Question 146

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some questions sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 subscription that contains the users shown in the following table.

You discover that all the users in the subscription can access Compliance Manager reports.
The Compliance Manager Reader role is not assigned to any users.
You need to recommend a solution to prevent a user named User5 from accessing the Compliance Manager reports.
Solution: You recommend removing User1 from the Compliance Manager Contributor role.
Does that meet the goal?
  • Question 147

    Note: Thisquestion is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some questions sets might have more than one correct solution, while others might not have acorrect solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You have a Microsoft 365 subscription.
    You have a user named User1. Severalusers have full access to the mailbox of User1.
    Some email messages sent to User1 appear to have been read and deleted before the user viewed them.
    When you search the audit log in Security & Compliance to identify who signed in to the mailbox of User1,the results are blank.
    You need to ensure that you can view future sign-ins to the mailbox of User1.
    You run the Set-AdminAuditLogConfig -AdminAuditLogEnabled $true
    -AdminAuditLogCmdlets *Mailbox* command.
    Does that meet the goal?
  • Question 148

    You plan to configure an access review to meet the security requirements for the workload administrators. You create an access review policy and specify the scope and a group.
    Which other settings should you configure? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 149

    You have a Microsoft 365 subscription that contains several Windows 10 devices. The devices are managed by using Microsoft Intune.
    You need to enable Windows Defender Exploit Guard (Windows Defender EG) on the devices.
    Which type of device configuration profile should you use?
  • Question 150

    You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table.

    You create and enforce an Azure AD Identity Protection user risk policy that has the following settings:
    Assignments: Include Group1, Exclude Group2
    Conditions: Sign in risk of Low and above
    Access: Allow access, Require password change
    You need to identify how the policy affectsUser1 and User2.
    What occurs when User1 and User2 sign in from an unfamiliar location? To answer, select the appropriate options in the answer area.
    NOTE:Each correct selection is worth one point.