nerdexam
Microsoft

MS-102 · Question #381

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. You are reviewing the activity log of the subscription. You need to ensure that events originating from the…

The correct answer is D. a named location. In Microsoft Defender for Cloud Apps, a "named location" is used to define trusted or untrusted IP address ranges. This can be applied to categorize activity originating from specific networks, such as your on-premises network, as "Administrative" based on IP address. By…

Submitted by layla.eg· Apr 18, 2026Implement and manage Microsoft Entra identity and access

Question

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Cloud Apps. You are reviewing the activity log of the subscription. You need to ensure that events originating from the on-premises network are categorized automatically as Administrative. What should you create?

Options

  • Aa critical asset classification
  • Ban indicator for IP addresses
  • Can IP address range
  • Da named location

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    10% (3)
  • C
    3% (1)
  • D
    84% (26)

Explanation

In Microsoft Defender for Cloud Apps, a "named location" is used to define trusted or untrusted IP address ranges. This can be applied to categorize activity originating from specific networks, such as your on-premises network, as "Administrative" based on IP address. By defining a named location for your on-premises network, you can automatically classify activities originating from

Topics

#Named Locations#Defender for Cloud Apps#Microsoft Entra#Event Categorization

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice