exam questions

Exam MS-102 All Questions

View all questions & answers for the MS-102 exam

Exam MS-102 topic 1 question 76 discussion

Actual exam question from Microsoft's MS-102
Question #: 76
Topic #: 1
[All MS-102 Questions]

You have an Azure AD tenant and a Microsoft 365 E5 subscription. The tenant contains the users shown in the following table.

You plan to implement Microsoft Defender for Endpoint.
You verify that role-based access control (RBAC) is turned on in Microsoft Defender for Endpoint.
You need to identify which user can view security incidents from the Microsoft 365 Defender portal.
Which user should you identify?

  • A. User1
  • B. User2
  • C. User3
  • D. User4
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AMDf
Highly Voted 1 year, 3 months ago
Selected Answer: A
A is correct Answer is correct "A". Security Administrator will not loose access after RBAC is enabled. Security Reader will so definitely not C. Initially, only those with Azure AD Global Administrator or Security Administrator rights will be able to create and assign roles in Microsoft Defender Security Center, therefore, having the right groups ready in Azure AD is important. Turning on role-based access control will cause users with read-only permissions (for example, users assigned to Azure AD Security reader role) to lose access until they are assigned to a role. https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/rbac?view=o365-worldwide
upvoted 21 times
...
amurp35
Highly Voted 1 year, 2 months ago
Selected Answer: A
"Turning on role-based access control will cause users with read-only permissions (for example, users assigned to Azure AD Security reader role) to lose access until they are assigned to a role." https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/rbac?view=o365-worldwide
upvoted 6 times
...
jedboy88
Most Recent 4 days, 1 hour ago
Selected Answer: C
Copilot: C. User3 (Security Reader), as this role is specifically designed for viewing security incidents https://learn.microsoft.com/en-us/defender-endpoint/manage-incidents
upvoted 1 times
...
Kock
3 weeks, 1 day ago
Políticas anti-phishing no Microsoft 365 https://learn.microsoft.com/en-us/defender-office-365/anti-phishing-policies-about
upvoted 1 times
...
AleFCI1908
2 months ago
Selected Answer: C
"When you first sign in to the Microsoft Defender portal, you're granted either full access or read only access. Full access rights are granted to users with the Security Administrator role in Microsoft Entra ID. Read only access is granted to users with a Security Reader role in Microsoft Entra ID."
upvoted 2 times
...
Tr619899
2 months, 1 week ago
The statement "You verify that role-based access control (RBAC) is turned on in Microsoft Defender for Endpoint" means that "role-based permissions" are being enforced within the Microsoft Defender for Endpoint environment. When RBAC is enabled, access to security data (such as incidents, alerts, or reports) is controlled based on the user’s assigned role in Azure AD. Each role has specific permissions regarding what they can view or manage. In the context of the question: - "Security Reader (User3)" is a role that grants "view-only access" to security information, including security incidents and alerts. With RBAC enabled, this role can view security incidents but cannot make changes to them, making "User3" the correct answer. Thus, turning on RBAC ensures that "only those with the proper permissions (e.g., Security Reader)" can view the security incidents in Microsoft 365 Defender. This is why "Option C (User3)" is correct.
upvoted 2 times
...
MR_Eliot
2 months, 3 weeks ago
Selected Answer: A
Initially, only those with Microsoft Entra Global Administrator or Security Administrator rights can create and assign roles in the Microsoft Defender portal; therefore, having the right groups ready in Microsoft Entra ID is important. Turning on role-based access control causes users with read-only permissions (for example, users assigned to Microsoft Entra Security reader role) to lose access until they are assigned to a role. Users with administrator permissions are automatically assigned the default built-in Defender for Endpoint Global Administrator role with full permissions. After opting in to use RBAC, you can assign additional users who aren't Microsoft Entra Global Administrators or Security Administrators to the Defender for Endpoint Global Administrator role. After opting in to use RBAC, you cannot revert to the initial roles as when you first logged into the portal.
upvoted 1 times
...
Jillis
1 year, 3 months ago
Selected Answer: A
AMDf is correct
upvoted 3 times
...
letters1234
1 year, 3 months ago
Selected Answer: C
Security reader Security readers can perform the following tasks: - View a list of onboarded devices - View security policies - View alerts and detected threats - View security information and reports Security readers can't add or edit security policies, nor can they onboard devices.
upvoted 4 times
...
mccheesey
1 year, 3 months ago
Selected Answer: C
This should be C I think... https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/scc-permissions?view=o365-worldwide "Security Reader - Members have read-only access to many security features of Identity Protection Center, Privileged Identity Management, Monitor Microsoft 365 Service Health, and the Defender and compliance portals. " I see nothing in this statement or anywhere around the Security Reader role in this article indicating they wouldn't be able to view incidents within that portal.
upvoted 5 times
...
Greatone1
1 year, 3 months ago
https://www.examtopics.com/discussions/microsoft/view/49358-exam-ms-101-topic-2-question-27-discussion/
upvoted 3 times
...
Greatone1
1 year, 3 months ago
Selected Answer: A
A is correct https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/rbac?view=o365-worldwide
upvoted 4 times
...
Casticod
1 year, 3 months ago
Selected Answer: C
Only view security incident... Security reader. https://learn.microsoft.com/en-us/microsoft-365/security/defender-business/mdb-roles-permissions?view=o365-worldwide&tabs=M365Admin
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago