Courseiva

CCNA Deploy Manage M365 Tenant Questions

75 of 196 questions · Page 2/3 · Deploy Manage M365 Tenant topic · Answers revealed

76
MCQmedium

You have a Microsoft 365 E5 tenant. Users report that they cannot access the Microsoft 365 admin center (https://admin.microsoft.com). You verify that they have the Global Administrator role assigned. You check the sign-in logs in Microsoft Entra ID and see that the sign-in was blocked by a Conditional Access policy. The policy requires MFA and a compliant device. The users are using personal devices that are not enrolled. What should you do to allow access while maintaining security?

A.Disable the Conditional Access policy.
B.Ask users to enroll their personal devices in Microsoft Intune.
C.Remove the Global Administrator role from the users and assign a lower privilege role.
D.Modify the Conditional Access policy to exclude the Microsoft 365 admin center from the device compliance requirement, but keep MFA.
AnswerD

Modifying the Conditional Access policy to exclude the Microsoft 365 admin center from the device compliance requirement, while keeping MFA, is a least-privilege approach. This allows administrators to sign in to the admin center from any device using MFA as a compensating control, but still enforces device compliance for all other cloud apps. This balances security and usability by scoping the exception only to the app that is causing the issue.

Why this answer

It allows users to access the Microsoft 365 admin center by removing the device compliance requirement for that specific cloud app while still enforcing MFA. This maintains security through MFA and avoids blocking access for users on personal, unenrolled devices. Disabling the policy entirely or requiring enrollment would either weaken security or be impractical for personal devices.

Exam trap

The trap here is that candidates may think removing the Global Administrator role (Option C) will bypass the Conditional Access policy, but Conditional Access policies apply to all users regardless of role unless explicitly excluded, and the policy's grant controls are evaluated before role-based access is considered.

How to eliminate wrong answers

Option A is wrong because disabling the Conditional Access policy entirely would remove all security controls (MFA and device compliance) for the admin center, exposing the tenant to unauthorized access. Option B is wrong because asking users to enroll personal devices in Intune may not be feasible or desired for personal devices, and it does not address the immediate access issue without policy modification. Option C is wrong because removing the Global Administrator role does not resolve the Conditional Access block; the policy applies to all users regardless of role, and the users need admin privileges to perform their duties.

77
MCQeasy

You are a Microsoft 365 administrator for a small business with 50 users. The company uses Microsoft 365 Business Premium. You need to ensure that all users have multi-factor authentication (MFA) enabled. The company does not have any custom conditional access policies. You want to implement MFA as quickly as possible with minimal configuration. What should you do?

A.Enable security defaults in the Microsoft Entra admin center.
B.Configure MFA registration campaign for all users.
C.Enable per-user MFA for each user.
D.Create a conditional access policy that requires MFA for all users.
AnswerA

Security defaults in the Microsoft Entra admin center enforces MFA for every user, blocks legacy authentication, and requires users to complete MFA registration on first sign-in — all with a single toggle and no conditional access policy creation. For a small business without granular exclusion requirements, this is the fastest and most minimal-configuration path to satisfy the scenario. Microsoft recommends security defaults for tenants that do not have Microsoft Entra ID P1/P2 licenses, and even with Business Premium it provides immediate baseline protection without policy dependencies.

Why this answer

Security defaults provide a pre-configured set of security policies, including requiring MFA for all users, that can be enabled with a single toggle in the Microsoft Entra admin center. This is the fastest and simplest method for a small business with no existing conditional access policies, as it requires minimal configuration and immediately enforces MFA for every user.

Exam trap

The trap here is that candidates often confuse the MFA registration campaign (which only prompts registration) with actual MFA enforcement, or they overcomplicate the solution by choosing per-user MFA or a custom conditional access policy when security defaults are the fastest and simplest answer for a tenant with no existing policies.

How to eliminate wrong answers

Option B is wrong because the MFA registration campaign is a feature that nudges users to register for MFA but does not enforce MFA at sign-in; it only prompts registration, leaving authentication unprotected until users voluntarily comply. Option C is wrong because per-user MFA is a legacy method that requires manually enabling MFA for each of the 50 users individually, which is time-consuming and does not leverage the modern, policy-based approach of security defaults. Option D is wrong because creating a conditional access policy requires additional configuration steps (e.g., excluding break-glass accounts, defining conditions) and is not the fastest option; security defaults are designed for organizations without existing policies to achieve MFA enforcement instantly.

78
MCQmedium

You are the Microsoft 365 administrator for a company that has a Microsoft 365 E5 tenant. The security team requires that all administrative actions performed in the Microsoft 365 admin center and Microsoft Entra admin center be retained for seven years. You need to configure the appropriate audit log retention. What should you do?

A.Enable a Microsoft Entra diagnostic setting to export audit logs to an Azure Log Analytics workspace with a seven-year retention period.
B.Assign Microsoft 365 E5 Compliance licenses to all administrators and rely on the default retention.
C.In the Microsoft Purview compliance portal, create an audit retention policy that applies to the admin activities and set the retention period to seven years.
D.In the Microsoft 365 admin center, change the default audit log retention period to seven years.
AnswerC

Audit retention policies in Microsoft Purview allow you to retain specific audit records for a custom duration, up to 10 years, independent of the default tenant retention. Applying the policy to admin activities ensures those events are kept for seven years, meeting the security team's requirement without affecting other workloads.

Why this answer

To retain audit records for longer than the default period, you must create an audit retention policy in Microsoft Purview. This policy can target specific activities, such as admin actions, and set a custom retention duration up to 10 years. Changing default settings or relying on licenses alone does not extend retention.

Exam trap

The trap here is assuming that Microsoft 365 E5 licensing automatically provides extended audit retention or that a simple toggle in the admin center can change it.

79
MCQmedium

Your organization uses Microsoft 365 E5 licenses for all users. You need to configure role-based access control (RBAC) so that helpdesk staff can reset passwords and manage licenses, but cannot modify user principal names (UPNs) or delete users. Which role assignment should you use?

A.License Administrator
B.Helpdesk Administrator
C.Password Administrator
D.User Administrator
AnswerB

Helpdesk Administrator is the correct choice because Microsoft Entra ID grants this role the combined abilities to reset passwords for non-administrator users and to manage license assignments by including the License Administrator permission as part of its delegated scope. Critically, it explicitly excludes the more privileged User Administrator capabilities such as deleting users or modifying user principal names (UPNs), which aligns exactly with the stated restrictions. This makes Helpdesk Administrator the least-privileged built-in role that satisfies both required tasks without permitting the prohibited actions.

Why this answer

The Helpdesk Administrator role is correct because it grants the specific permissions needed to reset passwords and manage licenses, while explicitly preventing modifications to user principal names (UPNs) and user deletions. This role is designed for tier-1 support staff who require these capabilities without elevated user management rights.

Exam trap

The trap here is that candidates often confuse the Helpdesk Administrator role with the User Administrator role, assuming the latter is required for license management, but User Administrator includes dangerous permissions like UPN modification and user deletion that are explicitly prohibited in the question.

How to eliminate wrong answers

Option A is wrong because the License Administrator role can only manage license assignments and cannot reset passwords, failing the password reset requirement. Option C is wrong because the Password Administrator role can only reset passwords and cannot manage licenses, failing the license management requirement. Option D is wrong because the User Administrator role can modify UPNs and delete users, which violates the restriction against those actions.

80
MCQeasy

A user reports they cannot access Microsoft Teams. They see a message: 'Your account is not enabled for Teams.' You verify the user has a valid Microsoft 365 E3 license assigned. What is the most likely cause?

A.The user does not have the correct Microsoft Entra ID role.
B.The user is not assigned a valid license.
C.The Teams service plan is disabled in the user's license.
D.The user is not a global administrator.
AnswerC

Microsoft 365 license assignments include per-service-plan toggles, and when the Teams service plan is disabled for a user, Teams will not launch even though the user still appears as licensed. The user can have a fully valid E3 license with Exchange Online, SharePoint Online, and other plans active, but if the Teams plan is unchecked, the Teams client cannot authenticate or access the service. Enabling the Teams service plan on the user's license assignment is the required corrective action.

Why this answer

The error 'Your account is not enabled for Teams' indicates that the Teams service plan is disabled within the user's assigned Microsoft 365 E3 license. Even with a valid license, each service plan (e.g., Teams, Exchange Online, SharePoint) can be individually toggled on or off via the Microsoft 365 admin center or PowerShell. Since the user has a valid license but cannot access Teams, the most likely cause is that the Teams service plan has been explicitly disabled.

Exam trap

The trap here is that candidates often assume a valid license automatically enables all included services, but Microsoft 365 allows granular control over service plans, so a license assignment does not guarantee Teams is enabled.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID roles (e.g., Global Administrator, Teams Administrator) control administrative permissions, not the ability to use Teams as an end user; a user without any admin role can still access Teams if the service plan is enabled. Option B is wrong because the scenario explicitly states the user has a valid Microsoft 365 E3 license assigned, so the issue is not a missing license. Option D is wrong because being a Global Administrator is not required to use Teams; the error message is about service enablement, not administrative privileges.

81
MCQmedium

Your organization recently deployed Microsoft Defender for Office 365. Users report that some legitimate external emails are being quarantined as phishing attempts. You need to reduce false positives without compromising security. What should you do?

A.Increase the Spam Confidence Level (SCL) threshold to 9
B.Disable the anti-phishing policy and use a custom mail flow rule
C.Add the sender domains to the allowed senders list in the anti-phishing policy
D.Change the spam filtering action to 'Move message to Junk Email folder' instead of quarantine
AnswerC

The correct approach is to add the legitimate sender domains to the allowed senders list within the anti-phishing policy in Microsoft Defender for Office 365. Doing so instructs the impersonation detection engine to trust those specific domains, thereby preventing legitimate messages from being flagged as impersonation attempts while still applying malware scanning, spam filtering, and spoof intelligence to those messages. This is a targeted exception that does not weaken global security, making it the recommended and effective way to reduce phishing false positives for trusted domains.

Why this answer

Adding the sender domains to the allowed senders list in the anti-phishing policy explicitly whitelists those domains for phishing checks, reducing false positives while still scanning for other threats. This approach preserves security by not lowering the overall spam filtering threshold or disabling protections, and it targets only the specific domains that are being incorrectly flagged.

Exam trap

The trap here is that candidates often confuse the anti-phishing policy's allowed senders list with the tenant-level allowed/blocked list in the anti-spam policy, or they mistakenly think changing the action to junk email reduces false positives when it only changes the delivery outcome, not the detection logic.

How to eliminate wrong answers

Option A is wrong because increasing the SCL threshold to 9 would make the filter less sensitive, allowing more spam and phishing to reach users, which compromises security. Option B is wrong because disabling the anti-phishing policy removes critical protection against sophisticated phishing attacks, and a custom mail flow rule cannot replicate the advanced heuristics and impersonation detection of the built-in policy. Option D is wrong because changing the action to 'Move message to Junk Email folder' instead of quarantine still applies the same false-positive classification; it only changes the delivery location, not the underlying detection logic, so legitimate emails would still be incorrectly categorized.

82
Drag & Dropmedium

Drag and drop the steps to deploy Microsoft Defender for Office 365 policies in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Defender for Office 365 policies are created in the Defender portal, configured with threat protection settings, and applied to recipients.

83
Multi-Selecthard

Your organization uses Microsoft Sentinel for security operations. You need to ensure that Sentinel can ingest logs from Microsoft 365 Defender (XDR) and Microsoft Entra ID. Which THREE data connectors should you enable? (Choose three.)

Select 3 answers
A.Microsoft Defender for Endpoint
B.Microsoft Purview Information Protection
C.Microsoft Entra ID (formerly Azure AD)
D.Microsoft Intune
E.Microsoft Defender for Office 365 (formerly Office 365 ATP)
AnswersA, C, E

The Microsoft Defender for Endpoint connector is a built-in Sentinel data source that directly ingests endpoint detection and response telemetry, including tables such as DeviceLogonEvents, DeviceProcessEvents, and DeviceNetworkEvents. These raw Advanced Hunting events enable detections for malware, lateral movement, and other endpoint attacks. Without this connector, endpoint visibility would rely on manual log forwarding or third-party agents.

Why this answer

Microsoft Defender for Endpoint is a correct data connector because it ingests endpoint detection and response (EDR) logs from Windows, macOS, and Linux devices into Microsoft Sentinel. This integration allows security operations to correlate endpoint alerts with other signals, enabling advanced hunting and automated incident response across the Microsoft 365 Defender ecosystem.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Information Protection or Intune as security log sources, when in fact they are governance and management tools without native data connectors for Sentinel's security log ingestion.

84
MCQmedium

Your organization is deploying Microsoft 365 and needs to ensure that all new users are automatically assigned a Microsoft 365 Business Basic license. You want to use a group-based licensing strategy with an Azure AD security group. What should you do first?

A.Configure directory synchronization and create the group in on-premises Active Directory.
B.Create a dynamic Azure AD group with a rule for user attributes and enable self-service group management.
C.Assign the license directly to each user via the Microsoft 365 admin center.
D.Create a new Azure AD security group and assign the license to the group.
AnswerD

Creating a new Azure AD security group and assigning the license to that group is the definitive group-based licensing model. Once the license is assigned to the group, all current members immediately receive it, and any users added later are automatically provisioned without an admin step. Because group membership controls the license assignment, this method scales efficiently and provides a clean audit trail, which is exactly why Microsoft recommends it for bulk user licensing.

Why this answer

Group-based licensing in Azure AD requires you to first create a security group (which can be cloud-only or synced) and then assign the Microsoft 365 Business Basic license directly to that group. Once the license is assigned to the group, all members automatically receive the license, including new users added to the group. This approach centralizes license management and ensures automatic assignment without manual intervention.

Exam trap

The trap here is that candidates often think they must first configure directory synchronization (Option A) or create a dynamic group (Option B) before assigning a license to a group, but the correct first step is simply to create a security group and assign the license to it, as group-based licensing works with any Azure AD security group, including cloud-only static groups.

How to eliminate wrong answers

Option A is wrong because directory synchronization and creating the group in on-premises Active Directory is not the first step; you can use a cloud-only Azure AD security group without requiring on-premises sync, and the question does not specify a hybrid environment. Option B is wrong because creating a dynamic group with a user attribute rule and enabling self-service group management is not the first step; while dynamic groups can be used for licensing, the initial requirement is to create a security group and assign the license to it, not to configure dynamic membership or self-service. Option C is wrong because assigning licenses directly to each user via the Microsoft 365 admin center is a manual, per-user approach that contradicts the group-based licensing strategy specified in the question.

85
MCQeasy

A newly hired administrator needs to manage user accounts, licenses, and reset passwords. Which portal should they access?

A.Microsoft 365 admin center
B.Microsoft Entra admin center
C.Microsoft 365 Defender
D.Azure Active Directory admin center
AnswerA

The Microsoft 365 admin center is the designated operational hub for managing Microsoft 365 user accounts, including creating new users, resetting passwords, adding users from a CSV, and assigning or revoking Microsoft 365 subscription licenses. It provides a service-aware view of all M365 workloads and is the primary portal for common administrative tasks like user lifecycle management and billing. While identity data resides in Microsoft Entra ID, the M365 admin center is the intended interface for day-to-day account administration.

Why this answer

The Microsoft 365 admin center (admin.microsoft.com) is the primary portal for day-to-day user administration tasks such as creating and managing user accounts, assigning licenses, and resetting passwords. It provides a unified interface for these common identity and license management operations within a Microsoft 365 tenant.

Exam trap

The trap here is that candidates often confuse the Microsoft Entra admin center (formerly Azure AD) with the Microsoft 365 admin center, thinking that all user management must be done in the identity portal, but the exam tests that routine user tasks like license assignment and password resets are performed in the Microsoft 365 admin center.

How to eliminate wrong answers

Option B (Microsoft Entra admin center) is wrong because it is focused on identity and access management (IAM) configuration, including conditional access policies, enterprise apps, and security defaults, not on routine user license assignment or password resets for end users. Option C (Microsoft 365 Defender) is wrong because it is a security operations portal for threat detection, investigation, and response (e.g., incident management, advanced hunting), not for user account or license management. Option D (Azure Active Directory admin center) is wrong because it is the legacy portal for Azure AD directory-level settings and bulk operations; while it can manage users, the Microsoft 365 admin center is the correct modern portal for license and password management in a Microsoft 365 context, and the Azure AD portal is now rebranded as Microsoft Entra admin center.

86
Multi-Selecthard

Your company is deploying Microsoft 365 Copilot for all users. You need to ensure that Copilot responses are grounded only in organizational data that users already have permission to access. Additionally, you must comply with data residency requirements in the European Union. Which THREE actions should you take?

Select 3 answers
A.Apply sensitivity labels to restrict Copilot from accessing specific files.
B.Set the data residency preference for Microsoft 365 Copilot to the European Union in the admin center.
C.Configure Microsoft 365 Copilot to respect existing user permissions via Microsoft Entra ID.
D.Block Copilot for all users outside the EU using conditional access policies.
E.Enable Copilot caching in Microsoft Purview to control data storage locations.
AnswersA, B, C

Sensitivity labels in Microsoft Purview can be configured with encryption or permissions settings that explicitly exclude the Copilot service principal, preventing Copilot from retrieving labeled content. For example, applying a label with 'Do Not Forward' or custom conditional access grants ensures Copilot only returns data when the user has the corresponding decryption rights. This provides granular control at the file level, allowing specific documents or emails to be hidden from Copilot-generated responses while other content remains accessible.

Why this answer

Sensitivity labels can be configured to block Copilot from accessing files with specific labels, ensuring that Copilot responses are grounded only in organizational data that users already have permission to access. This is done by using Microsoft Purview Information Protection to define label-based restrictions that Copilot respects, preventing it from surfacing content from labeled files even if the user has direct access.

Exam trap

The trap here is that candidates may confuse conditional access policies (which control access) with data residency controls (which control data storage and processing location), and may incorrectly think caching in Purview is a real feature for data residency, when in fact Microsoft 365 Copilot does not use Purview caching for this purpose.

87
MCQeasy

An organization wants to receive email notifications for all service health incidents. Which role must an administrator have to configure service health notifications in the Microsoft 365 admin center?

A.Global Administrator
B.Service Support Administrator
C.Helpdesk Administrator
D.Billing Administrator
AnswerA

Global Administrator holds the highest-level role in Microsoft 365 and inherits every permission, including the ability to view the Service Health dashboard and configure email notifications for service health incidents. Under 'Service Health' in the Microsoft 365 admin center, a Global Administrator can select 'Edit preferences' to subscribe to incident email alerts for all services. No other role has the necessary write permission to change those notification preferences, so only this role fully satisfies the requirement.

Why this answer

Only the Global Administrator role has the necessary permissions to access and modify the Service Health section in the Microsoft 365 admin center, including configuring email notifications for service health incidents. This is because the Global Administrator role is the highest privileged role and is required to manage tenant-wide settings such as service health alerts, which are not delegated to lower-level administrative roles.

Exam trap

The trap here is that candidates often assume the Service Support Administrator role, which can view service health, can also configure notifications, but Microsoft deliberately restricts write access to the Global Administrator role to prevent unauthorized changes to critical alerting infrastructure.

How to eliminate wrong answers

Option B (Service Support Administrator) is wrong because this role can only view service health and manage support tickets, but cannot configure notification settings for service health incidents. Option C (Helpdesk Administrator) is wrong because this role is limited to password resets, user management, and basic support tasks, and does not have permission to access or modify service health notification configurations. Option D (Billing Administrator) is wrong because this role is restricted to managing billing accounts, invoices, and payment methods, and has no access to service health or notification settings.

88
Multi-Selectmedium

Your organization uses Microsoft 365 and wants to implement a passwordless authentication strategy. Which THREE methods are supported natively in Microsoft Entra ID for passwordless sign-in?

Select 3 answers
A.Smart cards (physical or virtual)
B.Microsoft Authenticator app (phone sign-in)
C.Temporary Access Pass
D.Certificate-based authentication
E.FIDO2 security keys
AnswersB, C, E

Microsoft Entra ID supports phone sign-in through the Microsoft Authenticator app as a native passwordless method, binding credentials to the device. Users approve a number match rather than entering a password, satisfying the passwordless sign-in requirement.

Why this answer

Microsoft Entra ID natively supports three passwordless authentication methods: Windows Hello, FIDO2 security keys, and the Microsoft Authenticator app (phone sign-in), so option B is correct because Authenticator phone sign-in lets users sign in by approving a notification with a biometric or PIN instead of a password. Option C is correct because Temporary Access Pass is a native passwordless method that issues a time-limited passcode used to register other passwordless methods or recover access. Option E is correct because FIDO2 security keys are native passwordless credentials that use WebAuthn for phishing-resistant sign-in.

Options A and D are not correct because smart cards and certificate-based authentication, while supported for authentication in Entra ID, are not classified as native passwordless sign-in methods in the passwordless authentication strategy.

Exam trap

A common trap is thinking that Temporary Access Pass is not a native passwordless method because it is often used for recovery, but it is indeed a supported native method in Entra ID. Candidates may also overlook it because it is limited in duration, but it is still considered passwordless.

89
Multi-Selecthard

You are the Microsoft 365 administrator for a company that uses Microsoft 365 E5. The company has a Microsoft Entra tenant with hybrid identity synchronized from on-premises Active Directory using Microsoft Entra Connect. You need to implement self-service password reset (SSPR) so that users can reset their passwords from the Azure portal. The solution must ensure that password changes are written back to on-premises Active Directory. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Configure the on-premises Active Directory domain to use fine-grained password policies.
B.Enable password hash synchronization and seamless single sign-on.
C.Enable self-service password reset for all users in the Microsoft Entra admin center.
D.Configure Microsoft Entra Connect to use password hash synchronization.
E.Enable password writeback in Microsoft Entra Connect.
AnswersC, E

To allow users to reset their passwords, SSPR must be enabled and scoped to the appropriate users. Enabling SSPR in the Microsoft Entra admin center is a necessary step. Without it, users cannot initiate a password reset from the Azure portal. This action, combined with password writeback, meets the requirement.

Why this answer

Enabling SSPR in Microsoft Entra ID allows users to reset their passwords, and enabling password writeback in Microsoft Entra Connect ensures those new passwords are synchronized back to on-premises Active Directory. Together, these actions provide a seamless self-service password reset experience that keeps on-premises and cloud passwords in sync.

Exam trap

The trap here is assuming that password hash synchronization or seamless SSO enables writeback, when in fact writeback is a separate feature that must be explicitly enabled.

90
MCQmedium

A company has a Microsoft 365 tenant with domain contoso.com. They own an additional domain fabrikam.com and have already added and verified it with a TXT record. Now they need to configure email to be routed to Exchange Online for fabrikam.com. Which DNS record must they create?

A.MX record pointing to contoso-com.mail.protection.outlook.com
B.CNAME record for autodiscover
C.TXT record for SPF
D.SRV record for SIP
AnswerA

Creating an MX record for fabrikam.com that points to `contoso-com.mail.protection.outlook.com` correctly configures email routing to Exchange Online. The MX record is the fundamental DNS mechanism that directs sending mail servers to the correct destination for a domain's email. For Microsoft 365, all verified domains within a single tenant share the same Exchange Online mail routing infrastructure. The `contoso-com` prefix identifies the specific Microsoft 365 tenant's mail protection service, ensuring that email for fabrikam.com is routed to the correct Exchange Online instance.

Why this answer

To route email for fabrikam.com to Exchange Online, you must create an MX record that points to the Exchange Online mail exchanger. The correct target is contoso-com.mail.protection.outlook.com, where 'contoso-com' is the hashed version of the primary domain (contoso.com) used by Microsoft 365. This MX record tells the internet's mail servers to deliver messages addressed to @fabrikam.com into the tenant's Exchange Online environment.

Exam trap

The trap here is that candidates often think they need to create an MX record pointing to 'fabrikam-com.mail.protection.outlook.com' (using the added domain), but Microsoft 365 always uses the primary domain's hashed value in the MX target regardless of which domain's email is being routed.

How to eliminate wrong answers

Option B is wrong because a CNAME record for autodiscover is used to automatically configure Outlook clients with Exchange Online settings, not to route email delivery. Option C is wrong because a TXT record for SPF is used to authorize sending servers and prevent spoofing, not to direct inbound email flow. Option D is wrong because an SRV record for SIP is used for VoIP and unified communications (Skype for Business/Teams), not for email routing.

91
MCQeasy

A global administrator wants to track service health issues and configure notifications for service incidents. Which portal should they use to view the current health status and set up email notifications?

A.Microsoft 365 admin center
B.Azure portal
C.Microsoft 365 Defender portal
D.Microsoft Purview compliance portal
AnswerA

The Service Health page in the Microsoft 365 admin center (under Health > Service health) aggregates current and historical health status for all Microsoft 365 workloads, including incidents, advisories, and expected resolutions. From this page, a global administrator can filter by product or region, view detailed problem descriptions, and configure proactive email notifications using the 'Notify me about issues' option. This dashboard is the designated console for tracking Microsoft 365 service health and directly satisfies the requirement.

Why this answer

The Microsoft 365 admin center provides the Service Health dashboard under Health > Service Health, which displays the current status of all Microsoft 365 services and allows administrators to configure email notifications for service incidents. This is the designated portal for managing tenant-wide service health and notifications, aligning with the role of a global administrator.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 admin center with the Azure portal for service health, because Azure also has a Service Health blade, but it only covers Azure services, not Microsoft 365 services like Exchange Online or Teams.

How to eliminate wrong answers

Option B is wrong because the Azure portal is used for managing Azure services and resources, not for Microsoft 365 service health or email notifications; it lacks the Service Health dashboard for Microsoft 365. Option C is wrong because the Microsoft 365 Defender portal focuses on security threats, incidents, and alerts (e.g., from Microsoft Defender for Office 365), not on service health incidents or email notifications for service availability. Option D is wrong because the Microsoft Purview compliance portal is dedicated to data governance, compliance, and eDiscovery, not to tracking service health or configuring notifications for service incidents.

92
MCQhard

Your organization has a hybrid identity setup with Azure AD Connect. You need to ensure that users can reset their passwords from the cloud and have the changes synchronized back to on-premises Active Directory. Which feature must you enable?

A.Password writeback.
B.Seamless single sign-on.
C.Pass-through authentication.
D.Password hash synchronization.
AnswerA

Password writeback is the only option that supports a bidirectional password flow: when a user performs a self-service password reset or changes their password in Azure AD, Azure AD Connect writes the new password back to the on-premises Active Directory. This requires Azure AD Premium licensing and must be explicitly enabled in Azure AD Connect, making it the correct feature for a hybrid identity organization that needs cloud-originated password changes reflected on-premises.

Why this answer

Password writeback is the Azure AD Connect feature that enables password changes performed in the cloud (e.g., via Azure AD SSPR) to be written back to on-premises Active Directory. This ensures the on-premises password stays synchronized with the cloud, which is required for hybrid identity scenarios where users reset passwords from the cloud.

Exam trap

The trap here is that candidates often confuse password hash synchronization (which only syncs one-way) with password writeback (which enables cloud-to-on-premises password changes), leading them to select password hash synchronization as the answer.

How to eliminate wrong answers

Option B (Seamless single sign-on) is wrong because it provides automatic sign-in for domain-joined devices on the corporate network, not password synchronization or writeback. Option C (Pass-through authentication) is wrong because it validates passwords directly against on-premises AD without storing password hashes in the cloud, and it does not support writing password changes back to on-premises AD. Option D (Password hash synchronization) is wrong because it only synchronizes password hashes from on-premises to Azure AD; it does not write password changes from the cloud back to on-premises AD.

93
MCQeasy

Your organization needs to create a custom domain in Microsoft 365. You have added the domain 'contoso.com' to the tenant. What is the next step to verify domain ownership?

A.Create user accounts with the custom domain.
B.Configure the email exchange (MX) record.
C.Assign licenses to users with the custom domain.
D.Add a TXT record to the public DNS zone.
AnswerD

The correct approach is to add a TXT record to the public DNS zone. Microsoft provides a unique TXT value in the domain verification wizard, and placing it in your DNS zone demonstrates that you control the domain's DNS namespace. Once the TXT record propagates and Microsoft queries it successfully, the domain is marked verified, allowing subsequent configuration steps like setting up MX records and creating users.

Why this answer

After adding a custom domain to a Microsoft 365 tenant, the next mandatory step is to prove ownership of the domain by adding a specific TXT record provided by Microsoft to the domain's public DNS zone. Microsoft queries this TXT record to verify that you control the domain before allowing you to use it for services like email or user accounts. This verification step is required by Microsoft's domain onboarding process and must succeed before any other configuration can proceed.

Exam trap

The trap here is that candidates often confuse domain verification (TXT record) with domain configuration (MX record), mistakenly thinking that setting up email routing is the immediate next step after adding the domain.

How to eliminate wrong answers

Option A is wrong because creating user accounts with the custom domain requires the domain to be verified first; attempting to assign a non-verified domain to users will fail. Option B is wrong because configuring the MX record is part of setting up email routing after domain verification, not a step to prove ownership. Option C is wrong because assigning licenses to users with the custom domain also depends on the domain being verified; licenses cannot be applied to unverified domains.

94
MCQmedium

You are reviewing an ARM template that will be used to deploy a storage account for a Microsoft 365 migration project. The template includes 'supportsHttpsTrafficOnly': true. What is the primary benefit of this setting?

A.It enforces secure transfer (HTTPS) for all requests to the storage account.
B.It reduces latency by enabling CDN integration.
C.It enables geo-redundant storage.
D.It minimizes storage costs by reducing bandwidth usage.
AnswerA

The supportsHttpsTrafficOnly property (also known as enableHttpsTrafficOnly in ARM templates) blocks any HTTP request to the storage account, forcing clients to use TLS/HTTPS for all read, write, and management operations. This prevents data from being transmitted in cleartext, meeting security and compliance requirements such as PCI DSS and HIPAA. Without this flag, a misconfigured client could silently fall back to HTTP, exposing account keys and data in transit.

Why this answer

Setting 'supportsHttpsTrafficOnly' to true enforces secure transfer by requiring all requests to the storage account to use HTTPS (TLS). This ensures data in transit is encrypted, protecting against man-in-the-middle attacks and eavesdropping. It is a critical security control for compliance with standards like PCI-DSS and HIPAA.

Exam trap

The trap here is that candidates may confuse 'supportsHttpsTrafficOnly' with performance or redundancy features, but it is purely a security control for enforcing encrypted transport.

How to eliminate wrong answers

Option B is wrong because enabling HTTPS-only does not reduce latency or enable CDN integration; CDN integration is configured separately via Azure CDN profiles. Option C is wrong because geo-redundant storage (GRS) is controlled by the 'sku.name' property (e.g., Standard_GRS), not by the HTTPS setting. Option D is wrong because HTTPS-only does not minimize storage costs; bandwidth usage is unaffected by the protocol, and HTTPS may add slight overhead due to TLS handshake.

95
MCQeasy

Your organization is planning to deploy Microsoft 365 Copilot. You need to ensure that all prerequisites are met. Which of the following is a mandatory prerequisite for enabling Microsoft 365 Copilot?

A.Microsoft Purview Data Loss Prevention policies.
B.Microsoft Entra ID P2 licenses.
C.An active Azure subscription.
D.Exchange Online Plan 2 licenses.
AnswerB

Microsoft Entra ID P2 licenses are not mandatory. While Copilot uses Entra ID for identity, only the free tier or P1 is sufficient. P2 is not a requirement.

Why this answer

None of the listed options are mandatory prerequisites for Microsoft 365 Copilot. The actual mandatory requirements are a qualifying Microsoft 365 license (E3, E5, or Business Premium) and the Microsoft 365 Copilot add-on license. Microsoft Entra ID P2 is not required; a basic Entra ID (free) is sufficient.

Purview DLP, an Azure subscription, and Exchange Online Plan 2 are also not mandatory.

Exam trap

The trap here is that candidates might assume Microsoft Entra ID P2 is required because Copilot relies on identity and security features, but in reality, a standard Entra ID (free) is sufficient. The actual mandatory prerequisites are a qualifying Microsoft 365 license and the Copilot add-on.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Loss Prevention policies are not a prerequisite for enabling Copilot; they are an optional compliance feature that can be applied after deployment to control data sharing. Option C is wrong because an active Azure subscription is not required for Microsoft 365 Copilot, which is a SaaS add-on to Microsoft 365 and does not depend on Azure infrastructure for its core functionality. Option D is wrong because Exchange Online Plan 2 licenses are not mandatory; Copilot works with Exchange Online Plan 1 or other mail-enabled plans as long as the user has a valid Microsoft 365 license that includes Exchange Online.

