Courseiva

Microsoft 365 Fundamentals MS-900 (MS-900) — Questions 676–750

794 questions total · 11pages · All types, answers revealed

Page 9

Page 10 of 11

Page 11
676
MCQeasy

A user wants to create a dashboard that visualizes sales data from multiple sources in real time. Which Microsoft 365 app should they use?

A.Excel
B.Microsoft Lists
C.Microsoft Forms
D.Power BI
AnswerD

Power BI connects to multiple data sources and refreshes datasets on schedules or via streaming, rendering live dashboards that update without manual intervention. This satisfies the real-time, multi-source visualisation requirement, whereas Excel and Power Apps lack native streaming dashboards across heterogeneous sources.

Why this answer

Power BI is Microsoft's business analytics service that enables users to create interactive dashboards and reports from multiple data sources, with real-time data refresh capabilities. It is designed for data visualization and business intelligence, making it the appropriate tool for this requirement.

Exam trap

MS-900 often tests the distinction between apps for data entry (Forms, Lists) and data visualization (Power BI), and candidates may confuse Excel's charting with Power BI's interactive dashboards.

How to eliminate wrong answers

Option A is wrong because Excel is a spreadsheet application primarily for data analysis and modeling, but it lacks the real-time dashboarding and multi-source connectivity of Power BI. Option B is wrong because Microsoft Lists is for tracking information and managing workflows, not for data visualization. Option C is wrong because Microsoft Forms is for creating surveys and quizzes, not for dashboarding.

677
MCQhard

A compliance officer needs to ensure that any document containing passport numbers automatically gets a 'Highly Confidential' label and is encrypted when saved in SharePoint. The labeling should occur without any user interaction. Which Microsoft Purview feature should they configure?

A.Auto-labeling policy for sensitivity labels
B.Manual labeling using the Office apps
C.Retention labels with DLP policy
D.Trainable classifiers
AnswerA

Auto-labeling policies for sensitivity labels are purpose-built to evaluate content against sensitive information types—such as passport numbers, credit card numbers, or other regex-based classifiers—and automatically apply the appropriate sensitivity label without any user intervention. In Microsoft 365, these policies can be run in simulation mode first to validate accuracy, then switched to enforced mode to consistently label and optionally encrypt content. This directly satisfies the compliance officer's requirement because labeling and protection are applied programmatically at rest or in motion, rather than depending on human action.

Why this answer

Auto-labeling policies in Microsoft Purview can automatically apply a sensitivity label (e.g., 'Highly Confidential') to documents containing passport numbers when saved in SharePoint, without any user interaction. This is achieved by configuring a policy that uses sensitive info types (e.g., 'Passport Number') to detect the data and then automatically apply the label and encryption. The labeling occurs at rest, triggered by document upload or modification, meeting the compliance officer's requirement for zero user intervention.

Exam trap

The trap here is that candidates often confuse retention labels (which manage lifecycle) with sensitivity labels (which enforce protection like encryption), leading them to choose Option C, or they mistakenly think trainable classifiers (Option D) can directly apply labels without an auto-labeling policy.

How to eliminate wrong answers

Option B is wrong because manual labeling requires users to actively select a label in Office apps, which contradicts the requirement for automatic labeling without user interaction. Option C is wrong because retention labels are designed for managing data retention and deletion, not for applying encryption or sensitivity classifications; DLP policies can enforce actions but do not automatically apply sensitivity labels with encryption. Option D is wrong because trainable classifiers are used to identify content based on machine learning patterns (e.g., contracts or resumes), but they do not directly apply sensitivity labels or encryption; they can be used as conditions in auto-labeling policies, but the feature itself is not the policy that applies the label.

678
MCQeasy

Your organization is implementing Microsoft Entra ID (formerly Azure AD) for identity management. Users report that they are prompted for multifactor authentication (MFA) every time they sign in, even from trusted devices. What should you configure to reduce MFA prompts while maintaining security?

A.Define trusted IP ranges in Named locations.
B.Configure self-service password reset (SSPR) to require MFA less often.
C.Use Microsoft Entra Privileged Identity Management (PIM) to grant MFA exemption.
D.Modify the Conditional Access policy to set session control 'Sign-in frequency' to a longer period.
AnswerD

Sign-in frequency controls how often users must reauthenticate, so lengthening the interval reduces repeated MFA prompts on trusted devices. This satisfies the requirement to cut prompts while Conditional Access still enforces MFA and device conditions.

Why this answer

The 'Sign-in frequency' session control in a Conditional Access policy defines how often users must reauthenticate. By extending this period (e.g., to 30 days) for trusted devices, MFA prompts are reduced while Conditional Access still enforces MFA when the session expires or risk conditions change. This directly addresses the symptom of repeated MFA prompts on trusted devices.

Exam trap

MS-900 often tests the confusion between authentication methods (MFA) and session controls (sign-in frequency), leading candidates to pick Named locations or SSPR when the question is really about reducing reauthentication prompts.

How to eliminate wrong answers

Option A is wrong because Named locations (trusted IP ranges) only influence Conditional Access policy targeting and risk evaluation; they do not by themselves control how often MFA is prompted, and without a session control the default sign-in frequency still applies. Option B is wrong because SSPR is for password reset and does not govern MFA prompt frequency during normal sign-ins. Option C is wrong because PIM is for just-in-time privileged role activation and does not provide a general MFA exemption mechanism for regular users.

679
Multi-Selectmedium

Which TWO Microsoft 365 services allow users to collaborate in real-time on the same document?

Select 2 answers
A.SharePoint Online
B.OneDrive for Business
C.Microsoft Viva
D.Yammer
E.Microsoft Teams
AnswersA, B

SharePoint Online is a cloud-based collaboration platform that stores documents in team libraries. Multiple users can co-author these documents in real time using Office for the web, desktop apps, or mobile apps, with version history and presence indicators. It enforces granular permissions and metadata, enabling organization-wide shared editing on a single source of truth.

Why this answer

SharePoint Online and OneDrive for Business both support real-time co-authoring, allowing multiple users to edit the same document simultaneously. This is enabled by the Office Online Server infrastructure and the use of WebDAV and REST APIs to synchronize changes in near real-time. Co-authoring works in Word, Excel, and PowerPoint files stored in these services, with conflict resolution handled by the application.

Exam trap

The trap here is that candidates often select Microsoft Teams as a correct answer because it is a collaboration tool, but Teams itself does not provide real-time document editing—it merely hosts files that are stored in SharePoint or OneDrive, where the actual co-authoring happens.

680
MCQhard

Your organization is deploying Microsoft 365 for a subsidiary with 1,000 users. The subsidiary needs to be billed separately. Which licensing model should you use?

A.Create separate subscriptions in the same tenant with different billing profiles
B.Create a separate Microsoft 365 tenant for the subsidiary
C.Use a Microsoft Enterprise Agreement for the entire organization
D.Create a single Microsoft 365 tenant with multiple subscriptions
AnswerA

Separate subscriptions within one tenant let you attach distinct billing profiles, so the subsidiary's 1,000 licences invoice independently while users stay in a single Microsoft Entra ID tenant. This satisfies the separate-billing constraint without provisioning a second tenant, which would duplicate identity management and complicate collaboration.

Why this answer

The correct approach is to create separate subscriptions within the same Microsoft 365 tenant, each with its own billing profile. This allows the subsidiary to be billed separately while still benefiting from centralized administration, shared services (like Azure AD), and unified management. Billing profiles in Microsoft 365 let you assign different payment methods and invoice recipients for different subscriptions, so the subsidiary can have its own billing without needing a separate tenant.

Exam trap

MS-900 often tests the misconception that separate billing requires a separate tenant, but Microsoft 365 supports multiple subscriptions with distinct billing profiles within a single tenant, allowing separate invoicing without sacrificing centralized management.

How to eliminate wrong answers

Option B is wrong because creating a separate tenant would isolate the subsidiary's users and resources, preventing centralized management and collaboration, and would require separate administration and duplication of services. Option C is wrong because a Microsoft Enterprise Agreement is a single agreement for the entire organization and does not provide separate billing for a subsidiary; it would bill the parent organization. Option D is wrong because while a single tenant with multiple subscriptions is part of the correct answer, it lacks the crucial element of different billing profiles that enable separate billing for the subsidiary.

681
MCQeasy

A sales team needs to collaborate on a document in real time and track changes. Which Microsoft 365 app is most suitable?

A.OneNote
B.Microsoft Forms
C.Word for the web
D.Microsoft Teams
AnswerC

Word for the web is the correct choice because it was purpose-built for document authoring and includes native real-time co-authoring, allowing multiple users to edit the same document simultaneously with visible presence indicators. It also provides track changes, comments, and version history, all of which are essential for a sales team iterating on a document together. Because it synchronizes through OneDrive or SharePoint, every collaborator immediately sees updates without conflict.

Why this answer

Word for the web (Option C) is the most suitable app because it is specifically designed for real-time co-authoring, allowing multiple users to edit a document simultaneously while tracking changes via the built-in version history and 'Track Changes' feature. Unlike desktop Word, the web version requires no manual sync and leverages Microsoft's Fluid Framework for seamless collaboration across devices.

Exam trap

The trap here is that candidates often confuse Microsoft Teams as a document collaboration tool because it displays files, but Teams relies on Word for the web for actual editing; the question specifically asks for the app that enables real-time editing and change tracking, which is Word for the web, not Teams.

How to eliminate wrong answers

Option A is wrong because OneNote is a digital notebook for free-form note-taking, not a word processor; it lacks structured document formatting and granular change tracking required for collaborative document editing. Option B is wrong because Microsoft Forms is a survey and quiz tool, not a document editor; it cannot support real-time co-authoring or track changes on a document. Option D is wrong because Microsoft Teams is a collaboration hub for chat, meetings, and file sharing, but its built-in document editing relies on Word for the web; Teams itself does not provide native document editing or change tracking capabilities.

682
Multi-Selecthard

Which THREE Microsoft 365 capabilities are included in Microsoft 365 E5 that are NOT included in Microsoft 365 E3?

Select 3 answers
A.Microsoft Purview Audit (Standard)
B.Microsoft Defender for Office 365 Plan 1
C.Microsoft Defender for Office 365 Plan 2
D.Microsoft Purview Advanced Audit
E.Microsoft Power BI Pro
AnswersC, D, E

Microsoft Defender for Office 365 Plan 2 is a true E5 component: it builds on Plan 1 by adding threat hunting in the advanced hunting schema, automated investigation and response (AIR) across email, Teams, and SharePoint, and full access to Threat Explorer's real-time detections. These capabilities are not bundled with E3, making Plan 2 the security-operations answer for this question. It is the choice that specifically represents E5's expanded threat-investigation posture.

Why this answer

Microsoft Defender for Office 365 Plan 2 is included in Microsoft 365 E5 but not in E3. It provides advanced threat protection capabilities such as automated investigation and response (AIR), threat hunting with Threat Explorer, and simulation training, which are not available in Plan 1 or E3.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Office 365 Plan 1 (included in E3) with Plan 2 (included in E5), or mistakenly think that Purview Audit (Standard) is an E5-only feature when it is actually available in both E3 and E5.

683
MCQmedium

A law firm uses Microsoft 365 and wants to ensure that only authorized users can access client files stored in SharePoint Online. They also need to track when these files are accessed. Which combination of features should they use?

A.Sensitivity labels with encryption and Microsoft Purview auditing.
B.Conditional Access policies and Privileged Identity Management (PIM).
C.eDiscovery cases and Content search.
D.Data Loss Prevention (DLP) policies and Microsoft Defender for Cloud Apps.
AnswerA

Sensitivity labels apply encryption via Azure Rights Management, allowing administrators to assign granular permissions like view-only or co-author to specific users or groups. Because the label attaches to the document, the encryption and permissions persist even if the file is copied or shared externally. Microsoft Purview auditing then captures every access attempt, including successful opens and denied tries, giving the law firm a detailed, searchable log of who did what.

Why this answer

Sensitivity labels with encryption enforce access control at the item level by encrypting SharePoint files so only authorized identities can open them, and Microsoft Purview auditing logs every access event for tracking. Together they satisfy both the access restriction and the access-tracking requirements.

Exam trap

MS-900 often tests the confusion between access control (Conditional Access/PIM) and data-level protection (sensitivity labels/encryption) — candidates pick Conditional Access thinking it restricts file access, but it only gates sign-in.

How to eliminate wrong answers

Option B is wrong because Conditional Access controls sign-in conditions and PIM governs privileged role activation — neither encrypts individual files nor provides file-level access auditing for SharePoint content. Option C is wrong because eDiscovery and Content Search are for legal hold and investigation, not for enforcing ongoing access control or routine access tracking. Option D is wrong because DLP prevents exfiltration of sensitive data and Defender for Cloud Apps monitors SaaS activity, but neither restricts who can open a specific encrypted file nor provides the granular per-file access audit trail the firm needs.

684
MCQmedium

A help desk lead is documenting the correct Microsoft 365 approach to estimate monthly Microsoft 365 subscription cost. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Microsoft Stream
C.Plan selection, user count, add-ons, billing term, and applicable discounts
D.Microsoft Forms
AnswerC

The total cost of a Microsoft 365 deployment relies directly on the selected plan tier (Business Basic through E5), the total number of licensed users, optional add-ons like Microsoft Copilot or extra Exchange Online storage, the billing cycle (monthly vs. annual), and eligible discounts such as Enterprise Agreement or nonprofit pricing. These factors combine to produce the per-user monthly or annual price, meaning any accurate cost calculation must consider them. This option is correct because it enumerates the actual commercial variables that Microsoft uses to price subscriptions, unlike an application name.

Why this answer

Estimating monthly Microsoft 365 subscription cost requires evaluating plan selection (e.g., Business Basic, Business Premium, Enterprise E3/E5), user count, add-ons (e.g., Microsoft 365 E5 Compliance, Power BI Pro), billing term (monthly vs. annual commitment), and applicable discounts (e.g., EA, CSP, or promotional offers). These factors directly determine the total monthly cost, making this the most relevant concept under the 'Describe Microsoft 365 pricing and support' domain.

Exam trap

The trap here is that candidates confuse individual Microsoft 365 services (like Whiteboard, Stream, or Forms) with the licensing and pricing concepts that actually determine subscription costs, leading them to select a service name rather than the correct cost-estimation factors.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a collaboration tool for real-time visual brainstorming, not a pricing or licensing concept. Option B is wrong because Microsoft Stream is a video service for enterprise content management, unrelated to subscription cost estimation. Option D is wrong because Microsoft Forms is a survey and quiz creation tool, with no role in calculating licensing costs.

685
MCQmedium

A company uses Microsoft 365 Business Premium and wants to enable secure remote access for employees using personal devices. Which Microsoft 365 app should they configure to enforce conditional access policies based on device compliance?

A.Microsoft Purview
B.Microsoft Intune
C.Microsoft Sentinel
D.Microsoft Defender for Cloud Apps
AnswerB

Microsoft Intune is the correct answer because it serves as the mobile device management (MDM) and mobile application management (MAM) service that enrolls devices, applies compliance policies (such as requiring encryption, OS versions, or jailbreak detection), and reports each device's compliance status to Microsoft Entra ID. Entra ID then uses that status as a condition in Conditional Access policies to grant or block access. Without Intune, there is no authoritative source for device health and no way to enforce access restrictions based on device compliance.

Why this answer

Microsoft Intune is the correct answer because it is the Microsoft 365 app that provides mobile device management (MDM) and mobile application management (MAM). It allows administrators to define device compliance policies (e.g., requiring encryption, PIN, or a minimum OS version) and integrate those policies with Microsoft Entra ID (formerly Azure AD) Conditional Access. When a user attempts to access corporate resources from a personal device, Conditional Access checks the device's compliance status reported by Intune before granting access.

Exam trap

The trap here is that candidates may confuse Microsoft Defender for Cloud Apps (a CASB) with device compliance enforcement, but Defender for Cloud Apps controls app access via session policies, not device health checks, which is Intune's role.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview is a suite of data governance, compliance, and risk management solutions (e.g., data loss prevention, eDiscovery, insider risk management); it does not enforce device compliance policies for remote access. Option C is wrong because Microsoft Sentinel is a cloud-native security information and event management (SIEM) and security orchestration automated response (SOAR) solution; it analyzes security logs and threats but does not manage device compliance or conditional access policies. Option D is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that provides visibility and control over cloud app usage, including session policies and threat detection, but it does not directly enforce device compliance-based conditional access; that function belongs to Intune and Entra ID.

686
MCQeasy

Your company wants to ensure that only managed and compliant devices can access Microsoft 365 resources. Which Microsoft 365 security feature enforces conditional access based on device compliance?

A.Microsoft Purview Compliance Manager
B.Microsoft Defender for Cloud Apps
C.Microsoft Sentinel
D.Microsoft Intune with Conditional Access in Microsoft Entra ID
AnswerD

Microsoft Intune evaluates device compliance and writes the result into Microsoft Entra ID, where Conditional Access policies grant or block access to Microsoft 365 resources based on that device state. This enforces the managed-and-compliant device requirement at authentication time.

Why this answer

Microsoft Intune manages device compliance policies (e.g., requiring encryption, antivirus, or a minimum OS version), and when integrated with Conditional Access in Microsoft Entra ID (formerly Azure AD), it enforces access decisions based on the device's compliance status. This ensures only managed and compliant devices can access Microsoft 365 resources, blocking or granting limited access to non-compliant devices.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps (a CASB) with the device compliance enforcement mechanism, but Conditional Access with Intune is the specific feature that enforces access based on device compliance, not Defender for Cloud Apps.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a compliance management solution for assessing and managing regulatory compliance (e.g., GDPR, ISO 27001), not for enforcing device-level conditional access. Option B is wrong because Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility and control over cloud app usage, but it does not natively enforce conditional access based on device compliance; it can integrate with Conditional Access but is not the primary enforcement point. Option C is wrong because Microsoft Sentinel is a Security Information and Event Management (SIEM) and Security Orchestration Automation and Response (SOAR) solution for threat detection and incident response, not for device compliance-based access control.

687
MCQmedium

A legal team is involved in a court case and needs to identify all emails and documents related to a specific project across the entire organization. They need to place these items on hold to prevent deletion or modification. Which Microsoft Purview solution should they use?

A.Data Loss Prevention (DLP)
B.eDiscovery (Standard)
C.Audit (Standard)
D.Communication Compliance
AnswerB

eDiscovery (Standard) is the native Microsoft 365 solution for legal discovery, enabling keyword and metadata searches across Exchange Online, SharePoint Online, OneDrive for Business, and Teams content. It supports placing non-custodial and custodial holds to preserve in-place content from deletion, and its export function packages the search results and metadata for review. This aligns exactly with the legal team's need to identify and preserve relevant information for the court case.

Why this answer

EDiscovery (Standard), is correct because it is specifically designed for legal discovery processes, allowing authorized users to search for content across Exchange Online, SharePoint Online, OneDrive for Business, and Teams. It can place a legal hold on identified items to preserve them from deletion or modification, which directly meets the legal team's requirement to identify and hold all emails and documents related to a specific project.

Exam trap

The trap here is that candidates often confuse eDiscovery with Audit, thinking that logging all activities (Audit) is sufficient for legal holds, but Audit only records events and cannot preserve or search content for litigation purposes.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) is focused on preventing sensitive data from being shared or leaked, not on searching for and preserving content for legal cases. Option C is wrong because Audit (Standard) provides logging and visibility into user and admin activities but does not include search capabilities or the ability to place holds on content. Option D is wrong because Communication Compliance is designed to detect and remediate inappropriate communications (e.g., harassment, insider trading) and does not provide the discovery or hold functionality needed for litigation.

688
MCQeasy

A startup wants to focus only on developing and deploying its application code without managing underlying servers or operating systems. Which cloud service model best fits this need?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.On-premises deployment
AnswerB

PaaS delivers a fully managed hosting environment that includes the operating system, language runtime, web server, and deployment tooling as part of the service. The startup only manages its application code and data, while the platform provider automatically handles patching, scaling, and infrastructure maintenance—exactly matching the requirement to focus purely on development and deployment.

Why this answer

Platform as a Service (PaaS) is the correct choice because it abstracts the underlying infrastructure, including servers, operating systems, and runtime environments, allowing the startup to focus solely on developing and deploying application code. With PaaS, the cloud provider manages the OS patching, hardware scaling, and middleware, while the customer only manages the application and data. This directly matches the requirement of not managing servers or operating systems.

Exam trap

The trap here is that candidates often confuse PaaS with IaaS, mistakenly thinking that IaaS also abstracts the OS, but IaaS only abstracts the hardware while leaving OS management to the customer.

How to eliminate wrong answers

Option A is wrong because Infrastructure as a Service (IaaS) provides virtualized servers, storage, and networking, but the customer is still responsible for managing the operating system, middleware, and runtime—contradicting the requirement to avoid managing servers or OS. Option C is wrong because Software as a Service (SaaS) delivers fully managed applications (e.g., Office 365, Salesforce) where the customer does not develop or deploy code, only consumes the software—this does not fit the need to develop and deploy custom application code. Option D is wrong because on-premises deployment requires the startup to own and manage all hardware, servers, and operating systems, which is the opposite of the stated goal of not managing underlying infrastructure.

689
MCQmedium

A compliance administrator needs to assess compliance posture against standards and improvement actions. Which Microsoft 365 capability is the best fit?

A.OneDrive sync client
B.Microsoft Teams live events
C.Microsoft Purview Compliance Manager
D.Microsoft Bookings
AnswerC

Microsoft Purview Compliance Manager provides a compliance score, tracks improvement actions, and maps controls to standards such as ISO 27001 and GDPR. This directly satisfies the administrator's need to assess posture against standards and prioritise remediation, unlike tools offering only alerts or configuration drift.

Why this answer

Microsoft Purview Compliance Manager is the correct choice because it provides a comprehensive dashboard for assessing an organization's compliance posture against standards like ISO 27001, NIST, and GDPR, and it offers actionable improvement actions with step-by-step guidance. It automatically tracks controls, assigns scores, and integrates with Microsoft Secure Score to help administrators prioritize remediation efforts.

Exam trap

The trap here is that candidates may confuse general security or productivity tools (like OneDrive or Teams) with compliance-specific capabilities, overlooking that Compliance Manager is the dedicated solution for assessing and improving compliance posture against standards.

How to eliminate wrong answers

Option A is wrong because the OneDrive sync client is a file synchronization tool that syncs local files with cloud storage; it has no compliance assessment or improvement action capabilities. Option B is wrong because Microsoft Teams live events is a broadcasting feature for large virtual meetings; it does not provide compliance posture evaluation or improvement actions. Option D is wrong because Microsoft Bookings is a scheduling and appointment management tool; it lacks any compliance assessment or remediation functionality.

690
MCQhard

A company wants to use AI-powered features to summarize chat conversations in Microsoft Teams. Which Microsoft 365 service provides this capability?

A.Microsoft 365 Copilot
B.Microsoft Forms
C.Microsoft Stream
D.Microsoft Viva Insights
AnswerA

Microsoft 365 Copilot is the correct answer because it integrates large language models with the Microsoft 365 Graph, enabling it to read and summarize Teams chat threads, meeting transcripts, and channel conversations. It uses grounded AI to generate concise summaries that cite specific messages, capturing decisions, action items, and key discussion points directly from the chat context.

Why this answer

Microsoft 365 Copilot is the correct answer because it integrates AI directly into Microsoft Teams to summarize chat conversations, leveraging large language models and the Microsoft Graph to process conversation context and generate concise summaries. This capability is part of Copilot's broader AI-powered features across Microsoft 365 apps, specifically designed for real-time productivity enhancements like chat summarization.

Exam trap

The trap here is that candidates may confuse Microsoft Viva Insights' personal analytics features (like meeting recaps) with AI-powered chat summarization, but Viva Insights does not provide generative AI summaries of chat conversations.

How to eliminate wrong answers

Option B (Microsoft Forms) is wrong because it is a survey and data collection tool, not designed for AI-powered chat summarization in Teams. Option C (Microsoft Stream) is wrong because it is a video hosting and sharing service, lacking the natural language processing capabilities needed to summarize text-based chat conversations. Option D (Microsoft Viva Insights) is wrong because it focuses on personal productivity and wellbeing analytics, such as meeting habits and focus time, not on summarizing chat conversations using AI.

691
MCQmedium

An e-commerce application runs in the cloud and automatically adjusts the number of virtual machines based on real-time traffic. When traffic spikes, more VMs are added; when traffic drops, VMs are removed. Which cloud computing characteristic does this behavior exemplify?

A.Rapid elasticity
B.Measured service
C.Resource pooling
D.On-demand self-service
AnswerA

Rapid elasticity is the cloud characteristic that lets an e-commerce application dynamically add or remove compute capacity—such as VM instances or containers—in near-real time as traffic spikes or falls. An autoscaling group monitors metrics like CPU utilization or request count and adjusts resources automatically, so the application always has enough capacity without manual intervention. This exactly matches the scenario's automatic scaling based on demand.

Why this answer

Rapid elasticity is the cloud characteristic that enables resources to scale out (add VMs) and scale in (remove VMs) automatically in response to real-time demand. In this e-commerce scenario, the application adjusts VM count based on traffic spikes and drops, which directly matches the definition of rapid elasticity as defined by NIST SP 800-145.

Exam trap

The trap here is that candidates confuse 'on-demand self-service' (manual provisioning by the user) with 'rapid elasticity' (automatic scaling), because both involve responding to demand, but only elasticity handles real-time, automated adjustments without user intervention.

How to eliminate wrong answers

Option B (Measured service) is wrong because measured service refers to the metering and billing of cloud resource usage (e.g., pay-per-hour or per-GB), not the automatic scaling of resources. Option C (Resource pooling) is wrong because resource pooling describes the multi-tenant model where physical and virtual resources are dynamically assigned to multiple customers, not the ability to scale out/in based on demand. Option D (On-demand self-service) is wrong because on-demand self-service allows a user to provision resources without human interaction, but it does not inherently include automatic scaling based on real-time traffic.

692
MCQhard

A healthcare organization is using Microsoft 365 and needs to ensure that patient data (protected health information) is not accidentally shared externally. They want to classify all documents containing medical terms and apply automatic encryption when shared outside the organization. Which two Microsoft Purview features should they combine? (Select TWO)

A.Sensitivity labels with auto-labeling based on trainable classifiers
B.Data Loss Prevention (DLP) policies with encryption action
C.Insider Risk Management policies
D.Communication Compliance policies
E.Microsoft Entra ID Conditional Access policies
AnswerA, B

Sensitivity labels with auto-labeling use trainable classifiers to detect medical terminology in documents, then apply encryption automatically. This satisfies the requirement to classify patient data and enforce protection when shared externally, since label-based encryption persists with the file and blocks unauthorised external access.

Why this answer

Sensitivity labels with auto-labeling based on trainable classifiers can automatically detect and classify documents containing medical terminology (PHI) without manual tagging. DLP policies with encryption actions then enforce protection by automatically encrypting those labeled documents when they are shared externally. Together they provide detection (classification) and enforcement (encryption) for PHI.

Exam trap

MS-900 often tests the confusion between classification (sensitivity labels/auto-labeling) and enforcement (DLP) — candidates must recognize that both are needed to detect PHI and encrypt it on external sharing.

How to eliminate wrong answers

Option C is wrong because Insider Risk Management detects risky user behavior (e.g., mass downloads) but does not classify documents or apply encryption on external sharing. Option D is wrong because Communication Compliance monitors communications for policy violations (e.g., harassment, regulatory) but does not classify or encrypt documents. Option E is wrong because Entra ID Conditional Access controls authentication and access conditions, not document classification or encryption.

693
MCQeasy

A service owner is comparing Microsoft 365 capabilities and needs to meter compute and storage usage for consumption-based billing. Cloud concept or benefit best matches this requirement?

A.Sensitivity labels
B.Microsoft Planner
C.Data Loss Prevention (DLP)
D.Measured service
AnswerD

Measured service tracks usage so customers can be charged according to consumption.

Why this answer

Measured service is a core cloud computing concept where resource usage (such as compute and storage) is metered, tracked, and billed based on actual consumption. This directly matches the service owner's requirement for consumption-based billing, as Microsoft 365 uses metering for services like Azure Active Directory and Exchange Online to enable pay-as-you-go models.

Exam trap

The trap here is that candidates confuse operational features (like DLP or sensitivity labels) with cloud service model characteristics, mistakenly thinking data protection tools are related to billing rather than recognizing measured service as a fundamental cloud attribute.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are a Microsoft Purview Information Protection feature used to classify and protect data based on sensitivity, not to meter compute or storage usage. Option B is wrong because Microsoft Planner is a task management and collaboration tool within Microsoft 365, not a billing or metering mechanism. Option C is wrong because Data Loss Prevention (DLP) is a security policy feature that prevents unauthorized sharing of sensitive data, not a consumption-based billing capability.

694
MCQeasy

A user wants to create a custom dashboard that displays key performance indicators from multiple data sources, such as Excel files and SharePoint lists. Which Microsoft 365 app should the user use?

A.Microsoft Excel
B.Microsoft Lists
C.Microsoft Power BI
D.Microsoft Forms
AnswerC

Power BI is Microsoft's dedicated business analytics service that connects to dozens of data sources, builds a semantic model with DAX measures, and publishes interactive, shareable dashboards in the Power BI service. Its features such as custom visuals, real-time refresh, and row-level security make it the appropriate tool for creating a custom dashboard that displays key metrics.

Why this answer

Microsoft Power BI is the correct choice because it is a business analytics service designed to connect to multiple data sources—including Excel files and SharePoint lists—and create interactive, custom dashboards with key performance indicators (KPIs). Unlike the other options, Power BI provides built-in data modeling, visualization, and real-time refresh capabilities, making it the only app in this list that fulfills the requirement for a multi-source KPI dashboard.

Exam trap

The trap here is that candidates often confuse Microsoft Lists or Excel as capable of creating dashboards because they can display data visually, but neither supports multi-source, interactive KPI dashboards with live data integration like Power BI does.

How to eliminate wrong answers

Option A is wrong because Microsoft Excel is a spreadsheet application for data entry and analysis, but it cannot natively create a live, multi-source dashboard that aggregates data from SharePoint lists and other sources without manual data import or complex add-ins. Option B is wrong because Microsoft Lists is a data tracking app for creating and managing lists (like SharePoint lists), but it lacks dashboarding and data visualization features to combine multiple data sources into a KPI dashboard. Option D is wrong because Microsoft Forms is a survey and form creation tool for collecting responses, not a dashboard or analytics tool; it cannot display KPIs from Excel or SharePoint lists.

695
MCQeasy

A tenant administrator is advising a department that wants to stop maintaining local file servers by using managed cloud storage. Cloud concept or benefit best matches this requirement?

A.Sensitivity labels
B.Reduced infrastructure maintenance
C.Microsoft Planner
D.Data Loss Prevention (DLP)
AnswerB

Reduced infrastructure maintenance is the correct benefit because moving file storage to Microsoft 365 transfers responsibility for server hardware, storage capacity, patching, backups, and physical security to Microsoft under the shared responsibility model. The tenant administrator no longer needs to provision, monitor, upgrade, or repair on-premises file servers, lowering operational overhead and hardware lifecycle costs. This is the primary infrastructure-related advantage when advising a department that wants to move away from maintaining its own storage servers.

Why this answer

Moving from on-premises file servers to managed cloud storage (e.g., Microsoft OneDrive, SharePoint Online, or Azure Files) eliminates the need for the department to handle hardware procurement, patching, backups, and physical maintenance. This directly aligns with the cloud benefit of reduced infrastructure maintenance, a core concept in the MS-900 exam's 'Describe cloud concepts' domain.

Exam trap

The trap here is that candidates confuse security or compliance features (like sensitivity labels or DLP) with cloud benefits, when the question specifically asks for the cloud concept or benefit that matches reducing local server maintenance.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are a Microsoft Purview Information Protection feature used to classify and protect data based on sensitivity, not a cloud concept or benefit for reducing infrastructure maintenance. Option C is wrong because Microsoft Planner is a task management and collaboration tool within Microsoft 365, unrelated to replacing local file servers or reducing maintenance overhead. Option D is wrong because Data Loss Prevention (DLP) is a security policy feature that helps prevent accidental sharing of sensitive data, not a cloud benefit that addresses the requirement of stopping local file server maintenance.

696
MCQmedium

A company currently uses Microsoft 365 Business Basic licenses for 80 users. They want to add the desktop versions of Office apps (Word, Excel, PowerPoint) without any additional security or compliance features. Which upgrade is the most cost-effective?

A.Upgrade to Microsoft 365 Business Standard
B.Upgrade to Microsoft 365 Business Premium
C.Upgrade to Microsoft 365 E3
D.Purchase Office 2019 Professional Plus standalone
AnswerA

Business Standard provides the full suite of desktop Office applications (Word, Excel, PowerPoint, Outlook) along with Exchange Online, SharePoint, Teams, and OneDrive, at a lower per-user monthly cost than Premium or E3. It directly meets the requirement for installed Office apps while preserving the cloud-based collaboration and management capabilities already present in Business Basic. It also includes the same core productivity and communication services without the additional security and device-management overhead that would be unnecessary for this scenario.

Why this answer

Microsoft 365 Business Standard is the most cost-effective upgrade from Business Basic because it includes the desktop versions of Office apps (Word, Excel, PowerPoint) without adding the advanced security and compliance features found in Business Premium or Enterprise plans. Business Standard provides the same core productivity tools at a lower per-user price point, making it the ideal choice when only desktop Office is needed.

Exam trap

The trap here is that candidates often choose Business Premium or E3 because they assume 'more features' means 'better value,' but the question explicitly states no additional security or compliance features are needed, making the lower-tier Business Standard the correct cost-effective choice.

How to eliminate wrong answers

Option B is wrong because Microsoft 365 Business Premium includes advanced security and compliance features (e.g., Microsoft Defender for Office 365, Azure Information Protection) that are not required, making it more expensive than necessary. Option C is wrong because Microsoft 365 E3 is an enterprise plan with additional capabilities like advanced eDiscovery, legal hold, and larger mailbox storage, which are overkill and significantly more costly for a small business needing only desktop Office. Option D is wrong because Office 2019 Professional Plus standalone is a non-subscription product that lacks cloud integration, updates, and support, and is not a direct upgrade path from Microsoft 365 Business Basic; it also does not include the same cloud services (e.g., Exchange Online, SharePoint) that the company already uses.

697
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to assign licenses automatically when users join a department group. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Microsoft Forms
C.Microsoft Whiteboard
D.Group-based licensing
AnswerD

Group-based licensing in Microsoft Entra ID assigns licences through group membership, so users automatically receive the appropriate Microsoft 365 licence when they join the department group and lose it on removal, meeting the automatic-assignment requirement without per-user scripting.

Why this answer

Group-based licensing in Microsoft 365 allows administrators to automatically assign or remove licenses based on Azure AD group membership. When a user joins a department group, the licensing assignment is triggered without manual intervention, making it the most relevant concept for automating license assignments in an adoption plan.

Exam trap

The trap here is that candidates confuse collaboration tools (Stream, Forms, Whiteboard) with licensing automation, failing to recognize that group-based licensing is the only option that directly addresses automatic license assignment via group membership.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video service for recording, sharing, and managing videos, not a licensing or group management tool. Option B is wrong because Microsoft Forms is a survey and quiz creation tool, unrelated to license automation. Option C is wrong because Microsoft Whiteboard is a digital canvas for collaboration, with no role in license assignment or group-based policies.

698
MCQeasy

A company wants to ensure that all outgoing emails containing sensitive financial data are encrypted automatically. The encryption should require the recipient to authenticate to read the message. Which Microsoft 365 solution should the administrator configure?

A.Microsoft Defender for Office 365
B.Microsoft Purview Message Encryption
C.Microsoft Purview Data Loss Prevention (DLP)
D.Microsoft Purview Insider Risk Management
AnswerB

Microsoft Purview Message Encryption, built on Azure Rights Management, encrypts outbound email content so that only authenticated recipients can decrypt it using a Microsoft account or a one-time passcode in a secure web portal. This capability can be fully automated via mail flow rules in Exchange Online, such as applying encryption when a DLP policy identifies sensitive financial data or when a message is sent to an external domain. The service ensures confidentiality for both data at rest and in transit, directly meeting the stated requirement.

Why this answer

Microsoft Purview Message Encryption (MPME) is the correct solution because it allows organizations to send encrypted emails that require recipients to authenticate (via a Microsoft account or a one-time passcode) before they can read the message. This directly meets the requirement for automatic encryption of outgoing emails with sensitive financial data and recipient authentication.

Exam trap

The trap here is that candidates often confuse Microsoft Purview Data Loss Prevention (DLP) with Message Encryption, but DLP only detects and blocks sensitive data, while Message Encryption provides the actual encryption and recipient authentication required by the question.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Office 365 is a security solution focused on threat protection (anti-phishing, anti-malware, safe attachments/links), not on encrypting outgoing emails with recipient authentication. Option C is wrong because Microsoft Purview Data Loss Prevention (DLP) can detect and block sensitive data in emails but does not natively encrypt messages with recipient authentication; it can trigger MPME policies but is not the encryption solution itself. Option D is wrong because Microsoft Purview Insider Risk Management is designed to detect and mitigate internal risks (e.g., data theft, policy violations) and does not provide email encryption or recipient authentication.

699
MCQmedium

A help desk lead is documenting the correct Microsoft 365 approach to web/mobile Office apps, business email, Teams, OneDrive, and SharePoint, but not desktop Office apps. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Microsoft Whiteboard
C.Microsoft Forms
D.Microsoft 365 Business Basic
AnswerD

Microsoft 365 Business Basic licenses web and mobile Office apps, business email, Teams, OneDrive and SharePoint, but excludes desktop Office applications. It matches the stated requirement precisely, unlike Business Standard or Premium, which include desktop apps.

Why this answer

The question describes a scenario requiring web/mobile Office apps, business email, Teams, OneDrive, and SharePoint—but explicitly excludes desktop Office apps. Microsoft 365 Business Basic is the correct plan because it includes all these services (Exchange Online for email, Teams, SharePoint Online, OneDrive for Business, and web/mobile versions of Office apps) without including the desktop Office applications, making it the most relevant licensing concept.

Exam trap

The trap here is that candidates often confuse Microsoft 365 Business Basic with Microsoft 365 Business Standard or Apps for Business, mistakenly thinking Basic includes desktop Office apps, or they incorrectly select a feature-specific tool (like Stream or Forms) instead of recognizing the question is about the correct licensing plan.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video service (for recording, sharing, and managing videos) and does not provide any of the core productivity services listed (email, Teams, OneDrive, SharePoint, or Office apps). Option B is wrong because Microsoft Whiteboard is a digital canvas collaboration tool, not a licensing plan that bundles the required services. Option C is wrong because Microsoft Forms is a survey and quiz creation tool, not a licensing plan that includes email, Teams, OneDrive, or SharePoint.

700
MCQmedium

An organization wants to automatically detect when a user attempts to share a document containing a customer's credit card number via email. The system should block the sharing and display a warning to the user. Which Microsoft Purview solution should they configure?

A.Data Loss Prevention (DLP)
B.Sensitivity labels
C.Retention policies
D.eDiscovery
AnswerA

Data Loss Prevention (DLP) uses Microsoft Purview's content analyzers and sensitive information types, such as credit card numbers or Social Security numbers, to scan documents in real time when a user attempts to share them through SharePoint, OneDrive, or Teams. When a match occurs, the DLP policy can block the sharing action, restrict access, or show a policy tip to the user. Because DLP inspects the actual file content and is integrated into the sharing workflow, it is the only solution that proactively detects and stops sensitive data from leaving the organization.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is designed to identify, monitor, and automatically protect sensitive information—such as credit card numbers—across Exchange Online, SharePoint, OneDrive, and Teams. When a user attempts to share a document containing a credit card number via email, DLP can inspect the content using built-in sensitive information types (e.g., Credit Card Number), block the email, and display a policy tip warning to the user. This matches the requirement exactly.

Exam trap

The trap here is that candidates confuse sensitivity labels with DLP, assuming labels can block sharing, when in fact labels only apply protection settings (encryption, markings) and rely on DLP or other controls to enforce blocking actions.

How to eliminate wrong answers

Option B (Sensitivity labels) is wrong because sensitivity labels classify and protect data by applying encryption or visual markings, but they do not automatically inspect content for specific patterns like credit card numbers or block sharing actions in real time. Option C (Retention policies) is wrong because retention policies are used to preserve or delete data after a specified period for compliance or legal reasons, not to prevent sharing or detect sensitive content. Option D (eDiscovery) is wrong because eDiscovery is a tool for searching and exporting content for legal or investigative purposes, not for real-time blocking or warning on outbound sharing.

701
MCQmedium

During requirements gathering, an IT manager says the organization must allow a junior admin to read tenant configuration without making changes. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Forms
B.Microsoft Whiteboard
C.Global Reader
D.Microsoft Stream
AnswerC

Global Reader is the appropriate choice because it provides broad read-only access to all Microsoft 365 admin centers, including user license assignments, security settings, and service health. This role allows an IT manager to gather requirements and audit the tenant without risking accidental changes, embodying least privilege. In contrast, a Global Administrator would have write access and is not needed for read-only visibility.

Why this answer

The Global Reader role in Microsoft Entra ID (formerly Azure AD) is specifically designed for read-only access to tenant configuration and settings across Microsoft 365 services. It allows a junior admin to view all administrative settings without the ability to make any changes, directly matching the requirement for read-only tenant configuration access.

Exam trap

The trap here is that candidates may confuse Global Reader with other read-only roles like Security Reader or Compliance Reader, but Global Reader is the only role that provides comprehensive read-only access to all tenant configuration settings across Microsoft 365.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and data collection application, not an admin role or licensing concept; it cannot provide read-only access to tenant configuration. Option B is wrong because Microsoft Whiteboard is a collaborative digital canvas tool, unrelated to administrative roles or tenant configuration access. Option D is wrong because Microsoft Stream is a video management service; it does not offer any administrative role for reading tenant configuration.

702
MCQeasy

A user is trying to access Microsoft 365 services but is prompted for additional verification via a phone call. Which Microsoft 365 feature is enforcing this?

A.Microsoft Entra ID
B.Microsoft Purview
C.Microsoft Defender XDR
D.Microsoft Intune
AnswerA

Microsoft Entra ID is the cloud identity and access management service that authenticates user credentials and issues security tokens for Microsoft 365. When a user attempts to access services, Entra ID validates their sign-in and can enforce multifactor authentication (MFA) and conditional access policies for additional verification. Thus, any authentication failure or prompt for MFA is handled at the Entra ID layer, making it the correct service for sign-in problems.

Why this answer

Microsoft Entra ID (formerly Azure AD) is the identity and access management service that enforces Conditional Access policies. When a user is prompted for additional verification via a phone call, it means a Conditional Access policy requiring multi-factor authentication (MFA) has been triggered. Entra ID evaluates the sign-in risk, user location, or device compliance and then invokes MFA through the Microsoft Authenticator service, which can deliver a phone call as one of the verification methods.

Exam trap

The trap here is that candidates often confuse Microsoft Defender XDR (a security monitoring tool) with identity security features, or they mistakenly think Intune or Purview handle authentication challenges, when in fact only Microsoft Entra ID (the identity provider) can enforce MFA prompts like phone call verification.

