Sample questions
Microsoft 365 Fundamentals MS-900 practice questions
A compliance-aware administrator is selecting the right Microsoft 365 capability to use Microsoft 365 and another public cloud provider for different workloads. Cloud concept or benefit best matches this requirement?
Trap 1: Microsoft Planner
Planner manages tasks and does not describe this cloud model or benefit.
Trap 2: Sensitivity labels
Sensitivity labels classify and protect content, not this cloud concept.
Trap 3: Data Loss Prevention (DLP)
DLP protects sensitive information from inappropriate sharing, not this cloud concept.
- A
Microsoft Planner
Why wrong: Planner manages tasks and does not describe this cloud model or benefit.
- B
Sensitivity labels
Why wrong: Sensitivity labels classify and protect content, not this cloud concept.
- C
Multi-cloud
Multi-cloud means using cloud services from more than one public cloud provider.
- D
Data Loss Prevention (DLP)
Why wrong: DLP protects sensitive information from inappropriate sharing, not this cloud concept.
A company currently has Microsoft 365 E3 licenses for all users. They need to retain all Exchange Online mailbox data for 10 years and place legal holds for litigation. Which add-on license provides these retention and eDiscovery capabilities?
Trap 1: Microsoft 365 E5 Security
Incorrect. E5 Security focuses on threat protection (e.g., Defender for Office 365) and does not cover retention or eDiscovery.
Trap 2: Microsoft 365 E5
Incorrect. Upgrading to full E5 is more expensive than the Compliance add-on and includes many features not required, making it less cost-effective.
Trap 3: Office 365 E5
Incorrect. Office 365 E5 includes similar compliance tools but is a separate product; the most straightforward add-on for existing Microsoft 365 E3 is the Microsoft 365 E5 Compliance add-on.
- A
Microsoft 365 E5 Compliance
Correct. The E5 Compliance add-on includes advanced data governance, retention policies, and legal hold capabilities needed for this scenario.
- B
Microsoft 365 E5 Security
Why wrong: Incorrect. E5 Security focuses on threat protection (e.g., Defender for Office 365) and does not cover retention or eDiscovery.
- C
Microsoft 365 E5
Why wrong: Incorrect. Upgrading to full E5 is more expensive than the Compliance add-on and includes many features not required, making it less cost-effective.
- D
Office 365 E5
Why wrong: Incorrect. Office 365 E5 includes similar compliance tools but is a separate product; the most straightforward add-on for existing Microsoft 365 E3 is the Microsoft 365 E5 Compliance add-on.
A nonprofit organization with 50 users needs to use Microsoft 365 for email, file storage, and online versions of Office apps. They have a very limited budget. Which Microsoft 365 plan should they consider first?
Trap 1: Microsoft 365 Business Basic
Business Basic is a commercial plan and does not offer the nonprofit discount, making it more expensive than the nonprofit equivalent.
Trap 2: Microsoft 365 Business Premium
Business Premium includes advanced security features but is priced at a commercial rate, not suitable for a limited budget nonprofit.
Trap 3: Office 365 E3
E3 is an enterprise plan with full compliance and security features, but it is expensive and unnecessary for basic needs.
- A
Microsoft 365 Business Basic
Why wrong: Business Basic is a commercial plan and does not offer the nonprofit discount, making it more expensive than the nonprofit equivalent.
- B
Microsoft 365 Business Premium
Why wrong: Business Premium includes advanced security features but is priced at a commercial rate, not suitable for a limited budget nonprofit.
- C
Office 365 E3
Why wrong: E3 is an enterprise plan with full compliance and security features, but it is expensive and unnecessary for basic needs.
- D
Microsoft 365 Nonprofit Business Basic
This plan is designed for nonprofits and provides email, file storage, and web Office apps at a heavily discounted or donated price, fitting the budget.
A legal firm must ensure that all documents containing a specific project code are automatically retained for 7 years after the project ends. After the 7-year period, the documents should be permanently deleted. The firm already uses sensitivity labels to classify documents. Which Microsoft Purview solution should they configure?
Trap 1: Microsoft Purview Data Lifecycle Management
While Data Lifecycle Management is related, Records Management is the specific solution that includes retention labels with disposition and is part of Purview for record retention.
Trap 2: Microsoft Purview Sensitivity Labels
Sensitivity labels are used for protection and access control, not for enforcing retention or deletion schedules.
Trap 3: Microsoft Purview Data Loss Prevention
DLP policies detect and act on sensitive data but do not manage retention periods or automatic deletion after a specific time.
- A
Microsoft Purview Data Lifecycle Management
Why wrong: While Data Lifecycle Management is related, Records Management is the specific solution that includes retention labels with disposition and is part of Purview for record retention.
- B
Microsoft Purview Records Management
Records Management enables retention labels that can be auto-applied based on sensitive info types. These labels can enforce retention and deletion. It is the correct solution for this scenario.
- C
Microsoft Purview Sensitivity Labels
Why wrong: Sensitivity labels are used for protection and access control, not for enforcing retention or deletion schedules.
- D
Microsoft Purview Data Loss Prevention
Why wrong: DLP policies detect and act on sensitive data but do not manage retention periods or automatic deletion after a specific time.
A legal team needs to preserve all data related to a specific user involved in litigation, including Exchange emails, SharePoint documents, OneDrive files, and Teams chats. They require a hold that cannot be removed by the user and must allow for later searching and export. Which Microsoft Purview solution should they use?
Trap 1: Retention policies
Retention policies govern automatic retention and deletion rules, not ad-hoc holds for litigation cases.
Trap 2: Communication Compliance
Communication Compliance monitors messages for policy violations, not for preserving data for legal holds.
Trap 3: Data Loss Prevention (DLP)
DLP prevents unauthorized sharing of sensitive data, not preserving data from deletion.
- A
eDiscovery (Standard)
eDiscovery (Standard) places legal holds on mailboxes and sites, preserving content from deletion, and allows search and export.
- B
Retention policies
Why wrong: Retention policies govern automatic retention and deletion rules, not ad-hoc holds for litigation cases.
- C
Communication Compliance
Why wrong: Communication Compliance monitors messages for policy violations, not for preserving data for legal holds.
- D
Data Loss Prevention (DLP)
Why wrong: DLP prevents unauthorized sharing of sensitive data, not preserving data from deletion.
A project manager wants to automate the process of sending a welcome email to new team members when they are added to a SharePoint site. Which two Microsoft 365 technologies should they use? (Choose two.)
Trap 1: Microsoft Power Apps
Power Apps is for building custom apps; it does not natively provide event-driven email workflows.
Trap 2: Microsoft Outlook
Outlook is an email client; the automation logic is handled by Power Automate, not Outlook itself.
- A
Microsoft Power Automate
Correct. Power Automate can create a flow that triggers when a new member is added to a SharePoint site and sends an email.
- B
Microsoft SharePoint
Correct. SharePoint hosts the site and provides the event (membership change) that triggers the workflow.
- C
Microsoft Power Apps
Why wrong: Power Apps is for building custom apps; it does not natively provide event-driven email workflows.
- D
Microsoft Outlook
Why wrong: Outlook is an email client; the automation logic is handled by Power Automate, not Outlook itself.
A security team wants Microsoft 365 access to be allowed only when a user's device is marked compliant by management policy. Which two capabilities are normally combined? (Choose two.)
Trap 1: Microsoft Stream
Stream hosts video content.
Trap 2: Microsoft Forms
Forms collects survey responses.
- A
Microsoft Stream
Why wrong: Stream hosts video content.
- B
Microsoft Intune compliance policies
Intune evaluates whether devices meet compliance requirements.
- C
Microsoft Forms
Why wrong: Forms collects survey responses.
- D
Conditional Access
Conditional Access enforces access decisions using compliance and identity signals.
A non-profit organization with 200 employees needs to equip their staff with Microsoft 365 Business Premium, which includes desktop Office apps, Microsoft Intune, Microsoft Entra ID Premium P1, and Microsoft Defender for Office 365 Plan 1. They are eligible for non-profit pricing. What is the most cost-effective way to obtain these capabilities?
Trap 1: Microsoft 365 Business Basic (non-profit) plus separate add-ons for…
Incorrect. While possible, this approach often costs more than the all-in-one Business Premium plan and adds administrative overhead.
Trap 2: Microsoft 365 E3 (non-profit pricing)
Incorrect. E3 includes many advanced features not required (e.g., advanced compliance, analytics), making it more expensive than Business Premium.
Trap 3: Microsoft 365 Business Standard (non-profit) plus add-ons for…
Incorrect. Business Standard does not include the needed security and management add-ons, and purchasing them separately results in higher overall cost.
- A
Microsoft 365 Business Premium (non-profit pricing)
Correct. Business Premium includes all required features in one plan, and non-profit pricing provides a significant discount.
- B
Microsoft 365 Business Basic (non-profit) plus separate add-ons for Intune and Defender for Office 365
Why wrong: Incorrect. While possible, this approach often costs more than the all-in-one Business Premium plan and adds administrative overhead.
- C
Microsoft 365 E3 (non-profit pricing)
Why wrong: Incorrect. E3 includes many advanced features not required (e.g., advanced compliance, analytics), making it more expensive than Business Premium.
- D
Microsoft 365 Business Standard (non-profit) plus add-ons for Intune and Defender for Office 365
Why wrong: Incorrect. Business Standard does not include the needed security and management add-ons, and purchasing them separately results in higher overall cost.
A marketing manager can access the company's cloud resources from her laptop at home, her tablet while traveling, and her smartphone. Which essential characteristic of cloud computing does this describe?
Trap 1: Resource pooling
Resource pooling refers to the provider's computing resources being pooled to serve multiple customers, with physical and virtual resources dynamically assigned. It does not directly describe multi-device access.
Trap 2: Scalability
Scalability is the ability to handle growing demands by adding resources. The scenario does not mention changing demand or resource capacity.
Trap 3: Measured service
Measured service means resource usage is metered and billed accordingly. The scenario does not discuss billing or metering.
- A
Resource pooling
Why wrong: Resource pooling refers to the provider's computing resources being pooled to serve multiple customers, with physical and virtual resources dynamically assigned. It does not directly describe multi-device access.
- B
Scalability
Why wrong: Scalability is the ability to handle growing demands by adding resources. The scenario does not mention changing demand or resource capacity.
- C
Broad network access
Broad network access allows users to connect from various devices (laptops, tablets, phones) over the network, which matches the marketing manager's ability to use multiple devices.
- D
Measured service
Why wrong: Measured service means resource usage is metered and billed accordingly. The scenario does not discuss billing or metering.
A security administrator needs to automatically restrict access to documents labeled as 'Highly Confidential' when accessed from devices that are not joined to the domain. The restriction should block editing and printing, and apply encryption. Which combination of Microsoft 365 solutions should the administrator use?
Trap 1: Microsoft Purview Data Loss Prevention + Microsoft Entra ID…
DLP policies control sharing behavior but do not enforce device-based access restrictions on documents. Identity Protection focuses on sign-in risk, not device state.
Trap 2: Microsoft Defender for Office 365 + Microsoft 365 Business Premium
Defender for Office 365 protects against threats in email and SharePoint, but does not provide sensitivity labels or device-based conditional access.
Trap 3: Microsoft Purview Audit + Microsoft Entra ID Privileged Identity…
Audit logs activities for investigation, and PIM manages privileged access, but neither enforces document-level access controls or device restrictions.
- A
Microsoft Purview Information Protection + Microsoft Entra ID Conditional Access
Sensitivity labels defined in MIP can enforce encryption and usage restrictions. Conditional Access policies can require domain-joined devices for access, creating a layered approach.
- B
Microsoft Purview Data Loss Prevention + Microsoft Entra ID Identity Protection
Why wrong: DLP policies control sharing behavior but do not enforce device-based access restrictions on documents. Identity Protection focuses on sign-in risk, not device state.
- C
Microsoft Defender for Office 365 + Microsoft 365 Business Premium
Why wrong: Defender for Office 365 protects against threats in email and SharePoint, but does not provide sensitivity labels or device-based conditional access.
- D
Microsoft Purview Audit + Microsoft Entra ID Privileged Identity Management
Why wrong: Audit logs activities for investigation, and PIM manages privileged access, but neither enforces document-level access controls or device restrictions.
A security administrator needs to audit all activities related to a specific user in Exchange Online, SharePoint Online, and Microsoft Entra ID for the past 90 days. They also need to export the audit log as a CSV file. Which Microsoft Purview solution provides this capability without additional licensing beyond Microsoft 365 E3?
Trap 1: Microsoft Purview Audit (Premium)
Audit (Premium) requires E5 or an add-on license; it is not included with E3 alone.
Trap 2: Microsoft Purview eDiscovery (Standard)
eDiscovery is used for searching and holding content (emails, documents), not for auditing user activity logs.
Trap 3: Microsoft Purview Content Search
Content Search is used to find content across mailboxes and sites, not to retrieve audit logs.
- A
Microsoft Purview Audit (Standard)
Correct. Audit (Standard) is included with E3, retains logs for 90 days, covers the required services, and allows export to CSV.
- B
Microsoft Purview Audit (Premium)
Why wrong: Audit (Premium) requires E5 or an add-on license; it is not included with E3 alone.
- C
Microsoft Purview eDiscovery (Standard)
Why wrong: eDiscovery is used for searching and holding content (emails, documents), not for auditing user activity logs.
- D
Microsoft Purview Content Search
Why wrong: Content Search is used to find content across mailboxes and sites, not to retrieve audit logs.
A compliance administrator needs to block sharing of documents containing credit card numbers. Which Microsoft 365 capability is the best fit?
Trap 1: Microsoft Teams live events
Teams events are for communication, not this compliance/security requirement.
Trap 2: Microsoft Bookings
Bookings schedules appointments and is unrelated to this security requirement.
Trap 3: OneDrive sync client
The sync client synchronizes files and does not implement this control by itself.
- A
Data Loss Prevention policies
DLP detects sensitive information types and can restrict sharing across Microsoft 365 locations.
- B
Microsoft Teams live events
Why wrong: Teams events are for communication, not this compliance/security requirement.
- C
Microsoft Bookings
Why wrong: Bookings schedules appointments and is unrelated to this security requirement.
- D
OneDrive sync client
Why wrong: The sync client synchronizes files and does not implement this control by itself.
A global company needs to ensure that only employees in the 'HR' security group can access a specific set of HR documents stored in SharePoint. If a user outside the group attempts to view or copy the content, it must be blocked. The protection must persist even if someone downloads the files and shares them externally, or if the files are saved to a personal device. Which Microsoft Purview solution should be used?
Trap 1: Data Loss Prevention (DLP) policy
DLP policies can prevent sharing of sensitive data but do not encrypt the file; once downloaded, the file loses protection.
Trap 2: Microsoft Entra ID Conditional Access
Conditional Access controls access to cloud apps based on user, device, or location, but does not protect the file after download.
Trap 3: Microsoft Defender for Cloud Apps session policy
Session policies monitor and control activity in the cloud, but do not embed persistent protection into files.
- A
Data Loss Prevention (DLP) policy
Why wrong: DLP policies can prevent sharing of sensitive data but do not encrypt the file; once downloaded, the file loses protection.
- B
Sensitivity labels with encryption and permission settings
Encryption via sensitivity labels protects the file regardless of where it is stored, and permissions ensure only the 'HR' group can access it.
- C
Microsoft Entra ID Conditional Access
Why wrong: Conditional Access controls access to cloud apps based on user, device, or location, but does not protect the file after download.
- D
Microsoft Defender for Cloud Apps session policy
Why wrong: Session policies monitor and control activity in the cloud, but do not embed persistent protection into files.
A non-profit organization with 100 users needs business-grade email, desktop versions of Office apps (Word, Excel, PowerPoint), and 1 TB of cloud storage per user. They are eligible for non-profit pricing. Which Microsoft 365 plan meets these requirements at the lowest cost?
Trap 1: Microsoft 365 Business Basic (Nonprofit)
Incorrect. Business Basic provides online versions of Office apps only, not desktop versions.
Trap 2: Microsoft 365 Business Premium (Nonprofit)
Incorrect. Business Premium includes all features of Business Standard plus advanced security and device management, which are not required and cost more.
Trap 3: Microsoft 365 E3 (Nonprofit)
Incorrect. E3 is a larger enterprise plan with additional compliance and analytics features, at a higher price point.
- A
Microsoft 365 Business Basic (Nonprofit)
Why wrong: Incorrect. Business Basic provides online versions of Office apps only, not desktop versions.
- B
Microsoft 365 Business Standard (Nonprofit)
Correct. This plan includes desktop Office apps, business email, and 1 TB storage per user at a lower cost than Premium or E3.
- C
Microsoft 365 Business Premium (Nonprofit)
Why wrong: Incorrect. Business Premium includes all features of Business Standard plus advanced security and device management, which are not required and cost more.
- D
Microsoft 365 E3 (Nonprofit)
Why wrong: Incorrect. E3 is a larger enterprise plan with additional compliance and analytics features, at a higher price point.
A compliance-aware administrator is selecting the right Microsoft 365 capability to evaluate Microsoft 365 before purchasing. Microsoft 365 licensing, admin, or support concept is most relevant?
Trap 1: Microsoft Stream
Stream hosts video content and does not address this licensing or support need.
Trap 2: Microsoft Whiteboard
Whiteboard is for visual collaboration, not this licensing or admin requirement.
Trap 3: Microsoft Forms
Forms collects survey responses and does not meet this requirement.
- A
Microsoft Stream
Why wrong: Stream hosts video content and does not address this licensing or support need.
- B
A Microsoft 365 trial subscription
Trials allow evaluation before committing to a paid subscription.
- C
Microsoft Whiteboard
Why wrong: Whiteboard is for visual collaboration, not this licensing or admin requirement.
- D
Microsoft Forms
Why wrong: Forms collects survey responses and does not meet this requirement.
A non-profit organization with 300 users currently uses Microsoft 365 Business Basic. They want to add Microsoft Defender for Office 365 (Plan 1) and endpoint management capabilities using Microsoft Intune. They are eligible for non-profit pricing. What is the most cost-effective way to obtain these features?
Trap 1: Switch to Microsoft 365 E3 licenses
E3 lacks Defender for Office 365 and would require additional licensing, making it more expensive.
Trap 2: Add Microsoft 365 E5 Security add-on
The E5 Security add-on is applicable only to E5 licenses; it cannot be added to Business Basic or E3.
Trap 3: Add Microsoft 365 Business Extra File Storage
This add-on only provides additional storage, not security or management features.
- A
Upgrade to Microsoft 365 Business Premium
Business Premium includes Defender for Office 365 and Intune, meeting the requirements at the lowest cost for a non-profit.
- B
Switch to Microsoft 365 E3 licenses
Why wrong: E3 lacks Defender for Office 365 and would require additional licensing, making it more expensive.
- C
Add Microsoft 365 E5 Security add-on
Why wrong: The E5 Security add-on is applicable only to E5 licenses; it cannot be added to Business Basic or E3.
- D
Add Microsoft 365 Business Extra File Storage
Why wrong: This add-on only provides additional storage, not security or management features.
A marketing team needs to create a visually rich newsletter that includes dynamic content from a SharePoint list, such as upcoming events and product images. Which Microsoft 365 app is specifically designed for creating interactive newsletters and presentations?
Trap 1: Microsoft Forms
Microsoft Forms is used for creating surveys, quizzes, and polls, not for interactive newsletters.
Trap 2: Microsoft Stream
Microsoft Stream is a video-sharing service, not suitable for creating newsletters.
Trap 3: Microsoft Microsoft Viva Engage
Microsoft Viva Engage is an enterprise social network for communication and communities, not for creating newsletters.
- A
Microsoft Sway
Sway is ideal for creating interactive, web-based newsletters and presentations that can pull in dynamic content from SharePoint lists and other sources.
- B
Microsoft Forms
Why wrong: Microsoft Forms is used for creating surveys, quizzes, and polls, not for interactive newsletters.
- C
Microsoft Stream
Why wrong: Microsoft Stream is a video-sharing service, not suitable for creating newsletters.
- D
Microsoft Microsoft Viva Engage
Why wrong: Microsoft Viva Engage is an enterprise social network for communication and communities, not for creating newsletters.
A sales manager needs a visual tool to track the sales pipeline with stages, deal values, and assigned team members. The team should be able to update the board in real time and see changes instantly. Which Microsoft 365 app is most suitable?
Trap 1: Microsoft Dynamics 365 Sales
This is a full-featured CRM application that goes well beyond simple pipeline tracking and requires additional licensing.
Trap 2: Microsoft Planner
Planner is designed for task management with buckets and cards, not for tracking deals with monetary values and stages.
Trap 3: Microsoft Excel
Excel can be used for pipeline tracking but lacks a native board view and real-time collaboration is limited compared to Lists.
- A
Microsoft Lists
Lists allows creation of a visual board (using the Gallery or Board view) that can track stages, values, and assignments with real-time updates across the team.
- B
Microsoft Dynamics 365 Sales
Why wrong: This is a full-featured CRM application that goes well beyond simple pipeline tracking and requires additional licensing.
- C
Microsoft Planner
Why wrong: Planner is designed for task management with buckets and cards, not for tracking deals with monetary values and stages.
- D
Microsoft Excel
Why wrong: Excel can be used for pipeline tracking but lacks a native board view and real-time collaboration is limited compared to Lists.
A financial services company must prevent users from accidentally sharing sensitive customer data externally. They want to block sharing of any document containing a credit card number via email or SharePoint. What combination of Microsoft 365 compliance solutions should they use?
Trap 1: Sensitivity labels and Microsoft Purview Information Protection…
Labels classify content but require DLP to enforce blocking actions on sharing.
Trap 2: Microsoft Purview Compliance Manager
Compliance Manager assesses compliance posture, does not block data sharing.
Trap 3: Exchange Online Protection (EOP) and Microsoft Defender for…
These protect against threats like malware and phishing, not against accidental sharing of sensitive data.
- A
Sensitivity labels and Microsoft Purview Information Protection (Microsoft Purview Information Protection)
Why wrong: Labels classify content but require DLP to enforce blocking actions on sharing.
- B
Data Loss Prevention (DLP) policies
DLP policies detect sensitive data and block sharing actions automatically across services.
- C
Microsoft Purview Compliance Manager
Why wrong: Compliance Manager assesses compliance posture, does not block data sharing.
- D
Exchange Online Protection (EOP) and Microsoft Defender for Microsoft 365
Why wrong: These protect against threats like malware and phishing, not against accidental sharing of sensitive data.
A multinational corporation must comply with GDPR. They need to ensure that personal data of EU residents is retained for a specific period and then securely deleted. Additionally, they must be able to respond to data subject access requests (DSARs) within 30 days by finding and exporting relevant data. Which two Microsoft Purview solutions should they use together? (Choose two.)
Trap 1: Data Lifecycle Management (via sensitivity labels)
Data Lifecycle Management is implemented through labels and auto-labeling policies; while it assists in lifecycle management, retention policies are the primary solution for automatic retention and deletion across workloads.
Trap 2: Audit (Standard)
Audit logs user activity but does not provide the search and export capabilities needed to respond to DSARs.
- A
Retention policies
Retention policies can automatically retain personal data for a defined period and then delete it, meeting GDPR retention and erasure obligations.
- B
Data Lifecycle Management (via sensitivity labels)
Why wrong: Data Lifecycle Management is implemented through labels and auto-labeling policies; while it assists in lifecycle management, retention policies are the primary solution for automatic retention and deletion across workloads.
- C
eDiscovery (Premium)
eDiscovery (Premium) allows you to search, hold, and export data from multiple sources, which is essential for fulfilling DSARs within the required timeframe.
- D
Audit (Standard)
Why wrong: Audit logs user activity but does not provide the search and export capabilities needed to respond to DSARs.
A security team wants to ensure that only devices that are compliant with company security policies (e.g., antivirus enabled, disk encrypted) can access Exchange Online and SharePoint Online. Which feature should they configure in Microsoft 365?
Trap 1: Data loss prevention (DLP) policies
Incorrect. DLP policies prevent sensitive data from being shared, but do not control which devices can access services.
Trap 2: Information Rights Management (IRM)
Incorrect. IRM protects content by restricting actions like copying or forwarding, but does not enforce device compliance.
Trap 3: Microsoft Defender for Office 365
Incorrect. Defender for Office 365 protects against email threats like phishing and malware, not device compliance.
- A
Conditional Access policies
Correct. Conditional Access policies can enforce device compliance by checking with Intune before allowing access to cloud apps.
- B
Data loss prevention (DLP) policies
Why wrong: Incorrect. DLP policies prevent sensitive data from being shared, but do not control which devices can access services.
- C
Information Rights Management (IRM)
Why wrong: Incorrect. IRM protects content by restricting actions like copying or forwarding, but does not enforce device compliance.
- D
Microsoft Defender for Office 365
Why wrong: Incorrect. Defender for Office 365 protects against email threats like phishing and malware, not device compliance.
A security administrator needs to review all sign-in attempts and identify suspicious login patterns for the past 30 days. Which Microsoft 365 portal should they use to access this information?
Trap 1: Microsoft Purview compliance portal
The Purview portal focuses on compliance, data governance, and eDiscovery, not sign-in logs.
Trap 2: Microsoft 365 admin center
The admin center provides user management and some activity reports, but detailed sign-in logs are accessed through Microsoft Entra ID.
Trap 3: Microsoft Defender for Cloud Apps
Defender for Cloud Apps provides visibility into cloud app usage and can generate alerts, but the raw sign-in logs originate from Microsoft Entra ID.
- A
Microsoft Purview compliance portal
Why wrong: The Purview portal focuses on compliance, data governance, and eDiscovery, not sign-in logs.
- B
Microsoft 365 admin center
Why wrong: The admin center provides user management and some activity reports, but detailed sign-in logs are accessed through Microsoft Entra ID.
- C
Microsoft Entra ID sign-in logs
Microsoft Entra ID Sign-ins logs (in the Azure portal or Entra admin center) provide comprehensive sign-in activity data for analysis and investigation.
- D
Microsoft Defender for Cloud Apps
Why wrong: Defender for Cloud Apps provides visibility into cloud app usage and can generate alerts, but the raw sign-in logs originate from Microsoft Entra ID.
A security analyst receives an alert about a user who downloaded a large number of files from a SharePoint document library in a short period. The analyst needs to investigate the user's activities across Exchange, SharePoint, and Teams to determine if data exfiltration is occurring. Which Microsoft Purview solution should the analyst use to review detailed activity logs?
Trap 1: Microsoft Purview eDiscovery (Premium)
eDiscovery is used to search for content (emails, documents) for legal cases, not for activity audit logs.
Trap 2: Microsoft Purview Communication Compliance
This solution monitors communications for inappropriate content, not general user activities like file downloads.
Trap 3: Microsoft Purview Data Loss Prevention (DLP)
DLP policies prevent data leakage; it does not provide a retrospective log of user activities.
- A
Microsoft Purview Audit (Premium)
Audit (Premium) captures a comprehensive record of user activities, enabling investigation of potential data exfiltration.
- B
Microsoft Purview eDiscovery (Premium)
Why wrong: eDiscovery is used to search for content (emails, documents) for legal cases, not for activity audit logs.
- C
Microsoft Purview Communication Compliance
Why wrong: This solution monitors communications for inappropriate content, not general user activities like file downloads.
- D
Microsoft Purview Data Loss Prevention (DLP)
Why wrong: DLP policies prevent data leakage; it does not provide a retrospective log of user activities.
A sales team needs to track customer interactions, manage leads, and automate follow-up emails. Which Microsoft 365 app is specifically designed for this customer relationship management (CRM) purpose?
Trap 1: Microsoft Outlook
Incorrect. Outlook is an email and calendar client; it lacks structured lead management and automation features.
Trap 2: Microsoft SharePoint
Incorrect. SharePoint is a document management and collaboration platform, not a CRM tool.
Trap 3: Microsoft Power Automate
Incorrect. Power Automate is a workflow automation tool that can be used to send follow-up emails, but it is not a CRM application for tracking leads.
- A
Microsoft Dynamics 365 Sales
Correct. This is a dedicated CRM app for managing sales processes, leads, and customer interactions.
- B
Microsoft Outlook
Why wrong: Incorrect. Outlook is an email and calendar client; it lacks structured lead management and automation features.
- C
Microsoft SharePoint
Why wrong: Incorrect. SharePoint is a document management and collaboration platform, not a CRM tool.
- D
Microsoft Power Automate
Why wrong: Incorrect. Power Automate is a workflow automation tool that can be used to send follow-up emails, but it is not a CRM application for tracking leads.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.