Courseiva

Microsoft 365 Fundamentals MS-900 (MS-900) — Questions 751–794

794 questions total · 11pages · All types, answers revealed

Page 10

Page 11 of 11

751
MCQmedium

Your company is deploying Microsoft Purview to manage data subject requests (DSRs) under GDPR. Users need to submit requests to access or delete their personal data. Which Microsoft Purview solution should you use?

A.Microsoft Purview Data Subject Requests
B.Microsoft Purview Records Management
C.Microsoft Purview Audit (Premium)
D.Microsoft Purview Data Loss Prevention (DLP)
AnswerA

Microsoft Purview Data Subject Requests is the definitive solution for managing DSRs under GDPR, providing a centralized portal to profile personal data, find matches, and orchestrate the review and export of data. Unlike other Purview modules, it includes built-in workflows to handle subjects' rights to access, rectify, and erase personal data across Microsoft 365 services, and it generates auditable trails for compliance. This makes it the correct choice whenever the requirement is specifically about responding to DSRs.

Why this answer

Microsoft Purview Data Subject Requests is the dedicated solution for managing data subject requests (DSRs) under GDPR. It provides a centralized interface for users to submit requests to access or delete their personal data, and for administrators to track and fulfill those requests. The other options are incorrect: Records Management handles retention and disposition of records, Audit (Premium) provides logging and investigation capabilities, and Data Loss Prevention (DLP) protects against data leaks.

Therefore, option A is the correct answer.

752
MCQhard

A multinational corporation uses Microsoft 365 E5. They need to enforce that all documents marked as 'Confidential' are encrypted and cannot be printed or forwarded. Which Microsoft Purview Information Protection capability should they configure?

A.Sensitivity labels with encryption
B.Data Loss Prevention (DLP) policies
C.Retention policies
D.Azure Information Protection (AIP) client
AnswerA

Sensitivity labels with encryption are the correct choice because they apply persistent protection directly to content, enforcing encryption, and usage restrictions such as 'Do Not Forward' or 'View Only' settings. These labels work natively across Microsoft 365 apps and services, ensuring that print, copy, and edit actions are blocked based on policies defined by the organization.

Why this answer

Sensitivity labels with encryption are the correct choice because they allow you to classify and protect documents at the file level, applying encryption that restricts actions such as printing and forwarding. This is a core capability of Microsoft Purview Information Protection, enabling persistent protection that travels with the document regardless of where it is stored or shared.

Exam trap

The trap here is that candidates often confuse DLP policies with sensitivity labels, thinking DLP can enforce encryption and restrict actions like printing, but DLP only monitors and alerts on content in transit or at rest, while sensitivity labels provide persistent, user-enforced protection at the file level.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) policies are designed to detect and prevent accidental sharing of sensitive information based on rules, but they do not enforce persistent encryption or restrict printing/forwarding at the file level. Option C is wrong because retention policies are used to retain or delete content for compliance or legal reasons, not to apply encryption or restrict user actions like printing or forwarding. Option D is wrong because the Azure Information Protection (AIP) client is a legacy tool that has been deprecated in favor of built-in sensitivity labels in Microsoft 365 Apps; the modern approach uses sensitivity labels with encryption directly in Purview, not the AIP client.

753
MCQmedium

During a Microsoft 365 planning workshop, show security recommendations and a score for Microsoft 365 posture. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Secure Score
B.Microsoft Forms
C.Microsoft Planner
D.Microsoft Stream
AnswerA

Microsoft Secure Score (available in the Microsoft 365 Defender portal) assigns a numeric score based on how closely the tenant's security configurations match recommended baselines across identities, devices, apps, and email. Its improvement actions include both the maximum attainable points and a list of controls to remediate, making it the right tool during a planning workshop to evaluate the organization's current security posture and prioritize remediation. It is specifically designed to assess and increase security, unlike the other options.

Why this answer

Microsoft Secure Score is the correct tool because it provides a numerical score and actionable security recommendations based on your tenant's security posture. It analyzes configurations across Microsoft 365 services (e.g., Exchange Online, Azure AD, Intune) and suggests improvements to reduce risk, directly matching the workshop requirement for showing recommendations and a score.

Exam trap

The trap here is that candidates may confuse Microsoft Secure Score with other Microsoft 365 tools that have 'score' or 'recommendations' in their names, but only Secure Score is specifically designed for security posture assessment and scoring.

How to eliminate wrong answers

Option B (Microsoft Forms) is wrong because it is a survey and data collection tool, not a security posture assessment tool. Option C (Microsoft Planner) is wrong because it is a task management and project planning application, unrelated to security scoring. Option D (Microsoft Stream) is wrong because it is a video hosting and sharing service, with no capability to evaluate security configurations or generate a posture score.

754
MCQmedium

A non-profit organization with 300 users needs to deploy Microsoft 365 Business Basic for all users. They also require device management via Microsoft Intune for 50 users who use company-owned mobile devices. The organization is eligible for non-profit pricing. What is the most cost-effective licensing approach?

A.Assign Microsoft 365 Business Premium to all 300 users
B.Purchase Microsoft Intune Plan 1 add-on licenses for the 50 users who need device management
C.Create a separate Microsoft 365 Business Basic tenant for the 50 users and include Intune
D.Purchase Microsoft 365 E3 licenses for the 50 users
AnswerB

Intune Plan 1 is available as a standalone per-user add-on that can be layered onto Microsoft 365 Business Basic, and licenses can be selectively assigned in the Microsoft 365 admin center to only the 50 users responsible for device management. Because the add-on is independent of the base subscription tier, you pay a low per-user price (about $8/user/month) for just those users, while the other 250 users remain on plain Business Basic. This delivers the required MDM/MAM capability at the absolute lowest licensing cost and avoids paying for extra suite features.

Why this answer

Microsoft 365 Business Basic provides the core productivity and collaboration tools (Exchange Online, Teams, SharePoint) needed by all 300 users. For the 50 users requiring device management, purchasing Microsoft Intune Plan 1 as an add-on license is the most cost-effective approach because it adds mobile device management (MDM) capabilities to their existing Business Basic subscription without upgrading the entire tenant or purchasing more expensive suites. Non-profit pricing applies to both the base license and the add-on, minimizing costs.

Exam trap

The trap here is that candidates often assume device management requires an entire suite upgrade (e.g., Business Premium or E3) rather than recognizing that Intune Plan 1 can be purchased as a cost-effective standalone add-on for specific users, leveraging the existing base license.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Premium includes advanced security and device management features (e.g., Intune, Azure AD P1, Microsoft Defender for Office 365) that are not needed for all 300 users, resulting in unnecessary cost for the 250 users who only require basic productivity tools. Option C is wrong because creating a separate tenant for 50 users introduces administrative overhead, breaks single-tenant management, and prevents unified collaboration (e.g., cross-tenant sharing complexities), while still requiring Intune licenses for those 50 users. Option D is wrong because Microsoft 365 E3 licenses are significantly more expensive than Business Basic plus Intune Plan 1 add-on, and they include many enterprise features (e.g., eDiscovery, advanced compliance) that are not required for device management alone.

755
MCQmedium

A legal team needs to preserve all data related to a specific user involved in litigation, including Exchange emails, SharePoint documents, OneDrive files, and Teams chats. They require a hold that cannot be removed by the user and must allow for later searching and export. Which Microsoft Purview solution should they use?

A.eDiscovery (Standard)
B.Retention policies
C.Communication Compliance
D.Data Loss Prevention (DLP)
AnswerA

eDiscovery (Standard) creates a case in the Microsoft Purview compliance portal that can place an in-place Litigation Hold on Exchange mailboxes, SharePoint sites, OneDrive accounts, and Teams. With query-based holds, it preserves any content matching the case-specific search criteria, and it automatically retains copies of items that users try to edit or delete. The hold freezes content indefinitely until the legal team removes it, and the tool also provides comprehensive search and export capabilities for the preserved data.

Why this answer

eDiscovery (Standard) is the correct solution because it allows legal teams to place a hold on all content relevant to a specific user, including Exchange emails, SharePoint documents, OneDrive files, and Teams chats. This hold is enforced at the service level, preventing the user from deleting or modifying the data, and it preserves the content in its original location for later searching and export via Content Search or eDiscovery export tools.

Exam trap

The trap here is that candidates often confuse retention policies with litigation holds, not realizing that retention policies are scheduled and policy-based, whereas eDiscovery holds are user-specific, immediate, and designed for legal preservation with full search and export capabilities.

How to eliminate wrong answers

Option B is wrong because retention policies are designed to retain or delete data based on a fixed schedule, not to place a litigation hold on a specific user's content; they cannot be applied ad hoc for a single user in a legal case and do not provide the same search and export capabilities. Option C is wrong because Communication Compliance is focused on detecting and remediating policy violations (e.g., inappropriate language or sensitive information) in communications, not on preserving all data for litigation; it does not offer a hold mechanism or export for legal discovery. Option D is wrong because Data Loss Prevention (DLP) is used to prevent unauthorized sharing or leakage of sensitive data through policies and alerts, not to preserve data for legal holds; it cannot place a hold on content or allow for later searching and export of all user data.

756
MCQeasy

A marketing team needs to temporarily increase their cloud storage capacity from 5 TB to 10 TB for a product launch. They can perform this change themselves through a web portal without contacting the cloud provider. Which cloud characteristic does this scenario demonstrate?

A.On-demand self-service
B.Rapid elasticity
C.Measured service
D.Resource pooling
AnswerA

On-demand self-service is correct because the scenario describes the marketing team's user directly provisioning additional storage capacity through a web portal, without needing to submit a request or wait for a human administrator. This is the defining NIST characteristic: a consumer can unilaterally provision computing capabilities automatically, eliminating provider interaction. The user's own action makes this the most precise match.

Why this answer

This scenario demonstrates on-demand self-service because the marketing team can provision and manage their own cloud storage capacity increase from 5 TB to 10 TB through a web portal without any human interaction with the cloud provider. This is a core NIST-defined characteristic where users can unilaterally provision computing resources as needed automatically, requiring no service provider intervention.

Exam trap

The trap here is confusing 'on-demand self-service' with 'rapid elasticity' because both involve scaling, but on-demand self-service focuses on the user's ability to provision resources without provider interaction, while rapid elasticity focuses on automatic, dynamic scaling in response to load changes.

How to eliminate wrong answers

Option B (Rapid elasticity) is wrong because rapid elasticity refers to the ability to automatically scale resources up or down in response to demand, often dynamically and programmatically, not a manual one-time increase via a portal. Option C (Measured service) is wrong because measured service involves metering and billing for resource usage (pay-per-use), not the ability to self-provision capacity. Option D (Resource pooling) is wrong because resource pooling describes the provider's multi-tenant model where physical and virtual resources are dynamically assigned to multiple customers, not the customer's ability to adjust their own allocation.

757
MCQeasy

A user accidentally deletes a critical file from their OneDrive for Business. The IT admin needs to restore the file. What is the maximum number of days that OneDrive for Business retains deleted files by default for users without a retention policy?

A.30 days
B.60 days
C.183 days
D.93 days
AnswerD

OneDrive for Business retains deleted files for 93 days by default, encompassing both the user's recycle bin and the site collection recycle bin. The 93-day period is a continuous countdown from the original deletion date, not a reset when an item moves between the two stages. Administrators can adjust this default to any value between 30 and 365 days via SharePoint Online PowerShell, but 93 days remains the standard out-of-the-box setting.

Why this answer

By default, OneDrive for Business retains deleted files in the recycle bin for 93 days. This includes both the first-stage recycle bin (30 days) and the second-stage recycle bin (an additional 63 days), totaling 93 days before permanent deletion. This default retention applies when no specific retention policy or legal hold is configured.

Exam trap

The trap here is that candidates often confuse the 30-day first-stage recycle bin retention with the total retention period, or mistakenly apply Exchange Online's 183-day deleted item retention to OneDrive for Business.

How to eliminate wrong answers

Option A is wrong because 30 days is only the retention period for the first-stage recycle bin, not the total retention for deleted files. Option B is wrong because 60 days is not a standard default retention period for OneDrive for Business; it may be confused with SharePoint Online's default retention for deleted items in some contexts. Option C is wrong because 183 days (approximately 6 months) is the default retention period for deleted items in the Microsoft 365 Exchange Online mailbox, not for OneDrive for Business.

758
MCQmedium

A tenant administrator is advising a department that wants to view usage reports without changing configuration. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Microsoft Stream
C.Microsoft Forms
D.Reports Reader
AnswerD

The Reports Reader role provides read-only access to Microsoft 365 usage analytics and reports within the admin center, allowing a department to view reporting data without being granted broader administrative permissions. It is purpose-built for users who need to monitor metrics such as user activity, licensing consumption, and service usage, thereby enforcing the principle of least privilege. This makes it the correct solution for a department that wants to access reporting data without full admin rights.

Why this answer

The Reports Reader role in Microsoft 365 is specifically designed to allow users to view usage reports and activity logs without needing any administrative permissions to change configurations. This role provides read-only access to reporting data, making it the most relevant concept for a department that wants to monitor usage without altering settings.

Exam trap

The trap here is that candidates often confuse product features (like Whiteboard, Stream, or Forms) with administrative roles or permissions, assuming any Microsoft 365 service can provide report access, when in fact only specific roles like Reports Reader or Global Reader grant such read-only reporting capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a collaborative digital canvas tool, not a role or feature for viewing usage reports. Option B is wrong because Microsoft Stream is a video service for recording and sharing videos, unrelated to report viewing permissions. Option C is wrong because Microsoft Forms is a survey and quiz creation tool, not a mechanism for accessing usage analytics.

759
MCQmedium

A department asks for the Microsoft 365 service best suited for department document libraries with version history. Which service should they use? The design must avoid adding custom operational scripts.

A.Microsoft Purview Compliance Manager
B.SharePoint Online
C.Microsoft Entra Privileged Identity Management
D.Microsoft Defender for Endpoint
AnswerB

SharePoint Online is the correct choice because it provides structured team sites and document libraries with granular permission management, version history, metadata columns, and co-authoring in the browser. A department can organize its day-to-day work into a shared space, with files secured by SharePoint permission inheritance and integrated with OneDrive and Microsoft Teams. This makes SharePoint Online the Microsoft 365 service best suited for the department’s collaboration and content management requirement.

Why this answer

SharePoint Online is the correct choice because it provides document libraries with built-in version history, allowing users to track, restore, and manage previous versions of documents without any custom scripting. This service is designed for collaborative document management and meets the requirement of avoiding custom operational scripts.

Exam trap

The trap here is that candidates may confuse Microsoft Purview Compliance Manager with document management features due to its 'compliance' name, but it lacks document library and versioning capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a compliance management solution for assessing and managing regulatory risks, not a document library service with version history. Option C is wrong because Microsoft Entra Privileged Identity Management is an identity governance tool for managing, controlling, and monitoring access to privileged roles, not for document storage or versioning. Option D is wrong because Microsoft Defender for Endpoint is a security solution for endpoint protection, detection, and response, not a document management service with version history.

760
MCQeasy

A sales team wants to use an AI-powered assistant that can draft email replies directly in Outlook using customer data from Dynamics 365. Which Microsoft 365 capability should the admin enable?

A.Microsoft 365 Copilot
B.Microsoft Viva Insights
C.Microsoft Editor
D.Microsoft Power Automate
AnswerA

Microsoft 365 Copilot is an AI-powered assistant embedded across M365 apps, including Outlook. It leverages the Microsoft Graph and user context, and can pull Customer Insights or Dynamics 365 sales data directly into email drafts, generating personalized, grammatically correct email content without manual template creation. It is specifically designed to augment user productivity with generative AI, not just correct or automate existing content.

Why this answer

Microsoft 365 Copilot is the correct answer because it integrates AI-powered assistance directly into Outlook, using data from Dynamics 365 to draft email replies. This capability leverages large language models and the Microsoft Graph to access customer context, enabling personalized and context-aware email composition without leaving the Outlook interface.

Exam trap

The trap here is that candidates may confuse Microsoft Editor's grammar and style suggestions with AI-powered content generation, or assume Power Automate can handle the drafting task, but neither provides the integrated, context-aware email drafting from Dynamics 365 data that Copilot uniquely offers.

How to eliminate wrong answers

Option B is wrong because Microsoft Viva Insights focuses on workplace analytics and productivity insights, such as focus time and wellbeing, not on drafting emails with customer data. Option C is wrong because Microsoft Editor provides grammar, spelling, and style suggestions in documents and emails, but it does not use AI to generate replies based on external data sources like Dynamics 365. Option D is wrong because Microsoft Power Automate is a workflow automation tool that can trigger actions based on events, but it does not natively provide an AI-powered assistant for drafting email replies within Outlook.

761
MCQhard

A global organization with 20,000 users is running Microsoft 365 E5 licenses. Due to budget cuts, the CIO wants to reduce licensing costs by 20% while ensuring that all users still have access to Exchange Online, SharePoint, Teams, and OneDrive. The organization also needs to maintain compliance with industry regulations that require eDiscovery and retention policies. The security team is willing to give up advanced threat protection features like Microsoft Defender for Office 365 P2 and Microsoft Purview Data Loss Prevention. Which licensing strategy should the organization adopt?

A.Downgrade all users to Microsoft 365 E3
B.Switch to Microsoft 365 F3 for all users
C.Keep E5 but remove all add-on licenses
D.Switch to Microsoft 365 Business Premium for all users
AnswerA

Microsoft 365 E3 is the correct licensing tier for a 20,000-user organization that requires enterprise-grade compliance without the premium security features of E5. It includes Exchange Online, SharePoint Online, Teams, OneDrive, as well as eDiscovery (Content Search) and retention policy capabilities that meet standard regulatory requirements. While E5 adds advanced threat protection and analytics, E3 provides the necessary workloads and compliance tools at a lower per-user cost, making it the optimal cost-saving choice without sacrificing required functionality.

Why this answer

Microsoft 365 E3 includes Exchange Online, SharePoint, Teams, and OneDrive, and provides eDiscovery and retention policies via Microsoft Purview compliance features. Downgrading from E5 to E3 reduces licensing costs by approximately 20-30% per user while retaining the required core productivity and compliance capabilities, and removes advanced threat protection (Defender for Office 365 P2, DLP) that the security team is willing to give up.

Exam trap

The trap here is that candidates may assume E5 is required for compliance features, but Microsoft 365 E3 includes the necessary eDiscovery and retention policies, and the question explicitly states the security team is willing to give up advanced threat protection, making E3 the correct cost-saving choice.

How to eliminate wrong answers

Option B is wrong because Microsoft 365 F3 is a frontline worker plan that lacks full desktop versions of Office apps and has limited compliance features (e.g., no eDiscovery or retention policies at the same level as E3/E5), and it does not include Exchange Online with full mailbox capabilities for all 20,000 users. Option C is wrong because E5 licenses inherently include all E5 features; removing add-on licenses does not change the base E5 license cost, so it would not achieve the 20% cost reduction. Option D is wrong because Microsoft 365 Business Premium is designed for organizations with up to 300 users, not 20,000 users, and it lacks the enterprise-level compliance and eDiscovery capabilities required for industry regulations.

762
MCQmedium

A charitable organization with 50 employees wants to use Microsoft 365 for email and collaboration but has a very limited budget. What should they do first to obtain licenses at a reduced cost?

A.Purchase Microsoft 365 Business Basic licenses
B.Apply for Microsoft 365 Nonprofit eligibility
C.Use the free web versions of Office apps
D.Purchase Microsoft 365 E3 licenses
AnswerB

Applying for Microsoft 365 Nonprofit eligibility is the correct first action because Microsoft requires charitable organizations to undergo a verification process before granting donated or highly discounted plans. A 50-employee nonprofit can then qualify for offers such as a free Business Basic license per user or substantial discounts on enterprise products, ultimately meeting their business productivity and email needs at minimal expense.

Why this answer

Microsoft offers substantial nonprofit discounts (often free or heavily reduced Microsoft 365 Business Basic/E3 grants) to eligible charitable organizations through the Microsoft Nonprofit program. Before purchasing any licenses, the organization must first apply and be validated as an eligible nonprofit via Microsoft's partner (typically TechSoup). Only after eligibility is confirmed can they obtain the reduced-cost or donated licenses.

Exam trap

MS-900 often tests the sequence of steps for nonprofit licensing, tricking candidates into picking a specific license SKU when the question is really asking about the prerequisite eligibility application.

How to eliminate wrong answers

Option A is wrong because purchasing Business Basic at commercial retail pricing ignores the nonprofit discount that would dramatically reduce cost — the question asks what to do FIRST, and eligibility must be established before buying. Option C is wrong because free web versions of Office apps do not provide the full email, Teams, and collaboration capabilities of Microsoft 365 and do not address the licensing requirement. Option D is wrong because E3 is the most expensive enterprise tier and would be the worst budget choice, especially without first applying for nonprofit pricing.

763
MCQhard

A global organization uses Microsoft 365 E5 and needs to securely share sensitive documents with external partners. The compliance officer requires that external users can view but not edit, print, or forward the documents, and access must expire after 30 days. Which combination of services should the admin use?

A.SharePoint Online External Sharing and Microsoft Entra B2B
B.Microsoft Purview Information Protection with sensitivity labels and SharePoint Online
C.Microsoft Entra B2B collaboration with Conditional Access
D.Microsoft Teams with guest access and sharing permissions
AnswerB

Microsoft Purview Information Protection with sensitivity labels provides the actual protection layer: labels can be configured to apply encryption, set permissions such as View-only, disable printing and copying, and attach expiration dates to the document itself. SharePoint Online then hosts the protected file and enforces these label-based restrictions when the document is opened through Office apps or the web, including for external guests. This combination directly satisfies the requirement to allow viewing only, prevent downloads/prints/forwards, and enforce an automatic access expiration, making it the correct solution.

Why this answer

Microsoft Purview Information Protection with sensitivity labels can enforce 'View Only' permissions that prevent editing, printing, and forwarding, while SharePoint Online allows setting an expiration date for external access via sharing links. Together, they meet the compliance officer's requirements for granular document-level restrictions and time-bound access.

Exam trap

The trap here is that candidates confuse external sharing controls (like B2B or guest access) with document-level protection, assuming that any external sharing mechanism can enforce granular usage restrictions, but only sensitivity labels with Azure RMS can apply 'View Only' and expiration at the file level.

How to eliminate wrong answers

Option A is wrong because SharePoint Online External Sharing and Microsoft Entra B2B control access at the site or folder level, not at the document level, and cannot enforce 'View Only' restrictions that block printing or forwarding. Option C is wrong because Microsoft Entra B2B collaboration with Conditional Access controls authentication and device compliance but does not apply document-level usage restrictions like preventing print or forward. Option D is wrong because Microsoft Teams with guest access and sharing permissions provides only coarse-grained controls (e.g., read/write) and lacks the ability to set document-level 'View Only' permissions or an expiration date on individual files.

764
MCQmedium

A security administrator at Contoso wants to ensure that users can only access Microsoft 365 services from compliant devices that meet specific security requirements, such as having encryption enabled and a minimum OS version. Which Microsoft 365 feature should the administrator use?

A.Microsoft Defender for Endpoint device groups
B.Exchange Online mobile device mailbox policies
C.Conditional Access policies with device compliance
D.Microsoft Purview Data Loss Prevention device policies
AnswerC

Conditional Access policies can integrate with Microsoft Intune device compliance policies to allow access only from devices that meet specific security requirements. This ensures that devices are compliant with encryption, OS version, and other conditions before granting access to Microsoft 365 services.

Why this answer

Conditional Access policies with device compliance allow administrators to require that devices meet specific security conditions before accessing Microsoft 365 services. This is achieved by integrating with Microsoft Intune, which evaluates device compliance and reports the status to Microsoft Entra ID. This feature directly addresses the requirement to restrict access to compliant devices.

Exam trap

The trap here is confusing device management or DLP features with access control, assuming that any device-related policy can enforce compliance for Microsoft 365 access.

765
MCQmedium

A help desk lead is documenting the correct Microsoft 365 approach to preserve relevant mailboxes and SharePoint content during a legal case. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Stream
B.Microsoft Forms
C.Microsoft Planner
D.Microsoft Purview eDiscovery hold
AnswerD

Microsoft Purview eDiscovery hold preserves mailbox and SharePoint content in place, satisfying the legal-case retention constraint without altering user access. Unlike litigation hold applied per mailbox, an eDiscovery hold spans Exchange, SharePoint, and Teams through a single case, keeping custodian data immutable for review.

Why this answer

Microsoft Purview eDiscovery hold is the correct capability because it allows organizations to place legal holds on mailboxes, SharePoint sites, and other content sources to preserve data relevant to a legal case. This ensures that content cannot be altered or deleted until the hold is released, meeting compliance and eDiscovery requirements.

Exam trap

The trap here is that candidates may confuse general productivity tools like Stream, Forms, or Planner with compliance capabilities, mistakenly thinking they can be used for legal preservation when they lack the necessary retention and hold features.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video hosting and sharing service, not designed for legal hold or content preservation. Option B is wrong because Microsoft Forms is used for creating surveys and quizzes, with no capability to place holds on mailboxes or SharePoint content. Option C is wrong because Microsoft Planner is a task management tool for organizing work, lacking any compliance or eDiscovery hold functionality.

766
MCQhard

During requirements gathering, an IT manager says the organization must compare service models and identify where the customer manages the most layers. Cloud concept or benefit best matches this requirement?

A.Platform as a Service (PaaS)
B.Software as a Service (SaaS)
C.Infrastructure as a Service (IaaS)
D.Hybrid cloud
AnswerC

IaaS leaves the customer managing the most layers: operating systems, runtime, middleware, applications and data, while the provider handles virtualisation, servers, storage and networking. This matches the requirement to identify the service model with the greatest customer management responsibility.

Why this answer

The IT manager's requirement is to identify the service model where the customer manages the most layers. In Infrastructure as a Service (IaaS), the cloud provider manages only the physical infrastructure (servers, storage, networking), while the customer is responsible for managing the operating system, middleware, runtime, data, and applications. This gives the customer the highest degree of control and management responsibility compared to PaaS or SaaS.

Exam trap

The trap here is that candidates often confuse 'most management' with 'most convenience,' incorrectly selecting PaaS or SaaS because they assume more provider management is the goal, whereas the question explicitly asks for the model where the customer manages the most layers.

How to eliminate wrong answers

Option A is wrong because Platform as a Service (PaaS) offloads management of the operating system, middleware, and runtime to the provider, leaving the customer to manage only applications and data — fewer layers than IaaS. Option B is wrong because Software as a Service (SaaS) shifts nearly all management to the provider, with the customer typically only managing user access and data — the fewest layers of any cloud service model. Option D is wrong because hybrid cloud is a deployment model (combining public and private cloud), not a service model, and does not define which layers the customer manages; it is irrelevant to the specific requirement of comparing service models by management responsibility.

767
MCQmedium

An administrator is reviewing a request from users who need to create a team site with document libraries, version history, permissions, and news pages. Microsoft 365 app or service is the best fit?

A.SharePoint Online
B.Microsoft Forms
C.Microsoft Planner
D.Microsoft Purview Audit
AnswerA

SharePoint Online is the correct Microsoft 365 service for creating a team site because it provides team sites as first-class containers with document libraries, lists, pages, news, and permission management. A modern SharePoint team site is typically connected to a Microsoft 365 group, enabling shared calendar, mailbox, and memberships, while site features like version history, co-authoring, and granular sharing controls support day-to-day collaboration. No other option in the list provisions a site infrastructure with these capabilities.

Why this answer

SharePoint Online is the correct choice because it provides team sites with document libraries, version history, granular permissions, and news pages as core features. These capabilities are built into SharePoint's site architecture, allowing administrators to create collaboration spaces with full control over content management and access.

Exam trap

The trap here is that candidates may confuse Microsoft Planner's task boards with a team site's document management features, or assume Microsoft Forms can create news pages, when in fact only SharePoint Online provides the full suite of document libraries, versioning, permissions, and news pages required for this scenario.

How to eliminate wrong answers

Option B is wrong because Microsoft Forms is a survey and quiz tool that collects responses via forms, not a platform for creating team sites with document libraries, version history, permissions, or news pages. Option C is wrong because Microsoft Planner is a task management application for organizing work with boards and buckets, lacking document libraries, version history, and news page capabilities. Option D is wrong because Microsoft Purview Audit is a compliance and auditing solution for tracking user and admin activities across Microsoft 365, not a service for building collaborative team sites or managing content.

768
Drag & Dropmedium

Drag and drop the steps to reset a user's password in Microsoft 365 admin center into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order to reset a user's password in Microsoft 365 admin center is to first navigate to Users > Active users, then select the user, click Reset password, and finally enter and confirm the new password. This sequence ensures the proper workflow for password management.

769
MCQmedium

A compliance-aware administrator is selecting the right Microsoft 365 capability to encrypt email messages sent to internal or external recipients. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Stream
B.Microsoft Purview Message Encryption
C.Microsoft Planner
D.Microsoft Forms
AnswerB

Microsoft Purview Message Encryption applies encryption to email in transit, letting senders protect messages to internal or external recipients. It satisfies the compliance requirement by enforcing encryption at the message level without relying on recipient-side configuration.

Why this answer

Microsoft Purview Message Encryption (B) is the correct choice because it is the dedicated Microsoft 365 service that provides encryption for email messages sent to both internal and external recipients. It leverages Azure Rights Management (Azure RMS) to protect messages, ensuring only intended recipients can decrypt and read them, which directly meets the compliance requirement for email encryption.

Exam trap

The trap here is that candidates might confuse Microsoft Purview Message Encryption with other Microsoft 365 security features like Microsoft Defender for Office 365 or Azure Information Protection, but the question specifically asks for an email encryption capability, not a broader security or compliance tool.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video sharing and management service, not an email encryption capability. Option C is wrong because Microsoft Planner is a task management and collaboration tool, unrelated to email security or encryption. Option D is wrong because Microsoft Forms is used for creating surveys and quizzes, and does not provide any email encryption functionality.

770
MCQmedium

A service owner is comparing Microsoft 365 capabilities and needs to give different departments different Microsoft 365 features without wasting licenses. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Assign plans based on user role and requirements
B.Microsoft Whiteboard
C.Microsoft Forms
D.Microsoft Stream
AnswerA

Assign plans based on user role and requirements is correct because Microsoft 365 licensing is role-aligned. Administrators must select the appropriate subscription tier (e.g., Microsoft 365 F3, E3, or E5) that matches each user's job function, ensuring they receive the necessary features without overspending. This is accomplished through the Microsoft 365 admin center or group-based licensing, making it the proper administrative capability for this scenario.

Why this answer

The service owner needs to assign Microsoft 365 licenses efficiently by matching features to departmental roles. The concept of assigning plans based on user role and requirements (Option A) directly addresses this by using Azure AD group-based licensing or direct assignment to ensure each user gets only the necessary SKU (e.g., E3 for knowledge workers, F3 for frontline), avoiding waste. This is the core licensing principle for cost optimization in Microsoft 365.

Exam trap

The trap here is that candidates confuse specific Microsoft 365 applications (like Whiteboard, Forms, or Stream) with licensing concepts, failing to recognize that the question asks for the most relevant licensing, admin, or support concept, not a feature.

How to eliminate wrong answers

Option B (Microsoft Whiteboard) is wrong because it is a specific application, not a licensing, admin, or support concept; it cannot address the strategic need to allocate different features across departments. Option C (Microsoft Forms) is wrong because it is a survey tool, not a licensing or administration concept; it does not help in assigning or managing license plans. Option D (Microsoft Stream) is wrong because it is a video service, not a licensing or support concept; it is irrelevant to the task of matching features to user roles without wasting licenses.

771
MCQmedium

A company currently has Microsoft 365 E5 licenses for all users. They need to perform advanced threat hunting using queries across email, endpoints, and identities to investigate a potential security incident. Which of the following capabilities is already included in their existing license?

A.Microsoft Defender for Microsoft 365 Plan 1
B.Microsoft Entra ID Premium P1
C.Microsoft 365 Defender (including advanced hunting)
D.Microsoft Cloud App Security
AnswerC

Microsoft 365 Defender (including advanced hunting) is the correct choice because E5 includes the full unified security operations experience, enabling investigators to use KQL to query over email, endpoints, identities, and applications in one portal. Advanced hunting allows proactive, multi-domain searches for indicators of compromise, exactly what is needed when hunting for a cross-domain attack. This capability is exclusive to the combined Microsoft 365 Defender product, not to individual add-ons.

Why this answer

Microsoft 365 Defender (formerly Microsoft Threat Protection) includes advanced hunting capabilities that allow security teams to run Kusto Query Language (KQL) queries across email, endpoints, identities, and cloud apps. Since the company already has Microsoft 365 E5 licenses, this capability is included without any additional purchase.

Exam trap

The trap here is that candidates often confuse Microsoft 365 Defender (the unified security suite) with its individual component plans (e.g., Defender for Office 365 Plan 1 or Plan 2), not realizing that advanced hunting is a feature of the full Microsoft 365 Defender included in E5, not a separate add-on.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Microsoft 365 Plan 1 is a subset of the full Microsoft 365 Defender and does not include advanced hunting; advanced hunting is only available in Plan 2 or the full Microsoft 365 Defender included in E5. Option B is wrong because Microsoft Entra ID Premium P1 provides identity and access management features like Conditional Access but does not include advanced threat hunting across email, endpoints, and identities. Option D is wrong because Microsoft Cloud App Security (now part of Microsoft Defender for Cloud Apps) provides cloud app discovery and data protection but does not include the unified advanced hunting query capability across email and endpoints that Microsoft 365 Defender provides.

772
Multi-Selectmedium

Which TWO of the following are key capabilities of Microsoft Purview Communication Compliance? (Choose two.)

Select 2 answers
A.Detect and respond to inappropriate messages
B.Enforce multifactor authentication
C.Configure retention labels
D.Monitor communications for regulatory compliance
E.Block external email forwarding
AnswersA, D

Communication Compliance uses machine-learning classifiers and keyword policies to surface inappropriate messages such as harassment or threats, then routes them to reviewers for remediation. This satisfies the capability requirement by detecting and responding to policy-violating communications across Microsoft 365 channels.

Why this answer

Option A is correct because Microsoft Purview Communication Compliance is specifically designed to detect potentially inappropriate, harassing, or offensive messages across channels like Teams, Exchange, and Viva Engage, and to let reviewers investigate and remediate them with actions such as tagging, notifying, or escalating. Option D is correct because the same solution supports regulatory compliance use cases by monitoring communications for policy violations tied to regulations (for example, FINRA, HIPAA, or insider trading), using trainable classifiers, sensitive information types, and review workflows. Option B is not a capability of Communication Compliance; multifactor authentication is enforced through Microsoft Entra ID (Conditional Access / authentication methods), not through communication monitoring policies.

Option C is not part of Communication Compliance; retention labels are configured in Microsoft Purview Data Lifecycle Management / Records Management to govern how long content is kept. Option E is not a Communication Compliance feature; blocking external email forwarding is handled by Exchange Online transport rules, Defender for Office 365 anti-spam/anti-phishing policies, or DLP, not by Communication Compliance's detection-and-review model.

Exam trap

MS-900 often tests whether candidates can distinguish Purview's many sub-solutions — Communication Compliance is frequently confused with Data Lifecycle Management (retention) or Insider Risk Management, so candidates must map each capability to the correct workload.

773
MCQmedium

A service owner is comparing Microsoft 365 capabilities and needs to detect exact customer records rather than only generic data patterns. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Stream
B.Microsoft Planner
C.Exact Data Match sensitive information type
D.Microsoft Forms
AnswerC

Exact Data Match (EDM) sensitive information types are custom-defined types in Microsoft Purview that let you detect highly structured sensitive data using a database of exact values. EDM hashes the values in your schema-based database and compares them to hashed tokens in scanned content, enabling precise detection with minimal false positives. This is essential when built-in sensitive information types rely on patterns or checksums but cannot guarantee an exact match. By uploading a structured data set, you can reliably identify sensitive records, which meets the requirement.

Why this answer

Exact Data Match (EDM) sensitive information types allow a service owner to define custom sensitive information types based on exact database records, such as customer names or account numbers, rather than relying on generic pattern matching like regular expressions. This capability is part of Microsoft Purview compliance and enables precise detection of specific customer data in Microsoft 365 environments.

Exam trap

The trap here is that candidates may confuse generic data classification (e.g., built-in sensitive info types like Social Security numbers) with the need for exact record matching, leading them to overlook EDM as the precise solution for custom, database-driven detection.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video sharing and management service, not a security, identity, or compliance capability for detecting exact customer records. Option B is wrong because Microsoft Planner is a project management and task tracking tool, lacking any data classification or exact match detection features. Option D is wrong because Microsoft Forms is a survey and form creation tool, not designed for sensitive information detection or exact data matching.

774
Multi-Selecteasy

Which TWO Microsoft 365 apps include AI-powered features that can summarize email threads and documents? (Select two.)

Select 2 answers
A.Microsoft Outlook
B.Microsoft Excel
C.Microsoft OneNote
D.Microsoft PowerPoint
E.Microsoft Word
AnswersA, E

Outlook Copilot uses natural language processing to summarize email threads, condensing lengthy conversations into key points, action items, and pending decisions directly within the app. This native AI-powered summarization of existing textual content is exactly what the question asks for, making Outlook a correct choice.

Why this answer

Microsoft Outlook (A) is correct because its AI-powered features, such as Microsoft Copilot in Outlook, can summarize long email threads and generate concise recaps directly within the mailbox. Microsoft Word (E) is correct because Copilot in Word can summarize lengthy documents, producing key points and overviews of the file's content. Excel (B) focuses on data analysis, formulas, and spreadsheet insights rather than email or document summarization, so it does not fit.

OneNote (C) is a note-taking app and does not provide the specified email-thread and document summarization features. PowerPoint (D) is designed for creating and summarizing presentations, not email threads or general documents, so it is not one of the two correct answers.

Exam trap

The MS-900 exam often tests the misconception that all Office apps have the same AI capabilities, leading candidates to select Excel or PowerPoint because they assume 'AI' means any smart feature, but the question specifically requires summarization of email threads and documents.

775
MCQeasy

A company runs its customer relationship management (CRM) system using a cloud provider's SaaS offering. They also use virtual machines (IaaS) from the same provider to host a legacy application. In this scenario, who is responsible for patching the operating system of the virtual machines?

A.The cloud provider is fully responsible for patching all components.
B.The customer is responsible for patching the operating system of the virtual machines.
C.The cloud provider patches the OS for all services equally.
D.No patching is needed because the cloud handles everything.
AnswerB

This is the correct statement for an IaaS virtual machine. Because the customer provisions and controls the VM, they are accountable for the guest operating system and must apply patches, including critical security updates, to that OS. The provider manages the underlying physical hosts and the hypervisor, but does not access or modify the guest OS unless the customer explicitly enables a management or patching service. Therefore, the customer must have an ongoing patching process for the VM's operating system to maintain security and compliance.

Why this answer

In an IaaS model, the cloud provider is responsible for the security of the physical infrastructure, hypervisor, and network, but the customer retains responsibility for the guest operating system and applications. Since the virtual machines are IaaS resources, the customer must manage OS patches, updates, and configuration. This follows the shared responsibility model, where the customer is accountable for anything they configure or deploy within the virtual machine.

Exam trap

The trap here is that candidates confuse the IaaS model with SaaS, assuming the cloud provider patches everything, but Microsoft explicitly tests the shared responsibility model where the customer patches the OS in IaaS.

How to eliminate wrong answers

Option A is wrong because the cloud provider is not fully responsible for patching all components; in IaaS, the customer patches the OS and applications. Option C is wrong because the cloud provider does not patch the OS for all services equally; for SaaS, the provider patches the OS, but for IaaS, the customer does. Option D is wrong because patching is absolutely needed; the cloud does not handle OS-level patching for IaaS resources, and unpatched systems are vulnerable to exploits.

776
MCQmedium

During a Microsoft 365 planning workshop, view service health and create support requests without broad user management. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Microsoft Forms
C.Microsoft Whiteboard
D.Service Support Administrator
AnswerD

The Service Support Administrator role grants permissions to view service health dashboards and open support requests in the Microsoft 365 admin centre, without the broad user and licence management rights of Global Administrator. This matches the workshop requirement precisely.

Why this answer

The Service Support Administrator role in Microsoft 365 is specifically designed to allow users to view service health and create support requests without granting broader user management permissions. This role is part of the least-privilege administrative model, enabling helpdesk or support staff to monitor service incidents and open tickets via the Microsoft 365 admin center or the Microsoft 365 admin mobile app, while being restricted from modifying users, licenses, or other administrative settings.

Exam trap

The trap here is that candidates often confuse the Service Support Administrator role with the Helpdesk Administrator role, which also can create support requests but additionally has broader user management capabilities (e.g., resetting passwords), leading to an incorrect choice if they don't carefully read the requirement for 'without broad user management.'

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video service for uploading, sharing, and managing enterprise videos; it does not provide any administrative capabilities for viewing service health or creating support requests. Option B is wrong because Microsoft Forms is a survey and quiz creation tool; it has no role in service health monitoring or support ticket management. Option C is wrong because Microsoft Whiteboard is a digital canvas for collaboration; it lacks any administrative or support functionality related to service health or support requests.

777
MCQmedium

Your organization uses Microsoft Purview to manage data governance. A data owner needs to classify sensitive data across SharePoint, OneDrive, and Exchange automatically based on content patterns. Which Microsoft Purview feature should they use?

A.Sensitivity labels with auto-labeling
B.eDiscovery (Premium)
C.Data Loss Prevention (DLP) policies
D.Audit (Standard)
AnswerA

Auto-labelling sensitivity labels scan content across SharePoint, OneDrive and Exchange using pattern matching, applying classification automatically without manual intervention. This satisfies the requirement to classify sensitive data based on content patterns across all three workloads, which manual labelling cannot achieve at scale.

Why this answer

Sensitivity labels with auto-labeling in Microsoft Purview are designed to automatically classify and label content based on sensitive information types (SITs) or trainable classifiers. They apply across SharePoint, OneDrive, and Exchange, matching content patterns to detect sensitive data. This is the correct feature for automatic classification based on content patterns.

Exam trap

MS-900 often tests the confusion between DLP policies (which protect) and sensitivity labels (which classify and protect), causing candidates to pick DLP when the question asks for classification.

How to eliminate wrong answers

Option B is wrong because eDiscovery (Premium) is used for identifying, collecting, and reviewing content for legal cases, not for automatic classification. Option C is wrong because DLP policies enforce protection actions (block, encrypt) based on sensitive info, but they do not classify or label content; they rely on existing labels or SITs. Option D is wrong because Audit (Standard) only logs user and admin activities, it does not classify data.

778
MCQeasy

Your organization uses Microsoft 365 and wants to automatically scale resources based on demand, paying only for what is used. Which cloud characteristic does this describe?

A.Fault tolerance
B.Disaster recovery
C.High availability
D.Elasticity
AnswerD

Elasticity matches the stem's demand-based scaling requirement: resources expand or contract automatically as workload fluctuates. Unlike vertical scaling, which resizes a single resource, elasticity adds or removes instances horizontally. Consumption-based billing then charges only for what is used, satisfying both stated constraints.

Why this answer

Elasticity is the cloud characteristic that allows resources to automatically scale based on demand, paying only for what is used. This matches the requirement to scale resources automatically and pay only for consumption.

Exam trap

The trap is confusing elasticity with high availability or scalability; candidates may pick high availability because it sounds like the system is always available, but elasticity specifically addresses automatic scaling and pay-per-use.

How to eliminate wrong answers

Option A is wrong because fault tolerance refers to the ability to continue operating despite component failures, not scaling. Option B is wrong because disaster recovery is about recovering from major outages, not dynamic scaling. Option C is wrong because high availability ensures uptime, but does not imply automatic scaling or pay-per-use.

779
MCQmedium

A hospital uses Microsoft 365 E5 and needs to ensure that patient health information (PHI) is not accidentally shared externally. They want to block sharing of emails containing credit card numbers or medical record numbers. Which Microsoft Purview feature should they configure?

A.Microsoft Purview Privileged Access Management
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Sensitivity Labels
D.Microsoft Purview Information Barriers
AnswerB

Microsoft Purview Data Loss Prevention (DLP) uses configurable policies to scan messages and files for sensitive information types such as HIPAA-specific identifiers, medical record numbers, and diagnosis codes, and then automatically blocks or restricts the sharing of those items. In a healthcare tenant, a DLP policy can be applied to Exchange, SharePoint, OneDrive, Teams, and endpoints so that any attempt to email or upload PHI to an unapproved external domain triggers a block action, encryption, or a policy tip to the user. This provides the proactive, content-based control needed to prevent patient data from leaving the hospital.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct feature because it is specifically designed to detect and block the accidental sharing of sensitive data, such as credit card numbers and medical record numbers, via email. DLP uses deep content analysis with built-in sensitive information types (e.g., Credit Card Number, U.S. Medical Record Number) to scan emails and enforce policies that prevent external sharing.

This directly addresses the hospital's requirement to protect PHI from being leaked externally.

Exam trap

The trap here is that candidates often confuse Sensitivity Labels with DLP, not realizing that labels are for classification and protection (e.g., encryption), while DLP is the enforcement engine that scans content and blocks sharing based on those labels or built-in sensitive data types.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Privileged Access Management (PAM) provides just-in-time access control for elevated administrative tasks, not content inspection or blocking of sensitive data in emails. Option C is wrong because Sensitivity Labels are used to classify and protect data with encryption and visual markings, but they do not automatically scan and block sharing of specific data patterns like credit card numbers or medical record numbers without a DLP policy to enforce actions. Option D is wrong because Information Barriers are designed to restrict communication and collaboration between specific groups (e.g., to prevent conflicts of interest), not to scan email content for sensitive data patterns or block external sharing.

780
MCQeasy

A compliance officer needs to automatically retain all emails in Exchange Online for exactly 7 years, and then permanently delete them. Which Microsoft Purview solution should they configure?

A.Data Loss Prevention (DLP) policy
B.Retention policy
C.Sensitivity label
D.eDiscovery case
AnswerB

Retention policies in Microsoft Purview are the correct answer because they are purpose-built to automatically retain content for a specified duration and then optionally delete it, directly satisfying the compliance officer's need. You can apply a retention policy to Exchange mailboxes, and it works at the item level, ensuring every email is retained for the configured period. These policies support both adaptive and static scopes and can be set to keep items indefinitely or for a specific number of days, making them ideal for regulatory compliance.

Why this answer

A retention policy in Microsoft Purview is designed to retain data for a specified period and then automatically delete it. By configuring a retention policy with a retention period of 7 years and an action to permanently delete the content at the end of that period, the compliance officer can meet the requirement for Exchange Online emails. This policy applies at the mailbox level and ensures that all emails are retained for exactly 7 years before being irreversibly removed.

Exam trap

The trap here is that candidates often confuse retention policies (which automate lifecycle management) with DLP policies (which prevent data leaks) or sensitivity labels (which classify data), leading them to select an option that addresses a different compliance goal.

How to eliminate wrong answers

Option A is wrong because a Data Loss Prevention (DLP) policy is used to detect and prevent the sharing of sensitive information (e.g., credit card numbers) via rules and actions like blocking or warning, not to enforce time-based retention and deletion. Option C is wrong because a sensitivity label is used to classify and protect data based on sensitivity (e.g., encryption, visual markings), and while it can be part of a retention label, it does not independently enforce a fixed retention and deletion schedule without being published as a retention label policy. Option D is wrong because an eDiscovery case is used for legal holds and content searches for litigation or investigation purposes, not for automated, scheduled retention and deletion of all emails.

781
MCQeasy

A small business with 25 employees wants to purchase Microsoft 365 Business Standard licenses through a Cloud Solution Provider (CSP) partner. How will the billing be handled?

A.The customer pays Microsoft directly via credit card, and the CSP partner receives a commission.
B.The customer receives a quarterly invoice from Microsoft and pays the CSP partner a separate service fee.
C.The CSP partner bills the customer directly, and the customer pays the partner.
D.Microsoft bills the customer directly on a monthly basis.
AnswerC

In the CSP model, the partner is responsible for billing the customer and managing the subscription. The customer pays the CSP partner, who then handles payment to Microsoft. This allows the customer to have a single point of contact for billing and support.

Why this answer

When purchasing Microsoft 365 through a Cloud Solution Provider (CSP), the CSP partner is responsible for billing the customer. The customer pays the partner, and the partner manages the subscription and support. Microsoft does not bill the customer directly in this model.

This simplifies billing for the customer and allows the partner to add value-added services.

Exam trap

The trap here is assuming Microsoft always bills the customer directly, but in CSP the partner handles billing.

782
MCQmedium

An organization uses Microsoft 365 and wants to automatically classify and protect sensitive data in SharePoint Online based on content patterns. Which Microsoft Purview solution should they implement?

A.Auto-labeling policies
B.Retention policies
C.Data Loss Prevention (DLP) policies
D.Trainable classifiers
AnswerA

Auto-labeling policies in Microsoft Purview scan SharePoint Online content using pattern-based rules, such as regex or sensitive information types, then apply sensitivity labels automatically. This satisfies the requirement to classify and protect data based on content patterns without manual intervention, unlike manual labelling or DLP policies that only alert or block.

Why this answer

Auto-labeling policies in Microsoft Purview can automatically apply sensitivity labels to documents in SharePoint Online based on sensitive information types or patterns, classifying and protecting data without manual intervention. Option B (Retention policies) is incorrect because they manage data retention and deletion, not classification. Option C (DLP policies) is incorrect because they detect and prevent data loss but do not automatically classify content.

Option D (Trainable classifiers) is incorrect because they use AI to identify content based on examples, not automatic pattern-based classification.

783
MCQeasy

A marketing team needs to collaboratively create and edit documents in real time, share files securely, and track version history. Which Microsoft 365 service should they primarily use?

A.Microsoft Teams
B.OneDrive for Business
C.SharePoint Online
D.Microsoft Viva Engage
AnswerC

SharePoint Online is the correct choice because it provides team sites with document libraries designed for collaborative content creation and editing at scale. Its capabilities include real-time co-authoring, version history, check-in/check-out, and fine-grained permission management, all of which are essential for a marketing team working on shared assets. SharePoint serves as the central file repository for Microsoft 365, powering file collaboration across Teams and other apps.

Why this answer

SharePoint Online is the correct choice because it is designed for team collaboration with real-time co-authoring, granular permission-based file sharing, and built-in version history that tracks every change. Unlike OneDrive, which is optimized for individual file storage and sharing, SharePoint provides a centralized team site where multiple users can simultaneously edit documents and manage versions at the site or library level.

Exam trap

The trap here is that candidates often confuse OneDrive for Business with SharePoint Online because both offer real-time co-authoring and version history, but the question specifies a team needing collaborative creation and secure sharing, which is the defining use case for SharePoint's team sites rather than OneDrive's personal storage.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is a chat-based collaboration hub that integrates with SharePoint for file storage, but its primary function is communication and meetings, not native document co-authoring and version history management. Option B is wrong because OneDrive for Business is a personal cloud storage service that supports real-time co-authoring and version history for individual files, but it lacks the team-centric site structure, metadata, and permission inheritance needed for a marketing team to collaboratively manage documents as a group. Option D is wrong because Microsoft Viva Engage (formerly Yammer) is an enterprise social networking tool focused on community discussions and knowledge sharing, not document creation, real-time editing, or version control.

784
MCQmedium

A company with 50 users currently has Microsoft 365 Business Standard licenses. They face new compliance regulations that require automatic data classification and retention policies across all Microsoft 365 workloads. They want to add these capabilities without replacing their existing licenses, and they want to minimize costs. What is the most cost-effective licensing strategy?

A.Add Microsoft 365 E5 Compliance add-on for all users
B.Upgrade all users to Microsoft 365 E5
C.Upgrade all users to Microsoft 365 Business Premium
D.Add Microsoft 365 E5 Security add-on for all users
AnswerA

Purchasing the Microsoft 365 E5 Compliance add-on as a per-user license directly addresses the requirement for advanced compliance capabilities without changing the organization's existing Microsoft 365 Business Standard base plan. This add-on provides data classification with auto-labeling, retention and lifecycle management, advanced eDiscovery, and Compliance Manager. It is the most cost-effective, targeted approach because each user can be licensed only for the compliance workloads they need, rather than forcing a higher-tier enterprise SKU across the entire tenant.

Why this answer

Microsoft 365 E5 Compliance is an add-on that provides advanced compliance features like automatic data classification and retention policies across all Microsoft 365 workloads. Since the company already has Microsoft 365 Business Standard licenses, adding this add-on is the most cost-effective way to meet the new regulatory requirements without replacing existing licenses.

Exam trap

The trap here is that candidates may confuse the E5 Security add-on with the E5 Compliance add-on, assuming security features automatically include compliance capabilities, but they are separate add-ons with distinct feature sets.

How to eliminate wrong answers

Option B is wrong because upgrading all users to Microsoft 365 E5 is significantly more expensive than adding the E5 Compliance add-on, and it includes many features (like advanced security and analytics) that are not required by the compliance regulations. Option C is wrong because Microsoft 365 Business Premium does not include automatic data classification and retention policies across all workloads; it focuses on security and device management, not the advanced compliance capabilities needed. Option D is wrong because Microsoft 365 E5 Security add-on provides security features (e.g., threat protection, identity management) but does not include the compliance-specific capabilities like data classification and retention policies required by the regulations.

785
MCQeasy

Your organization wants to ensure that users can only access Microsoft 365 resources from compliant devices. Which security feature should you implement?

A.Microsoft Entra Conditional Access
B.Microsoft Purview Data Loss Prevention
C.Microsoft Defender for Cloud Apps
D.Microsoft Intune
AnswerA

Microsoft Entra Conditional Access evaluates signals such as device compliance state and enforces access controls, blocking sign-ins from non-compliant devices. This directly satisfies the requirement that users reach Microsoft 365 resources only from compliant devices, which Intune alone cannot enforce at authentication.

Why this answer

Microsoft Entra Conditional Access is the policy engine that evaluates signals such as device compliance state, user risk, location, and application, and then enforces access decisions like requiring a compliant device or MFA. To restrict Microsoft 365 access to compliant devices, you create a Conditional Access policy that requires the device to be marked compliant (a signal Intune provides). Conditional Access is the enforcement point; Intune supplies the compliance signal.

Exam trap

MS-900 often tests the confusion between Intune (which sets compliance state) and Conditional Access (which enforces access based on that state) — candidates pick Intune when the question asks what enforces the restriction.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview DLP focuses on preventing leakage of sensitive information, not on gating access based on device compliance. Option C is wrong because Microsoft Defender for Cloud Apps is a CASB for shadow IT discovery, session controls, and anomaly detection — it does not natively enforce device compliance for M365 sign-ins. Option D is wrong because Microsoft Intune manages device configuration and compliance but does not itself block resource access; it feeds compliance state into Conditional Access, which performs the enforcement.

786
MCQmedium

During requirements gathering, an IT manager says the organization must deploy application code without maintaining the operating system or runtime platform. Cloud concept or benefit best matches this requirement?

A.Private cloud
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Software as a Service (SaaS)
AnswerB

Platform as a Service (PaaS) is correct because it provides an integrated, managed hosting environment that includes the runtime, middleware, database, and underlying servers, allowing developers to focus exclusively on writing and deploying custom application code. The cloud provider handles operating system patching, scaling, and infrastructure maintenance, directly matching the requirement to build a custom app without managing the underlying platform. This is the service model that best fits the stated need.

Why this answer

Platform as a Service (PaaS) is the correct choice because it provides a managed hosting environment where you can deploy your own application code without needing to manage the underlying operating system or runtime platform. The IT manager's requirement explicitly states they want to avoid maintaining the OS and runtime, which is the core value proposition of PaaS. In contrast, IaaS would require them to manage the OS and runtime themselves.

Exam trap

The trap here is that candidates often confuse PaaS with IaaS because both allow custom code deployment, but IaaS requires full OS and runtime management, which directly contradicts the requirement to avoid maintaining those layers.

How to eliminate wrong answers

Option A is wrong because private cloud describes a deployment model (single-tenant, on-premises or hosted) rather than a service model; it does not inherently relieve the organization from managing the OS or runtime. Option C is wrong because Infrastructure as a Service (IaaS) provides virtualized compute, storage, and networking resources, but the customer remains responsible for patching, configuring, and maintaining the operating system and runtime environment. Option D is wrong because Software as a Service (SaaS) delivers fully managed applications to end users, not a platform for deploying custom application code.

787
MCQmedium

A marketing team needs to create a shared workspace to manage projects, store documents, and track tasks. Which Microsoft 365 service should the administrator recommend?

A.SharePoint Online
B.Microsoft Sway
C.Microsoft Bookings
D.Microsoft Stream
AnswerA

SharePoint Online is the correct choice because it provides a true shared workspace via team sites that include document libraries, versioning, and co-authoring for files, as well as integrated Lists and Planner for task tracking. Team site permissions allow granular control over member access, and the site can serve as a central hub for project assets, communications, and status reporting. This makes SharePoint Online purpose-built for collaborative project management, unlike the other listed services.

Why this answer

SharePoint Online is the correct recommendation because it provides a centralized platform for creating team sites that serve as shared workspaces. It includes document libraries for storing and co-authoring files, lists for tracking tasks, and integration with Microsoft Teams and Planner for project management, directly meeting all the stated requirements.

Exam trap

The trap here is that candidates may confuse SharePoint Online with other Microsoft 365 apps like Teams or Planner, but the question specifically asks for a service that combines document storage, task tracking, and a shared workspace, which is the core function of SharePoint Online.

How to eliminate wrong answers

Option B is wrong because Microsoft Sway is a presentation and storytelling app for creating interactive reports and newsletters, not a shared workspace for project management or task tracking. Option C is wrong because Microsoft Bookings is a scheduling tool for managing customer appointments, lacking document storage and task management capabilities. Option D is wrong because Microsoft Stream is a video hosting and sharing service for enterprise video content, not designed for project collaboration or task tracking.

788
MCQhard

A compliance officer needs to ensure that all outgoing emails containing a customer's credit card number are automatically encrypted before delivery. External recipients must be able to reply with the same level of encryption without a separate signing-up process. Which Microsoft Purview solution should be configured?

A.Office 365 Message Encryption (OME) with a DLP policy
B.Sensitivity labels with automatic marking
C.Azure Information Protection (AIP)
D.Microsoft Defender for Office 365
AnswerA

Office 365 Message Encryption (OME) integrated with a Data Loss Prevention (DLP) policy is the standard mechanism for automatically encrypting outgoing emails that contain sensitive data such as credit card numbers. The DLP policy scans outbound messages for specific sensitive info types and, when matched, conditionally modifies the message to apply OME encryption via Azure Rights Management. OME ensures external recipients receive an encrypted email and can authenticate via a secure web portal to read and reply, maintaining end-to-end confidentiality without requiring the recipient to have an M365 license.

Why this answer

Office 365 Message Encryption (OME) with a Data Loss Prevention (DLP) policy is the correct solution because OME provides automatic encryption for emails based on sensitive information types (e.g., credit card numbers) detected by DLP rules. It also supports the 'encrypt-only' option, which allows external recipients to reply with the same level of encryption without requiring a separate sign-up or certificate exchange, leveraging the Microsoft 365 message encryption infrastructure.

Exam trap

The trap here is that candidates often confuse sensitivity labels (Option B) with DLP-based encryption, not realizing that sensitivity labels require explicit configuration for automatic encryption and do not inherently handle reply encryption without additional setup, whereas OME with DLP provides the seamless, policy-driven encryption and reply capability described.

How to eliminate wrong answers

Option B is wrong because sensitivity labels with automatic marking can apply visual markings or encryption, but they do not natively trigger encryption based on DLP-sensitive information types like credit card numbers; they require manual or policy-based labeling and do not inherently enable seamless encrypted replies without recipient sign-up. Option C is wrong because Azure Information Protection (AIP) is a classification and labeling solution that can apply encryption via rights management, but it is not primarily designed for automatic email encryption based on DLP policies and often requires the recipient to have an Azure RMS-enabled client or sign in for decryption. Option D is wrong because Microsoft Defender for Office 365 focuses on threat protection (e.g., anti-phishing, anti-malware, safe attachments) and does not provide automatic email encryption based on content inspection for compliance purposes.

