Microsoft 365 Administrator Expert MS-102 Practice Question

You have a Microsoft 365 E5 subscription with Microsoft Defender for Office 365 Plan 2 enabled. A security requirement states:

  • When users select Report message or Report phishing in Outlook, the message must automatically trigger an investigation.
  • If the investigation verdict is Malicious, the message must be purged from all mailboxes automatically without requiring analyst approval.

You confirm that user submissions are already enabled.

Which action should you perform next to meet the requirement?

  • Create a Quarantine policy that allows end users to release only non-malicious messages.

  • Edit the Automated investigation and response (AIR) settings and configure the remediation action policy to Automatically remediate detected threats.

  • Create a custom Alert policy that triggers when a user submits a phishing report and sets the action to purge the message.

  • Assign the Strict preset security policy and turn on Zero-hour auto purge (ZAP).

Microsoft 365 Administrator Expert MS-102
Manage security and threats by using Microsoft Defender XDR
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot