Filtering Secure Score by Department

Answer Correct answer: B — Create a tag to categorize users and devices, which then enables filtering of Secure Score recommendations by department in the Microsoft 365 Defender portal.

You have a Microsoft 365 E5 subscription. From the Microsoft 365 Defender portal, you review your company’s Microsoft Secure Score. You discover a large number of recommended actions. You need to ensure that the actions can be filtered based on specific department names. What should you create first?

  1. a dynamic security group
  2. a tag Correct Answer
  3. an administrative unit
  4. a custom detection rule

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests knowledge of Secure Score management features, specifically highlighting that Tags are the mechanism for categorizing and filtering recommendations, whereas Administrative Units are for delegation.

This question addresses how to filter Microsoft Secure Score recommendations by department using Tags. It establishes that creating a Tag is the required first step to enable filtering capabilities in the Defender portal.

Candidates often choose Administrative Units (C) because they associate 'departments' with admin scopes. However, Admin Units do not provide the filtering view needed for Secure Score recommendations.

Community Discussion (6 comments)

examcrammer 👍 12 Selected: B
tested, create a tag on 1 recommendation, refresh the Defender portal, and the tag name shows up for filtering.
roelski 👍 1 Selected: C
Creating a dynamic security group can be useful for automatically managing group memberships based on user attributes, such as department names. However, in the context of filtering recommended actions in Microsoft Secure Score based on specific department names, a dynamic security group might not be the most direct solution. Administrative units are specifically designed to segment your organization into smaller units, making it easier to manage and apply policies based on those segments. This segmentation aligns more closely with the need to filter actions by department. So, while dynamic security groups are powerful for managing memberships dynamically, administrative units are more suitable for your specific requirement of filtering actions in Microsoft Secure Score by department.
APK1 👍 4 Selected: B
Correct answer is B. Tag
Khattak3143 👍 2 Selected: B
Answer: B Tags in Microsoft 365 are used to categorize and filter objects (like users and devices) based on specific attributes. By creating tags for different departments, you can then apply these tags to users and devices. This allows you to filter and view recommendations and actions in the Microsoft Secure Score tailored to these tagged departments.
[Removed] 👍 3 Selected: B
https://security.microsoft.com/securescore The only option for filtering from these answers is TAG
egman18 👍 1 Selected: C
C. an administrative unit The reasoning behind this answer is that an administrative unit in Microsoft 365 allows for the organization of users based on different departments or other criteria, such as geographical location or job function. Once these users are organized into administrative units, various settings and policies, including those related to security, can be applied specifically to these units. In the context of Microsoft Secure Score, being able to filter recommendations based on specific departments will require that these departments are first organized in a way that they can be individually addressed, which is facilitated by creating administrative units. This allows for a more targeted and efficient management of the recommendations based on the particular needs and characteristics of each department.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Creating a Tag (Option B) is the correct first step. In Microsoft 365 Defender, Tags allow administrators to categorize users, devices, and mailboxes based on attributes like department. Once a tag is created and applied to objects, it becomes available as a filter option in the Secure Score recommendations view, enabling targeted remediation.

Why the Other Options Are Wrong

Administrative Units (C) are designed for delegating administrative tasks and permissions, not for filtering views within Secure Score. While they segment users, they do not expose a filtering dimension for score recommendations. Dynamic Security Groups (A) manage membership but do not inherently create a filter category in the Secure Score UI. Custom Detection Rules (D) relate to threat detection logic, not score organization or filtering.

Community Comment Notes

Community consensus strongly supports Option B. As noted by user 'examcrammer', testing this workflow confirms that creating a tag makes it visible for filtering in the portal. User '[Removed]' emphasized that among the given choices, only Tags offer the necessary filtering capability for Secure Score actions.

Official Reference

Exam Strategy

Differentiate between 'Delegation' (Admin Units) and 'View/Filter Management' (Tags). When a question asks about organizing or filtering views rather than assigning permissions, look for Tags or Labels.

Frequently Asked Questions

Why not use Administrative Units to filter Secure Score?

Administrative Units delegate permissions and management scope. They do not provide a filtering interface for viewing or prioritizing Secure Score recommendations.

Do I need to apply the tag manually after creating it?

Yes, you must assign the created tag to specific users or devices before it appears as an available filter option in the Secure Score view.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide