Free MS-101 Exam Braindumps (page: 7)

Page 7 of 104

You have a Microsoft 365 tenant.
You have a line-of-business application named App1 that users access by using the My Apps portal. After some recent security breaches, you implement a conditional access policy for App1 that uses Conditional Access App Control. You need to be alerted by email if impossible travel is detected for a user of App1. The solution must ensure that alerts are generated for App1 only.
What should you do?

  1. From Microsoft Cloud App Security, create a Cloud Discovery anomaly detection policy.
  2. From Microsoft Defender for Cloud Apps, modify the impossible travel alert policy.
  3. From Microsoft Defender for Cloud Apps, create an app discovery policy.
  4. From the Azure Active Directory admin center, modify the conditional access policy.

Answer(s): A


Reference:

https://docs.microsoft.com/en-us/cloud-app-security/cloud-discovery-anomaly-detection-policy



A user receives the following message when attempting to sign in to https://myapps.microsoft.com:
`Your sign-in was blocked. We've detected something unusual about this sign-in. For example, you might be signing in from a new location, device, or app. Before you can continue, we need to verify your identity. Please contact your admin.` Which con guration prevents the users from signing in?

  1. Microsoft Azure Active Directory (Azure AD) Identity Protection policies
  2. Microsoft Azure Active Directory (Azure AD) conditional access policies
  3. Endpoint Manager compliance policies
  4. Security & Compliance data loss prevention (DLP) policies

Answer(s): A


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/overview https://docs.microsoft.com/en- us/mem/intune/protect/device-compliance-get-started



HOTSPOT (Drag and Drop is not supported).
You have the Microsoft Azure Active Directory (Azure AD) users shown in the following table.



Your company uses Microsoft Intune.
Several devices are enrolled in Intune as shown in the following table.



The device compliance policies in Intune are con gured as shown in the following table.



You create a conditional access policy that has the following settings:
The Assignments settings are con gured as follows:
1. Users and groups: Group1
2. Cloud apps: Microsoft O ce 365 Exchange Online
3. Conditions: Include All device state, exclude Device marked as compliant Access controls is set to Block access.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Box 1: Yes.
User1 is in Group1. The Conditional Access Policy applies to Group1. The Conditional Access Policy blocks access unless the device is marked as compliant.
BitLocker is disabled for Device1. Device1 is in Group3 which is assigned device Policy1. The BitLocker policy in Policy1 is not con gured so BitLocker is not required.
Therefore, Device1 is compliant so User1 can access Exchange online from Device1.
Box 2: No.
User1 is in Group1. The Conditional Access Policy applies to Group1. The Conditional Access Policy blocks access unless the device is marked as compliant.
BitLocker is disabled for Device2. Device2 is in Group4 which is assigned device Policy2. The BitLocker policy in Policy2 is Required so BitLocker is required.
Therefore, Device2 is not compliant so User1 cannot access Exchange online from Device2.
Box3: Yes.
User2 is in Group2. The Conditional Access Policy applies to Group1. The Conditional Access Policy does not apply to Group2. So even though Device2 is non- compliant, User2 can access Exchange Online using Device2 because there is no Conditional Access Policy preventing him/her from doing so.


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/conditions



HOTSPOT (Drag and Drop is not supported).
You have several devices enrolled in Microsoft Endpoint Manager.
You have a Microsoft Azure Active Directory (Azure AD) tenant that includes the users shown in the following table.



The device limit restrictions in Endpoint Manager are con gured as shown in the following table.



You add User3 as a device enrollment manager in Endpoint Manager.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/intune/device-enrollment-manager-enroll



Page 7 of 104



Post your Comments and Discuss Microsoft MS-101 exam with other Community members:

Phil commented on December 08, 2022
i have a lot of experience but what comes in the exam is totally different from the practical day to day tasks. so i thought i would rather rely on these brain dumps rather failing the exam.
GERMANY
upvote

Marco commented on June 12, 2023
I paid and downloaded my files. So far everything looks promising.
SPAIN
upvote

Fang commented on June 04, 2023
Same exam dumps as other sites. But the 50% off make is much cheaper. I bought 2 exams to get the 50% discount. I passed one exam now preparing for my second test.
SINGAPORE
upvote

Justina commented on May 30, 2023
If you are serious about acing your exams, I urge you to give these exam dumps a try. They surpassed all my expectations, providing me with everything I needed to prepare and pass my exam. And the 50% sale is a cool deal!
UNITED STATES
upvote

Phil commented on December 08, 2022
I have a lot of experience but what comes in the exam is totally different from the practical day to day tasks. So I thought I would rather rely on these brain dumps rather failing the exam.
GERMANY
upvote