Courseiva

Microsoft 365 Fundamentals MS-900 (MS-900) — Questions 175

217 questions total · 3pages · All types, answers revealed

Page 1 of 3

Page 2
1
MCQeasy

A user wants to access their work files from a personal laptop without installing any Microsoft 365 Apps. Which web-based service allows them to view and edit documents in a browser?

A.Microsoft OneDrive
B.Microsoft 365 for the web
C.Microsoft Teams
D.Microsoft SharePoint
AnswerB

Microsoft 365 for the web, formerly known as Office Online, delivers browser-based versions of Word, Excel, PowerPoint, and other Office applications. It allows users to view, create, and edit documents directly in a web browser without requiring any local installation, making it ideal for accessing work files from a personal laptop. As long as the user has an internet connection and appropriate licensing, they can use these web apps for full editing capability, which directly addresses the user's need.

Why this answer

Microsoft 365 for the web (formerly Office Web Apps) provides browser-based versions of Word, Excel, PowerPoint, and OneNote, enabling users to view and edit documents without installing any local applications. This service is accessed through a web browser on any device, including a personal laptop, and requires only an internet connection and a valid Microsoft 365 subscription.

Exam trap

Microsoft often tests the distinction between storage services (OneDrive, SharePoint) and the actual web-based editing service (Microsoft 365 for the web), causing candidates to mistakenly choose OneDrive because it is the most familiar file-access option.

How to eliminate wrong answers

Option A is wrong because Microsoft OneDrive is primarily a cloud storage and file synchronization service, not a web-based document editing suite; while it can launch documents in Microsoft 365 for the web, OneDrive itself does not provide the editing capabilities. Option C is wrong because Microsoft Teams is a collaboration platform focused on chat, meetings, and channel-based communication, not a dedicated web-based document editor; although it integrates with Office for the web for file previews, its primary function is not browser-based document creation and editing. Option D is wrong because Microsoft SharePoint is a web-based document management and collaboration platform that stores and organizes files, but it relies on Microsoft 365 for the web or desktop apps to actually edit documents; SharePoint itself does not provide the in-browser editing functionality.

2
MCQmedium

An administrator is reviewing a request from users who need to let support staff troubleshoot without tenant-wide change permissions. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Assign least-privileged support or reader roles
C.Microsoft Forms
D.Microsoft Whiteboard
AnswerB

Support roles should be scoped to the minimum access needed.

Why this answer

The scenario requires granting support staff the ability to troubleshoot without tenant-wide change permissions, which directly maps to the principle of least privilege. In Microsoft 365, this is achieved by assigning a role like Helpdesk Administrator or a reader role (e.g., Global Reader), which provides read-only or limited administrative access without allowing modifications to tenant-wide settings. This aligns with the 'Describe Microsoft 365 pricing and support' domain, specifically the support and admin concepts.

Exam trap

The trap here is that candidates may confuse a specific Microsoft 365 service (like Stream, Forms, or Whiteboard) with an admin or support concept, failing to recognize that the question is about role-based access control and least privilege, not about a particular application.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video service for recording and sharing videos, not an admin or support concept for granting granular permissions. Option C is wrong because Microsoft Forms is a survey and quiz tool, unrelated to role-based access control or troubleshooting permissions. Option D is wrong because Microsoft Whiteboard is a collaborative digital canvas, not a mechanism for assigning least-privileged support roles.

3
Drag & Dropmedium

Drag and drop the steps to create a new user account in Microsoft 365 admin center into the correct order.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Creating a user in M365 admin center requires signing in, navigating to active users, adding a user, entering details, and assigning licenses/roles.

4
Multi-Selecthard

Which THREE of the following are benefits of the Microsoft 365 E5 license compared to E3?

Select 3 answers
A.Exchange Online
B.Power BI Pro
C.Microsoft Purview Communication Compliance
D.Microsoft Defender for Office 365 Plan 2
E.Microsoft Entra ID P1
AnswersB, C, D

E5 includes Power BI Pro, while E3 does not.

Why this answer

Power BI Pro is included with Microsoft 365 E5 but not with E3, enabling advanced data visualization and analytics capabilities. This is a key differentiator for organizations requiring self-service business intelligence tools integrated with Microsoft 365.

Exam trap

The trap here is that candidates often assume all core productivity services like Exchange Online are exclusive to higher tiers, when in fact they are baseline features across E3 and E5, while the real differentiators are advanced security, compliance, and analytics add-ons.

5
MCQmedium

A cloud provider offers a service where customers can provision virtual machines, storage, and networks on-demand through a web portal. The customer is responsible for patching the guest operating system. Which cloud service model best describes this offering?

A.Software as a Service (SaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Desktop as a Service (DaaS)
AnswerC

Correct. The customer provisions the VMs and is responsible for OS updates and patches, while the provider manages the underlying hardware.

Why this answer

(Infrastructure as a Service) because the customer provisions fundamental compute, storage, and networking resources on-demand, and retains control over the guest OS, including patching. In IaaS, the provider manages only the physical infrastructure (hypervisor, networking, storage hardware), while the customer is responsible for the OS and applications, matching the scenario exactly.

Exam trap

The trap here is that candidates confuse PaaS with IaaS because both involve 'platform' or 'infrastructure' terms, but the key differentiator is who patches the guest OS — in PaaS, the provider patches it, while in IaaS, the customer does.

How to eliminate wrong answers

Option A is wrong because SaaS delivers fully managed applications (e.g., Office 365) where the provider handles all patching, including the OS, and the customer only uses the software via a browser or client. Option B is wrong because PaaS provides a managed platform (runtime, middleware, database) where the provider patches the underlying OS and runtime, and the customer only deploys code, not managing VMs or guest OS patches. Option D is wrong because DaaS delivers virtual desktops as a managed service, where the provider typically manages the guest OS image and patching, shifting OS responsibility away from the customer.

6
MCQmedium

A compliance officer needs to automatically detect documents stored in SharePoint Online that contain sensitive data types (e.g., credit card numbers) and apply a sensitivity label that restricts access to only certain users. The classification should occur without user intervention and the label must be applied to the document. Which Microsoft Purview solution should be configured?

A.Data Loss Prevention (DLP)
B.Sensitivity labels with auto-labeling
C.Retention labels
D.Information barriers
AnswerB

Sensitivity labels with auto-labeling meet this requirement because they combine detection and protection: an auto-labeling policy in Microsoft Purview can scan files in SharePoint or OneDrive for predefined sensitive information types or trainable classifiers. When a match occurs, the policy automatically assigns a sensitivity label configured with encryption, rights management permissions, and visual markings. This creates a persistent classification that travels with the document, exactly matching the officer's need to automatically detect and protect sensitive documents.

Why this answer

Sensitivity labels with auto-labeling are the correct solution because they can automatically classify documents based on sensitive data types (such as credit card numbers) and apply a sensitivity label that enforces protection actions like restricting access to specific users. This occurs without user intervention, meeting the requirement for automatic classification and labeling in SharePoint Online.

Exam trap

The trap here is that candidates often confuse DLP policies with auto-labeling, but DLP only detects and blocks sharing actions, whereas auto-labeling applies the sensitivity label and its associated protection directly to the document.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) policies detect and prevent the sharing of sensitive data but do not apply sensitivity labels or enforce access restrictions on documents; they trigger alerts or block actions. Option C is wrong because retention labels are designed to manage data retention and deletion policies, not to classify documents based on sensitive data types or apply access restrictions. Option D is wrong because information barriers are used to restrict communication and collaboration between specific groups or users, not to automatically detect sensitive data or apply labels to documents.

7
MCQhard

A security team needs to ensure that all Microsoft 365 administrative actions—such as creating user accounts or resetting passwords—are logged and searchable for at least 90 days. They also need to create custom alert rules for suspicious admin activity. Which Microsoft Purview solution should they use?

A.Microsoft Purview Audit (Standard)
B.Microsoft Purview Audit (Premium)
C.Microsoft Entra ID sign-in logs
D.Microsoft Defender for Cloud Apps
AnswerA

Correct. Audit (Standard) records admin and user activities with 90-day retention and supports custom alert rules via the Microsoft Purview compliance portal.

Why this answer

Microsoft Purview Audit (Standard) logs and retains all administrative actions (e.g., creating users, resetting passwords) for 90 days by default, meeting the retention requirement. It also supports creating custom alert rules for suspicious admin activity via the Microsoft 365 Defender portal, which queries the audit log. This makes it the correct solution for both logging and alerting on admin actions.

Exam trap

The trap here is that candidates often confuse Audit (Premium) as mandatory for any alerting or retention beyond 30 days, but the question's 90-day requirement is exactly met by Audit (Standard), and Premium is only needed for longer retention or specific high-value events.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Audit (Premium) extends retention up to 1 year (or more with add-ons) and provides higher-value events like MailItemsAccessed, but the question specifically requires only 90 days of retention, which Standard already covers. Option C is wrong because Microsoft Entra ID sign-in logs capture authentication events (e.g., user logins, MFA failures), not administrative actions like creating accounts or resetting passwords, and they are retained for 30 days by default (or 30 days with Azure AD P1/P2). Option D is wrong because Microsoft Defender for Cloud Apps focuses on cloud app discovery, session controls, and anomaly detection for SaaS apps, not on logging and alerting for Microsoft 365 administrative actions within the audit log.

8
MCQmedium

A tenant administrator is advising a department that wants to review upcoming Microsoft 365 changes and recommended admin actions. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Microsoft Forms
C.Microsoft Whiteboard
D.Message center
AnswerD

The Message center provides tenant-relevant change announcements and admin actions.

Why this answer

The Message center in the Microsoft 365 admin center is the dedicated hub for reviewing upcoming changes, new features, and recommended admin actions. It provides service advisories, planned changes, and action-required notifications, making it the most relevant concept for a tenant administrator advising a department on upcoming Microsoft 365 changes.

Exam trap

The trap here is that candidates confuse productivity tools (Stream, Forms, Whiteboard) with administrative communication channels, overlooking that the Message center is the specific admin portal feature for change management and action items.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video management and sharing service, not a tool for reviewing upcoming changes or admin actions. Option B is wrong because Microsoft Forms is a survey and quiz creation tool, unrelated to change notifications or admin advisories. Option C is wrong because Microsoft Whiteboard is a digital canvas for collaboration, not a mechanism for tracking service updates or recommended actions.

9
MCQmedium

A sales team wants to build a custom inventory tracking application with minimal code. They need a cloud-based database that can securely store structured data and integrate with the low-code app builder. Which Microsoft 365 service should they use as the database backend?

A.Microsoft Lists
B.Power Apps
C.Microsoft Dataverse
D.Power Automate
AnswerC

Microsoft Dataverse is the correct choice because it is a fully managed, low-code data platform that provides relational tables, rich metadata, role-based security, and built-in auditing for structured business data. It is tightly integrated with Power Apps and the Power Platform, enabling the sales team to model inventory items, relationships, and business rules without writing custom code, all within a scalable, secure cloud database.

Why this answer

Microsoft Dataverse is the correct choice because it provides a scalable, cloud-based relational database that securely stores structured data and integrates natively with Power Apps, the low-code app builder. Unlike simpler list-based storage, Dataverse supports rich data types, relationships, business logic, and role-based security, making it ideal for custom inventory tracking applications built with minimal code.

Exam trap

The trap here is that candidates often confuse Microsoft Lists (a simple list tool) with a proper database backend, or mistakenly think Power Apps or Power Automate can serve as data storage, when in fact they are application and automation layers that require a separate data source like Dataverse.

How to eliminate wrong answers

Option A is wrong because Microsoft Lists is a list-based data storage service designed for simple tracking and collaboration, not a full relational database with support for complex relationships, business rules, and integration with low-code app builders like Power Apps. Option B is wrong because Power Apps is the low-code app builder itself, not a database backend; it requires a data source such as Dataverse, SharePoint, or SQL to store and retrieve data. Option D is wrong because Power Automate is a workflow automation service for creating automated processes, not a database; it can trigger actions based on data but does not provide persistent storage for structured inventory data.

10
MCQeasy

A cloud provider offers virtual machines, but customers must install, configure, and maintain the operating system and applications. Which cloud service model does this describe?

A.IaaS (Infrastructure as a Service)
B.PaaS (Platform as a Service)
C.SaaS (Software as a Service)
D.FaaS (Function as a Service)
AnswerA

In IaaS, the provider supplies virtualized compute, storage, and networking as on-demand resources, but the customer deploys and manages the virtual machines' guest OS, runtime, and installed applications. This shared-responsibility model places patching, configuration, and application stack maintenance squarely on the customer, which is exactly the scenario described. The provider's responsibility ends at the hypervisor and physical infrastructure, so customers must handle everything inside the VM.

Why this answer

This scenario describes Infrastructure as a Service (IaaS), where the cloud provider supplies virtualized computing resources such as virtual machines, storage, and networking, but the customer retains full control over the operating system, middleware, and applications. In IaaS, the provider manages only the physical infrastructure (hypervisor, servers, storage, and network), while the customer is responsible for OS installation, configuration, patching, and application management. This aligns directly with the question's description of customer-managed OS and applications on provider-hosted VMs.

Exam trap

The trap here is that candidates often confuse IaaS with PaaS because both involve virtual machines, but PaaS (e.g., Azure App Service) hides the OS and runtime, whereas IaaS requires full customer OS management.

How to eliminate wrong answers

Option B (PaaS) is wrong because PaaS abstracts the underlying OS and runtime; the provider manages the OS, middleware, and runtime environment, so customers do not install or maintain the OS. Option C (SaaS) is wrong because SaaS delivers fully functional applications accessed via a web browser or API, with no customer control over the OS or underlying infrastructure. Option D (FaaS) is wrong because FaaS (Function as a Service) executes stateless code functions in response to events, with the provider managing all infrastructure including the OS, and customers only upload code without any OS-level access.

11
MCQmedium

A hospital must store patient medical records on-premises to comply with strict data sovereignty regulations. However, they also want to use advanced analytics tools hosted on a public cloud platform. Which cloud deployment model best meets their needs?

A.Private cloud
B.Public cloud
C.Hybrid cloud
D.Community cloud
AnswerC

Hybrid cloud combines on-premises and public cloud resources, enabling the hospital to keep sensitive data on-site while using public cloud analytics.

Why this answer

(Hybrid cloud) is correct because it allows the hospital to keep sensitive patient medical records on-premises to satisfy strict data sovereignty regulations, while leveraging public cloud services for advanced analytics. This model combines private and public cloud resources, enabling data to remain compliant without sacrificing access to cloud-hosted analytics tools.

Exam trap

The trap here is that candidates often choose Private cloud (Option A) thinking it is the only way to ensure data sovereignty, but they overlook the requirement for advanced analytics tools hosted on a public cloud, which Hybrid cloud uniquely satisfies.

How to eliminate wrong answers

Option A (Private cloud) is wrong because while it meets data sovereignty requirements, it does not provide access to public cloud-based advanced analytics tools, limiting the hospital's ability to use those services. Option B (Public cloud) is wrong because it would require storing patient data off-premises, violating data sovereignty regulations that mandate on-premises storage. Option D (Community cloud) is wrong because it is designed for multiple organizations with shared concerns (e.g., compliance), but it still typically involves off-premises infrastructure and does not inherently support a hybrid approach that keeps specific data on-premises while using public cloud analytics.

12
Drag & Dropmedium

Drag and drop the steps to configure a Microsoft 365 group expiration policy in the Azure AD admin center into the correct order.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

To configure a Microsoft 365 group expiration policy, you must first sign in to the Azure AD admin center, then navigate to Groups > Expiration, configure the desired expiration settings, and finally save the policy. This sequence ensures proper access and application of the configuration.

13
MCQeasy

A nonprofit organization with 50 users needs to use Microsoft 365 for email, file storage, and online versions of Office apps. They have a very limited budget. Which Microsoft 365 plan should they consider first?

A.Microsoft 365 Business Basic
B.Microsoft 365 Business Premium
C.Office 365 E3
D.Microsoft 365 Nonprofit Business Basic
AnswerD

Microsoft 365 Nonprofit Business Basic is the correct choice because it is tailor-made for eligible nonprofits, offering Exchange Online, Teams, SharePoint, and web versions of Word, Excel, PowerPoint, and OneDrive at no cost or at a very low monthly rate depending on qualification. This plan satisfies the essential needs of email, file storage, and web-based Office apps for up to 300 users, making it economically ideal for a 50-person nonprofit. It also includes the same security and compliance baselines as the commercial Business Basic but at a nonprofit-aggregated price.

Why this answer

Microsoft 365 Nonprofit Business Basic (Option D) is the correct choice because it provides email (Exchange Online), file storage (OneDrive and SharePoint), and online versions of Office apps (Word, Excel, etc.) at no cost for eligible nonprofit organizations with up to 300 users. This plan is specifically designed for nonprofits with limited budgets, offering the required functionality without the expense of paid plans.

Exam trap

The trap here is that candidates may overlook the nonprofit-specific plans and choose a commercial plan like Business Basic (Option A) or Business Premium (Option B), assuming they are the only options, without realizing that Microsoft offers free or heavily discounted plans for eligible nonprofits, which directly address the budget constraint.

How to eliminate wrong answers

Option A (Microsoft 365 Business Basic) is wrong because it is a paid commercial plan that requires a monthly subscription per user, whereas the nonprofit version of Business Basic is available at no cost for eligible organizations. Option B (Microsoft 365 Business Premium) is wrong because it includes advanced security and device management features (e.g., Microsoft Defender for Business, Intune) that are unnecessary for basic email, storage, and online Office apps, and it is significantly more expensive. Option C (Office 365 E3) is wrong because it is an enterprise plan designed for larger organizations with advanced compliance and analytics capabilities (e.g., eDiscovery, Power BI Pro), and it is not optimized for the limited budget or specific needs of a small nonprofit; additionally, it is a paid plan unlike the free nonprofit offering.

14
MCQeasy

A company wants to provide its employees with access to email, calendar, and document editing tools through a web browser without installing any software. The provider manages all maintenance, updates, and security of the applications. Which cloud service model best describes this scenario?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Desktop as a Service (DaaS)
AnswerC

SaaS (Software as a Service) is correct because it delivers fully functional, ready-to-use applications over the internet, with the provider managing all underlying infrastructure, platform, and application code. Email, shared calendars, and document editing are classic SaaS workloads — think of Microsoft 365 Exchange Online, Outlook on the web, and Office for the web. Users only need a browser or thin client, never having to worry about servers, patching, or maintenance, which perfectly matches the need to provide employees with access to these applications.

Why this answer

This scenario describes Software as a Service (SaaS) because the provider delivers fully functional applications—such as email, calendar, and document editing—over the web, with no local installation required. The provider handles all maintenance, updates, and security, which is the defining characteristic of SaaS. Examples include Microsoft 365 (Exchange Online, Outlook, Word Online) and Google Workspace.

Exam trap

The trap here is that candidates often confuse SaaS with PaaS because both involve managed services, but PaaS is for developers building custom applications, not for end users consuming ready-made applications like email and calendars.

How to eliminate wrong answers

Option A is wrong because Infrastructure as a Service (IaaS) provides virtualized computing resources (e.g., VMs, storage, networks) but requires the customer to install and manage their own operating systems and applications, not just use pre-built tools via a browser. Option B is wrong because Platform as a Service (PaaS) provides a runtime environment and development tools for building and deploying custom applications, not ready-to-use end-user applications like email and document editing. Option D is wrong because Desktop as a Service (DaaS) delivers a full virtual desktop environment (including OS and applications) to end users, but the scenario specifies accessing specific applications through a web browser without a full desktop experience, and DaaS typically requires a client or browser-based remote desktop connection, not just direct web access to individual apps.

15
MCQmedium

A compliance officer needs to automatically encrypt any outgoing email that contains a customer's credit card number. The solution should work without requiring the sender to take any manual action. Which Microsoft Purview feature should be configured?

A.Data Loss Prevention (DLP) policy
B.Microsoft Purview Message Encryption
C.Sensitivity labels
D.Retention policies
AnswerA

Data Loss Prevention (DLP) policies in Microsoft Purview inspect outbound email for sensitive information types, such as credit card numbers, and can automatically invoke encryption as a corrective action before the message is sent. This is a built-in, policy-driven capability that requires no manual user action or separate rule configuration, making it the correct choice for automatically encrypting messages containing regulated data.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft Purview can be configured to automatically detect sensitive information types, such as credit card numbers, in outgoing email. When a match is found, the policy can enforce an action like 'Encrypt the message' without requiring any manual action from the sender, fulfilling the compliance officer's requirement for automatic, sender-transparent encryption.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Message Encryption (a manual or rule-triggered encryption method) with a DLP policy's ability to automatically detect and encrypt content, leading them to select Message Encryption as the direct solution instead of the policy that orchestrates the detection and action.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Message Encryption is a feature that provides encryption capabilities, but it requires manual action by the sender (e.g., selecting 'Encrypt' in Outlook) or must be triggered by a DLP policy; it is not a policy itself that automatically detects and encrypts based on content. Option C is wrong because sensitivity labels are used to classify and protect data based on user-applied or automatic labeling, but they do not natively scan for specific patterns like credit card numbers in transit; they rely on DLP or auto-labeling policies for such detection. Option D is wrong because retention policies are designed to preserve or delete data after a specified period, not to inspect content in real-time for sensitive information or enforce encryption on outgoing messages.

16
MCQmedium

A project team needs to create a shared workspace to manage tasks, share files, track project milestones, and communicate through conversation threads. They want a single app that integrates with other Microsoft 365 services like Outlook and Teams. Which Microsoft 365 app is best suited for this requirement?

A.Microsoft Planner
B.Microsoft To Do
C.Microsoft Project for the web
D.Microsoft Lists
AnswerA

Microsoft Planner is correct because it provides a shared Kanban-style task board within Microsoft 365, where team members can create buckets, assign tasks, set due dates, attach files, and add checklists. Each task includes a comments section for threaded, collaborative conversations, and the board offers real-time progress charts. Planner integrates natively as a tab in Microsoft Teams and syncs with Outlook tasks, making it purpose-built for lightweight team project management and milestone tracking.

Why this answer

Microsoft Planner is best suited because it provides a shared workspace with buckets and cards for task management, file attachments, milestone tracking via checklists and due dates, and conversation threads on each task. It integrates natively with Outlook for task visibility and with Teams via the Planner tab, meeting the requirement for a single app that combines these capabilities.

Exam trap

The trap here is that candidates confuse Microsoft To Do as a team tool because of its integration with Outlook tasks, but it lacks shared workspaces and team collaboration features, which are core to Planner.

How to eliminate wrong answers

Option B (Microsoft To Do) is wrong because it is a personal task management app focused on individual to-do lists and lacks shared workspaces, file sharing, milestone tracking, and conversation threads for team collaboration. Option C (Microsoft Project for the web) is wrong because it is designed for complex project portfolio management with Gantt charts and resource allocation, not for lightweight task management with conversation threads and file sharing in a single app. Option D (Microsoft Lists) is wrong because it is a data tracking app for creating custom lists (e.g., inventory, issues) and does not include built-in task management features like buckets, checklists, or conversation threads.

17
MCQmedium

A company deploys a custom application on a cloud platform where they manage the operating system and runtime environment, but the cloud provider manages the underlying physical infrastructure, storage, and networking. Which cloud service model is being used?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Function as a Service (FaaS)
AnswerA

In IaaS, the customer has control over the operating system, storage, and deployed applications, while the provider manages the underlying infrastructure.

Why this answer

The scenario describes a model where the customer manages the operating system and runtime environment, while the cloud provider handles the physical infrastructure, storage, and networking. This aligns precisely with Infrastructure as a Service (IaaS), as IaaS provides virtualized computing resources (e.g., virtual machines) where the customer retains control over the OS, middleware, and applications, but the provider manages the underlying hardware, hypervisor, and physical network.

Exam trap

The trap here is that candidates often confuse IaaS with PaaS because both involve deploying applications, but the key differentiator is who manages the OS and runtime—IaaS gives the customer full control over these layers, whereas PaaS abstracts them away entirely.

How to eliminate wrong answers

Option B (PaaS) is wrong because in PaaS, the provider manages not only the physical infrastructure but also the operating system and runtime environment, leaving the customer only to deploy and manage their application code and data. Option C (SaaS) is wrong because in SaaS, the provider manages the entire application stack, including the OS, runtime, and application, and the customer only uses the software via a web browser or API without any control over the underlying platform. Option D (FaaS) is wrong because FaaS is a subset of serverless computing where the customer only deploys individual functions (code snippets) and the provider dynamically manages the runtime and infrastructure, including the OS, scaling, and execution environment, which contradicts the customer managing the OS and runtime.

18
Multi-Selectmedium

Which of the following are included as part of Microsoft 365 E3 or E5 subscriptions? Choose all that apply. (There are four correct answers.)

Select 4 answers
.Microsoft Teams
.Exchange Online with 100 GB mailbox and unlimited storage via archiving
.Windows 10/11 Enterprise E3
.Microsoft Defender for Office 365
.Azure Active Directory Premium P1 only (not P2)
.Microsoft 365 Personal (single user) license

Why this answer

Microsoft 365 E3 and E5 subscriptions include Microsoft Teams as a core collaboration service, Exchange Online with a 100 GB mailbox and unlimited archive storage via auto-expanding archiving, Windows 10/11 Enterprise E3 for device management and security, and Microsoft Defender for Office 365 (in E5, and as an add-on for E3 but included in the E5 suite). These are standard components of the enterprise-grade plans.

Exam trap

Microsoft often tests the misconception that Azure AD Premium P1 is the only identity tier in E3/E5, but E5 actually includes P2, and that Microsoft 365 Personal is a valid enterprise license, when it is a consumer-only product.

19
MCQmedium

You are the compliance officer for Fabrikam, a medium-sized company with 500 users on Microsoft 365 Business Premium. Fabrikam must comply with the California Consumer Privacy Act (CCPA). The legal team has identified that they need to be able to respond to consumer requests to delete personal data within 45 days. They also need to ensure that personal data is not retained longer than necessary. You have been asked to configure Microsoft Purview to meet these requirements. Specifically, you need to search for and delete personal data when a deletion request is received, and set up a data retention policy to automatically delete personal data after 2 years. What should you do?

A.Implement auto-labeling to label personal data and configure a retention label to delete after 2 years.
B.Use Content Search to find personal data, then use eDiscovery to delete it for deletion requests. Create a retention policy with a retention period of 2 years for all SharePoint sites and OneDrive accounts.
C.Create a retention label that deletes data after 2 years and apply it manually to all documents containing personal data.
D.Configure a DLP policy to block sharing of personal data and set a retention policy for 2 years.
AnswerB

Content Search and eDiscovery handle deletion; retention policy handles automatic deletion.

Why this answer

To delete personal data for a specific user, you need to use Content Search to find the data and then eDiscovery to delete it. A retention policy can be set to automatically delete data after 2 years. Option A is incorrect because a retention label is for manual application, not automatic deletion.

Option C is incorrect because DLP does not delete data. Option D is incorrect because auto-labeling does not delete data.

20
MCQhard

A legal team is preparing for litigation. They need to place a hold on all content (emails, documents, Teams messages) related to a specific project across the entire organization. The hold must prevent any deletion or modification of the content. Which Microsoft Purview solution should they use?

A.eDiscovery (Premium) with legal hold
B.Audit log search
C.Data Loss Prevention (DLP)
D.Retention policy
AnswerA

eDiscovery (Premium) is the Microsoft Purview solution built for legal investigations. It allows you to create a case, search across Exchange, SharePoint, OneDrive, Teams, and other workloads, and apply a legal hold that preserves all responsive content indefinitely until the hold is released by case attorneys. A legal hold overrides user deletions, auto-purge policies, and even mailbox retention cleanup processes, ensuring data stays intact for the duration of litigation. This directly satisfies the legal team's requirement to place a hold on potentially relevant data.

Why this answer

EDiscovery (Premium) with legal hold is the Microsoft Purview solution specifically designed to preserve content in-place for litigation. When a legal hold is applied to a case, it prevents deletion or modification of emails, documents, and Teams messages across the entire organization by placing a hold on the underlying Exchange Online mailboxes, SharePoint sites, and OneDrive accounts. This ensures that all content related to the project is immutable for the duration of the hold, meeting the legal team's requirement.

Exam trap

The trap here is that candidates often confuse retention policies (which are broad, time-based preservation rules) with legal holds (which are case-specific, litigation-driven holds that prevent any modification or deletion), leading them to incorrectly select Option D.

How to eliminate wrong answers

Option B (Audit log search) is wrong because it only records and allows searching of past activities (e.g., who accessed or deleted content) but does not prevent deletion or modification of content; it is a detective control, not a preventive one. Option C (Data Loss Prevention or DLP) is wrong because DLP policies are designed to identify, monitor, and protect sensitive data from being shared or leaked (e.g., via email or Teams), not to place a hold on content for litigation purposes. Option D (Retention policy) is wrong because while retention policies can preserve content for a specified period, they are typically applied based on content type or location and do not provide the granular, case-specific hold required for litigation; retention policies also allow modification of content unless combined with a retention label that blocks editing, which is not the same as a legal hold.

21
MCQhard

A multinational corporation needs to ensure that all emails containing a customer's passport number are automatically blocked from being sent externally. Additionally, the sending user should receive a policy tip explaining the block. Which Microsoft Purview solution should be configured?

A.Sensitivity labels
B.Data Loss Prevention (DLP) policies
C.Conditional Access policies
D.eDiscovery
AnswerB

DLP policies can detect passport numbers in emails and block them from being sent, with user notification via policy tips.

Why this answer

Data Loss Prevention (DLP) policies in Microsoft Purview are specifically designed to detect sensitive information, such as passport numbers, in emails and automatically block external transmission while displaying a policy tip to the user. This matches the requirement exactly, as DLP can inspect email content for sensitive data types and enforce actions like blocking and notifying the sender.

Exam trap

The trap here is that candidates often confuse sensitivity labels with DLP, assuming labels can block emails, but labels only apply protection after classification, whereas DLP actively inspects content and enforces rules like blocking and policy tips.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are used for classification and protection (e.g., encryption or visual markings) but do not natively block external email transmission based on content detection or provide policy tips. Option C is wrong because Conditional Access policies control access to resources based on user, device, or location conditions, not content inspection or blocking of outbound emails. Option D is wrong because eDiscovery is designed for searching and exporting content for legal or compliance investigations, not for real-time prevention of data exfiltration or user notifications.

22
MCQmedium

During requirements gathering, an IT manager says the organization must see how many paid licenses are unused. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Available license count
B.Microsoft Stream
C.Microsoft Forms
D.Microsoft Whiteboard
AnswerA

Available license count shows purchased but unassigned licenses.

Why this answer

The Available license count in the Microsoft 365 admin center allows administrators to view how many licenses have been purchased versus how many are assigned, directly revealing unused paid licenses. This is the core licensing management feature under 'Billing > Licenses' that tracks consumption and helps optimize costs.

Exam trap

The trap here is that candidates confuse productivity tools (Stream, Forms, Whiteboard) with administrative licensing features, assuming any Microsoft 365 app might show license counts, when only the admin center's license management section provides that data.

How to eliminate wrong answers

Option B (Microsoft Stream) is wrong because it is a video service for recording and sharing videos, not a licensing or admin tool for tracking license usage. Option C (Microsoft Forms) is wrong because it is a survey and data collection tool, unrelated to license management or admin reporting. Option D (Microsoft Whiteboard) is wrong because it is a collaborative digital canvas app, with no role in monitoring license assignments or availability.

23
MCQeasy

A company wants to reduce hardware maintenance costs by moving to the cloud. They need to maintain full control over the operating system, applications, and security configurations, but do not want to manage physical servers or data center facilities. Which cloud service model should they choose?

A.Software as a Service (SaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.On-premises
AnswerC

Infrastructure as a Service (IaaS) provides virtualized computing resources over the internet, with the cloud provider owning and maintaining the physical servers, storage, and networking equipment. This shifts hardware maintenance and capital costs to the provider, while you retain full administrative control over the operating system, runtime, and security configurations. That combination of provider-managed hardware and customer-managed OS precisely matches the requirement to reduce maintenance costs while keeping administrative authority.

Why this answer

Infrastructure as a Service (IaaS) provides virtualized computing resources over the internet, allowing the company to deploy and manage their own operating systems, applications, and security configurations while offloading the physical hardware and data center management to the cloud provider. This model gives the highest level of control over the software stack without the burden of maintaining physical servers, aligning perfectly with the requirement to reduce hardware maintenance costs while retaining full administrative access.

Exam trap

The trap here is that candidates often confuse PaaS with IaaS because both are cloud models, but PaaS removes control over the OS and runtime environment, which is the critical distinction when the question explicitly requires maintaining full control over the operating system and security configurations.

How to eliminate wrong answers

Option A is wrong because Software as a Service (SaaS) delivers fully managed applications accessed via a web browser, where the customer has no control over the underlying operating system, runtime, or security configurations—contradicting the need for full control. Option B is wrong because Platform as a Service (PaaS) abstracts the operating system and middleware, providing a managed runtime environment for application development; the customer cannot control the OS or security configurations at the infrastructure level. Option D is wrong because on-premises deployment requires the company to own and manage physical servers and data center facilities, directly conflicting with the goal of reducing hardware maintenance costs.

24
MCQmedium

A department head asks which Microsoft 365 option should be used to manage billing without granting full tenant control. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Microsoft Forms
C.Billing Administrator
D.Microsoft Whiteboard
AnswerC

Billing Administrator manages subscriptions, purchases, and billing-related tasks.

Why this answer

The Billing Administrator role in Azure AD allows a user to manage billing accounts, subscriptions, and invoices without having full administrative access to the tenant. This role is specifically designed for scenarios where a department head needs to handle financial operations but should not have permissions to manage users, security, or other tenant-wide settings.

Exam trap

The trap here is that candidates may confuse a functional app (like Stream, Forms, or Whiteboard) with an administrative role, because the question asks for an 'option' to manage billing, leading them to think of a tool rather than a role-based access control concept.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video management service for storing, sharing, and streaming videos, not a role or feature for billing management. Option B is wrong because Microsoft Forms is a survey and quiz creation tool, unrelated to billing administration or tenant access control. Option D is wrong because Microsoft Whiteboard is a collaborative digital canvas application, with no role in managing billing or administrative permissions.

25
MCQhard

A company with 100 users has Microsoft 365 Business Basic licenses. They want to add Phone System and Audio Conferencing for all users to enable PSTN calling and dial-in capabilities. They wish to minimize additional costs. What is the most cost-effective licensing approach?

A.Upgrade all users to Microsoft 365 E3 and add Phone System and Audio Conferencing.
B.Add the Microsoft 365 Business Voice add-on for each user.
C.Purchase Phone System and Audio Conferencing as standalone add-ons separately.
D.Add the Microsoft Teams Phone Standard add-on.
AnswerB

Microsoft 365 Business Voice is a single add-on SKU that bundles Phone System, Audio Conferencing, and a domestic Calling Plan for users on Microsoft 365 Business Basic, Standard, or Apps. It gives Teams full PBX features, dial-in meeting numbers, and PSTN calling without requiring a plan upgrade or separate telephony components. For this scenario, adding Business Voice to each of the 100 existing Business users is the most direct, economical path because it is purpose-built for small and mid-size businesses and avoids purchasing each voice capability individually.

Why this answer

Microsoft 365 Business Voice is a cost-effective add-on specifically designed for Business Basic, Standard, or Premium subscribers to add Phone System and Audio Conferencing capabilities. It bundles both PSTN calling and dial-in features into a single license, avoiding the higher cost of upgrading to E3 or purchasing separate add-ons.

Exam trap

The trap here is that candidates often assume upgrading to a higher-tier plan like E3 is the only way to get advanced voice features, overlooking the purpose-built, lower-cost Business Voice add-on for Business license holders.

How to eliminate wrong answers

Option A is wrong because upgrading all users from Business Basic to Microsoft 365 E3 is significantly more expensive and unnecessary; E3 includes Phone System but still requires Audio Conferencing as an additional add-on, increasing costs. Option C is wrong because purchasing Phone System and Audio Conferencing as standalone add-ons separately costs more per user than the bundled Business Voice add-on, which is designed to minimize expenses for Business license holders. Option D is wrong because the Microsoft Teams Phone Standard add-on provides only Phone System capabilities without Audio Conferencing, so it would require an additional Audio Conferencing license to meet the dial-in requirement, increasing total cost.

26
MCQhard

Contoso Ltd. is a global manufacturing company with 10,000 users. They are deploying Microsoft 365 E5 and require: (1) All Microsoft 365 data must be encrypted at rest and in transit using customer-managed keys; (2) Email must be archived for 10 years; (3) Users must be able to access files offline on mobile devices and sync changes when online; (4) The IT team must monitor and respond to threats across email, endpoints, and identities from a single console. You need to recommend the appropriate Microsoft 365 services. Which combination should you choose?

A.Microsoft Purview Double Key Encryption, Exchange Online Archiving, SharePoint Online, Microsoft Sentinel
B.Microsoft Purview Customer Key, Exchange Online Archiving, OneDrive, Microsoft Defender XDR
C.Azure Information Protection, Exchange Online Archiving, Windows 365, Microsoft Defender for Endpoint
D.Microsoft Purview Customer Key, Exchange Online In-Place Hold, OneDrive, Microsoft 365 Defender for Cloud Apps
AnswerB

Microsoft Purview Customer Key gives the tenant control over the root encryption keys that encrypt data at rest across Microsoft 365 services, meeting a strict encryption-at-rest requirement. Exchange Online Archiving provides unlimited archiving and supports retention policies with Preservation Lock that can be configured for 10 years, satisfying long-term regulatory retention. OneDrive for Business offers automatic offline synchronization for user files without manual per-library configuration. Microsoft Defender XDR unifies signals from endpoints, email, identity, and cloud apps into a single incident queue, providing the needed unified threat response and monitoring.

Why this answer

Microsoft Purview Customer Key provides customer-managed encryption keys for data at rest in Microsoft 365, meeting the first requirement. Exchange Online Archiving with a 10-year retention policy satisfies the email archiving requirement. OneDrive enables offline file access on mobile devices with sync capabilities.

Microsoft Defender XDR (Extended Detection and Response) offers a unified console to monitor and respond to threats across email, endpoints, and identities.

Exam trap

The trap here is confusing Microsoft Purview Customer Key (which encrypts all data at rest with customer-managed keys) with Double Key Encryption (which only protects a subset of data) or Azure Information Protection (which is a labeling solution, not encryption at rest).

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Double Key Encryption (DKE) protects only specific sensitive data with two keys, not all Microsoft 365 data, and Microsoft Sentinel is a SIEM/SOAR tool, not a single console for threat response across email, endpoints, and identities. Option C is wrong because Azure Information Protection is a classification and labeling solution, not a customer-managed encryption key service, and Windows 365 is a cloud PC service, not a file sync solution for offline mobile access. Option D is wrong because Exchange Online In-Place Hold is a litigation hold feature, not a 10-year archiving solution, and Microsoft 365 Defender for Cloud Apps is a CASB, not the unified XDR console that covers email, endpoints, and identities.

27
MCQhard

A company with 100 Microsoft 365 E3 users needs to add cloud access security broker capabilities to monitor and control user access to SaaS applications and shadow IT. They want the most cost-effective add-on. What should they purchase?

A.Microsoft Defender for Cloud Apps
B.Microsoft Defender for Microsoft 365 Plan 2
C.Microsoft Entra ID Premium P2
D.Microsoft 365 E5 Compliance
AnswerA

Microsoft Defender for Cloud Apps is the correct add-on because it functions as a Cloud Access Security Broker (CASB). It discovers shadow IT by analyzing user web traffic and logs, assesses the risk of thousands of SaaS applications, and enforces access and data-control policies such as session governance and app-level conditional access. For a tenant with M365 E3, adding this service directly addresses the need to monitor and control unsanctioned SaaS usage across the organization.

Why this answer

Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility into shadow IT, controls over user access to SaaS applications, and data protection policies. It is the most cost-effective add-on for this specific requirement because it can be licensed standalone without requiring higher-tier Microsoft 365 or Entra ID plans, and it directly addresses the need to monitor and control SaaS app usage.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps with Microsoft Defender for Microsoft 365 Plan 2, assuming the latter is required for CASB functionality, when in fact the standalone Defender for Cloud Apps license provides the same CASB capabilities at a lower cost.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Microsoft 365 Plan 2 includes Defender for Cloud Apps but bundles it with additional endpoint, email, and identity protection features at a higher cost, making it less cost-effective when only CASB capabilities are needed. Option C is wrong because Microsoft Entra ID Premium P2 provides identity governance and privileged identity management, not CASB functionality for monitoring and controlling SaaS applications or shadow IT. Option D is wrong because Microsoft 365 E5 Compliance focuses on data governance, eDiscovery, and compliance management, not on cloud access security broker capabilities for SaaS app access control.

28
MCQmedium

A tenant administrator is advising a department that wants to grant temporary, approved privileged administrator access. Microsoft security, identity, or compliance capability should it use?

A.Privileged Identity Management (PIM)
B.Microsoft Forms
C.Microsoft Stream
D.Microsoft Planner
AnswerA

Privileged Identity Management (PIM) provides time-bound, just-in-time activation of built-in roles in Microsoft Entra ID, such as Global Administrator or Privileged Role Administrator. By making a user eligible for a role, the tenant can require on-demand activation with optional approval, justification, and multi-factor authentication. This eliminates permanent standing privileged access and creates detailed audit records for every activation, directly supporting the department's need for controlled, temporary elevation of administrator rights.

Why this answer

Privileged Identity Management (PIM) is the correct choice because it provides just-in-time privileged access, allowing the tenant administrator to grant temporary, approved administrator roles with time-bound activation and approval workflows. PIM is part of Microsoft Entra ID Governance and directly addresses the requirement for temporary privileged access with oversight.

Exam trap

The trap here is that candidates may confuse PIM with other Microsoft 365 tools that have 'management' or 'planning' in their names, but only PIM provides the specific privileged access governance required for temporary administrator roles.

How to eliminate wrong answers

Option B (Microsoft Forms) is wrong because it is a survey and data collection tool, not designed for identity or access management. Option C (Microsoft Stream) is wrong because it is a video hosting and sharing platform, unrelated to privileged access control. Option D (Microsoft Planner) is wrong because it is a task management and planning tool, lacking any security or identity governance capabilities.

29
Multi-Selecthard

A multinational corporation must comply with GDPR. They need to ensure that personal data of EU residents is retained for a specific period and then securely deleted. Additionally, they must be able to respond to data subject access requests (DSARs) within 30 days by finding and exporting relevant data. Which two Microsoft Purview solutions should they use together? (Choose two.)

Select 2 answers
A.Retention policies
B.Data Lifecycle Management (via sensitivity labels)
C.eDiscovery (Premium)
D.Audit (Standard)
AnswersA, C

Retention policies in Microsoft Purview are the primary mechanism for automatically enforcing GDPR's storage-limitation obligations. They can be configured to retain personal data for a defined period and then permanently delete it, operating consistently across Exchange, SharePoint, OneDrive, and Teams. By allowing you to set precise retention and deletion rules based on content age or sensitive data types, they directly satisfy data-minimization and erasure requirements without manual intervention. This makes them the correct answer for meeting GDPR retention and deletion obligations.

Why this answer

Retention policies (A) are correct because they allow organizations to define rules that retain personal data for a specific period and then automatically delete it, meeting GDPR retention and secure deletion requirements. eDiscovery (Premium) (C) is correct because it enables searching, collecting, and exporting data from various Microsoft 365 workloads to fulfill data subject access requests (DSARs) within the 30-day regulatory timeframe.

Exam trap

The trap here is that candidates confuse Data Lifecycle Management (via sensitivity labels) with retention policies, not realizing that sensitivity labels handle classification and protection, not automated time-based retention and deletion, while retention policies are the correct tool for that purpose.

30
MCQmedium

A company has 150 users with Microsoft 365 Business Basic licenses. They now need to manage mobile devices using Microsoft Intune for all users. They want to keep costs as low as possible and do not want to upgrade to a more expensive plan if an add-on is available. What is the most cost-effective licensing strategy?

A.Add Microsoft Intune licenses for all users
B.Upgrade all users to Microsoft 365 Business Premium
C.Upgrade all users to Microsoft 365 E3
D.Purchase Microsoft 365 Enterprise Mobility + Security E3 add-on
AnswerA

Add Microsoft Intune licenses for all users is the correct choice. Microsoft 365 Business Basic includes Exchange Online, SharePoint, Teams, and Microsoft Entra ID P1 but lacks endpoint management. A standalone Microsoft Intune Plan 1 license, available as an add-on to Business Basic, provides cloud-based MDM/MAM for Windows, iOS, Android, and macOS with compliance and conditional access driven by the existing Entra ID tenant, at a per-user cost far lower than rebundling the entire business suite.

Why this answer

Microsoft Intune is available as a standalone add-on license for Microsoft 365 Business Basic, Business Standard, and other plans. By purchasing the Microsoft Intune license per user, the company can add device management capabilities to their existing Business Basic subscriptions without paying for other unnecessary features. Upgrading to Business Premium or E3 would include Intune but also many other features, increasing cost.

31
Multi-Selectmedium

A company is choosing a Microsoft 365 plan for 150 users who need email, file storage, and Teams. They also need basic compliance features such as data retention policies and eDiscovery. Which TWO plans meet these requirements?

Select 2 answers
A.Microsoft 365 E1
B.Microsoft 365 E3
C.Microsoft 365 Business Premium
D.Microsoft 365 E5
E.Microsoft 365 Business Basic
AnswersB, C

E3 includes all required features and is suitable for any size.

Why this answer

Microsoft 365 E3 includes Exchange Online, SharePoint Online, and Teams, plus advanced compliance features like data retention policies and eDiscovery (Standard). Microsoft 365 Business Premium also includes these core services and compliance capabilities, making both suitable for 150 users needing email, file storage, Teams, and basic compliance.

Exam trap

The trap here is that candidates often assume only E3 or E5 can provide compliance features, forgetting that Microsoft 365 Business Premium also includes data retention policies and eDiscovery (Standard) for organizations under 300 users.

32
MCQeasy

A company's CFO is pleased that they only pay for the compute and storage resources consumed each month, with no upfront hardware costs. This billing model is a direct result of which cloud computing characteristic?

A.On-demand self-service
B.Broad network access
C.Measured service
D.Resource pooling
AnswerC

Measured service is the cloud characteristic that automatically monitors, controls, and reports resource usage, enabling providers to bill customers for exactly the compute, storage, or network capacity they consume. This metering capability makes pay-per-use pricing possible, so the CFO only pays for the compute actually used, avoiding fixed upfront costs. Without measured service, usage-based billing and cost optimization would not be feasible.

Why this answer

The CFO's observation that the company only pays for consumed compute and storage resources with no upfront hardware costs directly reflects the 'measured service' characteristic of cloud computing. Measured service means cloud providers meter resource usage (e.g., CPU hours, GB-months of storage) and bill based on actual consumption, typically using a pay-as-you-go model. This eliminates the need for capital expenditure on hardware, as costs are operational and tied to usage metrics.

Exam trap

The trap here is that candidates often confuse 'measured service' with 'resource pooling' because both involve multi-tenancy and efficiency, but measured service is specifically about usage metering and billing, not the underlying resource sharing architecture.

How to eliminate wrong answers

Option A is wrong because on-demand self-service refers to a user's ability to provision resources automatically without requiring human interaction with the provider, not to the billing or cost model. Option B is wrong because broad network access describes the availability of resources over the network via standard protocols (e.g., HTTP, HTTPS) and accessed by various devices, not the consumption-based pricing. Option D is wrong because resource pooling involves the provider's multi-tenant model where physical and virtual resources are dynamically assigned to serve multiple customers, which enables efficiency but does not directly result in pay-per-use billing.

33
MCQmedium

A compliance team needs to prevent employees from copying sensitive data (such as financial records or customer PII) to USB drives and other removable media from their Windows 10/11 devices. When a user attempts to copy data to an unapproved USB device, the action should be blocked and an alert should be generated. Which Microsoft Purview solution should they configure?

A.Microsoft Purview Data Lifecycle Management (retention policies)
B.Microsoft Purview Information Protection (sensitivity labels)
C.Microsoft Purview Data Loss Prevention (DLP) with device policies
D.Microsoft Purview eDiscovery (Standard or Premium)
AnswerC

Endpoint DLP policies in Microsoft Purview Data Loss Prevention are purpose-built to monitor and block risky activities on devices, including copying sensitive data to removable storage such as USB drives. By leveraging configurable sensitive information types, these policies enforce real-time restrictions, display user notifications, and trigger security alerts when violations occur, directly addressing the compliance team's objective to prevent copying.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) with device policies is the correct solution because it is specifically designed to monitor and control actions like copying sensitive data to removable media on Windows 10/11 endpoints. DLP device policies can block the copy action to unapproved USB devices and generate alerts when a policy violation occurs, directly addressing the compliance team's requirement to prevent data exfiltration via USB drives.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which classify and protect data) with DLP policies (which enforce actions like blocking copy to USB), but sensitivity labels alone cannot block endpoint-level copy actions without DLP device policies.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Lifecycle Management (retention policies) governs how long data is retained and when it is deleted, not real-time blocking of copy actions to removable media. Option B is wrong because Microsoft Purview Information Protection (sensitivity labels) classifies and protects data with encryption or visual markings but does not enforce endpoint-level controls like blocking USB copy actions. Option D is wrong because Microsoft Purview eDiscovery (Standard or Premium) is used for legal discovery and search of content, not for preventing data exfiltration via removable media.

34
MCQmedium

A department head asks which Microsoft 365 option should be used to access cloud resources from laptops, tablets, and phones over the internet. Cloud concept or benefit best matches this requirement?

A.Sensitivity labels
B.Microsoft Planner
C.Data Loss Prevention (DLP)
D.Broad network access
AnswerD

Broad network access means cloud services are reachable over standard networks from different client platforms.

Why this answer

Broad network access is a core NIST cloud characteristic that enables resources to be accessed over the internet by standard protocols (e.g., HTTPS, TLS) from a wide range of client devices such as laptops, tablets, and phones. This directly matches the requirement for accessing cloud resources from multiple device types over the internet.

Exam trap

The trap here is that candidates confuse operational features (like sensitivity labels or DLP) with foundational cloud characteristics, failing to recognize that 'broad network access' is the specific NIST-defined term for multi-device internet-based access.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are a Microsoft Purview Information Protection feature used to classify and protect data based on sensitivity, not to enable network access from devices. Option B is wrong because Microsoft Planner is a task management and collaboration tool within Microsoft 365, not a cloud concept or benefit for device access. Option C is wrong because Data Loss Prevention (DLP) is a security policy mechanism to prevent unauthorized sharing of sensitive data, not a cloud characteristic for broad device connectivity.

35
MCQmedium

A project team needs a centralized workspace that includes a shared calendar for deadlines, a document library for storing deliverables, and a task list with assignments. They also want threaded discussions about each item. Which Microsoft 365 service provides this integrated experience out of the box?

A.Microsoft Teams
B.SharePoint Online
C.Microsoft 365 Groups
D.Microsoft Outlook
AnswerC

A Microsoft 365 Group is the correct answer because it is the underlying identity and membership container that automatically provisions a complete set of collaboration services: a shared Outlook inbox and calendar, a SharePoint Online document library, a Planner plan for task management, and a shared workspace for threaded conversations. Everything is bound to the same group ID, so membership and permissions propagate consistently across all services. This meets the requirement of a centralized workspace with a calendar and tasks out of the box, without requiring manual assembly of separate tools.

Why this answer

Microsoft 365 Groups is the correct answer because it provides a unified, out-of-the-box workspace that includes a shared calendar, document library (via connected SharePoint), task list (via Planner or To Do), and a group mailbox with threaded conversations. Unlike standalone services, a Microsoft 365 Group bundles these resources together automatically when created, offering the integrated experience described without requiring manual configuration.

Exam trap

The trap here is that candidates often confuse Microsoft Teams as the integrated workspace, but Teams is actually a client that surfaces the underlying Microsoft 365 Group resources, not the service that provides them out of the box.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is a chat-based collaboration hub that relies on a Microsoft 365 Group for its underlying calendar, document library, and task list; Teams itself does not natively provide a shared calendar or threaded discussions about each item without the group's resources. Option B is wrong because SharePoint Online provides document libraries and lists but lacks a built-in shared calendar and threaded discussions; it requires integration with other services like Outlook or Teams to achieve the full integrated experience. Option D is wrong because Microsoft Outlook is an email and calendar client that can display group resources but does not natively create or manage the document library, task list, or threaded discussions as a centralized workspace; it consumes the group's resources rather than providing them.

36
MCQmedium

A sales representative needs to quickly create a professional-looking price quote that includes dynamic pricing from a company database and send it as a PDF to a customer. Which Microsoft 365 app is best suited for this?

A.Microsoft Word
B.Microsoft Excel
C.Microsoft Sway
D.Microsoft SharePoint Online
AnswerA

Word is a full-featured word processor that supports precise page layout, rich typography, tables, headers/footers, and embedded objects, all essential for a polished, branded sales quote. It can pull live data from Excel or external databases via linked content and mail merge fields, then export to a fixed-layout PDF via Save As, guaranteeing the recipient sees an identical professional document.

Why this answer

Microsoft Word is best suited because it supports mail merge and dynamic content from external data sources like a company database. Using Word's 'Insert Quick Parts' or mail merge features, a sales rep can pull live pricing data into a professional quote template and then export the document as a PDF directly from Word.

Exam trap

The trap here is that candidates often confuse Excel's data calculation capabilities with document creation, assuming a spreadsheet can produce a professional quote, but Word is the correct app for formatted, PDF-ready documents with dynamic content.

How to eliminate wrong answers

Option B is wrong because Microsoft Excel is a spreadsheet app optimized for data analysis and calculations, not for creating professional-looking documents with dynamic text and images; it lacks the rich layout and PDF export capabilities needed for a polished quote. Option C is wrong because Microsoft Sway is a presentation and storytelling app for interactive web-based content, not for generating static PDF documents with dynamic database-driven pricing. Option D is wrong because Microsoft SharePoint Online is a collaboration and document management platform, not a content creation app; it cannot directly create a formatted quote with dynamic pricing from a database.

37
MCQeasy

A company uses cloud resources and notices that their monthly bill is based on the exact amount of storage and compute hours they consumed. They did not pay for any fixed, unused capacity. Which cloud characteristic does this describe?

A.Rapid elasticity
B.Resource pooling
C.On-demand self-service
D.Measured service
AnswerD

Measured service is the cloud characteristic that monitors, controls, reports, and bills customers based on their actual resource consumption, such as processing time, storage, or bandwidth. This metering capability enables pay-as-you-go pricing, where the monthly invoice directly reflects the quantity and type of cloud resources used. It provides transparency and allows customers to align costs with usage, which is precisely the scenario of a monthly bill based on consumption.

Why this answer

Measured service is the cloud characteristic that enables usage-based billing, where customers pay only for the resources they actually consume (e.g., storage GB-hours, compute vCPU-hours) without any upfront or fixed costs for idle capacity. This is implemented through metering capabilities at the hypervisor or resource provider level, which track consumption in granular units and feed into billing systems. The scenario explicitly describes paying for exact consumption, which aligns directly with the pay-per-use model of measured service.

Exam trap

The trap here is that candidates confuse 'measured service' with 'on-demand self-service' because both involve user-driven provisioning, but measured service specifically addresses the metering and billing aspect, not the provisioning mechanism.

How to eliminate wrong answers

Option A is wrong because rapid elasticity refers to the ability to automatically scale resources up or down quickly in response to demand, not to billing based on consumption. Option B is wrong because resource pooling describes the provider's ability to serve multiple tenants from a shared physical infrastructure using multi-tenancy, not the metering or billing mechanism. Option C is wrong because on-demand self-service allows users to provision resources without human interaction via a web portal or API, but it does not inherently describe how those resources are billed or that unused capacity is not charged.

38
MCQeasy

A financial services firm uses a public cloud provider for its customer-facing web application, but stores sensitive client data on its own on-premises servers. A secure VPN connection is used to transfer anonymized data from the public cloud to the on-premises environment for processing. Which cloud deployment model does this describe?

A.Public cloud
B.Private cloud
C.Hybrid cloud
D.Community cloud
AnswerC

Hybrid cloud is the correct model because it combines a private or on-premises environment with one or more public cloud providers, connected via a secure link such as a VPN or dedicated ExpressRoute. This architecture allows the financial services firm to keep sensitive data on-premises for regulatory compliance while leveraging public cloud scalability for non-sensitive workloads or burst capacity. It also enables workload portability between environments, which aligns directly with the scenario of integrating public cloud services with the firm's own on-premises servers.

Why this answer

This scenario describes a hybrid cloud because it combines a public cloud provider for the customer-facing web application with an on-premises private cloud for sensitive client data, connected via a secure VPN. The hybrid cloud model enables organizations to leverage the scalability and cost-efficiency of public cloud resources while maintaining strict control over sensitive data in a private environment. The use of a VPN to transfer anonymized data between the two environments is a key characteristic of hybrid cloud architecture, as it ensures secure communication across the boundary.

Exam trap

The trap here is that candidates may incorrectly choose 'Public cloud' because they focus on the customer-facing web application being hosted there, ignoring the on-premises storage of sensitive data, which is the defining characteristic of a hybrid deployment.

How to eliminate wrong answers

Option A is wrong because a public cloud model would have all resources, including sensitive client data, hosted and managed by the third-party cloud provider, not stored on-premises. Option B is wrong because a private cloud model would have all resources, including the web application, hosted on-premises or in a dedicated environment, not using a public cloud provider. Option D is wrong because a community cloud is shared by several organizations with common concerns (e.g., compliance or security requirements), but this scenario involves only one firm using both public and private infrastructure, not a multi-tenant community.

39
MCQhard

An organization uses Microsoft 365 E5 licenses. Users report that Microsoft 365 Apps for enterprise (e.g., Word, Excel) are slow to open. The IT team considers deploying a cloud-based solution to improve performance. Which cloud service model should they use?

A.Platform as a Service (PaaS)
B.Software as a Service (SaaS)
C.Infrastructure as a Service (IaaS)
D.Function as a Service (FaaS)
AnswerB

SaaS delivers Microsoft 365 Apps via the cloud, optimized for performance and reduced local load.

Why this answer

The organization is already using Microsoft 365 Apps for enterprise, which are delivered as a SaaS offering. To improve performance for slow-opening desktop apps, deploying a cloud-based solution means leveraging the same SaaS model—Microsoft 365 Apps are already SaaS. The issue is likely related to local installation or network latency, and using the web-based versions (also SaaS) or optimizing the existing SaaS delivery can help.

Option B is correct because SaaS provides ready-to-use applications like Word and Excel via the cloud, eliminating local installation overhead.

Exam trap

The trap here is that candidates may confuse the need for a cloud-based solution with IaaS or PaaS, thinking they need to build or host the applications themselves, when the organization already has the SaaS solution (Microsoft 365) and just needs to optimize its delivery or use the web-based SaaS versions.

How to eliminate wrong answers

Option A is wrong because PaaS provides a platform for developing and deploying custom applications, not ready-to-use productivity apps like Word or Excel. Option C is wrong because IaaS provides virtualized computing resources (VMs, storage, networking) but requires the organization to install and manage the operating system and applications, which does not directly address slow-opening Microsoft 365 Apps. Option D is wrong because FaaS (serverless functions) is for running event-driven code snippets, not for delivering full desktop applications like Word or Excel.

40
MCQmedium

Your organization has 500 users with Microsoft 365 E3 licenses. You want to add security features such as Microsoft Defender for Office 365 (Plan 1) and Microsoft Purview Information Protection. Which licensing approach should you recommend?

A.Keep E3 and add Microsoft 365 E5 Compliance add-on
B.Keep E3 and add Microsoft 365 E5 Security add-on
C.Upgrade all users to Microsoft 365 E5
D.Keep E3 and use the Security & Compliance Center for E3
AnswerC

Upgrading all users to Microsoft 365 E5 is the correct choice because E5 directly includes both Defender for Office 365 Plan 1 and Microsoft Purview Information Protection. E5 bundles all E3 features with advanced security and compliance workloads, eliminating the need for additional add-ons and ensuring both the email protection and information protection requirements are met under a single license.

Why this answer

Microsoft 365 E5 includes both Defender for Office 365 (Plan 1) and Purview Information Protection (formerly Azure Information Protection P2) natively, whereas E3 requires separate add-ons. Upgrading all users to E5 is the simplest and most cost-effective licensing approach when both security features are needed for all 500 users, as it avoids the complexity and potential per-user cost of stacking multiple add-on SKUs.

Exam trap

The trap here is that candidates assume the E5 Security add-on or E5 Compliance add-on alone can cover both requirements, but each add-on only covers its respective domain (security or compliance), and neither alone includes both Defender for Office 365 (Plan 1) and Purview Information Protection.

How to eliminate wrong answers

Option A is wrong because the Microsoft 365 E5 Compliance add-on provides Purview Compliance features (e.g., eDiscovery, Audit) but does not include Defender for Office 365 (Plan 1), which is a security feature. Option B is wrong because the Microsoft 365 E5 Security add-on includes Defender for Office 365 (Plan 1) but does not include Purview Information Protection (which requires the E5 Compliance add-on or full E5). Option D is wrong because the Security & Compliance Center in E3 only offers basic security and compliance capabilities (e.g., limited DLP, basic audit) and does not include Defender for Office 365 (Plan 1) or Purview Information Protection, which require additional licensing.

41
MCQhard

An organization wants to use AI to summarize long email threads and suggest replies in Outlook. Which Microsoft 365 feature provides this capability?

A.Microsoft Copilot for Microsoft 365
B.Microsoft Editor
C.Microsoft Search
D.Microsoft Viva Insights
AnswerA

Copilot uses AI to summarize email threads and suggest replies in Outlook.

Why this answer

Microsoft Copilot for Microsoft 365 integrates AI directly into Outlook to summarize long email threads and generate suggested replies. It uses large language models and the Microsoft Graph to analyze conversation context, extract key points, and draft responses, all within the user's mailbox. This is the only Microsoft 365 feature designed specifically for these natural language processing tasks in Outlook.

Exam trap

The trap here is that candidates often confuse Microsoft Editor's basic AI writing assistance with Copilot's advanced generative AI capabilities, assuming Editor can handle complex tasks like summarization and reply generation, but Editor lacks the underlying large language model and Graph integration required for those features.

How to eliminate wrong answers

Option B is wrong because Microsoft Editor is a writing assistant that provides grammar, spelling, and style suggestions, but it cannot summarize email threads or generate suggested replies. Option C is wrong because Microsoft Search helps users find content across Microsoft 365 (e.g., emails, files, people) via a search index, but it does not perform AI-driven summarization or reply generation. Option D is wrong because Microsoft Viva Insights focuses on productivity and wellbeing analytics (e.g., focus time, meeting habits) and does not include capabilities for summarizing conversations or suggesting replies.

42
MCQmedium

A field service team needs a mobile-friendly app that allows technicians to view customer information from a central database, log completed tasks, and capture photos on-site. The IT department has limited development resources and wants to build this app quickly without writing extensive code. Which Microsoft 365 app is best suited for this requirement?

A.Microsoft Power Apps
B.Microsoft Forms
C.Microsoft Power Automate
D.Microsoft Power BI
AnswerA

Correct. Power Apps allows building custom mobile apps quickly with minimal code, integrating with various data sources.

Why this answer

Microsoft Power Apps is the correct choice because it enables rapid development of custom mobile-friendly apps with minimal code, allowing the field service team to view customer data from a central database (e.g., Dataverse or SharePoint), log completed tasks, and capture photos on-site. Its low-code platform provides pre-built connectors and templates that directly address the need for a data-driven, mobile-first application without extensive development resources.

Exam trap

The trap here is that candidates often confuse Power Automate with Power Apps, thinking that automation alone can build an app, but Power Automate only orchestrates workflows and cannot provide the interactive user interface required for field technicians to view data, log tasks, and capture photos.

How to eliminate wrong answers

Option B (Microsoft Forms) is wrong because it is designed for creating surveys and forms for data collection, not for building a multi-functional mobile app that integrates with a central database and supports task logging and photo capture. Option C (Microsoft Power Automate) is wrong because it focuses on workflow automation and process orchestration, not on creating a user-facing mobile application with custom UI and data interaction. Option D (Microsoft Power BI) is wrong because it is a business analytics and visualization tool, not an app development platform; it cannot provide the interactive, data-entry functionality required for field technicians.

43
MCQmedium

A company runs a custom application on a cloud provider's infrastructure. The provider manages the physical servers, networking, and storage, but the company installs, configures, and patches the operating system and application. Which cloud service model is this?

A.Software as a Service (SaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Function as a Service (FaaS)
AnswerC

IaaS provides virtualized compute, storage, and networking as raw infrastructure blocks, with the provider maintaining only the physical data center, hosts, hypervisor, and network fabric. The customer provisions virtual machines, installs and patches the guest operating system, configures storage and firewall rules, and runs the custom application on top. In the scenario, the customer has control over the OS and app stack, which is exactly the IaaS responsibility model.

Why this answer

This scenario describes Infrastructure as a Service (IaaS) because the cloud provider manages the underlying physical infrastructure (servers, networking, storage), while the customer retains control over the operating system, middleware, and application. In IaaS, the customer is responsible for OS patching, configuration, and application management, which matches the given responsibilities.

Exam trap

The trap here is confusing IaaS with PaaS because both involve deploying applications, but the key differentiator is OS-level control and patching responsibility—IaaS gives you full OS access, while PaaS abstracts it away.

How to eliminate wrong answers

Option A is wrong because Software as a Service (SaaS) delivers a fully managed application to end users, where the provider handles everything including the OS and application, and the customer does not install or patch the OS. Option B is wrong because Platform as a Service (PaaS) provides a managed runtime environment where the provider manages the OS and middleware, and the customer only deploys code, not the OS or its patches. Option D is wrong because Function as a Service (FaaS) is an event-driven compute model where the provider manages the entire infrastructure and the customer only uploads individual functions, with no OS-level access or patching responsibility.

44
MCQmedium

A development team uses a cloud service to run applications where the provider manages the runtime environment, operating system, and middleware. The team only writes and uploads code. Which service model are they using?

A.IaaS (Infrastructure as a Service)
B.PaaS (Platform as a Service)
C.SaaS (Software as a Service)
D.FaaS (Function as a Service)
AnswerB

PaaS provides a managed hosting environment in which the provider handles the operating system, runtime, middleware, and underlying hardware, allowing developers to focus exclusively on writing and deploying application code. This directly fits a development team that wants to run applications in the cloud without provisioning or maintaining servers, while still having full control over their code and configuration.

Why this answer

The scenario describes the team writing and uploading code while the provider manages the runtime environment, operating system, and middleware. This is the defining characteristic of Platform as a Service (PaaS), where the cloud provider abstracts the underlying infrastructure and platform layers, allowing developers to focus solely on application code. In PaaS, the provider handles OS patching, runtime updates, and middleware configuration, which matches the description exactly.

Exam trap

The trap here is that candidates often confuse PaaS with IaaS because both involve deploying applications, but the key differentiator is who manages the runtime and middleware — PaaS abstracts them away, while IaaS requires the user to manage them.

How to eliminate wrong answers

Option A (IaaS) is wrong because IaaS provides virtualized computing resources (e.g., VMs, storage, networks) but the user is responsible for managing the runtime environment, operating system, and middleware; the team would need to install and configure these themselves, not just upload code. Option C (SaaS) is wrong because SaaS delivers fully functional software applications over the internet (e.g., Office 365, Salesforce) where users consume the application without writing or uploading code; the team in the question is actively developing and uploading code. Option D (FaaS) is wrong because FaaS (Function as a Service) is a subset of serverless computing where developers upload individual functions that are executed in response to events, but the provider still manages the runtime environment; however, the question specifies the team runs 'applications' and manages the 'runtime environment, operating system, and middleware' at a higher abstraction level than individual functions, and FaaS typically involves event-driven, stateless functions rather than full application hosting.

45
MCQhard

A company uses Microsoft 365 (a SaaS offering). A security incident occurs where an employee's account is compromised because the employee reused their corporate password on a personal website. According to the shared responsibility model, who is primarily responsible for this security failure?

A.The customer (the company using Microsoft 365)
B.Microsoft, because they provide the SaaS platform
C.Both Microsoft and the customer share equal responsibility
D.It depends on the contract terms with Microsoft
AnswerA

The customer is accountable for the identity plane in the Microsoft 365 shared responsibility model. Entra ID (Azure AD) tenant configuration, user accounts, passwords, and access policies like MFA and Conditional Access are all customer-managed controls. Because the incident stemmed from weak password practices and password reuse, the failure resides in the customer's cloud-hosted data and identity responsibilities, not in Microsoft's infrastructure or code.

Why this answer

In the Microsoft 365 shared responsibility model, the customer is responsible for securing user identities, including password hygiene and multi-factor authentication (MFA). Since the employee reused their corporate password on a personal website, this is a customer-side identity management failure, not a platform vulnerability. Microsoft secures the SaaS infrastructure, but customer-managed credentials fall under the customer's responsibility.

Exam trap

The trap here is that candidates often assume SaaS means Microsoft handles all security, but the shared responsibility model clearly places identity and credential management on the customer, especially for user-caused password reuse incidents.

How to eliminate wrong answers

Option B is wrong because Microsoft is responsible for the security of the SaaS platform itself (e.g., physical data centers, network infrastructure, and service-level controls), not for how customers manage their own user credentials or enforce password policies. Option C is wrong because the shared responsibility model does not assign equal responsibility for all incidents; identity and access management (IAM) tasks like password policies and user training are explicitly customer obligations. Option D is wrong because the shared responsibility model is a standard framework defined by Microsoft for all Microsoft 365 tenants, not a negotiable contract term; while specific contractual clauses may add details, the core division of responsibilities is fixed.

46
MCQmedium

During a Microsoft 365 planning workshop, keep a workload on-premises while using Microsoft cloud collaboration services. Cloud concept or benefit best matches this requirement?

A.Hybrid cloud
B.Sensitivity labels
C.Microsoft Planner
D.Data Loss Prevention (DLP)
AnswerA

Hybrid cloud combines on-premises or private resources with public cloud services.

Why this answer

A hybrid cloud model is the correct answer because it explicitly describes a scenario where an organization keeps certain workloads on-premises while integrating with Microsoft cloud collaboration services like Microsoft 365. This allows for a unified management plane, identity federation via Azure AD Connect, and seamless data synchronization between on-premises infrastructure and cloud services such as Exchange Online, SharePoint Online, or Teams.

Exam trap

The trap here is that candidates may confuse a specific Microsoft 365 feature (like sensitivity labels or DLP) with a cloud deployment model, failing to recognize that 'hybrid cloud' is the architectural concept that directly addresses the requirement of mixing on-premises and cloud services.

How to eliminate wrong answers

Option B is wrong because sensitivity labels are a Microsoft 365 compliance feature used to classify and protect data based on sensitivity, not a cloud deployment model that enables hybrid connectivity. Option C is wrong because Microsoft Planner is a task management application within Microsoft 365, not a cloud concept or benefit that supports keeping workloads on-premises. Option D is wrong because Data Loss Prevention (DLP) is a policy-based security feature to prevent unauthorized sharing of sensitive data, not a cloud architecture that allows hybrid workloads.

47
MCQeasy

During requirements gathering, an IT manager says the organization must let users provision resources from a portal without provider interaction. Cloud concept or benefit best matches this requirement?

A.On-demand self-service
B.Data Loss Prevention (DLP)
C.Microsoft Planner
D.Sensitivity labels
AnswerA

On-demand self-service allows consumers to provision resources automatically when needed.

Why this answer

On-demand self-service is a core NIST-defined characteristic of cloud computing that allows users to provision computing resources—such as virtual machines, storage, or network capacity—automatically through a web portal or API without requiring human interaction from the service provider. This directly matches the IT manager's requirement for users to provision resources from a portal without provider interaction, making option A correct.

Exam trap

The trap here is that candidates may confuse a specific Microsoft 365 feature (like Planner or sensitivity labels) with a fundamental cloud computing characteristic, or mistakenly think DLP is a provisioning mechanism, when the question explicitly tests the NIST definition of on-demand self-service.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) is a security policy and technology used to prevent sensitive data from being leaked or shared inappropriately, not a cloud concept for self-service resource provisioning. Option C is wrong because Microsoft Planner is a task management and planning application within Microsoft 365, not a cloud computing characteristic or benefit related to provisioning resources without provider interaction. Option D is wrong because sensitivity labels are classification and protection mechanisms applied to documents and emails to enforce access controls and encryption, not a cloud concept for automated resource provisioning.

48
MCQeasy

A department asks for the Microsoft 365 service best suited for enterprise video publishing and town hall recordings. Which service should they use?

A.Microsoft Purview Compliance Manager
B.Microsoft Stream on SharePoint
C.Microsoft Entra Privileged Identity Management
D.Microsoft Defender for Endpoint
AnswerB

Stream built on SharePoint supports enterprise video experiences.

Why this answer

Microsoft Stream on SharePoint is the correct service because it is designed for enterprise video publishing, including town hall recordings, live events, and on-demand video. It leverages SharePoint's storage and permissions model, allowing videos to be stored as files in document libraries with metadata, retention policies, and granular access controls, making it ideal for internal communications.

Exam trap

The trap here is that candidates may confuse Microsoft Stream (classic) with Stream on SharePoint, or think that Microsoft Purview Compliance Manager or Defender for Endpoint could handle video content due to their broad names, but the question specifically requires a service for enterprise video publishing and town hall recordings.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a compliance management solution that provides risk assessments and controls for regulatory standards (e.g., GDPR, ISO 27001), not a video publishing or recording service. Option C is wrong because Microsoft Entra Privileged Identity Management is an identity governance tool for managing, monitoring, and auditing privileged roles and just-in-time access, not for video content. Option D is wrong because Microsoft Defender for Endpoint is a security solution for endpoint detection and response (EDR), antivirus, and threat hunting, not for video publishing or town hall recordings.

49
MCQmedium

A service owner is comparing Microsoft 365 capabilities and needs to understand which security tasks Microsoft handles and which remain with the customer. Cloud concept or benefit best matches this requirement?

A.Microsoft Planner
B.Data Loss Prevention (DLP)
C.Sensitivity labels
D.Shared responsibility model
AnswerD

The shared responsibility model explains provider and customer responsibilities in cloud services.

Why this answer

The shared responsibility model defines which security tasks are handled by Microsoft (e.g., physical security, hypervisor patching) and which remain with the customer (e.g., user access management, data classification). This directly matches the service owner's need to understand the division of security responsibilities in Microsoft 365.

Exam trap

The trap here is that candidates may confuse specific security features (like DLP or sensitivity labels) with the overarching responsibility framework, failing to recognize that the shared responsibility model is the foundational concept that explains the division of security tasks.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management and collaboration tool, not a security concept that defines responsibility boundaries. Option B is wrong because Data Loss Prevention (DLP) is a specific security feature that helps prevent data leaks, but it does not describe the overarching model of shared security responsibilities. Option C is wrong because sensitivity labels are used to classify and protect data based on policies, but they are a tool within the customer's responsibilities, not the model that explains which tasks Microsoft handles versus the customer.

50
MCQmedium

A help desk lead is documenting the correct Microsoft 365 approach to keep a workload on-premises while using Microsoft cloud collaboration services. Cloud concept or benefit best matches this requirement?

A.Hybrid cloud
B.Sensitivity labels
C.Microsoft Planner
D.Data Loss Prevention (DLP)
AnswerA

Hybrid cloud combines on-premises or private resources with public cloud services.

Why this answer

A hybrid cloud model is the correct approach because it allows an organization to keep a specific workload on-premises while leveraging Microsoft cloud collaboration services (such as Exchange Online, SharePoint Online, or Teams). This is achieved through integration technologies like Azure AD Connect for identity synchronization and Exchange Hybrid Configuration Wizard for mail routing, enabling a seamless coexistence between on-premises and cloud environments.

Exam trap

The trap here is that candidates confuse a specific Microsoft 365 service or feature (like Planner or DLP) with a cloud deployment model, failing to recognize that 'hybrid cloud' is the architectural concept that directly addresses the requirement of keeping a workload on-premises while using cloud services.

How to eliminate wrong answers

Option B (Sensitivity labels) is wrong because sensitivity labels are a Microsoft Information Protection feature used to classify and protect data based on sensitivity, not to architect a hybrid deployment where workloads remain on-premises. Option C (Microsoft Planner) is wrong because Planner is a cloud-based task management tool within Microsoft 365, not a concept or benefit that describes keeping workloads on-premises while using cloud services. Option D (Data Loss Prevention) is wrong because DLP is a security policy mechanism to prevent unauthorized sharing of sensitive data, not a cloud deployment model that supports hybrid scenarios.

51
MCQhard

A company has 50 users with Microsoft 365 Business Basic licenses. They require the desktop versions of Office apps (Word, Excel, PowerPoint) for all 50 users. Additionally, 20 of those users need device management capabilities via Microsoft Intune. The company wants to minimize total licensing costs. Which licensing strategy is most cost-effective?

A.Upgrade all 50 users to Microsoft 365 Business Premium.
B.Upgrade all 50 users to Microsoft 365 Business Standard and purchase Microsoft Intune standalone licenses for the 20 users.
C.Upgrade 20 users to Microsoft 365 Business Premium and keep 30 users on Business Basic.
D.Upgrade all 50 users to Microsoft 365 Business Standard and purchase Microsoft Intune standalone licenses for all 50 users.
AnswerB

Microsoft 365 Business Standard includes the full Office desktop applications for every user, satisfying the requirement for all 50. Adding Microsoft Intune Plan 1 as a standalone per-user license lets you assign device-management capability only to the 20 users who need it, rather than paying for it across the entire tenant. This combination is the cheapest configuration that covers both requirements exactly, and it keeps licensing simple because the base SKU is uniform for all users.

Why this answer

Microsoft 365 Business Standard includes the desktop versions of Office apps, fulfilling the requirement for all 50 users. For the 20 users needing device management, purchasing standalone Microsoft Intune licenses is the most cost-effective approach, as it avoids the higher cost of upgrading all users to Business Premium, which includes Intune but also additional security features not required here.

Exam trap

The trap here is that candidates may assume Business Premium is the only way to get Intune, overlooking the option to purchase Intune standalone licenses separately, or they may forget that Business Basic does not include desktop Office apps, leading them to choose an option that fails the core requirement.

How to eliminate wrong answers

Option A is wrong because upgrading all 50 users to Microsoft 365 Business Premium is unnecessarily expensive; it includes Intune and advanced security features for all users, but only 20 users need device management. Option C is wrong because upgrading only 20 users to Business Premium leaves the remaining 30 users on Business Basic, which lacks the desktop versions of Office apps required by all 50 users. Option D is wrong because purchasing Microsoft Intune standalone licenses for all 50 users is wasteful; only 20 users need device management, so buying Intune for the other 30 users incurs unnecessary cost.

52
MCQmedium

A company with 200 users has Microsoft 365 Business Standard licenses. They need to add Microsoft 365 Defender for Office 365 (Plan 2) for increased protection against advanced threats. What should they purchase?

A.Upgrade each user to Microsoft 365 Business Premium
B.Purchase the Microsoft 365 Defender for Office 365 Plan 2 add-on
C.Purchase Microsoft 365 E3 licenses
D.Install the Microsoft Defender for Endpoint standalone subscription
AnswerB

The Microsoft 365 Defender for Office 365 Plan 2 add-on is the correct choice because it can be licensed per user directly onto an existing Microsoft 365 Business Standard subscription. This add-on supplies advanced email and collaboration protection that goes beyond the baseline Exchange Online Protection controls, including Threat Explorer, advanced hunting, automated investigation and response, and attack simulation training. It is designed for tenants that already have a qualifying base plan but need the higher tier of Defender for Office 365 without switching suites.

Why this answer

Microsoft 365 Business Standard licenses include basic email security but lack advanced threat protection features like automated investigation, threat hunting, and simulation training. Purchasing the Microsoft 365 Defender for Office 365 Plan 2 add-on directly adds these capabilities to existing Business Standard users without requiring a license upgrade, making it the most cost-effective and targeted solution.

Exam trap

The trap here is that candidates often confuse the licensing tiers and assume that upgrading to Business Premium is the only way to get advanced security, when in fact Microsoft offers targeted add-ons like Defender for Office 365 Plan 2 that can be layered onto existing Business Standard subscriptions without a full suite upgrade.

How to eliminate wrong answers

Option A is wrong because upgrading to Microsoft 365 Business Premium would replace the existing Business Standard licenses with a more expensive suite that includes Defender for Office 365 Plan 1 (not Plan 2) plus other features like Intune and Azure AD P1, which are unnecessary for the stated requirement. Option C is wrong because Microsoft 365 E3 licenses are a different licensing plan intended for enterprise customers, not a direct upgrade path from Business Standard, and they would require a full license migration and higher per-user cost without specifically adding Defender for Office 365 Plan 2. Option D is wrong because Microsoft Defender for Endpoint is a separate product focused on endpoint device protection (antivirus, EDR), not email and collaboration security, and does not provide the advanced threat protection for Exchange Online, SharePoint, and Teams that Defender for Office 365 Plan 2 delivers.

53
MCQeasy

Refer to the exhibit. You have a Conditional Access policy as shown. A user reports they cannot access Exchange Online from a non-compliant device. What is the most likely reason?

A.The device is not marked as compliant
B.The policy only applies to administrators
C.The user has not registered for MFA
D.The policy is disabled
AnswerA

The conditional access policy includes the grant control "Require device to be marked as compliant." If the device is not enrolled in Microsoft Intune or does not meet the configured compliance policy, this control is not satisfied, and access is denied. This is the immediate and technical reason the user is blocked, regardless of other grants like MFA.

Why this answer

The Conditional Access policy shown requires device compliance for Exchange Online access. When a device is non-compliant, the policy blocks access regardless of user identity or MFA status. The most likely reason for the user's inability to access Exchange Online is that the device is not marked as compliant, which is the condition explicitly enforced by the policy.

Exam trap

The trap here is that candidates may assume MFA or admin-only scoping is the issue, but the policy explicitly targets device compliance, which is the direct cause of the block.

How to eliminate wrong answers

Option B is wrong because the policy does not specify 'Only apply to administrators' — it applies to all users or a specific user group, not just admins. Option C is wrong because MFA registration is not the blocking factor; the policy targets device compliance, not authentication strength. Option D is wrong because if the policy were disabled, it would not enforce any restrictions, and the user would not be blocked.

54
MCQeasy

A sales manager wants to track customer interactions, manage leads, and automate follow-up emails from a single platform. Which Microsoft 365 service is specifically designed for customer relationship management (CRM)?

A.Microsoft Bookings
B.Microsoft Dynamics 365 Sales
C.Microsoft Power Automate
D.Microsoft To Do
AnswerB

Microsoft Dynamics 365 Sales is a purpose-built CRM application that leverages the Dataverse (Common Data Service) to store leads, contacts, accounts, and opportunities with full relationship hierarchies. It records customer interactions such as emails, calls, meetings, and notes as activities, while sales automation features—including workflows and Power Automate connectors—can trigger follow-up actions automatically. Its dashboards and built-in sales insights give managers the analytics needed to monitor pipeline health, making it the correct choice here.

Why this answer

Microsoft Dynamics 365 Sales is the dedicated CRM service within the Microsoft 365 ecosystem, purpose-built for tracking customer interactions, managing leads, and automating follow-up emails. Unlike general productivity tools, it provides a unified platform with lead scoring, opportunity management, and workflow automation specifically for sales processes.

Exam trap

The trap here is that candidates often confuse Microsoft Bookings (a scheduling tool) or Power Automate (an automation tool) with a full CRM solution, failing to recognize that Dynamics 365 Sales is the only option specifically designed for end-to-end customer relationship management.

How to eliminate wrong answers

Option A is wrong because Microsoft Bookings is a scheduling and appointment management tool, not a CRM platform; it lacks lead management and automated follow-up email capabilities. Option C is wrong because Microsoft Power Automate is a workflow automation service that can integrate with CRM systems but is not itself a CRM platform; it does not provide native lead tracking or customer interaction management. Option D is wrong because Microsoft To Do is a personal task management app with no CRM features such as lead tracking, customer history, or automated email sequences.

55
MCQhard

A compliance officer wants to proactively prevent users from sending emails that contain sensitive personal data (e.g., credit card numbers) to external recipients. When a user attempts to send such an email, they should see a policy tip explaining the restriction and be blocked from sending. Which Microsoft Purview feature should be configured?

A.Microsoft Purview Data Loss Prevention (DLP) policy
B.Microsoft Purview Information Barriers
C.Microsoft Purview Records Management
D.Microsoft Purview Communication Compliance
AnswerA

Microsoft Purview DLP policies use built-in sensitive information types (e.g., credit card numbers) to inspect message body and attachments as they are composed, then apply actions such as blocking the send action and displaying customizable policy tips. This prevents the exfiltration of sensitive data before it leaves the organization, satisfying the compliance officer's proactive prevention requirement.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policy is the correct feature because it is specifically designed to detect sensitive data (e.g., credit card numbers) in transit and enforce actions such as showing a policy tip and blocking the email. DLP policies use sensitive information types (e.g., Credit Card Number) and conditions to inspect email content in Exchange Online, triggering a block action with an end-user notification when a match occurs.

Exam trap

The trap here is that candidates often confuse Communication Compliance (which reviews messages after they are sent) with DLP (which proactively blocks messages in transit), leading them to select Communication Compliance when the question explicitly requires proactive blocking with a policy tip.

How to eliminate wrong answers

Option B (Microsoft Purview Information Barriers) is wrong because Information Barriers are used to prevent communication between specific groups or users (e.g., to avoid conflicts of interest), not to scan for sensitive data patterns like credit card numbers. Option C (Microsoft Purview Records Management) is wrong because Records Management focuses on classifying, retaining, and disposing of records based on regulatory requirements, not on real-time content inspection and blocking of outbound emails. Option D (Microsoft Purview Communication Compliance) is wrong because Communication Compliance is designed to detect policy violations in communications (e.g., harassment, insider trading) by reviewing messages after they are sent, not to proactively block emails based on sensitive data patterns.

56
MCQeasy

A small business with 10 users needs the fully installed desktop versions of Office apps (Word, Excel, PowerPoint), business-class email, and 1 TB of cloud storage per user. They do not require advanced security or compliance features. Which Microsoft 365 plan is the most cost-effective choice?

A.Microsoft 365 Business Basic
B.Microsoft 365 Business Standard
C.Microsoft 365 E3
D.Office 365 E1
AnswerB

Microsoft 365 Business Standard is the correct choice because it bundles the fully installed Microsoft 365 desktop apps (Word, Excel, PowerPoint, Outlook, and others) with Exchange Online email, SharePoint, Teams, and 1 TB of OneDrive storage per user. It is designed for small businesses with up to 300 users, providing all the stated needs at a per-user cost that is lower than enterprise-level plans like E3. This makes it the optimal balance of functionality and price for a 10-user organization.

Why this answer

Microsoft 365 Business Standard is the most cost-effective plan for this small business because it includes the fully installed desktop versions of Office apps (Word, Excel, PowerPoint), business-class email (Exchange Online), and 1 TB of OneDrive cloud storage per user. It meets all stated requirements without the higher cost of E3 or the lack of desktop apps in Business Basic or Office 365 E1.

Exam trap

The trap here is that candidates often confuse 'Business Basic' (which has web-only apps) with 'Business Standard' (which includes desktop apps), or assume that 'E3' is always the best choice for any business due to its enterprise branding, overlooking the cost and feature overkill for small businesses without advanced security needs.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Basic provides only web and mobile versions of Office apps, not the fully installed desktop versions required. Option C is wrong because Microsoft 365 E3 includes advanced security and compliance features (e.g., Data Loss Prevention, eDiscovery) that the customer does not need, making it unnecessarily expensive for a 10-user business. Option D is wrong because Office 365 E1 lacks the desktop Office apps entirely, offering only web-based versions, and also includes advanced compliance features not required.

57
MCQmedium

A company with 120 users needs desktop Office apps, Intune device management, and enhanced security. Which option best matches the requirement?

A.Microsoft Defender for Cloud only
B.Azure Virtual Desktop only
C.A free personal Microsoft account only
D.Microsoft 365 Business Premium
AnswerD

Business Premium combines productivity apps with Intune and enhanced security features for SMBs.

Why this answer

Microsoft 365 Business Premium includes desktop Office apps (Office 365 E3 equivalent), Intune for device management, and advanced security features such as Microsoft Defender for Office 365, Azure Information Protection, and Conditional Access. This bundle directly satisfies all three requirements for a 120-user organization without needing separate subscriptions.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a security monitoring tool for cloud infrastructure) with Microsoft Defender for Office 365 (an email and collaboration security service), leading them to incorrectly select Option A when they see 'enhanced security' without recognizing the missing Office apps and device management.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud is a cloud workload protection platform (CWPP) for securing Azure, on-premises, and multi-cloud resources; it does not include desktop Office apps or Intune device management. Option B is wrong because Azure Virtual Desktop provides virtualized Windows desktops and apps, but it does not include Intune device management or the specific enhanced security features like Defender for Office 365; it also requires separate licensing for Office apps. Option C is wrong because a free personal Microsoft account offers no enterprise-grade desktop Office apps, no Intune device management, and no enhanced security controls; it is intended for individual consumer use only.

58
MCQmedium

A company with 300 Microsoft 365 E3 users needs to add advanced identity protection features: Microsoft Entra ID Premium P2 and Microsoft Defender for Identity. They want to add these capabilities without upgrading all users to E5. What is the most cost-effective licensing strategy?

A.Upgrade all users to Microsoft 365 E5.
B.Add Microsoft Entra ID Premium P2 and Microsoft Defender for Identity as standalone add-ons.
C.Add the Microsoft 365 E5 Security add-on for each user.
D.Add Enterprise Mobility + Security E5 add-on.
AnswerC

The Microsoft 365 E5 Security add-on is the correct choice because it attaches the necessary proprietary workloads to E3 without a full E5 upgrade. This per-user add-on bundles Microsoft Entra ID Premium P2, Microsoft Defender for Identity, Defender for Office 365, Defender for Endpoint, and other advanced security tools explicitly designed to close the security gap. It provides the advanced protection the company requires while remaining more economical than upgrading to E5 or assembling separate add-ons.

Why this answer

The Microsoft 365 E5 Security add-on bundles Microsoft Entra ID Premium P2 and Microsoft Defender for Identity (along with other security features) at a lower per-user cost than purchasing them separately, and it can be added to an existing E3 subscription without upgrading the entire license. This provides the required identity protection capabilities cost-effectively for all 300 users.

Exam trap

The trap here is that candidates often confuse the Enterprise Mobility + Security E5 add-on with the E5 Security add-on, not realizing that EMS E5 lacks Microsoft Defender for Identity and is therefore insufficient for the stated requirements.

How to eliminate wrong answers

Option A is wrong because upgrading all users to Microsoft 365 E5 would be significantly more expensive than adding the E5 Security add-on, as E5 includes many additional features (e.g., advanced compliance, analytics) not required by the company. Option B is wrong because purchasing Microsoft Entra ID Premium P2 and Microsoft Defender for Identity as standalone add-ons would cost more per user than the bundled E5 Security add-on, which includes both plus additional security services like Microsoft Purview Information Protection and Microsoft 365 Defender. Option D is wrong because Enterprise Mobility + Security E5 includes Microsoft Entra ID Premium P2 and Microsoft Intune but does not include Microsoft Defender for Identity; it would require an additional purchase for that capability, making it less cost-effective than the E5 Security add-on.

59
MCQmedium

A company is preparing for a merger and wants to prevent communication between the Human Resources and Research departments regarding sensitive salary data during the due diligence period. They need a Microsoft Purview solution that can block all email and chat between users in these two groups, as well as prevent file sharing in Teams and SharePoint. Which solution should they configure?

A.Information Barriers
B.Data Loss Prevention (DLP)
C.Sensitivity Labels
D.eDiscovery (Premium)
AnswerA

Information Barriers in Microsoft Purview are purpose-built to restrict real-time and async collaboration between defined user segments. Admins define segments based on attributes like department or organization and create policy rules that block one-way or two-way communication; the policy is enforced by the service layer itself across Exchange Online, Microsoft Teams, and file-sharing workflows. This goes far beyond individual content protection—it prohibits the relationship itself, so an attempted email or Teams chat between barred users is rejected before the message is delivered.

Why this answer

Information Barriers (IB) in Microsoft Purview are specifically designed to prevent communication and collaboration between defined user groups, such as HR and Research, by blocking email, Teams chat, and SharePoint/OneDrive file sharing. This solution enforces policies at the transport and service level, ensuring that sensitive salary data is not inadvertently shared during the merger due diligence period.

Exam trap

The trap here is that candidates often confuse Information Barriers with DLP, assuming that blocking sensitive data patterns is equivalent to blocking all communication between groups, but DLP cannot enforce department-wide communication restrictions—it only acts on content matches.

How to eliminate wrong answers

Option B (Data Loss Prevention) is wrong because DLP policies monitor and prevent the sharing of sensitive data (e.g., credit card numbers) based on content inspection, but they do not block all communication between two entire departments—they only act on specific data patterns. Option C (Sensitivity Labels) is wrong because labels classify and protect data with encryption or visual markings, but they do not enforce communication blocks between groups; they require users to apply them and do not prevent chat or email between departments. Option D (eDiscovery Premium) is wrong because eDiscovery is used for searching, preserving, and exporting content for legal or investigative purposes, not for proactively blocking real-time communication or file sharing.

60
Drag & Dropmedium

Drag and drop the steps to set up a Microsoft Teams meeting with external participants into the correct order.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Creating a Teams meeting involves scheduling, adding attendees, setting options, and sending the invite.

61
MCQeasy

A company has 10 users who need only Exchange Online mailboxes and Microsoft Teams. They do not need desktop versions of Office apps. What is the most cost-effective Microsoft 365 plan for this requirement?

A.Microsoft 365 Business Basic
B.Microsoft 365 Apps for Business
C.Microsoft 365 Business Standard
D.Office 365 E1
AnswerA

Microsoft 365 Business Basic is the correct choice because it bundles hosted Exchange Online mailboxes with Microsoft Teams, and it does so at the lowest per-user price among plans that include both services. It also provides web and mobile versions of Office apps, which is sufficient for users who only need email and chat/collaboration. For a 10-person tenant, this plan avoids paying for desktop Office applications that are not required.

Why this answer

Microsoft 365 Business Basic provides Exchange Online mailboxes and Microsoft Teams, along with web and mobile versions of Office apps, without including desktop Office installations. This makes it the most cost-effective plan for the 10 users who need only email and Teams, as it offers the required services at the lowest per-user price among the options.

Exam trap

The trap here is that candidates often confuse 'Office 365 E1' as the cheapest option due to its 'E' enterprise branding, but Microsoft 365 Business Basic is actually the lowest-cost plan that includes both Exchange Online and Teams, and the exam tests the distinction between business and enterprise pricing tiers.

How to eliminate wrong answers

Option B (Microsoft 365 Apps for Business) is wrong because it includes only the desktop versions of Office apps (e.g., Word, Excel, PowerPoint) and does not include Exchange Online mailboxes or Microsoft Teams, so it fails to meet the core requirements. Option C (Microsoft 365 Business Standard) is wrong because it includes desktop Office apps, which are not needed, making it more expensive than necessary for the stated needs. Option D (Office 365 E1) is wrong because, while it provides Exchange Online and Teams, it is an enterprise plan with a higher per-user cost than Business Basic, and it is not the most cost-effective choice for a small group of 10 users who do not require enterprise-grade compliance or advanced features.

62
MCQeasy

A company uses a cloud service where they can provision virtual machines, install any operating system, and manage all software on those machines. The cloud provider is responsible for the physical hardware, data center security, and network infrastructure. Which cloud service model does this represent?

A.IaaS (Infrastructure as a Service)
B.PaaS (Platform as a Service)
C.SaaS (Software as a Service)
D.FaaS (Function as a Service)
AnswerA

In the Infrastructure-as-a-Service model, the cloud provider supplies fundamental computing resources such as virtual machines, storage, and virtual networks on demand. Subscribers can provision these VMs with their own operating system, middleware, and applications, retaining administrative control over the OS, security patching, and software configuration while the provider maintains the physical host hardware and datacenter infrastructure. This directly matches the scenario of provisioning a virtual machine.

Why this answer

This scenario describes Infrastructure as a Service (IaaS) because the customer has full control over virtual machines, including the operating system and all installed software, while the cloud provider manages the underlying physical hardware, data center security, and network infrastructure. In IaaS, the provider offers virtualized computing resources over the internet, and the customer is responsible for everything above the hypervisor layer, such as OS patches, application configuration, and middleware.

Exam trap

The trap here is that candidates often confuse IaaS with PaaS because both involve virtual machines, but the key differentiator is whether the customer manages the operating system and software stack (IaaS) or the provider manages them (PaaS).

How to eliminate wrong answers

Option B is wrong because PaaS (Platform as a Service) provides a managed platform where the provider handles the runtime, middleware, and OS, and the customer only deploys code; the customer cannot install or manage an arbitrary operating system on virtual machines. Option C is wrong because SaaS (Software as a Service) delivers fully managed applications accessed via a web browser or client, with no customer control over the underlying infrastructure, OS, or virtual machines. Option D is wrong because FaaS (Function as a Service) is a serverless compute model where customers deploy individual functions that execute in response to events, and they have no visibility or control over virtual machines or operating systems.

63
MCQmedium

An administrator is reviewing a request from users who need to enterprise licensing options for an organization with more complex or larger-scale requirements. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Microsoft Forms
C.Microsoft 365 Enterprise plans
D.Microsoft Stream
AnswerC

Enterprise plans such as E3 and E5 are intended for larger and more complex organizations.

Why this answer

Microsoft 365 Enterprise plans (E3, E5) are designed for organizations with complex or large-scale requirements, offering advanced security, compliance, analytics, and voice capabilities beyond the Business plans. The question specifically asks about enterprise licensing options, making C the most relevant concept.

Exam trap

The trap here is that candidates may confuse a specific application (like Whiteboard, Forms, or Stream) with a licensing plan, when the question explicitly asks for the 'licensing, admin, or support concept' relevant to enterprise-scale requirements.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a collaboration app, not an enterprise licensing plan or support concept. Option B is wrong because Microsoft Forms is a survey and data collection tool, not a licensing or support offering. Option D is wrong because Microsoft Stream is a video service, not an enterprise licensing plan or support concept.

64
MCQmedium

A compliance administrator needs to retain mailbox content for legal investigation. Which Microsoft 365 capability is the best fit?

A.Microsoft Teams live events
B.Microsoft Bookings
C.OneDrive sync client
D.eDiscovery and retention capabilities in Microsoft Purview
AnswerD

Purview eDiscovery and retention help preserve and search content for investigations.

Why this answer

eDiscovery and retention capabilities in Microsoft Purview are designed specifically for legal investigations, allowing compliance administrators to preserve mailbox content via legal holds, search across mailboxes, and export data for litigation. This directly meets the requirement to retain mailbox content for legal investigation, unlike the other options which serve unrelated business functions.

Exam trap

The trap here is that candidates may confuse general data storage or communication tools (like OneDrive or Teams) with compliance-specific features, overlooking that only Purview provides the legal hold and search capabilities required for retaining mailbox content in investigations.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams live events is a broadcast and meeting feature for large audiences, not a compliance tool for retaining mailbox content. Option B is wrong because Microsoft Bookings is a scheduling and appointment management app, lacking any data retention or eDiscovery functionality. Option C is wrong because the OneDrive sync client is for synchronizing files between a local device and cloud storage, not for preserving or searching mailbox content for legal purposes.

65
MCQmedium

A compliance officer needs to automatically detect when an employee attempts to send an email containing a social security number (SSN) to an external recipient. The solution should block the email from being sent and notify the employee with a policy tip. Which Microsoft Purview solution should be configured?

A.Microsoft Purview Data Loss Prevention (DLP)
B.Microsoft Purview Information Protection
C.Microsoft Purview eDiscovery
D.Microsoft Purview Audit
AnswerA

Microsoft Purview Data Loss Prevention (DLP) in Exchange Online includes policies that scan email content in transit for sensitive information types such as social security numbers. When a match occurs, DLP can enforce an action like blocking the message from being sent and generating a policy tip to the sender, which satisfies the automatic detection and remediation requirement.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect sensitive information (such as social security numbers) in emails and other data in transit. When a DLP policy is configured with a rule that matches the SSN condition and an action to block the message, it automatically prevents the email from being sent and displays a policy tip to the user, notifying them of the violation. This aligns directly with the requirement to both block the email and provide real-time user notification.

Exam trap

The trap here is that candidates often confuse Information Protection (labeling) with Data Loss Prevention (enforcement), assuming that applying a sensitivity label automatically blocks data exfiltration, when in fact DLP policies are required to enforce actions like blocking and policy tips.

How to eliminate wrong answers

Option B (Microsoft Purview Information Protection) is wrong because it focuses on classifying and labeling sensitive data (e.g., applying sensitivity labels) but does not include the ability to block email transmission or enforce real-time actions like policy tips; it is a classification and protection layer, not a blocking enforcement mechanism. Option C (Microsoft Purview eDiscovery) is wrong because it is used for searching and exporting content for legal or investigative purposes, not for preventing data exfiltration or providing user notifications during email composition. Option D (Microsoft Purview Audit) is wrong because it logs user and admin activities for forensic review but cannot block emails or display policy tips; it is a passive logging tool, not an active enforcement solution.

66
MCQmedium

A legal firm needs to send a confidential document to a client via email. The firm requires that the client cannot forward or print the email and that the email expires after seven days. Which Microsoft Purview solution should they use?

A.Microsoft Purview Message Encryption
B.Data Loss Prevention (DLP) policies
C.Sensitivity labels
D.eDiscovery (Premium)
AnswerA

Microsoft Purview Message Encryption is the correct choice because it uses Azure Rights Management (Azure RMS) to encrypt email messages and apply persistent usage restrictions on the client's copy, even after they are sent. It can prevent forwarding, disable printing, and set an expiration date that revokes access to the message after a specified time. This works seamlessly with external recipients regardless of their email provider, making it ideal for a legal firm sending confidential documents to a client.