How to eliminate wrong answers

Option B (Microsoft Purview) is wrong because it is a compliance and data governance solution (e.g., data loss prevention, eDiscovery, retention policies), not an identity or authentication service; it does not enforce MFA prompts. Option C (Microsoft Defender XDR) is wrong because it is a unified security operations platform for threat detection and response across endpoints, email, and identities, but it does not directly enforce user authentication challenges like phone call verification. Option D (Microsoft Intune) is wrong because it is a mobile device management (MDM) and mobile application management (MAM) service that manages devices and apps, not authentication policies; while Intune can provide device compliance signals to Entra ID, the actual MFA enforcement is done by Entra ID, not Intune.

703
MCQeasy

Refer to the exhibit. An administrator is configuring a new Azure subscription with this ARM template snippet for Microsoft Defender for Cloud. What will be the immediate result?

A.All virtual machines will be automatically onboarded to Microsoft Defender for Endpoint
B.The subscription will be monitored for security issues and receive recommendations
C.The subscription will be protected by the highest security tier
D.No changes will occur until a security policy is manually created
AnswerB

When Microsoft Defender for Cloud is enabled on the subscription, it continuously assesses the environment against built-in security benchmarks and policy initiatives. The service surfaces misconfigurations, computes a secure score, and provides prioritized, actionable recommendations; this monitoring and guidance happen automatically after enabling Defender for Cloud, with no need for manual security policy creation to get basic CSPM value.

Why this answer

The ARM template snippet enables Microsoft Defender for Cloud at the subscription level. By default, this activates the foundational Cloud Security Posture Management (CSPM) capabilities, which continuously assess the subscription's resources against security baselines and generate actionable security recommendations. This does not automatically onboard VMs to Defender for Endpoint or apply the highest security tier; it simply enables monitoring and recommendations.

Exam trap

The trap here is that candidates confuse 'enabling Microsoft Defender for Cloud' with automatically activating premium features like Defender for Endpoint or the highest security tier, when in reality the default is only foundational CSPM with recommendations.

How to eliminate wrong answers

Option A is wrong because automatic onboarding to Microsoft Defender for Endpoint requires explicit integration via the Defender for Cloud 'Integrations' blade or a separate policy assignment, not just enabling the basic Defender for Cloud plan. Option C is wrong because the 'highest security tier' (e.g., Microsoft Defender for Servers Plan 2) is an optional paid add-on that must be explicitly selected; the default plan only provides foundational CSPM. Option D is wrong because enabling Defender for Cloud automatically applies the default security policy (built-in initiative) to the subscription, generating recommendations immediately without manual policy creation.

704
MCQmedium

A small business with 50 users currently has Microsoft 365 Business Basic subscriptions. They need the desktop versions of Office apps (Word, Excel, PowerPoint) for each user, in addition to the web and mobile versions they already have. What should they purchase for each user?

A.Microsoft 365 Business Standard license
B.Microsoft 365 F3 license
C.Office 365 E1 license
D.Microsoft 365 Business Voice add-on
AnswerA

Microsoft 365 Business Standard is a per-user subscription for up to 300 users that includes the installed Microsoft 365 Apps for business (Word, Excel, PowerPoint, Outlook, and others) alongside the same cloud services as Business Basic: Exchange Online, SharePoint, Teams, OneDrive, and Power Platform tools. This plan adds the full desktop Office clients to your existing business-grade collaboration stack, letting each user install Office on up to five devices. For a small business with 50 users who need desktop Office, this is the direct, cost-effective upgrade from Business Basic, as it precisely resolves the desktop app gap without adding unnecessary enterprise-level features.

Why this answer

Microsoft 365 Business Standard includes the desktop versions of Office apps (Word, Excel, PowerPoint) plus web and mobile access, making it the correct upgrade from Business Basic. The customer already has web and mobile apps via Business Basic, so adding Business Standard provides the missing desktop apps without over-provisioning.

Exam trap

The trap here is that candidates confuse 'Business Voice' as an Office app add-on rather than a PSTN telephony service, or they assume F3 or E1 include desktop apps because they are higher-tier enterprise plans, when in fact only Business Standard, Business Premium, and E3/E5 provide the full desktop Office suite.

How to eliminate wrong answers

Option B (Microsoft 365 F3 license) is wrong because F3 is a firstline worker plan that does not include the full desktop Office apps—it only provides web and mobile versions, which the customer already has. Option C (Office 365 E1 license) is wrong because E1 is an enterprise plan that also lacks desktop Office apps, offering only web and mobile access. Option D (Microsoft 365 Business Voice add-on) is wrong because it is a telephony add-on for calling features, not a license that includes desktop Office applications.

705
MCQmedium

A department head asks which Microsoft 365 option should be used to confirm whether a feature is included in a Microsoft 365 plan. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Official Microsoft plan comparison and licensing documentation
B.Microsoft Stream
C.Microsoft Whiteboard
D.Microsoft Forms
AnswerA

The official Microsoft plan comparison and licensing documentation is the authoritative source because it contains the detailed feature set and service availability for each Microsoft 365 subscription (e.g., Business Basic, Standard, E3, E5), including current licensing terms and limitations. Unlike productivity apps, this documentation is designed to answer exactly which services and capabilities are included, ensuring accurate procurement and administrative decisions.

Why this answer

The official Microsoft plan comparison and licensing documentation (available at the Microsoft 365 admin center and the Microsoft 365 for business or enterprise plans page) provides the definitive, up-to-date list of features included in each subscription tier. This is the primary resource for confirming feature availability, as it directly maps service names (e.g., Exchange Online, Teams, SharePoint) to specific licensing SKUs, such as Microsoft 365 Business Basic or Microsoft 365 E5.

Exam trap

The trap here is that candidates often mistake a popular Microsoft 365 application (like Stream, Whiteboard, or Forms) for a resource that can verify licensing, when in fact only the official plan comparison and licensing documentation provides authoritative feature-to-plan mapping.

How to eliminate wrong answers

Option B is wrong because Microsoft Stream is a video service within Microsoft 365, not a tool for verifying licensing or feature inclusion; it is a feature itself, not a reference source. Option C is wrong because Microsoft Whiteboard is a collaborative digital canvas application, not a licensing or support resource; it cannot be used to confirm plan inclusions. Option D is wrong because Microsoft Forms is a survey and data collection tool, not a licensing documentation or support mechanism; it has no role in determining feature availability under a plan.

706
MCQhard

Your company is experiencing high costs for maintaining an on-premises email server and wants to reduce IT management overhead. Which Microsoft 365 service provides enterprise-grade email with minimal infrastructure management?

A.Microsoft Entra ID
B.SharePoint Online
C.Microsoft Intune
D.Exchange Online
AnswerD

Exchange Online is the Microsoft 365 cloud-hosted email service, providing user mailboxes, calendars, contacts, and tasks through the Exchange Online architecture. It accepts, stores, and routes email messages, and includes built-in protection with anti-malware, anti-spam, and data loss prevention policies. Administrators manage Exchange Online through the Exchange admin center, and it is the correct service for email-related tasks in the Microsoft 365 ecosystem.

Why this answer

Exchange Online is Microsoft's cloud-hosted email service that eliminates the need for on-premises Exchange servers, providing enterprise-grade email with minimal infrastructure management. It includes built-in security, compliance, and high availability, and is part of most Microsoft 365 subscriptions. By moving to Exchange Online, the company offloads server maintenance, patching, and scaling to Microsoft, reducing IT overhead and costs.

Exam trap

MS-900 often tests the confusion between Microsoft 365 services that sound similar, such as Exchange Online (email) versus SharePoint Online (document collaboration) or Entra ID (identity), so candidates must map each service to its primary function.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID (formerly Azure AD) is an identity and access management service, not an email service; it handles authentication and authorization but does not provide mailboxes or email transport. Option B is wrong because SharePoint Online is a collaboration and document management platform, not an email service; it offers sites, libraries, and lists but no email hosting. Option C is wrong because Microsoft Intune is a mobile device and application management service, not an email service; it manages device compliance and app deployment but does not provide email functionality.

707
Multi-Selectmedium

Which THREE Microsoft 365 services are included in the Enterprise Mobility + Security (EMS) suite?

Select 3 answers
A.Microsoft Sentinel
B.Microsoft Purview
C.Microsoft Intune
D.Microsoft Entra ID
E.Microsoft Defender for Cloud Apps
AnswersC, D, E

Microsoft Intune is a cloud-based endpoint management service that provides mobile device management (MDM) and mobile application management (MAM) across Windows, iOS, Android, and macOS. As a core EMS pillar, Intune enforces device configuration, deploys applications, and integrates with conditional access to restrict access to compliant devices. Without Intune, EMS would lack its primary mechanism for controlling user device security and application availability.

Why this answer

Microsoft Intune is a core component of Enterprise Mobility + Security (EMS) because it provides cloud-based mobile device management (MDM) and mobile application management (MAM) using the OMA-DM protocol. It enforces conditional access policies and allows IT to manage devices and applications without requiring on-premises infrastructure, directly aligning with EMS's goal of securing and managing endpoints.

Exam trap

Microsoft often tests the misconception that Microsoft Purview or Microsoft Sentinel are part of EMS, when in fact EMS focuses exclusively on identity, endpoint management, and cloud app security, not on SIEM or data governance.

708
MCQmedium

An organization wants to provide employees with a personalized news feed and learning resources within Microsoft 365. Which app should they use?

A.Microsoft Teams
B.Microsoft Stream
C.Microsoft Viva
D.Microsoft SharePoint
AnswerC

Microsoft Viva is the correct answer because it is the employee experience platform (EXP) built on Microsoft 365, with Viva Connections delivering a personalized news feed and Viva Learning curating micro-learning content. Viva uses Microsoft Graph to aggregate signals from email, calendar, and collaboration data to tailor what each employee sees. It includes Viva Insights for productivity analytics and Viva Topics for knowledge discovery, making it the only option that directly provides the personalized news, insights, and learning resources described.

Why this answer

Microsoft Viva is the correct app because it is an employee experience platform that integrates with Microsoft 365 to deliver personalized news feeds via Viva Connections and curated learning resources through Viva Learning. Unlike other apps, Viva is specifically designed to aggregate content from across the organization and external sources into a single, tailored dashboard.

Exam trap

The trap here is that candidates often confuse Microsoft Viva with SharePoint or Teams, assuming those apps can natively provide personalized news and learning, but they lack the dedicated employee experience and AI-driven personalization that Viva is specifically built for.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is a collaboration hub for chat, meetings, and file sharing, not a dedicated app for personalized news feeds and learning resources. Option B is wrong because Microsoft Stream is a video service for recording, sharing, and managing videos, not for delivering personalized news or learning content. Option D is wrong because Microsoft SharePoint is a document management and collaboration platform that can host news and learning content, but it lacks the built-in personalization and aggregation features that Viva provides out of the box.

709
MCQeasy

A company wants to enable its sales team to automatically generate meeting summaries and action items from Microsoft Teams conversations. Which Microsoft 365 app or feature provides this capability?

A.Microsoft Viva Insights
B.Microsoft Stream
C.Microsoft Copilot for Microsoft 365
D.Microsoft Forms
AnswerC

Microsoft Copilot for Microsoft 365 uses the Microsoft Graph and large language models to summarise Teams meetings and extract action items automatically. It satisfies the requirement by generating recaps from conversation content within the sales team's existing Teams workflow.

Why this answer

Microsoft Copilot for Microsoft 365 is an AI-powered assistant integrated across Microsoft 365 apps, including Microsoft Teams. It can automatically generate meeting summaries, action items, and key discussion points from Teams conversations using advanced natural language processing. This capability is part of Copilot's intelligent recap and meeting productivity features, directly addressing the sales team's need.

Exam trap

MS-900 often tests the confusion between analytics tools like Viva Insights and AI assistants like Copilot, so candidates may mistakenly choose Viva Insights for meeting summarization.

How to eliminate wrong answers

Option A is wrong because Microsoft Viva Insights focuses on employee well-being, productivity analytics, and work patterns, not on generating meeting summaries or action items from conversations. Option B is wrong because Microsoft Stream is a video streaming service for uploading, sharing, and managing videos, not an AI tool for meeting summarization. Option D is wrong because Microsoft Forms is a survey and quiz creation tool, not designed for meeting content analysis or summarization.

710
MCQeasy

A small business with 10 users needs Microsoft 365 desktop versions of Office apps (Word, Excel, PowerPoint), business-grade email, and 1 TB of cloud storage per user. They do not need advanced security or compliance features. Which Microsoft 365 plan is the most cost-effective choice?

A.Microsoft 365 Business Basic
B.Microsoft 365 Business Standard
C.Microsoft 365 Business Premium
D.Microsoft 365 E3
AnswerB

Microsoft 365 Business Standard is the correct choice because it includes the fully installed desktop versions of Office apps (Word, Excel, PowerPoint, Outlook, and others) for each of the 10 users, alongside business-grade email (Exchange Online), 1 TB of OneDrive cloud storage per user, and Teams collaboration tools. This plan directly satisfies the stated need for desktop apps without adding unnecessary enterprise-level features.

Why this answer

Microsoft 365 Business Standard is the most cost-effective plan that includes desktop versions of Office apps (Word, Excel, PowerPoint), business-grade email (Exchange Online), and 1 TB of OneDrive cloud storage per user. Business Basic only provides web and mobile apps, not desktop versions. Business Premium adds advanced security and compliance features (e.g., Microsoft Defender for Office 365, Azure Information Protection) that the customer explicitly does not need.

E3 is an enterprise plan with similar features but at a higher per-user cost, making it overkill for a 10-user small business.

Exam trap

The trap here is that candidates often confuse 'business-grade email' with the need for desktop Office apps, and incorrectly choose Business Basic because it includes Exchange Online email, forgetting that Basic lacks the desktop Office client installation rights that the question explicitly requires.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Basic includes only web and mobile versions of Office apps, not the full desktop installable versions (Word, Excel, PowerPoint) required by the customer. Option C is wrong because Microsoft 365 Business Premium includes advanced security and compliance features (e.g., Microsoft Defender for Office 365, Azure Information Protection, Data Loss Prevention) that the customer explicitly does not need, making it more expensive than necessary. Option D is wrong because Microsoft 365 E3 is an enterprise-grade plan designed for larger organizations with advanced compliance, security, and analytics capabilities (e.g., eDiscovery, Litigation Hold, Advanced Audit), and its per-user cost is significantly higher than Business Standard, making it an overpriced choice for a small business with only 10 users and no advanced requirements.

711
MCQeasy

A company uses a cloud service where administrators can add or remove virtual machine instances through a web portal without contacting the provider. The provider bills only for the exact resources consumed. Which cloud computing characteristic does this scenario best demonstrate?

A.Rapid elasticity
B.On-demand self-service
C.Measured service
D.Resource pooling
AnswerB

On-demand self-service is a cloud characteristic that allows consumers to provision and manage computing resources (e.g., VMs, storage) independently through a self-service portal or API, without requiring human interaction with the service provider. The scenario directly illustrates this: an administrator adds or removes VMs via a web portal, and the organization only pays for what they consume (consumption-based billing). This is the primary characteristic being demonstrated because the focus is on the user's ability to unilaterally change resources, not on the underlying metering or resource sharing.

Why this answer

On-demand self-service is the cloud characteristic where consumers can provision capabilities, such as VM instances, automatically through a web portal or API without requiring human interaction with the service provider. The scenario explicitly states administrators add or remove VMs via a web portal without contacting the provider, which is the textbook definition of on-demand self-service per NIST SP 800-145.

Exam trap

MS-900 often tests the confusion between on-demand self-service (provisioning without provider interaction) and measured service (paying only for what is consumed), since both appear in the same billing-related scenario.

How to eliminate wrong answers

Option A is wrong because rapid elasticity refers to capabilities scaling outward and inward commensurate with demand, not the self-provisioning mechanism itself. Option C is wrong because measured service refers to the metering and billing of resource usage, which is a separate characteristic from the self-service provisioning action. Option D is wrong because resource pooling describes the provider's multi-tenant model where resources are pooled to serve multiple consumers, not the consumer's ability to self-provision.

712
Multi-Selectmedium

A sales team needs to manage leads, track customer interactions, and automate follow-up emails. They also want to collect customer feedback through surveys. Which two Microsoft 365 apps should they adopt for these requirements? (Choose two.)

Select 2 answers
A.Microsoft Dynamics 365 Sales
B.Microsoft Forms
C.Microsoft Stream
D.Microsoft Planner
AnswersA, B

Microsoft Dynamics 365 Sales is a purpose-built customer relationship management (CRM) application that uses a relational data model with entities such as Lead, Opportunity, Account, and Contact. It provides out-of-the-box business process flows for lead qualification and opportunity management, plus customizable workflows and Power Automate integration for automated follow-ups. Because it securely stores customer interaction history, tracks deal stages, and integrates with Outlook and Teams, it directly fulfills the sales team's requirement to manage leads and monitor customer interactions.

Why this answer

Microsoft Dynamics 365 Sales is a customer relationship management (CRM) application that provides lead management, customer interaction tracking, and automated follow-up email workflows. Microsoft Forms enables the creation and distribution of surveys to collect customer feedback, with responses automatically stored in Excel for analysis.

Exam trap

The trap here is that candidates may confuse Microsoft Stream or Planner as tools for customer interaction or feedback, overlooking that Dynamics 365 Sales is the dedicated CRM solution and Microsoft Forms is the specific survey tool within the Microsoft 365 ecosystem.

713
MCQmedium

Litware Inc. is a law firm that uses Microsoft 365 E5. They have a requirement to preserve all communications between attorneys and clients as legal hold for ongoing litigation. The legal team needs to identify and preserve all relevant emails and documents from specific users. The preservation should be indefinite until the hold is released. The IT team has enabled Litigation Hold for the mailboxes of the involved users. However, the legal team also needs to preserve documents in SharePoint Online and OneDrive for Business. What should you do to preserve the documents?

A.Create a retention policy in Microsoft Purview to retain all documents in the involved sites for 10 years.
B.Enable Litigation Hold for the users' OneDrive for Business accounts.
C.Create an eDiscovery case and place a hold on the relevant SharePoint sites and OneDrive accounts.
D.Apply a retention label to all documents in the involved sites.
AnswerC

An eDiscovery case in Microsoft Purview provides a legal hold that can be placed on SharePoint sites and OneDrive accounts, preserving all content in-place without a predefined expiration date. This hold retains current and previous versions of documents, as well as metadata and deleted items, until the hold is explicitly removed or the case is closed. Because the requirement is an indefinite hold pending litigation, a standard eDiscovery hold is the only mechanism among these options that fully preserves the relevant sites and accounts at both the site and item level.

Why this answer

A eDiscovery hold can be placed on specific sites and mailboxes for a specific case. Option A (Litigation Hold) only applies to mailboxes, not SharePoint/OneDrive. Option B (retention policy) is for time-based retention, not indefinite hold.

Option D (label) does not preserve content permanently.

714
MCQmedium

During a Microsoft 365 planning workshop, identify purchased Microsoft 365 licenses that are not assigned. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Forms
B.Microsoft Stream
C.Microsoft Whiteboard
D.Available licenses
AnswerD

Available licenses are the term used in the Microsoft 365 admin console to show the count of purchased user subscription licenses that have not yet been assigned to any user. During a planning workshop, identifying these is essential to understand spend, redistribute entitlements, or assign them to new employees; unassigned licenses still incur cost. In the admin center, the Licenses page breaks down total, assigned, and available counts per product, which is exactly what the scenario requires.

Why this answer

The question asks which concept is most relevant when identifying purchased but unassigned Microsoft 365 licenses. The 'Available licenses' count in the Microsoft 365 admin center directly shows the number of licenses purchased minus those assigned to users. This is a core licensing management concept, distinct from specific service apps like Forms, Stream, or Whiteboard.

Exam trap

The trap here is that candidates may confuse specific service applications (Forms, Stream, Whiteboard) with the licensing management concept, when the question is about identifying unassigned licenses, which is a core admin task tracked via the 'Available licenses' count.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and quiz application, not a licensing management tool; it does not show license counts or assignment status. Option B is wrong because Microsoft Stream is a video service for enterprise content, unrelated to tracking license inventory or assignments. Option C is wrong because Microsoft Whiteboard is a digital canvas collaboration app, not a licensing or admin console feature for viewing unassigned licenses.

715
MCQhard

An organization uses Microsoft 365 E5 and wants to automatically classify and protect sensitive documents stored in SharePoint Online based on content patterns (e.g., credit card numbers). They need to apply encryption and restrict access when such content is detected. Which Microsoft 365 service should they configure?

A.Microsoft Entra ID
B.Microsoft Purview Information Protection
C.Microsoft Sentinel
D.Microsoft Defender for Cloud Apps
AnswerB

Microsoft Purview Information Protection applies sensitivity labels with automatic classification based on content patterns such as credit card numbers, and labels can enforce encryption and access restrictions. Configuring it in SharePoint Online satisfies the detection, encryption and access-limiting requirements.

Why this answer

Microsoft Purview Information Protection (formerly Azure Information Protection) is the correct service because it provides content-based classification and protection for sensitive data. It uses trainable classifiers and sensitive information types (e.g., credit card numbers) to automatically apply encryption and restrict access via sensitivity labels in SharePoint Online.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps (a CASB) with data classification, but it lacks the native content scanning and encryption enforcement that Purview Information Protection provides.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID is an identity and access management service, not a content classification or protection engine; it cannot scan documents for patterns like credit card numbers. Option C is wrong because Microsoft Sentinel is a security information and event management (SIEM) solution for threat detection and response, not for data classification or encryption. Option D is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that provides visibility and control over cloud apps, but it does not natively classify or encrypt content based on patterns within SharePoint documents.

716
MCQeasy

A sales team uses Microsoft 365 and wants to automatically capture and store email signatures for all outgoing messages. Which Microsoft 365 app should the administrator configure?

A.Microsoft Teams
B.Microsoft Viva Insights
C.Microsoft SharePoint Online
D.Microsoft Exchange Online
AnswerD

Microsoft Exchange Online applies mail flow rules (transport rules) that append signatures and disclaimers to outgoing messages server-side, regardless of client. This satisfies the requirement to capture and store signatures automatically for all outgoing mail across the sales team, without relying on per-device Outlook configuration.

Why this answer

(Microsoft Exchange Online) is correct because email signatures are managed via Exchange mail flow rules or the Exchange admin center. Option A is wrong because Microsoft Teams is for collaboration, not email signatures. Option B is wrong because Microsoft Viva Insights focuses on productivity analytics.

Option C is wrong because Microsoft SharePoint Online is for document management.

Exam trap

Candidates may confuse Microsoft Teams with Exchange Online for email features, but Teams is not involved in email signature management.

717
MCQhard

A compliance officer needs to ensure that all user activities related to sensitive data in Microsoft 365 are recorded and available for forensic investigation. They require detailed logs of who accessed specific files in SharePoint Online, including attempts to access files that were blocked by DLP policies. Which solution should they enable?

A.Microsoft 365 Audit Log
B.Microsoft Defender for Cloud Apps
C.Microsoft Purview Activity Explorer
D.Microsoft 365 Defender
AnswerA

The Microsoft 365 Audit Log is the authoritative, organization-wide record of every user and admin action across Exchange Online, SharePoint, OneDrive, Azure AD, and other workloads. It captures critical forensics details, including actor, action, timestamp, client IP, and affected item, so it fully satisfies a compliance officer's requirement for a comprehensive audit trail. Unified audit logging is available in the Purview compliance portal and can be queried with Search-UnifiedAuditLog, making it the correct foundational solution.

Why this answer

Microsoft 365 Audit Log (Unified Audit Log) is the correct solution because it captures detailed records of user activities, including file access in SharePoint Online and blocked DLP policy actions. These logs are retained for forensic investigation and can be searched via the Microsoft 365 Purview compliance portal or accessed programmatically.

Exam trap

The trap here is that candidates confuse the real-time monitoring capabilities of Activity Explorer or Defender for Cloud Apps with the historical, searchable audit trail required for forensic investigation, mistakenly thinking those tools replace the Unified Audit Log.

How to eliminate wrong answers

Option B (Microsoft Defender for Cloud Apps) is wrong because it focuses on cloud app discovery, session controls, and anomaly detection, not on providing a comprehensive, searchable audit log of all user activities for forensic investigation. Option C (Microsoft Purview Activity Explorer) is wrong because it shows real-time activity insights and DLP rule matches, but it does not retain historical logs for extended forensic analysis; it relies on the underlying audit log for data. Option D (Microsoft 365 Defender) is wrong because it is a threat protection suite (including Microsoft Defender for Endpoint, Office 365, Identity, and Cloud Apps) designed for detecting and responding to security incidents, not for recording and retaining detailed user activity logs for compliance auditing.

718
MCQmedium

A compliance administrator needs to automatically detect when employees share documents containing a customer's credit card number via email and block such sharing before the email is sent. Which Microsoft Purview solution should they configure?

A.Data Loss Prevention (DLP)
B.Information Rights Management (IRM)
C.Sensitivity labels
D.Microsoft Defender for Office 365 (ATP)
AnswerA

Data Loss Prevention (DLP) policies in Microsoft 365 compliance automatically scan outbound email messages and attachments for sensitive information types, such as credit card numbers, and can block the message at the transport layer. A DLP rule can trigger a block action, preventing the sender from delivering the message, and even include a policy tip to notify the user. This is the only option here that directly inspects message content for defined sensitive patterns and enforces an outbound send block.

Why this answer

Data Loss Prevention (DLP) is the correct solution because it is specifically designed to automatically detect sensitive data, such as credit card numbers, in transit (e.g., email) and enforce policy actions like blocking the email before it is sent. DLP uses deep content analysis, including pattern matching against predefined sensitive information types (e.g., credit card number regex), to inspect email bodies and attachments in real time within Exchange Online.

Exam trap

The trap here is that candidates often confuse Information Rights Management (IRM) with DLP because both involve protecting sensitive data, but IRM controls access after sending while DLP prevents the send action itself.

How to eliminate wrong answers

Option B is wrong because Information Rights Management (IRM) protects content after it is sent by encrypting and restricting permissions (e.g., prevent forwarding or printing), but it does not automatically detect or block sensitive data before transmission. Option C is wrong because sensitivity labels are used to classify and protect data based on manual or automatic labeling, but they do not natively scan for specific patterns like credit card numbers or block emails in transit; DLP policies can leverage labels, but the detection and blocking action is DLP's function. Option D is wrong because Microsoft Defender for Office 365 (formerly ATP) focuses on threat protection against malware, phishing, and malicious links, not on preventing accidental sharing of sensitive data like credit card numbers via content inspection.

719
Multi-Selectmedium

A retail company is evaluating Microsoft 365 for a new subsidiary. Management wants to understand which characteristics are fundamental to cloud computing as described by the National Institute of Standards and Technology (NIST). Which two characteristics should the company include? (Choose two.)

Select 2 answers
A.Mandatory multi-year contracts
B.On-demand self-service
C.Dedicated physical hardware per tenant
D.Broad network access
E.Unlimited storage at no cost
AnswersB, D

On-demand self-service means consumers can provision computing capabilities, such as services and storage, automatically without requiring human interaction with the provider. NIST lists this as an essential cloud characteristic. For the retail subsidiary, this means administrators can enable Microsoft 365 services themselves rather than waiting for manual provider provisioning, matching the NIST definition.

Why this answer

NIST defines five essential cloud characteristics: on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service. On-demand self-service and broad network access are both on that list. Dedicated hardware per tenant, unlimited free storage, and mandatory multi-year contracts are commercial or hosting concepts that are not part of the NIST definition, so they should not be included.

Exam trap

The trap here is mixing commercial licensing terms or hosting models into the NIST essential characteristics of cloud computing.

720
MCQeasy

Your organization uses Microsoft 365 Business Premium. You need to protect users from phishing attacks by blocking malicious links in real-time when they click them in emails. Which feature provides this capability?

A.Microsoft Defender for Office 365 Safe Attachments
B.Microsoft Defender for Office 365 Safe Links
C.Exchange Online Protection (EOP) anti-spam policy
D.Microsoft Defender XDR
AnswerB

Safe Links rewrites URLs in email and checks them against Microsoft's threat intelligence at click time, blocking malicious destinations in real time. This directly satisfies the requirement to protect Microsoft 365 Business Premium users from phishing links when they click them in messages.

Why this answer

Safe Links in Microsoft Defender for Office 365 provides real-time protection by checking links in emails and documents at the time of click. It blocks malicious links and can also detonate URLs to analyze for phishing. This directly matches the requirement to block malicious links in real-time when clicked.

Exam trap

The trap is confusing Safe Links with Safe Attachments; candidates may pick Safe Attachments because it also protects against malicious content, but the question specifically asks about links clicked in real-time.

How to eliminate wrong answers

Option A is wrong because Safe Attachments scans attachments, not links. Option C is wrong because EOP anti-spam policies filter spam but do not provide real-time link blocking at click time. Option D is wrong because Microsoft Defender XDR is a broader suite that includes Safe Links, but the specific feature is Safe Links.

721
MCQhard

A company wants to automate a business process where an approval request is sent to a manager when a new employee is added to the HR system. The HR system is a custom list in SharePoint Online. The process should run without any custom code. Which Microsoft 365 tool should they use to create this automation?

A.Microsoft Power Automate
B.Microsoft Power Apps
C.Microsoft SharePoint Designer
D.Microsoft Visio
AnswerA

Microsoft Power Automate is the correct choice because it is a cloud-based workflow service within the Power Platform designed specifically for automating business processes. It offers pre-built connectors for SharePoint, such as the 'When an item is created or modified' trigger, and an Approvals connector that can route an approval request to specific users or groups with customizable conditions and templates. This makes it the ideal tool to listen for SharePoint list changes and initiate an interactive approval workflow without requiring custom code.

Why this answer

Microsoft Power Automate is the correct tool because it is designed specifically for creating automated workflows between apps and services without custom code. In this scenario, Power Automate can use a trigger (e.g., 'When an item is created or modified' in SharePoint) to send an approval request to a manager, fully meeting the requirement for a no-code solution.

Exam trap

The trap here is that candidates may confuse Microsoft Power Apps (for building apps) with Power Automate (for workflows), or mistakenly think SharePoint Designer is still a viable no-code option, when in fact it is deprecated and requires custom code.

How to eliminate wrong answers

Option B (Microsoft Power Apps) is wrong because Power Apps is a low-code platform for building custom applications, not for automating workflows or approval processes. Option C (Microsoft SharePoint Designer) is wrong because SharePoint Designer is a legacy tool for customizing SharePoint sites and workflows, but it requires custom code and is deprecated in favor of Power Automate. Option D (Microsoft Visio) is wrong because Visio is a diagramming and visualization tool for creating process maps, not for executing automated workflows.

722
MCQmedium

A tenant administrator is advising a department that wants to find who made Microsoft 365 admin changes and when. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Microsoft Whiteboard
C.Microsoft Forms
D.Microsoft Purview Audit
AnswerD

Microsoft Purview Audit is the correct choice because it provides a unified audited log of user and administrative activities across Microsoft 365 services. It captures the identity, timestamp, and details of each action, enabling a tenant administrator to search the audit log for specific admin changes and compliance investigations. This directly meets the need to show administrator activities and timing.

Why this answer

Microsoft Purview Audit (formerly Office 365 Audit) is the correct answer because it provides a unified audit log that records every admin and user action across Microsoft 365 services, including who made a change, what change was made, and when it occurred. This directly meets the department's requirement to track Microsoft 365 admin changes. The other options are productivity tools that do not offer audit logging or change tracking capabilities.

Exam trap

The trap here is that candidates may confuse Microsoft Purview Audit with other Microsoft 365 services that have 'audit' in their name or assume that productivity tools like Forms or Stream include administrative logging, when in fact only Purview Audit provides the centralized, searchable audit log required for tracking admin changes.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video management and sharing service, not a tool for auditing admin changes. Option B is wrong because Microsoft Whiteboard is a digital canvas for collaboration, with no audit or change-tracking functionality. Option C is wrong because Microsoft Forms is a survey and quiz creation tool, lacking any audit logging features.

723
MCQmedium

During a Microsoft 365 planning workshop, understand which security tasks Microsoft handles and which remain with the customer. Cloud concept or benefit best matches this requirement?

A.Microsoft Planner
B.Data Loss Prevention (DLP)
C.Sensitivity labels
D.Shared responsibility model
AnswerD

The shared responsibility model is the foundational cloud computing principle that describes how the service provider is responsible for the security of the cloud, while the customer is responsible for security in the cloud. For Microsoft 365 as a SaaS offering, Microsoft handles infrastructure, platform, and most application security, but the customer remains accountable for identity management, user access, data classification, and compliance decisions. This model directly delineates the division of duties that organizations must understand when planning a Microsoft 365 deployment, making it the correct answer.

Why this answer

The shared responsibility model defines which security tasks are managed by Microsoft (e.g., physical security, hypervisor patching) and which remain with the customer (e.g., user access, data classification). This directly matches the requirement to understand task ownership during a planning workshop. Options like Microsoft Planner, DLP, and sensitivity labels are specific features, not the overarching cloud concept that clarifies responsibility boundaries.

Exam trap

The trap here is that candidates confuse specific security features (like DLP or sensitivity labels) with the overarching shared responsibility model, which is the foundational cloud concept that defines who owns each security task.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a project management tool for task assignment and scheduling, not a security concept or model for defining responsibility boundaries. Option B is wrong because Data Loss Prevention (DLP) is a specific security policy feature that helps prevent data leaks, but it does not explain which security tasks Microsoft handles versus the customer. Option C is wrong because sensitivity labels are a classification and protection mechanism for data, not a model that delineates shared security responsibilities between provider and tenant.

724
MCQmedium

A company wants to automatically send an email notification to a manager when a new request is submitted in a SharePoint list. The process should require no custom code. Which Microsoft 365 tool should they use?

A.Power Automate
B.SharePoint Designer
C.Power Apps
D.Microsoft Lists
AnswerA

Power Automate is the correct answer because it is a cloud-based automation service specifically designed to connect apps and services. With pre-built templates and triggers such as 'When a new item is created in SharePoint,' it can instantly fire a condition-based email notification, requiring no code. Its robust connector library includes Outlook and Microsoft 365, enabling automated manager alerts directly from list or library events. Authoring a flow in Power Automate takes minutes and is the standard modern solution for this task.

Why this answer

Power Automate is the correct choice because it provides a no-code, trigger-based workflow engine that can automatically send an email when a new item is added to a SharePoint list. It integrates directly with SharePoint and Outlook, requiring no custom code or developer intervention.

Exam trap

The trap here is that candidates may confuse Microsoft Lists (a data storage tool) with Power Automate (the automation engine), or mistakenly think SharePoint Designer is still the standard for no-code workflows, when in fact Power Automate is the modern, recommended solution for this scenario.

How to eliminate wrong answers

Option B is wrong because SharePoint Designer is a legacy tool that requires custom workflows (often using SharePoint 2010/2013 workflow types) and is deprecated for new solutions; it also demands more technical overhead and is not recommended for modern no-code automation. Option C is wrong because Power Apps is a low-code platform for building custom applications and user interfaces, not for automating email notifications based on list events. Option D is wrong because Microsoft Lists is a data management and tracking application that does not include built-in automation capabilities; it relies on Power Automate for any workflow or notification logic.

725
MCQmedium

A manager wants to set up a daily automated reminder email to employees who have not completed a mandatory training video in Microsoft Stream. The reminder should stop once the training is marked complete. Which Microsoft 365 tool should the manager use?

A.Power Automate
B.Microsoft Forms
C.SharePoint Designer
D.Viva Learning
AnswerA

Power Automate is the correct solution because it uses a recurrence trigger to start a cloud flow daily. That flow can query training completion status via Microsoft Graph or a SharePoint list, apply a conditional branch to filter only employees who haven't completed, and then send personalized reminder emails through Outlook. Crucially, you can add a 'terminate' or condition-based logic to stop the flow after all employees finish, and schedule maintenance is built into the platform's licensing.

Why this answer

Power Automate is the correct tool because it can create an automated workflow that queries Microsoft Stream (or a connected system like SharePoint or a custom list) for employees who have not completed the training, sends a daily reminder email, and stops when the training status changes to 'complete'. This leverages triggers like 'Recurrence' and conditions based on data from Stream or a related data source.

Exam trap

The trap here is that candidates often confuse Viva Learning (a learning portal) with an automation tool, assuming it can send reminders, but Viva Learning lacks workflow triggers and actions for automated email scheduling.

How to eliminate wrong answers

Option B is wrong because Microsoft Forms is a survey and data collection tool, not an automation engine; it cannot send automated reminders or check completion status. Option C is wrong because SharePoint Designer is a legacy tool for SharePoint 2010/2013 workflows, not designed for Microsoft 365 cloud automation or integration with Stream. Option D is wrong because Viva Learning is a learning management interface for accessing and assigning training content, but it lacks native workflow automation to send recurring reminders based on completion status.

726
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to let users report suspicious phishing messages from Outlook for investigation. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Defender for Office 365 user submissions
B.Microsoft Planner
C.Microsoft Forms
D.Microsoft Stream
AnswerA

Microsoft Defender for Office 365 user submissions is the correct service because it provides a supported workflow for end users to report suspicious emails directly from Outlook or Outlook on the web. These submissions are surfaced in the Microsoft 365 Defender portal, where admins can review them, send them to Microsoft for detonation and analysis, or use them to update tenant policies. This capability aligns with a security element in an adoption plan by actively involving users in threat reporting and incident response workflows.

Why this answer

Microsoft Defender for Office 365 user submissions (Option A) is the correct capability because it allows users to report suspicious phishing messages directly from Outlook, which are then routed to the Microsoft 365 Defender portal for investigation and analysis. This feature integrates with the built-in Report Message or Report Phishing add-ins, enabling security teams to review and act on user-reported threats within the unified security operations framework.

Exam trap

The trap here is that candidates may confuse Microsoft Forms (a generic survey tool) with a legitimate reporting mechanism, overlooking that Microsoft 365 provides a dedicated, integrated security solution (Defender for Office 365) for phishing submissions.

How to eliminate wrong answers

Option B (Microsoft Planner) is wrong because it is a task management and project planning tool, not a security or compliance feature for reporting phishing messages. Option C (Microsoft Forms) is wrong because it is a survey and data collection tool that lacks the automated integration with Microsoft 365 Defender required for phishing investigation workflows. Option D (Microsoft Stream) is wrong because it is a video sharing and management platform, with no capability to process or analyze email security threats.

727
MCQhard

Refer to the exhibit. You are configuring a Microsoft Purview Data Loss Prevention (DLP) policy in the Microsoft 365 compliance portal. The policy is intended to block access to files containing credit card numbers when accessed from outside the organization. However, users report that the policy is not blocking access. What is the most likely reason?

A.The policy is not assigned to any locations.
B.The policy mode is set to 'advanced' which is not a valid mode; it should be 'enforce' or 'test'.
C.The confidence level is set to 'high' which is too restrictive.
D.The sensitive information type is incorrect.
AnswerB

The mode column displays 'advanced', which is not a valid Microsoft Purview DLP policy mode. Valid modes are 'Enforce' and 'Test'; when a policy is in Enforce mode it applies protective actions, while Test mode lets you observe matches without blocking. An unhandled value such as 'advanced' means the policy is not validly configured and will not enforce, so this is the actual cause.

Why this answer

The policy mode 'advanced' is not a valid mode in Microsoft Purview DLP. The valid modes are 'enforce' (to actively block actions) and 'test' (to simulate policy effects without blocking). Setting the mode to an invalid value like 'advanced' would prevent the policy from enforcing any restrictions, explaining why access is not being blocked.

Exam trap

The trap here is that candidates may confuse policy mode with other settings like confidence level or location assignment, or assume 'advanced' is a valid mode similar to other Microsoft 365 features (e.g., advanced audit), when in fact DLP only supports 'enforce' and 'test' modes.

How to eliminate wrong answers

Option A is wrong because if the policy were not assigned to any locations, it would not apply at all, but users report the policy is configured and expected to work, implying it is assigned; the issue is with enforcement mode. Option C is wrong because setting the confidence level to 'high' makes the policy more restrictive (requiring stronger evidence of a credit card number), which would reduce false positives but not prevent blocking when a match occurs; it would not cause a failure to block. Option D is wrong because if the sensitive information type were incorrect, the policy would not detect credit card numbers at all, but users report the policy is intended to block such content, and the issue is that it is not blocking despite being configured; the type is likely correct.

728
Multi-Selectmedium

A security administrator at Adventure Works is reviewing how Microsoft 365 protects data at rest and in transit across Exchange Online, SharePoint Online, and Teams. Which TWO statements accurately describe Microsoft 365 encryption behavior in this environment? (Choose two.)

Select 2 answers
A.Data in transit between clients and Microsoft 365 services is protected with TLS, and Microsoft uses forward secrecy and strong cipher suites
B.Customer-managed keys in Microsoft Purview replace the default service encryption and are the only way to protect data at rest
C.Service encryption can be disabled by a tenant administrator to improve performance for large mailboxes
D.Data at rest in Exchange Online, SharePoint Online, and Teams is encrypted by using BitLocker and Distributed Key Manager
E.Data in transit between Microsoft datacenters is unencrypted because it stays on Microsoft's private backbone
AnswersA, D

Client-to-service traffic for Exchange Online, SharePoint Online, and Teams uses TLS, and Microsoft negotiates strong cipher suites with forward secrecy for internet-facing endpoints. This protects credentials, mail, and file content while they travel over untrusted networks, which is a documented part of how Microsoft 365 secures data in transit.

Why this answer

Microsoft 365 applies encryption at rest by default across Exchange Online, SharePoint Online, and Teams using BitLocker and Distributed Key Manager, and it protects data in transit with TLS and strong cipher suites, including forward secrecy. Customer-managed keys add organizational control but do not replace the default layers, inter-datacenter traffic is also encrypted, and service encryption cannot be disabled by tenants. The two accurate statements describe those default protections.

Exam trap

The trap here is treating customer-managed keys as a replacement for service encryption, when they actually add a customer-controlled layer on top of encryption that is always enabled by default.

729
MCQmedium

During a Microsoft 365 planning workshop, host custom applications on virtual machines while managing the operating system. Cloud concept or benefit best matches this requirement?

A.Platform as a Service (PaaS)
B.Infrastructure as a Service (IaaS)
C.Hybrid cloud
D.Software as a Service (SaaS)
AnswerB

IaaS supplies virtualised compute, storage, and networking where the customer manages the guest operating system and hosts custom applications. This matches the stem's requirement to run custom apps on VMs while retaining OS management responsibility.

Why this answer

Infrastructure as a Service (IaaS) provides virtualized computing resources over the internet, including virtual machines where you can host custom applications and have full control over the operating system. This matches the requirement because IaaS gives you the flexibility to manage the OS, install custom software, and configure the environment without worrying about the underlying physical hardware.

Exam trap

The trap here is that candidates often confuse PaaS with IaaS because both involve hosting applications, but PaaS does not allow OS-level management, which is the key differentiator in this question.

How to eliminate wrong answers

Option A is wrong because Platform as a Service (PaaS) abstracts away the operating system and infrastructure management, focusing on deploying and managing applications without OS-level control, which contradicts the requirement to manage the operating system. Option C is wrong because Hybrid cloud is a deployment model that combines public and private clouds, not a service model that provides virtual machines with OS management capabilities. Option D is wrong because Software as a Service (SaaS) delivers fully managed applications accessed via a browser or client, with no access to the underlying OS or virtual machines.

730
MCQeasy

Refer to the exhibit. A PowerShell script snippet. What is this script creating?

A.A mail-enabled security group.
B.A distribution group.
C.A shared mailbox.
D.A Microsoft 365 group.
AnswerD

The script calls the Microsoft Graph or Exchange Online cmdlets that provision a unified group with a mail-enabled identity, creating a Microsoft 365 group rather than a distribution list or security group. Its group type and mail attributes match the Microsoft 365 group object.

Why this answer

The New-UnifiedGroup cmdlet (Exchange Online PowerShell) creates a Microsoft 365 group — a modern group object that provides a shared mailbox, calendar, SharePoint site, and Teams-compatible membership. A mail-enabled security group or distribution group would be created with New-DistributionGroup, and a shared mailbox with New-Mailbox -Shared. The "Unified" in the cmdlet name is the historical term for Microsoft 365 groups (formerly Office 365 unified groups).

Exam trap

The MS-900 exam tests recognising which group type each admin tool or cmdlet produces. The trap is confusing Microsoft 365 groups (New-UnifiedGroup — collaboration features) with distribution groups (New-DistributionGroup — email broadcast only).

How to eliminate wrong answers

Option A is wrong because a SQL database is deployed using the 'Microsoft.Sql/servers/databases' resource type, not 'Microsoft.Storage/storageAccounts'. Option B is wrong because a virtual machine is deployed using the 'Microsoft.Compute/virtualMachines' resource type, which includes properties like 'hardwareProfile' and 'storageProfile', not storage account properties. Option C is wrong because a web app is deployed using the 'Microsoft.Web/sites' resource type, which defines site configurations and app settings, not storage account properties.

731
MCQmedium

A marketing team needs to create a short promotional video that includes screen recordings, webcam footage, and text overlays. Which Microsoft 365 app should they use to create this video?

A.Microsoft Stream
B.Microsoft Clipchamp
C.Microsoft PowerPoint
D.Microsoft Sway
AnswerB

Microsoft Clipchamp is Microsoft 365's built-in video editor, acquired and integrated into the suite. It provides a full editing experience including a multi-track timeline, screen recording, webcam capture, and text overlays, making it exactly the tool needed to assemble a short promotional video. Unlike the other options, Clipchamp directly enables the required content creation and editing.

Why this answer

Microsoft Clipchamp is the correct app because it is a built-in video editor in Microsoft 365 designed for creating and editing videos with features like screen recording, webcam capture, and text overlays. It provides a timeline-based editing interface that allows users to combine multiple media sources into a single promotional video, making it the ideal tool for this task.

Exam trap

The trap here is that candidates often confuse Microsoft Stream (a video hosting service) with a video creation tool, or assume PowerPoint's basic video insertion capabilities are sufficient for multi-track editing, leading them to overlook Clipchamp's dedicated video editing functionality.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video hosting and sharing platform, not a video creation or editing tool; it lacks native editing capabilities for combining screen recordings, webcam footage, and text overlays. Option C is wrong because Microsoft PowerPoint is a presentation application that can insert videos but does not offer a timeline-based video editor with multi-track support for screen recordings and webcam footage simultaneously. Option D is wrong because Microsoft Sway is a digital storytelling and presentation tool focused on interactive web-based content, not a video editor with screen recording or webcam integration.

732
Multi-Selectmedium

Which three of the following are characteristics of Microsoft 365 subscription plans? (Choose three.)

Select 3 answers
.Subscription plans are available in monthly and annual commitment terms.
.All subscription plans include the full desktop version of Office applications.
.Plans can be upgraded or downgraded at any time without any restrictions.
.Business plans include Microsoft 365 Business Basic, Business Standard, and Business Premium.
.Enterprise plans are licensed on a per-user basis with a minimum of 5 seats.
.Add-on services, such as Microsoft 365 Copilot, can be purchased to supplement existing plans.

Why this answer

Microsoft 365 subscription plans offer monthly and annual commitment terms, giving customers flexibility in billing. Business plans are specifically categorized as Business Basic, Business Standard, and Business Premium, each with different feature sets. Add-on services like Microsoft 365 Copilot can be purchased to enhance existing subscriptions, allowing organizations to scale capabilities without changing their base plan.

Exam trap

The trap here is that candidates assume all subscription plans include full desktop Office apps, but Microsoft deliberately excludes them from lower-tier plans (e.g., Business Basic) to drive upsell to higher SKUs.

733
Multi-Selecthard

A healthcare organization is adopting Microsoft 365 and must meet compliance requirements: retain all communications for 7 years, prevent accidental deletion of documents, and classify sensitive data automatically. Which THREE Microsoft Purview features should the organization use?

Select 3 answers
A.Data loss prevention (DLP) policies
B.eDiscovery
C.Auto-labeling
D.Preservation hold lock
E.Retention policies
AnswersC, D, E

Auto-labeling in Microsoft 365 automatically applies sensitivity or retention labels to content based on rules, sensitive information patterns, or machine-learning classifiers. For a healthcare organization, this ensures that communications containing protected health information (e.g., a patient ID with a diagnosis) are immediately classified as sensitive without manual user intervention. This classification is a prerequisite for enforcing downstream governance actions like encryption or access restrictions, and it directly fulfills the 'classify' part of the requirement. Auto-labeling alone does not retain content for a set period, but it is the correct mechanism for automated classification.

Why this answer

Auto-labeling (Option C) is correct because it enables the organization to automatically classify sensitive data based on content patterns (e.g., healthcare records, PII) without manual intervention. This aligns directly with the requirement to classify sensitive data automatically, using trainable classifiers or sensitive info types in Microsoft Purview.

Exam trap

The trap here is that candidates often confuse DLP policies with auto-labeling, but DLP is about preventing data loss after classification, not the classification itself.

734
MCQhard

A company with 100 Microsoft 365 Business Premium users needs to add advanced compliance features: eDiscovery (Premium) and Communication Compliance. They want to keep their existing Business Premium subscriptions to retain current capabilities. What is the most cost-effective licensing approach?

A.Upgrade all 100 users from Business Premium to Microsoft 365 E5
B.Purchase Microsoft 365 E5 Compliance add-on for all 100 users
C.Purchase Microsoft 365 E5 eDiscovery and Audit add-on
D.Purchase Microsoft 365 E5 Compliance and Information Protection add-on
AnswerB

Microsoft 365 E5 Compliance is an officially supported add-on that can be purchased on top of Microsoft 365 Business Premium to close specific compliance gaps. It provides eDiscovery (Premium), Communication Compliance, and other advanced compliance tools without requiring users to change their base license. This is the most cost-effective option because only the missing functionality is added, and assigning it to all 100 users exactly matches the stated business need.

Why this answer

Microsoft 365 Business Premium already includes the base compliance features, and the Microsoft 365 E5 Compliance add-on provides the advanced capabilities (eDiscovery Premium and Communication Compliance) without requiring a full license upgrade. This add-on is the most cost-effective approach as it adds only the needed compliance features to existing Business Premium subscriptions.

Exam trap

The trap here is that candidates often assume they must upgrade to a full E5 license to get advanced compliance features, overlooking the existence of targeted add-ons like Microsoft 365 E5 Compliance that can be layered onto existing Business Premium subscriptions.

How to eliminate wrong answers

Option A is wrong because upgrading all 100 users from Business Premium to Microsoft 365 E5 is significantly more expensive than adding the E5 Compliance add-on, and it provides many extra features (e.g., advanced analytics, advanced threat protection) that are not required, making it not cost-effective. Option C is wrong because there is no standalone 'Microsoft 365 E5 eDiscovery and Audit add-on'; eDiscovery (Premium) and Communication Compliance are part of the Microsoft 365 E5 Compliance suite, not a separate eDiscovery-only add-on. Option D is wrong because 'Microsoft 365 E5 Compliance and Information Protection add-on' is not a valid SKU name; the correct add-on is simply 'Microsoft 365 E5 Compliance', which includes both eDiscovery Premium and Communication Compliance, and the mention of 'Information Protection' is redundant or misleading.

735
MCQeasy

A compliance-aware administrator is selecting the right Microsoft 365 capability to add and remove capacity quickly when demand changes. Cloud concept or benefit best matches this requirement?

A.Rapid elasticity
B.Microsoft Planner
C.Data Loss Prevention (DLP)
D.Sensitivity labels
AnswerA

Rapid elasticity lets Microsoft 365 capacity scale up and down automatically with demand, so the administrator adds and removes resources quickly without manual provisioning. This matches the requirement for fast, demand-driven adjustment rather than fixed or pre-purchased capacity.

Why this answer

Rapid elasticity is a core cloud computing concept defined by NIST (SP 800-145) that allows resources to be provisioned and released automatically in response to demand. In Microsoft 365, this is demonstrated by the ability to add or remove user licenses (e.g., via the Microsoft 365 admin center or PowerShell) on a per-seat basis, scaling capacity up or down almost instantly without manual infrastructure changes.

Exam trap

The trap here is that candidates confuse a cloud concept (rapid elasticity) with a specific Microsoft 365 feature (Planner, DLP, sensitivity labels), failing to recognize that the question asks for the cloud concept or benefit, not a product or feature name.

How to eliminate wrong answers

Option B is wrong because Microsoft Planner is a task management and project planning tool, not a cloud concept or benefit for scaling capacity. Option C is wrong because Data Loss Prevention (DLP) is a security policy feature that prevents sensitive data from being shared inappropriately, not a mechanism for adding or removing capacity. Option D is wrong because sensitivity labels are used to classify and protect data (e.g., encryption, marking), not to scale cloud resources dynamically.

736
MCQeasy

A user receives an error message when trying to activate Microsoft 365 Apps for enterprise. The administrator checks the license assignment and confirms the user has a Microsoft 365 E3 license. What is the most likely cause of the activation failure?

A.The Microsoft 365 trial period has expired
B.The license is not yet assigned to the user
C.The user is signed in with a personal Microsoft account instead of a work or school account
D.The device does not meet the minimum system requirements for Office
AnswerC

Microsoft 365 Apps for enterprise validate licenses through the user's work or school account (an Azure AD identity associated with the organization's tenant). When a user signs in with a personal Microsoft account (e.g., Outlook.com or hotmail.com), the activation request reaches Microsoft's licensing service, but that personal identity has no link to the organization's subscription, so the license token cannot be issued. This mismatch produces an activation error even though the device, license, and subscription are all healthy. The fix is to sign out and sign in explicitly with the work/school account whose UPN belongs to the licensed tenant.

Why this answer

Microsoft 365 Apps for enterprise activation requires signing in with a work or school account that has the appropriate license. If the user is signed in with a personal Microsoft account, activation will fail even if the license is assigned. The most likely cause is that the user is using the wrong account type.

Exam trap

MS-900 often tests the difference between work/school accounts and personal accounts for Office activation, where candidates may overlook the account type and focus on license assignment.

How to eliminate wrong answers

Option A is wrong because the question states the user has an E3 license, so a trial expiration is not relevant. Option B is wrong because the administrator already confirmed the license is assigned. Option D is wrong because if the device did not meet system requirements, the user would likely see a different error or the app would not install.

Option C is correct because using a personal account instead of a work account prevents license validation.

737
MCQmedium

A non-profit organization with 100 users needs business-grade email, desktop versions of Office apps (Word, Excel, PowerPoint), and 1 TB of cloud storage per user. They are eligible for non-profit pricing. Which Microsoft 365 plan meets these requirements at the lowest cost?

A.Microsoft 365 Business Basic (Nonprofit)
B.Microsoft 365 Business Standard (Nonprofit)
C.Microsoft 365 Business Premium (Nonprofit)
D.Microsoft 365 E3 (Nonprofit)
AnswerB

This subscription includes the full desktop Office suite, business-grade email with a 50 GB mailbox, 1 TB of OneDrive storage per user, and Teams, all at the discounted nonprofit pricing. For an organization with 100 users that simply needs reliable business productivity tools, this plan delivers the necessary installed applications and collaboration capabilities without paying for advanced security or compliance extras. It aligns directly with the core requirement and is the most cost-effective eligible option.

Why this answer

Microsoft 365 Business Standard (Nonprofit) is the lowest-cost plan that includes business-grade email (Exchange Online), desktop versions of Office apps (Word, Excel, PowerPoint), and 1 TB of cloud storage per user (OneDrive for Business). Microsoft 365 Business Basic (Nonprofit) lacks the desktop Office apps, while Business Premium and E3 include additional security and compliance features that increase cost beyond the stated requirements.

Exam trap

The trap here is that candidates often confuse 'Business Basic' as sufficient because it includes email and cloud storage, forgetting that desktop Office apps are a separate, higher-tier requirement, or they over-select 'Business Premium' or 'E3' thinking more features are always better for nonprofits.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Basic (Nonprofit) provides only web and mobile versions of Office apps, not the full desktop versions required by the question. Option C is wrong because Microsoft 365 Business Premium (Nonprofit) includes all the required features but adds advanced security and device management capabilities (e.g., Microsoft Defender for Business, Intune) that raise the cost unnecessarily. Option D is wrong because Microsoft 365 E3 (Nonprofit) is an enterprise-grade plan with additional compliance, analytics, and advanced security features (e.g., eDiscovery, Advanced Audit) that far exceed the stated needs and come at a higher price point.

738
MCQmedium

A compliance administrator needs to investigate emails that may be part of a phishing campaign. Which Microsoft 365 capability is the best fit?

A.Microsoft Bookings
B.Microsoft Teams live events
C.OneDrive sync client
D.Threat Explorer in Microsoft Defender for Office 365
AnswerD

Threat Explorer is a real-time report and investigation tool in Microsoft Defender for Office 365 that allows security teams to view and analyze email threats, including malware, phishing, and spam. It provides powerful filters for delivery actions, detection technology, and campaign insights, enabling admins to identify and remediate malicious emails. This makes it the appropriate tool for a compliance administrator to investigate potentially harmful emails.

Why this answer

Threat Explorer in Microsoft Defender for Office 365 is the correct tool because it provides security teams with a powerful, real-time investigation interface to search, filter, and analyze email threats, including phishing campaigns. It allows administrators to view detailed email metadata, delivery actions, and threat types (e.g., phishing, malware) across the organization, making it the best fit for investigating suspected phishing emails.

Exam trap

The trap here is that candidates may confuse general Microsoft 365 admin tools (like Bookings or Teams) with security-specific capabilities, failing to recognize that only Threat Explorer provides the granular email investigation features required for phishing analysis.

How to eliminate wrong answers

Option A is wrong because Microsoft Bookings is a scheduling and appointment management tool, not a security or email investigation capability. Option B is wrong because Microsoft Teams live events is a broadcast and meeting feature for large audiences, with no email threat analysis or phishing investigation functionality. Option C is wrong because the OneDrive sync client is designed for file synchronization and offline access, and it cannot be used to investigate email threats or phishing campaigns.

739
MCQmedium

A compliance-aware administrator is selecting the right Microsoft 365 capability to delete content automatically after a defined retention period. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Forms
B.Microsoft Planner
C.Microsoft Stream
D.Retention policy or retention label
AnswerD

Retention policies and retention labels are the core Microsoft 365 compliance tools for data lifecycle governance. A retention policy can be configured to retain content for a specified period and then delete it, or simply retain it indefinitely, across workloads like Exchange, SharePoint, OneDrive, and Teams. Similarly, retention labels allow granular, item-level control and can be combined with event-based retention or disposition reviews. This capability directly meets the requirement to retain and later delete content according to policy.

Why this answer

Retention policies and retention labels are the Microsoft 365 compliance capabilities designed to automatically delete content after a defined retention period. They enforce data lifecycle management by applying rules to content in Exchange, SharePoint, OneDrive, and Teams, ensuring compliance with regulatory requirements. Microsoft Forms, Planner, and Stream are productivity or collaboration tools, not compliance capabilities for automated deletion.

Exam trap

The trap here is that candidates may confuse productivity tools (Forms, Planner, Stream) with compliance capabilities, assuming they have built-in retention features, when in fact only retention policies and labels provide automated deletion based on a defined period.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and quiz creation tool, not a compliance capability; it lacks native features to automatically delete content after a retention period. Option B is wrong because Microsoft Planner is a task management and project planning tool, not a compliance capability; it does not provide retention or deletion policies for content. Option C is wrong because Microsoft Stream is a video hosting and sharing service, not a compliance capability; while it integrates with retention policies, it is not the tool used to define or manage retention periods.

740
MCQmedium

A company uses Microsoft 365 and wants to automatically classify documents containing credit card numbers as 'Highly Confidential' and apply encryption when shared externally. Which solution should they use?

A.Microsoft Intune
B.Microsoft Sentinel
C.Microsoft Purview Information Protection with auto-labeling
D.Microsoft Defender for Cloud Apps
AnswerC

Microsoft Purview Information Protection with auto-labeling is the correct service for automatic classification. It uses sensitivity labels and service-side detection of sensitive info types to automatically apply labels to documents and emails stored in Exchange, SharePoint, and OneDrive. Administrators define policies that trigger on credit card numbers, driver's license IDs, or other data types, ensuring sensitive content is consistently protected.

Why this answer

Microsoft Purview Information Protection with auto-labeling is the correct solution because it uses trainable classifiers or exact data match (EDM) to detect sensitive data types like credit card numbers, automatically apply a 'Highly Confidential' sensitivity label, and enforce encryption when the document is shared externally. This capability is built into Microsoft 365 compliance center and integrates with sensitivity labels to protect data at rest and in transit.

Exam trap

The trap here is that candidates confuse Microsoft Defender for Cloud Apps (a CASB) with Purview's auto-labeling, assuming a CASB can classify and encrypt content natively, when in fact it only applies labels that are already defined and managed by Purview Information Protection.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) solution that manages devices and apps, not content classification or encryption based on sensitive data patterns. Option B is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR solution for security analytics and threat detection, not for automatic content classification or labeling of documents. Option D is wrong because Microsoft Defender for Cloud Apps is a CASB that provides visibility and control over cloud app usage, but it does not natively perform automatic classification and encryption of documents based on sensitive data types like credit card numbers; it can apply labels only after they are created by Purview.

741
MCQmedium

An IT administrator needs to ensure that all company-issued Windows 11 devices are configured with the latest security policies and that applications are deployed automatically. Which Microsoft 365 service should they use?

A.Microsoft Intune
B.Microsoft Microsoft Entra ID
C.Microsoft Defender for Endpoint
D.Microsoft 365 Apps for enterprise
AnswerA

Microsoft Intune is the correct service—it is a cloud-based endpoint management solution that uses the Windows 10/11 MDM enrollment channel and configuration service providers (CSPs) to enforce device configuration policies, deploy applications via Intune Managed Apps or Company Portal, and assess compliance. This directly satisfies the requirement for consistent configuration of all company-issued Windows 11 devices.

Why this answer

Microsoft Intune is the correct choice because it is a cloud-based endpoint management solution that provides mobile device management (MDM) and mobile application management (MAM). It allows IT administrators to enforce security policies (e.g., BitLocker, Windows Defender Firewall, compliance rules) and automate application deployment to Windows 11 devices without requiring on-premises infrastructure. Intune integrates with Microsoft Entra ID for identity-based conditional access but is the primary service for device configuration and app deployment.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID (identity management) with device management, assuming it can enforce device policies, when in fact Entra ID only provides conditional access policies that rely on Intune compliance data.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID is an identity and access management service that handles authentication, single sign-on, and conditional access policies, but it does not manage device configuration or deploy applications directly. Option C is wrong because Microsoft Defender for Endpoint is a security solution focused on endpoint detection and response (EDR), vulnerability management, and threat protection, not device policy enforcement or automated app deployment. Option D is wrong because Microsoft 365 Apps for enterprise is a suite of productivity applications (e.g., Word, Excel, Teams) and does not provide device management or policy configuration capabilities.

742
Matchingmedium

Match each Microsoft 365 license type to its typical audience.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Large organizations with 500+ users

Organizations buying through a partner

Small and medium businesses up to 300 users

Individual users or teams buying directly

Why these pairings

Microsoft 365 licensing varies by organization size and needs. Business Basic and Business Premium target small to medium businesses, while E5 targets large enterprises. Distractors confuse the feature sets across different plans.

743
MCQmedium

Contoso Ltd. is a global consulting firm with 5,000 employees. They use Microsoft 365 E5 and have recently deployed Microsoft Copilot for Microsoft 365 to enhance productivity. The IT team wants to ensure that users' interactions with Copilot are compliant with the company's data retention policies. They need to retain all Copilot interactions for 7 years for legal reasons. Which Microsoft Purview solution should the IT team implement?

A.Apply sensitivity labels to Copilot data
B.Create retention policies for Copilot interactions
C.Set up eDiscovery cases for Copilot data
D.Configure Data Loss Prevention (DLP) policies
AnswerB

Retention policies in Microsoft Purview apply to Copilot interaction data stored in Exchange Online, letting administrators set a seven-year retention duration. This directly satisfies the legal requirement to retain all Copilot interactions for seven years without relying on manual preservation.

Why this answer

Retention policies in Microsoft Purview can be applied to Copilot interactions stored in Exchange Online and SharePoint Online to retain them for 7 years. Option A is incorrect because sensitivity labels classify data but do not enforce retention. Option C is incorrect because eDiscovery is for searching and exporting content, not setting retention.

Option D is incorrect because Data Loss Prevention (DLP) policies prevent data loss but do not retain data for legal hold.

744
Multi-Selecteasy

Which TWO Microsoft 365 subscription plans include the Microsoft 365 Copilot add-on as an optional purchase?

Select 2 answers
A.Microsoft 365 Education A1
B.Microsoft 365 E3
C.Microsoft 365 Business Basic
D.Microsoft 365 F3
E.Microsoft 365 E5
AnswersB, E

Microsoft 365 E3 is a commercial enterprise subscription that includes Office desktop apps, Exchange Online, SharePoint, OneDrive, and core security services. It does not include Microsoft 365 Copilot by default, but E3 is one of the qualifying licenses that can be augmented with the Copilot for Microsoft 365 add-on on a per-user basis. Since the question asks which plans can include Copilot, E3 is a correct answer.

Why this answer

Microsoft 365 Copilot is an AI-powered productivity add-on that requires a qualifying base subscription. Microsoft 365 E3 and E5 are enterprise-grade plans that include the necessary security, compliance, and identity features to support Copilot, making them eligible for the optional Copilot add-on purchase.

Exam trap

The trap here is that candidates often assume any paid Microsoft 365 plan, including Business Basic or F3, can add Copilot, but Microsoft restricts Copilot to plans with full desktop Office apps and advanced security features like Azure AD P1/P2.

745
Matchingmedium

Match each Microsoft 365 support channel to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Web portal for managing users, billing, and support requests

Assisted onboarding and deployment service

Peer-to-peer forums and knowledge base

Direct voice assistance for critical issues

Why these pairings

Microsoft 365 offers multiple support channels: Phone support for critical issues, Online self-help for documentation, Community forums for peer assistance, and the Service health dashboard for real-time status. Common confusions involve mixing definitions of phone and self-help or community and phone.

746
MCQeasy

A company wants to move its IT infrastructure to the cloud but must keep all customer data within a specific geographic region due to data residency laws. They also want to avoid paying for large upfront hardware costs. Which cloud characteristic best supports this need?

A.Geographic distribution (regional data centers)
B.Elasticity
C.High availability
D.Self-service
AnswerA

Cloud providers maintain physically distinct regional data centers that let customers designate a specific location for data at rest, such as an Azure region in the same country or border. This is the only attribute that directly addresses data residency and sovereignty requirements, because workload placement is tied to the chosen region's legal and regulatory jurisdiction. Scaling, availability, and self-service mechanics do not have any intrinsic capability to constrain where data is stored.

Why this answer

Geographic distribution refers to cloud providers operating multiple data centers across different regions, enabling customers to choose a specific region to store data and comply with data residency laws. This characteristic directly addresses the requirement to keep customer data within a specific geographic region while avoiding upfront hardware costs, as the cloud provider owns and manages the infrastructure.

Exam trap

The trap here is that candidates often confuse geographic distribution with high availability or elasticity, mistakenly thinking that scaling or redundancy can satisfy data residency requirements, when only region-specific data centers can enforce legal data boundaries.

How to eliminate wrong answers

Option B (Elasticity) is wrong because elasticity refers to the ability to automatically scale resources up or down based on demand, not to the geographic placement of data. Option C (High availability) is wrong because high availability ensures that services remain operational despite failures through redundancy within or across data centers, but it does not guarantee data residency in a specific region. Option D (Self-service) is wrong because self-service allows users to provision resources on demand without manual intervention from the provider, but it has no relation to geographic data placement or compliance with data residency laws.

747
MCQhard

A company with 1,000 users has Microsoft 365 E3 subscriptions. They are experiencing a major outage affecting all users and need guaranteed 1-hour response time for a critical support issue. What should they purchase?

A.Standard Support (included)
B.Professional Direct Support
C.Azure Support Basic
D.Partner support via a Microsoft CSP
AnswerB

Professional Direct Support is a paid support add-on for Microsoft 365 that provides a guaranteed one-hour response for critical severity (Sev A) issues, ensuring urgent problems are addressed promptly. It also includes proactive services such as health checks, change management assistance, and access to Microsoft subject matter experts. This plan is specifically designed for organizations that require rapid, SLA-backed assistance and ongoing technical guidance.

Why this answer

Professional Direct Support provides a guaranteed 1-hour response time for critical severity issues, which is required for the company's major outage affecting all 1,000 users. Standard Support, included with Microsoft 365 E3, offers a 1-hour response for critical issues only for Business-level subscriptions; for Enterprise subscriptions like E3, the critical response time is 2 hours. Professional Direct Support also includes proactive guidance and a named support engineer, making it the correct choice for guaranteed 1-hour response.

Exam trap

The trap here is that candidates assume Standard Support (included) always provides a 1-hour critical response, but Microsoft differentiates response times by subscription type (Business vs. Enterprise), and for E3 (Enterprise), the critical response is 2 hours, not 1.

How to eliminate wrong answers

Option A is wrong because Standard Support (included with Microsoft 365 E3) provides a 2-hour response time for critical severity issues for Enterprise subscriptions, not the guaranteed 1-hour response required. Option C is wrong because Azure Support Basic is a free tier for Azure services only, not for Microsoft 365, and it does not include any guaranteed response times or technical support for M365 issues. Option D is wrong because partner support via a Microsoft CSP may offer varying response times depending on the partner's service level agreement, but it does not guarantee a 1-hour response time from Microsoft directly, and the question specifies a guaranteed 1-hour response for a critical issue.

748
Multi-Selectmedium

Which three options describe features or capabilities of Microsoft Viva? (Choose three.)

Select 3 answers
.Provides personalized learning and training resources through Viva Learning
.Integrates employee communications and company news in Viva Connections
.Offers insights into work patterns and well-being in Viva Insights
.Delivers advanced threat protection for email and documents
.Functions as a cloud-based customer relationship management (CRM) system
.Automates complex business workflows using Power Automate

Why this answer

Microsoft Viva is an employee experience platform (EXP) that brings together communications, knowledge, learning, resources, and insights. Viva Learning provides a centralized hub for learning and training resources from LinkedIn Learning, Microsoft Learn, and third-party content providers. Viva Connections delivers a personalized dashboard that integrates company news, conversations, and resources from SharePoint and Yammer.

Viva Insights uses Microsoft Graph data to provide analytics on work patterns, such as meeting time, focus hours, and well-being trends, helping individuals and managers improve productivity and work-life balance.

Exam trap

The trap here is that candidates confuse Microsoft Viva's employee experience features with other Microsoft 365 security, CRM, or automation services, mistakenly selecting options that describe Defender, Dynamics 365, or Power Automate instead of recognizing Viva's specific focus on employee engagement, learning, and insights.

749
MCQmedium

A business stakeholder asks how Microsoft 365 can help them periodically review group memberships and application access. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Planner
B.Access reviews
C.Microsoft Stream
D.Microsoft Forms
AnswerB

Access reviews in Microsoft Entra ID Governance let reviewers periodically recertify group memberships and application assignments, with recurring schedules and automatic removal on denial. This satisfies the stem's requirement for periodic review of memberships and app access.

Why this answer

Access reviews in Microsoft Entra ID (formerly Azure AD) allow administrators to periodically review and certify group memberships and application access. This capability directly addresses the stakeholder's requirement by automating recurring attestation workflows, ensuring that only authorized users retain access. It is part of Microsoft's identity governance framework, not a general productivity or media tool.

Exam trap

The trap here is confusing general productivity tools (Planner, Stream, Forms) with identity governance capabilities, leading candidates to pick a familiar-sounding option instead of recognizing Access Reviews as the specific Entra ID feature for periodic access certification.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management and collaboration tool for organizing work, not an identity governance or access review feature. Option C is wrong because Microsoft Stream is a video hosting and sharing service for enterprise content, with no capability to review group memberships or application access. Option D is wrong because Microsoft Forms is a survey and quiz creation tool, lacking any identity or access review functionality.

750
Matchingmedium

Match each Microsoft 365 deployment model to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

All users and data are managed in the cloud

Some services on-premises, some in the cloud

All services run on local servers

Cloud services designed for US government agencies

Why these pairings

Correct matches: Hybrid deployment uses both cloud and on-premises resources; GCC is tailored for US government compliance. Common confusions: mixing up cloud-only and on-premises definitions, and assuming 21Vianet operates globally when it is specific to China.

Page 9

Page 10 of 11

Page 11

All pages