96
MCQeasy

Your organization wants to use Microsoft Intune to manage devices. You need to ensure that only corporate-owned devices can enroll. What configuration should you use?

A.Use a conditional access policy to require device compliance.
B.Configure enrollment restrictions to block personally owned devices.
C.Set a compliance policy requiring devices to be marked as corporate.
D.Create a device type restriction for iOS and Android.
AnswerB

Enrollment restrictions in Microsoft Intune are administrative policies that govern the actual enrollment action, and they include an ownership-type setting. By configuring the 'Allow personally owned devices' restriction to 'Block' under the default or custom enrollment restriction, Intune will reject enrollment attempts from devices that are not marked as corporate-owned, while still permitting corporate-owned devices enrolled via methods such as Apple Business Manager or Windows Autopilot. This is the correct approach because it directly prevents the enrollment of personal devices without affecting corporate-enrolled assets.

Why this answer

Enrollment restrictions in Microsoft Intune allow you to block personally owned devices by setting the 'Allow personally owned devices' option to 'No' for the platform. This ensures that only corporate-owned devices, which are identified by their corporate enrollment token or IMEI/MEID numbers, can enroll. This is the direct and intended method to restrict enrollment to corporate-owned devices only.

Exam trap

The trap here is that candidates often confuse post-enrollment controls (like compliance policies or conditional access) with pre-enrollment restrictions, mistakenly thinking that requiring compliance or marking devices as corporate can block personal devices from enrolling, when in fact only enrollment restrictions can prevent the enrollment process itself.

How to eliminate wrong answers

Option A is wrong because a conditional access policy requiring device compliance does not prevent enrollment; it controls access to cloud apps after enrollment, and non-compliant devices can still enroll but then be blocked from accessing resources. Option C is wrong because a compliance policy requiring devices to be marked as corporate is not a pre-enrollment restriction; compliance policies are evaluated after enrollment and cannot block the enrollment process itself. Option D is wrong because a device type restriction for iOS and Android only blocks specific device models or platforms, not the ownership status (corporate vs. personal), so it cannot ensure that only corporate-owned devices enroll.

97
MCQmedium

You are the Microsoft 365 administrator for a company that has a Microsoft 365 E5 subscription. The company has a policy that all files stored in SharePoint Online and OneDrive for Business must be retained for seven years. You need to implement a retention solution that meets this requirement and ensures that users cannot permanently delete the files before the retention period expires. What should you do?

A.Create a retention policy in Microsoft Purview that retains content in SharePoint and OneDrive for seven years and locks the policy.
B.Configure a data loss prevention (DLP) policy that blocks deletion of files in SharePoint and OneDrive for seven years.
C.Create a retention policy that applies to all SharePoint sites and OneDrive accounts, set the retention period to seven years, and configure the policy to retain items even if users delete them.
D.Create a retention label that retains items for seven years and configure a retention label policy to publish the label to all SharePoint sites and OneDrive accounts.
AnswerC

A retention policy applied to all SharePoint sites and OneDrive accounts with a seven-year retention period ensures that items are retained even if users delete them. The policy preserves a copy in the Preservation Hold library, preventing permanent deletion. This meets the requirement that files must be retained for seven years and cannot be permanently deleted by users before the retention period expires.

Why this answer

A retention policy applied to all SharePoint sites and OneDrive accounts with a seven-year retention period ensures that items are retained even if users delete them. The policy preserves copies in the Preservation Hold library, preventing permanent deletion. This meets the requirement that files must be retained for seven years and cannot be permanently deleted by users before the retention period expires.

Exam trap

The trap here is confusing retention with DLP; DLP can block actions like sharing but cannot enforce retention, while retention policies preserve content even after deletion.

98
MCQeasy

An administrator has added a custom domain 'contoso.com' to their Microsoft 365 tenant and verified ownership. However, users are unable to receive emails sent to their custom domain. Which type of DNS record must the administrator add in the public DNS zone to route emails to Exchange Online?

A.TXT record
B.MX record
C.CNAME record
D.SPF record
AnswerB

An MX record specifies the mail exchanger accepting messages for contoso.com, directing inbound mail to Exchange Online's protection service. Without it, senders cannot locate a mail server, so users receive nothing despite verified domain ownership.

Why this answer

The MX (Mail Exchange) record is the DNS record type that directs email messages to a specific mail server. For Exchange Online, the MX record must point to the tenant's mail exchanger (e.g., contoso-com.mail.protection.outlook.com) with a priority value (typically 0). Without this record, sending mail servers cannot route inbound emails to the custom domain's mailbox store in Exchange Online.

Exam trap

The trap here is that candidates confuse the purpose of MX records with SPF or TXT records, thinking that SPF alone enables email delivery, when in fact MX records are the fundamental requirement for inbound mail routing.

How to eliminate wrong answers

Option A (TXT record) is wrong because TXT records hold arbitrary text data, such as SPF or DKIM keys, but they do not route email traffic. Option C (CNAME record) is wrong because CNAME records alias one domain to another and are not used for mail routing; MX records are the standard for mail exchange. Option D (SPF record) is wrong because SPF records authorize sending servers to prevent spoofing, but they do not direct inbound email delivery.

99
Multi-Selectmedium

You need to configure Microsoft Purview Data Loss Prevention (DLP) to prevent sensitive data from being shared via email. Which THREE elements can you use to define the policy?

Select 3 answers
A.Actions
B.Locations
C.Sensitivity labels
D.Exceptions
E.Conditions
AnswersA, B, E

Actions are a mandatory component of any Microsoft Purview DLP policy because they determine the enforcement response—such as blocking a SharePoint file share, applying encryption to an email, or displaying a policy tip—when a condition matches sensitive content. Without an action, the policy would only perform detection without any remediation or prevention, failing to satisfy data loss protection requirements. The action defines the resulting 'do you want to do' part of the rule, making it essential for the policy to be functional.

Why this answer

Actions are a required element in a Microsoft Purview DLP policy because they define what happens when sensitive data is detected—such as blocking the email, sending a notification, or applying encryption. Without specifying actions, the policy would have no enforcement mechanism to prevent data sharing.

Exam trap

The trap here is that candidates confuse sensitivity labels as a top-level policy element instead of recognizing they are merely a condition type, while exceptions are often mistakenly considered a separate core component rather than a refinement of conditions.

100
MCQmedium

Your organization uses Microsoft Defender for Office 365. You need to configure a policy that automatically redirects emails containing malicious attachments to a quarantine folder for admin review. What type of policy should you create?

A.Safe Attachments policy.
B.Anti-malware policy.
C.Anti-spam policy.
D.Safe Links policy.
AnswerB

The anti-malware policy in Microsoft Defender for Office 365 is the correct place to configure how messages containing malware are handled. It uses heuristics and signature-based detection to identify malicious attachments, and when malware is found, the policy can be set to quarantine the entire message. This policy also allows admins to specify the quarantine retention period and enable/disable malware filters, making it the definitive control for malware-induced quarantine.

Why this answer

B is correct because the Anti-malware policy in Microsoft Defender for Office 365 is specifically designed to handle malware detected in email messages, including attachments. When configured, it can automatically redirect messages containing malicious attachments to a quarantine folder for admin review, providing a controlled remediation workflow.

Exam trap

Microsoft often tests the distinction between Anti-malware (for attachment malware) and Safe Attachments (for advanced sandbox analysis), leading candidates to mistakenly choose Safe Attachments when the core requirement is simply redirecting known malicious attachments to quarantine.

How to eliminate wrong answers

Option A is wrong because Safe Attachments policy focuses on scanning and detonating attachments in a sandbox environment before delivery, but its primary quarantine action is for messages with malicious attachments detected during that process, not for general malware redirection; the question's requirement for automatic redirection of emails containing malicious attachments is directly met by the Anti-malware policy. Option C is wrong because Anti-spam policy handles spam, phishing, and bulk mail, not malware or malicious attachments. Option D is wrong because Safe Links policy protects users from malicious URLs in messages and Office documents, not from malicious attachments.

101
MCQeasy

An organization has just purchased Microsoft 365 subscriptions and wants to add their custom domain 'fabrikam.com' to the tenant. Which record must they add to their DNS provider to verify domain ownership?

A.MX record
B.TXT record
C.CNAME record
D.SRV record
AnswerB

A TXT record is the standard method Microsoft 365 uses to verify domain ownership because it can hold an arbitrary text string. Microsoft gives you a unique verification token during the domain setup wizard; when you publish it as a TXT record, Microsoft queries your DNS zone and confirms the exact token exists. This proves you control the domain without affecting existing services, and you can remove the record after verification succeeds.

Why this answer

To verify domain ownership in Microsoft 365, you must add a TXT record provided by the Microsoft 365 admin center to your DNS hosting provider. This TXT record contains a unique verification string that Microsoft checks to confirm you control the domain. MX, CNAME, and SRV records are used for mail routing, service aliasing, and service location, respectively, but they do not serve the purpose of domain ownership verification.

Exam trap

The trap here is that candidates often confuse the TXT record used for verification with the MX record required for email routing, mistakenly thinking they can skip verification by adding an MX record directly.

How to eliminate wrong answers

Option A is wrong because an MX record is used to specify the mail exchange server for a domain, not to prove domain ownership; adding an MX record would only affect email routing. Option C is wrong because a CNAME record creates an alias from one domain name to another and is used for service redirection, not for domain verification. Option D is wrong because an SRV record defines the location (hostname and port) of specific services like SIP or LDAP, and it is not used for domain ownership validation.

102
MCQeasy

An administrator is onboarding a new custom domain for email in a Microsoft 365 tenant. Which step should be performed first?

A.Add the domain in the Microsoft 365 admin center
B.Verify domain ownership by adding a TXT record
C.Configure DNS records for Microsoft services
D.Set the domain as the primary email domain
AnswerA

The first step in onboarding a custom email domain is to add it in the Microsoft 365 admin center (Settings > Domains > Add domain). This action registers the domain with your tenant and generates the necessary verification token, allowing you to proceed to the next step of proving ownership. This must occur before any TXT record or DNS changes can be associated with the domain.

Why this answer

Before you can use a custom domain for email or any other service in Microsoft 365, you must first add the domain to the tenant in the Microsoft 365 admin center. This creates the domain object in Azure Active Directory and initiates the verification process. Only after the domain is added can you proceed to verify ownership and configure DNS records.

Exam trap

The trap here is that candidates often confuse the order of operations, thinking DNS verification (Option B) is the first step, but Microsoft 365 requires the domain to be added to the tenant first to generate the verification token.

How to eliminate wrong answers

Option B is wrong because verifying domain ownership by adding a TXT record is a subsequent step that cannot be performed until the domain has been added to the tenant. Option C is wrong because configuring DNS records for Microsoft services (e.g., MX, CNAME, TXT) is done after verification, not before. Option D is wrong because setting the domain as the primary email domain is a final step that requires the domain to be added, verified, and DNS records configured first.

103
MCQeasy

An administrator adds the custom domain 'adatum.com' to a new Microsoft 365 tenant. In the Microsoft 365 admin center, the domain status shows 'Pending verification'. Which type of DNS record must the administrator add to the public DNS zone to complete the domain ownership verification?

A.TXT record
B.MX record
C.CNAME record
D.SPF record
AnswerA

Microsoft 365 generates a unique verification code and instructs you to add it as a TXT record in your domain's DNS. The service then queries DNS for that exact string; if found, it confirms you control the domain and can use it for Exchange Online, Teams, or SharePoint. TXT records are the standard mechanism for proving ownership because they can hold arbitrary text, which the verification token is.

Why this answer

To verify domain ownership in Microsoft 365, you must add a TXT record containing a unique verification string provided by the Microsoft 365 admin center to the public DNS zone. The DNS provider checks for this TXT record, and when found, Microsoft 365 confirms you control the domain. This is a standard domain verification method defined in RFC 1035 and used by many cloud services.

Exam trap

The trap here is that candidates confuse the TXT record used for domain verification with the TXT record used for SPF or DKIM, or assume an MX record is required because email is involved, but Microsoft 365 uses a dedicated verification TXT record separate from any email-related records.

How to eliminate wrong answers

Option B is wrong because an MX record routes email to a mail server, not for domain ownership verification; it is used later for mail flow configuration. Option C is wrong because a CNAME record aliases one domain to another and is not used for domain verification; it is typically used for services like autodiscover. Option D is wrong because an SPF record is a TXT record used for email authentication (anti-spoofing), not for domain ownership verification; it is configured after verification is complete.

104
MCQeasy

You run the PowerShell command shown in the exhibit for a Microsoft 365 tenant. The output shows DisplayName as 'Contoso', DefaultDomainName as 'contoso.onmicrosoft.com', and InitialDomain as 'contoso.onmicrosoft.com'. What does this indicate about the tenant?

A.The command requires global admin privileges.
B.The tenant is using the initial .onmicrosoft.com domain as the default domain.
C.The tenant has not been verified.
D.The tenant has a custom domain set as the default.
AnswerB

When DefaultDomainName and InitialDomain display the same .onmicrosoft.com address, it means Microsoft 365 is using the originally provisioned domain as the primary SMTP routing domain. This is the default state for a new tenant; the initial domain is always verified and cannot be removed, so no custom domain has been designated as default.

Why this answer

The output shows DefaultDomainName and InitialDomain both set to 'contoso.onmicrosoft.com', which means the tenant is using its initial Microsoft-provided domain as the default domain. The Get-MgDomain cmdlet retrieves domain objects, and the DefaultDomainName property indicates which domain is used by default for new users and services. Since no custom domain is set as default, the initial .onmicrosoft.com domain remains the default.

Exam trap

The trap here is that candidates may assume the DefaultDomainName property reflects a custom domain that has been set as default, but the output explicitly shows it is the initial .onmicrosoft.com domain, indicating no custom domain has been promoted to default.

How to eliminate wrong answers

Option A is wrong because the Get-MgDomain cmdlet does not require global admin privileges; it can be run by any user with appropriate read permissions (e.g., Domain Reader or Global Reader). Option C is wrong because the presence of a DisplayName, DefaultDomainName, and InitialDomain in the output indicates the domain is verified and active; unverified domains would not appear in the domain list or would show a different status. Option D is wrong because the DefaultDomainName is 'contoso.onmicrosoft.com', not a custom domain; if a custom domain were set as default, that custom domain name would appear in the DefaultDomainName property.

105
Multi-Selecteasy

An administrator needs to open a Microsoft 365 support request because a critical service issue is affecting all users. Which two pieces of information should the administrator have readily available before contacting support? (Choose two.)

Select 2 answers
A.Tenant ID
B.User principal names of affected users
C.Current service health status
D.Billing contact information
AnswersA, C

The tenant ID uniquely identifies the affected Microsoft 365 organisation, letting support locate the correct tenant, correlate service telemetry and open the case against the right environment. Without it, engineers cannot verify the impacted directory or scope diagnostics to the customer's instance.

Why this answer

Option A (Tenant ID) is correct because Microsoft 365 support requires the tenant GUID to uniquely identify the organization's directory and route the case to the correct environment. Option C (Current service health status) is correct because checking the Service health dashboard in the Microsoft 365 admin center shows whether the issue is a known incident or advisory, which support uses to correlate the report and avoid duplicate tickets. Option B is not required because support needs the tenant-level scope, not individual UPNs, for a service-wide outage affecting all users.

Option D is not required because billing contact information is irrelevant to a technical service incident; support asks for tenant and service health details instead.

Exam trap

The trap here is that candidates often assume user principal names (UPNs) are needed for any support request, but Microsoft Support requires the Tenant ID and service health status for tenant-wide issues, not individual user identifiers.

106
MCQhard

A Microsoft 365 tenant uses a custom domain named fabrikam.com for all user principal names and email addresses. The security team requires that any email message sent from an external sender that spoofs fabrikam.com be rejected outright, while legitimate messages from the on-premises mail relay must still be accepted. You configure DKIM signing and SPF with a hard fail. What should you configure next to meet the rejection requirement?

A.Create a DMARC TXT record with p=quarantine and rely on the existing SPF hard fail to block spoofed messages.
B.Create a DMARC TXT record with p=reject and add the on-premises relay to the SPF record's include list.
C.Add a second SPF record for fabrikam.com that lists only the on-premises relay's public IP address.
D.Configure an Exchange Online transport rule that rejects messages where the sender's domain is fabrikam.com and the message originates outside the organization.
AnswerB

A DMARC policy of p=reject instructs receiving systems to reject messages that fail both SPF and DKIM alignment for fabrikam.com, which stops external spoofing. Including the on-premises relay in SPF ensures its legitimate messages pass authentication, so they are not caught by the reject policy, satisfying both halves of the requirement.

Why this answer

Enforcing rejection of spoofed fabrikam.com mail requires a DMARC record with p=reject, because DMARC is the only mechanism that tells receivers to refuse messages failing SPF and DKIM alignment. Legitimate on-premises relay traffic must still authenticate, so the relay's sending infrastructure belongs in the SPF record. Quarantine softens the action, duplicate SPF records are invalid, and transport rules cannot influence external receivers.

Exam trap

The trap here is believing that an SPF hard fail by itself rejects spoofed mail, when receivers only enforce rejection if a DMARC policy of p=reject is published.

107
MCQeasy

An organization has just purchased Microsoft 365 Business Standard licenses and has added the custom domain 'contoso.com' to the tenant. The administrator wants all new user email addresses to use '@contoso.com' instead of the default '@contoso.onmicrosoft.com'. How can this be achieved?

A.Set the default domain in the Microsoft 365 admin center to contoso.com
B.Change the primary SMTP address for each user manually after creation
C.Remove the onmicrosoft.com domain from the tenant
D.Edit the user creation PowerShell script to specify the domain
AnswerA

Setting contoso.com as the default domain in the Microsoft 365 admin center is the correct tenant-wide configuration. When you set a verified custom domain as the default, every new user created through the admin center automatically receives a user principal name (UPN) and email address ending with @contoso.com, without requiring any per-user steps. This setting persists for all future user creations and does not alter existing users' addresses, making it the standard way to ensure automatic assignment of the custom domain.

Why this answer

Setting the default domain to 'contoso.com' in the Microsoft 365 admin center ensures that all newly created users automatically receive an email address with the custom domain as their primary SMTP address. This is the standard method because the default domain setting controls the domain appended to new user accounts during creation, eliminating the need for manual changes.

Exam trap

The trap here is that candidates may think they must manually update each user or use PowerShell because they overlook the simple default domain configuration in the admin center, which automatically applies to all new user creations.

How to eliminate wrong answers

Option B is wrong because manually changing the primary SMTP address for each user after creation is inefficient and does not address the requirement for all new users to automatically use '@contoso.com'; it is a workaround, not a configuration. Option C is wrong because removing the 'onmicrosoft.com' domain from the tenant is not possible—it is a reserved default domain that cannot be deleted and is required for internal routing and Azure AD operations. Option D is wrong because editing a PowerShell script to specify the domain is a valid but unnecessary approach when the default domain setting in the admin center achieves the same result more simply; the question asks how to achieve this, and the admin center method is the direct, supported way.

108
MCQeasy

You are the Microsoft 365 administrator for a company that has a Microsoft 365 E5 tenant. The legal department requires that all email messages sent to and from the tenant be retained for seven years, and that users cannot permanently delete messages before that period ends. The solution must apply to all mailboxes, including new ones created later, and must not require users to apply retention labels manually. What should you do?

A.Create a retention policy in Microsoft Purview that retains Exchange email for seven years, applies to all Exchange mailboxes, and configure the policy to retain items at the end of the retention period.
B.Enable a litigation hold on each mailbox by using Exchange Online PowerShell for all current users, and repeat the process whenever a new user is created.
C.Create a data loss prevention policy that blocks users from deleting email messages that contain sensitive information.
D.Create a retention label with a seven-year retention period, publish it to all users, and instruct users to apply it to their messages.
AnswerA

A retention policy in Microsoft Purview can target all Exchange mailboxes, including future ones, and applies automatically without user action. Setting the retention period to seven years and choosing to retain rather than delete keeps items and prevents users from permanently removing them before the period expires, satisfying the legal hold requirement.

Why this answer

A Microsoft Purview retention policy applies retention settings at the workload and location level, so Exchange email can be retained for seven years across all current and future mailboxes without user or administrator action. Configuring the policy to retain items preserves them and prevents permanent deletion during the retention period, which meets the legal department's requirement.

Exam trap

The trap here is choosing a retention label or litigation hold, which either requires manual application or does not automatically cover mailboxes created later.

109
MCQhard

Your organization uses Microsoft Defender for Identity and has enabled Microsoft Secure Score. You notice that the Secure Score for Identity has dropped significantly after a recent configuration change. Which action is most likely to have caused the decrease?

A.Changing password expiration policy to 180 days.
B.Enabling MFA for all users.
C.Disabling password hash synchronization in Microsoft Entra Connect.
D.Implementing a conditional access policy blocking legacy authentication.
AnswerC

Disabling password hash synchronization (PHS) in Microsoft Entra Connect lowers Microsoft Secure Score for Identity because Defender for Identity relies on PHS to obtain on-premises password hashes for leaked-credential analysis and lateral movement path detection. Without PHS, Microsoft Entra ID loses a crucial data source that helps correlate on-premises and cloud activities, impairing the ability to identify compromised accounts and reducing the overall identity threat detection visibility. As a result, the identity protection pillar of Secure Score decreases, making this the correct action.

Why this answer

Disabling password hash synchronization (PHS) in Microsoft Entra Connect removes the ability for Microsoft Defender for Identity to correlate on-premises Active Directory credential exposure events with cloud authentication attempts. Without PHS, Defender for Identity cannot detect when leaked credentials are used against Azure AD, causing the Secure Score for Identity to drop because key detection capabilities are no longer available.

Exam trap

The trap here is that candidates often assume disabling password hash synchronization is a security improvement (to avoid storing hashes in the cloud), but they overlook that Defender for Identity requires it for critical leaked credential detection, and Secure Score penalizes its absence.

How to eliminate wrong answers

Option A is wrong because changing password expiration policy to 180 days does not directly affect Defender for Identity's detection capabilities or Secure Score; it may even reduce risk by encouraging longer passwords, but Secure Score for Identity focuses on configuration and detection health, not password age. Option B is wrong because enabling MFA for all users improves security posture and typically increases Secure Score, not decreases it. Option D is wrong because implementing a conditional access policy blocking legacy authentication reduces attack surface and improves security, which would raise Secure Score for Identity, not lower it.

110
MCQhard

Your company is deploying Microsoft Defender for Office 365. The security team wants to automatically remove messages identified as malware from all mailboxes after delivery. What should you configure?

A.Configure an anti-malware policy with a high-confidence verdict.
B.Enable Zero-hour auto purge (ZAP) in the anti-malware policy.
C.Set up a mailbox intelligence policy.
D.Create an anti-phishing policy to block spoofed senders.
AnswerB

Enabling Zero-hour auto purge (ZAP) in the anti-malware policy instructs the service to continually re-evaluate delivered messages against updated threat intelligence. For malware specifically, ZAP detects a zero-day or newly identified malware payload in an already delivered email and automatically deletes or quarantines the message from the user's mailbox. This is the correct control for post-delivery remediation, which is why it satisfies the requirement.

Why this answer

Zero-hour auto purge (ZAP) is the correct feature because it automatically detects and removes messages that are identified as malware after they have already been delivered to a user's mailbox. By enabling ZAP in the anti-malware policy, the system retroactively moves malicious messages to the user's Junk Email folder or quarantines them, ensuring post-delivery protection without manual intervention.

Exam trap

The trap here is that candidates often confuse ZAP with initial filtering policies, assuming that configuring a high-confidence verdict in the anti-malware policy alone will handle post-delivery removal, when in fact ZAP must be explicitly enabled for that purpose.

How to eliminate wrong answers

Option A is wrong because configuring an anti-malware policy with a high-confidence verdict only affects the initial filtering and delivery decision; it does not automatically remove messages that were already delivered. Option C is wrong because a mailbox intelligence policy is part of Exchange Online Protection (EOP) for detecting unusual sending patterns and user compromise, not for removing malware after delivery. Option D is wrong because an anti-phishing policy targets spoofed senders and phishing attempts, not malware removal, and does not provide post-delivery cleanup.

111
MCQmedium

Your company uses Microsoft 365 and has recently deployed Microsoft Intune for mobile device management. You need to ensure that corporate data on iOS devices is protected by preventing users from copying data from managed apps to unmanaged apps. What should you configure?

A.Mobile application management (MAM) without enrollment.
B.Device compliance policies.
C.Conditional Access policies.
D.App protection policies.
AnswerD

App protection policies in Microsoft Intune are specifically designed to manage data protection at the application layer, including settings to prevent copy-paste of organizational data into unmanaged apps. These policies can be assigned directly to users across devices with or without MDM enrollment, making them the correct mechanism for this scenario. For example, the 'Restrict cut, copy, and paste' policy mode can block the action entirely or allow it only between managed apps.

Why this answer

App protection policies (APP) are the correct choice because they provide mobile application management (MAM) controls that specifically prevent data transfer between managed and unmanaged apps on iOS devices. Unlike device-level policies, APP operates at the application layer, allowing you to restrict copy/paste, cut, and data sharing actions without requiring device enrollment. This directly addresses the requirement to protect corporate data on iOS devices by blocking data leakage to unmanaged apps.

Exam trap

The trap here is that candidates confuse the deployment model (MAM without enrollment) with the actual policy configuration (app protection policies), or they mistakenly think device compliance or Conditional Access can control app-level data sharing, which they cannot.

How to eliminate wrong answers

Option A is wrong because MAM without enrollment (also known as MAM-WE) is a deployment model, not a specific policy configuration; while it can use app protection policies, the question asks what to configure, and the correct configuration is the app protection policy itself, not the deployment model. Option B is wrong because device compliance policies enforce device-level security requirements (e.g., jailbreak detection, passcode compliance) but do not control data transfer between apps at the application layer. Option C is wrong because Conditional Access policies control access to resources based on signals like device compliance or location, but they do not directly restrict copy/paste or data sharing between managed and unmanaged apps.

112
MCQmedium

Refer to the exhibit. You are reviewing a Microsoft Entra ID Governance access review. The JSON shows an access review scope for a SharePoint site. What does the 'isExternallyAccessible': false setting indicate about the site?

A.The site's external sharing settings are not reviewed.
B.External users cannot access the site.
C.The site is configured to allow sharing with anyone.
D.External users are automatically granted access.
AnswerB

This is correct because the external sharing level is configured to 'Only people in your organization' (or equivalent), which prevents any external users from accessing the site. Even if external users receive a link, they will be blocked by the site's sharing policy. This setting ensures that only authenticated users within the tenant can view or edit content.

Why this answer

The 'isExternallyAccessible': false setting in the access review scope JSON indicates that the SharePoint site is not configured to allow external sharing. This means external users cannot access the site, making option B correct. The setting directly controls whether the site is visible to external identities in the access review, not the review process itself.

Exam trap

The trap here is that candidates confuse 'isExternallyAccessible' with the access review's review scope filtering, thinking it means the site is excluded from review, when it actually indicates the site's external sharing state.

How to eliminate wrong answers

Option A is wrong because 'isExternallyAccessible' controls the site's external sharing configuration, not whether the sharing settings are reviewed; access reviews always evaluate the site's sharing state. Option C is wrong because 'isExternallyAccessible': false explicitly means the site does not allow sharing with anyone (including 'Anyone' links), which would require the setting to be true. Option D is wrong because external users are not automatically granted access when the setting is false; they are explicitly blocked from accessing the site.

113
MCQeasy

A company has just purchased Microsoft 365 Business Standard and added the custom domain 'fabrikam.com' to the tenant. They want to verify domain ownership. Which DNS record type must they add to their DNS provider?

A.MX record
B.CNAME record
C.TXT record
D.SPF record
AnswerC

The TXT record is the correct method because it is designed to hold arbitrary text, allowing you to publish the exact verification string Microsoft provides (e.g., MS=ms12345678). Microsoft's directory service queries the public DNS and looks for that unique token; if found, it proves you can modify DNS records and therefore own the domain. This is the standard mechanism used by Microsoft 365 and Azure AD to verify domain control without affecting mail routing or other services.

Why this answer

To verify domain ownership in Microsoft 365, you must add a TXT record containing a unique verification string provided by the Microsoft 365 admin center. The TXT record is the standard DNS record type used for domain validation because it can store arbitrary text data without affecting email routing or other services. Microsoft 365 checks for this specific TXT record to confirm you control the domain.

Exam trap

The trap here is that candidates often confuse the TXT record used for domain verification with the SPF record, which is also a TXT record type, but SPF is specifically for email authentication and not for proving domain ownership.

How to eliminate wrong answers

Option A is wrong because an MX record specifies the mail server for the domain and is used for email routing, not domain ownership verification. Option B is wrong because a CNAME record aliases one domain name to another and is not used for domain validation; it is typically used for services like autodiscover. Option D is wrong because an SPF record is a TXT record subtype that authorizes email senders and is not used for domain ownership verification; adding an SPF record alone does not prove domain control.

114
MCQeasy

An administrator needs to update the organization's display name, technical contact, and privacy statement URL in the Microsoft 365 admin center. Which page should they navigate to?

A.Settings > Org settings > Organization profile
B.Users > Active users > More actions > Edit contact info
C.Billing > Billing accounts > Edit organization info
D.Admin centers > Azure AD > Properties
AnswerA

The Microsoft 365 admin center path Settings > Org settings > Organization profile is the intended, tenant-wide location for editing the organization's display name, technical contact, privacy statement URL, default language, and country/region. These values are stored on the organization object in Microsoft Entra ID and surfaced across M365 services, so changing them here updates the banner, notification sender identity, and privacy links globally. No other admin center page exposes all of these fields together.

Why this answer

The 'Settings > Org settings > Organization profile' page in the Microsoft 365 admin center is the dedicated location for modifying tenant-wide metadata, including the organization's display name, technical contact email, and privacy statement URL. These settings are stored in the Microsoft 365 tenant's directory properties and are distinct from user-level or billing-level configurations.

Exam trap

The trap here is that candidates confuse the Azure AD tenant Properties blade (which shows the organization name and technical contact) with the Microsoft 365 admin center's Organization profile page, overlooking that the privacy statement URL is a Microsoft 365-specific setting not available in Azure AD.

How to eliminate wrong answers

Option B is wrong because 'Users > Active users > More actions > Edit contact info' modifies individual user contact details, not tenant-wide organization properties like the display name or privacy statement URL. Option C is wrong because 'Billing > Billing accounts > Edit organization info' manages billing-related account information (e.g., invoice address, payment method) and does not include the technical contact or privacy statement URL fields. Option D is wrong because 'Admin centers > Azure AD > Properties' opens the Azure AD tenant properties blade, which allows editing the organization name and technical contact but lacks the privacy statement URL field; the privacy statement URL is configured exclusively in the Microsoft 365 admin center's Organization profile page, not in Azure AD.

115
MCQmedium

Your organization has a Microsoft 365 tenant with a custom domain contoso.com. You have configured Exchange Online to accept emails for contoso.com. You now need to add a subdomain sales.contoso.com and ensure that email sent to sales.contoso.com is delivered to a specific shared mailbox. What should you do?

A.Add sales.contoso.com as a custom domain in the Microsoft 365 admin center and verify ownership.
B.Add sales.contoso.com as an accepted domain in Exchange Online and create a transport rule to redirect emails to the shared mailbox.
C.Configure an auto-expanding archive for the shared mailbox.
D.Create a distribution group named sales@contoso.com and add the shared mailbox as a member.
AnswerB

This is correct because an accepted domain in Exchange Online tells the service to accept email addressed to that domain (or subdomain). To make the subdomain deliverable, you must add sales.contoso.com as an accepted domain with the 'Internal Relay' or 'Authoritative' type. Then, a transport rule (mail flow rule) can be configured to match any recipient in that subdomain and redirect the message to the sales shared mailbox. This ensures all mail sent to @sales.contoso.com lands in the shared mailbox without needing separate mailboxes.

Why this answer

To route email for a subdomain to a specific mailbox, you must first add the subdomain as an accepted domain in Exchange Online (not as a custom domain in the admin center, since the parent domain is already verified). Then, you create a transport rule that matches recipients in that accepted domain and redirects the messages to the target shared mailbox. This ensures that all emails sent to sales.contoso.com are delivered to the designated mailbox without requiring additional MX records or domain verification.

Exam trap

The trap here is that candidates confuse adding a subdomain as a custom domain (which requires unnecessary DNS verification) with adding it as an accepted domain in Exchange Online, which is the correct approach for routing email to a specific mailbox without altering the parent domain's verification status.

How to eliminate wrong answers

Option A is wrong because adding sales.contoso.com as a custom domain in the Microsoft 365 admin center would require DNS verification (e.g., TXT record) for the subdomain, which is unnecessary and incorrect—the parent domain contoso.com is already verified, and subdomains inherit that verification; instead, you should add it as an accepted domain in Exchange Online. Option C is wrong because configuring an auto-expanding archive for the shared mailbox addresses storage capacity, not email routing for a subdomain. Option D is wrong because creating a distribution group with the shared mailbox as a member would not route emails sent to sales.contoso.com to that mailbox; it would only allow the group to receive emails sent to the group's address, and the subdomain routing is not configured.

116
MCQeasy

A company has purchased Microsoft 365 Business Standard and added the custom domain 'fabrikam.com' to the tenant. The company wants all new users to have 'fabrikam.com' as their default email domain instead of the onmicrosoft.com domain. How should the administrator achieve this?

A.Update the MX record in the DNS to point to Microsoft 365 with the custom domain.
B.In the admin center, go to Settings > Domains, select the custom domain, and click 'Set as default'.
C.Use the Exchange admin center to set the default email address policy to use the custom domain.
D.For each new user, manually add an email alias with the custom domain and remove the onmicrosoft.com alias.
AnswerB

This is the correct method. In the Microsoft 365 admin center, navigating to Settings > Domains, selecting the verified custom domain, and clicking 'Set as default' changes the tenant-level default domain. Once set, all new users are automatically assigned a user principal name (UPN) and primary SMTP address using that custom domain, rather than the initial onmicrosoft.com domain. This is a global, automated setting that applies to every subsequently created user, making it the intended administrative control.

Why this answer

The Microsoft 365 admin center provides a dedicated setting under Settings > Domains to mark a custom domain as the default email domain. Once set as default, all new users will automatically receive a primary email address using that domain instead of the initial onmicrosoft.com domain, without requiring manual changes or additional configuration.

Exam trap

The trap here is that candidates often confuse DNS record management (like MX records) with tenant-level domain configuration, or assume that Exchange email address policies are the only way to control default domains, when in fact the admin center's 'Set as default' option is the correct and simplest method for new users.

How to eliminate wrong answers

Option A is wrong because updating the MX record only controls mail routing (where incoming emails are delivered), not the default email domain assigned to new users. Option C is wrong because the Exchange admin center's email address policy applies to existing mailboxes and can set domain preferences, but the default domain for new users is controlled at the tenant level in the Microsoft 365 admin center, not via an email address policy. Option D is wrong because manually adding and removing aliases for each new user is inefficient and unnecessary; the default domain setting automates this process for all new users.

117
MCQmedium

Your organization plans to use Microsoft 365 Copilot. To ensure compliance, you need to prevent Copilot from accessing sensitive content in SharePoint Online document libraries that are labeled as 'Highly Confidential'. What should you configure?

A.Configure a retention policy to prevent Copilot from accessing older content.
B.Create a conditional access policy to block Copilot from accessing SharePoint.
C.Create a DLP policy to block Copilot from processing 'Highly Confidential' content.
D.Configure a sensitivity label with encryption and apply it to the documents.
AnswerD

Sensitivity labels that include encryption encrypt the file itself and protect it with cryptographic access controls that Copilot explicitly respects. Because Copilot requires decrypted content to index and generate grounded responses, encrypted files are excluded from its semantic index and are not returned in Copilot results, even for users who have permission. Applying such a label is the supported way to prevent Copilot from processing sensitive documents.

Why this answer

Sensitivity labels with encryption can restrict access to documents based on their classification. When a document is labeled 'Highly Confidential' and encrypted, Microsoft 365 Copilot cannot process it because Copilot respects the encryption applied by the label, effectively preventing it from accessing the sensitive content. This is the only configuration that directly controls Copilot's ability to read the content at the file level.

Exam trap

The trap here is that candidates often confuse DLP policies (which control data sharing) with sensitivity labels (which control access and usage), leading them to choose option C, but DLP does not block internal processing by Copilot.

How to eliminate wrong answers

Option A is wrong because retention policies are designed to preserve or delete content based on time, not to control access or processing by Copilot; they do not block Copilot from reading current or older content. Option B is wrong because conditional access policies control user authentication and device access to SharePoint, not the behavior of Copilot as a service principal; Copilot operates under its own service identity and is not subject to user-level conditional access policies. Option C is wrong because DLP policies are used to detect and prevent the sharing of sensitive information, not to block internal processing by Copilot; DLP does not prevent Copilot from reading or summarizing content within the tenant.

118
MCQmedium

An administrator has added the custom domain 'contoso.co.uk' to their Microsoft 365 tenant and verified ownership. Users now need to receive email at @contoso.co.uk. Which DNS record must the administrator add in the public DNS zone to route emails to Exchange Online?

A.Add an MX record pointing to <tenant>.mail.protection.outlook.com
B.Add a CNAME record for autodiscover
C.Add an SPF record
D.Add a DKIM record
AnswerA

The MX record is the authoritative DNS mechanism that routes incoming SMTP mail for a domain. For Microsoft 365, it must be configured to point to <tenant>.mail.protection.outlook.com, the Exchange Online boundary, to ensure external senders deliver messages to your mailboxes. Without this record, email addressed to your domain will not reach Exchange Online, even if all other DNS records are present.

Why this answer

To route email for a custom domain to Exchange Online, you must add an MX record in the public DNS zone that points to the Exchange Online mail exchanger. The correct target is <tenant>.mail.protection.outlook.com, where <tenant> is your initial tenant name (e.g., contoso-com). This MX record tells sending mail servers to deliver messages for @contoso.co.uk to Microsoft's email infrastructure.

Exam trap

The trap here is that candidates confuse DNS records required for email routing (MX) with records required for email security or client discovery (SPF, DKIM, Autodiscover), leading them to select a record that does not actually deliver inbound messages.

How to eliminate wrong answers

Option B is wrong because a CNAME record for autodiscover is used to configure client connectivity (Outlook auto-configuration), not to route inbound email. Option C is wrong because an SPF record is a TXT record that authorizes sending servers and helps prevent spoofing, but it does not direct email delivery. Option D is wrong because a DKIM record is a TXT record used to sign outgoing emails for cryptographic verification, not to route inbound messages.

119
MCQeasy

Your company has a Microsoft 365 E5 subscription. You need to configure multi-factor authentication (MFA) for all users. However, the CEO insists that he should not be prompted for MFA when connecting from the corporate office. What should you do?

A.Use per-user MFA and set the CEO's account to bypass.
B.Disable MFA for the CEO's account.
C.Configure trusted IPs in the MFA service settings.
D.Create a Conditional Access policy that excludes the corporate office named location from requiring MFA.
AnswerD

Create a Conditional Access policy that targets the CEO (or all users) and the cloud apps you want to protect, with a condition that requires MFA. In that policy, add a 'named location' for the corporate office IP ranges and exclude it from the policy's assignment, so MFA is not required when the sign-in originated from that range. This is the correct approach because named locations can be defined with trusted IP ranges, and the exclusion is scoped to the policy rather than applied tenant-wide, preserving MFA protection everywhere else.

Why this answer

Conditional Access is the modern, recommended way to enforce MFA in Microsoft 365 E5, and it supports named locations (trusted IPs) that can be excluded from the MFA requirement. Creating a policy that requires MFA for all users but excludes the corporate office named location satisfies the CEO's requirement while keeping MFA enforced everywhere else.

Exam trap

MS-102 often tests the difference between legacy per-user MFA (with its bypass and trusted IP settings) and Conditional Access — the correct modern answer is always Conditional Access with named locations, not per-user bypass.

How to eliminate wrong answers

Option A is wrong because per-user MFA is the legacy approach and its 'bypass' setting disables MFA entirely for that user, not just from the corporate office — it does not meet the requirement of skipping MFA only at the office. Option B is wrong because disabling MFA for the CEO's account removes protection everywhere, which is a security regression and not what was asked. Option C is wrong because configuring trusted IPs in the legacy per-user MFA service settings is deprecated and does not integrate with Conditional Access; Microsoft now recommends named locations in Conditional Access instead, and the legacy setting is being retired.

120
MCQeasy

Your company has a Microsoft 365 E3 tenant. You need to enable Microsoft Purview Data Loss Prevention (DLP) to prevent sensitive data from being shared externally via email. What must you do first?

A.Create a DLP policy in Microsoft Defender XDR
B.Navigate to the Microsoft Purview compliance portal and create a DLP policy
C.Use Exchange Online PowerShell to configure DLP rules
D.Upgrade to Microsoft 365 E5 or purchase a DLP add-on
AnswerB

Microsoft Purview DLP policies are authored in the compliance portal, so creating one establishes the rule set that detects sensitive data and blocks external email sharing. This is the prerequisite step; the E3 licence already covers the portal, so no additional licensing action is needed.

Why this answer

Microsoft 365 E3 includes DLP capabilities for Exchange Online via the Microsoft Purview compliance portal. Therefore, the correct first step is to navigate to the Microsoft Purview compliance portal and create a DLP policy (option B). Upgrading to E5 or purchasing a DLP add-on (option D) is not required for Exchange Online DLP in E3.

Exam trap

The trap is that candidates may incorrectly assume that E3 lacks DLP capabilities and that an upgrade is required. However, Microsoft 365 E3 includes DLP for Exchange Online, and policies can be created in the compliance portal.

How to eliminate wrong answers

Option A is wrong because creating a DLP policy in Microsoft Defender XDR is not the first step; Defender XDR policies focus on security incidents and threat protection, not data loss prevention, and the tenant lacks the required license. Option B is wrong because navigating to the Microsoft Purview compliance portal and creating a DLP policy is not possible without the E5 or DLP add-on license; the portal will block policy creation or enforcement due to licensing restrictions. Option C is wrong because using Exchange Online PowerShell to configure DLP rules is ineffective without the proper license; PowerShell cannot bypass licensing requirements, and the underlying DLP engine will not enforce the rules.

121
MCQeasy

You are deploying a new Microsoft 365 tenant for a company that has a single domain, contoso.com. You need to verify domain ownership to enable email routing. Which DNS record type must you add to the public DNS zone?

A.CNAME record with 'autodiscover' pointing to 'autodiscover.outlook.com'.
B.SPF record including Microsoft 365 IP addresses.
C.MX record pointing to Microsoft 365.
D.TXT record with a verification code provided by Microsoft 365.
AnswerD

This is the correct method: in the Microsoft 365 admin center you select the domain you want to verify, copy the unique verification code, and publish it as a TXT record at the root of that domain (for example, MS=123456). Microsoft 365 then performs a DNS query for that exact TXT value; when it resolves, the domain is considered verified because only someone with administrative control of the domain's DNS zone could create that record. TXT records are able to carry arbitrary text, which makes them ideal for storing the verification token, and this same mechanism is used for verifying domains in Azure AD as well.

Why this answer

To verify domain ownership in Microsoft 365, you must add a TXT record containing a unique verification code provided by the Microsoft 365 admin center to your public DNS zone. This proves you control the domain, enabling email routing and other services. Other DNS records like CNAME, SPF, or MX are used for service configuration, not ownership verification.

Exam trap

The trap here is that candidates confuse service configuration records (like MX, SPF, or CNAME) with the mandatory verification record, assuming any DNS change proves ownership, but only the TXT record with the specific code satisfies Microsoft 365's domain proof requirement.

How to eliminate wrong answers

Option A is wrong because a CNAME record for 'autodiscover' pointing to 'autodiscover.outlook.com' is used to configure automatic client discovery for Exchange Online, not to verify domain ownership. Option B is wrong because an SPF record specifies authorized sending IP addresses for email authentication and is not used for domain verification. Option C is wrong because an MX record directs email flow to Microsoft 365 but requires prior domain ownership verification to be accepted.

122
MCQhard

A company has 500 users across Sales, Marketing, and IT departments. User objects are synced from on-premises Active Directory to Microsoft Entra ID using Azure AD Connect. Each department requires different Microsoft 365 license plans (e.g., Sales needs E3, Marketing needs Business Premium, IT needs E5). The administrator wants to automatically assign the appropriate license based on the department attribute without manual intervention. Which approach should the administrator use?

A.Create a script that runs daily to sync department values and assign licenses using PowerShell.
B.Configure group-based licensing using Microsoft Entra dynamic groups with rules based on the department attribute.
C.Use Azure AD Connect to filter objects and assign licenses during sync.
D.Manually assign licenses to each user in the Microsoft 365 admin center.
AnswerB

Dynamic groups in Microsoft Entra ID evaluate membership using a rule on the department attribute, so users are automatically added or removed as their department changes. When combined with group-based licensing, a license is provisioned to every member of the group automatically, and it is removed when a user leaves the group. This approach is the recommended Microsoft solution because it scales to thousands of users without manual steps or custom code, and it integrates with Entra ID's inherent license management.

Why this answer

Microsoft Entra ID supports group-based licensing, which allows automatic license assignment to users based on their membership in dynamic groups. By creating dynamic groups with rules that filter on the department attribute (e.g., 'user.department -eq "Sales"'), the administrator can assign the appropriate license plan (E3, Business Premium, E5) to each group, and licenses are automatically applied or removed as users are added or removed from the group, without any manual or scripted intervention.

Exam trap

The trap here is that candidates may confuse Azure AD Connect's attribute filtering or sync capabilities with license assignment, or assume that a PowerShell script is the only automated method, overlooking the native group-based licensing feature that is designed exactly for this scenario.

How to eliminate wrong answers

Option A is wrong because using a script that runs daily introduces unnecessary complexity, potential delays (up to 24 hours), and administrative overhead; it also does not leverage the built-in, real-time license assignment capabilities of Microsoft Entra ID. Option C is wrong because Azure AD Connect is used for syncing identity objects and attributes, not for assigning licenses; filtering objects during sync controls which users are synced, not how licenses are assigned. Option D is wrong because manually assigning licenses to 500 users across three departments is not scalable, error-prone, and violates the requirement for automatic assignment without manual intervention.

123
Multi-Selecthard

Your organization is deploying Windows 11 using Microsoft Intune. You need to ensure that devices are automatically enrolled in Intune when users sign in with their Microsoft Entra ID credentials. Which THREE prerequisites must be met?

Select 3 answers
A.Devices must run Windows 10/11 Home edition.
B.Microsoft Configuration Manager must be deployed.
C.Microsoft Entra ID P1 or P2 license.
D.Devices must be Microsoft Entra joined or hybrid Microsoft Entra joined.
E.MDM user scope must be set to All or Some in Microsoft Entra ID.
AnswersC, D, E

A Microsoft Entra ID P1 or P2 license is required in the tenant to enable the automatic MDM enrollment feature that connects Microsoft Entra ID to Intune. This license tier permits group-based assignment of Intune licenses and allows the MDM auto-enrollment policy to be configured for users. Without P1 or P2, the automatic enrollment setting is not available, even if the user has a standalone Intune license assigned.

Why this answer

Microsoft Entra ID P1 or P2 licenses are required to enable automatic MDM enrollment via Intune. Without these licenses, the MDM authority cannot be set to Intune, and the automatic enrollment policy in Microsoft Entra ID will not function. This licensing requirement ensures that the tenant has the necessary features for conditional access and device management policies.

Exam trap

The trap here is that candidates often confuse the licensing requirement (Entra ID P1/P2) with the need for a separate MDM license like Intune, or mistakenly think that Windows Home edition or Configuration Manager are required for automatic enrollment.

124
MCQeasy

Your organization has a Microsoft 365 E5 tenant. You need to ensure that users are prompted to register for multifactor authentication (MFA) the first time they sign in. Which Microsoft Entra ID policy should you configure?

A.Enable Security defaults
B.Create a Conditional Access policy requiring MFA and enable Microsoft Entra ID Identity Protection to enforce MFA registration
C.Enable combined registration for SSPR and MFA
D.Configure MFA service settings per-user
AnswerB

This combined approach works because Identity Protection's MFA registration policy is a Conditional Access grant control that prompts users to register at their first interactive sign-in, before they can access protected apps. The separate Conditional Access policy requiring MFA for all cloud apps then enforces the actual MFA challenge at every subsequent sign-in, ensuring both registration and ongoing enforcement. This is the modern, recommended method, as it is customizable per user, group, or application and integrates seamlessly with the Conditional Access engine.

Why this answer

Combining a Conditional Access policy that requires MFA with Identity Protection's MFA registration policy ensures users are prompted to register for MFA at first sign-in. The MFA registration policy in Identity Protection specifically enforces that users must register their authentication methods before accessing applications, which triggers the registration prompt on initial authentication.

Exam trap

The trap here is that candidates often confuse the MFA registration policy in Identity Protection with a standard Conditional Access policy that requires MFA, but the registration policy specifically triggers the registration prompt, not the MFA challenge itself.

How to eliminate wrong answers

Option A is wrong because Security defaults is a baseline security feature that enforces MFA for all users but does not provide a granular registration prompt on first sign-in; it applies MFA automatically after registration, not a registration-only trigger. Option C is wrong because combined registration for SSPR and MFA only consolidates the user registration portal for both features; it does not enforce or prompt registration at sign-in. Option D is wrong because configuring MFA service settings per-user is a legacy method that requires manual enablement and does not automatically prompt users to register on first sign-in; it also lacks the integration with Identity Protection for registration enforcement.

125
MCQmedium

A company needs to migrate several shared mailboxes from on-premises Exchange 2016 to Exchange Online. The company plans to keep some user mailboxes on-premises for now. Which migration strategy should they use for the shared mailboxes?

A.Cutover migration
B.Staged migration
C.IMAP migration
D.Hybrid migration
AnswerD

Hybrid migration leverages the Mailbox Replication Service (MRSproxy) in an Exchange hybrid deployment to move mailbox objects, including shared mailboxes, between on-premises and Exchange Online with full coexistence. Because the hybrid configuration establishes synchronization and trusts between the two environments, the shared mailbox's attributes, permissions, and user object are migrated atomically, preserving its type as a shared mailbox in the cloud. This is the only method listed that natively supports moving shared mailboxes, making it the correct answer for the migration scenario.

Why this answer

A hybrid migration is the correct choice because it allows the coexistence of on-premises Exchange 2016 and Exchange Online mailboxes, enabling the selective migration of shared mailboxes while keeping some user mailboxes on-premises. This approach uses the Hybrid Configuration Wizard to establish a secure connection and synchronize directory objects via Azure AD Connect, supporting mailbox moves with the New-MoveRequest cmdlet.

Exam trap

The trap here is that candidates often choose cutover migration because it is simpler, but they overlook the requirement to keep some mailboxes on-premises, which cutover migration cannot accommodate.

How to eliminate wrong answers

Option A is wrong because cutover migration migrates all mailboxes in a single batch and requires all mailboxes to be moved to Exchange Online, which conflicts with the requirement to keep some user mailboxes on-premises. Option B is wrong because staged migration is designed for migrating user mailboxes from on-premises Exchange 2003 or 2007, not Exchange 2016, and it does not support shared mailboxes natively. Option C is wrong because IMAP migration only migrates email data (not calendar, contacts, or tasks) and does not preserve shared mailbox properties or enable coexistence; it is intended for non-Exchange systems.

126
MCQmedium

Your organization has 5,000 users and uses Microsoft 365 E3. You are planning to migrate from on-premises Exchange to Exchange Online. You have already synchronized identities using Microsoft Entra Connect. The CIO wants to ensure that users can continue to access their email if the internet connection to Microsoft 365 is temporarily lost. You need to recommend a solution that provides offline access while minimizing cost and administrative overhead. What should you recommend?

A.Configure Outlook to use Cached Exchange Mode.
B.Implement a hybrid deployment and keep some mailboxes on-premises.
C.Deploy a VPN to ensure connectivity.
D.Enable Exchange Online Archiving for all users.
AnswerA

Cached Exchange Mode (CEM) creates a local copy of the user's mailbox in an Offline Outlook Data (.ost) file, enabling full access to synced folders, messages, calendar items, and contacts even when the device is disconnected from the network. When connectivity is restored, the OST synchronizes incremental changes via HTTPS using autodiscover and MAPI over HTTP, making it the correct solution for maintaining productivity during network outages. It also ensures that changes are queued locally and then propagated to Exchange Online, providing a seamless online/offline experience.

Why this answer

Cached Exchange Mode (CEM) downloads a copy of the user's mailbox to a local .ost file, allowing full access to email, calendar, and contacts even when the internet connection to Microsoft 365 is temporarily lost. This meets the CIO's requirement for offline access with zero additional cost and no administrative overhead, as CEM is a built-in feature of Outlook that is already available with Microsoft 365 E3.

Exam trap

The trap here is that candidates often confuse 'offline access' with 'high availability' or 'redundancy,' leading them to choose a hybrid deployment (Option B) or a VPN (Option C), when the simplest and most cost-effective solution is a client-side caching feature already included in the subscription.

How to eliminate wrong answers

Option B is wrong because implementing a hybrid deployment with some mailboxes on-premises increases cost (additional on-premises servers, licensing, and maintenance) and administrative overhead, and does not guarantee offline access for users whose mailboxes are moved to Exchange Online. Option C is wrong because deploying a VPN does not provide offline email access; it only attempts to maintain connectivity, and if the internet is lost, the VPN connection also fails. Option D is wrong because Exchange Online Archiving is a cloud-based feature that stores archived email in the cloud, not locally, so it does not provide offline access and adds cost without solving the stated requirement.

127
MCQmedium

Your organization uses Microsoft Entra ID. You want to enforce Multi-Factor Authentication (MFA) for all users. You have already configured Conditional Access policies. However, some users are still able to sign in without MFA. What should you check first?

A.Ensure all users have registered for MFA.
B.Verify that the Conditional Access policy is enabled.
C.Confirm that all users are included in the policy's user assignment.
D.Check if there are any exclusions configured.
AnswerC

The user assignment is the principal scope control in a Conditional Access policy. For MFA to apply to every user, the policy's 'Include' list must target 'All users' or a group containing all users. If some users are omitted, they will bypass the policy entirely regardless of other settings. Confirming this assignment is the critical diagnostic step.

Why this answer

The most common reason a Conditional Access policy fails to enforce MFA is that not all users are included in the policy's user assignment. If the policy targets only a subset of users (e.g., a test group), users outside that scope will bypass MFA entirely. The first troubleshooting step is to verify that the policy's 'Users and groups' assignment includes 'All users' or the specific groups covering all users.

Exam trap

The trap here is that candidates often jump to checking exclusions or MFA registration status first, overlooking the fundamental requirement that the policy must actually apply to the user via its assignment scope.

How to eliminate wrong answers

Option A is wrong because MFA registration is a prerequisite for MFA prompts, but even if users are registered, the Conditional Access policy must be correctly scoped to enforce MFA; unregistered users would simply be blocked or prompted to register, not allowed to sign in without MFA. Option B is wrong because if the policy were disabled, no users would be prompted for MFA, but the question states some users are still able to sign in without MFA, implying the policy is enabled but not applying to those users. Option D is wrong because checking exclusions is a valid step, but it is secondary to verifying that all users are included in the policy's assignment; exclusions only matter if users are already included.

128
MCQeasy

An administrator wants to add a second custom domain, 'contoso-europe.com', to their existing Microsoft 365 tenant. The domain 'contoso.com' is already verified. What is the first step the administrator should take?

A.Add the domain in the Microsoft 365 admin center
B.Create a DNS TXT verification record
C.Update the UPN suffixes for users
D.Create a new Microsoft 365 tenant
AnswerA

Adding the domain in the Microsoft 365 admin center is the mandatory initial step. Navigate to Settings → Domains → Add domain, enter the domain name, and the wizard will present verification instructions and the exact TXT record you need. This action creates the domain object in the tenant and initiates the verification process, which is a prerequisite for later DNS and UPN configuration.

Why this answer

Before any DNS records can be created or users can be assigned the new domain, the domain must first be added to the tenant in the Microsoft 365 admin center (or via the Microsoft Graph/Exchange admin center). This step registers the domain in the tenant and generates the required verification TXT record values. Only after the domain is added can the administrator proceed to DNS verification and then configure services.

Exam trap

The trap is that candidates jump straight to DNS record creation because that feels like the 'technical' first step, but the exam expects you to know that the domain must be added to the tenant first so Microsoft can generate the unique verification token.

How to eliminate wrong answers

Option B is wrong because creating the DNS TXT record is the second step — you cannot know the exact TXT value (e.g., MS=msXXXXXXX) until the domain has been added to the tenant, which generates that value. Option C is wrong because updating UPN suffixes is a later step performed after the domain is verified and is used to assign user principal names to the new domain, not to initiate the add-domain workflow. Option D is wrong because creating a new tenant is unnecessary and would actually prevent the new domain from being associated with the existing tenant's users and services — a single tenant can host many verified domains.

129
MCQhard

Refer to the exhibit. A Conditional Access policy is created in Microsoft Entra ID. The policy targets the Office 365 app (which includes Exchange Online). You have 1000 users assigned. What is the immediate effect of this policy on users who are currently signed in?

A.All high-risk users are immediately blocked from accessing email.
B.No immediate effect; users will be blocked on their next sign-in attempt.
C.The policy is invalid because the Office 365 app does not support block.
D.Only users with a sign-in risk of high are blocked.
AnswerB

Conditional Access is an evaluation-time access control: when a user attempts to sign in, Azure AD checks the policy conditions—such as the assigned Office 365 app and the user-risk level—and then applies the Block grant control. Immediately after the policy is saved, there is no background task that scans and revokes existing sessions. The policy only takes effect on the next interactive or non-interactive sign-in attempt, at which point a high user-risk user will be denied access. This is why the policy has no immediate effect and the block occurs at the next sign-in.

Why this answer

Conditional Access policies in Microsoft Entra ID are evaluated at the time of sign-in. They do not terminate existing sessions. Therefore, users who are already signed in will not be affected until their next authentication attempt, at which point the policy's block action will be enforced.

Exam trap

Microsoft often tests the misconception that Conditional Access policies apply immediately to active sessions, when in fact they only take effect on the next sign-in attempt unless combined with session controls like sign-in frequency or continuous access evaluation.

How to eliminate wrong answers

Option A is wrong because the policy targets all users assigned, not only high-risk users; also, Conditional Access does not immediately terminate active sessions. Option C is wrong because the Office 365 app (which includes Exchange Online) fully supports the block grant control in Conditional Access policies. Option D is wrong because the policy does not specify a sign-in risk condition; it applies to all targeted users regardless of risk level.

130
MCQmedium

An administrator recently added a custom domain 'tailspintoys.com' to their Microsoft 365 tenant and verified it. They now need to configure the domain so that all recipient email addresses for 'info@tailspintoys.com' are delivered to a shared mailbox in Exchange Online. The domain is currently set as internal relay. What should the administrator do first to route email for this domain to Exchange Online?

A.Update the MX record at the DNS registrar to point to Exchange Online
B.Change the domain type from 'Internal relay' to 'Authoritative' in Exchange admin center
C.Create the shared mailbox 'info@tailspintoys.com' in Exchange Online
D.Disable the internal relay option for the domain in the Microsoft 365 admin center
AnswerB

In the Exchange admin center, open Mail flow > Accepted domains, select the tailspintoys.com entry, and set its type to Authoritative. This tells Exchange Online that it is the only authorized mail system for that domain, so it will accept all inbound messages and attempt to deliver them to valid mailboxes in the organization, while generating non-delivery reports for unknown recipients. This is the required first configuration task because neither creating recipients nor updating MX records will make Exchange Online the owner of the address space until the accepted domain type is changed.

Why this answer

When a domain is set to 'Internal relay' in Exchange Online, the service expects to relay messages to an on-premises server for that domain. To have Exchange Online accept and deliver messages directly to a shared mailbox (or any hosted recipient), the domain must be changed to 'Authoritative'. This tells Exchange Online that it is the final destination for all recipients in that domain, enabling local delivery.

Exam trap

The trap here is that candidates often think updating the MX record (Option A) is the first step to route email to Exchange Online, but they overlook that the domain type must be changed to 'Authoritative' first; otherwise, Exchange Online will not deliver messages to cloud recipients even after the MX record is pointed correctly.

How to eliminate wrong answers

Option A is wrong because updating the MX record to point to Exchange Online is necessary for mail flow from the internet, but it does not change how Exchange Online treats the domain internally; if the domain remains 'Internal relay', Exchange Online will still attempt to relay messages for that domain to an on-premises server rather than delivering locally. Option C is wrong because creating the shared mailbox is a subsequent step; the domain must first be set to 'Authoritative' so that Exchange Online recognizes the recipient as local and can deliver to it. Option D is wrong because disabling the internal relay option in the Microsoft 365 admin center is not a valid action; the domain type is configured in the Exchange admin center, not the Microsoft 365 admin center, and simply removing the relay setting does not change the domain to authoritative.

131
MCQmedium

Refer to the exhibit. You are creating a custom role in Microsoft Entra ID for helpdesk staff. What can users assigned this role do?

A.Read user properties and reset passwords
B.Read security groups and reset passwords
C.Create new users and reset passwords
D.Read user properties and assign licenses
AnswerA

This option is correct because the exhibit's custom role permission list contains exactly two entries: 'Read user properties' and 'Reset passwords.' These permissions align precisely with the task of viewing a user's profile and resetting their password, with no extra administrative rights such as creating users or assigning licenses. Therefore, the role description 'Read user properties and reset passwords' accurately and completely reflects the configured permissions.

Why this answer

The custom role shown in the exhibit includes only the 'Users' > 'Basic' > 'Read' permission and the 'Authentication' > 'Passwords' > 'Reset password' permission. This combination allows helpdesk staff to read basic user properties (such as display name, user principal name, and job title) and reset user passwords. It does not grant write access to other user attributes, security groups, or license assignments.

Exam trap

The trap here is that candidates often assume 'reset password' implies full user management or that reading user properties automatically includes reading groups, but Microsoft Entra ID separates these into distinct permission scopes.

How to eliminate wrong answers

Option B is wrong because reading security groups requires the 'Groups' > 'Read' permission, which is not included in this custom role. Option C is wrong because creating new users requires the 'Users' > 'Create' permission, which is not granted here. Option D is wrong because assigning licenses requires the 'Users' > 'Assign license' permission, which is also absent from this role.

132
MCQhard

Your organization uses Microsoft 365 and has enabled Microsoft Entra ID P2 licenses. You need to configure automatic user provisioning for a third-party SaaS application that supports SCIM 2.0. What should you do first in the Microsoft Entra admin center?

A.Add the application from the gallery, then configure provisioning.
B.Configure provisioning in 'App registrations'.
C.Navigate to 'Enterprise applications' and create a new application.
D.Use the 'App registrations' blade to register the app.
AnswerA

This is the only correct sequence for a gallery application that supports SCIM provisioning. You must first add the application from the Azure AD gallery, which creates an enterprise application object with the vendor's prebuilt provisioning template. After it is added, you open the app's Provisioning blade, set the provisioning mode to Automatic, enter the SCIM endpoint URL and an authentication token supplied by the SaaS vendor, and then save and test the connection. This is the standard, supported workflow; provisioning settings and attribute mappings are made available only after the gallery app has been installed.

Why this answer

To configure automatic user provisioning for a third-party SaaS application that supports SCIM 2.0, you must first add the application from the Microsoft Entra gallery. This action creates an enterprise application object in your tenant, which is required to access the provisioning configuration blade. Only after adding the gallery application can you configure the provisioning settings, including the SCIM endpoint URL and token, to enable automated user lifecycle management.

Exam trap

The trap here is that candidates confuse 'App registrations' (for custom app development) with 'Enterprise applications' (for SaaS app provisioning), leading them to choose an option that registers an app instead of adding a gallery application.

How to eliminate wrong answers

Option B is wrong because 'App registrations' is used for custom-developed applications that use OAuth/OpenID Connect, not for provisioning configuration of gallery or non-gallery SaaS apps. Option C is wrong because 'Enterprise applications' does not have a 'create new application' option; you add applications from the gallery or create a non-gallery app via the 'New application' button, but the correct first step is specifically to add from the gallery. Option D is wrong because registering an app in 'App registrations' creates a service principal for a custom app, not the provisioning configuration for a third-party SaaS app that supports SCIM.

133
Multi-Selectmedium

Your organization is planning to migrate from on-premises Exchange to Exchange Online. You need to choose a migration strategy. Which TWO statements about migration methods are correct?

Select 2 answers
A.A hybrid migration requires that you do not synchronize on-premises Active Directory with Microsoft Entra ID.
B.A minimal hybrid deployment allows you to manage mailboxes in both on-premises and Exchange Online.
C.A staged migration can be used to migrate mailboxes from Exchange 2019 to Exchange Online.
D.A cutover migration is suitable for organizations with fewer than 2000 mailboxes.
E.An IMAP migration migrates email, contacts, and calendar data.
AnswersB, D

A minimal hybrid deployment deliberately configures just enough coexistence to support mailbox management across both environments. Even at this baseline, the Hybrid Configuration Wizard creates a management relationship so administrators can view and move mailboxes from the on-premises Exchange admin center or the Exchange Online admin center, and mail flow works between the two. This makes it a valid and lightweight method for both coexistence and migration, so the statement is correct.

Why this answer

A minimal hybrid deployment uses Azure AD Connect to synchronize on-premises Active Directory with Microsoft Entra ID, enabling centralized management of mailboxes across both environments. This allows administrators to manage on-premises and Exchange Online mailboxes from a single Exchange admin center, making option B correct.

Exam trap

The trap here is that candidates often confuse 'minimal hybrid' with 'no synchronization,' but Microsoft requires directory synchronization for any hybrid deployment, and they may also incorrectly assume IMAP migration can handle calendar and contact data, which it cannot.

134
MCQhard

Your company is migrating from on-premises Exchange to Exchange Online. You have configured a hybrid deployment. During testing, you notice that free/busy information is not being shared between on-premises and cloud users. All other hybrid features work. What is the most likely cause?

A.The organization relationship between the on-premises and cloud tenants is missing or misconfigured.
B.Azure AD Connect has not been configured with the correct synchronization scope.
C.The on-premises firewall is blocking traffic to the Exchange Online endpoints.
D.OAuth authentication is not configured between on-premises and Exchange Online.
AnswerA

In Exchange hybrid deployments, free/busy sharing depends on a specific organization relationship between the on-premises Exchange organization and the Exchange Online tenant. This relationship defines the federated trust, sharing domain, and the availability service endpoints, so if it is missing or misconfigured, the Availability service cannot resolve cross-premises calendar requests even though mail routing remains functional. The organization relationship is the control plane for calendaring, not for transport, so its absence presents exactly the symptom described: messages flow but free/busy fails. Verify the relationship's sharing domain and the Autodiscover URLs to restore availability.

Why this answer

The organization relationship defines the trust and sharing settings between on-premises Exchange and Exchange Online tenants, specifically for free/busy information. Since all other hybrid features (e.g., mail flow, mailbox moves) work, the issue is isolated to the organization relationship, which must be configured on both sides to enable cross-premises calendar availability queries.

Exam trap

The trap here is that candidates assume OAuth is required for all hybrid features, but Microsoft specifically decouples free/busy sharing from OAuth in hybrid scenarios, making the organization relationship the primary culprit when only calendar availability fails.

How to eliminate wrong answers

Option B is wrong because Azure AD Connect synchronization scope controls identity and attribute sync (e.g., users, groups), not free/busy sharing; incorrect scope would cause missing or mismatched user objects, not a failure of free/busy queries specifically. Option C is wrong because firewall blocks would affect all hybrid traffic (e.g., SMTP, Autodiscover, EWS), not just free/busy; since other features work, a firewall issue is unlikely. Option D is wrong because OAuth authentication is required for modern hybrid features like archive access and eDiscovery, but free/busy sharing can function with legacy organization relationship settings using the AvailabilityAddressSpace or IntraOrganizationConnector; OAuth is not strictly necessary for basic free/busy.

135
MCQeasy

An administrator needs to add a custom domain 'contoso.org' to their Microsoft 365 tenant. They have already purchased the domain and have access to the DNS registrar. What is the first step the administrator should perform in the Microsoft 365 admin center?

A.Add a TXT record in the public DNS zone
B.Add the domain in the Microsoft 365 admin center
C.Configure email routing (MX record)
D.Create user accounts with the new domain
AnswerB

The first action is adding the custom domain in the Microsoft 365 admin center, which creates a domain object in Azure AD and marks it as unverified. This step generates the exact DNS records (including the unique TXT verification string) that you will need to prove ownership. Once the domain is added, you can retrieve and then add those records — but the addition in the admin center must happen first.

Why this answer

The first step to add a custom domain to a Microsoft 365 tenant is to initiate the domain addition process in the Microsoft 365 admin center. This triggers Microsoft to generate the unique verification TXT record that must be published in the public DNS zone. Without first adding the domain in the admin center, the administrator would not know the specific verification string required for the TXT record.

Exam trap

The trap here is that candidates often confuse the sequence of steps and think that adding a DNS record (like TXT or MX) is the first action, when in reality the domain must first be registered in the admin center to obtain the required verification token.

How to eliminate wrong answers

Option A is wrong because adding a TXT record in the public DNS zone is the second step, performed after the domain has been added in the admin center to obtain the unique verification value. Option C is wrong because configuring email routing (MX record) is a later step that occurs after domain verification is complete and the domain is set as the primary email domain. Option D is wrong because creating user accounts with the new domain requires the domain to first be verified and added to the tenant; otherwise, the domain is not recognized by Azure AD.

136
Multi-Selectmedium

Your organization is planning to migrate from on-premises Active Directory to Microsoft Entra ID using Azure AD Connect. You need to ensure that password synchronization is enabled. Which TWO components are required for password synchronization to work?

Select 2 answers
A.Azure AD Connect with password hash synchronization selected.
B.Active Directory Federation Services (AD FS).
C.Password Writeback enabled.
D.Microsoft Identity Manager (MIM).
E.Microsoft Entra ID service to process synchronization.
AnswersA, E

Azure AD Connect is the official Microsoft synchronization tool that connects on-premises Active Directory with Microsoft Entra ID. When password hash synchronization (PHS) is selected, Azure AD Connect retrieves a one-way hash (using MD5, SHA-256, and PBKDF2) of each user's on-premises password and securely transfers it to Entra ID. This allows users to authenticate to cloud services using the same password without any federation infrastructure, and it is the core mechanism that satisfies the migration requirement.

Why this answer

Azure AD Connect with password hash synchronization (PHS) selected is the component that hashes the on-premises Active Directory password and synchronizes it to Microsoft Entra ID. Option E is correct because the Microsoft Entra ID service must process the incoming password hashes and store them in the cloud directory, enabling authentication against Entra ID. Without both the local sync engine (Azure AD Connect) and the cloud-side service, password synchronization cannot function.

Exam trap

The trap here is that candidates often confuse Password Writeback (a separate feature for cloud-to-on-premises password changes) as a prerequisite for password synchronization, when in fact it is an optional add-on that is not required for the one-way sync of password hashes from on-premises to the cloud.

137
MCQeasy

A company has an existing Microsoft 365 tenant with the verified custom domain 'contoso.com'. The administrator now wants to add a second custom domain, 'contoso-europe.com', to the same tenant. What is the first step the administrator should take?

A.Add the domain in the Microsoft 365 admin center.
B.Add a TXT verification record in the public DNS zone for 'contoso-europe.com'.
C.Add an MX record pointing to Exchange Online in the public DNS zone for 'contoso-europe.com'.
D.Contact Microsoft support to enable the domain addition feature.
AnswerA

Adding the domain in the Microsoft 365 admin center is the first step, which generates the required TXT or MX verification record. Only after DNS verification succeeds can the administrator create users, mailboxes and configure services for contoso-europe.com.

Why this answer

The first step to add a second custom domain to an existing Microsoft 365 tenant is to initiate the domain addition process in the Microsoft 365 admin center. This triggers the system to generate the unique TXT verification record that must be added to the public DNS zone to prove ownership of the domain. Without first adding the domain in the admin center, the administrator would not know the specific verification value required for the DNS record.

Exam trap

The trap here is that candidates often assume the first step is to create a DNS record (like TXT or MX) directly, but the correct sequence requires initiating the domain addition in the admin center first to obtain the necessary verification value.

How to eliminate wrong answers

Option B is wrong because adding a TXT verification record in the public DNS zone is the second step, not the first; the administrator must first add the domain in the admin center to obtain the unique verification string. Option C is wrong because adding an MX record pointing to Exchange Online is a post-verification step used to route email, and it is not required for domain ownership verification. Option D is wrong because Microsoft 365 allows domain addition without contacting support; the feature is enabled by default for all tenants with verified custom domains.

138
MCQmedium

Your organization has a Microsoft 365 E5 tenant with 10,000 users. You need to ensure that when a user is detected as high-risk by Microsoft Entra ID Protection, the user is automatically blocked from accessing sensitive SharePoint sites. The solution should minimize administrative overhead. What should you do?

A.Create a Conditional Access policy targeting high-risk users, apply to SharePoint, and set 'Block access' or 'Use app enforced restrictions'.
B.Create a session policy in Microsoft Defender for Cloud Apps to block high-risk users from accessing SharePoint.
C.Configure a user risk policy in Microsoft Entra ID Protection to block sign-ins for high-risk users.
D.Deploy Microsoft Sentinel and create a custom analytics rule to trigger an automated response via Logic App.
AnswerA

Conditional Access policies natively consume Entra ID Protection risk signals. By selecting 'High risk' under User risk and assigning the SharePoint cloud app, you can enforce access controls directly: 'Block access' fully prevents access, while 'Use app enforced restrictions' applies SharePoint's built-in restricted-access user policy. This is the most straightforward, scenario-specific configuration for preventing high-risk users from reaching SharePoint.

Why this answer

A Conditional Access (CA) policy can directly target 'High risk' users (via Microsoft Entra ID Protection risk detection) and apply to SharePoint. By setting the grant control to 'Block access' or 'Use app enforced restrictions', you automatically block or restrict access to sensitive SharePoint sites without manual intervention, minimizing administrative overhead. This integrates natively with Microsoft 365 and requires no additional services or custom scripting.

Exam trap

The trap here is that candidates often confuse a user risk policy in Entra ID Protection (which blocks all sign-ins globally) with a Conditional Access policy (which can target specific applications like SharePoint), leading them to choose Option C instead of A.

How to eliminate wrong answers

Option B is wrong because a session policy in Microsoft Defender for Cloud Apps (MCAS) can only monitor or control access in real time after the user is already authenticated; it does not natively block access based on Entra ID Protection risk level without additional configuration, and it introduces extra overhead. Option C is wrong because a user risk policy in Microsoft Entra ID Protection blocks sign-ins globally (i.e., prevents authentication entirely), which is too broad and would block the user from all applications, not just sensitive SharePoint sites. Option D is wrong because deploying Microsoft Sentinel and creating a custom analytics rule with a Logic App is overly complex and introduces significant administrative overhead, violating the 'minimize administrative overhead' requirement; the native CA policy is simpler and more efficient.

139
MCQmedium

The exhibit shows a DLP policy configuration. A user reports that they cannot share a document containing a credit card number from OneDrive for Business. However, the document was shared successfully last week. What is the most likely reason for the change?

A.The DLP policy was recently deployed or updated.
B.The DLP policy requires administrator override for sharing.
C.The DLP policy is applied only to SharePoint Online, not OneDrive.
D.The DLP policy does not include Microsoft Teams.
AnswerA

When a Microsoft Purview DLP policy with a Block external-sharing action is newly deployed or updated, the policy engine starts evaluating new sharing operations from that point forward. In this scenario the user's earlier successful share almost certainly occurred when no restrictive policy was active, and the current attempt to share another link is now being blocked by the newly enforced rule. This timing makes a recent deployment or update the most plausible explanation for a sudden change from permitted to blocked external sharing.

Why this answer

The most likely reason is that the DLP policy was recently deployed or updated. DLP policies in Microsoft 365 are evaluated in near real-time, and a newly deployed or modified policy will immediately enforce its rules on content sharing. Since the document was shared successfully last week, the policy change is the most plausible cause for the sudden block.

Exam trap

The trap here is that candidates may assume DLP policies are static and only apply to new content, but Microsoft 365 DLP policies are dynamic and can affect existing shares when deployed or updated.

How to eliminate wrong answers

Option B is wrong because DLP policies do not require an administrator override for sharing; they either block or allow sharing based on policy rules, and an override is an optional feature that must be explicitly configured. Option C is wrong because DLP policies in Microsoft 365 can be applied to both SharePoint Online and OneDrive for Business, and the exhibit shows a policy that includes OneDrive. Option D is wrong because the question is about sharing from OneDrive for Business, not Microsoft Teams, and the policy's inclusion of Teams is irrelevant to the reported issue.

140
MCQhard

Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that automatically blocks downloads of files containing sensitive information from SharePoint Online to unmanaged devices. What type of policy should you create?

A.Session policy
B.Microsoft Purview Data Loss Prevention policy
C.Activity policy
D.File policy
AnswerA

Session policies apply real-time controls during a user session, including blocking downloads of files containing sensitive information from SharePoint Online to unmanaged devices. Access and activity policies cannot enforce this inline download restriction, so a session policy is required.

Why this answer

A session policy in Microsoft Defender for Cloud Apps is used to enforce real-time controls on user sessions, including blocking downloads of files with sensitive information from SharePoint Online to unmanaged devices. Session policies leverage Conditional Access App Control to proxy the session and apply DLP-like controls.

Exam trap

MS-102 often tests the distinction between session policies (real-time, proxy-based controls) and activity policies (alerting/governance) or Purview DLP policies (data-centric, not session-based).

How to eliminate wrong answers

Option B is wrong because a Microsoft Purview DLP policy can block sharing or downloading in some contexts, but for real-time session control with unmanaged devices, Defender for Cloud Apps session policies are the correct tool. Option C is wrong because an activity policy is used for alerting or governance actions based on user activities, not for real-time blocking of downloads. Option D is wrong because a file policy in Defender for Cloud Apps is used for malware detection and file labeling, not for blocking downloads based on sensitivity.

141
MCQeasy

Your company is using Microsoft 365 Business Premium. You want to ensure that all company-owned Windows 10 devices are automatically upgraded to Windows 11 when it becomes available through Windows Update. What should you configure?

A.Create a Windows 10 update ring policy in Intune that deploys quality updates.
B.Create a feature update policy for Windows 10 devices in Intune, targeting the Windows 11 version.
C.Create a device compliance policy in Intune that requires Windows 11.
D.Configure a Windows 11 readiness assessment in Microsoft Intune.
AnswerB

A feature update policy is the Intune-native mechanism to deploy a specific Windows feature update version, and by targeting the Windows 11 version, you instruct eligible Windows 10 devices to upgrade to Windows 11. This policy leverages Windows Update for Business to install the chosen feature update and then keeps devices on that version until you change the policy. Unlike an update ring or compliance policy, this is an actual remediation action that performs the in-place OS upgrade.

Why this answer

A feature update policy in Intune is specifically designed to upgrade Windows devices from one version to another, such as from Windows 10 to Windows 11. By targeting the Windows 11 version in this policy, you ensure that eligible Windows 10 devices automatically receive the upgrade when it becomes available via Windows Update. This is the correct mechanism for controlling OS version upgrades in a Microsoft 365 Business Premium environment.

Exam trap

The trap here is that candidates often confuse update ring policies (which handle quality updates and deferral settings) with feature update policies (which are required for OS version upgrades), leading them to select option A instead of B.

How to eliminate wrong answers

Option A is wrong because a Windows 10 update ring policy for quality updates only manages monthly cumulative and security patches, not feature upgrades like moving from Windows 10 to Windows 11. Option C is wrong because a device compliance policy enforces security and configuration requirements on devices that are already enrolled, but it cannot trigger an OS upgrade; it only reports non-compliance if the OS version does not match the policy. Option D is wrong because a Windows 11 readiness assessment in Intune only evaluates hardware compatibility and provides a report, but it does not configure or deploy the actual upgrade to devices.

142
MCQmedium

Your organization uses Microsoft 365 Defender for Office 365. You need to ensure that phishing emails reported by users are automatically submitted for analysis in Microsoft Defender XDR. What should you configure?