789
MCQeasy

A user reports that they cannot access Microsoft 365 services. You check the Microsoft 365 admin center and see that their license is expired. What is the most likely result of an expired license?

A.Microsoft automatically purchases a new license
B.The user's data is immediately deleted
C.The user loses access to Microsoft 365 services after a grace period
D.The user's account is automatically deleted
AnswerC

When a subscription expires or an admin removes a license, the account enters a grace period (typically 30 days) during which users may see warnings but still access services. Once the grace period ends, the license is disabled and the user can no longer sign in or access Exchange Online, SharePoint, Teams, or other Microsoft 365 workloads. The user object remains in Azure AD, but service access is revoked until a valid license is assigned.

Why this answer

When a Microsoft 365 license expires, Microsoft does not immediately revoke access. Instead, the user enters a grace period (typically 30 days) during which they retain access but may see warnings. After the grace period ends, the user loses access to Microsoft 365 services, and their data is preserved for a further period (usually 90 days) before being deleted.

This aligns with Microsoft's licensing and data retention policies.

Exam trap

The trap here is that candidates often assume license expiration leads to immediate data deletion or account removal, but Microsoft's phased approach (grace period followed by retention) is designed to prevent accidental data loss and give administrators time to renew or reassign licenses.

How to eliminate wrong answers

Option A is wrong because Microsoft does not automatically purchase new licenses; license renewal or purchase requires explicit action by the tenant administrator. Option B is wrong because user data is not immediately deleted upon license expiration; it is preserved through the grace period and a subsequent data retention period (typically 90 days) before deletion. Option D is wrong because the user's account is not automatically deleted; the account remains disabled but intact until the tenant administrator takes action or the retention period expires.

790
Drag & Dropmedium

Drag and drop the steps to deploy Microsoft 365 Apps for enterprise to a Windows device using the Microsoft 365 Apps admin center into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Deploying Office uses the admin center to create a config, then ODT to install based on that config.

791
MCQmedium

A compliance officer needs to ensure that all emails and documents in Exchange Online and SharePoint are automatically retained for five years. After five years, the data should be automatically deleted. Which Microsoft Purview solution should they configure?

A.Retention policies
B.Data loss prevention (DLP) policies
C.Sensitivity labels
D.eDiscovery (Standard)
AnswerA

Retention policies in Microsoft Purview are lifecycle management rules applied to workloads such as Exchange email and SharePoint Online, enabling organizations to automatically keep content for a defined period (for example, seven years) and then trigger permanent deletion at the end of that schedule. They support adaptive and static scopes and can be complemented by retention labels for item-level control. This time-based retain-then-delete behavior directly satisfies the compliance officer's requirement.

Why this answer

Retention policies in Microsoft Purview are designed to automatically retain data for a specified period and then delete it, meeting the compliance officer's requirement for Exchange Online and SharePoint. This solution applies at the container level (e.g., mailboxes, sites) and can enforce a five-year retention followed by automatic deletion without user intervention.

Exam trap

The trap here is that candidates often confuse retention policies with DLP policies, mistakenly thinking DLP can enforce time-based retention and deletion, when DLP is solely focused on preventing data loss through content inspection and action rules.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) policies focus on preventing unauthorized sharing or leakage of sensitive data through rules and actions (e.g., blocking emails), not on automated retention and deletion schedules. Option C is wrong because Sensitivity labels classify and protect data with encryption or visual markings, but they do not inherently enforce time-based retention or deletion; they can be used with retention policies but are not the primary solution for automated lifecycle management. Option D is wrong because eDiscovery (Standard) is used for searching and exporting content for legal or investigative purposes, not for configuring automatic retention and deletion policies.

792
MCQeasy

Your company, Contoso Ltd., has a Microsoft 365 E5 subscription with 500 users. The IT department recently discovered that some employees are sharing sensitive customer data via email with external parties. You need to implement a solution that automatically detects and prevents the sharing of credit card numbers and social security numbers in emails. The solution should notify the sender when a potential violation occurs and allow them to override the block by providing a business justification. The compliance team must be able to review these overrides. What should you configure?

A.Enable Microsoft Defender for Office 365 Safe Attachments and Safe Links.
B.Create a Microsoft Purview Data Loss Prevention (DLP) policy in the Microsoft Purview compliance portal.
C.Create a sensitivity label with auto-labeling for emails containing sensitive data.
D.Create an Exchange mail flow rule to block emails containing sensitive data and send a non-delivery report.
AnswerB

Microsoft Purview DLP policies inspect email content for sensitive information types such as credit card and social security numbers, blocking transmission automatically. Policy tips notify senders of violations and permit override with a business justification, while the compliance team reviews those overrides through activity explorer and DLP reports, satisfying every stated requirement.

Why this answer

A Microsoft Purview Data Loss Prevention (DLP) policy can detect sensitive information types such as credit card numbers and social security numbers, and can be configured to block emails containing that data, notify the sender with an option to override by providing a business justification, and allow compliance team review of overrides. Option A is incorrect because Microsoft Defender for Office 365 Safe Attachments and Safe Links protect against malicious attachments and links, not against data leakage of sensitive information. Option C is incorrect because sensitivity labels are used for classification and protection (e.g., encryption) but not for blocking emails based on content.

Option D is incorrect because an Exchange mail flow rule can block emails based on patterns but lacks the built-in sensitive info types, override with justification, and compliance review capabilities that DLP provides.

793
MCQmedium

During requirements gathering, an IT manager says the organization must discover where sensitive information is stored across Microsoft 365. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Planner
B.Microsoft Stream
C.Microsoft Forms
D.Data classification / Content explorer
AnswerD

Data classification and Content Explorer are built into Microsoft Purview and give administrators a centralized, filterable view of all items that contain sensitive information, have sensitivity labels, or have retention labels applied. Content Explorer lets you search across Exchange, SharePoint, OneDrive, and Teams to verify that data is properly classified and to pinpoint at-risk content. This directly supports the IT manager's goal of identifying sensitive information during requirements gathering, making it the correct answer.

Why this answer

Data classification and Content explorer in Microsoft 365 Purview allow organizations to discover, classify, and monitor sensitive information across Exchange, SharePoint, OneDrive, and Teams. This capability uses trainable classifiers and sensitive information types to identify data like credit card numbers or PII, providing a unified view in Content explorer for compliance administrators. It directly meets the requirement to discover where sensitive information is stored.

Exam trap

The trap here is that candidates may confuse productivity tools (Planner, Stream, Forms) with compliance capabilities, assuming any Microsoft 365 app can discover sensitive data, when only Purview features like Data classification and Content explorer are designed for this purpose.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management tool for organizing work, not a security or compliance discovery tool. Option B is wrong because Microsoft Stream is a video hosting and sharing service, with no native capability to scan or classify sensitive data. Option C is wrong because Microsoft Forms is used to create surveys and quizzes, and lacks any data classification or content scanning features.

794
MCQmedium

A mid-size company with 300 users currently has Microsoft 365 Business Basic licenses. They need to add desktop versions of Office apps (Word, Excel, PowerPoint) and advanced security features such as Microsoft Defender for Office 365. What is the most cost-effective licensing upgrade?

A.Microsoft 365 Business Standard
B.Microsoft 365 Business Premium
C.Microsoft 365 E3
D.Microsoft 365 E5
AnswerB

Microsoft 365 Business Premium is the lowest tier bundling desktop Office apps plus Defender for Office 365, satisfying both requirements. Business Standard adds desktop apps but lacks the advanced security features, so upgrading to Premium avoids paying for separate Defender licences.

Why this answer

Microsoft 365 Business Premium includes both the desktop versions of Office apps (Word, Excel, PowerPoint) and Microsoft Defender for Office 365 (Plan 1) in a single license. This makes it the most cost-effective upgrade from Business Basic because it bundles the required productivity and security features without the higher per-user cost of E3 or E5.

Exam trap

The trap here is that candidates often assume Microsoft 365 Business Standard is sufficient because it includes desktop Office apps, overlooking that Microsoft Defender for Office 365 is a separate security feature not included in that plan, and that Business Premium is the most cost-effective bundle for both requirements.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Standard adds desktop Office apps but does not include Microsoft Defender for Office 365 or any advanced security features. Option C is wrong because Microsoft 365 E3 includes desktop Office apps and basic security but lacks Microsoft Defender for Office 365 (Plan 1) unless an additional add-on is purchased, making it less cost-effective than Business Premium. Option D is wrong because Microsoft 365 E5 includes all required features but at a significantly higher per-user cost than Business Premium, making it overkill for a 300-user company that only needs Defender for Office 365 and desktop apps.

Page 10

Page 11 of 11

All pages