Courseiva

Microsoft 365 Fundamentals MS-900 (MS-900) — Questions 76150

217 questions total · 3pages · All types, answers revealed

Page 1

Page 2 of 3

Page 3
76
MCQmedium

A department asks for the Microsoft 365 service best suited for forms-based surveys and quizzes. Which service should they use?

A.Microsoft Entra Privileged Identity Management
B.Microsoft Forms
C.Microsoft Purview Compliance Manager
D.Microsoft Defender for Endpoint
AnswerB

Forms is used to create surveys, quizzes, and polls.

Why this answer

Microsoft Forms is the correct service because it is specifically designed for creating forms-based surveys, quizzes, and polls. It provides real-time response tracking, automatic grading for quizzes, and seamless integration with Microsoft 365 apps like Excel and Teams, making it the ideal choice for the department's request.

Exam trap

The trap here is that candidates may confuse Microsoft Forms with other Microsoft 365 services that have 'management' or 'compliance' in their names, assuming they include survey capabilities, but only Forms is purpose-built for forms-based data collection and quizzes.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Privileged Identity Management is an identity governance tool for managing, controlling, and monitoring access to Azure AD resources, not for creating surveys or quizzes. Option C is wrong because Microsoft Purview Compliance Manager is a compliance management solution that helps organizations assess and manage their compliance posture, not a forms-based survey tool. Option D is wrong because Microsoft Defender for Endpoint is an enterprise endpoint security platform designed to protect devices from threats, not for building forms or quizzes.

77
MCQmedium

A company with 250 users has Microsoft 365 E3 licenses. They want to add advanced anti-phishing and anti-malware protection for email and also deploy endpoint detection and response (EDR) for all devices. What is the most cost-effective licensing add-on?

A.Microsoft 365 E5 Security add-on
B.Microsoft Defender for Microsoft 365 Plan 1 and Microsoft Defender for Endpoint Plan 1 add-ons
C.Microsoft 365 E5 Compliance add-on
D.Upgrade all users to Microsoft 365 E5
AnswerA

The Microsoft 365 E5 Security add-on is explicitly designed to extend E3 with advanced threat protection, bundling Defender for Microsoft 365 Plan 2 and Defender for Endpoint Plan 1. This bundle provides advanced hunting, automated investigation, and endpoint detection and response at a lower combined price than purchasing the components individually. It directly satisfies the company's security requirements without unnecessary extras, making it the optimal cost-effective choice.

Why this answer

Microsoft 365 E5 Security add-on provides advanced anti-phishing and anti-malware protection via Microsoft Defender for Office 365 Plan 2 and includes Microsoft Defender for Endpoint Plan 2 for EDR capabilities. This is the most cost-effective option because it adds exactly the required security features to existing E3 licenses without the higher cost of a full E5 upgrade or the redundancy of separate plan 1 add-ons.

Exam trap

The trap here is that candidates often confuse the 'Plan 1' vs 'Plan 2' tiers, assuming that any Defender add-on provides full EDR and advanced anti-phishing, when in reality Plan 1 lacks key features like automated investigation and advanced threat hunting.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Office 365 Plan 1 and Microsoft Defender for Endpoint Plan 1 do not include advanced anti-phishing (e.g., impersonation protection, campaign views) or full EDR capabilities (e.g., automated investigation and response, threat analytics) — those require Plan 2. Option C is wrong because Microsoft 365 E5 Compliance add-on focuses on data governance, eDiscovery, and information protection (e.g., DLP, retention labels), not on anti-phishing/anti-malware for email or endpoint EDR. Option D is wrong because upgrading all users to Microsoft 365 E5 is more expensive than adding the E5 Security add-on, which provides the same security features without the extra compliance and analytics features of full E5.

78
MCQhard

A company uses a third-party Human Resources (HR) system. Whenever a new employee is added to the HR system, they want to automatically create a user account in Microsoft 365, assign the appropriate license, and send a welcome email. Which Microsoft 365 service should be used to orchestrate this automation?

A.Microsoft Power Automate
B.Microsoft Identity Manager
C.Microsoft Entra ID Connect
D.Microsoft Graph API
AnswerA

Microsoft Power Automate enables no-code/low-code cloud flows that use built-in connectors and triggers to react to events in third-party HR systems. These flows can orchestrate user provisioning, send approval emails, and update Microsoft Entra ID or other systems automatically, making it the correct tool for automating HR-driven identity workflows.

Why this answer

Microsoft Power Automate is the correct service because it provides a low-code workflow automation platform that can trigger actions based on events in external systems (e.g., a new employee record in a third-party HR system) and then orchestrate a sequence of tasks in Microsoft 365, such as creating a user account via the Microsoft Graph API, assigning a license, and sending a welcome email. It integrates seamlessly with hundreds of connectors, including HR systems and Microsoft 365 services, making it the ideal tool for this cross-system automation scenario.

Exam trap

The trap here is that candidates often confuse the Microsoft Graph API (a development tool) with Power Automate (a no-code/low-code orchestration service), mistakenly thinking that because the Graph API can perform the individual actions, it is the correct answer for orchestrating the entire automated workflow.

How to eliminate wrong answers

Option B (Microsoft Identity Manager) is wrong because it is an on-premises identity and access management solution focused on synchronizing identities between on-premises directories and cloud directories, not on orchestrating event-driven workflows like creating users and sending emails. Option C (Microsoft Entra ID Connect) is wrong because it is a synchronization tool that replicates on-premises Active Directory objects to Microsoft Entra ID for hybrid identity scenarios; it does not provide workflow automation or trigger actions based on external HR system events. Option D (Microsoft Graph API) is wrong because while it can be used to programmatically create users, assign licenses, and send emails, it is a RESTful API that requires custom code and does not provide the orchestration, scheduling, or low-code workflow capabilities that Power Automate offers for automating a multi-step process triggered by an external system.

79
MCQeasy

A startup with 25 employees needs business-grade email (50 GB mailbox per user), web versions of Office apps, and 1 TB of cloud storage per user. They do not need the desktop versions of Office or advanced security features. Which Microsoft 365 plan is the most cost-effective choice?

A.Microsoft 365 Business Basic
B.Microsoft 365 Business Standard
C.Microsoft 365 Business Premium
D.Microsoft 365 Apps for business
AnswerA

Microsoft 365 Business Basic provides a 50 GB Exchange Online mailbox for business email, web and mobile versions of Office apps, and 1 TB OneDrive storage per user. It matches every stated requirement (business-grade email and 50 GB capacity) at the lowest available subscription price for this plan family. Desktop Office apps are not included, but they were not required by the startup, so this is the correct, cost-optimal plan.

Why this answer

Microsoft 365 Business Basic provides business-grade email with 50 GB mailboxes, web versions of Office apps (Word, Excel, PowerPoint, etc.), and 1 TB of cloud storage per user via OneDrive for Business. Since the startup does not need desktop Office apps or advanced security features, this plan meets all stated requirements at the lowest cost.

Exam trap

The trap here is that candidates often confuse 'web versions of Office apps' with 'desktop versions' and select Business Standard, or they assume that business-grade email requires a higher-tier plan like Business Premium, when in fact Business Basic includes Exchange Online mailboxes.

How to eliminate wrong answers

Option B (Microsoft 365 Business Standard) is wrong because it includes desktop versions of Office apps, which the startup does not need, making it more expensive than necessary. Option C (Microsoft 365 Business Premium) is wrong because it adds advanced security features (e.g., Microsoft Defender for Office 365, Intune) and desktop Office apps, exceeding the stated requirements and increasing cost. Option D (Microsoft 365 Apps for business) is wrong because it provides only desktop and web versions of Office apps without Exchange Online mailboxes (no business-grade email) and offers only 1 TB of cloud storage per user but lacks the 50 GB mailbox requirement.

80
MCQmedium

An administrator is reviewing a request from users who need to avoid overprovisioning for a seasonal workload. Cloud concept or benefit best matches this requirement?

A.Data Loss Prevention (DLP)
B.Sensitivity labels
C.Microsoft Planner
D.Rapid elasticity
AnswerD

Rapid elasticity allows capacity to increase during peaks and reduce when demand falls.

Why this answer

Rapid elasticity is a core cloud computing characteristic defined by NIST (SP 800-145) that allows resources to scale out and in automatically based on demand. For a seasonal workload, this means the cloud can provision additional compute or storage capacity during peak periods and release it when demand drops, preventing overprovisioning and optimizing costs.

Exam trap

The trap here is that candidates confuse operational tools (like Planner) or security features (like DLP and sensitivity labels) with core cloud architectural benefits, failing to recognize that rapid elasticity is the specific NIST-defined characteristic that directly addresses overprovisioning for variable workloads.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) is a security feature in Microsoft Purview that monitors and protects sensitive data from unauthorized sharing or leakage, not a mechanism for scaling resources. Option B is wrong because sensitivity labels are classification and protection controls applied to documents and emails to enforce encryption or access restrictions, unrelated to workload elasticity. Option C is wrong because Microsoft Planner is a task management and collaboration tool within Microsoft 365, not a cloud infrastructure feature for dynamic resource allocation.

81
MCQmedium

During requirements gathering, an IT manager says the organization must manage users, licenses, billing, and tenant settings. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft 365 admin center
B.Microsoft Whiteboard
C.Microsoft Forms
D.Microsoft Stream
AnswerA

The Microsoft 365 admin center is the central location for common tenant administration.

Why this answer

The Microsoft 365 admin center is the centralized web portal for managing users, licenses, billing, and tenant-wide settings. It provides administrators with a single pane of glass to perform tasks such as adding or removing users, assigning licenses, viewing invoices, and configuring tenant-level policies. This directly matches the IT manager's stated requirements for managing users, licenses, billing, and tenant settings.

Exam trap

The trap here is that candidates may confuse collaboration tools (Whiteboard, Forms, Stream) with administrative tools, assuming any Microsoft 365 service can manage users and licenses, when only the admin center provides the required centralized management capabilities.

How to eliminate wrong answers

Option B is wrong because Microsoft Whiteboard is a digital canvas collaboration tool, not an administrative interface for managing users, licenses, billing, or tenant settings. Option C is wrong because Microsoft Forms is a survey and data collection tool, not a platform for administrative management of licensing or billing. Option D is wrong because Microsoft Stream is a video management and sharing service, not a tool for managing users, licenses, billing, or tenant configurations.

82
Multi-Selectmedium

Which of the following are key characteristics of cloud computing as defined by the National Institute of Standards and Technology (NIST)? (Choose all that apply. There are four correct answers.)

Select 4 answers
.On-demand self-service
.Broad network access
.Resource pooling
.Rapid elasticity
.Fixed, non-scalable capacity
.Locally installed software only

Why this answer

The NIST SP 800-145 definition identifies five essential characteristics of cloud computing: on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service. On-demand self-service allows users to provision computing capabilities automatically without requiring human interaction with each service provider. Broad network access means capabilities are available over the network and accessed through standard mechanisms (e.g., mobile phones, laptops, workstations).

Resource pooling enables the provider's computing resources to serve multiple consumers using a multi-tenant model, with physical and virtual resources dynamically assigned and reassigned according to consumer demand. Rapid elasticity allows capabilities to be elastically provisioned and released, in some cases automatically, to scale rapidly outward and inward commensurate with demand.

Exam trap

Microsoft often tests that candidates confuse 'measured service' (the fifth NIST characteristic) as one of the four correct answers, but the question explicitly asks for four correct answers and omits measured service, so the trap is to include it or to incorrectly select 'Fixed, non-scalable capacity' as a valid characteristic.

83
Multi-Selectmedium

A project team needs to collaborate on Teams channel conversations and meetings and co-author related Office files. Which two Microsoft 365 capabilities are most relevant?

Select 2 answers
A.Microsoft Teams
B.SharePoint Online document storage
C.Microsoft Purview eDiscovery case
D.Exchange anti-malware policy
AnswersA, B

Teams is the hub for chat, meetings, calls, and team collaboration.

Why this answer

Microsoft Teams is the correct answer because it provides the central hub for channel conversations, meetings, and real-time collaboration. SharePoint Online document storage is also correct because Teams channels use SharePoint as the underlying storage for all shared files, enabling co-authoring of Office documents directly within the Teams interface.

Exam trap

The trap here is that candidates may think Microsoft Teams alone covers all collaboration needs, forgetting that SharePoint Online is the underlying file storage and co-authoring engine for Teams channel files.

84
MCQmedium

A business stakeholder asks how Microsoft 365 can help them check known incidents affecting Microsoft 365 services. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Forms
B.Microsoft Whiteboard
C.Microsoft Stream
D.Service health
AnswerD

Service health shows incidents and advisories for Microsoft 365 services.

Why this answer

Service health in the Microsoft 365 admin center provides real-time status and incident information for all Microsoft 365 services. It allows administrators and stakeholders to check known incidents, advisories, and historical uptime data, directly addressing the need to monitor service availability.

Exam trap

The trap here is that candidates may confuse productivity tools (Forms, Whiteboard, Stream) with administrative or support features, failing to recognize that Service health is the dedicated console for incident monitoring within the Microsoft 365 admin center.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and data collection tool, not a service monitoring or incident reporting feature. Option B is wrong because Microsoft Whiteboard is a digital canvas for collaboration, unrelated to checking service health or incidents. Option C is wrong because Microsoft Stream is a video management and sharing service, not a dashboard for service status or incident tracking.

85
MCQmedium

A company with 1,000 users currently has Microsoft 365 E3 licenses. They need to add advanced threat protection for email (including anti-phishing and anti-malware) and endpoint detection and response (EDR) for all devices. What is the most cost-effective licensing addition?

A.Microsoft 365 E5 Security add-on
B.Microsoft 365 E5 Compliance add-on
C.Upgrade all users to Microsoft 365 E5
D.Microsoft Defender for Microsoft 365 Plan 1 standalone
AnswerA

Correct. This add-on bundles Defender for Microsoft 365 Plan 2 and Defender for Endpoint Plan 2, providing the needed capabilities at a lower cost than other options.

Why this answer

The Microsoft 365 E5 Security add-on provides advanced threat protection (including anti-phishing and anti-malware for email via Defender for Office 365 Plan 2) and endpoint detection and response (EDR) via Microsoft Defender for Endpoint Plan 2, all without requiring a full E5 license upgrade. This is the most cost-effective solution for adding these specific security capabilities to existing E3 users.

Exam trap

The trap here is that candidates often confuse the E5 Security add-on with the full E5 upgrade, not realizing the add-on provides the same security features at a lower cost, or they mistakenly think the E5 Compliance add-on includes security capabilities like EDR.

How to eliminate wrong answers

Option B is wrong because the Microsoft 365 E5 Compliance add-on focuses on compliance features (e.g., eDiscovery, audit, data loss prevention) and does not include advanced threat protection for email or EDR capabilities. Option C is wrong because upgrading all users to Microsoft 365 E5 is more expensive than adding the E5 Security add-on, which provides the same security features without the additional E5 productivity and compliance features. Option D is wrong because Microsoft Defender for Microsoft 365 Plan 1 standalone includes only basic email protection and lacks EDR capabilities (which require Defender for Endpoint Plan 2) and advanced anti-phishing features found in Defender for Office 365 Plan 2.

86
MCQhard

A financial services company must prevent users from accidentally sharing sensitive customer data externally. They want to block sharing of any document containing a credit card number via email or SharePoint. What combination of Microsoft 365 compliance solutions should they use?

A.Sensitivity labels and Microsoft Purview Information Protection (Microsoft Purview Information Protection)
B.Data Loss Prevention (DLP) policies
C.Microsoft Purview Compliance Manager
D.Exchange Online Protection (EOP) and Microsoft Defender for Microsoft 365
AnswerB

DLP policies detect sensitive data and block sharing actions automatically across services.

Why this answer

Data Loss Prevention (DLP) policies in Microsoft Purview are specifically designed to detect and block the sharing of sensitive information, such as credit card numbers, across email (Exchange Online) and SharePoint. By scanning content for predefined sensitive info types (e.g., credit card numbers using regex patterns from the DLP engine), DLP can automatically block or warn users before external sharing occurs, meeting the company's requirement.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which classify and protect data at rest) with DLP (which monitors and blocks data in motion), leading them to choose Option A, even though DLP is the correct solution for preventing accidental external sharing of sensitive content like credit card numbers.

How to eliminate wrong answers

Option A is wrong because sensitivity labels and Microsoft Purview Information Protection focus on classifying and protecting data through encryption and access controls, but they do not natively scan content in transit or block sharing based on sensitive data patterns like credit card numbers; DLP is required for that detection and enforcement. Option C is wrong because Microsoft Purview Compliance Manager is a risk assessment and compliance management tool that provides a score and recommendations for regulatory frameworks (e.g., GDPR, HIPAA), but it does not actively scan or block data sharing. Option D is wrong because Exchange Online Protection (EOP) provides anti-spam and anti-malware protection for email, and Microsoft Defender for Office 365 adds advanced threat protection (e.g., phishing, safe attachments), but neither includes the content-based sensitive data detection and blocking capabilities of DLP.

87
MCQmedium

A manager wants to quickly create a survey to collect employee feedback on a new policy. The survey must automatically store responses in an Excel spreadsheet and trigger an email notification when a response is submitted. Which Microsoft 365 service should the manager use?

A.Microsoft Forms
B.Microsoft Lists
C.Microsoft Power Apps
D.Microsoft SharePoint
AnswerA

Microsoft Forms is the correct choice because it provides an out-of-the-box survey creation interface with ready-to-use question types, branching, and themes, enabling an employee feedback survey to be built in minutes. Responses are automatically collected into an Excel workbook for immediate analysis, and the built-in Power Automate integration allows you to trigger an email alert to a manager or HR whenever a new response is submitted, without writing any code.

Why this answer

Microsoft Forms is the correct choice because it is designed specifically for creating surveys and quizzes, and it natively integrates with Excel to automatically store responses in a spreadsheet. Additionally, Forms supports Power Automate flows out of the box, allowing you to trigger an email notification whenever a new response is submitted, meeting both requirements without custom development.

Exam trap

The trap here is that candidates may confuse Microsoft Lists with Forms because both can collect data, but Lists is a structured data repository, not a survey tool, and lacks the automatic Excel storage and email trigger capabilities that Forms offers through its native Power Automate integration.

How to eliminate wrong answers

Option B is wrong because Microsoft Lists is a data-tracking application for organizing information in a list format, not a survey tool; it lacks built-in survey creation and does not automatically store responses in Excel or trigger email notifications on submission. Option C is wrong because Microsoft Power Apps is a low-code platform for building custom applications, which would require significant development effort to create a survey and integrate Excel storage and email triggers, making it overkill for this simple task. Option D is wrong because Microsoft SharePoint is a content management and collaboration platform; while it can host surveys via SharePoint lists or web parts, it does not automatically store responses in Excel or provide native email notification triggers without additional configuration or Power Automate flows.

88
MCQmedium

A compliance team needs to ensure that any email sent from the Finance department that contains a bank account number is automatically encrypted. External recipients must be able to reply securely without needing to sign up for any service. Which Microsoft Purview solution should they configure?

A.Microsoft Purview Data Loss Prevention (DLP)
B.Microsoft Purview Message Encryption
C.Microsoft Purview Information Protection (sensitivity labels)
D.Microsoft Defender for Office 365
AnswerB

Microsoft Purview Message Encryption is the actual email encryption service that protects message content in transit and at rest. It is the underlying technology invoked when a DLP policy detects sensitive data, and it enables sending encrypted emails to any recipient, including external users without Microsoft Entra ID accounts, via a secure web experience. Additionally, it supports secure reply without requiring the recipient to sign up for an account, making it the correct answer for automatic email encryption.

Why this answer

Microsoft Purview Message Encryption (B) is the correct solution because it allows the organization to automatically encrypt emails based on conditions (e.g., emails from Finance containing bank account numbers) and enables external recipients to reply securely using the encrypted reply portal without requiring any sign-up or additional software. This is achieved through Azure Rights Management (Azure RMS) and the Office 365 Message Encryption (OME) portal, which provides a seamless, browser-based experience for external users.

Exam trap

The trap here is that candidates often confuse the automatic encryption trigger in DLP policies with the actual encryption mechanism, forgetting that DLP alone cannot encrypt emails or provide the secure reply portal—those capabilities require Message Encryption (OME) to be configured as the action.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Loss Prevention (DLP) can detect sensitive data like bank account numbers and trigger actions such as blocking or warning, but it does not natively provide automatic encryption of emails with a secure reply mechanism for external recipients; DLP policies can integrate with Message Encryption, but the encryption itself is not a DLP feature. Option C is wrong because Microsoft Purview Information Protection (sensitivity labels) can apply encryption to emails and documents, but they require the recipient to have a Microsoft 365 account or use the Azure RMS client, and they do not offer the built-in, no-sign-up secure reply portal that Message Encryption provides for external users. Option D is wrong because Microsoft Defender for Office 365 focuses on threat protection (anti-phishing, anti-malware, safe attachments/links) and does not include native email encryption or secure reply capabilities for external recipients.

89
MCQeasy

A project manager needs to create a shared workspace for a cross-functional team to manage tasks, share files, track deadlines, and have threaded conversations. Which Microsoft 365 app should be the primary platform for this workspace?

A.Microsoft SharePoint
B.Microsoft Teams
C.Microsoft Planner
D.Microsoft To Do
AnswerB

Microsoft Teams is designed specifically as a shared workspace, offering persistent channels with threaded conversations, native file sharing and co-authoring via the SharePoint-backed Files tab, and integration of Planner tasks through the Tasks by Planner and To Do app. This convergence of chat, files, meetings, and tasks within a single interface makes it the ideal hub for a cross-functional team. Additionally, Teams supports multiple channels for distinct workstreams, ensuring that communication and collaboration are contextual and organized, which is exactly what dynamic team environments need.

Why this answer

Microsoft Teams is the correct primary platform because it integrates chat, threaded conversations, file sharing, task management (via integrated Planner or Tasks by Planner and To Do), and deadline tracking into a single shared workspace. Unlike SharePoint, which is a document management and intranet platform, Teams provides a real-time collaboration hub with persistent threaded conversations and direct task assignment capabilities, making it ideal for cross-functional team coordination.

Exam trap

The trap here is that candidates often confuse SharePoint as the primary collaboration workspace because it is a powerful content management platform, but the question specifically requires threaded conversations and real-time task management, which are native to Teams, not SharePoint.

How to eliminate wrong answers

Option A is wrong because Microsoft SharePoint is a document management and intranet portal platform focused on content storage, version control, and site-based collaboration, not a real-time workspace with threaded conversations and integrated task management. Option C is wrong because Microsoft Planner is a lightweight task management tool that provides Kanban boards and task assignments but lacks native threaded conversations, file sharing, and a persistent chat workspace. Option D is wrong because Microsoft To Do is a personal task management app designed for individual productivity and list-based task tracking, not for team collaboration, shared workspaces, or threaded conversations.

90
MCQhard

A non-profit organization with 15 employees needs business-grade email, desktop versions of Office apps, and 1 TB of cloud storage per user. They are eligible for Microsoft's non-profit program. Which plan provides these features at the lowest cost?

A.Microsoft 365 Business Basic for Nonprofits
B.Microsoft 365 Business Standard for Nonprofits
C.Microsoft 365 E3 for Nonprofits
D.Microsoft 365 Enterprise for Nonprofits
AnswerB

Business Standard includes desktop Office apps, business-grade email, and 1 TB storage, meeting all needs at the lowest cost for a small nonprofit.

Why this answer

Microsoft 365 Business Standard for Nonprofits is the correct choice because it includes business-grade email (Exchange Online), desktop versions of Office apps (Word, Excel, PowerPoint, etc.), and 1 TB of OneDrive cloud storage per user, all at a significantly reduced cost (or free for qualifying organizations) under the nonprofit program. Business Basic only provides web and mobile Office apps, not desktop versions, and E3/Enterprise plans are more expensive and include advanced security and compliance features not required by this 15-employee organization.

Exam trap

The trap here is that candidates often confuse 'Business Basic' as sufficient because it includes email and storage, but they overlook the explicit requirement for 'desktop versions of Office apps,' which only Business Standard and higher plans provide.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Basic for Nonprofits includes only web and mobile versions of Office apps, not the desktop versions required by the question. Option C is wrong because Microsoft 365 E3 for Nonprofits, while including desktop apps and 1 TB storage, is a higher-tier enterprise plan with advanced security, compliance, and analytics features that are unnecessary for a 15-employee organization, resulting in higher cost than Business Standard. Option D is wrong because Microsoft 365 Enterprise for Nonprofits is not a specific plan name; the correct enterprise-level plans are E3 or E5, and this option is vague and implies a more expensive suite than needed.

91
MCQhard

A security administrator needs to audit all activities related to a specific user in Exchange Online, SharePoint Online, and Microsoft Entra ID for the past 90 days. They also need to export the audit log as a CSV file. Which Microsoft Purview solution provides this capability without additional licensing beyond Microsoft 365 E3?

A.Microsoft Purview Audit (Standard)
B.Microsoft Purview Audit (Premium)
C.Microsoft Purview eDiscovery (Standard)
D.Microsoft Purview Content Search
AnswerA

Correct. Audit (Standard) is included with E3, retains logs for 90 days, covers the required services, and allows export to CSV.

Why this answer

Microsoft Purview Audit (Standard) is included with Microsoft 365 E3 and provides the ability to search and export audit logs for user activities across Exchange Online, SharePoint Online, and Microsoft Entra ID for up to 90 days. This meets the administrator's requirement without needing additional licensing.

Exam trap

The trap here is that candidates confuse 'auditing user activities' with 'searching for content' and pick Content Search or eDiscovery, not realizing that audit logs track actions (like 'User logged in' or 'Deleted file') while Content Search finds the actual data files.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Audit (Premium) offers extended retention (up to 1 year) and intelligent insights, but it requires an E5 or add-on license, not E3. Option C is wrong because Microsoft Purview eDiscovery (Standard) is designed for legal holds and case-based content searches, not for exporting a raw audit log of user activities as a CSV. Option D is wrong because Microsoft Purview Content Search is used to find and export content (emails, documents) from mailboxes and sites, not to audit administrative or user actions in the audit log.

92
MCQeasy

In a Software as a Service (SaaS) model, which of the following responsibilities is typically handled by the cloud provider?

A.Managing user passwords and accounts
B.Patching the underlying operating system and application
C.Configuring application settings for the organization
D.Backing up customer data
AnswerB

For Microsoft 365, Microsoft handles patching the underlying Windows Server operating systems, the hypervisor/fabric, Exchange Online mailboxes, SharePoint servers, and Teams services because the customer never has administrative access to the VM or host OS. The provider applies security and feature updates on a continuous deployment schedule to maintain service availability and protection. This is exactly the kind of infrastructure maintenance that remains with the SaaS vendor, unlike tenant configuration or user administration.

Why this answer

In a SaaS model, the cloud provider is responsible for managing the underlying infrastructure, including patching the operating system and the application itself. This is a core tenet of the shared responsibility model, where the provider handles the security and maintenance of the software stack, while the customer is responsible for data and user access. For example, in Microsoft 365, Microsoft automatically applies security updates to Exchange Online and SharePoint without customer intervention.

Exam trap

The trap here is that candidates often confuse 'backing up customer data' (Option D) as a provider responsibility, but in SaaS, the provider ensures infrastructure redundancy, while the customer must configure and verify their own backup and recovery policies, such as using Microsoft 365 Backup or third-party tools.

How to eliminate wrong answers

Option A is wrong because managing user passwords and accounts is a customer responsibility, as the customer controls identity and access management (IAM) within their tenant, such as configuring Azure AD password policies or self-service password reset. Option C is wrong because configuring application settings for the organization, like setting up email retention policies or SharePoint site permissions, is performed by the customer's administrators, not the provider. Option D is wrong because while the provider may offer backup infrastructure, the customer is typically responsible for ensuring their data is backed up according to their own compliance needs; for instance, in Microsoft 365, customers must enable and manage retention policies and backup configurations.

93
MCQmedium

A project manager wants to create a collaborative workspace that includes a shared calendar, a document library, and a task list. The workspace should be accessible from within Microsoft Teams and allow team members to discuss topics in a threaded conversation. Which Microsoft 365 service should they use as the foundation?

A.Microsoft Teams with a channel
B.SharePoint Team Site
C.Microsoft Planner
D.Microsoft Viva Engage Community
AnswerB

A SharePoint Team Site is the correct choice because it natively provides a shared calendar list, a document library, and task management capabilities in one place. This team site can be connected to Microsoft Teams for chat and meetings, but the calendar and files live in SharePoint, making it the actual collaboration workspace. It fully satisfies the requirement of a shared calendar without relying on external services.

Why this answer

A SharePoint Team Site provides the foundational structure for a collaborative workspace with a shared calendar, document library, and task list. It integrates natively with Microsoft Teams, allowing the workspace to be accessed via a Teams channel, and supports threaded conversations through the connected Teams channel or Yammer web parts. This makes it the correct choice for the described requirements.

Exam trap

The trap here is that candidates often confuse a Microsoft Teams channel (Option A) as the workspace itself, not realizing that the channel is merely a collaboration layer that depends on SharePoint for persistent storage and structured components like calendars and document libraries.

How to eliminate wrong answers

Option A is wrong because a Microsoft Teams channel is a communication interface within a team, not a standalone workspace; it relies on an underlying SharePoint site for document libraries, calendars, and task lists. Option C is wrong because Microsoft Planner is a task management tool that provides task lists and boards but lacks a shared calendar and document library, and it does not serve as a full collaborative workspace foundation. Option D is wrong because Microsoft Viva Engage Community is designed for broad organizational discussions and social networking, not for structured collaboration with a shared calendar, document library, and task list within a Teams channel.

94
MCQmedium

A multinational organization wants a central hub for employee communication that includes company-wide announcements, topic-based communities, and the ability to integrate with SharePoint and Power BI dashboards. Which Microsoft 365 service is designed specifically for this purpose?

A.Microsoft Teams
B.Microsoft Viva Engage
C.SharePoint Online
D.Outlook
AnswerB

Microsoft Viva Engage is an enterprise social network that allows organizations to create company-wide announcements, topic-based communities, and integrate with other apps like SharePoint and Power BI. It is the intended service for broad employee communication.

Why this answer

Microsoft Viva Engage (formerly Yammer) is designed as a social networking and employee communication hub that provides company-wide announcements, topic-based communities, and seamless integration with SharePoint and Power BI dashboards. It focuses on fostering open communication across the organization, unlike collaboration tools that are team-centric.

Exam trap

The trap here is that candidates often confuse Microsoft Teams' 'general' channel or SharePoint's news web part with a true company-wide social hub, but Viva Engage is the only service purpose-built for open, topic-based communities and organization-wide announcements with native integration to SharePoint and Power BI.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is primarily a chat-based collaboration workspace for teams and channels, not a central hub for company-wide announcements and topic-based communities; it lacks the enterprise social network features like broadcast announcements to the entire organization. Option C is wrong because SharePoint Online is a document management and intranet platform that can host announcements and dashboards but is not specifically designed as a social communication hub with topic-based communities and company-wide feeds. Option D is wrong because Outlook is an email and calendar client, not a platform for topic-based communities or integrated social networking; it cannot replace the community-driven, announcement-focused functionality of Viva Engage.

95
MCQeasy

A public relations team needs to create an interactive, visually rich newsletter that includes embedded video and dynamic content from a SharePoint list. Which app should they use?

A.Sway
B.PowerPoint
C.SharePoint News
D.Microsoft Stream
AnswerA

Sway's card-based, responsive canvas is purpose-built for interactive digital storytelling; it automatically rearranges text, images, and embedded video into a fluid layout that adapts to any device. It supports direct embedding of dynamic SharePoint content and social media, requiring no manual updates, making it the ideal choice for a visually engaging newsletter.

Why this answer

Sway is the correct choice because it is designed specifically for creating interactive, visually rich newsletters that can embed videos and dynamically pull content from SharePoint lists using its integration with Microsoft 365. Unlike other apps, Sway offers a responsive design canvas that adapts to different devices and allows embedding of multimedia elements directly, making it ideal for a public relations team's needs.

Exam trap

The trap here is that candidates often confuse SharePoint News with Sway because both can display news and embed videos, but SharePoint News is a site-level feature for internal communications, not a standalone app for creating interactive, visually rich newsletters with dynamic content from SharePoint lists.

How to eliminate wrong answers

Option B (PowerPoint) is wrong because it is a presentation tool focused on slide-based content, not a newsletter format, and lacks native support for dynamically pulling content from SharePoint lists without complex add-ins. Option C (SharePoint News) is wrong because while it can display news posts and embed videos, it does not provide the same level of interactive, visually rich design flexibility as Sway and is more suited for internal communications within a SharePoint site. Option D (Microsoft Stream) is wrong because it is a video hosting and management platform, not a content creation tool for newsletters, and cannot generate interactive documents with embedded dynamic content from SharePoint lists.

96
MCQmedium

A company uses Microsoft Purview to monitor for potential data security incidents. They want to automatically detect and remediate activities like downloading large amounts of data to a personal device. Which solution should they configure?

A.Data Loss Prevention (DLP)
B.Insider Risk Management
C.Audit
D.eDiscovery
AnswerB

Insider Risk Management is the Microsoft Purview solution built specifically to identify, triage, and respond to risky user behavior by aggregating signals from Windows, Microsoft 365, and HR systems into a consolidated risk score. It uses predefined risk indicator policies—such as mass file downloads, unusual device connections, or repeated data exfiltration—and applies machine learning to surface anomalous patterns with a case-management workflow. When a threshold is met, it can automatically escalate to an investigation, notify the user, or trigger a policy response, making it the correct choice for monitoring and remediating potential data loss from insiders.

Why this answer

Insider Risk Management is the correct solution because it is specifically designed to detect and remediate risky user activities that could lead to data security incidents, such as downloading large amounts of data to a personal device. It uses machine learning and behavioral analytics to identify anomalous patterns and can trigger automated remediation actions like blocking the activity or notifying the user.

Exam trap

The trap here is that candidates often confuse Data Loss Prevention (DLP) with Insider Risk Management, assuming DLP handles all data security incidents, but DLP focuses on content-based policies (e.g., credit card numbers) rather than behavioral detection of risky user actions like bulk downloads to personal devices.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) is focused on preventing data exfiltration by enforcing policies on data in use, in transit, or at rest, but it does not natively detect or remediate behavioral patterns like downloading large volumes to a personal device; it typically blocks or alerts on policy violations based on content inspection. Option C is wrong because Audit (Microsoft Purview Audit) is a logging and investigation tool that records user and admin activities for compliance and forensic analysis, but it does not automatically detect or remediate risky behaviors in real time. Option D is wrong because eDiscovery is used for legal and regulatory discovery of electronic content, such as searching and exporting data for litigation or investigations, and has no capability to automatically detect or remediate data security incidents.

97
MCQhard

A multinational organization with 500 users currently has Microsoft 365 E3 licenses. They need to perform advanced threat hunting using queries across email, endpoints, and identities to investigate a security incident. They also need the ability to automatically isolate infected endpoints. What is the most cost-effective licensing addition?

A.Microsoft 365 E5 Security
B.Microsoft 365 E5
C.Microsoft 365 E5 Compliance
D.Enterprise Mobility + Security (EMS) E5
AnswerA

Microsoft 365 E5 Security is a targeted add-on for organizations on Microsoft 365 E3 that unlocks the full Microsoft 365 Defender stack. This includes Defender for Endpoint P2, Defender for Office 365 P2, Defender for Identity, and Defender for Cloud Apps, enabling advanced threat hunting via KQL, automated investigation and response, and automated endpoint isolation. It provides comprehensive security operations capabilities without the extra cost of non-security features found in the full E5 suite.

Why this answer

Microsoft 365 E5 Security is the most cost-effective addition because it provides advanced threat hunting via Microsoft 365 Defender (including queries across email, endpoints, and identities) and automated endpoint isolation through Microsoft Defender for Endpoint. This add-on delivers the required capabilities without the full cost of upgrading all users to Microsoft 365 E5, which would also include unnecessary features like advanced compliance and analytics.

Exam trap

The trap here is that candidates often confuse Microsoft 365 E5 Security with the full Microsoft 365 E5 license, assuming the full E5 is required for security features, when in fact the Security add-on provides the specific threat hunting and isolation capabilities at a lower cost.

How to eliminate wrong answers

Option B (Microsoft 365 E5) is wrong because it includes the full suite of E5 features (e.g., advanced compliance, analytics, and voice capabilities) at a higher per-user cost, making it less cost-effective than just adding the Security add-on. Option C (Microsoft 365 E5 Compliance) is wrong because it focuses on eDiscovery, data loss prevention, and information protection, not on advanced threat hunting with queries across email, endpoints, and identities or automated endpoint isolation. Option D (Enterprise Mobility + Security (EMS) E5) is wrong because it provides identity and access management (e.g., Azure AD P2, Intune) and mobile device management, but lacks the advanced threat hunting and automated endpoint isolation capabilities found in Microsoft 365 Defender.

98
MCQmedium

A growing company with 120 users currently holds Microsoft 365 Business Basic licenses. They need to add endpoint management (Microsoft Intune) and advanced threat protection (Microsoft Defender for Office 365 Plan 1). They also want to keep their existing Business Basic subscriptions. What is the most cost-effective way to add these capabilities?

A.Upgrade all users to Microsoft 365 Business Premium
B.Add Microsoft 365 Business Premium licenses as a standalone for all users
C.Purchase add-on subscriptions for Microsoft Intune Plan 1 and Microsoft Defender for Office 365 Plan 1
D.Switch to Microsoft 365 E3 and drop Business Basic
AnswerC

The correct approach is to purchase Microsoft Intune Plan 1 and Microsoft Defender for Office 365 Plan 1 as add-on subscriptions for the existing Business Basic users. These are incremental, per-user services designed to be attached to base plans, delivering exactly the mobile device management and email threat protection required without changing current workloads. For 120 users, this minimizes cost by paying only for the missing capabilities while preserving the existing Office 365 services and administrator familiarity.

Why this answer

Microsoft 365 Business Basic supports add-on subscriptions for Microsoft Intune Plan 1 and Microsoft Defender for Office 365 Plan 1, allowing the company to retain their existing licenses while adding endpoint management and advanced threat protection. This is the most cost-effective approach as it avoids the higher per-user cost of upgrading to Business Premium or switching to E3, which would include unnecessary features like desktop Office apps.

Exam trap

The trap here is that candidates often assume they must upgrade to a higher-tier plan (like Business Premium or E3) to get Intune and Defender, overlooking that Microsoft 365 Business Basic supports targeted add-on subscriptions for specific capabilities, which is the most cost-effective path.

How to eliminate wrong answers

Option A is wrong because upgrading all users to Microsoft 365 Business Premium would include features like desktop Office apps and other capabilities not required, resulting in unnecessary cost per user compared to purchasing only the needed add-ons. Option B is wrong because adding Business Premium as a standalone license for all users is redundant and more expensive than using add-ons, as it would duplicate the Business Basic subscription and include unneeded features. Option D is wrong because switching to Microsoft 365 E3 would drop the existing Business Basic subscriptions and introduce a higher per-user cost with features like advanced compliance and eDiscovery that are not required, making it less cost-effective than add-ons.

99
MCQmedium

A company has 100 Microsoft 365 E3 users. They need to add advanced threat protection (Microsoft Defender for Microsoft 365 Plan 2) and advanced compliance (eDiscovery Premium) for all users. They want to minimize additional costs while keeping their existing E3 subscriptions. What is the most cost-effective licensing strategy?

A.Purchase both the Microsoft 365 E5 Compliance add-on and the Microsoft 365 E5 Security add-on
B.Upgrade all users to Microsoft 365 E5
C.Purchase only the Microsoft 365 E5 Compliance add-on
D.Purchase only the Microsoft 365 E5 Security add-on
AnswerA

These add-ons provide exactly the advanced compliance and security features needed without upgrading to E5.

Why this answer

The Microsoft 365 E5 Security add-on provides Microsoft Defender for Office 365 Plan 2, and the Microsoft 365 E5 Compliance add-on provides eDiscovery Premium. Purchasing both add-ons for existing E3 users delivers the required advanced threat protection and advanced compliance capabilities without the full cost of upgrading to E5, making it the most cost-effective strategy.

Exam trap

The trap here is that candidates may assume upgrading to E5 is the only way to get both advanced security and compliance features, overlooking the cost-saving option of purchasing the specific E5 add-ons for existing E3 users.

How to eliminate wrong answers

Option B is wrong because upgrading all users to Microsoft 365 E5 includes both the security and compliance features but at a higher per-user cost than purchasing the two add-ons separately, which is unnecessary when E3 licenses are already in place. Option C is wrong because purchasing only the E5 Compliance add-on provides eDiscovery Premium but does not include Microsoft Defender for Office 365 Plan 2, leaving the advanced threat protection requirement unmet. Option D is wrong because purchasing only the E5 Security add-on provides Microsoft Defender for Office 365 Plan 2 but does not include eDiscovery Premium, failing to address the advanced compliance requirement.

100
MCQeasy

A company wants to use a cloud service where they only manage their data and user access, while the cloud provider handles everything from the physical infrastructure to the applications. Which cloud service model is this?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.On-premises deployment
AnswerC

Correct. The provider manages everything from infrastructure to the application, and the customer only manages data and user access.

Why this answer

This scenario describes Software as a Service (SaaS), where the cloud provider manages the entire stack—physical infrastructure, operating system, middleware, runtime, data, and applications—while the customer only manages their data and user access. In SaaS, the provider delivers fully functional applications over the internet, such as Microsoft 365, where users simply log in and use the software without any infrastructure or platform management responsibilities.

Exam trap

The trap here is that candidates often confuse PaaS with SaaS because both abstract infrastructure, but PaaS still requires the customer to manage their own applications and data, whereas SaaS offloads even application management to the provider.

How to eliminate wrong answers

Option A is wrong because Infrastructure as a Service (IaaS) provides only virtualized computing resources (e.g., VMs, storage, networks), and the customer must manage the operating systems, middleware, runtime, data, and applications themselves. Option B is wrong because Platform as a Service (PaaS) abstracts the underlying infrastructure and middleware, but the customer still manages their own applications and data, not just user access and data. Option D is wrong because an on-premises deployment means the company manages everything—from physical hardware to applications—which is the opposite of the described model where the provider handles all layers.

101
MCQmedium

A project manager wants a shared workspace where team members can create and track tasks, set deadlines, and collaborate on documents. This workspace should integrate with Microsoft Teams for quick access. Which Microsoft 365 service is best suited for this purpose?

A.Microsoft Lists
B.Microsoft Planner
C.Microsoft To Do
D.Microsoft Project Online
AnswerB

Microsoft Planner is a collaborative task management tool built around a visual Kanban board where each task has assignees, due dates, checklists, labels, and file attachments. Every Planner plan is backed by a Microsoft 365 Group, giving the team a shared mailbox, calendar, and SharePoint document library for co-authoring, and the Board can be embedded into Teams as a tab. Its simplicity and native Teams integration make it the correct choice for a shared workspace with assignments and deadlines.

Why this answer

Microsoft Planner is the correct choice because it provides a shared workspace (Plan) where team members can create and track tasks, set deadlines, and collaborate on documents. It integrates natively with Microsoft Teams via the Planner tab, allowing quick access within a Teams channel, and supports file attachments from SharePoint/OneDrive for collaboration.

Exam trap

The trap here is that candidates often confuse Microsoft Lists with Planner because both involve tracking items, but Lists is for static data collection (like a spreadsheet) while Planner is for dynamic task management with assignments and deadlines.

How to eliminate wrong answers

Option A is wrong because Microsoft Lists is a data-tracking app for creating custom lists (e.g., issue trackers, inventories) but lacks built-in task assignment, deadline tracking, and Kanban-style task management that Planner offers. Option C is wrong because Microsoft To Do is a personal task management tool for individual users, not designed for team collaboration or shared workspaces with document collaboration. Option D is wrong because Microsoft Project Online is a full-featured project management solution for complex scheduling, resource management, and Gantt charts, which is overkill for a simple shared workspace and does not integrate as seamlessly with Teams for quick task tracking.

102
MCQhard

An organization needs to prevent users from sharing documents that contain credit card numbers via email and Microsoft Teams. When a user attempts to share such a document, they should see a policy tip explaining the restriction. Which Microsoft Purview solution should the compliance team configure?

A.Microsoft Purview Information Barriers
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Retention Policies
D.Microsoft Purview Sensitivity Labels
AnswerB

Microsoft Purview Data Loss Prevention (DLP) is designed to identify, monitor, and protect sensitive data through content analysis based on sensitive information types, including credit card numbers. DLP policies can be applied to Exchange, SharePoint, OneDrive, Teams, and endpoints, and they evaluate actions like external sharing or downloads. When a user attempts to share a document containing a credit card number, the policy can block the sharing action and display a policy tip that informs the user about the violation. This matches the requirement precisely.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect sensitive information types—such as credit card numbers—in documents and communications. DLP policies can be configured to block or warn users via policy tips when they attempt to share such content through email or Microsoft Teams, enforcing compliance without disrupting legitimate work.

Exam trap

The trap here is that candidates often confuse Sensitivity Labels (which classify data) with DLP (which enforces actions based on that classification or on sensitive data patterns), leading them to choose D when the question specifically asks for a solution that scans for credit card numbers and shows policy tips.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Barriers restrict communication and collaboration between specific user groups (e.g., to prevent conflicts of interest), but they do not inspect content for sensitive data like credit card numbers or provide policy tips. Option C is wrong because Microsoft Purview Retention Policies manage how long content is kept or deleted for legal or regulatory purposes, not to prevent sharing of sensitive data in real time. Option D is wrong because Microsoft Purview Sensitivity Labels classify and protect content based on sensitivity (e.g., 'Confidential'), but they do not natively scan for specific data patterns like credit card numbers or trigger policy tips on their own; they require integration with DLP for such enforcement.

103
MCQmedium

A marketing manager needs to create a modern intranet site that publishes news, important announcements, and upcoming events. The site must be responsive on mobile devices and allow employees to like, comment, and share articles. Which Microsoft 365 service should they use?

A.Microsoft Teams
B.SharePoint Communication site
C.Microsoft Viva Engage
D.Microsoft Viva Connections
AnswerB

SharePoint Communication sites are the specific modern intranet site type built to broadcast information to a broad audience. They provide flexible page layouts, news web parts, audience targeting, scheduling, approval workflows, and responsive mobile rendering, making them ideal for a marketing manager publishing company news and events. These sites integrate with Viva Connections and Teams, but the communication site itself is the authoritative content repository and structured intranet destination.

Why this answer

A SharePoint Communication site is designed for broadcasting news, announcements, and events to a broad audience, with built-in support for responsive mobile rendering and social features like likes, comments, and sharing. This makes it the correct choice for a modern intranet that needs to engage employees across devices.

Exam trap

The trap here is that candidates often confuse Microsoft Viva Connections (a dashboard) with the underlying content source (SharePoint Communication site), leading them to select D when the question explicitly asks for the service used to create the intranet site.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is a chat-based collaboration hub focused on persistent conversations and channel-based teamwork, not a publishing platform for news and announcements with like/comment/share capabilities. Option C is wrong because Microsoft Viva Engage (formerly Yammer) is an enterprise social network for community discussions and knowledge sharing, but it lacks the structured page publishing and modern intranet site features required for news and events. Option D is wrong because Microsoft Viva Connections is a personalized dashboard that aggregates content from SharePoint, Teams, and other sources, but it is not a site creation service itself—it depends on a SharePoint Communication site as its underlying content source.

104
MCQhard

A healthcare provider must ensure that patient health information (PHI) is not accidentally shared outside the organization. They want to automatically detect if an email contains PHI (such as diagnosis codes) and block it from being sent externally. Additionally, the sender should receive a notification explaining the block. Which Microsoft Purview solution should be configured?

A.Microsoft Purview Information Protection
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Insider Risk Management
D.Microsoft Purview Audit
AnswerB

Microsoft Purview Data Loss Prevention (DLP) is correct because it is designed precisely for this scenario: identifying sensitive information types (such as U.S. HIPAA data or generic health record patterns) and enforcing protective actions on outbound messages. When a DLP policy is applied to Exchange Online, the service scans email content and attachments in transit, matches against defined conditions, and can block the email, send a policy tip to the sender, or generate an incident report. For a healthcare provider, DLP can use regulatory templates (like HIPAA) to automatically prevent accidental or deliberate leakage of patient health information via email.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect sensitive information—such as patient health information (PHI) with diagnosis codes—in emails and automatically block external transmission while sending a notification to the sender. DLP policies can be configured with sensitive information types (e.g., HIPAA-defined PHI patterns) and rules to enforce actions like blocking and policy tips.

Exam trap

The trap here is that candidates often confuse Information Protection (labeling) with DLP (enforcement), assuming that applying a sensitivity label alone will block external sharing, when in fact DLP is required to enforce the block and notification action.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Protection focuses on classifying and labeling sensitive data (e.g., applying sensitivity labels) but does not inherently enforce real-time blocking of email transmission or send sender notifications; it requires integration with DLP for such actions. Option C is wrong because Microsoft Purview Insider Risk Management is designed to detect and investigate risky user activities (e.g., data exfiltration by insiders) using analytics and alerts, not to automatically block outbound emails containing specific content. Option D is wrong because Microsoft Purview Audit provides logging and investigation of past activities (e.g., who accessed what), but it cannot proactively block emails or notify senders in real time.

105
MCQmedium

A project team needs to create a central workspace where they can store project documents, assign tasks, track a shared calendar of milestones, and have threaded discussions about each item. The solution must integrate directly with Microsoft Teams. Which Microsoft 365 service provides this out-of-the-box?

A.SharePoint Online
B.Microsoft Lists
C.Planner
D.Project Online
AnswerA

SharePoint Online provides the full collaborative workspace the team needs: a team site includes document libraries for file storage and versioning, list apps for tracking tasks and issues, a shared calendar web part, and a discussion board for threaded conversations. These capabilities can also be surfaced directly inside Microsoft Teams via tabs, making SharePoint the underlying storage and permissions backbone for Teams-connected teamwork.

Why this answer

SharePoint Online provides a central workspace with document libraries for storing project documents, task lists for assignment, shared calendars for milestones, and discussion boards for threaded conversations. It integrates natively with Microsoft Teams via the SharePoint tab, allowing the team to access all these features directly within the Teams interface without additional configuration.

Exam trap

The trap here is that candidates often confuse Planner or Microsoft Lists as a complete workspace solution, but they lack the document storage, calendar, and threaded discussion capabilities that SharePoint Online provides out-of-the-box.

How to eliminate wrong answers

Option B (Microsoft Lists) is wrong because it is a data-tracking app for creating simple lists (e.g., issue trackers, inventories) but does not include document storage, shared calendars, or threaded discussions out-of-the-box. Option C (Planner) is wrong because it focuses solely on task management with Kanban boards and charts, lacking document libraries, calendars, and threaded discussions. Option D (Project Online) is wrong because it is a premium project management solution for complex scheduling and resource management, not a lightweight central workspace, and its integration with Teams requires additional connectors or third-party tools.

106
MCQeasy

A company uses a cloud provider and is billed monthly based only on the exact amount of storage used and the number of compute hours consumed. They can increase or decrease usage at any time without upfront commitments. Which cloud computing characteristic does this billing model primarily demonstrate?

A.On-demand self-service
B.Rapid elasticity
C.Measured service
D.Resource pooling
AnswerC

Measured service is the cloud characteristic where resource usage is automatically metered, monitored, controlled, and reported, enabling a transparent pay-per-use billing model. The scenario's statement that the company is billed monthly based on actual usage is a textbook example of this attribute. It allows the provider to charge only for consumed resources and gives the customer visibility into usage and costs.

Why this answer

The billing model charges only for actual storage used and compute hours consumed, with no upfront commitments and the ability to adjust usage at any time. This directly aligns with the 'measured service' characteristic, where cloud resource usage is metered, monitored, and billed based on consumption. The key is that the provider tracks and reports usage transparently, enabling a pay-per-use model.

Exam trap

The trap here is that candidates confuse 'measured service' with 'rapid elasticity' because both involve scaling, but measured service is specifically about metering and billing, not the speed of scaling.

How to eliminate wrong answers

Option A is wrong because on-demand self-service refers to a user's ability to provision resources automatically without human interaction, not the billing mechanism. Option B is wrong because rapid elasticity describes the ability to quickly scale resources up or down, which is a separate characteristic from how usage is metered and billed. Option D is wrong because resource pooling refers to the provider's multi-tenant model where physical and virtual resources are shared among customers, not the consumption-based billing approach.

107
MCQeasy

A small business with 10 employees needs the desktop versions of Microsoft 365 apps (Word, Excel, PowerPoint) and 1 TB of cloud storage per user. They do not need business email because they use a separate provider. Which Microsoft 365 plan should they purchase?

A.Microsoft 365 Business Basic
B.Microsoft 365 Business Standard
C.Microsoft 365 Apps for Business
D.Microsoft 365 Business Premium
AnswerC

Microsoft 365 Apps for Business is the correct choice because it delivers the full desktop versions of Office applications (Word, Excel, PowerPoint, Outlook, and others) that can be installed on up to five devices per user, along with 1 TB of OneDrive storage, yet it deliberately excludes Exchange Online email and other collaboration workloads. For a small business that only needs desktop Office, this plan meets the requirement at the lowest cost among the options that provide desktop apps.

Why this answer

Microsoft 365 Apps for Business is the correct plan because it provides the desktop versions of Word, Excel, and PowerPoint along with 1 TB of OneDrive cloud storage per user, but does not include Exchange Online (business email). This matches the requirement exactly, as the customer uses a separate email provider and only needs the Office apps and storage.

Exam trap

The trap here is that candidates often assume Business Standard is the minimum for desktop apps, forgetting that Microsoft 365 Apps for Business is a separate, lower-cost plan that excludes Exchange Online and is specifically designed for organizations that do not need Microsoft-hosted email.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Basic includes only web and mobile versions of the Office apps (no desktop apps) and includes Exchange Online email, which the customer does not need. Option B is wrong because Microsoft 365 Business Standard includes desktop apps and 1 TB storage but also includes Exchange Online email, making it an unnecessary expense for a customer who already has a separate email provider. Option D is wrong because Microsoft 365 Business Premium includes everything in Business Standard plus advanced security and device management features (e.g., Microsoft Defender, Intune), which are not required and add cost without benefit.

108
MCQeasy

A training manager needs to create a simple video that includes screen recordings, webcam overlay, and transitions to announce a new compliance policy. The manager wants to use a Microsoft 365 app that is designed for video creation and editing. Which Microsoft 365 app should the manager use?

A.Microsoft Clipchamp
B.Microsoft Stream
C.Microsoft Teams
D.Microsoft PowerPoint
AnswerA

Clipchamp is Microsoft's web-based video editor included with Microsoft 365 consumer and commercial plans. Its timeline-based editor combines screen recordings, webcam footage, imported images, and audio, then lets you trim clips, add transitions, text overlays, filters, and captions before exporting or publishing. That makes it the appropriate tool for creating a simple training video, because you can produce and polish a finished MP4 in one workflow.

Why this answer

Microsoft Clipchamp is the correct app because it is a dedicated video creation and editing tool included with Microsoft 365, specifically designed for tasks like combining screen recordings, webcam overlays, and transitions. Unlike other Microsoft 365 apps, Clipchamp provides a full timeline-based editor with built-in support for these features, making it ideal for producing a polished compliance policy announcement video.

Exam trap

The trap here is that candidates often confuse Microsoft Stream (a video hosting service) with a video editor, or assume PowerPoint's recording features are sufficient for multi-track video editing, when Clipchamp is the only Microsoft 365 app purpose-built for creating and editing videos with screen recordings, webcam overlays, and transitions.

How to eliminate wrong answers

Option B (Microsoft Stream) is wrong because Stream is a video hosting and sharing platform, not a video creation or editing tool; it lacks features like screen recording, webcam overlay, and transition editing. Option C (Microsoft Teams) is wrong because Teams is a collaboration and communication app focused on chat, meetings, and file sharing, not a video editor; while it can record meetings, it cannot edit or add transitions to existing recordings. Option D (Microsoft PowerPoint) is wrong because PowerPoint is a presentation software that can record slides with narration and webcam, but it does not support multi-track video editing, screen recording with overlay, or custom transitions between video clips; its video export is limited to slide-based recordings.

109
MCQmedium

A company wants to ensure that sensitive documents classified as 'Confidential' are automatically encrypted and have restricted access permissions applied when they are shared via email. The protection must persist even if the email is forwarded to external parties. Which Microsoft Purview solution should be used?

A.Microsoft Purview Information Protection
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Message Encryption
D.Microsoft Purview Compliance Manager
AnswerA

Sensitivity labels in Microsoft Purview Information Protection can apply persistent encryption via Azure Rights Management so that documents carry their own usage restrictions (view, edit, print, forward) wherever they travel. Because the encryption and permissions are embedded in the document itself, the protection remains enforced when the file is sent to external users or copied to another tenant. This is exactly what you need for confidential documents that must stay controlled after they leave the organization.

Why this answer

Microsoft Purview Information Protection (A) is correct because it enables classification and labeling of documents (e.g., 'Confidential'), with built-in encryption and rights management that persists regardless of where the document is shared or forwarded. This is achieved through Azure Rights Management (Azure RMS), which enforces access restrictions even when the email is forwarded to external parties, ensuring the protection travels with the content.

Exam trap

The trap here is that candidates confuse Microsoft Purview Message Encryption (which encrypts the email transport) with Information Protection (which applies persistent rights management to the content itself), leading them to choose C when the question explicitly requires protection that persists after forwarding.

How to eliminate wrong answers

Option B (Microsoft Purview Data Loss Prevention) is wrong because DLP policies detect and prevent accidental sharing of sensitive data but do not apply persistent encryption or access restrictions that survive forwarding; they block or warn at the point of transmission. Option C (Microsoft Purview Message Encryption) is wrong because it encrypts the email message itself (using OME) but does not apply persistent rights management to attachments or documents; once decrypted, the content loses protection. Option D (Microsoft Purview Compliance Manager) is wrong because it is a risk assessment and compliance management tool that tracks regulatory posture, not a solution for applying encryption or access controls to content.

110
MCQeasy

A sales team needs to create a shared list of customer contact information with custom fields like company, email, phone, and deal stage. The list should be accessible from within Outlook and allow real-time updates by multiple users. Which Microsoft 365 app should they use?

A.Microsoft Lists
B.Microsoft To Do
C.Microsoft Planner
D.Microsoft Dynamics 365
AnswerA

Microsoft Lists is a SharePoint-backed data-tracking app in Microsoft 365 that lets you build a tailored customer contact list with custom columns for name, email, phone, and other fields. It supports real-time multi-user editing, version history, and sorting or filtering, and it appears in Outlook via the "My Lists" entry point or direct list sharing. Because it is built on SharePoint, it can be embedded in Teams and automated with Power Automate, making it the correct fit for a shared, structured list.

Why this answer

Microsoft Lists is the correct choice because it provides a customizable, shared list that supports custom columns (e.g., company, email, phone, deal stage) and real-time collaboration. It integrates directly with Outlook via the Lists app or by adding a list as a tab in Outlook, allowing the sales team to access and update the list without leaving their email client.

Exam trap

The trap here is that candidates may confuse Microsoft Lists with Microsoft To Do or Planner because both involve task tracking, but Lists is the only one that supports custom columns and real-time multi-user editing for structured data like contacts.

How to eliminate wrong answers

Option B is wrong because Microsoft To Do is a personal task management app that does not support custom fields or real-time multi-user editing of shared lists; it lacks the column customization and collaborative features needed. Option C is wrong because Microsoft Planner is designed for team task management with boards and buckets, not for creating a shared list of contacts with custom fields, and it does not integrate directly into Outlook for inline access. Option D is wrong because Microsoft Dynamics 365 is a full Customer Relationship Management (CRM) platform that is far more complex and costly than needed; it is not a simple list app and does not provide the lightweight, Outlook-integrated shared list functionality required.

111
MCQmedium

An administrator is reviewing a request from users who need to reduce maintenance of power, cooling, and server replacement. Cloud concept or benefit best matches this requirement?

A.Reduced data center management
B.Microsoft Planner
C.Data Loss Prevention (DLP)
D.Sensitivity labels
AnswerA

Cloud providers manage physical data center facilities and hardware for cloud services.

Why this answer

The users' requirement to reduce maintenance of power, cooling, and server replacement directly maps to the cloud benefit of reduced data center management. By moving to a cloud model, the cloud provider assumes responsibility for the physical infrastructure, including hardware lifecycle, environmental controls, and facility upkeep, allowing the organization to offload these operational burdens.

Exam trap

The trap here is that candidates may confuse operational benefits like reduced maintenance with specific Microsoft 365 features (Planner, DLP, sensitivity labels), failing to recognize that the question is about fundamental cloud concepts and benefits, not individual product capabilities.

How to eliminate wrong answers

Option B is wrong because Microsoft Planner is a task management and planning application within Microsoft 365, not a cloud concept or benefit related to infrastructure maintenance. Option C is wrong because Data Loss Prevention (DLP) is a security policy technology that helps protect sensitive data from unauthorized sharing or leakage, not a benefit addressing physical data center maintenance. Option D is wrong because sensitivity labels are classification and protection tools applied to data and documents for governance and compliance, not a cloud concept that reduces power, cooling, or server replacement tasks.

112
Multi-Selectmedium

A company uses Microsoft 365 E3 and wants to implement a collaboration solution that allows multiple users to co-author documents in real time, track version history, and set permissions at the document level. Which THREE Microsoft 365 services can fulfill these requirements?

Select 3 answers
A.SharePoint Online
B.OneDrive for Business
C.Microsoft Teams
D.Exchange Online
E.Yammer
AnswersA, B, C

SharePoint provides team collaboration with co-authoring and permissions.

Why this answer

SharePoint Online is correct because it provides document libraries that support real-time co-authoring, version history tracking, and granular permission settings at the document level. These features align directly with the requirements for collaborative document management in Microsoft 365 E3.

Exam trap

The trap here is that candidates often confuse Microsoft Teams as a separate collaboration tool, but Teams relies on SharePoint Online and OneDrive for its file storage and co-authoring capabilities, making it a valid answer when the question explicitly asks for services that fulfill the requirements directly.

113
MCQmedium

A compliance officer needs to identify users who are at risk of leaking sensitive data based on their activities such as copying files to USB drives or emailing content outside the organization. The solution must also allow reviewing the activities in a case-based workflow. Which Microsoft Purview solution should they use?

A.Microsoft Purview Data Loss Prevention
B.Microsoft Purview Insider Risk Management
C.Microsoft Purview Audit (Premium)
D.Microsoft Purview Communication Compliance
AnswerB

Microsoft Purview Insider Risk Management is the correct solution because it correlates signals from audit logs, DLP alerts, and other behavioral indicators to mathematically assess a user's risk of insider activity. It uses predefined and customizable policies to detect anomalies such as mass file downloads, unusual access times, or exfiltration attempts, and then places the user in a triage space with a case-based workflow. This is specifically designed to help compliance officers identify, investigate, and act on users who are at risk of committing data leaks.

Why this answer

Microsoft Purview Insider Risk Management is specifically designed to detect, investigate, and act on risky user activities that could lead to data leaks, such as copying files to USB drives or emailing sensitive content externally. It provides a case-based workflow for reviewing and managing these activities, aligning directly with the compliance officer's requirements.

Exam trap

The trap here is that candidates often confuse Data Loss Prevention (DLP) with Insider Risk Management, but DLP is a preventive control that blocks actions in real-time, whereas Insider Risk Management is a detective control that identifies risky users and provides a case workflow for post-event review.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Loss Prevention (DLP) focuses on preventing data leaks through policies that block or warn users in real-time, but it does not provide a case-based workflow for reviewing activities after they occur. Option C is wrong because Microsoft Purview Audit (Premium) logs user and admin activities for forensic investigation but lacks the risk analysis, user risk scoring, and case management workflow needed to identify at-risk users proactively. Option D is wrong because Microsoft Purview Communication Compliance is designed to detect policy violations in communications (e.g., harassment, insider trading) and does not cover activities like copying files to USB drives or emailing content outside the organization.

114
MCQmedium

An administrator is reviewing a request from users who need to give different departments different Microsoft 365 features without wasting licenses. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Assign plans based on user role and requirements
B.Microsoft Whiteboard
C.Microsoft Forms
D.Microsoft Stream
AnswerA

Licensing should match the features each user group actually needs.

Why this answer

The most relevant concept is assigning plans based on user role and requirements because it directly addresses the need to provide different Microsoft 365 features to different departments without wasting licenses. This involves using group-based licensing or per-user license assignment to match features like Exchange Online, SharePoint, or Teams to specific job functions, ensuring cost efficiency and compliance with licensing terms.

Exam trap

The trap here is that candidates confuse specific Microsoft 365 applications (like Whiteboard, Forms, or Stream) with licensing administration concepts, leading them to pick a product name instead of the correct licensing strategy.

How to eliminate wrong answers

Option B is wrong because Microsoft Whiteboard is a specific application, not a licensing or administration concept for managing feature assignments across departments. Option C is wrong because Microsoft Forms is a survey tool, irrelevant to license optimization or role-based feature allocation. Option D is wrong because Microsoft Stream is a video service, not a mechanism for controlling license distribution or feature access.

115
MCQmedium

An administrator needs to monitor and investigate potential data breaches by reviewing detailed records of file access and sharing activities across Microsoft 365. They require a centralized report showing who accessed what, from where, and any unusual patterns. Which tool should they use?

A.Microsoft 365 Defender
B.Microsoft Purview Audit (Standard)
C.Microsoft Purview eDiscovery
D.Microsoft Secure Score
AnswerB

Microsoft Purview Audit (Standard) is the correct tool because it records timestamped events for user and admin actions across Exchange, SharePoint, OneDrive, Teams, and Azure AD. Investigators can query the unified audit log to identify exactly when a file was accessed, downloaded, shared, or deleted and which account performed the action. This historical, activity-level evidence is essential for monitoring, triaging, and thoroughly investigating a potential data breach, with default retention of 90 days for standard events.

Why this answer

Microsoft Purview Audit (Standard) is the correct tool because it provides a centralized, searchable log of all file access and sharing activities across Microsoft 365 services, including who accessed what, from which IP address, and when. This allows administrators to detect and investigate unusual patterns indicative of data breaches by reviewing detailed audit records.

Exam trap

The trap here is that candidates often confuse Microsoft 365 Defender (a threat protection tool) with audit logging, but the question specifically asks for a centralized report of historical file access and sharing activities, which only Purview Audit provides.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Defender is a security incident response and threat protection platform that focuses on detecting and responding to active threats (like malware or phishing), not on providing detailed historical audit logs of file access and sharing activities. Option C is wrong because Microsoft Purview eDiscovery is designed for legal discovery and compliance searches to find and export content (e.g., emails, documents) for litigation, not for monitoring real-time or historical access patterns. Option D is wrong because Microsoft Secure Score is a security posture assessment tool that measures an organization's security configuration against best practices, not a logging or monitoring tool for file access activities.

116
MCQeasy

A company uses a cloud service that provides virtual machines. The company manages the operating system, middleware, and applications, while the cloud provider manages the physical hardware, networking, and data center security. Which cloud service model does this represent?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Desktop as a Service (DaaS)
AnswerA

IaaS (Infrastructure as a Service) delivers virtualized compute resources as ready-to-use VMs, and the customer retains full control over the guest operating system, runtime, and application stack. The cloud provider is responsible for the physical hosts, the hypervisor, and the data-center networking, while the customer patches, configures, and secures the OS. In this scenario, the company is using a cloud service that provides virtual machines, which directly matches the IaaS delivery model.

Why this answer

This scenario describes Infrastructure as a Service (IaaS) because the customer manages the operating system, middleware, and applications, while the cloud provider is responsible for the physical hardware, networking, and data center security. In IaaS, the provider delivers virtualized computing resources over the internet, and the customer retains control over the guest OS, storage, and deployed applications, which matches the division of responsibilities given.

Exam trap

The trap here is that candidates confuse IaaS with PaaS because both involve virtual machines, but PaaS abstracts the OS and middleware, so the key differentiator is who manages the operating system and middleware—if the customer manages them, it is IaaS.

How to eliminate wrong answers

Option B (PaaS) is wrong because in Platform as a Service, the provider manages the operating system, middleware, and runtime environment, leaving the customer to only deploy and manage their own applications and data, not the OS or middleware. Option C (SaaS) is wrong because in Software as a Service, the provider manages the entire application stack, including the operating system, middleware, and applications, and the customer only uses the software via a web browser or client, with no management of the underlying infrastructure. Option D (DaaS) is wrong because Desktop as a Service delivers virtual desktops to end users, where the provider manages the desktop OS and underlying infrastructure, and the customer typically does not manage the OS or middleware as described.

117
MCQeasy

A company wants to ensure that all Microsoft 365 users authenticate using multi-factor authentication (MFA). Which Microsoft 365 security feature should they configure?

A.Microsoft Intune compliance policies
B.Microsoft Purview Data Loss Prevention
C.Microsoft Defender XDR
D.Microsoft Entra ID Conditional Access
AnswerD

Microsoft Entra ID Conditional Access is the correct solution because it enables administrators to build granular policies that evaluate sign-in risk, location, device compliance, and user attributes, and then require MFA as one of the access controls. By targeting all users or specific groups, an organization can ensure MFA is enforced for every authentication attempt, satisfying the requirement.

Why this answer

Microsoft Entra ID Conditional Access. Conditional Access policies enable organizations to enforce MFA based on conditions such as user, location, device state, or risk level. Microsoft Intune compliance policies (Option A) enforce device compliance requirements but do not directly enforce MFA.

Microsoft Purview Data Loss Prevention (Option B) focuses on preventing unauthorized sharing of sensitive data, not authentication. Microsoft Defender XDR (Option C) is a threat detection and response solution, not an MFA enforcement tool. Therefore, only Conditional Access (Option D) can enforce MFA for all users.

118
MCQeasy

A company uses a cloud provider that hosts multiple customers on the same physical servers. Each customer's data and applications are isolated, but customers have no knowledge or control over the exact physical location of their resources. Which cloud characteristic does this describe?

A.Resource pooling
B.Rapid elasticity
C.On-demand self-service
D.Measured service
AnswerA

Resource pooling is the cloud characteristic that lets a provider serve many customers, or tenants, from shared physical infrastructure—servers, storage, and network—while isolating each tenant's data and workloads through virtualization and access controls. In Microsoft 365, this means compute and storage capacity are pooled across customers but logically segmented per tenant. This directly matches the scenario's wording, so it is the correct answer.

Why this answer

Resource pooling is the correct answer because the scenario describes a multi-tenant model where the cloud provider's physical and virtual resources are pooled to serve multiple customers, with isolation between tenants. Customers have no knowledge or control over the exact physical location of their resources, which is a defining characteristic of resource pooling as defined by NIST SP 800-145.

Exam trap

The trap here is that candidates often confuse resource pooling with rapid elasticity because both involve shared infrastructure, but resource pooling specifically focuses on multi-tenancy and location transparency, not dynamic scaling.

How to eliminate wrong answers

Option B (Rapid elasticity) is wrong because it refers to the ability to quickly scale resources up or down based on demand, not to multi-tenant isolation or location transparency. Option C (On-demand self-service) is wrong because it describes the capability for a user to provision computing capabilities automatically without requiring human interaction with the provider, not the pooling of resources across customers. Option D (Measured service) is wrong because it involves metering and billing based on usage (e.g., pay-per-use), not the sharing of physical infrastructure among multiple tenants.

119
MCQmedium

A company subscribes to a cloud service where they can provision virtual machines, choose the operating system, install any software, and manage all applications. The cloud provider is responsible for the underlying physical hardware and network infrastructure. Which cloud service model is being used?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.On-premises
AnswerA

IaaS is correct because the provider supplies virtualized compute, storage, and networking on physical servers it owns and operates, while customers provision these resources as virtual machines and install their own operating systems, runtime environments, and applications. This gives customers the same administrative control over the OS and application stack as they would have on physical servers, without needing to manage datacenter hardware, cooling, or power. The ability to define the OS version, configure its settings, and deploy arbitrary software exactly matches the scenario's description of controlling both OS and applications.

Why this answer

This scenario describes Infrastructure as a Service (IaaS) because the customer provisions virtual machines, chooses the operating system, installs software, and manages applications, while the cloud provider is responsible for the underlying physical hardware and network infrastructure. In IaaS, the provider delivers virtualized computing resources over the internet, and the customer retains control over the OS, storage, and deployed applications, which matches the description exactly.

Exam trap

The trap here is that candidates often confuse IaaS with PaaS because both involve virtual machines, but PaaS abstracts the OS and runtime, whereas IaaS gives the customer full control over the OS and software installation, as explicitly stated in the question.

How to eliminate wrong answers

Option B (PaaS) is wrong because PaaS provides a managed platform where the provider handles the OS, runtime, and middleware, and the customer only deploys and manages applications—not the OS or full software stack. Option C (SaaS) is wrong because SaaS delivers fully managed applications accessed via a browser or client, with no customer control over the underlying infrastructure, OS, or software installation. Option D (On-premises) is wrong because on-premises deployment means the customer owns and manages all hardware, software, and networking within their own data center, contradicting the cloud provider's responsibility for physical infrastructure.

120
MCQhard

A company has employees who frequently work from home on personal devices. They need to ensure corporate data in Microsoft 365 is protected even if the device is lost or compromised, without managing the entire device. What should they implement?

A.Microsoft Intune App Protection Policies
B.Microsoft Defender for Endpoint
C.Microsoft Entra Conditional Access
D.Microsoft Purview Data Loss Prevention
AnswerA

Intune App Protection Policies (APP) are the correct choice because they provide mobile application management (MAM) capabilities that do not require device enrollment or full device management. APP applies policy directly to managed apps, allowing control over corporate data via features like preventing copy/paste, restricting save-as, enforcing app-level encryption, and enabling selective wipe of corporate data without removing personal data from a BYOD device. This gives protection of corporate data within apps on unmanaged personal devices, which is exactly what is needed for employees working from home on personal devices.

Why this answer

Microsoft Intune App Protection Policies (MAM) protect data at the app level without device enrollment. Conditional Access controls access. DLP prevents data loss.

MAM is the correct approach for unmanaged devices.

121
MCQmedium

A compliance-aware administrator is selecting the right Microsoft 365 capability to use Microsoft 365 and another public cloud provider for different workloads. Cloud concept or benefit best matches this requirement?

A.Microsoft Planner
B.Sensitivity labels
C.Multi-cloud
D.Data Loss Prevention (DLP)
AnswerC

Multi-cloud means using cloud services from more than one public cloud provider.

Why this answer

Multi-cloud is the correct answer because the requirement explicitly involves using Microsoft 365 alongside another public cloud provider for different workloads. Multi-cloud refers to the strategy of leveraging services from multiple cloud providers (e.g., Microsoft Azure and AWS) to avoid vendor lock-in, optimize costs, or meet compliance needs. This directly matches the scenario of using Microsoft 365 and another public cloud provider together.

Exam trap

The trap here is that candidates may confuse 'multi-cloud' with 'hybrid cloud' (which combines public and private cloud) or mistakenly think a specific Microsoft 365 feature like DLP or Sensitivity labels is the answer, when the question is about the overarching cloud concept of using multiple public providers.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management and planning tool within Microsoft 365, not a cloud concept or benefit that addresses multi-provider workload distribution. Option B is wrong because Sensitivity labels are a Microsoft Information Protection feature used to classify and protect data based on sensitivity, not a cloud deployment model or strategy for using multiple providers. Option D is wrong because Data Loss Prevention (DLP) is a security policy mechanism to prevent accidental sharing of sensitive data, not a cloud concept describing the use of multiple cloud providers.

122
MCQmedium

A compliance officer needs to automatically classify documents stored in SharePoint Online that contain personally identifiable information (PII) such as social security numbers. The classification must apply a sensitivity label that encrypts the document and restricts access to only employees in the Legal department. The process should run without any user interaction. Which Microsoft Purview solution should be configured?

A.Microsoft Purview Data Lifecycle Management
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Information Protection with auto-labeling
D.Microsoft Purview Insider Risk Management
AnswerC

Microsoft Purview Information Protection with auto-labeling is the correct solution because it natively applies sensitivity labels to files and emails based on content matches such as sensitive info types, trainable classifiers, or manual conditions. When an auto-labeling policy applies a sensitivity label, that label can automatically enforce encryption via Azure Rights Management, add visual markings, and restrict access, and the classification persists with the document or email across platforms. This provides the compliance officer with true automatic classification and protection without requiring user intervention.

Why this answer

Microsoft Purview Information Protection with auto-labeling can automatically detect PII (e.g., social security numbers) in documents stored in SharePoint Online and apply a sensitivity label that encrypts the content and restricts access to the Legal department. This process runs without user interaction, meeting the compliance officer's requirement for automatic classification and protection.

Exam trap

The trap here is that candidates often confuse DLP policies (which block sharing) with auto-labeling policies (which apply sensitivity labels and encryption), but DLP does not automatically encrypt or restrict access via sensitivity labels.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Lifecycle Management focuses on retaining or deleting data based on policies (e.g., retention labels), not on automatically classifying or encrypting documents with sensitivity labels. Option B is wrong because Microsoft Purview Data Loss Prevention (DLP) is designed to prevent unauthorized sharing or exfiltration of sensitive data (e.g., blocking emails or file transfers), not to apply sensitivity labels that encrypt and restrict access. Option D is wrong because Microsoft Purview Insider Risk Management detects risky user activities (e.g., data theft by insiders) through analytics and alerts, but does not automatically classify or encrypt documents with sensitivity labels.

123
MCQmedium

A company with 500 Microsoft 365 E3 users wants to add the highest level of threat protection and advanced investigation capabilities for their security team. Which licensing add-on should they purchase?

A.Microsoft 365 E5 Security
B.Microsoft 365 E5 Compliance
C.Microsoft 365 E5
D.Microsoft Defender for Microsoft 365 Plan 2 only
AnswerA

Microsoft 365 E5 Security is an add-on for E3 that includes advanced security features such as Microsoft 365 Defender, Defender for Microsoft 365 Plan 2, Defender for Identity, and more, providing the highest threat protection and investigation.

Why this answer

Microsoft 365 E5 Security is the correct add-on because it bundles the highest level of threat protection (Microsoft Defender for Office 365 Plan 2, Microsoft Defender for Endpoint Plan 2, and Microsoft Defender for Identity) along with advanced investigation capabilities like automated investigation and response (AIR), threat analytics, and advanced hunting in Microsoft 365 Defender. This meets the requirement for top-tier threat protection and advanced investigation without upgrading the entire E3 base license to E5.

Exam trap

The trap here is that candidates often confuse 'Microsoft 365 E5' (a full suite upgrade) with 'Microsoft 365 E5 Security' (an add-on), or they assume that Defender for Office 365 Plan 2 alone provides all advanced investigation features, when in fact E5 Security bundles multiple Defender plans and advanced hunting tools.

How to eliminate wrong answers

Option B is wrong because Microsoft 365 E5 Compliance focuses on data governance, eDiscovery, and compliance management (e.g., Communication Compliance, Insider Risk Management), not threat protection or advanced security investigation capabilities. Option C is wrong because Microsoft 365 E5 is a full suite upgrade that includes both security and compliance features, but the question asks for an add-on to existing E3 licenses, not a full license upgrade; purchasing E5 would be redundant and cost-inefficient. Option D is wrong because Microsoft Defender for Microsoft 365 Plan 2 only provides threat protection for email, collaboration tools, and endpoints, but it does not include the full breadth of advanced investigation capabilities (e.g., Microsoft Defender for Identity, Microsoft Defender for Cloud Apps) that are bundled in E5 Security.

124
MCQmedium

An administrator is reviewing a request from users who need to reset user passwords without assigning Global Administrator. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Password Administrator
C.Microsoft Forms
D.Microsoft Stream
AnswerB

Password Administrator can reset passwords for many users without full tenant-wide rights.

Why this answer

The Password Administrator role in Microsoft Entra ID (formerly Azure AD) allows users to reset passwords for non-administrator users and manage service requests without granting the highly privileged Global Administrator role. This directly addresses the user request while adhering to the principle of least privilege, making it the most relevant concept for this scenario.

Exam trap

The trap here is that candidates may confuse the Password Administrator role with the Global Administrator role, assuming only Global Admin can reset passwords, or they might pick a random Microsoft service like Forms or Stream because they sound 'administrative' without understanding the specific role-based access control (RBAC) permissions in Microsoft Entra ID.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a collaboration tool for visual brainstorming, not an administrative role or licensing concept for password management. Option C is wrong because Microsoft Forms is a survey and data collection tool, unrelated to user administration or password reset capabilities. Option D is wrong because Microsoft Stream is a video management and sharing service, with no role or feature for resetting user passwords.

125
MCQeasy

An HR manager needs to collect anonymous feedback from employees about a new benefits policy. They want the responses to be automatically summarized into charts and graphs. Which Microsoft 365 app is best suited for this task?

A.Microsoft Forms
B.Microsoft Excel
C.Microsoft Sway
D.Microsoft Power BI
AnswerA

Forms includes built-in anonymous response options and automatically generates charts from responses.

Why this answer

Microsoft Forms is the correct choice because it is specifically designed for creating surveys and quizzes, with built-in support for anonymous responses and automatic generation of charts and graphs from collected data. The HR manager can create a feedback form, enable anonymous submissions, and view real-time summaries with visualizations directly within Forms, without needing additional tools.

Exam trap

The trap here is that candidates often confuse Microsoft Forms with Microsoft Power BI, assuming that any charting or graphing requirement must involve a dedicated analytics tool, but Forms handles simple survey summarization natively without needing Power BI's complexity.

How to eliminate wrong answers

Option B is wrong because Microsoft Excel is a spreadsheet application for data analysis and manual chart creation, but it lacks native anonymous survey capabilities and does not automatically collect responses or generate charts without manual setup. Option C is wrong because Microsoft Sway is a presentation and storytelling app for creating interactive reports and newsletters, not for collecting feedback or generating charts from survey data. Option D is wrong because Microsoft Power BI is a business analytics service for advanced data visualization and reporting from multiple data sources, but it is overkill for simple anonymous feedback collection and does not provide built-in survey creation or anonymous response handling.

126
MCQeasy

A company uses a cloud storage service that automatically increases its storage capacity without any manual intervention as new files are added. This behavior is an example of which cloud computing characteristic?

A.On-demand self-service
B.Broad network access
C.Resource pooling
D.Rapid elasticity
AnswerD

Rapid elasticity is the NIST essential characteristic that allows a cloud service to provision and release resources automatically, scaling out and in quickly and in line with real-time demand. A storage service that automatically increases or decreases its capacity based on usage is a textbook example of this behavior, because the customer perceives the scaling as seamless and often without pre-planning. This precisely matches the scenario, so it is the correct answer.

Why this answer

The scenario describes storage capacity automatically increasing as new files are added, which is the essence of rapid elasticity. This cloud characteristic allows resources to scale out and in automatically, often to the point where the user perceives unlimited capacity, without requiring manual provisioning or intervention.

Exam trap

The trap here is that candidates often confuse 'resource pooling' (the multi-tenant sharing of resources) with 'rapid elasticity' (the ability to scale resources up/down automatically), because both involve dynamic allocation, but pooling is about sharing among tenants while elasticity is about scaling for a single tenant's demand.

How to eliminate wrong answers

Option A is wrong because on-demand self-service refers to a user's ability to provision computing resources (e.g., spinning up a VM) through a web portal or API without human interaction with the provider, not the automatic scaling of capacity. Option B is wrong because broad network access describes the ability to access cloud services over standard network protocols (e.g., HTTPS, SSH) from a wide variety of devices (laptops, phones, tablets), not the dynamic adjustment of storage. Option C is wrong because resource pooling means the provider's computing resources are pooled to serve multiple customers using a multi-tenant model, with physical and virtual resources dynamically assigned and reassigned according to demand; it does not describe the automatic increase in capacity for a single customer's storage.

127
MCQhard

A compliance officer wants to automatically encrypt outgoing emails containing credit card numbers and also prevent recipients from forwarding or copying the content. Which Microsoft Purview solution should be applied?

A.Data Loss Prevention (DLP) policy with encryption
B.Sensitivity label with encryption and rights management
C.Microsoft Information Bar
D.Azure Information Protection unified labeling client
AnswerB

Sensitivity labels in Microsoft Purview are the correct mechanism because they support automatic application of encryption and usage restrictions such as 'Do Not Forward' or 'View-Only' through label policies. When a label is auto-applied based on sensitive content types or user actions, the associated encryption is enforced via Azure Rights Management, giving the compliance officer the required control. This native integration allows for automatic encryption of outgoing emails without requiring end-user intervention.

Why this answer

Sensitivity labels with encryption and rights management (Azure Rights Management) allow you to apply persistent protection that encrypts the email and restricts actions like forwarding, copying, or printing. This meets both requirements: automatic detection of credit card numbers via auto-labeling policies and enforcement of usage restrictions through Rights Management templates (e.g., Do Not Forward).

Exam trap

The trap here is that candidates confuse DLP policies with sensitivity labels, thinking DLP alone can enforce usage restrictions like 'prevent forwarding,' when in fact DLP only detects and optionally triggers a label that provides the encryption and rights management.

How to eliminate wrong answers

Option A is wrong because a Data Loss Prevention (DLP) policy can detect credit card numbers and trigger encryption via a sensitivity label, but DLP itself does not apply rights management restrictions (e.g., prevent forwarding or copying); it relies on an associated sensitivity label for that protection. Option C is wrong because Microsoft Information Bar is a deprecated feature that only displayed a visual banner in Office apps; it does not enforce encryption or rights restrictions on outgoing emails. Option D is wrong because the Azure Information Protection unified labeling client is a legacy client-side tool for labeling files and emails on Windows, not a cloud-based policy that automatically encrypts and restricts outgoing emails in Exchange Online.

128
MCQeasy

A marketing manager can access the company's cloud resources from her laptop at home, her tablet while traveling, and her smartphone. Which essential characteristic of cloud computing does this describe?

A.Resource pooling
B.Scalability
C.Broad network access
D.Measured service
AnswerC

Broad network access is the cloud characteristic that makes capabilities available over the network and accessible through standard protocols from heterogeneous client platforms, including laptops, tablets, and smartphones. The marketing manager's ability to reach company cloud resources from multiple devices directly exemplifies this capability, because the same service is usable regardless of device type or location. This is why broad network access is the correct answer.

Why this answer

Broad network access means cloud resources can be accessed over standard network protocols (e.g., HTTPS, TLS) from a wide range of client devices, such as laptops, tablets, and smartphones. The scenario explicitly describes access from multiple device types and locations, which is the defining characteristic of broad network access as per NIST SP 800-145.

Exam trap

The trap here is that candidates confuse 'broad network access' with 'resource pooling' because both involve multiple users or devices, but resource pooling is about the provider's shared infrastructure, not the consumer's ability to use different device types.

How to eliminate wrong answers

Option A is wrong because resource pooling refers to the provider's multi-tenant model where physical and virtual resources are dynamically assigned and reassigned according to consumer demand, not to the ability to access resources from various devices. Option B is wrong because scalability (or rapid elasticity) is the capability to automatically scale resources up or down based on demand, not the cross-device access described. Option D is wrong because measured service involves metering and billing for resource usage (e.g., pay-per-use), not the device-agnostic access pattern.

129
MCQhard

A compliance administrator needs to ensure that any document containing a patient's health information (e.g., medical record number) is automatically encrypted and restricted to authorized users. The encryption should be enforced regardless of where the document is saved (SharePoint, OneDrive, or email). Which Microsoft Purview feature should they configure?

A.Information Rights Management (IRM)
B.Auto-labeling policies with sensitivity labels
C.Data Loss Prevention (DLP) policies
D.Retention labels
AnswerB

Auto-labeling can automatically detect sensitive data (like health info) and apply a sensitivity label that enforces encryption and access restrictions.

Why this answer

Auto-labeling policies with sensitivity labels are the correct choice because they can automatically apply encryption and access restrictions to documents containing sensitive data like medical record numbers, regardless of where the document is saved (SharePoint, OneDrive, or email). Sensitivity labels support persistent protection that travels with the file, enforcing encryption and authorized user restrictions even when the file is moved or copied. This meets the requirement for automatic, location-independent encryption and access control.

Exam trap

The trap here is that candidates often confuse DLP policies with sensitivity labels, thinking DLP can enforce encryption, but DLP only monitors and blocks actions—it does not apply persistent protection like sensitivity labels do.

How to eliminate wrong answers

Option A is wrong because Information Rights Management (IRM) applies encryption and permissions only at the file level within a specific application (e.g., Word, Outlook) and does not automatically scan for content patterns like medical record numbers; it requires manual or rule-based application and does not integrate with auto-labeling for content-based classification. Option C is wrong because Data Loss Prevention (DLP) policies can detect sensitive information and block or alert on actions, but they do not natively encrypt or restrict access to documents; DLP is about preventing data exfiltration, not applying persistent protection. Option D is wrong because retention labels are designed for managing data lifecycle (retention and deletion), not for encryption or access control; they do not enforce encryption or restrict user access based on content.

130
MCQmedium

A department asks for the Microsoft 365 service best suited for department document libraries with version history. Which service should they use?

A.Microsoft Purview Compliance Manager
B.SharePoint Online
C.Microsoft Entra Privileged Identity Management
D.Microsoft Defender for Endpoint
AnswerB

SharePoint provides team sites, document libraries, metadata, permissions, and versioning.

Why this answer

SharePoint Online is the correct answer because it provides document libraries with built-in version history, allowing users to track, restore, and manage previous versions of documents. This feature is essential for collaboration and compliance, as it enables rollback to earlier versions and audit trails without additional configuration.

Exam trap

The trap here is that candidates may confuse Microsoft Purview Compliance Manager's compliance features with document version history, but version history is a core SharePoint Online capability, not a compliance or security tool.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a compliance management tool that helps assess and manage regulatory compliance risks, not a service for document storage or version history. Option C is wrong because Microsoft Entra Privileged Identity Management is an identity governance service for managing, controlling, and monitoring privileged access to Azure AD and other Microsoft Online Services, not for document libraries. Option D is wrong because Microsoft Defender for Endpoint is a security solution for endpoint protection, detection, and response, not a document management service with version history capabilities.

131
MCQmedium

A sales team needs to track customer interactions, manage leads, and automate follow-up emails. Which Microsoft 365 app is specifically designed for this customer relationship management (CRM) purpose?

A.Microsoft Dynamics 365 Sales
B.Microsoft Outlook
C.Microsoft SharePoint
D.Microsoft Power Automate
AnswerA

Correct. This is a dedicated CRM app for managing sales processes, leads, and customer interactions.

Why this answer

Microsoft Dynamics 365 Sales is a dedicated customer relationship management (CRM) application within the Dynamics 365 suite, purpose-built for tracking customer interactions, managing leads, and automating follow-up emails. Unlike general productivity tools, it provides structured pipelines, lead scoring, and workflow automation specifically for sales processes.

Exam trap

The trap here is that candidates confuse a general productivity tool (Outlook) or a workflow engine (Power Automate) with a full CRM solution, overlooking that Dynamics 365 Sales is the only option specifically architected for end-to-end customer relationship management.

How to eliminate wrong answers

Option B is wrong because Microsoft Outlook is an email and calendar client, not a CRM system; it lacks lead management, pipeline tracking, and automated follow-up workflows. Option C is wrong because Microsoft SharePoint is a document management and collaboration platform, not designed for CRM functions like lead scoring or interaction tracking. Option D is wrong because Microsoft Power Automate is a workflow automation tool that can integrate with CRM systems but is not a CRM application itself; it has no native lead or customer interaction management capabilities.

132
MCQmedium

A company with 300 users currently has Microsoft 365 Business Premium licenses. They want to add the highest level of automated threat investigation and response capabilities for all users. Which licensing option should they purchase?

A.Upgrade all users to Microsoft 365 E5
B.Add the Microsoft 365 E5 Security add-on for each user
C.Add the Microsoft 365 Defender for Office 365 Plan 2 add-on for each user
D.Add the Microsoft 365 Business Premium Threat Protection add-on
AnswerC

Add the Microsoft 365 Defender for Office 365 Plan 2 add-on: Business Premium already includes Microsoft Defender for Office 365 Plan 1, which provides safe links, safe attachments, and anti-phishing protection for email and SharePoint. Adding the Plan 2 add-on per user elevates that protection with advanced features such as automated investigation and response, threat hunting, and detailed incident reporting. This is the exact SKU designed to address your need for advanced investigation, and it should be licensed for every user who needs those capabilities.

Why this answer

Microsoft 365 Defender for Office 365 Plan 2 provides the highest level of automated investigation and response (AIR) capabilities, including threat hunting, automated remediation, and simulation training. Since the company already has Microsoft 365 Business Premium, which includes Defender for Office 365 Plan 1, adding Plan 2 as an add-on is the most cost-effective way to achieve the desired capabilities without upgrading to E5.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 E5 Security add-on (Option B) with the more targeted Defender for Office 365 Plan 2 add-on, not realizing that the E5 Security add-on includes additional, unnecessary features and costs more, while the question specifically asks for the highest level of automated threat investigation and response for all users, which is exactly what Defender for Office 365 Plan 2 provides.

How to eliminate wrong answers

Option A is wrong because upgrading all users to Microsoft 365 E5 would provide the same capabilities but at a significantly higher cost per user, and the question asks for an add-on to the existing Business Premium licenses, not a full upgrade. Option B is wrong because the Microsoft 365 E5 Security add-on includes Defender for Office 365 Plan 2, but it also bundles other security features (e.g., Microsoft Defender for Identity, Defender for Cloud Apps) that are not required, making it more expensive than the targeted Plan 2 add-on. Option D is wrong because there is no official 'Microsoft 365 Business Premium Threat Protection add-on'—this is a fictitious option that does not exist in Microsoft's licensing catalog.

133
MCQmedium

A sales manager needs a visual tool to track the sales pipeline with stages, deal values, and assigned team members. The team should be able to update the board in real time and see changes instantly. Which Microsoft 365 app is most suitable?

A.Microsoft Lists
B.Microsoft Dynamics 365 Sales
C.Microsoft Planner
D.Microsoft Excel
AnswerA

Microsoft Lists provides a visual, web-based tracking tool by letting you create a list with custom columns for deal stage, value, and owner, and then switch to a Board or Gallery view to display records as cards that move between stages. Because each list is backed by SharePoint, edits sync in real time and team members can see the pipeline update immediately. You retain the robustness of a data table rather than a simple task card, so monetary values, rollups, and filtering are natively supported.

Why this answer

Microsoft Lists is the most suitable app because it provides a customizable, real-time collaborative board view that can track sales pipeline stages, deal values, and assigned team members. Lists supports real-time co-authoring and instant updates via SharePoint, making it ideal for a visual, always-current sales tracking tool without requiring a full CRM system.

Exam trap

The trap here is that candidates often confuse Microsoft Planner's task board with a sales pipeline tool, but Planner lacks custom fields for deal values and real-time data updates across multiple users, making Lists the correct choice for this specific requirement.

How to eliminate wrong answers

Option B (Microsoft Dynamics 365 Sales) is wrong because it is a full-featured CRM platform designed for complex sales processes, not a simple visual board tool; it requires licensing and setup beyond the scope of a lightweight team tracking need. Option C (Microsoft Planner) is wrong because it is task-oriented with Kanban boards but lacks native fields for deal values and pipeline stages, and its real-time sync is limited to task status, not custom data like monetary amounts. Option D (Microsoft Excel) is wrong because while it can track data, it does not support real-time collaborative board views with instant updates; changes require manual refresh or sharing, and it lacks the visual pipeline stage representation needed.

134
MCQmedium

A company needs a dedicated, private network connection between its on-premises data center and Microsoft's cloud infrastructure to support a hybrid deployment with low latency and high reliability. The connection must not traverse the public internet. Which service should they use?

A.Azure ExpressRoute
B.Azure VPN Gateway
C.Azure Virtual WAN
D.Microsoft Entra ID Application Proxy
AnswerA

Azure ExpressRoute provisions a dedicated, private Layer 2 or Layer 3 circuit through an MPLS or network service provider, extending an on-premises infrastructure directly into Azure at Microsoft edge locations without traversing the public internet. This private connectivity offers lower and more consistent latency, higher security, bandwidth up to 100 Gbps, and a 99.95% availability SLA when redundant circuits are configured. For a company that specifically requires a dedicated private network connection for hybrid workloads, ExpressRoute is the Azure service built exactly for that scenario.

Why this answer

Azure ExpressRoute is the correct choice because it provides a dedicated, private network connection from an on-premises data center directly into Microsoft's cloud infrastructure, bypassing the public internet entirely. This ensures low latency, high reliability, and consistent performance for hybrid deployments, as the traffic traverses a private MPLS or Ethernet link rather than the unpredictable internet.

Exam trap

The trap here is that candidates often confuse Azure VPN Gateway with a private connection because it uses encryption, but the key differentiator is that VPN traffic still traverses the public internet, whereas ExpressRoute bypasses it entirely for a truly private, dedicated link.

How to eliminate wrong answers

Option B (Azure VPN Gateway) is wrong because it creates an encrypted tunnel over the public internet, which means traffic traverses the internet and cannot guarantee the low latency, high reliability, or complete privacy required by the scenario. Option C (Azure Virtual WAN) is wrong because it is a networking service that aggregates branch connectivity and can use ExpressRoute or VPN, but by itself it does not provide a dedicated private connection; it is a management and routing overlay, not a direct private link. Option D (Microsoft Entra ID Application Proxy) is wrong because it is an identity and access proxy for publishing on-premises web applications to external users via the internet, not a private network connection between data centers and Azure.

135
Drag & Dropmedium

Drag and drop the steps to assign a Microsoft 365 license to a user via the admin center into the correct order.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

License assignment involves selecting the user, managing licenses, choosing the product, and saving.

136
MCQeasy

A company wants to run a workload that requires the highest level of physical security and control over hardware. They have the budget to purchase and maintain their own data center. Which cloud deployment model should they choose?

A.Public cloud
B.Private cloud
C.Hybrid cloud
D.Community cloud
AnswerB

Private cloud offers dedicated hardware and full control, ideal for workloads requiring high security and compliance.

Why this answer

A private cloud deployment model is correct because it provides dedicated infrastructure for a single organization, offering the highest level of physical security and full control over hardware. This model allows the company to purchase, own, and manage its own data center, ensuring compliance with stringent security requirements and complete hardware isolation.

Exam trap

The trap here is that candidates often confuse 'hybrid cloud' with 'best of both worlds' and overlook that the question explicitly demands the highest physical security and hardware control, which only a private cloud with dedicated on-premises hardware can provide.

How to eliminate wrong answers

Option A is wrong because the public cloud model shares physical hardware among multiple tenants via hypervisors, which reduces direct control over hardware and cannot guarantee the highest level of physical security. Option C is wrong because the hybrid cloud model combines public and private clouds, but the public cloud component inherently lacks the dedicated hardware control required, and the model does not mandate exclusive hardware ownership. Option D is wrong because the community cloud model shares infrastructure among several organizations with common concerns, which still involves shared hardware and does not provide the exclusive physical control and security of a single-tenant private cloud.

137
MCQmedium

A marketing team needs a shared workspace where they can store documents, manage a shared calendar, conduct video meetings, and collaborate on announcements. They want this workspace to be integrated with other Microsoft 365 apps. Which Microsoft 365 service is best suited for this requirement?

A.Microsoft Teams
B.Yammer
C.SharePoint
D.Microsoft Stream
AnswerA

Microsoft Teams provides a purpose-built multi-faceted workspace: each team contains channels for threaded conversations, a SharePoint-backed document library for file storage, a shared Outlook calendar (via the Calendar app), and native video/audio meetings. This integrated hub also supports third-party and Microsoft 365 app additions, such as Planner or Power BI, without leaving the client. That combination directly satisfies a marketing team's need for a shared workspace with notes, files, calendar, and meetings.

Why this answer

Microsoft Teams is best suited because it provides a shared workspace that integrates document storage (via SharePoint), a shared calendar (via Exchange), video meetings (via Teams meetings), and collaboration on announcements (via channel posts and the Announcement app), all within a single interface that natively integrates with other Microsoft 365 apps.

Exam trap

The trap here is that candidates often confuse SharePoint's document management capabilities with a complete workspace solution, overlooking that SharePoint alone cannot provide integrated video meetings or real-time chat without additional services.

How to eliminate wrong answers

Option B (Yammer) is wrong because Yammer is an enterprise social network focused on organization-wide conversations and communities, not a team workspace with integrated document storage, shared calendars, or video meetings. Option C (SharePoint) is wrong because while SharePoint provides document storage and some calendar functionality, it lacks native video meeting capabilities and real-time chat, requiring additional tools like Teams or Skype for Business for meetings. Option D (Microsoft Stream) is wrong because Stream is a video hosting and management platform for enterprise video content, not a collaborative workspace for documents, calendars, meetings, or announcements.

138
MCQmedium

A healthcare organization must keep sensitive patient data on-premises due to regulatory compliance, but wants to use cloud services for other applications like customer relationship management and collaboration. Which cloud deployment model best meets this requirement?

A.Public cloud
B.Private cloud
C.Hybrid cloud
D.Community cloud
AnswerC

A hybrid cloud combines an organization's on-premises infrastructure, such as an Azure Stack edge device or local datacenter, with public cloud services via a secure connection like VPN or ExpressRoute. This allows sensitive patient data to remain resident in the on-premises environment while compute and storage for non-sensitive workloads scale into the public cloud, directly satisfying the stated requirement.

Why this answer

The hybrid cloud model is correct because it allows the healthcare organization to keep sensitive patient data on-premises (private cloud) for regulatory compliance (e.g., HIPAA), while leveraging public cloud services for customer relationship management and collaboration tools like Microsoft Dynamics 365 and Microsoft 365. This deployment model provides a unified environment where workloads can be distributed across on-premises and cloud infrastructure, ensuring data sovereignty and compliance without sacrificing scalability or cost efficiency.

Exam trap

The trap here is that candidates often confuse 'private cloud' as the only compliant option for sensitive data, overlooking that hybrid cloud allows the organization to meet compliance for specific workloads while still benefiting from public cloud economics for others.

How to eliminate wrong answers

Option A is wrong because a public cloud model would require all workloads, including sensitive patient data, to run on shared infrastructure managed by a third-party provider, which violates regulatory compliance requirements for data residency and control. Option B is wrong because a private cloud model, while secure and compliant, would force the organization to host all applications—including CRM and collaboration tools—on-premises, negating the cost and scalability benefits of cloud services for non-sensitive workloads. Option D is wrong because a community cloud is designed for organizations with shared compliance concerns (e.g., multiple healthcare entities), but it still requires all participants to adhere to a common regulatory framework and does not inherently allow selective placement of sensitive data on-premises while using public cloud for other apps.

139
MCQhard

A security administrator needs to automatically restrict access to documents that contain 'PII' (personally identifiable information) so that only employees in the 'Data Privacy' security group can view them. Additionally, editing and printing of these documents must be disabled. Which combination of Microsoft Purview features should be used?

A.Sensitivity labels with auto-labeling and encryption that restricts permissions to the 'Data Privacy' group
B.Data Loss Prevention (DLP) policy with a block action
C.Retention policy with a restrict action
D.Privileged Identity Management (PIM)
AnswerA

This is the correct approach because sensitivity labels in Microsoft Purview can be configured to automatically detect sensitive data types (such as PII) during file uploads or edits, and then apply encryption that dynamically restricts access to approved members of the 'Data Privacy' group. The label's encryption settings enforce an 'only view' or 'co-author' permission level, meaning users outside the group cannot open the document even if they discover it. This combines classification with persistent access control, which directly satisfies the requirement.

Why this answer

Sensitivity labels in Microsoft Purview can be configured with auto-labeling to automatically detect and classify documents containing PII, and then apply encryption that restricts access to only the 'Data Privacy' security group. Additionally, the label can enforce usage rights such as 'View Only' to disable editing and printing, meeting all requirements.

Exam trap

The trap here is that candidates often confuse DLP policies with sensitivity labels, not realizing that DLP blocks data in motion or at rest but cannot enforce persistent document-level permissions like disabling editing or printing.

How to eliminate wrong answers

Option B is wrong because a DLP policy with a block action can prevent sharing or transmission of PII data but cannot restrict access to documents already stored or disable editing/printing within the document itself. Option C is wrong because a retention policy is designed to preserve or delete data based on timeframes, not to restrict access or control permissions on documents. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role assignments and does not classify, label, or restrict access to documents based on content.

140
MCQhard

A security administrator needs to automatically restrict access to documents labeled as 'Highly Confidential' when accessed from devices that are not joined to the domain. The restriction should block editing and printing, and apply encryption. Which combination of Microsoft 365 solutions should the administrator use?

A.Microsoft Purview Information Protection + Microsoft Entra ID Conditional Access
B.Microsoft Purview Data Loss Prevention + Microsoft Entra ID Identity Protection
C.Microsoft Defender for Office 365 + Microsoft 365 Business Premium
D.Microsoft Purview Audit + Microsoft Entra ID Privileged Identity Management
AnswerA

Sensitivity labels from Microsoft Purview Information Protection can be configured to encrypt documents and apply usage rights, while Microsoft Entra ID Conditional Access evaluates policy at sign-in and can require the device to be hybrid Azure AD joined and compliant before allowing access to labeled content. This combination creates a layered enforcement: the label protects the file wherever it travels, and Conditional Access blocks access from non-compliant devices to the cloud location hosting the document. Together they directly satisfy the requirement to automatically restrict access to highly confidential documents based on device state.

Why this answer

Microsoft Purview Information Protection (MIP) allows you to create sensitivity labels that apply encryption, restrict editing, and block printing on documents. Microsoft Entra ID Conditional Access can then enforce that these labels are automatically applied based on device compliance (e.g., devices not joined to the domain). Together, they provide the automated, policy-driven restriction described.

Exam trap

The trap here is that candidates confuse Microsoft Purview Data Loss Prevention (DLP) with Information Protection, not realizing DLP only monitors and blocks data in transit (e.g., email) and cannot enforce encryption or usage restrictions on documents at rest.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Data Loss Prevention (DLP) detects and prevents accidental sharing of sensitive data but does not apply encryption or restrict editing/printing on documents; it blocks transmission via email or apps. Microsoft Entra ID Identity Protection focuses on user risk and sign-in anomalies, not device-based access control. Option C is wrong because Microsoft Defender for Office 365 protects against email threats (phishing, malware) and does not enforce document-level restrictions like encryption or editing/printing.

Microsoft 365 Business Premium is a licensing bundle, not a specific solution for this scenario. Option D is wrong because Microsoft Purview Audit logs user and admin activities but does not enforce access restrictions. Microsoft Entra ID Privileged Identity Management (PIM) manages just-in-time privileged role assignments, not document-level encryption or device-based access control.

141
MCQmedium

A company wants to prevent users from sharing documents that contain credit card numbers via email. When a user attempts to share such a document, they should see a policy tip explaining the restriction and the share should be blocked. Which Microsoft Purview solution should the compliance team configure?

A.Retention policy
B.Data Loss Prevention (DLP) policy
C.Sensitivity label
D.Information Barriers
AnswerB

Data Loss Prevention (DLP) policies in Microsoft Purview are designed to identify, monitor, and protect sensitive information by inspecting content for predefined sensitive info types, such as credit card numbers, using pattern matching and validation. When a match is detected, DLP can enforce sophisticated actions like blocking the email or sharing attempt, notifying the user with a policy tip, and optionally encrypting the item. DLP works across Exchange, SharePoint, OneDrive, Teams, and devices, making it the correct control for preventing the exfiltration of documents containing credit card data.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies are specifically designed to detect sensitive information types—such as credit card numbers—in documents and emails, and then automatically block sharing while displaying a policy tip to the user. This matches the requirement exactly: DLP can inspect content for credit card patterns using built-in sensitive info types (e.g., Credit Card Number), enforce actions like 'Block' with an overridable policy tip, and apply to Exchange Online, SharePoint, OneDrive, and Teams. Retention policies only manage data lifecycle, not content-based blocking.

Exam trap

Microsoft often tests the distinction between DLP (which inspects content for sensitive data and blocks actions) and Sensitivity labels (which apply classification and protection but do not natively scan for specific data patterns like credit card numbers to enforce blocking with policy tips).

How to eliminate wrong answers

Option A is wrong because a Retention policy is used to preserve or delete data based on age or legal requirements, not to inspect content for sensitive information or block sharing in real time. Option C is wrong because a Sensitivity label applies classification and protection (e.g., encryption, visual markings) but does not natively scan for specific data patterns like credit card numbers or enforce block actions with policy tips; it relies on manual or automatic labeling, not content inspection for predefined sensitive types. Option D is wrong because Information Barriers are designed to restrict communication and collaboration between specific groups (e.g., to prevent conflicts of interest), not to scan content for sensitive data or block sharing based on data patterns.

142
Multi-Selectmedium

Which THREE Microsoft 365 apps are part of the Microsoft Viva employee experience platform?

Select 3 answers
A.Viva Insights
B.Viva Engage
C.Viva Connections
D.Microsoft Teams
E.Viva Learning
AnswersA, C, E

Viva Insights provides productivity and wellbeing analytics.

Why this answer

Viva Insights is correct because it is a core module of the Microsoft Viva employee experience platform that provides data-driven, privacy-protected insights to help individuals and managers improve productivity, wellbeing, and work-life balance. It leverages Microsoft Graph data to analyze collaboration patterns and deliver actionable recommendations directly within Microsoft Teams and the Viva Insights app.

Exam trap

The trap here is that candidates often confuse Microsoft Teams (the platform) with the Viva modules that run within it, leading them to select Teams as a Viva component instead of recognizing that Viva Connections, Viva Insights, and Viva Learning are the three core apps that make up the employee experience platform.

143
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to manage leads, opportunities, customer accounts, and sales processes. Microsoft 365 app or service is the best fit?

A.Dynamics 365 Sales
B.Microsoft Planner
C.Microsoft Forms
D.Microsoft Purview Audit
AnswerA

Dynamics 365 Sales provides CRM capabilities for sales teams.

Why this answer

Dynamics 365 Sales is purpose-built for managing leads, opportunities, customer accounts, and sales processes as part of the Microsoft 365 ecosystem. It provides a customer relationship management (CRM) platform with pipeline management, sales automation, and analytics, directly aligning with the consultant's requirements.

Exam trap

The trap here is that candidates may confuse Microsoft Planner's task management features with CRM functionality, or assume Microsoft Forms can handle sales processes due to its data collection capabilities, but neither provides the structured pipeline and account management required for sales.

How to eliminate wrong answers

Option B is wrong because Microsoft Planner is a task management tool for organizing work among teams, not designed for CRM functions like lead or opportunity tracking. Option C is wrong because Microsoft Forms is a survey and data collection tool, lacking sales process management capabilities. Option D is wrong because Microsoft Purview Audit is a compliance and auditing solution for tracking user activities, unrelated to sales pipeline or customer account management.

144
MCQeasy

Which cloud computing characteristic allows users to provision resources such as virtual machines and storage without requiring human interaction with the service provider?

A.Measured service
B.On-demand self-service
C.Resource pooling
D.Rapid elasticity
AnswerB

On-demand self-service allows users to provision resources automatically without human interaction.

Why this answer

On-demand self-service is one of the five essential characteristics of cloud computing defined by NIST. It enables users to automatically provision computing resources as needed through a web portal or API, without requiring manual intervention from the service provider.

145
MCQeasy

A department asks for the Microsoft 365 service best suited for enterprise video publishing and town hall recordings. Which service should they use? The design must avoid adding custom operational scripts.

A.Microsoft Purview Compliance Manager
B.Microsoft Stream on SharePoint
C.Microsoft Entra Privileged Identity Management
D.Microsoft Defender for Endpoint
AnswerB

Stream built on SharePoint supports enterprise video experiences.

Why this answer

Microsoft Stream on SharePoint is the correct service because it provides enterprise-grade video publishing and live event capabilities, including town hall recordings, directly integrated with SharePoint and Microsoft Teams. It leverages SharePoint's storage and permissions model, eliminating the need for custom operational scripts for video management.

Exam trap

The trap here is that candidates may confuse Microsoft Stream (classic) with the new Stream on SharePoint, or incorrectly associate video features with compliance or security services like Purview or Defender.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a compliance and risk management tool for assessing regulatory compliance, not a video publishing or recording service. Option C is wrong because Microsoft Entra Privileged Identity Management manages just-in-time privileged access to Azure AD roles, not video content. Option D is wrong because Microsoft Defender for Endpoint is an endpoint security solution for threat detection and response, not a video platform.

146
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to desktop Office apps plus Intune and enhanced security capabilities for a small or medium business. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Microsoft Whiteboard
C.Microsoft 365 Business Premium
D.Microsoft Forms
AnswerC

Business Premium adds security and device management to the business productivity bundle.

Why this answer

Microsoft 365 Business Premium is the correct answer because it bundles desktop Office apps, Microsoft Intune for mobile device management, and advanced security features like Microsoft Defender for Business and Azure AD Plan 1. This plan is specifically designed for small and medium businesses needing comprehensive productivity, management, and security capabilities under a single subscription.

Exam trap

The trap here is that candidates may confuse individual productivity apps (Stream, Whiteboard, Forms) with licensing plans, failing to recognize that only Business Premium bundles the required management and security components.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video sharing and recording service, not a licensing plan that includes desktop Office apps, Intune, or enhanced security. Option B is wrong because Microsoft Whiteboard is a digital canvas collaboration tool, not a subscription that bundles management or security features. Option D is wrong because Microsoft Forms is a survey and quiz creation tool, lacking any device management or advanced security capabilities.

147
MCQeasy

An organization needs to securely store and manage user identities for Microsoft 365. Which Microsoft service should they use?

A.Microsoft Entra ID
B.Microsoft Purview
C.Microsoft Defender for Cloud Apps
D.Microsoft Intune
AnswerA

Microsoft Entra ID is the identity and access management service for Microsoft 365.

Why this answer

Microsoft Entra ID (formerly Azure AD) is the correct choice because it is Microsoft's cloud-based identity and access management service, specifically designed to store and manage user identities for Microsoft 365. It provides authentication, single sign-on (SSO), and conditional access policies, ensuring secure access to Microsoft 365 resources. Other options focus on data protection, security monitoring, or device management, not identity storage.

Exam trap

The trap here is that candidates often confuse Microsoft Purview (data compliance) or Defender for Cloud Apps (security monitoring) with identity management, but only Microsoft Entra ID provides the core directory service for storing and authenticating user identities in Microsoft 365.

How to eliminate wrong answers

Option B (Microsoft Purview) is wrong because it is a data governance and compliance solution for managing sensitive data across environments, not for storing or managing user identities. Option C (Microsoft Defender for Cloud Apps) is wrong because it is a cloud access security broker (CASB) that monitors and controls cloud app usage, not an identity store. Option D (Microsoft Intune) is wrong because it is a mobile device management (MDM) and mobile application management (MAM) service for managing devices and apps, not for identity management.

148
MCQmedium

A company deploys Microsoft 365 Business Premium. The IT team wants to enable employees to sign in using a mobile app without passwords. Which app should they configure?

A.Microsoft Intune
B.Microsoft Entra ID
C.Microsoft Copilot
D.Microsoft Authenticator
AnswerD

Microsoft Authenticator is the mobile app specifically designed to handle sign-in verification for Microsoft 365. It enables passwordless sign-in and multi-factor authentication via push notification, number matching, or a rotating one-time code. When deploying Microsoft 365 Business Premium, users are expected to install and register Authenticator with their work account in Entra ID, making it the correct tool for user sign-in in this scenario.

Why this answer

Microsoft Authenticator is the correct app because it enables passwordless sign-in for Microsoft 365 Business Premium users via FIDO2-based phone sign-in or number matching. It allows employees to authenticate using biometrics or a PIN, eliminating the need for a password during sign-in.

Exam trap

The trap here is that candidates may confuse Microsoft Entra ID (the identity provider that enables passwordless authentication) with the actual user-facing app (Microsoft Authenticator) that performs the sign-in, leading them to select Entra ID instead of the correct app.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service, not an authentication app; it does not directly provide passwordless sign-in capabilities. Option B is wrong because Microsoft Entra ID (formerly Azure AD) is the identity and access management service that supports passwordless authentication methods, but it is not the app employees use to sign in; the app that facilitates the actual sign-in process is Microsoft Authenticator. Option C is wrong because Microsoft Copilot is an AI-powered productivity assistant integrated into Microsoft 365 apps, not an authentication app; it has no role in passwordless sign-in.

149
MCQmedium

A company wants to run a critical application that requires dedicated hardware to comply with regulatory isolation requirements. However, they want to avoid the upfront cost of building their own data center. Which cloud deployment model meets these needs?

A.Private cloud
B.Public cloud
C.Hybrid cloud
D.Community cloud
AnswerA

A private cloud delivers a single-tenant environment on dedicated physical hardware, giving the organization exclusive access to compute, storage, and networking. This fully satisfies the requirement for dedicated hardware while still providing cloud-like self-service and scalability. If hosted by a third-party, it also eliminates capital expenditure and can be tailored to meet regulatory or compliance constraints.

Why this answer

A private cloud is the correct deployment model because it provides dedicated hardware and infrastructure for a single organization, ensuring regulatory isolation without requiring the company to build and maintain its own on-premises data center. In Azure, a private cloud can be implemented via Azure Stack Hub or Azure VMware Solution, which run in the customer's own environment or a dedicated hosted environment, meeting compliance needs while avoiding upfront capital expenditure.

Exam trap

The trap here is that candidates often confuse 'private cloud' with 'on-premises only,' forgetting that a private cloud can be hosted by a third-party provider like Azure Stack Hub, which offers dedicated hardware without the upfront cost of building a data center.

How to eliminate wrong answers

Option B (Public cloud) is wrong because it uses shared multi-tenant infrastructure that cannot guarantee the dedicated hardware isolation required for strict regulatory compliance. Option C (Hybrid cloud) is wrong because it combines public and private clouds but does not inherently provide dedicated hardware; the public cloud portion still lacks isolation. Option D (Community cloud) is wrong because it is shared among several organizations with common concerns, not dedicated to a single company, and thus cannot meet the requirement for exclusive hardware isolation.

150
MCQeasy

A company runs a virtual machine in Azure that hosts a web application. The company is responsible for configuring the operating system, installing web server software, and managing application updates. The cloud provider is responsible for the physical hardware, networking, and data center security. Which cloud service model does this represent?

A.Software as a Service (SaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Function as a Service (FaaS)
AnswerC

Infrastructure as a Service (IaaS) provides virtualized computing resources over the internet, where the cloud provider supplies the physical hardware, virtualization, networking, and storage, but you are responsible for installing and managing the guest OS, middleware, and applications. For a VM hosting a web app, IaaS matches because you manage the OS, apply patches, configure the web server, and maintain the app itself. Azure Virtual Machines is a classic IaaS offering that gives you full administrative control.

Why this answer

This scenario describes Infrastructure as a Service (IaaS) because the customer manages the operating system, web server software, and application updates, while the cloud provider handles the physical hardware, networking, and data center security. In IaaS, the provider offers virtualized computing resources over the internet, and the customer retains control over the guest OS and installed software, which matches the responsibilities outlined.

Exam trap

The trap here is that candidates confuse PaaS with IaaS because both involve deploying applications, but the key differentiator is whether the customer manages the OS and installed software—PaaS abstracts the OS, while IaaS does not.

How to eliminate wrong answers

Option A is wrong because Software as a Service (SaaS) would have the provider manage the entire application stack, including the OS and software, leaving the customer only to use the application—here the customer configures the OS and installs web server software. Option B is wrong because Platform as a Service (PaaS) abstracts the OS and runtime, with the provider managing the underlying OS and middleware, but the customer is responsible for configuring the OS and installing web server software, which is not typical for PaaS. Option D is wrong because Function as a Service (FaaS) is a serverless compute model where the provider manages all infrastructure and the customer only deploys individual functions, not a full VM with OS and web server management.

Page 1

Page 2 of 3

Page 3

All pages