A.Modify the anti-phishing policy to include user-reported submissions.
B.Use the Attack simulation training to collect user reports.
C.Enable Safe Attachments policy to automatically submit reported messages.
D.Configure the User-reported messages settings in the Microsoft 365 Defender portal.
AnswerD

Configuring the User-reported messages settings in the Microsoft 365 Defender portal is the correct approach because this setting controls the end-user reporting experience and how reported messages are submitted: to Microsoft for automated analysis, to a designated internal mailbox for manual triage, or to both. It also integrates with the Submission portal, enabling admins to view, analyze, and take action on user-reported messages. This is the sole central configuration point that governs user-reported submissions for analysis in Defender for Office 365.

Why this answer

The User-reported messages settings in the Microsoft 365 Defender portal allow you to configure how user-reported phishing emails are handled. By enabling automatic submission to Microsoft for analysis, you ensure that reported messages are sent directly to the Microsoft security team for threat intelligence and policy tuning. This is the correct setting because it specifically controls the submission behavior for user-reported messages in Defender for Office 365.

Exam trap

The trap here is that candidates often confuse the anti-phishing policy (which handles detection settings) with the User-reported messages settings (which handles submission of user-reported emails), leading them to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because the anti-phishing policy controls protection settings like spoof intelligence and impersonation detection, not the submission of user-reported messages for analysis. Option B is wrong because Attack simulation training is used to create and manage simulated phishing campaigns, not to automatically submit real user-reported emails to Microsoft. Option C is wrong because Safe Attachments policy handles the scanning of email attachments in a sandbox environment, not the submission of user-reported messages for analysis.

143
MCQeasy

Your company has a Microsoft 365 E5 tenant. You need to ensure that all external emails are marked with a warning banner at the top of the email body. What should you configure?

A.A Safe Attachments policy in Microsoft Defender for Office 365.
B.External email tagging in the Microsoft 365 Defender portal.
C.A DLP policy with a sensitive information type.
D.A mail flow rule (transport rule) to add a disclaimer.
AnswerD

A mail flow rule (transport rule) in Exchange Online can apply a disclaimer to emails that meet specified conditions, such as being sent from an external sender. This rule can append a customized HTML banner to the message header or footer, which is exactly the visual warning required. This is the correct method for adding a disclaimer to external emails.

Why this answer

A mail flow rule (transport rule) in Exchange Online can be configured to prepend a disclaimer (warning banner) to the body of all external emails. This is the only mechanism that directly modifies the email body content for inbound or outbound messages based on sender/recipient criteria, such as when the sender is external to the organization.

Exam trap

The trap here is that candidates confuse 'external email tagging' (which adds a header or subject prefix) with adding a visible banner inside the email body, leading them to choose Option B instead of the correct mail flow rule.

How to eliminate wrong answers

Option A is wrong because Safe Attachments policies in Microsoft Defender for Office 365 are designed to detect and block malicious attachments, not to add visual warning banners to email bodies. Option B is wrong because External email tagging in the Microsoft 365 Defender portal adds an external tag to the email subject line or as a header, not a banner within the email body. Option C is wrong because a DLP policy with a sensitive information type is used to detect and protect sensitive data (e.g., credit card numbers) and can apply actions like blocking or notifying, but it cannot add a custom warning banner to the top of the email body.

144
MCQhard

Your company is planning to adopt Microsoft Copilot for Microsoft 365. The security team is concerned about data leakage. What must you implement to ensure that Copilot respects your organization's sensitivity labels and data classification?

A.Use Microsoft Defender for Cloud Apps to control Copilot
B.Configure Data Loss Prevention (DLP) policies
C.Deploy Microsoft Purview Information Protection with sensitivity labels
D.Enable Customer Lockbox
AnswerC

Deploying Microsoft Purview Information Protection with sensitivity labels is correct because Copilot respects these labels as the core data classification signal across files, emails, SharePoint sites, and Teams messages. When a label is applied, Copilot inherits the label's encryption and permission settings, and it either restricts content from being used in a prompt or adds the appropriate label/visual markings to its generated output. This gives organizations a direct way to ensure Copilot does not leak sensitive or confidential information, fulfilling the label-aware protection requirement.

Why this answer

Microsoft Purview Information Protection with sensitivity labels is the correct answer because Copilot for Microsoft 365 uses these labels to enforce data governance at the content level. When a sensitivity label is applied to a document or email, Copilot respects that label's encryption, marking, and access restrictions, preventing the model from generating responses that leak classified data. This is the foundational mechanism for ensuring Copilot adheres to your organization's data classification policies.

Exam trap

The trap here is that candidates often confuse DLP policies (which monitor and block data in transit or at rest) with sensitivity labels (which define and enforce data classification at the content level), leading them to choose DLP as the solution for controlling Copilot's behavior.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps is a CASB (Cloud Access Security Broker) that provides visibility and control over cloud app usage, but it does not directly enforce sensitivity labels within Copilot's processing pipeline. Option B is wrong because Data Loss Prevention (DLP) policies detect and prevent sharing of sensitive data after it is created, but they do not control how Copilot accesses or uses labeled content at the time of generation. Option D is wrong because Customer Lockbox provides a control mechanism for Microsoft support personnel to access your data, but it has no role in governing how Copilot respects sensitivity labels or classification.

145
MCQeasy

Your organization is deploying Microsoft 365 for a multinational company. You need to ensure users in different regions authenticate against the nearest Microsoft Entra ID endpoint for performance. What should you configure?

A.Add the appropriate regional subdomain (e.g., us.contoso.com) as a custom domain.
B.No additional configuration is required; Microsoft Entra ID automatically routes to the nearest endpoint.
C.Create a conditional access policy to route authentication to the nearest region.
D.Configure a traffic manager profile in Azure to route authentication requests.
AnswerB

No additional configuration is required because Microsoft Entra ID operates a globally distributed set of authentication front ends that are automatically selected through Microsoft's internal load balancing and DNS infrastructure. When a user signs in, their client resolves the Microsoft-managed login endpoint and is directed to the closest available regional service while the request is then handled consistently with the tenant's home instance. This routing is intrinsic to the platform and designed to optimize latency and resilience for multinational organizations without any tenant-side setup.

Why this answer

Microsoft Entra ID (formerly Azure AD) uses a global anycast network to automatically route authentication requests to the nearest available endpoint based on DNS resolution and network latency. No additional configuration is required because Entra ID's infrastructure is designed to provide optimal performance globally without manual traffic management.

Exam trap

The trap here is that candidates often overthink performance optimization and assume manual configuration (like custom domains or traffic managers) is needed, when Microsoft Entra ID's built-in anycast routing automatically handles regional proximity without any tenant-side setup.

How to eliminate wrong answers

Option A is wrong because adding a regional subdomain as a custom domain does not affect authentication routing; custom domains are used for user principal name (UPN) suffixes and email addresses, not for directing traffic to regional endpoints. Option C is wrong because Conditional Access policies control access based on conditions like location or device state, not the physical routing of authentication traffic to a nearest region. Option D is wrong because Azure Traffic Manager is used for load-balancing traffic to custom endpoints (e.g., web apps), but Microsoft Entra ID's authentication endpoints are managed by Microsoft and cannot be redirected via a Traffic Manager profile.

146
MCQmedium

An organization has registered the domain contoso.com and added it to their Microsoft 365 tenant. What is the next step to use this domain for user email addresses?

A.Add a DNS TXT record provided by Microsoft to the domain registrar
B.Create user accounts with the new domain
C.Configure Exchange Online connectors
D.Set up MX records for email routing
AnswerA

Domain ownership verification in Microsoft 365 is performed by adding the exact TXT record—containing a unique verification string generated in the Microsoft 365 admin center—to the domain's public DNS zone at the registrar. Microsoft periodically queries the TXT record for that domain; when the value matches, the domain is marked as verified and becomes an accepted domain. This must complete successfully before any user accounts, mail routing, or other service records can be associated with the custom domain.

Why this answer

After adding a custom domain to Microsoft 365, the domain's ownership must be verified by adding a specific DNS TXT record provided by Microsoft at the domain registrar. This verification proves you control the domain and is a prerequisite before you can assign user email addresses or configure other DNS records like MX. Without this step, Microsoft 365 will not trust the domain for email routing.

Exam trap

The trap here is that candidates often confuse domain verification (TXT record) with mail routing (MX record) and assume MX records are the immediate next step, but Microsoft 365 requires ownership proof before any DNS-based services can be configured.

How to eliminate wrong answers

Option B is wrong because creating user accounts with the new domain before verification will fail; Microsoft 365 rejects unverified domains for user creation. Option C is wrong because configuring Exchange Online connectors is an advanced step for hybrid or third-party mail flow, not the immediate next step after adding a domain. Option D is wrong because setting up MX records for email routing is done after domain verification, as MX records are used to direct incoming mail and require a verified domain to function correctly.

147
MCQeasy

An administrator needs to configure the default anti-spam policy for all users in the Microsoft 365 Defender portal. Where should the administrator navigate to find these settings?

A.Email & collaboration > Policies & rules > Threat policies > Anti-spam
B.Email & collaboration > Policies & rules > Threat policies > Anti-phishing
C.Email & collaboration > Policies & rules > Threat policies > Anti-malware
D.Email & collaboration > Policies & rules > Threat policies > Safe Attachments
AnswerA

The Anti-spam section in the Microsoft 365 Defender portal (Email & collaboration > Policies & rules > Threat policies) is the proper location to manage the default anti-spam policy, which applies to all recipients. This is where you configure the spam filter policy (e.g., 'Default' policy), connection filter policy, and outbound spam filter settings, including bulk email thresholds, spam actions, and allow/block lists. It directly addresses unwanted bulk email and spam.

Why this answer

The default anti-spam policy is configured under Email & collaboration > Policies & rules > Threat policies > Anti-spam in the Microsoft 365 Defender portal. This is the correct location because anti-spam settings, including the default policy that applies to all users, are managed specifically within the Anti-spam section of Threat policies. The other options address different threat protection areas (anti-phishing, anti-malware, Safe Attachments) that do not contain spam filtering configurations.

Exam trap

The trap here is that candidates often confuse the Anti-spam policy with Anti-phishing or Anti-malware policies because all are under Threat policies, but each addresses a distinct security layer, and the question specifically asks for spam configuration.

How to eliminate wrong answers

Option B is wrong because Anti-phishing policies handle protection against phishing attacks, not spam filtering, and include settings like impersonation protection and spoof intelligence. Option C is wrong because Anti-malware policies manage malware detection and quarantine actions for malicious files, not spam classification. Option D is wrong because Safe Attachments policies are part of Microsoft Defender for Office 365 and focus on scanning email attachments in a sandbox environment, not on spam filtering.

148
MCQmedium

You are the Microsoft 365 administrator for a multinational company. The company has deployed Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps. Recently, the security team detected that a user's credentials were compromised and used to access SharePoint Online from an unusual location. You need to investigate the incident and determine the full scope of the breach. The solution must use Microsoft 365 Defender to correlate events. What should you do first?

A.Use the Microsoft Purview compliance portal to search for the user's activity in audit logs.
B.Use advanced hunting in Microsoft 365 Defender portal to query for events related to the user across workloads.
C.Use Microsoft Defender for Cloud Apps to investigate the user's activity log.
D.Use Microsoft Sentinel to query the user's events from the workspace.
AnswerB

Advanced hunting in the Microsoft 365 Defender portal (now Microsoft Defender XDR) is a KQL-based, unified query interface that spans email, identity, endpoints, and cloud apps. It lets you join schema tables such as EmailEvents, IdentityLogonEvents, and CloudAppEvents to correlate a user's actions across a single incident, enabling detection of lateral movement or exfiltration. This is the correct first step because it uses the native, integrated signal of Defender XDR without additional licensing or setup.

Why this answer

Advanced hunting in the Microsoft 365 Defender portal allows you to query raw, cross-workload telemetry (e.g., from Identity, Exchange Online, SharePoint Online, and Defender for Cloud Apps) in a single Kusto Query Language (KQL) query. This is the most efficient first step to correlate events such as sign-ins, mailbox access, file downloads, and app sessions related to the compromised user, enabling you to determine the full scope of the breach across all Microsoft 365 services.

Exam trap

The trap here is that candidates often default to the audit log (Option A) because it is familiar from compliance scenarios, but the question explicitly requires correlation across workloads using Microsoft 365 Defender, which is only possible with advanced hunting's cross-table queries.

How to eliminate wrong answers

Option A is wrong because the Microsoft Purview compliance portal audit log search provides a limited, filtered view of audit records and does not natively correlate events across workloads like Identity, Defender for Cloud Apps, or advanced threat signals; it also lacks the raw telemetry and cross-query capabilities of advanced hunting. Option C is wrong because Microsoft Defender for Cloud Apps activity logs are scoped to cloud app sessions and do not include identity, mailbox, or endpoint events from other Defender workloads, making it insufficient for a full cross-workload investigation. Option D is wrong because Microsoft Sentinel is a separate SIEM that requires additional licensing, configuration, and data ingestion from Microsoft 365 Defender; it is not the first tool to use when the goal is to correlate events within the Microsoft 365 Defender portal itself.

149
Multi-Selecthard

Your company uses Microsoft Defender for Endpoint and wants to perform a live response on a device. Which THREE prerequisites must be met?

Select 3 answers
A.The user must be assigned a role that includes live response permissions
B.The device must be running a supported operating system (e.g., Windows 10 or newer)
C.The device must be managed by Microsoft Intune
D.The device must have Microsoft Defender Antivirus as the primary antivirus solution
E.The device must be onboarded to Microsoft Defender for Endpoint
AnswersA, B, E

Initiating a live response session is gated by role-based access control (RBAC). The user must be assigned an Azure AD role such as Security Operator, or a custom Defender for Endpoint role with the 'Live response' permission, and must have the device in their assigned scope; without this, the Start session button is unavailable even for an onboarded, supported device.

Why this answer

Live response in Microsoft Defender for Endpoint requires the user to be assigned a role that includes specific live response permissions, such as 'Live response' or 'Live response advanced' under the Microsoft 365 Defender role-based access control (RBAC). Without these permissions, the user cannot initiate a live response session, regardless of other configurations.

Exam trap

The trap here is that candidates often assume Intune management is required for live response, but Microsoft only requires the device to be onboarded to Defender for Endpoint and running a supported OS, with the user having the correct RBAC permissions.

150
MCQeasy

An administrator wants to restrict which users in the organization can create Microsoft 365 groups. The requirement is that only members of the IT department (identified by the department attribute in Azure AD) should be able to create groups. Which configuration should the administrator use?

A.Azure AD > Groups > Group settings > Group creation settings.
B.Azure AD Identity Governance > Access reviews.
C.Azure AD > Groups > Naming policy.
D.Microsoft 365 admin center > Groups > Add group.
AnswerA

This is correct because Azure AD's Groups > Group settings > General blade contains a group creation setting that lets you restrict who can create Microsoft 365 groups. The 'Group settings' pane includes an option to restrict user ability to create groups to a specific security group. When enabled, only members of that designated security group are allowed to create new Microsoft 365 groups across Azure AD, Teams, and other connected services. This directly addresses the requirement to restrict which users in the organization can create Microsoft 365 groups.

Why this answer

The Azure AD 'Group settings' blade includes a 'Group creation settings' option that allows administrators to restrict group creation to specific security groups. By configuring this setting, the administrator can limit group creation to only members of the IT department, identified by the department attribute in Azure AD, by placing those users into a designated security group.

Exam trap

The trap here is that candidates often confuse the 'Naming policy' (which controls group names) with the 'Group creation settings' (which controls who can create groups), or they mistakenly think that Access Reviews can enforce creation restrictions when it only reviews existing access.

How to eliminate wrong answers

Option B is wrong because Azure AD Identity Governance > Access reviews is used for periodic review and certification of access to groups, applications, and roles, not for controlling who can create groups. Option C is wrong because Azure AD > Groups > Naming policy enforces naming conventions and blocked words for groups, but does not restrict which users can create groups. Option D is wrong because the Microsoft 365 admin center > Groups > Add group is a manual creation interface for administrators and does not provide a tenant-wide policy to restrict group creation to specific users or departments.

← PreviousPage 2 of 3 · 196 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Deploy Manage M365 Tenant questions.