exam questions

Exam MS-102 All Questions

View all questions & answers for the MS-102 exam

Exam MS-102 topic 1 question 90 discussion

Actual exam question from Microsoft's MS-102
Question #: 90
Topic #: 1
[All MS-102 Questions]

HOTSPOT -
You have a Microsoft 365 E5 subscription that contains a user named User1.
Azure AD Password Protection is configured as shown in the following exhibit.

User1 attempts to update their password to the following passwords:

F@lcon -

Project22 -

T4il$pin45dg4 -
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
letters1234
Highly Voted 1 year, 7 months ago
Answers are correct Only T4il$pin45dg4 will be allowed to change, the other two have an exact or within 1 character match to the banned passwords: https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-password-ban-bad#fuzzy-matching-behavior Lockout period is 10 minutes (600 seconds) meaning on the 11th minute, the count starts again from 1 and would need another 15 bad passwords within the next 9 minutes to lock the user out.
upvoted 22 times
Kmkz83510
1 year, 4 months ago
Check here: https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-password-smart-lockout - see note regarding lockout after the first failed login following a lockout period.
upvoted 3 times
mikl
11 months, 1 week ago
If the first sign-in after a lockout period has expired also fails, the account locks out again. If an account locks repeatedly, the lockout duration increases.
upvoted 1 times
...
...
Noble00
1 year, 4 months ago
You are very right.
upvoted 1 times
...
...
vercracked_007
Highly Voted 1 year, 7 months ago
Box 1 - T4il$pin45dg4 Box 2 will be locked out again https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-password-smart-lockout
upvoted 21 times
MR_Eliot
6 months, 4 weeks ago
I second this.
upvoted 1 times
...
EM1234
1 year, 6 months ago
That link you provided explains how you can change the password protection defaults. Which, I believe, is the point of this question. I think provided answers are correct.
upvoted 3 times
...
Kmkz83510
1 year, 4 months ago
Agree. Given answer for Box 2 is incorrect. At the link provided, there is an explanation which says "If the first sign-in after a lockout period has expired also fails, the account locks out again. If an account locks repeatedly, the lockout duration increases."
upvoted 5 times
Kmkz83510
1 year, 3 months ago
Actually, I retract my statement. The given answer is correct because the account would never get locked out in the first place, due to smart lockout. The same password entered 15 times wouldn't trigger it. Box 2 would be wrong if the user entered in enough wrong passwords (not repeating) to get locked out.
upvoted 7 times
...
...
...
ca7859c
Most Recent 1 day, 9 hours ago
Answers correct T4il$pin45dg4 Signs in immediately The account locks again after each subsequent failed sign-in attempt. The lockout period is one minute at first, and longer in subsequent attempts. To minimize the ways an attacker could work around this behavior, we don't disclose the rate at which the lockout period increases after unsuccessful sign-in attempts. https://learn.microsoft.com/en-us/entra/identity/authentication/howto-password-smart-lockout#testing-smart-lockout
upvoted 1 times
...
h3h3h3
2 weeks, 3 days ago
If the first sign-in after a lockout period has expired also fails, the account locks out again. If an account locks repeatedly, the lockout duration increases.
upvoted 1 times
...
GingaNinja
6 months, 4 weeks ago
I think people are missing the point. 15 bad password attempts does not go over the threshold. Lockout happens on 16th try
upvoted 1 times
...
jarattdavis
8 months ago
Box 1 - T4il$pin45dg4 Box 2 - Can attempt to sign in again immediately. Explanation for Box2: After 15times user will be locked out. If user wait more than 600 seconds, he will be allowed to try again. Now the user has waited 60sec x 11 = 660. That means the user will be allowed to try again immediately
upvoted 1 times
...
mikl
11 months, 1 week ago
Box 1 - T4il$pin45dg4 Box 2 will be locked out again The reason why the F@lcon does not work is documented here : https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-configure-custom-password-protection#configure-custom-banned-passwords Regarding why its locked out again is found here : https://learn.microsoft.com/en-us/entra/identity/authentication/howto-password-smart-lockout
upvoted 3 times
...
GeorgeMar
1 year ago
Smart lockout tracks the last three bad password hashes to avoid incrementing the lockout counter for the same password. If someone enters the same bad password multiple times, this behavior doesn't cause the account to lock out.
upvoted 5 times
...
Vukosir
1 year, 1 month ago
All 3 passwords must be allowed , Password is different to Password22 and Falcon as well as F@lcon are not the same thing.
upvoted 1 times
mikl
11 months, 1 week ago
Wrong. Read here : https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-configure-custom-password-protection#configure-custom-banned-passwords
upvoted 1 times
...
...
TP447
1 year, 5 months ago
Key here is "Same wrong password" - entering the same wrong password 15 times would only be seen as 1 threshold on the counter so wouldnt trigger a lockout. Therefore the user could just attempt to sign in again. Seems like a poorly worded question or a trick..
upvoted 6 times
mikl
11 months, 1 week ago
If the first sign-in after a lockout period has expired also fails, the account locks out again. If an account locks repeatedly, the lockout duration increases.
upvoted 1 times
...
...
ExamCheater1993
1 year, 6 months ago
Picture is correct. The trap is, that this persons enters the SAME password multiple times. This doesn't count to the lockout policy because of smart lock out . https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-password-smart-lockout
upvoted 8 times
TP447
1 year, 5 months ago
Totally agree here.
upvoted 1 times
...
SandyBridge
1 year, 6 months ago
"Smart lockout tracks the last three bad password hashes to avoid incrementing the lockout counter for the same password. If someone enters the same bad password multiple times, this behavior doesn't cause the account to lock out." From source: https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-password-smart-lockout
upvoted 2 times
TP447
1 year, 5 months ago
Totally agree here.
upvoted 2 times
...
...
...
amurp35
1 year, 6 months ago
Box 1 - T4il$pin45dg4 -Each banned password that's found in a user's password is given one point. -Each remaining character that is not part of a banned password is given one point. -A password must be at least five (5) points to be accepted. Box 2 is incorrect The account locks again after each subsequent failed sign-in attempt, for one minute at first and longer in subsequent attempts.
upvoted 2 times
...
gomezmax
1 year, 7 months ago
1 Box Correct T4il$pin45dg4 The 2nd Box is incorrect it should be lockout
upvoted 2 times
mikl
11 months, 1 week ago
Agree my friend!
upvoted 1 times
...
...
nsotis28
1 year, 7 months ago
Box 1 - only T4il$pin45dg4 Box 2 - will be locked
upvoted 2 times
...
hogehogehoge
1 year, 7 months ago
Box1:Only F@lcon and T4il$pin45dg4. Because "a" is replaced "@", and match this policy.
upvoted 2 times
Romke_en_Tomke
1 year, 7 months ago
You made me look it up. You are wrong, box 1 is correct. An "a" as @ is considered as a common character substitution. https://learn.microsoft.com/en-us/azure/active-directory/authentication/tutorial-configure-custom-password-protection#configure-custom-banned-passwords
upvoted 4 times
mikl
11 months, 1 week ago
Thank you for clarifying this :)
upvoted 1 times
...
...
...
Vaati
1 year, 8 months ago
If you fail again after a lockout periode, you are locked again no?
upvoted 2 times
spectre786
1 year, 7 months ago
exactly
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago