During the onboarding process, you configure Windows Defender ATP-related data to be stored in the United States.

You plan to onboard all the devices to Windows Defender ATP.

You need to store the Windows Defender ATP data in Europe.

What should you first?
A . Create a workspace.
B . Onboard a new device.
C . Delete the workspace.
D . Offboard the test devices.

Answer: D

You have a Microsoft 365 E5 tenant that contains the users shown in the following table

HOTSPOT

You have a Microsoft 365 E5 tenant that contains the users shown in the following table.

The tenant contains the devices shown in the following table.

You have the apps shown in the following table.

You plan to use Microsoft Endpoint Manager to manage the apps for the users.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Graphical user interface, text, application

Description automatically generated

Which properties of the alerts can you modify?

You have a Microsoft 365 subscription that contains the alerts shown in the following table.

Which properties of the alerts can you modify?
A . Status only
B . Status and Comment only
C . Status and Severity only
D . Status, Severity, and Comment only
E . Status, Severity, Comment and Category

Answer: B

Explanation:

Reference: https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/update-alert?view=o365-worldwide#limitations

You have a Microsoft 365 tenant named contoso.com

HOTSPOT

You have a Microsoft 365 tenant named contoso.com.

The tenant contains the users shown in the following table.

You have the eDiscovery cases shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Answer:

Explanation:

References: https://docs.microsoft.com/en-us/microsoft-365/compliance/assign-ediscovery-permissions

You have the Microsoft Azure Active Directory (Azure AD) users shown in the following table

HOTSPOT

You have the Microsoft Azure Active Directory (Azure AD) users shown in the following table.

Your company uses Microsoft Intune.

Several devices are enrolled in Intune as shown in the following table.

The device compliance policies in Intune are configured as shown in the following table.

You create a conditional access policy that has the following settings:

The Assignments settings are configured as follows:

✑ Users and groups: Group1

✑ Cloud apps: Microsoft Office 365 Exchange Online

✑ Conditions: Include All device state, exclude Device marked as compliant Access controls is set to Block access.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Answer:

Your company uses Windows Defender Advanced Threat Protection (ATP)

HOTSPOT

Your company uses Windows Defender Advanced Threat Protection (ATP).

Windows Defender ATP includes the machine groups shown in the following table.

You onboard a computer named computer1 to Windows Defender ATP as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.

Answer:

Which labels can users apply to content?

You have the sensitivity labels shown in the following exhibit.

Which labels can users apply to content?
A . Label3, Label4, and Label6 only
B . Label1, Label2. Label3. Label4. Label5. and Label6
C . Label1, Label2, and Label5 only
D . Label1, Label3, Label4, and Label6 only

Answer: D

Explanation:

Reference: https://docs.microsoft.com/en-us/microsoft-365/compliance/sensitivity-labels?view=o365-worldwide

What should you use?

Your company has a Microsoft 365 E3 subscription.

All devices run Windows 10 Pro and are joined to Microsoft Azure Active Directory (Azure AD).

You need to change the edition of Windows 10 to Enterprise the next time users sign in to their computer. The solution must minimize downtime for the users.

What should you use?
A . Windows Autopilot
B . Windows Update
C . Subscription Activation
D . an in-place upgrade

Answer: C

Explanation:

https://docs.microsoft.com/en-us/windows/deployment/windows-10-subscription-activation

What should you include in the solution for each device type?

DRAG DROP

Your company has a Microsoft 365 E5 tenant.

Users access resources in the tenant by using both personal and company-owned Android devices. Company policies requires that the devices have a threat level of medium or lower to access Microsoft Exchange Online mailboxes.

You need to recommend a solution to identify the threat level of the devices and to control access of the devices to the resources.

What should you include in the solution for each device type? To answer, drag the appropriate components to the correct devices. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Graphical user interface, application, Word

Description automatically generated

Does this meet the goal?

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a computer that runs Windows 10.

You need to verify which version of Windows 10 is installed.

Solution: At a command prompt, you run the winver.exe command.

Does this meet the goal?
A . Yes
B . No

Answer: A

Explanation:

Reference: https://support.microsoft.com/en-us/windows/which-version-of-windows-operating-system-am-i-running-628bec99-476a-2c13-5296-9dd081cdd808