Why this answer

Microsoft Purview Message Encryption (A) is the correct solution because it allows the legal firm to apply usage restrictions such as preventing forwarding and printing, and to set an expiration period of seven days on the email. This is achieved through Azure Rights Management (Azure RMS) templates that enforce these controls directly on the encrypted message, ensuring the client cannot bypass the restrictions.

Exam trap

The trap here is that candidates often confuse sensitivity labels with Message Encryption, not realizing that while labels can apply encryption, they do not natively support per-message expiration or granular usage restrictions like 'do not forward' and 'do not print' without additional configuration via Azure RMS templates, which is exactly what Message Encryption provides out-of-the-box.

How to eliminate wrong answers

Option B (Data Loss Prevention (DLP) policies) is wrong because DLP policies are designed to detect and prevent the accidental sharing of sensitive information (e.g., credit card numbers) by blocking or warning users, but they do not provide granular post-delivery controls like 'do not forward' or 'expire after 7 days'. Option C (Sensitivity labels) is wrong because while sensitivity labels can apply encryption and visual markings, they do not natively support per-message expiration or specific usage restrictions like 'do not forward' or 'do not print' without being combined with Azure RMS templates; the question asks for a solution that directly provides these controls, which is Message Encryption. Option D (eDiscovery Premium) is wrong because eDiscovery is used for legal hold, search, and export of content for litigation or investigation, not for controlling how an email is used after it is sent.

67
MCQeasy

A company's e-commerce website experiences a sudden surge in traffic during a promotional event. The cloud infrastructure automatically adds additional virtual servers to handle the load and removes them when traffic subsides, without any manual intervention from the IT team. Which cloud computing characteristic does this demonstrate?

A.Rapid elasticity
B.On-demand self-service
C.Resource pooling
D.Measured service
AnswerA

Correct. Rapid elasticity allows automatic scaling of resources to meet fluctuating demand, as described in the scenario.

Why this answer

The scenario describes the cloud infrastructure automatically scaling virtual servers up and down in response to traffic changes, which is the defining characteristic of rapid elasticity. This capability allows resources to be provisioned and released elastically, often automatically, to match demand at any given time, as defined by NIST SP 800-145.

Exam trap

The trap here is that candidates confuse 'on-demand self-service' (manual provisioning by a user) with 'rapid elasticity' (automatic scaling by the cloud platform), but the key differentiator is the lack of manual intervention in the scenario.

How to eliminate wrong answers

Option B is wrong because on-demand self-service refers to a user's ability to provision computing resources (e.g., spinning up a VM) without human interaction with the provider, not the automatic scaling of resources based on load. Option C is wrong because resource pooling describes the provider's multi-tenant model where physical and virtual resources are dynamically assigned to serve multiple customers, not the automatic scaling behavior. Option D is wrong because measured service involves metering and reporting resource usage for billing and optimization (e.g., pay-per-use), not the automatic addition or removal of servers in response to demand.

68
MCQhard

A company is deploying a cloud solution where they have the ability to quickly scale up resources during peak demand and scale down during off-peak hours, paying only for what they use. They also need the provider to automatically manage the underlying platform, including patching the operating system. Which combination of cloud characteristics and service model best describes this scenario?

A.Elasticity and PaaS
B.Scalability and IaaS
C.Rapid elasticity and SaaS
D.Measured service and PaaS
AnswerA

Elasticity automatically adjusts computing capacity in real time to match fluctuating demand, while PaaS offloads management of the underlying OS, runtime, and middleware to the provider. This combination fits the scenario because the customer can scale the application on demand without handling infrastructure patching, while the provider maintains the platform. Unlike IaaS, the OS is not the customer's responsibility; unlike SaaS, the application itself remains under customer control.

Why this answer

The scenario describes elasticity (the ability to scale resources up and down automatically based on demand) and Platform as a Service (PaaS), where the provider manages the underlying platform, including OS patching. Elasticity is a key cloud characteristic that enables dynamic scaling, and PaaS abstracts infrastructure management, aligning perfectly with the requirement for automatic platform maintenance.

Exam trap

The trap here is confusing scalability (a general capability) with elasticity (dynamic, automated scaling), and assuming IaaS includes platform management like patching, which it does not—IaaS only provides virtual machines where the customer handles the OS.

How to eliminate wrong answers

Option B is wrong because IaaS (Infrastructure as a Service) does not include automatic OS patching; the customer is responsible for managing the operating system and middleware. Option C is wrong because SaaS (Software as a Service) delivers fully managed applications, not a platform for deploying custom code, and the scenario requires platform-level control, not just application usage. Option D is wrong because measured service (metering and billing) is a cloud characteristic that applies to all service models, but it does not describe the automatic scaling or platform management mentioned in the scenario.

69
MCQhard

A global organization relies on Microsoft 365 for critical business operations. They require guaranteed response times for support incidents: critical severity issues must receive an initial response within 15 minutes, and high severity within 1 hour. They also need proactive monitoring and advice from a designated support account manager. Which support plan should they purchase?

A.Microsoft 365 Standard Support (included with subscription)
B.Microsoft ProDirect Support
C.Microsoft Unified Support
D.Microsoft Premier Support
AnswerB

ProDirect Support is the correct choice because it provides the fastest guaranteed critical-severity response in the Microsoft 365 portfolio—15 minutes, compared to the 1-hour standard—and pairs that with a dedicated support account manager. This manager delivers proactive services such as incident avoidance, readiness assessments, and architectural guidance, making it ideal for a global organization where downtime has immediate operational impact.

Why this answer

ProDirect Support is the correct choice because it offers guaranteed response times of 15 minutes for critical severity incidents and 1 hour for high severity incidents, along with proactive monitoring and a designated support account manager. This plan is specifically designed for organizations that require rapid, managed support for critical business operations, unlike the standard or legacy plans.

Exam trap

The trap here is that candidates often confuse ProDirect Support with Premier Support, assuming Premier is the only premium option, but ProDirect is the correct modern plan for cloud-focused organizations needing guaranteed response times and a designated account manager.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Standard Support (included with subscription) does not provide guaranteed response times or a designated account manager; it offers only basic reactive support with no service level agreements (SLAs) for initial response. Option C is wrong because Microsoft Unified Support is a legacy plan that has been retired and replaced by ProDirect and Premier; it does not offer the specific 15-minute critical response guarantee or a dedicated account manager in the same way. Option D is wrong because Microsoft Premier Support is a separate, higher-cost plan typically for on-premises and hybrid environments, and while it offers fast response times, it is not the standard plan for Microsoft 365 cloud services and does not include proactive monitoring as a core feature like ProDirect does.

70
MCQmedium

A compliance administrator needs to apply encryption and usage restrictions to confidential documents. Which Microsoft 365 capability is the best fit?

A.OneDrive sync client
B.Sensitivity labels
C.Microsoft Bookings
D.Microsoft Teams live events
AnswerB

Sensitivity labels classify and protect content, including encryption and access restrictions.

Why this answer

Sensitivity labels from Microsoft Purview Information Protection are the correct choice because they allow the compliance administrator to apply both encryption and usage restrictions (such as 'Do Not Forward' or custom permissions) directly to confidential documents. This capability integrates with Microsoft 365 apps to enforce protection persistently, even when the document is shared outside the organization.

Exam trap

The trap here is that candidates often confuse the OneDrive sync client's ability to sync encrypted files with the ability to apply encryption itself, or they mistakenly think Microsoft Teams live events can restrict document usage because it is a 'live' feature with attendee controls.

How to eliminate wrong answers

Option A is wrong because the OneDrive sync client is a file synchronization tool that syncs files between cloud and local devices; it does not apply encryption or usage restrictions to documents. Option C is wrong because Microsoft Bookings is a scheduling and appointment management tool, with no capability to enforce document-level encryption or usage restrictions. Option D is wrong because Microsoft Teams live events is a broadcast and streaming feature for large audiences; it does not provide document-level encryption or usage restriction controls.

71
MCQeasy

A team needs to create a shared online document and collaborate in real time with colleagues. They require built-in version history and the ability to access the document from any device. Which Microsoft 365 app should they use?

A.Microsoft Word (desktop)
B.Microsoft Word Online
C.Microsoft OneNote
D.Microsoft Teams
AnswerB

Microsoft Word Online is the correct choice because it runs entirely in a web browser, so no software installation is required and it works on any device with internet access. It provides full real-time co-authoring with presence indicators, automatic saving, and version history through OneDrive or SharePoint. This makes the shared document instantly accessible and lets multiple people edit simultaneously without extra setup.

Why this answer

Microsoft Word Online is the correct choice because it is a browser-based version of Word that enables real-time co-authoring, automatic version history, and access from any device with an internet connection. Unlike the desktop app, it does not require installation and syncs changes instantly via OneDrive or SharePoint, meeting all stated requirements.

Exam trap

The trap here is that candidates often confuse Microsoft Teams as the app for document collaboration, but Teams itself is a hub for communication and relies on integrated Office Online apps for actual document editing, making Word Online the direct answer for the specific requirements of shared document creation and real-time collaboration.

How to eliminate wrong answers

Option A is wrong because Microsoft Word (desktop) requires installation on a specific device, lacks built-in real-time co-authoring without additional configuration (e.g., saving to OneDrive with AutoSave enabled), and does not inherently provide cross-device access without manual file transfer. Option C is wrong because Microsoft OneNote is a digital notebook app designed for free-form note-taking and organization, not for creating structured shared documents with the same real-time collaboration and version history features as Word Online. Option D is wrong because Microsoft Teams is a collaboration platform for chat, meetings, and channel-based file sharing, but its document editing capabilities rely on integrated Office Online apps (like Word Online) rather than providing a standalone document creation and editing experience.

72
MCQhard

A legal team needs to preserve all data belonging to a former employee who is involved in litigation. The preservation must cover Exchange Online email, SharePoint sites, Teams messages, and OneDrive files. Which Microsoft Purview solution should they use to enforce the preservation?

A.eDiscovery (Standard) case hold
B.Data Lifecycle Management retention policy
C.Sensitivity label with retention marking
D.Audit log search
AnswerA

eDiscovery (Standard) case hold creates a preservation hold within a Microsoft Purview eDiscovery case. It lets the legal team target a former employee's Exchange Online mailbox, OneDrive for Business, SharePoint sites, and Teams content, and all items in those locations are held in place, including metadata and versions. Because the hold is Custodian-based and applies organization-wide to the employee's data, it satisfies the requirement to preserve all data for legal proceedings.

Why this answer

eDiscovery (Standard) case hold is the correct solution because it allows legal teams to place a legal hold on all data sources associated with a specific user, including Exchange Online mailboxes, SharePoint sites, OneDrive accounts, and Teams messages. This preserves the data in its current state, preventing modification or deletion, which is essential for litigation. Unlike other options, eDiscovery holds are designed specifically for legal preservation scenarios and can target multiple workloads simultaneously.

Exam trap

The trap here is that candidates often confuse a retention policy (which is automated and rule-based) with a legal hold (which is manual, case-specific, and preserves data for litigation), leading them to choose Data Lifecycle Management instead of eDiscovery.

How to eliminate wrong answers

Option B is wrong because Data Lifecycle Management retention policies are designed for automated data retention and deletion based on regulatory or business rules, not for ad-hoc legal holds triggered by litigation. Option C is wrong because sensitivity labels with retention markings are used to classify and optionally retain data based on sensitivity, but they cannot enforce a comprehensive legal hold across all user data sources like eDiscovery can. Option D is wrong because Audit log search is a tool for reviewing historical activity logs, not for preserving data; it does not prevent data modification or deletion.

73
MCQmedium

Adventure Works is a non-profit with 200 users. They use Microsoft 365 for Nonprofits. They need to: (1) Restrict access to sensitive donor information to only specific users; (2) Automatically archive emails older than 5 years; (3) Allow volunteers to access shared files from their personal devices without enrolling them in device management; (4) Use AI to summarize long email threads and suggest replies. Which Microsoft 365 services or features should they use?

A.Sensitivity labels, Exchange Online archiving, SharePoint Online, Microsoft Copilot for Microsoft 365
B.Sensitivity labels, Exchange Online in-place hold, SharePoint Online, Microsoft Editor
C.Microsoft Purview Data Loss Prevention, Exchange Online archiving, Microsoft Teams, Microsoft Copilot for Microsoft 365
D.Azure Information Protection, Exchange Online retention policies, OneDrive, Microsoft Copilot for Microsoft 365
AnswerA

This combination is correct because Sensitivity labels in Microsoft Purview enable classification and permission restrictions (e.g., encrypt or view-only) on documents and emails, meeting the access-control requirement. Exchange Online archiving provides an In-Place Archive mailbox for email retention and compliance without needing separate on-premises storage. SharePoint Online supports granular external sharing via secure links, guest access, and expiration policies—all without requiring device management or Intune enrollment—making it ideal for sharing files with external volunteers. Microsoft Copilot for Microsoft 365 adds AI assistance that can summarize email threads and documents across Outlook and SharePoint, satisfying the summarization need.

Why this answer

Microsoft Purview sensitivity labels can restrict access to sensitive data. Exchange Online archiving can archive emails older than 5 years. SharePoint Online allows external sharing with expiration and permissions, without device enrollment.

Microsoft Copilot for Microsoft 365 provides AI email summaries and suggested replies. Microsoft Intune requires device enrollment, which is not desired.

74
Multi-Selectmedium

An organization wants to retain mailbox content for legal investigation. Which two statements are accurate about the Microsoft 365 capability involved?

Select 2 answers
A.It requires every document to be made public
B.eDiscovery and retention capabilities in Microsoft Purview
C.The policy should be tested with a limited group before broad rollout
D.It replaces the need for identity and access management
AnswersB, C

Purview eDiscovery and retention help preserve and search content for investigations.

Why this answer

Security and compliance controls should be selected by risk scenario and tested before tenant-wide enforcement.

75
MCQmedium

A business stakeholder asks how Microsoft 365 can help them guide assignment of Microsoft 365 admin roles. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Microsoft Stream
C.Least privilege
D.Microsoft Forms
AnswerC

Least privilege means assigning only the permissions required for a task.

Why this answer

The principle of least privilege is the most relevant concept for guiding assignment of Microsoft 365 admin roles. It dictates that users should be granted only the minimum permissions necessary to perform their job functions, which directly applies to assigning admin roles to reduce security risks. This is a core security and identity concept within Microsoft 365, not a specific application or service.

Exam trap

The trap here is that candidates may confuse productivity tools (Whiteboard, Stream, Forms) with security or administrative concepts, failing to recognize that 'least privilege' is a fundamental security principle directly tied to role assignment in Microsoft 365.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a digital canvas application for collaboration, not related to admin role assignment or security principles. Option B is wrong because Microsoft Stream is a video service for recording and sharing content, not a tool for managing admin permissions. Option D is wrong because Microsoft Forms is a survey and quiz creation tool, irrelevant to the principle of assigning admin roles with minimal permissions.

Page 1 of 3

Page 2

All pages