Courseiva

Microsoft 365 Fundamentals MS-900 (MS-900) — Questions 1–75

794 questions total · 11pages · All types, answers revealed

Page 1 of 11

Page 2
1
MCQeasy

A user wants to schedule a meeting with colleagues and automatically find a time that works for everyone. Which Microsoft 365 app should they use?

A.Microsoft Bookings
B.Microsoft Teams
C.Microsoft Viva Insights
D.Microsoft Outlook
AnswerD

Microsoft Outlook's Scheduling Assistant is the central tool for planning internal meetings, as it consults Exchange Online free/busy data for all invitees and graphically displays overlapping availability. It can automatically propose times when attendees and meeting rooms are all available, and it integrates directly with the calendar and meeting invitation flow. This availability-based scheduling capability is why Outlook is the correct answer.

Why this answer

Microsoft Outlook includes the Scheduling Assistant feature, which uses free/busy data from the Exchange Online calendar to automatically suggest meeting times that work for all attendees. This is the correct app for scheduling meetings with colleagues because it directly integrates with the organization's calendar system to find mutual availability.

Exam trap

The trap here is that candidates often confuse Microsoft Teams' ability to schedule a meeting (which uses Outlook's backend) with the primary app for finding mutual availability, leading them to select Teams instead of Outlook.

How to eliminate wrong answers

Option A is wrong because Microsoft Bookings is a scheduling tool for external customers to book appointments with a business, not for internal colleague meeting coordination. Option B is wrong because Microsoft Teams provides a scheduling feature that leverages Outlook's Scheduling Assistant, but it is not the primary app for finding mutual availability; Teams relies on Outlook for the underlying calendar and free/busy logic. Option C is wrong because Microsoft Viva Insights focuses on personal productivity analytics, wellbeing, and focus time suggestions, not on scheduling meetings with multiple colleagues.

2
MCQmedium

A department asks for the Microsoft 365 service best suited for task tracking using boards and buckets. Which service should they use? The design must avoid adding custom operational scripts.

A.Microsoft Defender for Endpoint
B.Microsoft Planner
C.Microsoft Entra Privileged Identity Management
D.Microsoft Purview Compliance Manager
AnswerB

Microsoft Planner provides native boards and buckets for task tracking, directly satisfying the department's requirement without custom operational scripts. Its Kanban-style interface organises tasks into buckets and cards, and integrates with Microsoft 365 groups for collaboration. Unlike SharePoint lists or Power Automate workarounds, Planner delivers this capability out of the box.

Why this answer

Microsoft Planner is the correct service because it provides task tracking using boards and buckets, which are core features of its Kanban-style interface. It is designed for lightweight project management within Microsoft 365, allowing users to create plans, organize tasks into buckets, and track progress without requiring custom scripts or additional configuration.

Exam trap

The trap here is that candidates may confuse Microsoft Planner with Microsoft Project or To Do, but the question specifically requires 'boards and buckets'—a hallmark of Planner's Kanban interface—and explicitly prohibits custom scripts, ruling out more complex or script-dependent solutions.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Endpoint is a security solution for endpoint protection, threat detection, and response, not a task tracking service with boards and buckets. Option C is wrong because Microsoft Entra Privileged Identity Management is an identity governance tool for managing, controlling, and monitoring access to privileged roles in Azure AD, not for task management. Option D is wrong because Microsoft Purview Compliance Manager is a compliance management solution for assessing and managing regulatory compliance risks, not a task tracking service.

3
MCQmedium

A company with 50 users currently has Microsoft 365 Business Basic licenses. They now need to use desktop versions of Office apps (Word, Excel, PowerPoint) for all users. They also want to keep their existing business email and online meeting features. What is the most cost-effective licensing strategy?

A.Upgrade all users to Microsoft 365 Business Standard
B.Purchase Microsoft 365 Apps for business for all users
C.Purchase Microsoft 365 E3 for all users
D.No change needed – Business Basic already includes desktop apps
AnswerA

Business Standard adds desktop Office apps to the existing Business Basic email and online meeting features, so a single upgrade satisfies both requirements without buying separate licences. It is the most cost-effective path for all 50 users.

Why this answer

Microsoft 365 Business Basic includes only web and mobile versions of Office apps, not the desktop versions. Upgrading to Microsoft 365 Business Standard provides the full desktop Office suite (Word, Excel, PowerPoint) while retaining the existing business email (Exchange Online) and online meeting features (Teams), making it the most cost-effective option for 50 users.

Exam trap

The trap here is that candidates may assume Microsoft 365 Apps for business is sufficient because it includes desktop Office, but they overlook that it lacks Exchange Online and Teams, which are required to maintain the existing email and meeting features.

How to eliminate wrong answers

Option B is wrong because Microsoft 365 Apps for business provides desktop Office apps but does not include Exchange Online for business email or Teams for online meetings, which the company wants to keep. Option C is wrong because Microsoft 365 E3 is an enterprise-grade plan with advanced security and compliance features that are unnecessary for a 50-user company, making it significantly more expensive than Business Standard. Option D is wrong because Microsoft 365 Business Basic does not include desktop versions of Office apps; it only offers web and mobile versions.

4
MCQmedium

Refer to the exhibit. The JSON shows Microsoft Entra ID role assignments using Privileged Identity Management (PIM). Which statement about user2@contoso.com is correct?

A.user2 is not assigned any administrative role
B.user2 cannot access any administrative features
C.user2 must activate the Global Administrator role before using it
D.user2 is permanently assigned the Global Administrator role
AnswerC

Correct. In Microsoft Entra ID (Azure AD) Privileged Identity Management, an 'Eligible' assignment does not confer active permissions. User2 must first activate the Global Administrator role—typically by performing MFA, providing business justification, and possibly receiving approval—before they can use any Global Administrator privileges. This time-bound activation is a core security feature that reduces standing admin access and enforces just-in-time access.

Why this answer

The JSON shows that user2@contoso.com has an eligible assignment for the Global Administrator role via Microsoft Entra ID PIM. In PIM, an eligible assignment means the user must activate the role (e.g., through the PIM portal or API) before gaining administrative privileges. The JSON snippet includes a property like "assignmentType": "Eligible" (implied by the context), which requires activation to elevate permissions temporarily.

Exam trap

The trap here is that candidates may confuse 'eligible assignment' with 'no assignment' or 'permanent assignment,' failing to recognize that PIM requires activation for eligible roles, which is a core concept tested in MS-900.

How to eliminate wrong answers

Option A is wrong because the JSON explicitly includes a role assignment for user2 with the Global Administrator role, so user2 is assigned an administrative role. Option B is wrong because user2 has an eligible assignment, meaning they can access administrative features after activating the role; they are not permanently blocked from administrative features. Option D is wrong because the assignment is eligible, not permanent (active); a permanent assignment would have an "assignmentType": "Active" or no activation requirement, which is not indicated in the exhibit.

5
MCQmedium

During a Microsoft 365 planning workshop, provide baseline anti-spam and anti-malware filtering for Exchange Online. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Stream
B.Microsoft Forms
C.Exchange Online Protection
D.Microsoft Planner
AnswerC

Exchange Online Protection (EOP) is the core email security service in Microsoft 365 that sits in front of Exchange Online mailboxes. EOP filters all inbound and outbound messages for spam, malware, and phishing using multiple detection engines and policy controls. It is the correct baseline anti-malware/anti-spam filter for an organization's email environment.

Why this answer

Exchange Online Protection (EOP) is the cloud-based filtering service built into Exchange Online that provides baseline anti-spam and anti-malware protection. It scans all inbound and outbound messages using heuristics, signature-based detection, and connection filtering to block malicious content before it reaches user mailboxes.

Exam trap

The trap here is that candidates confuse general Microsoft 365 apps (Stream, Forms, Planner) with security services, failing to recognize that Exchange Online Protection is the dedicated anti-spam/anti-malware service for Exchange Online.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video sharing and management service, not a security filtering capability. Option B is wrong because Microsoft Forms is a survey and quiz creation tool, not a messaging security service. Option D is wrong because Microsoft Planner is a task management and project planning application, not a security or compliance feature.

6
MCQmedium

A registered nonprofit organization with 100 employees wants to use Microsoft 365 Business Basic at no cost. Which program should they apply for to be eligible for donated or discounted subscriptions?

A.Microsoft Enterprise Agreement
B.Microsoft Open Licensing
C.Microsoft Nonprofit Program
D.Microsoft Cloud Solution Provider (CSP) program
AnswerC

The Microsoft Nonprofit Program (also known as Microsoft for Nonprofits) is the correct fit because it is a dedicated licensing and discount framework for eligible registered charities, NGOs, and other qualifying nonprofit entities. It provides donated products such as a $3,500 annual Azure credit, plus discounted or donated Microsoft 365 subscriptions (e.g., M365 Business Premium at a reduced rate) after the organization passes Microsoft's eligibility validation. This program is the only one among the options that directly addresses the status of being a nonprofit with a cost-reduction benefit. Therefore, it directly answers the organization's need for a grant or discount on Microsoft cloud services.

Why this answer

The Microsoft Nonprofit Program provides eligible nonprofit organizations with donated or discounted subscriptions to Microsoft 365 Business Basic (and other products). A registered nonprofit with 100 employees qualifies for up to 10 donated licenses of Microsoft 365 Business Basic (or equivalent) and can purchase additional licenses at a significant discount. This program is specifically designed to support nonprofit missions by reducing technology costs.

Exam trap

The trap here is that candidates often confuse volume licensing programs (Enterprise Agreement, Open Licensing) or partner programs (CSP) with the dedicated nonprofit donation program, failing to recognize that only the Microsoft Nonprofit Program offers free or heavily discounted subscriptions specifically for eligible charitable organizations.

How to eliminate wrong answers

Option A is wrong because the Microsoft Enterprise Agreement is a volume licensing program for commercial and government organizations, not a donation or discount program for nonprofits; it requires a minimum commitment of 500 users and does not offer free subscriptions. Option B is wrong because Microsoft Open Licensing is a transactional volume licensing program for small to medium businesses, not a nonprofit-specific program, and it does not provide donated or discounted subscriptions for charitable organizations. Option D is wrong because the Microsoft Cloud Solution Provider (CSP) program is a partner-led reseller model for commercial customers, not a direct donation or discount program for nonprofits; while CSP partners can offer nonprofit pricing, the eligibility and donation mechanism are managed through the Nonprofit Program, not CSP itself.

7
MCQeasy

A cloud provider bills a customer monthly based on the precise number of gigabytes of storage used and the number of virtual machine hours consumed. Which essential cloud computing characteristic does this billing model demonstrate?

A.Measured service
B.Resource pooling
C.On-demand self-service
D.Broad network access
AnswerA

Measured service is the cloud characteristic in which a provider automatically meters and optimizes resource use via abstraction, quantifying capabilities such as compute time, storage GB, and outbound bandwidth. This telemetry feeds a billing system that charges the customer exactly for the resources consumed, matching the scenario's monthly billing based on precise usage. In contrast to flat-rate pricing, this pay-as-you-go model depends entirely on the granular usage data that measured service provides.

Why this answer

The billing model charges based on exact gigabytes of storage used and virtual machine hours consumed, which directly aligns with the 'measured service' characteristic. This means the cloud provider meters resource usage (e.g., storage IOPS, compute hours) and bills only for what is consumed, enabling pay-as-you-go pricing. Measured service relies on telemetry and monitoring systems (e.g., Azure Monitor, AWS CloudWatch) to track usage and generate invoices.

Exam trap

Microsoft often tests the distinction between 'measured service' (billing granularity) and 'on-demand self-service' (provisioning capability), leading candidates to confuse the ability to spin up resources instantly with how those resources are billed.

How to eliminate wrong answers

Option B is wrong because resource pooling refers to the provider's ability to serve multiple customers from shared physical resources (e.g., multi-tenancy), not how usage is billed. Option C is wrong because on-demand self-service allows users to provision resources without human interaction (e.g., via Azure Portal or CLI), but does not define the billing granularity. Option D is wrong because broad network access describes the ability to access resources over the network via standard protocols (e.g., HTTPS, SSH), not the metering or charging model.

8
MCQeasy

A user wants to access their work files from a personal laptop without installing any Microsoft 365 Apps. Which web-based service allows them to view and edit documents in a browser?

A.Microsoft OneDrive
B.Microsoft 365 for the web
C.Microsoft Teams
D.Microsoft SharePoint
AnswerB

Microsoft 365 for the web, formerly known as Office Online, delivers browser-based versions of Word, Excel, PowerPoint, and other Office applications. It allows users to view, create, and edit documents directly in a web browser without requiring any local installation, making it ideal for accessing work files from a personal laptop. As long as the user has an internet connection and appropriate licensing, they can use these web apps for full editing capability, which directly addresses the user's need.

Why this answer

Microsoft 365 for the web (formerly Office Web Apps) provides browser-based versions of Word, Excel, PowerPoint, and OneNote, enabling users to view and edit documents without installing any local applications. This service is accessed through a web browser on any device, including a personal laptop, and requires only an internet connection and a valid Microsoft 365 subscription.

Exam trap

Microsoft often tests the distinction between storage services (OneDrive, SharePoint) and the actual web-based editing service (Microsoft 365 for the web), causing candidates to mistakenly choose OneDrive because it is the most familiar file-access option.

How to eliminate wrong answers

Option A is wrong because Microsoft OneDrive is primarily a cloud storage and file synchronization service, not a web-based document editing suite; while it can launch documents in Microsoft 365 for the web, OneDrive itself does not provide the editing capabilities. Option C is wrong because Microsoft Teams is a collaboration platform focused on chat, meetings, and channel-based communication, not a dedicated web-based document editor; although it integrates with Office for the web for file previews, its primary function is not browser-based document creation and editing. Option D is wrong because Microsoft SharePoint is a web-based document management and collaboration platform that stores and organizes files, but it relies on Microsoft 365 for the web or desktop apps to actually edit documents; SharePoint itself does not provide the in-browser editing functionality.

9
MCQmedium

During requirements gathering, an IT manager says the organization must review employee messages for harassment or regulatory policy violations. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Forms
B.Communication Compliance
C.Microsoft Stream
D.Microsoft Planner
AnswerB

Communication Compliance is the Microsoft Purview solution designed to detect, capture, and route potentially inappropriate or regulated communications for review. It uses configurable policies and machine-learning classifiers to flag harassment, threats, conflict of interest, or insider trading across Exchange, Teams, and third-party feeds. Because the IT manager needs a compliance capability to monitor and moderate communications, this is the correct choice.

Why this answer

Communication Compliance in Microsoft 365 is the correct capability because it is specifically designed to detect, capture, and act on inappropriate messages—such as harassment or regulatory policy violations—across email, Microsoft Teams, and third-party communications. It uses configurable policies with built-in classifiers for harassment, threats, and regulatory compliance, enabling automated review and remediation. This directly addresses the IT manager's requirement to monitor employee messages for policy violations.

Exam trap

The trap here is that candidates may confuse Communication Compliance with other Microsoft 365 tools that have 'communication' in their name (like Microsoft Teams) or assume any Microsoft 365 app can be repurposed for compliance, but only Communication Compliance provides the dedicated policy-based message surveillance and remediation workflow required for harassment and regulatory monitoring.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and data collection tool, not a compliance solution for monitoring employee messages. Option C is wrong because Microsoft Stream is a video hosting and sharing platform, lacking any capabilities for scanning text-based communications for harassment or regulatory violations. Option D is wrong because Microsoft Planner is a task and project management tool, with no features for message surveillance or compliance policy enforcement.

10
MCQmedium

A project manager wants to create a visual dashboard that tracks project tasks, deadlines, and progress. The dashboard should pull data from a Microsoft List and update in real time. Which Microsoft 365 app is best suited for building this interactive dashboard?

A.Microsoft Lists
B.Power BI
C.SharePoint Online
D.Microsoft Forms
AnswerB

Power BI is a dedicated business analytics suite that directly connects to Microsoft Lists, SharePoint, and other data sources to build live, interactive dashboards. It lets you create custom visuals, apply cross-filtering, set up conditional formatting, and publish reports to the Microsoft 365 ecosystem, making it the only option here that natively delivers the requested task-deadline dashboard with rich user interactivity and scheduled data refreshes.

Why this answer

Power BI is the correct choice because it is designed to create interactive, real-time dashboards with live data connectivity. It can connect directly to a Microsoft List as a data source and refresh automatically, enabling real-time tracking of project tasks, deadlines, and progress with visualizations like charts and gauges.

Exam trap

The trap here is that candidates often confuse Microsoft Lists (a data source) with a dashboard tool, or assume SharePoint's built-in list views are sufficient for interactive, real-time dashboards, overlooking Power BI's specialized visualization and refresh capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Lists is a data storage and tracking app, not a dashboard-building tool; it lacks native interactive visualization and real-time dashboard capabilities. Option C is wrong because SharePoint Online provides list and library functionality but does not offer the dedicated, interactive dashboard creation and real-time data refresh features of Power BI. Option D is wrong because Microsoft Forms is a survey and quiz tool for collecting responses, not for building dashboards or visualizing real-time data.

11
Multi-Selecthard

A marketing manager wants to create a mobile-friendly app that field sales representatives can use to submit expense reports with photos of receipts. The app should automatically save the data to a SharePoint list and send an email notification to the manager. Which two Microsoft 365 technologies should the developer use to build this solution? (Choose two.)

Select 2 answers
A.Microsoft Power Apps
B.Microsoft Power Automate
C.Microsoft SharePoint
D.Microsoft Power BI
AnswersA, B

Power Apps is the low-code platform purpose-built for creating custom mobile-friendly apps. You can design a canvas app with a responsive layout, add screens for capturing receipt photos and numeric data, and bind those controls directly to a SharePoint list through the SharePoint connector. This gives the marketing manager a real app interface without writing traditional code, making it the correct tool for the app-building requirement.

Why this answer

Microsoft Power Apps is correct because it enables rapid development of mobile-friendly apps with minimal code, allowing field sales representatives to capture expense data and receipt photos directly from their devices. It integrates seamlessly with SharePoint lists for data storage, making it the ideal low-code platform for this custom business app.

Exam trap

The trap here is that candidates often confuse SharePoint as a development tool for building apps, when in reality it is only a data storage service, while Power Apps and Power Automate are the actual low-code development and automation technologies required.

12
MCQmedium

A compliance manager wants a dashboard that maps Microsoft 365 controls to regulatory standards and gives recommended improvement actions. Which portal capability should they use?

A.Microsoft Purview Compliance Manager.
B.Microsoft Defender for Endpoint.
C.Exchange admin center message trace.
D.Microsoft Viva Connections.
AnswerA

Microsoft Purview Compliance Manager is specifically designed to map your organization's compliance posture across Microsoft 365 and other data sources. It provides a dashboard of assessments based on regulatory standards, displaying a compliance score, in-scope services, and recommended improvement actions. Its control-by-control mapping directly ties Microsoft cloud capabilities to your compliance requirements, making it the correct tool for a compliance manager seeking an overview.

Why this answer

Microsoft Purview Compliance Manager is the correct portal because it provides a centralized dashboard that maps Microsoft 365 controls to regulatory standards (e.g., ISO 27001, NIST, GDPR) and generates recommended improvement actions with implementation steps. It uses built-in assessments and control scoring to track compliance posture, directly meeting the compliance manager's need for a regulatory mapping and action-oriented dashboard.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Compliance Manager with Microsoft Defender for Endpoint, mistakenly thinking a security monitoring tool can also handle compliance mapping, but Defender for Endpoint focuses on threat protection, not regulatory control frameworks or improvement recommendations.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Endpoint is a security solution focused on endpoint detection and response (EDR), vulnerability management, and threat hunting—it does not provide a dashboard for mapping controls to regulatory standards or recommending compliance improvement actions. Option C is wrong because the Exchange admin center message trace is a mail flow troubleshooting tool used to track email delivery and routing, not a compliance dashboard for regulatory mapping or improvement recommendations. Option D is wrong because Microsoft Viva Connections is a employee experience platform that aggregates news, resources, and communications in Teams—it has no capability for compliance control mapping or regulatory standard assessments.

13
MCQmedium

Contoso Ltd. is a mid-sized company with 1,200 employees. They currently use on-premises Exchange and SharePoint. They plan to migrate to Microsoft 365 and have decided to use Microsoft 365 E3 for all users. The IT department is concerned about the cost of add-on services. The CFO wants to minimize monthly expenses while ensuring that users have access to Exchange Online, SharePoint Online, Teams, and OneDrive. Additionally, the company needs to meet basic compliance requirements such as retention policies and eDiscovery. They do not require advanced security features like Microsoft Defender for Office 365 P2 or Microsoft Purview Data Loss Prevention. Which approach should the IT department recommend to meet these requirements at the lowest cost?

A.Use Microsoft 365 E3 and add Microsoft Purview Compliance Manager
B.Use Microsoft 365 Business Premium for all users
C.Use Microsoft 365 E3 without any add-ons
D.Use Microsoft 365 E5 for all users
AnswerC

Microsoft 365 E3 provides the full Office applications, enterprise email and collaboration services, plus foundational Microsoft Purview compliance capabilities such as Data Loss Prevention, eDiscovery, and retention policies. It also includes Azure Active Directory P1 for identity and access management, covering typical mid-sized enterprise needs without requiring any add-ons. Since the business scenario does not specify advanced security or analytics requirements, E3 alone delivers the right balance of functionality and cost for Contoso's 1,200-employee organization.

Why this answer

Microsoft 365 E3 includes Exchange Online, SharePoint Online, Teams, and OneDrive, as well as core compliance features like retention policies and eDiscovery (via Microsoft Purview). Since the company does not require advanced security add-ons, no additional purchases are needed, making E3 the lowest-cost option that meets all stated requirements.

Exam trap

The trap here is that candidates may assume Microsoft 365 E3 lacks basic compliance features and incorrectly choose to add an add-on like Compliance Manager, or they may overlook the user count limitation of Business Premium, leading them to select a plan that is either overpriced or ineligible.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is an add-on that requires an additional license cost and is not needed for basic retention policies and eDiscovery, which are already included in E3. Option B is wrong because Microsoft 365 Business Premium is designed for organizations with up to 300 users, and Contoso has 1,200 employees, making it ineligible for this plan. Option D is wrong because Microsoft 365 E5 includes advanced security and compliance features (e.g., Microsoft Defender for Office 365 P2, Microsoft Purview Data Loss Prevention) that are not required, resulting in unnecessary higher monthly costs.

14
MCQeasy

A company migrates its database to a cloud service where the provider manages the database engine, patching, backups, and replication. The customer only manages the data and schema. Which cloud service model is this?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.On-premises
AnswerB

PaaS is the correct choice because it offers a managed database platform, such as Azure SQL Database, where the provider handles the operating system, database engine, patching, automated backups, and built-in high availability and replication. You focus only on the database schema, data, and query tuning, while the provider abstracts infrastructure maintenance. This aligns with the scenario where the company migrates its database to a cloud service and gains managed operational capabilities.

Why this answer

Platform as a Service (PaaS) provides a managed hosting environment where the cloud provider handles the underlying infrastructure, including the database engine, operating system, patching, backups, and replication. The customer is responsible only for managing the data and schema, which aligns directly with the scenario described.

Exam trap

The trap here is that candidates often confuse PaaS with IaaS because both involve cloud-hosted databases, but the key differentiator is who manages the database engine and patching—PaaS offloads this entirely to the provider, while IaaS leaves it to the customer.

How to eliminate wrong answers

Option A is wrong because Infrastructure as a Service (IaaS) provides virtualized computing resources where the customer manages the operating system, database engine, patching, and backups, not just the data and schema. Option C is wrong because Software as a Service (SaaS) delivers a complete application managed entirely by the provider, where the customer typically does not manage the database schema or data directly. Option D is wrong because an on-premises deployment requires the customer to manage all aspects of the database, including hardware, engine, patching, backups, and replication, which contradicts the provider-managed model described.

15
MCQmedium

An administrator is reviewing a request from users who need to host training videos securely for employees. Microsoft 365 app or service is the best fit?

A.Microsoft Purview Audit
B.Microsoft Forms
C.Microsoft Planner
D.Microsoft Stream
AnswerD

Microsoft Stream is Microsoft 365's enterprise video service, designed specifically for uploading, transcribing, searching, and playing videos across an organization with access controls. Stream integrates with Teams, SharePoint, and Viva and can handle training videos as part of a centralized, managed content library. With built-in support for permissions, captions, and analytics, it fully meets the requirement to host and share training videos.

Why this answer

Microsoft Stream is the correct choice because it is Microsoft 365's enterprise video service designed specifically for securely hosting, sharing, and managing training videos within an organization. It integrates with Azure AD for access control, supports permissions-based sharing, and provides features like transcripts, chapters, and engagement analytics, making it ideal for internal training content.

Exam trap

The trap here is that candidates may confuse Microsoft Stream with other Microsoft 365 apps that have 'video' or 'media' in their name or assume that any app with sharing capabilities (like Forms or Planner) can handle video, but only Stream is purpose-built for secure enterprise video hosting and management.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Audit is a compliance and auditing tool that logs user and admin activities across Microsoft 365, not a service for hosting or streaming video content. Option B is wrong because Microsoft Forms is a survey and quiz creation tool, not designed for video hosting or secure streaming of training materials. Option C is wrong because Microsoft Planner is a task management and project planning application, lacking any video storage, streaming, or permission management capabilities.

16
MCQmedium

A project manager needs to create a detailed project schedule with a Gantt chart view, task dependencies, critical path analysis, and milestones. The schedule must be shared with team members who can update their tasks, and the manager wants to track progress against a baseline. Which Microsoft 365 app is specifically designed for this type of project management?

A.Microsoft Lists
B.Microsoft Project
C.Microsoft Planner
D.Microsoft Excel
AnswerB

Microsoft Project (including Project for the Web, Project Online, and Project desktop) is the M365 portfolio's dedicated project management application. It has native Gantt chart views, supports task dependencies with lead/lag, constraint types, resource assignments, and critical path analysis, and saves baselines for variance tracking. Because scheduling is algorithmic, changes to one task automatically recalculate downstream dates across the entire plan. This is the correct choice when the requirement is to 'create a detailed project schedule with a Gantt chart view.'

Why this answer

Microsoft Project is the correct answer because it is specifically designed for advanced project management, offering native support for Gantt charts, task dependencies, critical path analysis, milestones, baseline tracking, and collaborative task updates. Unlike simpler tools, Project provides the scheduling engine and analytical capabilities required for detailed, enterprise-grade project plans.

Exam trap

The trap here is that candidates confuse Microsoft Planner's Kanban-style task management with full project scheduling, overlooking that Planner lacks Gantt charts, dependency chains, critical path analysis, and baseline tracking—features that are exclusive to Microsoft Project in the Microsoft 365 ecosystem.

How to eliminate wrong answers

Option A is wrong because Microsoft Lists is a data-tracking and organization app for creating custom lists (e.g., issue trackers, inventories), not a project scheduling tool—it lacks Gantt charts, dependency modeling, critical path analysis, and baseline tracking. Option C is wrong because Microsoft Planner is a lightweight task management app for team collaboration with Kanban boards and basic due dates, but it does not support Gantt charts, task dependencies, critical path analysis, or baseline tracking. Option D is wrong because Microsoft Excel is a spreadsheet application that can manually simulate a Gantt chart or schedule, but it has no built-in project management engine for automatic dependency resolution, critical path calculation, or baseline comparison.

17
MCQeasy

A sales team needs to collaborate on documents in real time, track changes, and co-author using familiar desktop tools. Which Microsoft 365 app should they use?

A.Microsoft Teams
B.Microsoft OneNote
C.Microsoft Word
D.Microsoft Planner
AnswerC

Microsoft Word is the correct choice because it is a full-featured word processor with native real-time co-authoring support for .docx files stored in OneDrive or SharePoint. Multiple authors can work simultaneously in Word for the web or Word desktop, with presence indicators, inline comments, version history, and Track Changes showing every insertion, deletion, or formatting change for later accept/reject. This precisely meets the sales team's need to collaborate on documents in real time while preserving an auditable editing trail.

Why this answer

Microsoft Word is the correct choice because it is the desktop app that natively supports real-time co-authoring, change tracking, and simultaneous editing by multiple users. These features are built into Word for Microsoft 365, allowing teams to collaborate on documents using the familiar desktop interface without needing to switch to a web or mobile app.

Exam trap

The trap here is that candidates often confuse Microsoft Teams' file-sharing capability with actual document editing, assuming Teams itself provides co-authoring, when in fact it merely hosts the file and launches Word for editing.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is a collaboration hub for chat, meetings, and file sharing, but it does not provide native desktop co-authoring or change tracking within its interface; documents opened in Teams are edited in Word Online or the Word desktop app. Option B is wrong because Microsoft OneNote is a digital notebook for free-form note-taking and does not support structured document co-authoring with tracked changes like a word processor. Option D is wrong because Microsoft Planner is a task management and project planning tool that organizes work with boards and checklists, not a document editing or co-authoring application.

18
MCQeasy

South Ridge School District uses Microsoft 365 Education A5. They have 10,000 students and 1,000 staff. The district wants to ensure that student data is protected and that only authorized staff can access student records. They also need to comply with FERPA (Family Educational Rights and Privacy Act). The IT team has created security groups for teachers, administrators, and support staff. They want to restrict access to a specific SharePoint site containing student records to only the teachers group. Additionally, they want to prevent teachers from sharing the site with external users. What should you configure?

A.In the SharePoint site settings, set the site permissions to 'Only members of the Teachers group can access' and set external sharing to 'Only people in your organization'.
B.Apply a sensitivity label to the site that restricts access to the teachers group.
C.Add the teachers group as site collection administrators.
D.Create a private channel in Microsoft Teams for teachers only.
AnswerA

Setting the SharePoint site permissions to 'Only members of the Teachers group can access' directly assigns the site's visitor/member scope to that specific security group, ensuring only teachers can authenticate and open the site. In parallel, configuring external sharing to 'Only people in your organization' blocks any anonymous links or external user invitations, so students and external parties cannot be granted access regardless of how a link is shared. Together these two settings enforce both the intended user boundary and the organization-wide sharing boundary, which is exactly the requirement.

Why this answer

Sharing controls in SharePoint site settings can be used to limit access to specific groups and disable external sharing. Option B (private channel) is for Teams, not SharePoint. Option C (sensitivity label) can restrict access but is not site-specific.

Option D (site collection admin) does not restrict sharing.

19
MCQhard

A company is deploying Microsoft Teams Rooms for its meeting rooms. They need to ensure that room calendars are automatically updated when a meeting is booked via Outlook. Which Microsoft 365 service enables this integration?

A.Microsoft Intune
B.Exchange Online
C.Microsoft Teams
D.SharePoint Online
AnswerB

Exchange Online is correct because it hosts the resource mailboxes that represent meeting rooms and runs the calendar processing logic for those mailboxes. When a Teams Rooms device displays availability or receives a booking, it is querying and updating the room mailbox in Exchange Online, which accepts or declines the invitation. This makes Exchange Online the component that manages calendars for Teams Rooms.

Why this answer

Exchange Online is the correct answer because it provides the mailbox and calendar infrastructure that Microsoft Teams Rooms relies on. When a meeting is booked via Outlook, the Exchange Online calendar processes the booking and automatically updates the room's calendar, enabling the Teams Rooms device to display the meeting details. This integration uses the Exchange Web Services (EWS) or REST APIs to synchronize calendar events between Outlook and the room resource mailbox.

Exam trap

The trap here is that candidates often assume Microsoft Teams directly manages room calendars because Teams Rooms is a Teams feature, but in reality, the calendar integration is entirely dependent on Exchange Online's resource mailbox and calendar processing capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service used for managing devices and apps, not for calendar synchronization or room mailbox updates. Option C is wrong because Microsoft Teams is the collaboration platform that provides the meeting experience, but it does not directly manage room calendars; it relies on Exchange Online for calendar data. Option D is wrong because SharePoint Online is a document management and collaboration platform focused on content storage and sharing, with no native capability to process room bookings or update room calendars.

20
MCQmedium

An organization wants to ensure that only compliant devices can access Microsoft 365 resources. They use Microsoft Intune for device management. Which policy should they configure?

A.Enable device enrollment in Intune
B.Create a Conditional Access policy in Microsoft Entra ID
C.Create a compliance policy in Intune
D.Create a device configuration policy in Intune
AnswerB

A Conditional Access policy in Microsoft Entra ID acts as the real-time access enforcement engine for cloud applications. By adding a condition that requires the device to be marked as compliant based on its Intune compliance status, the policy grants access only when the device meets all requirements and blocks or prompts for remediation when it does not. This is the control that directly decides whether a user's session is permitted, making it the correct mechanism to ensure only compliant devices can connect.

Why this answer

Conditional Access in Microsoft Entra ID is the policy engine that evaluates signals (user, device, location, app) and enforces access controls such as 'require compliant device' before granting access to Microsoft 365 resources. Intune supplies the device compliance state, but it is Conditional Access that actually blocks non-compliant devices from reaching the resource. This is the only option that enforces the access decision at authentication time.

Exam trap

MS-900 often tests the confusion between Intune compliance policies (which evaluate device state) and Conditional Access (which enforces access decisions), so candidates pick the Intune option when the question asks what actually blocks access.

How to eliminate wrong answers

Option A is wrong because device enrollment in Intune only onboards devices for management — it does not gate access to Microsoft 365 resources. Option C is wrong because a compliance policy in Intune only defines and evaluates the rules that mark a device compliant; it does not itself block access. Option D is wrong because a device configuration policy pushes settings to devices (Wi-Fi, certificates, restrictions) but has no role in enforcing access control.

21
MCQeasy

Your organization needs to provide access to Microsoft 365 for 50 temporary contractors who will work for 6 months. They require email and Teams. Which licensing approach is most cost-effective?

A.Purchase Microsoft 365 F3 licenses
B.Purchase Microsoft 365 E5 licenses
C.Purchase Microsoft 365 E3 licenses
D.Purchase Microsoft 365 Business Basic licenses
AnswerD

Microsoft 365 Business Basic provides a 50 GB Exchange Online mailbox, Microsoft Teams, and browser-based versions of Office apps (Outlook, Word, Excel, PowerPoint) at a low per-user monthly price. For temporary contractors who need core productivity and email without desktop apps, Business Basic is a cost-effective and appropriate license, hence the correct answer.

Why this answer

Microsoft 365 Business Basic is the most cost-effective option for temporary contractors needing only email (Exchange Online) and Teams, as it provides these core services at the lowest per-user price. It is designed for small and medium businesses (up to 300 users) and includes web and mobile versions of Office apps, which are sufficient for basic communication needs. F3, E3, and E5 licenses include additional features (e.g., desktop Office apps, advanced security, compliance) that are unnecessary for short-term contractors, making them more expensive.

Exam trap

The trap here is that candidates often choose F3 thinking it is the cheapest option for temporary workers, but they overlook that Business Basic is actually lower cost and sufficient for basic email and Teams, while F3 is designed for shift workers with specific frontline scenarios and includes extra features that increase price.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 F3 is a Frontline Worker license that, while lower cost than E3/E5, is still more expensive than Business Basic and includes features like desktop Office apps and advanced analytics that are not needed for temporary contractors. Option B is wrong because Microsoft 365 E5 includes advanced security, compliance, and analytics features (e.g., Microsoft Defender for Office 365, eDiscovery, Power BI Pro) that are overkill and significantly more costly for short-term email and Teams access. Option C is wrong because Microsoft 365 E3 includes full desktop Office apps, advanced security, and compliance capabilities (e.g., DLP, legal hold) that are unnecessary for temporary contractors, leading to wasted spend.

22
MCQmedium

An administrator is reviewing a request from users who need to let support staff troubleshoot without tenant-wide change permissions. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Assign least-privileged support or reader roles
C.Microsoft Forms
D.Microsoft Whiteboard
AnswerB

Least-privileged support or reader roles grant scoped, read-only visibility so support staff can troubleshoot without tenant-wide change permissions, satisfying the stem's constraint of avoiding broad administrative rights. Microsoft Entra ID role assignments enforce this boundary.

Why this answer

The scenario requires granting support staff the ability to troubleshoot without tenant-wide change permissions, which directly maps to the principle of least privilege. In Microsoft 365, this is achieved by assigning a role like Helpdesk Administrator or a reader role (e.g., Global Reader), which provides read-only or limited administrative access without allowing modifications to tenant-wide settings. This aligns with the 'Describe Microsoft 365 pricing and support' domain, specifically the support and admin concepts.

Exam trap

The trap here is that candidates may confuse a specific Microsoft 365 service (like Stream, Forms, or Whiteboard) with an admin or support concept, failing to recognize that the question is about role-based access control and least privilege, not about a particular application.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video service for recording and sharing videos, not an admin or support concept for granting granular permissions. Option C is wrong because Microsoft Forms is a survey and quiz tool, unrelated to role-based access control or troubleshooting permissions. Option D is wrong because Microsoft Whiteboard is a collaborative digital canvas, not a mechanism for assigning least-privileged support roles.

23
MCQmedium

A business stakeholder asks how Microsoft 365 can help them access cloud resources from laptops, tablets, and phones over the internet. Cloud concept or benefit best matches this requirement?

A.Sensitivity labels
B.Microsoft Planner
C.Data Loss Prevention (DLP)
D.Broad network access
AnswerD

Broad network access is one of the five essential characteristics defined by NIST (SP 800-145) and means that Microsoft 365 capabilities are available over the network through standard protocols such as HTTPS, IMAP, and SMTP, rather than requiring a dedicated physical connection. Users can reach Exchange Online, SharePoint, Teams, and other services from laptops, desktops, tablets, and smartphones, using either native apps or modern browsers. This characteristic is what gives Microsoft 365 its ubiquitous, anywhere-anytime accessibility and is the correct answer here. Note that it is not about raw bandwidth or connection speed; it is about standards-based, heterogeneous client access.

Why this answer

Broad network access is a core NIST cloud computing characteristic that enables resources to be accessed over the network by standard mechanisms (e.g., mobile phones, tablets, laptops, and workstations). This directly matches the stakeholder's requirement for accessing cloud resources from various devices over the internet, as Microsoft 365 leverages HTTPS and standard protocols to provide ubiquitous access.

Exam trap

The trap here is that candidates may confuse operational features (like sensitivity labels or DLP) with fundamental cloud characteristics, or incorrectly associate Microsoft Planner with cloud access, when the question specifically targets the NIST-defined cloud benefit of broad network access.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are a Microsoft Information Protection (MIP) feature used to classify and protect data based on sensitivity, not to enable network access from multiple devices. Option B is wrong because Microsoft Planner is a task management and collaboration tool within Microsoft 365, not a cloud concept or benefit related to device accessibility. Option C is wrong because Data Loss Prevention (DLP) policies help prevent accidental sharing of sensitive information, but they do not address the ability to access cloud resources from laptops, tablets, and phones.

24
MCQeasy

A company moves its on-premises servers to a cloud provider. The provider supplies the physical hardware, networking, and storage. The company installs and manages the operating system and applications on the virtual machines. Which cloud service model does this scenario represent?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Function as a Service (FaaS)
AnswerA

IaaS is the correct classification for migrating on-premises servers to a cloud provider because it delivers virtualized compute, storage, and networking while the customer retains control over the guest OS, middleware, and applications. When a company lifts and shifts its existing servers, it still manages the operating system, installs patches, and runs its own software, while the cloud provider operates only the physical hardware and hypervisor. This matches the scenario of moving entire server workloads without redesigning them.

Why this answer

This scenario describes Infrastructure as a Service (IaaS) because the cloud provider supplies the physical hardware, networking, and storage, while the customer retains full control over the operating system and applications. In IaaS, the provider manages the underlying infrastructure (e.g., hypervisor, physical servers, network switches), and the customer is responsible for the guest OS, middleware, and application stack. This aligns with the shared responsibility model where the customer handles OS patching, application configuration, and data management.

Exam trap

The trap here is that candidates confuse IaaS with PaaS because both involve virtual machines, but PaaS removes OS management — the key differentiator is who installs and patches the operating system.

How to eliminate wrong answers

Option B (PaaS) is wrong because PaaS abstracts the OS and runtime environment; the provider manages the OS, middleware, and runtime, while the customer only deploys code — here the customer installs and manages the OS. Option C (SaaS) is wrong because SaaS delivers fully managed applications accessed via a browser or API; the customer has no control over the underlying OS or infrastructure. Option D (FaaS) is wrong because FaaS (Function as a Service) is a serverless compute model where the provider manages all infrastructure and the customer only deploys individual functions triggered by events — it does not involve managing an OS or full applications.

25
MCQmedium

A security team wants to ensure that only devices that are compliant with company security policies (e.g., antivirus enabled, disk encrypted) can access Exchange Online and SharePoint Online. Which feature should they configure in Microsoft 365?

A.Conditional Access policies
B.Data loss prevention (DLP) policies
C.Information Rights Management (IRM)
D.Microsoft Defender for Office 365
AnswerA

Conditional Access policies are the correct control because they act as a gate before any cloud app or service is accessed. These policies evaluate user, location, and device signals in real time, and can require that the device be marked as compliant by Intune or be Hybrid Azure AD joined. If the device is non-compliant, Conditional Access blocks access or forces additional steps like MFA, making it the only option here that directly enforces device compliance.

Why this answer

Conditional Access policies in Microsoft Entra ID (formerly Azure AD) allow administrators to enforce device compliance as a condition for granting access to cloud apps like Exchange Online and SharePoint Online. By integrating with Microsoft Intune device compliance policies (e.g., requiring antivirus, disk encryption), Conditional Access can block or allow access based on real-time device health signals, ensuring only compliant devices can connect.

Exam trap

The trap here is that candidates often confuse Conditional Access with DLP or IRM because all three involve security policies, but only Conditional Access can enforce device compliance as a gate before access is granted.

How to eliminate wrong answers

Option B (Data loss prevention policies) is wrong because DLP is designed to identify, monitor, and protect sensitive data (e.g., credit card numbers) in transit or at rest, not to enforce device compliance or block access based on device health. Option C (Information Rights Management) is wrong because IRM protects content through encryption and usage restrictions (e.g., preventing forwarding or printing) after access is granted, but it does not evaluate device compliance before granting access. Option D (Microsoft Defender for Office 365) is wrong because it focuses on threat protection against malicious links, attachments, and phishing in email and collaboration tools, not on device-level compliance checks for access control.

26
Drag & Dropmedium

Drag and drop the steps to create a new user account in Microsoft 365 admin center into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Creating a user in M365 admin center requires signing in, navigating to active users, adding a user, entering details, and assigning licenses/roles.

27
Multi-Selecthard

Which THREE of the following are benefits of the Microsoft 365 E5 license compared to E3?

Select 3 answers
A.Exchange Online
B.Power BI Pro
C.Microsoft Purview Communication Compliance
D.Microsoft Defender for Office 365 Plan 2
E.Microsoft Entra ID P1
AnswersB, C, D

E5 includes Power BI Pro, while E3 does not.

Why this answer

Power BI Pro is included with Microsoft 365 E5 but not with E3, enabling advanced data visualization and analytics capabilities. This is a key differentiator for organizations requiring self-service business intelligence tools integrated with Microsoft 365.

Exam trap

The trap here is that candidates often assume all core productivity services like Exchange Online are exclusive to higher tiers, when in fact they are baseline features across E3 and E5, while the real differentiators are advanced security, compliance, and analytics add-ons.

28
MCQmedium

A sales team uses Microsoft Teams for collaboration. They need to securely share large files (up to 15 GB) with external partners without requiring the partners to sign in. Which Microsoft 365 service should they use?

A.OneDrive for Business
B.Microsoft Lists
C.Microsoft Stream
D.SharePoint Online
AnswerA

OneDrive for Business is a personal cloud library in Microsoft 365 that supports sharing large files via 'Anyone with the link' anonymous sharing, allowing external recipients to download without a Microsoft account or sign-in. This makes it the most direct solution for a sales team needing to send sizable files to outside parties. The default maximum file size is 250 GB, and you can set expiration dates and passwords for extra security.

Why this answer

OneDrive for Business allows users to share files with external partners via a secure link that does not require the partner to sign in, and supports file sizes up to 250 GB (including the 15 GB requirement). This meets the need for large file sharing without authentication, leveraging OneDrive's external sharing capabilities with anonymous guest links.

Exam trap

The trap here is that candidates may choose SharePoint Online because it is a general-purpose collaboration platform, but they overlook the specific requirement of 'without requiring the partners to sign in,' which is more natively and commonly achieved via OneDrive for Business anonymous links, whereas SharePoint Online typically enforces authentication or a verification code by default.

How to eliminate wrong answers

Option B is wrong because Microsoft Lists is a data-tracking and organization app for creating lists, not designed for file sharing or external collaboration with large files. Option C is wrong because Microsoft Stream is a video hosting and management service, not intended for sharing arbitrary large files like documents or archives. Option D is wrong because SharePoint Online supports external sharing but, by default, requires recipients to sign in or verify their identity via a one-time code; anonymous sharing without sign-in is possible only if explicitly enabled by the admin, and the question specifies 'without requiring the partners to sign in,' making OneDrive for Business the more straightforward and commonly used solution for this scenario.

29
MCQmedium

Refer to the exhibit. You are reviewing a Microsoft Defender for Cloud Apps access policy configuration. What does this policy do?

A.Allows access but prevents downloads from the specified IP range
B.Allows access to the SharePoint site only from the specified IP range
C.Blocks access from the specified IP range to the SharePoint site and prevents downloads
D.Disables the policy for the SharePoint site
AnswerC

This is the correct description. The policy's access rule is set to 'Block', which denies all access to the SharePoint site from the specified IP range. Independently, the download rule is also set to 'Block', so even if access were permitted by another policy, downloads would be prevented. Together, the policy imposes both an access block and a download block for that IP range.

Why this answer

This policy is configured with an action of 'Block' and a 'Download (including printing)' control set to 'Block' for the specified IP range. When both access and download are blocked, the result is that users from that IP range are completely denied access to the SharePoint site and cannot download any files. Option C correctly describes this combined blocking behavior.

Exam trap

The trap here is that candidates often focus on the 'Download' control and assume the policy only restricts downloads (Option A), overlooking that the 'Access' action is set to 'Block', which completely denies access from the specified IP range.

How to eliminate wrong answers

Option A is wrong because the policy blocks access entirely, not just downloads; the 'Access' action is set to 'Block', not 'Allow'. Option B is wrong because the policy blocks access from the specified IP range, rather than allowing it only from that range; the action is 'Block', not 'Allow only'. Option D is wrong because the policy is enabled and actively blocking, not disabled; the policy state is not set to 'Disabled'.

30
MCQmedium

A marketing team needs to create a professional-looking newsletter that includes embedded videos, images, and links to documents. The newsletter should be viewable on any device and allow team members to collaborate on the content. Which Microsoft 365 app is best suited for this purpose?

A.Word Online
B.Sway
C.Publisher
D.OneNote
AnswerB

Sway is Microsoft's digital storytelling app designed specifically for creating visually engaging, interactive newsletters that automatically adapt to any screen size. Its card-based canvas lets users mix text, images, videos, and embed content from social media or the web, with a built-in design engine that applies consistent styling. Sway supports real-time collaboration and sharing via a unique URL, making it ideal for a marketing team that needs a professional-looking, device-friendly newsletter without requiring coding or design expertise. Unlike static documents, Sway's responsive layout and interactive elements (e.g., clickable slideshows, embedded media) differentiate it as the right choice.

Why this answer

Sway is the correct choice because it is specifically designed for creating interactive, web-based reports and newsletters that can embed videos, images, and links to documents. It provides responsive design that automatically adapts to any device, and it supports real-time collaboration through sharing a link, allowing team members to co-author content.

Exam trap

The trap here is that candidates often confuse Sway with Word Online or Publisher because they associate newsletters with traditional document creation, but Sway is the only Microsoft 365 app that combines rich media embedding, responsive web output, and real-time collaboration in a single tool.

How to eliminate wrong answers

Option A is wrong because Word Online is primarily a word processor for creating text-heavy documents; while it can embed images and links, it lacks native support for embedded videos and its layout is not optimized for responsive, device-agnostic newsletters. Option C is wrong because Publisher is a desktop publishing app focused on print layouts (e.g., brochures, flyers) and does not support embedded videos or responsive web viewing; it also lacks real-time collaboration features. Option D is wrong because OneNote is a digital notebook for capturing notes and ideas, not designed for creating polished, professional newsletters with embedded media and collaborative editing in a presentation-style format.

31
MCQmedium

A cloud provider offers a service where customers can provision virtual machines, storage, and networks on-demand through a web portal. The customer is responsible for patching the guest operating system. Which cloud service model best describes this offering?

A.Software as a Service (SaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Desktop as a Service (DaaS)
AnswerC

IaaS delivers virtualised compute, storage and networking on demand, while the customer retains responsibility for the guest operating system, including patching. That split of responsibility matches the scenario exactly, unlike PaaS or SaaS, where the provider manages the OS layer.

Why this answer

(Infrastructure as a Service) because the customer provisions fundamental compute, storage, and networking resources on-demand, and retains control over the guest OS, including patching. In IaaS, the provider manages only the physical infrastructure (hypervisor, networking, storage hardware), while the customer is responsible for the OS and applications, matching the scenario exactly.

Exam trap

The trap here is that candidates confuse PaaS with IaaS because both involve 'platform' or 'infrastructure' terms, but the key differentiator is who patches the guest OS — in PaaS, the provider patches it, while in IaaS, the customer does.

How to eliminate wrong answers

Option A is wrong because SaaS delivers fully managed applications (e.g., Office 365) where the provider handles all patching, including the OS, and the customer only uses the software via a browser or client. Option B is wrong because PaaS provides a managed platform (runtime, middleware, database) where the provider patches the underlying OS and runtime, and the customer only deploys code, not managing VMs or guest OS patches. Option D is wrong because DaaS delivers virtual desktops as a managed service, where the provider typically manages the guest OS image and patching, shifting OS responsibility away from the customer.

32
MCQeasy

A company uses a cloud provider that charges them only for the actual storage and compute resources they consume each month. They can start or stop machines at any time and are billed precisely for what they use. Which cloud computing characteristic does this billing model demonstrate?

A.Rapid elasticity
B.On-demand self-service
C.Resource pooling
D.Measured service
AnswerD

Measured service is the cloud characteristic where resource usage is automatically monitored, controlled, and reported, providing transparency for both the provider and consumer. This metering capability is what enables a pay-per-use billing model, where customers are charged only for the amount of service they actually consume. The scenario directly illustrates this principle, making it the correct answer.

Why this answer

The billing model described—paying only for actual storage and compute resources consumed, with the ability to start/stop machines at any time—directly demonstrates 'Measured service'. This characteristic, defined by NIST SP 800-145, means cloud systems automatically control and optimize resource usage by leveraging a metering capability at some level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, active user accounts). Usage is monitored, controlled, and reported, providing transparency for both the provider and consumer.

Exam trap

The trap here is that candidates confuse 'Measured service' with 'On-demand self-service' because both involve user control, but measured service specifically addresses the metering and pay-per-use billing aspect, not the ability to provision without human interaction.

How to eliminate wrong answers

Option A is wrong because 'Rapid elasticity' refers to the ability to quickly scale resources up or down, often automatically, to match demand—not to the billing model based on consumption. Option B is wrong because 'On-demand self-service' means a consumer can unilaterally provision computing capabilities (like server time or network storage) without requiring human interaction with each service provider—it describes the provisioning mechanism, not the pay-per-use billing. Option C is wrong because 'Resource pooling' means the provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with physical and virtual resources dynamically assigned and reassigned according to consumer demand—it is about multi-tenancy and location independence, not billing granularity.

33
MCQmedium

A company uses Microsoft 365 Business Premium. All users have Microsoft 365 E3 licenses, but the IT team wants to enforce conditional access policies to require multifactor authentication (MFA) for all external access to SharePoint Online. Which service should they use to create and manage these policies?

A.Microsoft Defender XDR
B.Microsoft Intune
C.Microsoft Entra ID
D.Microsoft Purview
AnswerC

Microsoft Entra ID (formerly Azure Active Directory) is the identity and access management service in Microsoft 365, and its Conditional Access engine is the correct place to enforce MFA for all users. Conditional Access policies evaluate sign-in signals such as user risk, device state, location, and application, and then require MFA or block access. Administrators would create a policy in Entra ID to require MFA for all users or specific conditions, which is exactly what this scenario demands.

Why this answer

Microsoft Entra ID (formerly Azure AD) is the identity and access management service that provides Conditional Access policies, which can require MFA for external access to SharePoint Online. These policies are evaluated at authentication time based on signals like user location, device state, and application, and they are independent of the underlying Microsoft 365 license (E3 or Business Premium).

Exam trap

The trap here is that candidates confuse Microsoft Intune's device compliance policies with Conditional Access policies, but Intune only provides the compliance state signal, while Entra ID is the service that evaluates and enforces the access decision.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender XDR is a security analytics and threat response platform that correlates signals across endpoints, email, and identities, but it does not create or manage Conditional Access policies. Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service that enforces device compliance and app protection policies, but it does not handle Conditional Access policy creation. Option D is wrong because Microsoft Purview is a data governance, compliance, and risk management solution that focuses on data classification, retention, and eDiscovery, not on identity-based access controls like Conditional Access.

34
MCQmedium

A compliance officer needs to automatically detect documents stored in SharePoint Online that contain sensitive data types (e.g., credit card numbers) and apply a sensitivity label that restricts access to only certain users. The classification should occur without user intervention and the label must be applied to the document. Which Microsoft Purview solution should be configured?

A.Data Loss Prevention (DLP)
B.Sensitivity labels with auto-labeling
C.Retention labels
D.Information barriers
AnswerB

Sensitivity labels with auto-labeling meet this requirement because they combine detection and protection: an auto-labeling policy in Microsoft Purview can scan files in SharePoint or OneDrive for predefined sensitive information types or trainable classifiers. When a match occurs, the policy automatically assigns a sensitivity label configured with encryption, rights management permissions, and visual markings. This creates a persistent classification that travels with the document, exactly matching the officer's need to automatically detect and protect sensitive documents.

Why this answer

Sensitivity labels with auto-labeling are the correct solution because they can automatically classify documents based on sensitive data types (such as credit card numbers) and apply a sensitivity label that enforces protection actions like restricting access to specific users. This occurs without user intervention, meeting the requirement for automatic classification and labeling in SharePoint Online.

Exam trap

The trap here is that candidates often confuse DLP policies with auto-labeling, but DLP only detects and blocks sharing actions, whereas auto-labeling applies the sensitivity label and its associated protection directly to the document.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) policies detect and prevent the sharing of sensitive data but do not apply sensitivity labels or enforce access restrictions on documents; they trigger alerts or block actions. Option C is wrong because retention labels are designed to manage data retention and deletion policies, not to classify documents based on sensitive data types or apply access restrictions. Option D is wrong because information barriers are used to restrict communication and collaboration between specific groups or users, not to automatically detect sensitive data or apply labels to documents.

35
MCQmedium

An administrator is reviewing an ARM template for a storage account. The template includes a storage account with Standard_LRS redundancy. Which Microsoft 365 licensing feature does this relate to?

A.OneDrive for Business storage
B.Microsoft Purview audit log storage
C.SharePoint Online storage quotas
D.Exchange Online mailbox limits
AnswerB

Microsoft Purview audit log storage is correct because the compliance service can use an Azure Storage account for long-term retention of audit records beyond the default retention period. An ARM template is the standard way to deploy that storage account, along with settings like network access, encryption, or a private endpoint. This directly aligns with the administrator's review of an ARM template for storage, as Purview integration explicitly supports Azure Storage as a destination.

Why this answer

The ARM template's Standard_LRS redundancy is used for Azure storage accounts, which underpin Microsoft 365's audit log storage in Microsoft Purview. Audit logs are stored in Azure Blob Storage, and Standard_LRS (Locally Redundant Storage) is the default redundancy tier for this data, providing three copies within a single datacenter. This directly links to the Purview audit log storage feature, not user-facing storage quotas or limits.

Exam trap

The trap here is that candidates confuse Azure storage redundancy (Standard_LRS) with Microsoft 365 user storage features like OneDrive or SharePoint quotas, but the question specifically ties to the backend infrastructure for audit log storage in Microsoft Purview.

How to eliminate wrong answers

Option A is wrong because OneDrive for Business storage is provisioned per user and managed through SharePoint Online quotas, not directly via ARM templates or Azure storage redundancy settings. Option C is wrong because SharePoint Online storage quotas are tenant-level limits for site collections and document libraries, controlled through SharePoint admin center settings, not Azure storage account redundancy. Option D is wrong because Exchange Online mailbox limits are defined by licensing plans and managed via Exchange admin center, unrelated to Azure storage account configurations like Standard_LRS.

36
Multi-Selecthard

Which TWO Microsoft 365 apps use AI to assist users with content creation?

Select 2 answers
A.Microsoft PowerPoint with Copilot
B.Microsoft Word with Copilot
C.Microsoft Viva Insights
D.Microsoft Excel with Copilot
E.Microsoft Teams with Copilot
AnswersA, B

Copilot in PowerPoint uses natural language prompts to generate full presentation decks, including slide layouts, images, and speaker notes, directly from a user's intent. This is a content-creation feature because it produces original presentation assets, not merely analyzes existing data or surfaces productivity insights. It also supports one-click summarization and restructuring of existing decks, further reinforcing its role in creating and refining presentation content.

Why this answer

Microsoft PowerPoint with Copilot and Microsoft Word with Copilot are correct because Copilot in these apps leverages large language models (LLMs) integrated with the Microsoft Graph to generate, summarize, and refine content directly within the document or presentation. In PowerPoint, Copilot can create entire slide decks from a prompt or natural language outline, while in Word, it can draft text, rewrite paragraphs, or summarize documents, both using AI to assist users in content creation.

Exam trap

The trap here is that candidates may assume any Copilot-enabled app (like Excel or Teams) qualifies as 'content creation,' but the MS-900 exam specifically distinguishes between AI for content generation (Word, PowerPoint) and AI for data analysis or meeting summarization (Excel, Teams), so you must identify which apps focus on creating new textual or visual content.

37
MCQhard

A multinational corporation uses Microsoft 365 E5 and wants to implement a retention policy that automatically deletes emails in users' mailboxes after 7 years, except for emails from the legal department which must be retained indefinitely. Which approach should the admin use?

A.Apply a litigation hold to all mailboxes and a retention policy to delete after 7 years
B.Configure Exchange Online archive policies to move emails after 7 years
C.Create a default retention policy for 7 years and use auto-labeling for legal department emails
D.Use Microsoft Purview eDiscovery to manually delete emails after 7 years
AnswerC

This approach separates retention behaviors by scope: a default Microsoft 365 retention policy enforces deletion of all general mailbox content after 7 years, satisfying systematic destruction. Auto-labeling then identifies legal department emails—using sensitive info types, trainable classifiers, or keywords—and applies a retention label with indefinite retention, which overrides the default deletion policy. The result is a compliant dual outcome: non-legal email is purged on schedule, while legal correspondence is preserved permanently.

Why this answer

It uses a retention policy with a 7-year deletion period for all content, then overrides that for legal department emails via auto-labeling with a 'retain indefinitely' label. This ensures that only legal emails are preserved forever while all other emails are automatically purged after 7 years, meeting the compliance requirement without manual intervention.

Exam trap

The trap here is that candidates confuse litigation hold (which preserves everything indefinitely) with a retention label that allows indefinite retention for a subset of items, leading them to choose Option A instead of understanding that litigation hold blocks deletion for all content.

How to eliminate wrong answers

Option A is wrong because a litigation hold preserves all mailbox content indefinitely, preventing the 7-year deletion policy from taking effect on any emails, including non-legal ones. Option B is wrong because Exchange Online archive policies only move emails to the archive mailbox after a specified period; they do not delete emails, so they cannot meet the deletion requirement. Option D is wrong because eDiscovery is a search and export tool, not a retention or deletion mechanism; manually deleting emails after 7 years is impractical, error-prone, and violates the automated compliance requirement.

38
MCQeasy

A marketing team needs to collaborate on a campaign document in real time and track changes. Which Microsoft 365 app should they use?

A.Teams
B.Word
C.OneNote
D.SharePoint
AnswerB

Word supports real-time co-authoring and built-in tracked changes, directly meeting the marketing team's need to collaborate simultaneously on the campaign document while recording revisions. Unlike SharePoint or Teams, which host and share files, Word provides the document editing and change-tracking functionality the scenario requires.

Why this answer

Microsoft Word is the application designed for creating and editing documents with real-time co-authoring and built-in track changes, which is exactly what the marketing team needs for a campaign document. Word supports simultaneous editing by multiple users and provides a full revision history with accept/reject change tracking. This makes it the correct choice for document collaboration with change tracking.

Exam trap

MS-900 often tests the confusion between the collaboration platform (Teams, SharePoint) and the authoring application (Word), so candidates pick Teams or SharePoint thinking they handle document editing and track changes.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is a collaboration hub for chat, meetings, and file sharing — it hosts the document but is not the app used to author and track changes in it. Option C is wrong because OneNote is a note-taking application optimized for free-form notes and notebooks, not for formal document editing with track changes. Option D is wrong because SharePoint is a document management and storage platform — it stores and versions files but does not itself provide the rich document editing and track-changes experience that Word does.

39
MCQmedium

A security analyst receives an alert about a user who downloaded a large number of files from a SharePoint document library in a short period. The analyst needs to investigate the user's activities across Exchange, SharePoint, and Teams to determine if data exfiltration is occurring. Which Microsoft Purview solution should the analyst use to review detailed activity logs?

A.Microsoft Purview Audit (Premium)
B.Microsoft Purview eDiscovery (Premium)
C.Microsoft Purview Communication Compliance
D.Microsoft Purview Data Loss Prevention (DLP)
AnswerA

Microsoft Purview Audit (Premium) provides a comprehensive, forensic-grade record of user and admin activities across Microsoft 365 services, including file downloads from SharePoint/OneDrive. It extends the standard audit log with features like longer retention (up to 10 years), access to high-value events such as MailItemsAccessed and unusual admin actions, and intelligent insights that surface anomalies. For a security analyst triaging an alert about a suspicious download, Audit (Premium) is the correct tool because it lets you query the unified audit log for the specific 'FileDownloaded' event and reconstruct a timeline of the user's actions.

Why this answer

Microsoft Purview Audit (Premium) provides detailed, searchable activity logs for user actions across Exchange, SharePoint, and Teams, including file downloads, access events, and admin operations. The analyst can use the Audit log search to filter by user, date range, and activity type (e.g., 'FileDownloaded') to identify potential data exfiltration patterns. Audit (Premium) also offers longer retention (up to 1 year by default, extendable to 10 years) and higher-bandwidth APIs for large-scale investigations.

Exam trap

The trap here is that candidates confuse the investigative capability of Audit logs with the preventive or content-focused tools like DLP or eDiscovery, assuming that any security-related alert must be handled by DLP or eDiscovery, when in fact Audit (Premium) is the correct tool for reviewing historical activity logs.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview eDiscovery (Premium) is designed for legal discovery and content search (e.g., identifying, preserving, and exporting relevant documents and emails), not for real-time or historical activity log review of user actions like file downloads. Option C is wrong because Microsoft Purview Communication Compliance focuses on monitoring internal and external communications (e.g., email, Teams messages) for policy violations like harassment or insider trading, not on tracking file download activities from SharePoint. Option D is wrong because Microsoft Purview Data Loss Prevention (DLP) is a policy-based solution that prevents data exfiltration by blocking or alerting on sensitive content in transit or at rest, but it does not provide a searchable log of past user activities for forensic investigation.

40
MCQmedium

A financial services firm uses Microsoft 365 and must retain all business communications for 7 years to comply with SEC regulations. They also need to prevent users from permanently deleting emails. Which Microsoft Purview feature should they implement?

A.Retention policies and retention labels
B.Sensitivity labels
C.eDiscovery (Standard)
D.Data Loss Prevention (DLP) policies
AnswerA

Retention policies and labels apply retention settings across Exchange, SharePoint and Teams, and preserve content by blocking permanent deletion until the seven-year period expires. This satisfies both the SEC retention obligation and the requirement preventing users from purging emails.

Why this answer

Retention policies and retention labels in Microsoft Purview allow organizations to retain content for a specified period (e.g., 7 years) and prevent permanent deletion by users. They can be applied to Exchange email, SharePoint, OneDrive, and Teams, ensuring compliance with SEC regulations. This feature also supports disposition review and legal hold scenarios.

Exam trap

The trap is confusing retention with other Purview features like DLP or eDiscovery; candidates might think DLP prevents deletion, but DLP only blocks sharing or leakage, not deletion for retention.

How to eliminate wrong answers

Option B is wrong because sensitivity labels are used for classification and protection (e.g., encryption), not for retention or deletion prevention. Option C is wrong because eDiscovery (Standard) is for identifying and collecting data for legal cases, but it does not enforce retention or prevent deletion. Option D is wrong because DLP policies prevent data leakage but do not retain data or block deletion for compliance periods.

41
MCQeasy

A development team wants to deploy a custom web application to the cloud. They want to upload their code and let the cloud provider handle server infrastructure, operating system updates, and automatic scaling. Which cloud service model best fits this requirement?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.On-premises deployment
AnswerB

Platform as a Service (PaaS) is the right fit because it abstracts the underlying compute, storage, and networking into a ready-to-use hosting platform. The developer simply uploads the web app code or a container image, and the provider handles patching the OS, automatic scaling, load balancing, and health monitoring. This lets the team focus on business logic and data rather than on managing servers or runtimes.

Why this answer

Platform as a Service (PaaS) is the correct choice because it provides a managed hosting environment where the development team can upload their custom web application code without managing the underlying server infrastructure, operating system updates, or scaling. Azure App Service, a PaaS offering, automatically handles OS patching, load balancing, and auto-scaling based on demand, aligning perfectly with the requirement to let the cloud provider handle these tasks.

Exam trap

The trap here is that candidates often confuse IaaS with PaaS, mistakenly thinking that IaaS also abstracts OS updates and scaling, but IaaS still requires the user to manage the OS and configure scaling manually, unlike PaaS which fully automates these responsibilities.

How to eliminate wrong answers

Option A is wrong because Infrastructure as a Service (IaaS) provides virtual machines, storage, and networks, but the team would still be responsible for managing the operating system, applying updates, and configuring scaling manually, which contradicts the requirement to offload these tasks. Option C is wrong because Software as a Service (SaaS) delivers fully managed applications (e.g., Office 365) that users access via a browser, not a platform for deploying custom code. Option D is wrong because on-premises deployment requires the team to own and manage all hardware, software, and updates locally, which is the opposite of letting the cloud provider handle infrastructure.

42
MCQmedium

A tenant administrator is advising a department that wants to let users sign in once and access connected Microsoft 365 and SaaS apps. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Planner
B.Microsoft Forms
C.Microsoft Stream
D.Single sign-on (SSO)
AnswerD

Single sign-on (SSO) is an identity management capability in Microsoft Entra ID that allows users to authenticate once and then access all connected Microsoft 365 applications without re-entering credentials. It works by leveraging federation protocols such as SAML 2.0, OpenID Connect, and OAuth 2.0 to issue security tokens that trusted service providers accept. SSO directly fulfills the requirement for streamlined access while enabling centralized security controls like conditional access and multifactor authentication. This makes it the correct answer.

Why this answer

Single sign-on (SSO) enables users to authenticate once and gain access to multiple applications, including Microsoft 365 and third-party SaaS apps, without re-entering credentials. This is achieved through federation protocols such as SAML 2.0 or OpenID Connect, which allow the identity provider (Azure AD) to issue security tokens to relying party applications. SSO is the correct Microsoft security and identity capability for this requirement.

Exam trap

The trap here is that candidates may confuse productivity tools (Planner, Forms, Stream) with security/identity capabilities, failing to recognize that SSO is the specific feature designed for unified authentication across multiple apps.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management and project planning tool within Microsoft 365, not an identity or security capability; it cannot provide single sign-on or federated authentication. Option B is wrong because Microsoft Forms is a survey and data collection tool, lacking any identity federation or authentication functionality. Option C is wrong because Microsoft Stream is a video hosting and sharing service; it does not implement SSO or manage user authentication across apps.

43
MCQmedium

A tenant administrator is advising a department that wants to review upcoming Microsoft 365 changes and recommended admin actions. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Microsoft Forms
C.Microsoft Whiteboard
D.Message center
AnswerD

The Message center in the Microsoft 365 admin center publishes upcoming service changes and their required admin actions, directly satisfying the department's need to review planned updates. Unlike the Service health dashboard, which reports current incidents and advisories, Message center is the designated channel for change announcements and recommended preparation steps.

Why this answer

The Message center in the Microsoft 365 admin center is the dedicated hub for reviewing upcoming changes, new features, and recommended admin actions. It provides service advisories, planned changes, and action-required notifications, making it the most relevant concept for a tenant administrator advising a department on upcoming Microsoft 365 changes.

Exam trap

The trap here is that candidates confuse productivity tools (Stream, Forms, Whiteboard) with administrative communication channels, overlooking that the Message center is the specific admin portal feature for change management and action items.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video management and sharing service, not a tool for reviewing upcoming changes or admin actions. Option B is wrong because Microsoft Forms is a survey and quiz creation tool, unrelated to change notifications or admin advisories. Option C is wrong because Microsoft Whiteboard is a digital canvas for collaboration, not a mechanism for tracking service updates or recommended actions.

44
MCQmedium

A sales team wants to build a custom inventory tracking application with minimal code. They need a cloud-based database that can securely store structured data and integrate with the low-code app builder. Which Microsoft 365 service should they use as the database backend?

A.Microsoft Lists
B.Power Apps
C.Microsoft Dataverse
D.Power Automate
AnswerC

Microsoft Dataverse is the correct choice because it is a fully managed, low-code data platform that provides relational tables, rich metadata, role-based security, and built-in auditing for structured business data. It is tightly integrated with Power Apps and the Power Platform, enabling the sales team to model inventory items, relationships, and business rules without writing custom code, all within a scalable, secure cloud database.

Why this answer

Microsoft Dataverse is the correct choice because it provides a scalable, cloud-based relational database that securely stores structured data and integrates natively with Power Apps, the low-code app builder. Unlike simpler list-based storage, Dataverse supports rich data types, relationships, business logic, and role-based security, making it ideal for custom inventory tracking applications built with minimal code.

Exam trap

The trap here is that candidates often confuse Microsoft Lists (a simple list tool) with a proper database backend, or mistakenly think Power Apps or Power Automate can serve as data storage, when in fact they are application and automation layers that require a separate data source like Dataverse.

How to eliminate wrong answers

Option A is wrong because Microsoft Lists is a list-based data storage service designed for simple tracking and collaboration, not a full relational database with support for complex relationships, business rules, and integration with low-code app builders like Power Apps. Option B is wrong because Power Apps is the low-code app builder itself, not a database backend; it requires a data source such as Dataverse, SharePoint, or SQL to store and retrieve data. Option D is wrong because Power Automate is a workflow automation service for creating automated processes, not a database; it can trigger actions based on data but does not provide persistent storage for structured inventory data.

45
MCQmedium

During requirements gathering, an IT manager says the organization must license frontline workers with lighter productivity needs. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Plans designed for frontline worker scenarios
B.Microsoft Whiteboard
C.Microsoft Stream
D.Microsoft Forms
AnswerA

Frontline worker plans license staff who do not need full Office applications, providing web and mobile access to Teams, SharePoint and Viva Engage instead. This directly satisfies the stated constraint of lighter productivity needs, matching the licensing tier to the workforce's actual usage rather than paying for unused desktop software.

Why this answer

The IT manager's requirement specifically calls for licensing frontline workers with lighter productivity needs. Microsoft 365 offers dedicated plans (e.g., Microsoft 365 F1, F3) designed precisely for frontline worker scenarios, providing essential productivity and communication tools at a lower cost per user. This makes option A the most relevant concept for the given requirement.

Exam trap

The trap here is that candidates may confuse individual Microsoft 365 applications (like Whiteboard, Stream, or Forms) with licensing plans, overlooking that the question asks for the most relevant 'licensing, admin, or support concept' rather than a specific tool.

How to eliminate wrong answers

Option B (Microsoft Whiteboard) is wrong because it is a specific application, not a licensing or support concept; it does not address the requirement to license frontline workers. Option C (Microsoft Stream) is wrong because it is a video service, not a licensing plan or support concept; it does not provide a framework for licensing users with lighter needs. Option D (Microsoft Forms) is wrong because it is a survey and data collection tool, not a licensing or support concept; it does not help in categorizing or licensing frontline workers.

46
MCQeasy

A cloud provider offers virtual machines, but customers must install, configure, and maintain the operating system and applications. Which cloud service model does this describe?

A.IaaS (Infrastructure as a Service)
B.PaaS (Platform as a Service)
C.SaaS (Software as a Service)
D.FaaS (Function as a Service)
AnswerA

In IaaS, the provider supplies virtualized compute, storage, and networking as on-demand resources, but the customer deploys and manages the virtual machines' guest OS, runtime, and installed applications. This shared-responsibility model places patching, configuration, and application stack maintenance squarely on the customer, which is exactly the scenario described. The provider's responsibility ends at the hypervisor and physical infrastructure, so customers must handle everything inside the VM.

Why this answer

This scenario describes Infrastructure as a Service (IaaS), where the cloud provider supplies virtualized computing resources such as virtual machines, storage, and networking, but the customer retains full control over the operating system, middleware, and applications. In IaaS, the provider manages only the physical infrastructure (hypervisor, servers, storage, and network), while the customer is responsible for OS installation, configuration, patching, and application management. This aligns directly with the question's description of customer-managed OS and applications on provider-hosted VMs.

Exam trap

The trap here is that candidates often confuse IaaS with PaaS because both involve virtual machines, but PaaS (e.g., Azure App Service) hides the OS and runtime, whereas IaaS requires full customer OS management.

How to eliminate wrong answers

Option B (PaaS) is wrong because PaaS abstracts the underlying OS and runtime; the provider manages the OS, middleware, and runtime environment, so customers do not install or maintain the OS. Option C (SaaS) is wrong because SaaS delivers fully functional applications accessed via a web browser or API, with no customer control over the OS or underlying infrastructure. Option D (FaaS) is wrong because FaaS (Function as a Service) executes stateless code functions in response to events, with the provider managing all infrastructure including the OS, and customers only upload code without any OS-level access.

47
Multi-Selectmedium

Which TWO Microsoft 365 apps can be used to create and share forms for surveys? (Select exactly 2.)

Select 2 answers
A.Microsoft Forms
B.Microsoft Teams
C.Microsoft Outlook
D.OneNote
E.Microsoft Excel
AnswersA, E

Microsoft Forms is the dedicated web-based application for creating surveys, quizzes, and polls in Microsoft 365. It provides a rich authoring environment with question types, branching logic, and real-time response analytics, and it lets you share forms via links, QR codes, or email. While it integrates with Excel to export responses, the form creation itself occurs exclusively within Forms, making it the correct answer.

Why this answer

Microsoft Forms is a dedicated survey and quiz creation tool within Microsoft 365, allowing users to design forms, collect responses, and export data to Excel. It integrates with Teams and SharePoint for sharing, but the core creation and sharing capability for surveys is native to Forms itself. Microsoft Excel can also be used to create forms via the 'Insert > Forms' option, which leverages the same underlying Forms service to generate and share surveys directly from a spreadsheet.

Exam trap

The trap here is that candidates often mistake Microsoft Teams as a form creation tool because they see forms shared within Teams channels, but Teams is merely a distribution platform, not a creation app.

48
MCQeasy

A marketing team wants to quickly create a visually appealing report from data stored in Excel and share it with stakeholders via a web browser. Which Microsoft 365 app should they use?

A.Microsoft Forms
B.Microsoft Stream
C.Microsoft Excel
D.Microsoft Power BI
AnswerD

Power BI is Microsoft's dedicated business intelligence tool for turning data into interactive, visually rich reports. Users can connect to dozens of data sources, build cross-filtering visuals, add drilldowns, and publish to the Power BI service, where colleagues access the report in a browser or mobile app. This directly matches the team's need to quickly create and share an appealing, interactive report.

Why this answer

Microsoft Power BI is the correct choice because it is designed specifically for creating interactive, visually appealing reports and dashboards from data sources like Excel. It allows users to publish these reports to the Power BI service, where stakeholders can access them via a web browser without needing to install any software.

Exam trap

The trap here is that candidates may choose Microsoft Excel because they think it can create charts and share them via OneDrive or SharePoint, but they overlook that Power BI is the dedicated tool for interactive, browser-based reporting with advanced visualization and sharing capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and quiz tool, not a data visualization or reporting app; it cannot create reports from Excel data. Option B is wrong because Microsoft Stream is a video hosting and sharing platform, not designed for data analysis or report creation. Option C is wrong because while Microsoft Excel can create charts and graphs, it lacks the native capability to publish interactive, browser-accessible reports with the same level of visual interactivity and sharing controls as Power BI.

49
Multi-Selectmedium

Which TWO Microsoft 365 services provide real-time co-authoring in documents?

Select 2 answers
A.Microsoft Teams
B.SharePoint Online
C.Microsoft Lists
D.Exchange Online
E.OneDrive for Business
AnswersB, E

SharePoint Online stores documents in document libraries and natively supports real-time co-authoring via the Office Web Apps and desktop applications, allowing multiple users to edit a document simultaneously with presence indicators and automatic versioning. Because SharePoint is a first-class document management service, it is one of the two correct services.

Why this answer

SharePoint Online is correct because it supports real-time co-authoring in Word, Excel, and PowerPoint documents stored in SharePoint document libraries, leveraging the Office Online server infrastructure and the WebDAV protocol for simultaneous edits by multiple users.

Exam trap

The trap here is that candidates may confuse Microsoft Teams' file-sharing and preview capabilities with actual real-time co-authoring, but Teams merely surfaces files from SharePoint or OneDrive and does not host the co-authoring engine itself.

50
MCQmedium

During a Microsoft 365 planning workshop, check whether an Outlook on the web issue is caused by a known Microsoft incident. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Microsoft Stream
C.Microsoft Forms
D.Service health
AnswerD

Service health, accessible via the Microsoft 365 admin center or the Service Health API, is the authoritative feed that shows real-time status, active incidents, advisories, and historical uptime for each M365 service. During a planning workshop, administrators should consult this dashboard first to determine whether Microsoft has a known incident that could affect deployment, configuration, or support SLA. It also distinguishes between incidents, advisory notifications, and post-incident reports, giving the necessary operational context for planning decisions. This makes Service health the only correct option for verifying known service incidents.

Why this answer

Service health in the Microsoft 365 admin center provides real-time status of Microsoft services, including known incidents and advisories. When troubleshooting an Outlook on the web issue, checking Service health is the correct first step to determine if the problem is caused by a known Microsoft incident, rather than a local configuration or licensing problem.

Exam trap

The trap here is that candidates may confuse collaboration or productivity tools (Whiteboard, Stream, Forms) with administrative monitoring features, mistakenly thinking they can be used to diagnose service incidents, when only Service health provides the required incident status data.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a digital canvas collaboration tool, not a service health monitoring feature; it cannot be used to check for known incidents affecting Outlook on the web. Option B is wrong because Microsoft Stream is a video service for recording and sharing videos, unrelated to incident tracking or service health diagnostics. Option C is wrong because Microsoft Forms is a survey and quiz creation tool, not a mechanism to verify service incidents or outages.

51
Multi-Selectmedium

Which TWO Microsoft 365 apps are primarily used for business process automation and workflow? (Select two.)

Select 2 answers
A.Microsoft Planner
B.Microsoft To Do
C.Microsoft Forms
D.Microsoft Power Apps
E.Microsoft Power Automate
AnswersD, E

Power Apps is a low-code development platform for building custom business applications that can pull from Microsoft Dataverse, SharePoint, and hundreds of data connectors. Users create canvas, model-driven, or portal apps with responsive UI and business rules, enabling organizations to solve specific operational problems without writing traditional code. Because it is designed to digitize and customize end-to-end business processes, it is one of the two Microsoft/Power Platform apps primarily used for business.

Why this answer

Microsoft Power Apps is a low-code application development platform that enables users to build custom business apps for process automation, while Microsoft Power Automate (formerly Flow) is a cloud-based service for creating automated workflows between apps and services. Together, they form the core of Microsoft's Power Platform for business process automation and workflow orchestration.

Exam trap

The trap here is that candidates often confuse task management tools (Planner, To Do) with workflow automation platforms, or mistake data collection tools (Forms) for process automation, because all involve 'tasks' or 'forms' but lack the underlying workflow engine and integration capabilities.

52
MCQmedium

A hospital must store patient medical records on-premises to comply with strict data sovereignty regulations. However, they also want to use advanced analytics tools hosted on a public cloud platform. Which cloud deployment model best meets their needs?

A.Private cloud
B.Public cloud
C.Hybrid cloud
D.Community cloud
AnswerC

Hybrid cloud keeps regulated patient records on the hospital's on-premises infrastructure, satisfying the data sovereignty constraint, while securely connecting to public cloud analytics services over a private link or VPN. This split lets sensitive data remain local and computation-intensive analytics scale in the public cloud, which neither pure private nor public deployment achieves.

Why this answer

(Hybrid cloud) is correct because it allows the hospital to keep sensitive patient medical records on-premises to satisfy strict data sovereignty regulations, while leveraging public cloud services for advanced analytics. This model combines private and public cloud resources, enabling data to remain compliant without sacrificing access to cloud-hosted analytics tools.

Exam trap

The trap here is that candidates often choose Private cloud (Option A) thinking it is the only way to ensure data sovereignty, but they overlook the requirement for advanced analytics tools hosted on a public cloud, which Hybrid cloud uniquely satisfies.

How to eliminate wrong answers

Option A (Private cloud) is wrong because while it meets data sovereignty requirements, it does not provide access to public cloud-based advanced analytics tools, limiting the hospital's ability to use those services. Option B (Public cloud) is wrong because it would require storing patient data off-premises, violating data sovereignty regulations that mandate on-premises storage. Option D (Community cloud) is wrong because it is designed for multiple organizations with shared concerns (e.g., compliance), but it still typically involves off-premises infrastructure and does not inherently support a hybrid approach that keeps specific data on-premises while using public cloud analytics.

53
MCQmedium

During requirements gathering, an IT manager says the organization must classify files as Confidential and apply encryption to the most sensitive content. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Stream
B.Microsoft Planner
C.Sensitivity labels
D.Microsoft Forms
AnswerC

Sensitivity labels in Microsoft Purview are the correct choice because they let administrators define classification tiers and associate them with protections such as Azure Rights Management encryption, visual headers/footers/watermarks, and conditional access restrictions. Once applied, the label persists as metadata as the item travels, allowing Microsoft 365 apps and DLP policies to enforce the same protections everywhere. This directly satisfies the requirement to control access based on the sensitivity of content.

Why this answer

Sensitivity labels in Microsoft Purview Information Protection allow organizations to classify files as Confidential and apply encryption automatically or manually. This capability meets the requirement to protect the most sensitive content by enforcing access controls and encryption policies based on the label.

Exam trap

The trap here is that candidates may confuse Microsoft's collaboration tools (Stream, Planner, Forms) with security/compliance features, overlooking that sensitivity labels are the dedicated mechanism for classification and encryption in Microsoft 365.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video hosting and sharing service, not a security or compliance tool for file classification or encryption. Option B is wrong because Microsoft Planner is a task management and collaboration tool, lacking any native classification or encryption features. Option D is wrong because Microsoft Forms is used to create surveys and quizzes, with no capability to classify files or apply encryption.

54
MCQeasy

Your company is subject to the General Data Protection Regulation (GDPR). Which Microsoft 365 compliance feature helps you respond to a Data Subject Request (DSR) to export a user's personal data?

A.Microsoft Information Protection
B.Data Loss Prevention
C.Microsoft Purview eDiscovery
D.Unified audit log
AnswerC

Microsoft Purview eDiscovery locates and exports content across Exchange, SharePoint, OneDrive and Teams, matching a Data Subject Request for a user's personal data. Its search-and-export workflow satisfies the GDPR access right, unlike retention or labelling features.

Why this answer

Microsoft Purview eDiscovery (Standard or Premium) is the compliance tool designed to identify, collect, preserve, and export content in response to Data Subject Requests under GDPR. It can search across Exchange, SharePoint, OneDrive, Teams, and other workloads, then export the results in a review set that satisfies the DSR 'right of access' and 'right to data portability' requirements.

Exam trap

The trap is conflating 'compliance features that protect data' (MIP, DLP) with 'compliance features that find and export data' (eDiscovery) — DSRs require the latter, not the former.

How to eliminate wrong answers

Option A is wrong because Microsoft Information Protection (MIP) focuses on classifying and labeling sensitive data (sensitivity labels, encryption), not on locating and exporting a specific user's personal data for a DSR. Option B is wrong because Data Loss Prevention (DLP) prevents exfiltration of sensitive information via policies; it does not provide the search-and-export workflow required to fulfill a DSR. Option D is wrong because the Unified audit log records user and admin activity for forensic/investigative purposes; it does not retrieve the actual content of a user's personal data for export.

55
Drag & Dropmedium

Drag and drop the steps to configure a Microsoft 365 group expiration policy in the Azure AD admin center into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

To configure a Microsoft 365 group expiration policy, you must first sign in to the Azure AD admin center, then navigate to Groups > Expiration, configure the desired expiration settings, and finally save the policy. This sequence ensures proper access and application of the configuration.

56
MCQmedium

A compliance-aware administrator is selecting the right Microsoft 365 capability to manage formal records that must be retained and disposed of according to policy. Microsoft security, identity, or compliance capability should it use?

A.Records Management
B.Microsoft Forms
C.Microsoft Planner
D.Microsoft Stream
AnswerA

Records Management in Microsoft 365 (part of Microsoft Purview) is the correct choice because it provides a comprehensive lifecycle for content that must be treated as records. It allows administrators to declare records, apply retention labels, initiate disposition reviews, and securely dispose of items while maintaining an audit trail for regulatory compliance. This capability directly addresses the need for a compliance-aware administrator to handle retention and disposal obligations, which cannot be met by other service-specific tools.

Why this answer

Records Management in Microsoft 365 (part of Microsoft Purview) is specifically designed to manage formal records by applying retention labels that enforce retention and disposition policies. It allows administrators to declare records, lock them against modification or deletion, and trigger disposal actions based on regulatory or organizational requirements. This directly addresses the need to retain and dispose of records according to policy.

Exam trap

The trap here is that candidates may confuse general compliance features (like retention policies in Microsoft 365) with the specific Records Management capability, which is the only one designed for formal, policy-driven record declaration and disposition.

How to eliminate wrong answers

Option B (Microsoft Forms) is wrong because it is a survey and data collection tool, not a compliance capability for managing records retention or disposition. Option C (Microsoft Planner) is wrong because it is a task management and collaboration tool for organizing work, with no built-in features for formal records management or policy-based retention. Option D (Microsoft Stream) is wrong because it is a video hosting and sharing platform; while it may have some retention policies via broader Microsoft 365 compliance, it is not a dedicated records management capability.

57
Multi-Selecthard

Which THREE Microsoft 365 compliance features are available in Microsoft Purview to help organizations manage data lifecycle and retention?

Select 3 answers
A.Sensitivity Labels
B.Records Management
C.Data Lifecycle Management
D.Retention Policies
E.Data Loss Prevention
AnswersB, C, D

Records Management is a dedicated Microsoft Purview solution that lets organizations declare content as records, meaning it is retained and disposed of according to defined rules, and users cannot alter or delete it. It uses retention labels with event-based or manual disposition reviews to manage records from declaration through final disposition. This directly addresses compliance requirements for legal and regulatory retention, making it one of the correct features for lifecycle governance.

Why this answer

Records Management (B) is correct because it enables organizations to declare records, apply retention labels, and manage the disposition of content in a defensible manner. It is a core Purview feature for managing the data lifecycle, ensuring that records are retained for the required period and then disposed of appropriately.

Exam trap

The trap here is that candidates often confuse Sensitivity Labels with retention features because both are part of Purview, but Sensitivity Labels control access and protection, not the lifecycle or retention duration of data.

58
MCQeasy

A nonprofit organization with 50 users needs to use Microsoft 365 for email, file storage, and online versions of Office apps. They have a very limited budget. Which Microsoft 365 plan should they consider first?

A.Microsoft 365 Business Basic
B.Microsoft 365 Business Premium
C.Office 365 E3
D.Microsoft 365 Nonprofit Business Basic
AnswerD

Microsoft 365 Nonprofit Business Basic is the correct choice because it is tailor-made for eligible nonprofits, offering Exchange Online, Teams, SharePoint, and web versions of Word, Excel, PowerPoint, and OneDrive at no cost or at a very low monthly rate depending on qualification. This plan satisfies the essential needs of email, file storage, and web-based Office apps for up to 300 users, making it economically ideal for a 50-person nonprofit. It also includes the same security and compliance baselines as the commercial Business Basic but at a nonprofit-aggregated price.

Why this answer

Microsoft 365 Nonprofit Business Basic (Option D) is the correct choice because it provides email (Exchange Online), file storage (OneDrive and SharePoint), and online versions of Office apps (Word, Excel, etc.) at no cost for eligible nonprofit organizations with up to 300 users. This plan is specifically designed for nonprofits with limited budgets, offering the required functionality without the expense of paid plans.

Exam trap

The trap here is that candidates may overlook the nonprofit-specific plans and choose a commercial plan like Business Basic (Option A) or Business Premium (Option B), assuming they are the only options, without realizing that Microsoft offers free or heavily discounted plans for eligible nonprofits, which directly address the budget constraint.

How to eliminate wrong answers

Option A (Microsoft 365 Business Basic) is wrong because it is a paid commercial plan that requires a monthly subscription per user, whereas the nonprofit version of Business Basic is available at no cost for eligible organizations. Option B (Microsoft 365 Business Premium) is wrong because it includes advanced security and device management features (e.g., Microsoft Defender for Business, Intune) that are unnecessary for basic email, storage, and online Office apps, and it is significantly more expensive. Option C (Office 365 E3) is wrong because it is an enterprise plan designed for larger organizations with advanced compliance and analytics capabilities (e.g., eDiscovery, Power BI Pro), and it is not optimized for the limited budget or specific needs of a small nonprofit; additionally, it is a paid plan unlike the free nonprofit offering.

59
Multi-Selecteasy

Which TWO Microsoft 365 services can be used to create and manage tasks?

Select 2 answers
A.Power Automate
B.Microsoft Planner
C.Microsoft Word
D.Microsoft To Do
E.SharePoint
AnswersB, D

Microsoft Planner is a team-based task management service in Microsoft 365, part of the Power Platform and Teams. Each plan is a shared board with buckets, tasks, due dates, checklists, labels, and assignments, enabling groups to organize work visually. It directly satisfies the rubric of creating and managing tasks within a shared team context.

Why this answer

Microsoft Planner (B) is a dedicated Microsoft 365 task-management service where teams create plans, buckets, and tasks with assignments, due dates, checklists, and progress tracking, so it directly satisfies the requirement to create and manage tasks. Microsoft To Do (D) is the personal task-management app in Microsoft 365 that lets users create task lists, set reminders, due dates, steps, and sync tasks (including flagged Outlook items and assigned Planner tasks), so it also directly creates and manages tasks. Power Automate (A) is a workflow/automation service that triggers actions across services rather than a task-management tool itself, so it does not belong.

Microsoft Word (C) is a document-authoring application with no native task-management capability, and SharePoint (E) is a collaboration and content platform whose lists can store task-like items but it is not one of the two designated task creation/management services here.

Exam trap

The trap here is that candidates may confuse SharePoint's ability to create custom task lists with being a dedicated task management service, but SharePoint lacks the native Kanban boards, assignment workflows, and integration with To Do that define Planner and To Do as the correct answers.

60
MCQeasy

A company wants to provide its employees with access to email, calendar, and document editing tools through a web browser without installing any software. The provider manages all maintenance, updates, and security of the applications. Which cloud service model best describes this scenario?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Desktop as a Service (DaaS)
AnswerC

SaaS (Software as a Service) is correct because it delivers fully functional, ready-to-use applications over the internet, with the provider managing all underlying infrastructure, platform, and application code. Email, shared calendars, and document editing are classic SaaS workloads — think of Microsoft 365 Exchange Online, Outlook on the web, and Office for the web. Users only need a browser or thin client, never having to worry about servers, patching, or maintenance, which perfectly matches the need to provide employees with access to these applications.

Why this answer

This scenario describes Software as a Service (SaaS) because the provider delivers fully functional applications—such as email, calendar, and document editing—over the web, with no local installation required. The provider handles all maintenance, updates, and security, which is the defining characteristic of SaaS. Examples include Microsoft 365 (Exchange Online, Outlook, Word Online) and Google Workspace.

Exam trap

The trap here is that candidates often confuse SaaS with PaaS because both involve managed services, but PaaS is for developers building custom applications, not for end users consuming ready-made applications like email and calendars.

How to eliminate wrong answers

Option A is wrong because Infrastructure as a Service (IaaS) provides virtualized computing resources (e.g., VMs, storage, networks) but requires the customer to install and manage their own operating systems and applications, not just use pre-built tools via a browser. Option B is wrong because Platform as a Service (PaaS) provides a runtime environment and development tools for building and deploying custom applications, not ready-to-use end-user applications like email and document editing. Option D is wrong because Desktop as a Service (DaaS) delivers a full virtual desktop environment (including OS and applications) to end users, but the scenario specifies accessing specific applications through a web browser without a full desktop experience, and DaaS typically requires a client or browser-based remote desktop connection, not just direct web access to individual apps.

61
MCQmedium

A compliance officer needs to automatically encrypt any outgoing email that contains a customer's credit card number. The solution should work without requiring the sender to take any manual action. Which Microsoft Purview feature should be configured?

A.Data Loss Prevention (DLP) policy
B.Microsoft Purview Message Encryption
C.Sensitivity labels
D.Retention policies
AnswerA

Data Loss Prevention (DLP) policies in Microsoft Purview inspect outbound email for sensitive information types, such as credit card numbers, and can automatically invoke encryption as a corrective action before the message is sent. This is a built-in, policy-driven capability that requires no manual user action or separate rule configuration, making it the correct choice for automatically encrypting messages containing regulated data.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft Purview can be configured to automatically detect sensitive information types, such as credit card numbers, in outgoing email. When a match is found, the policy can enforce an action like 'Encrypt the message' without requiring any manual action from the sender, fulfilling the compliance officer's requirement for automatic, sender-transparent encryption.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Message Encryption (a manual or rule-triggered encryption method) with a DLP policy's ability to automatically detect and encrypt content, leading them to select Message Encryption as the direct solution instead of the policy that orchestrates the detection and action.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Message Encryption is a feature that provides encryption capabilities, but it requires manual action by the sender (e.g., selecting 'Encrypt' in Outlook) or must be triggered by a DLP policy; it is not a policy itself that automatically detects and encrypts based on content. Option C is wrong because sensitivity labels are used to classify and protect data based on user-applied or automatic labeling, but they do not natively scan for specific patterns like credit card numbers in transit; they rely on DLP or auto-labeling policies for such detection. Option D is wrong because retention policies are designed to preserve or delete data after a specified period, not to inspect content in real-time for sensitive information or enforce encryption on outgoing messages.

62
MCQmedium

A financial services company uses Microsoft 365 E5 and wants to implement a data loss prevention (DLP) policy that blocks users from sharing credit card numbers via email and Teams messages. The compliance team also wants to generate reports on policy violations. They are considering using Microsoft Purview. Which approach should they take to meet these requirements with minimum administrative overhead?

A.Create separate DLP policies in Exchange admin center and Teams admin center.
B.Create a unified DLP policy in the Microsoft Purview compliance portal that covers Exchange and Teams.
C.Use Microsoft Sentinel to create analytics rules that detect sharing of credit card numbers.
D.Use Microsoft Defender for Cloud Apps to create session policies for email and Teams.
AnswerB

A single unified DLP policy in Microsoft Purview applies across Exchange and Teams, blocking credit card numbers in both and generating violation reports. This meets both requirements with minimum administrative overhead, avoiding separate per-workload policies.

Why this answer

A unified DLP policy in Microsoft Purview covers Exchange Online, Teams, SharePoint, and OneDrive from a single policy definition, so credit card numbers (a built-in sensitive information type) can be blocked across both email and Teams chat with one configuration. This minimizes administrative overhead because there is no need to duplicate rules across separate admin centers, and violation reports are consolidated in the Purview compliance portal.

Exam trap

MS-900 often tests the misconception that DLP must be configured separately per workload (Exchange vs Teams), when Microsoft Purview provides a single unified policy engine across Microsoft 365 workloads.

How to eliminate wrong answers

Option A is wrong because creating separate DLP policies in the Exchange admin center and Teams admin center duplicates configuration, increases maintenance overhead, and does not provide a single unified reporting view. Option C is wrong because Microsoft Sentinel is a SIEM/SOAR platform for detection and investigation of security events, not a preventive DLP control that blocks sharing of sensitive data in real time. Option D is wrong because Defender for Cloud Apps session policies apply to cloud app access via Conditional Access App Control (typically for unsanctioned or third-party SaaS apps), not to native Exchange and Teams DLP enforcement.

63
MCQmedium

A project team needs to create a shared workspace to manage tasks, share files, track project milestones, and communicate through conversation threads. They want a single app that integrates with other Microsoft 365 services like Outlook and Teams. Which Microsoft 365 app is best suited for this requirement?

A.Microsoft Planner
B.Microsoft To Do
C.Microsoft Project for the web
D.Microsoft Lists
AnswerA

Microsoft Planner is correct because it provides a shared Kanban-style task board within Microsoft 365, where team members can create buckets, assign tasks, set due dates, attach files, and add checklists. Each task includes a comments section for threaded, collaborative conversations, and the board offers real-time progress charts. Planner integrates natively as a tab in Microsoft Teams and syncs with Outlook tasks, making it purpose-built for lightweight team project management and milestone tracking.

Why this answer

Microsoft Planner is best suited because it provides a shared workspace with buckets and cards for task management, file attachments, milestone tracking via checklists and due dates, and conversation threads on each task. It integrates natively with Outlook for task visibility and with Teams via the Planner tab, meeting the requirement for a single app that combines these capabilities.

Exam trap

The trap here is that candidates confuse Microsoft To Do as a team tool because of its integration with Outlook tasks, but it lacks shared workspaces and team collaboration features, which are core to Planner.

How to eliminate wrong answers

Option B (Microsoft To Do) is wrong because it is a personal task management app focused on individual to-do lists and lacks shared workspaces, file sharing, milestone tracking, and conversation threads for team collaboration. Option C (Microsoft Project for the web) is wrong because it is designed for complex project portfolio management with Gantt charts and resource allocation, not for lightweight task management with conversation threads and file sharing in a single app. Option D (Microsoft Lists) is wrong because it is a data tracking app for creating custom lists (e.g., inventory, issues) and does not include built-in task management features like buckets, checklists, or conversation threads.

64
MCQmedium

A company deploys a custom application on a cloud platform where they manage the operating system and runtime environment, but the cloud provider manages the underlying physical infrastructure, storage, and networking. Which cloud service model is being used?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Function as a Service (FaaS)
AnswerA

IaaS provides virtualised compute where the customer manages the operating system, runtime, and applications, while the provider handles physical infrastructure, storage, and networking. The stem's split of responsibilities matches this model precisely, ruling out PaaS and SaaS.

Why this answer

The scenario describes a model where the customer manages the operating system and runtime environment, while the cloud provider handles the physical infrastructure, storage, and networking. This aligns precisely with Infrastructure as a Service (IaaS), as IaaS provides virtualized computing resources (e.g., virtual machines) where the customer retains control over the OS, middleware, and applications, but the provider manages the underlying hardware, hypervisor, and physical network.

Exam trap

The trap here is that candidates often confuse IaaS with PaaS because both involve deploying applications, but the key differentiator is who manages the OS and runtime—IaaS gives the customer full control over these layers, whereas PaaS abstracts them away entirely.

How to eliminate wrong answers

Option B (PaaS) is wrong because in PaaS, the provider manages not only the physical infrastructure but also the operating system and runtime environment, leaving the customer only to deploy and manage their application code and data. Option C (SaaS) is wrong because in SaaS, the provider manages the entire application stack, including the OS, runtime, and application, and the customer only uses the software via a web browser or API without any control over the underlying platform. Option D (FaaS) is wrong because FaaS is a subset of serverless computing where the customer only deploys individual functions (code snippets) and the provider dynamically manages the runtime and infrastructure, including the OS, scaling, and execution environment, which contradicts the customer managing the OS and runtime.

65
Multi-Selectmedium

Which of the following are included as part of Microsoft 365 E3 or E5 subscriptions? Choose all that apply. (There are four correct answers.)

Select 4 answers
.Microsoft Teams
.Exchange Online with 100 GB mailbox and unlimited storage via archiving
.Windows 10/11 Enterprise E3
.Microsoft Defender for Office 365
.Azure Active Directory Premium P1 only (not P2)
.Microsoft 365 Personal (single user) license

Why this answer

Microsoft 365 E3 and E5 subscriptions include Microsoft Teams as a core collaboration service, Exchange Online with a 100 GB mailbox and unlimited archive storage via auto-expanding archiving, Windows 10/11 Enterprise E3 for device management and security, and Microsoft Defender for Office 365 (in E5, and as an add-on for E3 but included in the E5 suite). These are standard components of the enterprise-grade plans.

Exam trap

Microsoft often tests the misconception that Azure AD Premium P1 is the only identity tier in E3/E5, but E5 actually includes P2, and that Microsoft 365 Personal is a valid enterprise license, when it is a consumer-only product.

66
Multi-Selecteasy

Which TWO apps are included in Microsoft Viva?

Select 2 answers
A.Microsoft Stream
B.Microsoft Teams
C.Viva Connections
D.Microsoft Power Automate
E.Viva Insights
AnswersC, E

Viva Connections is a core Microsoft Viva app that serves as a personalized gateway to company resources, news, tasks, and tools within Teams. It aggregates internal communications and common actions into a single, curated employee experience. This makes it directly part of the Viva suite, fulfilling the requirement for an app included in Microsoft Viva.

Why this answer

Viva Connections is a core app within Microsoft Viva that provides a personalized employee experience dashboard, integrating company news, resources, and tasks directly into Microsoft Teams. Viva Insights is another core app that offers data-driven privacy-protected insights to help employees improve productivity and well-being. Both are explicitly part of the Microsoft Viva employee experience platform.

Exam trap

The trap here is that candidates confuse the platform (Microsoft Teams) with the apps that run on it (Viva Connections, Viva Insights), leading them to select Teams as a Viva app instead of recognizing it as the host environment.

67
MCQhard

A legal team is preparing for litigation. They need to place a hold on all content (emails, documents, Teams messages) related to a specific project across the entire organization. The hold must prevent any deletion or modification of the content. Which Microsoft Purview solution should they use?

A.eDiscovery (Premium) with legal hold
B.Audit log search
C.Data Loss Prevention (DLP)
D.Retention policy
AnswerA

eDiscovery (Premium) is the Microsoft Purview solution built for legal investigations. It allows you to create a case, search across Exchange, SharePoint, OneDrive, Teams, and other workloads, and apply a legal hold that preserves all responsive content indefinitely until the hold is released by case attorneys. A legal hold overrides user deletions, auto-purge policies, and even mailbox retention cleanup processes, ensuring data stays intact for the duration of litigation. This directly satisfies the legal team's requirement to place a hold on potentially relevant data.

Why this answer

EDiscovery (Premium) with legal hold is the Microsoft Purview solution specifically designed to preserve content in-place for litigation. When a legal hold is applied to a case, it prevents deletion or modification of emails, documents, and Teams messages across the entire organization by placing a hold on the underlying Exchange Online mailboxes, SharePoint sites, and OneDrive accounts. This ensures that all content related to the project is immutable for the duration of the hold, meeting the legal team's requirement.

Exam trap

The trap here is that candidates often confuse retention policies (which are broad, time-based preservation rules) with legal holds (which are case-specific, litigation-driven holds that prevent any modification or deletion), leading them to incorrectly select Option D.

How to eliminate wrong answers

Option B (Audit log search) is wrong because it only records and allows searching of past activities (e.g., who accessed or deleted content) but does not prevent deletion or modification of content; it is a detective control, not a preventive one. Option C (Data Loss Prevention or DLP) is wrong because DLP policies are designed to identify, monitor, and protect sensitive data from being shared or leaked (e.g., via email or Teams), not to place a hold on content for litigation purposes. Option D (Retention policy) is wrong because while retention policies can preserve content for a specified period, they are typically applied based on content type or location and do not provide the granular, case-specific hold required for litigation; retention policies also allow modification of content unless combined with a retention label that blocks editing, which is not the same as a legal hold.

68
MCQeasy

Your organization is migrating from on-premises Exchange to Exchange Online. You need to ensure that email communications comply with regulatory requirements for retention. Which Microsoft 365 feature should you use to define retention periods for emails?

A.Microsoft Purview eDiscovery cases
B.Microsoft Purview retention policies
C.Exchange Online journaling
D.Exchange Online litigation hold
AnswerB

Microsoft Purview retention policies apply retention settings directly to Exchange Online mailboxes, satisfying the regulatory retention requirement. Unlike journaling or litigation hold, they define configurable retention periods and can retain or delete email after that period, with scope targeted by location or user.

Why this answer

Microsoft Purview retention policies are used to define how long email and other content are retained and when they are deleted, ensuring compliance with regulatory requirements. They apply at the workload level and can be scoped to specific users or locations, making them the correct tool for setting retention periods for Exchange Online emails.

Exam trap

MS-900 often tests the confusion between retention policies (define retention/deletion periods) and litigation hold (indefinite preservation for legal cases), leading candidates to pick litigation hold for regulatory retention.

How to eliminate wrong answers

Option A is wrong because eDiscovery cases are for identifying and collecting content for legal matters, not for defining retention periods. Option C is wrong because journaling captures copies of messages for archiving or third-party systems but does not itself define retention periods. Option D is wrong because litigation hold preserves content indefinitely for legal purposes but does not set customizable retention periods for regulatory compliance.

69
MCQhard

A company wants to ensure that all Microsoft 365 admin actions are recorded and searchable for at least 180 days. They also need to create custom alert rules to notify the security team when critical events occur, such as a user being added to the Global Admin role. Which Microsoft Purview solution should they use?

A.Microsoft Purview Audit
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Information Protection
D.Microsoft Purview eDiscovery
AnswerA

Microsoft Purview Audit is the correct solution because it provides a unified audit log of user and admin activities across Microsoft 365. Audit (Premium) extends the default 90-day retention to one year (and up to 10 years with an add-on license), supports custom alert policies for critical events such as privileged role changes or eDiscovery searches, and can be queried via Search-AuditLog or the Purview compliance portal. For recording all admin actions with alerting on high-impact operations, this is the intended native capability.

Why this answer

Microsoft Purview Audit (specifically Audit (Standard) or Audit (Premium)) is the correct solution because it records all admin actions from Microsoft 365 services into the unified audit log, retains those logs for at least 180 days (Audit Standard) or up to 10 years (Audit Premium), and allows you to create custom alert policies that trigger notifications when specific events like 'Added member to role' (e.g., Global Admin) occur. This directly meets the requirement for recording, searchability, and custom alerting on critical admin events.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Audit with Microsoft Purview eDiscovery, mistakenly thinking eDiscovery is used for monitoring admin actions, when in fact eDiscovery is solely for legal content search and holds, not for real-time auditing or alerting.

How to eliminate wrong answers

Option B (Microsoft Purview Data Loss Prevention) is wrong because DLP is designed to detect and prevent accidental sharing of sensitive data (e.g., credit card numbers) through policies, not to record admin actions or create alerts for role changes. Option C (Microsoft Purview Information Protection) is wrong because it focuses on classifying, labeling, and protecting data at rest and in transit (e.g., sensitivity labels, encryption), not on auditing admin activities or triggering alerts for security events. Option D (Microsoft Purview eDiscovery) is wrong because eDiscovery is used for legal investigations to search, hold, and export content from mailboxes, SharePoint, and Teams, not for real-time monitoring of admin actions or creating custom alert rules.

70
MCQmedium

A company needs to provide external partners with access to a specific SharePoint Online site without granting them access to the entire tenant. Which approach should the administrator use?

A.Configure SharePoint Online external sharing and invite partners as authenticated users
B.Create an Azure AD B2C tenant for partners
C.Use anonymous sharing links for the site
D.Add partners as guests in Microsoft Teams and share the site from Teams
AnswerA

Configuring SharePoint Online external sharing with authenticated guests is the appropriate Microsoft 365 pattern. This leverages Azure AD Business-to-Business (B2B) collaboration, generating a one-time invitation that creates a guest identity in the tenant. Administrators can then grant granular permissions to specific SharePoint sites, document libraries, or files, ensuring partners are authenticated and access is auditable. External sharing must be enabled at the tenant and site collection level, and partners receive the SharePoint site link to access resources.

Why this answer

SharePoint Online external sharing allows administrators to invite external users as authenticated guests who can access only the specific site they are invited to, without gaining access to the entire tenant. This is achieved by configuring site-level sharing settings to 'New and existing guests' and sending an invitation that requires the external partner to authenticate with a Microsoft account or Azure AD credentials, ensuring granular access control.

Exam trap

The trap here is that candidates often confuse Azure AD B2B (guest users) with Azure AD B2C, or assume that anonymous sharing is the simplest way to share externally, overlooking the authentication and access control requirements specified in the question.

How to eliminate wrong answers

Option B is wrong because creating an Azure AD B2C tenant is designed for consumer-facing identity management in custom applications, not for granting external partners access to SharePoint Online sites; it would introduce unnecessary complexity and does not integrate directly with SharePoint Online sharing. Option C is wrong because anonymous sharing links provide access to anyone with the link without authentication, which violates the requirement to grant access only to specific external partners and poses a security risk. Option D is wrong because adding partners as guests in Microsoft Teams and sharing the site from Teams still requires the partners to be invited as Azure AD guests, which grants them access to the entire tenant's Azure AD directory and potentially other resources, not just the specific SharePoint site.

71
MCQmedium

Wide World Importers has 300 users and is currently using Microsoft 365 Business Premium. The company is expanding and expects to hire 50 more employees next quarter. The CFO is concerned that Business Premium has a 300-user limit and wants to ensure a smooth transition without service interruption. The company needs to keep all current services (Exchange, SharePoint, Teams, OneDrive, Microsoft Defender for Business). They also want to add Microsoft Copilot for Microsoft 365 for all users. Which licensing strategy should they implement to accommodate the growth and add Copilot?

A.Keep Business Premium and purchase extra licenses for the new hires
B.Upgrade all users to Microsoft 365 E5
C.Switch to Microsoft 365 E3 and add Copilot licenses
D.Switch to Microsoft 365 F3 and add Copilot
AnswerC

Microsoft 365 E3 removes the 300-seat limit inherent to Business Premium, allowing seamless scaling beyond the current 300 users. E3 includes the essential services needed—desktop Office apps, Exchange Online, SharePoint, Teams, and security/compliance baselines—and supports the Microsoft 365 Copilot add-on for AI-powered assistance. By switching to E3 and appending Copilot licenses only for the users who need them, you align license cost with the required functionality and future growth, avoiding the excess expense of E5 while meeting the organization's exact requirements.

Why this answer

Microsoft 365 Business Premium has a strict 300-user limit, and Wide World Importers will exceed that with 350 users. Switching to Microsoft 365 E3 provides unlimited user licensing and includes all required services (Exchange, SharePoint, Teams, OneDrive, and Defender for Business). Microsoft Copilot for Microsoft 365 is available as an add-on for E3, allowing the company to add it for all users without service interruption.

Exam trap

The trap here is that candidates assume Business Premium can be scaled by purchasing extra licenses, but Microsoft enforces a hard 300-user limit, requiring a migration to an enterprise plan (E3 or E5) for larger organizations.

How to eliminate wrong answers

Option A is wrong because Business Premium cannot exceed 300 users; purchasing extra licenses is not possible due to the hard subscription cap. Option B is wrong because upgrading all users to E5 is unnecessary and more expensive; E5 includes advanced security and analytics features not required here, and Copilot is an add-on for E5 as well, not a cost-saving approach. Option D is wrong because Microsoft 365 F3 is designed for frontline workers with limited functionality (e.g., no full desktop Office apps, reduced mailbox size), and it does not include Microsoft Defender for Business, which the company needs to keep.

72
MCQhard

A multinational corporation needs to ensure that all emails containing a customer's passport number are automatically blocked from being sent externally. Additionally, the sending user should receive a policy tip explaining the block. Which Microsoft Purview solution should be configured?

A.Sensitivity labels
B.Data Loss Prevention (DLP) policies
C.Conditional Access policies
D.eDiscovery
AnswerB

DLP policies in Microsoft Purview inspect outbound email content for sensitive information types such as passport numbers, then enforce blocking of external sends. Policy tips are a native DLP action, displayed to the sender explaining the block, satisfying both the automatic prevention and user-notification requirements.

Why this answer

Data Loss Prevention (DLP) policies in Microsoft Purview are specifically designed to detect sensitive information, such as passport numbers, in emails and automatically block external transmission while displaying a policy tip to the user. This matches the requirement exactly, as DLP can inspect email content for sensitive data types and enforce actions like blocking and notifying the sender.

Exam trap

The trap here is that candidates often confuse sensitivity labels with DLP, assuming labels can block emails, but labels only apply protection after classification, whereas DLP actively inspects content and enforces rules like blocking and policy tips.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are used for classification and protection (e.g., encryption or visual markings) but do not natively block external email transmission based on content detection or provide policy tips. Option C is wrong because Conditional Access policies control access to resources based on user, device, or location conditions, not content inspection or blocking of outbound emails. Option D is wrong because eDiscovery is designed for searching and exporting content for legal or compliance investigations, not for real-time prevention of data exfiltration or user notifications.

73
MCQeasy

A sales team uses Microsoft 365 and wants to track customer interactions and manage leads from within Outlook. Which app should they use?

A.Microsoft Lists
B.Microsoft Bookings
C.Microsoft Forms
D.Microsoft Dynamics 365 Sales
AnswerD

Microsoft Dynamics 365 Sales is a full-featured CRM application that provides lead and opportunity management, sales pipelines, and customer activity tracking, all deeply integrated with Outlook. It enables sales teams to view communication history, schedule follow-ups, and manage accounts from a single interface, making it the correct choice for tracking customers in a structured, relationship-centric way.

Why this answer

Microsoft Dynamics 365 Sales is a customer relationship management (CRM) application that integrates directly with Outlook to track customer interactions, manage leads, and automate sales processes. It provides a unified interface within Outlook for viewing contact history, logging emails, and managing opportunities, making it the correct choice for the sales team's requirements.

Exam trap

The trap here is that candidates may confuse Microsoft Lists or Bookings as CRM tools due to their data-tracking or scheduling features, but they lack the lead management, pipeline tracking, and customer interaction history that Dynamics 365 Sales provides.

How to eliminate wrong answers

Option A is wrong because Microsoft Lists is a data-tracking app for creating and sharing lists (e.g., issue trackers, inventory) but lacks CRM capabilities like lead management or customer interaction tracking within Outlook. Option B is wrong because Microsoft Bookings is a scheduling and appointment management tool, not designed for tracking customer interactions or managing sales leads. Option C is wrong because Microsoft Forms is used for creating surveys, quizzes, and polls, and does not provide lead management or customer interaction tracking features.

74
MCQeasy

An administrator needs to ensure that only compliant devices can access Exchange Online. Which Microsoft Entra ID feature should they configure?

A.Privileged Identity Management
B.Conditional Access policies
C.Multi-Factor Authentication
D.Identity Protection
AnswerB

Conditional Access policies evaluate device compliance signals from Intune, enforcing grant controls that block or permit access to Exchange Online. This directly satisfies the stem's requirement that only compliant devices connect, since the policy checks the device's compliance state at sign-in and denies access when that condition is unmet.

Why this answer

Conditional Access policies in Microsoft Entra ID evaluate signals such as user, device compliance state, location, and app, and can grant or block access based on those conditions. To restrict Exchange Online access to compliant devices only, the admin creates a policy targeting Exchange Online that requires the device to be marked compliant (via Intune) or hybrid Azure AD joined. This is the specific Entra ID feature designed for signal-based, conditional access enforcement.

Exam trap

MS-900 often tests the distinction between authentication-strengthening features (MFA, Authenticator) and access-decision features (Conditional Access), so candidates who see 'compliant devices' and jump to MFA or Identity Protection pick the wrong control.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management governs just-in-time elevation of privileged roles, not device compliance gating for application access. Option C is wrong because Multi-Factor Authentication only adds a second authentication factor and says nothing about whether the device is managed or compliant. Option D is wrong because Identity Protection detects and scores risky users and sign-ins but does not itself enforce device compliance requirements for Exchange Online.

75
MCQmedium

During requirements gathering, an IT manager says the organization must see how many paid licenses are unused. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Available license count
B.Microsoft Stream
C.Microsoft Forms
D.Microsoft Whiteboard
AnswerA

Available license count reports how many purchased Microsoft 365 subscriptions remain unassigned, directly answering the manager's need to see unused paid licences. It draws on Microsoft Entra ID licence assignment data, satisfying the stem's visibility requirement without additional tooling.

Why this answer

The Available license count in the Microsoft 365 admin center allows administrators to view how many licenses have been purchased versus how many are assigned, directly revealing unused paid licenses. This is the core licensing management feature under 'Billing > Licenses' that tracks consumption and helps optimize costs.

Exam trap

The trap here is that candidates confuse productivity tools (Stream, Forms, Whiteboard) with administrative licensing features, assuming any Microsoft 365 app might show license counts, when only the admin center's license management section provides that data.

How to eliminate wrong answers

Option B (Microsoft Stream) is wrong because it is a video service for recording and sharing videos, not a licensing or admin tool for tracking license usage. Option C (Microsoft Forms) is wrong because it is a survey and data collection tool, unrelated to license management or admin reporting. Option D (Microsoft Whiteboard) is wrong because it is a collaborative digital canvas app, with no role in monitoring license assignments or availability.

Page 1 of 11

Page 2

All pages