Microsoft 365 Administrator Expert MS-102 Practice Question

While troubleshooting a suspicious action performed by a user, you open the Activity log in Microsoft Defender for Cloud Apps. The entry shows the Traffic type field set to Proxy and the Session risk set to Medium. You need to understand what the Traffic type value indicates about how the action was collected. What does the Proxy traffic type tell you?

  • The activity was generated from the Microsoft 365 unified audit log that Defender for Cloud Apps ingests by default.

  • The activity was captured in near real time by the Conditional Access App Control proxy during the user session.

  • The activity was discovered from on-premises firewall and proxy logs that were uploaded through Cloud Discovery.

  • The activity was imported asynchronously from the app's audit API several hours after it occurred.

Microsoft 365 Administrator Expert MS-102
Manage security and threats by using Microsoft Defender XDR
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot