Courseiva

Microsoft 365 Fundamentals MS-900 (MS-900) — Questions 76–150

794 questions total · 11pages · All types, answers revealed

Page 1

Page 2 of 11

Page 3
76
MCQhard

Refer to the exhibit. An IT administrator is using Microsoft Intune to assign Microsoft 365 Apps for Enterprise to a group called Contoso-Sales. The exhibit shows a JSON snippet from the Intune deployment configuration. Based on the snippet, what is the most likely outcome?

A.The app will be automatically installed on all devices in the Contoso-Sales group.
B.The app will be excluded from installation for the Contoso-Sales group.
C.The app will be available for users in the group to install from Company Portal.
D.The app will be assigned but requires user approval before installation.
AnswerA

AutoAssignment is functionally equivalent to a Required assignment in Microsoft Intune. When an app is configured with AutoAssignment for a group, Intune automatically installs it on every enrolled device that belongs to that group, without requiring any user interaction. The device receives the deployment policy at its next check-in and the installation runs in the background.

Why this answer

The JSON snippet shows an assignment with 'intent' set to 'Required' and 'targetGroupId' pointing to the Contoso-Sales group. In Microsoft Intune, a 'Required' assignment for a mobile app (like Microsoft 365 Apps for Enterprise) triggers automatic installation on all targeted devices without user intervention, making option A correct.

Exam trap

The trap here is that candidates confuse 'Required' intent with 'Available' intent, assuming all assignments require user action, but 'Required' in Intune means mandatory, silent installation, not optional installation from Company Portal.

How to eliminate wrong answers

Option B is wrong because the JSON shows an assignment with 'intent' set to 'Required', not 'Excluded' — exclusion would require a separate 'Exclude' group assignment or an 'excludedGroupIds' property. Option C is wrong because 'Required' intent forces installation silently; making the app available for user-initiated install from Company Portal requires 'Available' intent. Option D is wrong because 'Required' intent does not require user approval — it installs automatically; user approval is only relevant for 'Available' intent or when using 'User must accept license' settings, which are not indicated here.

77
MCQmedium

A department head asks which Microsoft 365 option should be used to reduce email attachments by storing shared team documents in one place and collaborating from conversations. Microsoft 365 app or service is the best fit?

A.Microsoft Teams with SharePoint Online
B.Microsoft Purview Audit
C.Microsoft Planner
D.Microsoft Forms
AnswerA

This combination is correct because Teams provides a hub for chat, meetings, and channel-based collaboration, while every file shared in a channel is stored in that team's SharePoint Online document library. SharePoint adds native version history, co-authoring, metadata, and permission inheritance, which together meet the department head's need for a shared, persistent file workspace.

Why this answer

Microsoft Teams integrates with SharePoint Online to provide a centralized document repository where team files are stored and managed. This allows users to collaborate on documents directly within Teams conversations, eliminating the need for email attachments. The combination of Teams for chat-based collaboration and SharePoint for file storage and versioning directly addresses the requirement.

Exam trap

The trap here is that candidates might confuse Microsoft Teams as a standalone chat app, overlooking its deep integration with SharePoint Online for file storage and collaboration, or mistakenly think Planner or Forms can serve as document repositories.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Audit is a compliance and auditing solution that tracks user activities and events, not a tool for storing shared documents or collaborating from conversations. Option C is wrong because Microsoft Planner is a task management and project planning tool that organizes work into boards and tasks, not a document storage or conversation collaboration platform. Option D is wrong because Microsoft Forms is a survey and quiz creation tool for collecting data, not designed for document storage or team collaboration within conversations.

78
MCQeasy

A company wants to reduce hardware maintenance costs by moving to the cloud. They need to maintain full control over the operating system, applications, and security configurations, but do not want to manage physical servers or data center facilities. Which cloud service model should they choose?

A.Software as a Service (SaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.On-premises
AnswerC

Infrastructure as a Service (IaaS) provides virtualized computing resources over the internet, with the cloud provider owning and maintaining the physical servers, storage, and networking equipment. This shifts hardware maintenance and capital costs to the provider, while you retain full administrative control over the operating system, runtime, and security configurations. That combination of provider-managed hardware and customer-managed OS precisely matches the requirement to reduce maintenance costs while keeping administrative authority.

Why this answer

Infrastructure as a Service (IaaS) provides virtualized computing resources over the internet, allowing the company to deploy and manage their own operating systems, applications, and security configurations while offloading the physical hardware and data center management to the cloud provider. This model gives the highest level of control over the software stack without the burden of maintaining physical servers, aligning perfectly with the requirement to reduce hardware maintenance costs while retaining full administrative access.

Exam trap

The trap here is that candidates often confuse PaaS with IaaS because both are cloud models, but PaaS removes control over the OS and runtime environment, which is the critical distinction when the question explicitly requires maintaining full control over the operating system and security configurations.

How to eliminate wrong answers

Option A is wrong because Software as a Service (SaaS) delivers fully managed applications accessed via a web browser, where the customer has no control over the underlying operating system, runtime, or security configurations—contradicting the need for full control. Option B is wrong because Platform as a Service (PaaS) abstracts the operating system and middleware, providing a managed runtime environment for application development; the customer cannot control the OS or security configurations at the infrastructure level. Option D is wrong because on-premises deployment requires the company to own and manage physical servers and data center facilities, directly conflicting with the goal of reducing hardware maintenance costs.

79
MCQhard

A healthcare organization uses Microsoft 365 E5 and must comply with HIPAA. They need to ensure that all emails containing protected health information (PHI) are encrypted both in transit and at rest. They also need to prevent users from accidentally sending PHI to external recipients. What should they implement?

A.Use Microsoft Entra ID Conditional Access to require MFA for all email access.
B.Implement Microsoft Purview Message Encryption and create DLP policies to detect and block PHI sent externally.
C.Configure Microsoft Defender for Office 365 Safe Attachments and Safe Links policies.
D.Deploy Microsoft Purview Compliance Manager to assess compliance with HIPAA.
AnswerB

Implementing Microsoft Purview Message Encryption (OME) encrypts email messages and attachments, ensuring protected health information (PHI) is unreadable to unauthorized recipients, while DLP policies detect sensitive patterns such as medical record numbers or diagnosis codes and automatically block or warn before such content is sent externally. Together, these controls enforce both confidentiality and controlled sharing, which are core HIPAA safeguards. Unlike other options, this combination directly addresses the specific requirement to secure PHI in email.

Why this answer

Microsoft Purview Message Encryption (MPME) provides the necessary encryption for PHI in transit and at rest by using Azure Rights Management (RMS) to protect emails. Data Loss Prevention (DLP) policies in Microsoft Purview can be configured to detect patterns like social security numbers or medical record numbers and automatically block or warn users before sending such emails externally, preventing accidental PHI exposure.

Exam trap

The trap here is that candidates often confuse DLP with encryption, thinking that encryption alone prevents accidental sharing, or they mistake security features like MFA or Safe Attachments for data protection controls that address content-based compliance requirements.

How to eliminate wrong answers

Option A is wrong because Conditional Access with MFA only enforces multi-factor authentication for access, it does not encrypt email content or prevent accidental sending of PHI. Option C is wrong because Safe Attachments and Safe Links protect against malicious attachments and URLs in email, they do not provide encryption or DLP-based content blocking for PHI. Option D is wrong because Compliance Manager is a risk assessment and reporting tool that helps evaluate compliance posture but does not actively encrypt emails or block PHI in transit.

80
Matchingmedium

Match each Microsoft 365 subscription plan to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Web and mobile versions of Office apps with email and cloud services

Full desktop Office apps with email and cloud services

Includes security and device management in addition to Business Standard

Full desktop Office apps only, no email or cloud services

Why these pairings

Microsoft 365 Business Basic provides web and mobile Office apps only; Business Standard adds desktop apps; Business Premium adds advanced security and device management.

81
MCQhard

An organization uses Microsoft 365 and wants to implement a retention policy for all Exchange Online mailboxes that automatically deletes emails older than 7 years, except for emails from the legal department which must be kept for 10 years. What should the administrator configure?

A.Create a single retention policy with 7-year retention and apply preservation lock.
B.Configure retention tags in Exchange Online for each mailbox.
C.Place the legal department mailboxes on litigation hold and set a 7-year retention for others.
D.Create two retention policies: one for all mailboxes with 7-year retention, and another for the legal department with 10-year retention using adaptive scopes.
AnswerD

Creating two retention policies allows you to apply a 7-year retention to all mailboxes and a separate 10-year retention to the legal department, using adaptive scopes to dynamically include mailboxes based on the department attribute. Adaptive scopes let you target users by Azure AD properties, such as Department = 'Legal', so the policy automatically applies to current and future legal staff without manual maintenance. When both policies apply to a legal mailbox, Microsoft 365 retains content for the longer period (10 years), satisfying the legal department's requirement while still enforcing the 7-year baseline for everyone else.

Why this answer

Microsoft 365 retention policies can be scoped using adaptive scopes to apply different retention settings to different groups of users. By creating two policies—one with a 7-year deletion rule for all mailboxes and another with a 10-year deletion rule for the legal department—the administrator meets the requirement without conflicting settings. Adaptive scopes allow dynamic membership based on attributes like department, ensuring the legal department's emails are kept longer while others are deleted after 7 years.

Exam trap

The trap here is that candidates often confuse litigation hold or preservation lock with retention policies, thinking they can be used to set different retention periods for different groups, when in fact they are designed for preservation (preventing deletion) rather than scheduled deletion with varying durations.

How to eliminate wrong answers

Option A is wrong because a single retention policy with preservation lock would prevent any changes or deletions, not selectively keep legal emails for 10 years while deleting others after 7; preservation lock is used for regulatory compliance to make the policy immutable, not for differential retention. Option B is wrong because retention tags in Exchange Online are part of the Messaging Records Management (MRM) feature, which is separate from Microsoft 365 retention policies and cannot be used to create a unified organization-wide retention policy that applies to all mailboxes consistently; MRM tags are per-mailbox and require manual assignment or default policies, making them less suitable for this requirement. Option C is wrong because litigation hold places a hold on all content in the mailbox, preventing deletion entirely, which would conflict with the 7-year deletion requirement for other mailboxes; it does not allow a 10-year retention period for legal department emails while still allowing deletion after 7 years for others.

82
MCQmedium

A compliance administrator needs to manage user sign-in risk and require MFA for risky sign-ins. Which Microsoft 365 capability is the best fit?

A.OneDrive sync client
B.Microsoft Bookings
C.Microsoft Entra ID Protection with Conditional Access
D.Microsoft Teams live events
AnswerC

Microsoft Entra ID Protection aggregates risk signals from sign-ins, users, and workloads and calculates user sign-in risk in real time. Conditional Access can consume those risk detections and enforce automated responses, such as requiring MFA, prompting a secure password change, or blocking an attempt, which is exactly the mechanism a compliance administrator would use to manage user sign-in risk.

Why this answer

Microsoft Entra ID Protection (formerly Azure AD Identity Protection) detects sign-in risks such as anonymous IP addresses, atypical travel, or leaked credentials. When combined with Conditional Access policies, it can automatically require MFA for risky sign-ins, giving the compliance administrator precise control over user authentication based on real-time risk signals.

Exam trap

The trap here is that candidates may confuse Microsoft Entra ID Protection with basic MFA enforcement in Azure AD, but the question specifically requires managing sign-in risk, which only Identity Protection with Conditional Access can evaluate and respond to in real time.

How to eliminate wrong answers

Option A is wrong because the OneDrive sync client is a file synchronization tool and has no capability to evaluate sign-in risk or enforce MFA. Option B is wrong because Microsoft Bookings is a scheduling application and does not include identity protection or conditional access features. Option D is wrong because Microsoft Teams live events is a broadcast feature for video and presentations, not an identity or security management tool.

83
MCQhard

Contoso Ltd. is a medium-sized company with 500 employees using Microsoft 365 E5. They have a mixed environment: 300 Windows 10 devices are managed by Microsoft Intune, and 200 are unmanaged but Azure AD joined. The company uses Microsoft Teams for collaboration and SharePoint Online for document storage. The security team wants to implement the following: restrict access to company data from unmanaged devices, require multi-factor authentication (MFA) for all external users accessing SharePoint, and ensure that sensitive documents labeled 'Highly Confidential' are automatically encrypted when shared via email. Currently, the company has no conditional access policies, no MFA enforced, and no data classification policies. The administrator needs to design a solution using Microsoft 365 built-in capabilities without purchasing additional licenses. What should the administrator do?

A.Configure SharePoint to block access from unmanaged devices, enable MFA for all users, and use Microsoft Purview Data Loss Prevention (DLP) to encrypt sensitive emails.
B.Use Intune app protection policies to restrict data access, enable MFA for SharePoint, and use Microsoft Purview auto-labeling for encryption.
C.Create a conditional access policy to require MFA for all users, use Intune compliance policies to mark devices as compliant, and create a sensitivity label to encrypt documents.
D.Create a conditional access policy to grant access from compliant devices, require MFA for external users, and configure a sensitivity label with auto-labeling for 'Highly Confidential' documents.
AnswerD

This solution precisely maps each requirement to the correct Microsoft 365 capability: a Conditional Access policy can require both device compliance (based on Intune compliance policies) and MFA for external users, ensuring only approved, managed devices gain access while external identities are verified. The sensitivity label configured with auto-labeling for 'Highly Confidential' content automatically applies encryption and permissions when documents match the label's pattern, eliminating user error. By combining these two policy layers, the organization enforces least-privilege access and protects sensitive data at the file level, which fully addresses the stated scenario.

Why this answer

It uses Conditional Access policies to require compliant devices for access (addressing unmanaged devices), requires MFA specifically for external users (not all users, aligning with the requirement), and uses a sensitivity label with auto-labeling to automatically encrypt 'Highly Confidential' documents when shared via email. This leverages built-in Microsoft 365 capabilities without additional licenses.

Exam trap

The trap here is that candidates often assume MFA must be enforced for all users or that DLP policies can encrypt emails, but the scenario specifically requires MFA only for external users and encryption via sensitivity labels, not DLP.

How to eliminate wrong answers

Option A is wrong because blocking access from unmanaged devices via SharePoint alone is not granular enough and does not leverage Conditional Access; enabling MFA for all users is overkill and not required by the scenario; DLP policies do not automatically encrypt emails—they block or warn, not encrypt. Option B is wrong because Intune app protection policies require devices to be enrolled in Intune, which the 200 unmanaged Azure AD-joined devices are not; enabling MFA for SharePoint only does not cover external users accessing SharePoint via other apps; auto-labeling in Purview requires a subscription like Microsoft 365 E5 Compliance, which is not explicitly stated as available. Option C is wrong because requiring MFA for all users is unnecessary and does not specifically target external users; Intune compliance policies alone do not grant access—they require a Conditional Access policy to enforce; creating a sensitivity label to encrypt documents does not include auto-labeling, so manual application would be needed.

84
MCQhard

A company with 100 users has Microsoft 365 Business Basic licenses. They want to add Phone System and Audio Conferencing for all users to enable PSTN calling and dial-in capabilities. They wish to minimize additional costs. What is the most cost-effective licensing approach?

A.Upgrade all users to Microsoft 365 E3 and add Phone System and Audio Conferencing.
B.Add the Microsoft 365 Business Voice add-on for each user.
C.Purchase Phone System and Audio Conferencing as standalone add-ons separately.
D.Add the Microsoft Teams Phone Standard add-on.
AnswerB

Microsoft 365 Business Voice is a single add-on SKU that bundles Phone System, Audio Conferencing, and a domestic Calling Plan for users on Microsoft 365 Business Basic, Standard, or Apps. It gives Teams full PBX features, dial-in meeting numbers, and PSTN calling without requiring a plan upgrade or separate telephony components. For this scenario, adding Business Voice to each of the 100 existing Business users is the most direct, economical path because it is purpose-built for small and mid-size businesses and avoids purchasing each voice capability individually.

Why this answer

Microsoft 365 Business Voice is a cost-effective add-on specifically designed for Business Basic, Standard, or Premium subscribers to add Phone System and Audio Conferencing capabilities. It bundles both PSTN calling and dial-in features into a single license, avoiding the higher cost of upgrading to E3 or purchasing separate add-ons.

Exam trap

The trap here is that candidates often assume upgrading to a higher-tier plan like E3 is the only way to get advanced voice features, overlooking the purpose-built, lower-cost Business Voice add-on for Business license holders.

How to eliminate wrong answers

Option A is wrong because upgrading all users from Business Basic to Microsoft 365 E3 is significantly more expensive and unnecessary; E3 includes Phone System but still requires Audio Conferencing as an additional add-on, increasing costs. Option C is wrong because purchasing Phone System and Audio Conferencing as standalone add-ons separately costs more per user than the bundled Business Voice add-on, which is designed to minimize expenses for Business license holders. Option D is wrong because the Microsoft Teams Phone Standard add-on provides only Phone System capabilities without Audio Conferencing, so it would require an additional Audio Conferencing license to meet the dial-in requirement, increasing total cost.

85
MCQhard

WideWorldImporters (WWI) is a retail company with 2,000 employees using Microsoft 365 Business Premium. They have a mix of Windows 10 and Windows 11 devices managed by Microsoft Intune. WWI wants to deploy a new line-of-business (LOB) app to all devices. The app is a Win32 app packaged as an .intunewin file. The IT administrator needs to ensure the app is installed automatically on all devices within 24 hours. Which deployment method should the administrator use?

A.Use Azure AD Application Proxy to publish the app
B.Add the app as an available deployment for all users
C.Add the app as a required deployment for all devices
D.Publish the app to Microsoft Store for Business and sync with Intune
AnswerC

A required deployment in Intune pushes the .intunewin Win32 app to every targeted device automatically, with no user action, and Intune retries delivery until installation succeeds. This satisfies the stem's constraint of automatic installation across all devices within 24 hours.

Why this answer

A required deployment in Intune forces the app to be installed automatically on all targeted devices without user interaction. This is the correct choice for ensuring the Win32 app is installed on all devices within 24 hours, as Intune will push the installation and retry as needed. Available deployments require users to install the app themselves, which does not guarantee automatic installation.

Exam trap

MS-900 often tests the difference between 'required' and 'available' deployments — candidates may pick 'available' thinking it is faster, but only 'required' guarantees automatic installation without user action.

How to eliminate wrong answers

Option A is wrong because Azure AD Application Proxy publishes internal web apps for remote access; it does not deploy Win32 apps to devices. Option B is wrong because an available deployment only makes the app visible in the Company Portal for users to install manually, so it does not ensure automatic installation within 24 hours. Option D is wrong because Microsoft Store for Business is for store apps, not Win32 .intunewin packages, and syncing does not guarantee automatic installation.

86
MCQhard

Contoso Ltd. is a global manufacturing company with 10,000 users. They are deploying Microsoft 365 E5 and require: (1) All Microsoft 365 data must be encrypted at rest and in transit using customer-managed keys; (2) Email must be archived for 10 years; (3) Users must be able to access files offline on mobile devices and sync changes when online; (4) The IT team must monitor and respond to threats across email, endpoints, and identities from a single console. You need to recommend the appropriate Microsoft 365 services. Which combination should you choose?

A.Microsoft Purview Double Key Encryption, Exchange Online Archiving, SharePoint Online, Microsoft Sentinel
B.Microsoft Purview Customer Key, Exchange Online Archiving, OneDrive, Microsoft Defender XDR
C.Azure Information Protection, Exchange Online Archiving, Windows 365, Microsoft Defender for Endpoint
D.Microsoft Purview Customer Key, Exchange Online In-Place Hold, OneDrive, Microsoft 365 Defender for Cloud Apps
AnswerB

Microsoft Purview Customer Key gives the tenant control over the root encryption keys that encrypt data at rest across Microsoft 365 services, meeting a strict encryption-at-rest requirement. Exchange Online Archiving provides unlimited archiving and supports retention policies with Preservation Lock that can be configured for 10 years, satisfying long-term regulatory retention. OneDrive for Business offers automatic offline synchronization for user files without manual per-library configuration. Microsoft Defender XDR unifies signals from endpoints, email, identity, and cloud apps into a single incident queue, providing the needed unified threat response and monitoring.

Why this answer

Microsoft Purview Customer Key provides customer-managed encryption keys for data at rest in Microsoft 365, meeting the first requirement. Exchange Online Archiving with a 10-year retention policy satisfies the email archiving requirement. OneDrive enables offline file access on mobile devices with sync capabilities.

Microsoft Defender XDR (Extended Detection and Response) offers a unified console to monitor and respond to threats across email, endpoints, and identities.

Exam trap

The trap here is confusing Microsoft Purview Customer Key (which encrypts all data at rest with customer-managed keys) with Double Key Encryption (which only protects a subset of data) or Azure Information Protection (which is a labeling solution, not encryption at rest).

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Double Key Encryption (DKE) protects only specific sensitive data with two keys, not all Microsoft 365 data, and Microsoft Sentinel is a SIEM/SOAR tool, not a single console for threat response across email, endpoints, and identities. Option C is wrong because Azure Information Protection is a classification and labeling solution, not a customer-managed encryption key service, and Windows 365 is a cloud PC service, not a file sync solution for offline mobile access. Option D is wrong because Exchange Online In-Place Hold is a litigation hold feature, not a 10-year archiving solution, and Microsoft 365 Defender for Cloud Apps is a CASB, not the unified XDR console that covers email, endpoints, and identities.

87
MCQeasy

Which cloud computing characteristic allows users to be billed only for the resources they consume, such as processing power, storage, or bandwidth?

A.On-demand self-service
B.Broad network access
C.Measured service
D.Resource pooling
AnswerC

Measured service is the cloud characteristic that automatically controls and optimizes resource use by leveraging a metering capability at some level of abstraction appropriate to the service type. Usage data for storage, processing, bandwidth, or active user accounts is collected, monitored, and reported, giving transparency for both the provider and the consumer. Because this metering generates a quantifiable usage baseline, it directly enables pay-as-you-go billing, where customers are charged based on actual consumption rather than flat-rate licenses.

Why this answer

Measured service is the cloud computing characteristic that enables usage-based billing by monitoring, controlling, and reporting resource consumption (e.g., CPU hours, GB of storage, or data transfer) at a granular level. This metering capability allows providers to charge customers only for what they actually use, rather than a flat fee, and is typically implemented via telemetry and billing APIs.

Exam trap

The trap here is that candidates often confuse 'measured service' with 'resource pooling' because both involve dynamic allocation, but measured service specifically refers to the metering and billing aspect, not the multi-tenant sharing of resources.

How to eliminate wrong answers

Option A is wrong because on-demand self-service refers to a user's ability to provision computing resources automatically without requiring human interaction with the service provider, not to billing or consumption tracking. Option B is wrong because broad network access describes the availability of resources over the network via standard protocols (e.g., HTTP, HTTPS) from various devices, not the metering or charging mechanism. Option D is wrong because resource pooling involves the provider's multi-tenant model where physical and virtual resources are dynamically assigned and reassigned according to consumer demand, which supports scalability but does not directly enable per-consumption billing.

88
Multi-Selectmedium

Which three of the following are key capabilities of Microsoft 365 Apps for enterprise (formerly Office 365 ProPlus)? (Choose three.)

Select 3 answers
.Always-up-to-date versions of Word, Excel, PowerPoint, and Outlook
.Installation on up to 5 PCs or Macs per user
.Real-time co-authoring in Word, Excel, and PowerPoint
.Unlimited cloud storage per user in OneDrive
.Built-in video conferencing with unlimited meeting duration
.On-premises deployment with perpetual licensing

Why this answer

Microsoft 365 Apps for enterprise provides always-up-to-date versions of core Office applications like Word, Excel, PowerPoint, and Outlook, with updates delivered via the Click-to-Run technology from the cloud. It allows installation on up to 5 PCs or Macs per user, enabling productivity across multiple devices. Real-time co-authoring in Word, Excel, and PowerPoint is a key capability, leveraging OneDrive or SharePoint to allow multiple users to edit the same document simultaneously.

Exam trap

Microsoft often tests the distinction between cloud-based subscription services and perpetual on-premises licensing, leading candidates to incorrectly select on-premises deployment as a capability of Microsoft 365 Apps for enterprise.

89
MCQmedium

A compliance officer needs to automatically label and encrypt documents that contain personally identifiable information (PII) when they are saved in SharePoint. The labeling should happen without manual user intervention. Which Microsoft Purview feature should they configure?

A.Sensitivity labels (auto-labeling policy)
B.Data Loss Prevention (DLP) policy
C.Retention labels
D.Communication Compliance
AnswerA

Sensitivity labels, when used with auto-labeling policies, scan documents and emails for sensitive data patterns such as PII, credit card numbers, or passport IDs and automatically apply a pre-configured label. That label can carry encryption settings (e.g., end-user-defined permissions or 'Do Not Forward') and visual markings, thereby satisfying both automatic classification and encryption. This is the recommended solution for the compliance officer's stated requirement.

Why this answer

Sensitivity labels with auto-labeling policies in Microsoft Purview can automatically detect and classify documents containing PII when they are saved in SharePoint, and apply encryption based on the label configuration. This meets the requirement of automatic, user-intervention-free labeling and encryption by scanning content for sensitive data types (e.g., Social Security numbers) and applying the label at rest.

Exam trap

The trap here is confusing auto-labeling with DLP policies, as both deal with sensitive data, but DLP focuses on preventing data loss during transit or sharing, not on automatic classification and encryption of stored documents.

How to eliminate wrong answers

Option B (Data Loss Prevention policy) is wrong because DLP policies are designed to prevent unauthorized sharing or leakage of sensitive data by blocking or warning users, not to automatically label and encrypt documents at rest in SharePoint. Option C (Retention labels) is wrong because retention labels are used to manage data lifecycle (retention and deletion) and do not inherently apply encryption or classification based on PII content. Option D (Communication Compliance) is wrong because it focuses on monitoring and reviewing communications (e.g., email, Teams) for policy violations, not on automatically labeling and encrypting documents stored in SharePoint.

90
MCQhard

A company uses Microsoft 365 E5 and wants to implement a zero-trust security model. They need to ensure that all external file sharing requires multi-factor authentication (MFA) and that sensitive documents are automatically labeled. Which combination of services should they use?

A.Microsoft Defender XDR and Microsoft Purview Audit
B.Microsoft Intune and Microsoft Defender for Cloud Apps
C.Microsoft Defender for Cloud Apps and Microsoft Purview Data Lifecycle Management
D.Microsoft Entra Conditional Access and Microsoft Purview Information Protection
AnswerD

Microsoft Entra Conditional Access provides identity-driven policy enforcement, such as requiring MFA during sign-in based on user, location, device, or risk signals, which directly satisfies the MFA requirement. Microsoft Purview Information Protection automatically classifies emails and documents by applying sensitivity labels based on content detection and user-defined policies, thereby meeting the auto-labeling requirement. Together these two services form the correct combination: one governs access at the authentication boundary, the other governs data classification and protection at the content level.

Why this answer

Microsoft Entra Conditional Access can enforce MFA for external file sharing by requiring MFA as a condition for accessing SharePoint/OneDrive resources. Microsoft Purview Information Protection provides automatic sensitivity labeling for documents based on content or context, ensuring sensitive data is labeled without manual intervention. Together, these services directly address the zero-trust requirements of MFA for external sharing and automatic document labeling.

Exam trap

The trap here is that candidates confuse Microsoft Defender for Cloud Apps (a CASB) with Entra Conditional Access for MFA enforcement, or assume Purview Data Lifecycle Management handles labeling instead of Information Protection, leading them to select options that address only one requirement or use the wrong service for the task.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender XDR focuses on threat detection and response across endpoints, email, and identities, not on enforcing MFA for external sharing or automatic labeling; Microsoft Purview Audit only provides logging and auditing of activities, not labeling or access control. Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service, not designed to enforce MFA on external file sharing or apply sensitivity labels; Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that can apply session policies but does not natively handle automatic labeling of documents. Option C is wrong because while Microsoft Defender for Cloud Apps can enforce access policies, it does not directly integrate with MFA enforcement for external sharing as a primary function; Microsoft Purview Data Lifecycle Management manages retention and deletion policies, not automatic sensitivity labeling.

91
Matchingmedium

Match each Microsoft 365 workload to its associated AI feature.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Intelligent recap and meeting transcripts

Microsoft Editor for grammar and style suggestions

Designer for slide layout recommendations

Focused Inbox and suggested replies

Why these pairings

AI features in Microsoft 365 enhance productivity: Word uses Editor, Excel uses Ideas, Outlook uses Focused Inbox, PowerPoint uses Designer, and Teams uses Live Captions. Common confusions arise from swapping features across workloads.

92
MCQmedium

A company is deploying Microsoft 365 Apps for Enterprise to 500 users. The IT team wants to minimize network traffic during installation by downloading only the apps that users need, instead of the full Office suite. Which deployment tool should they use?

A.Microsoft Store for Business
B.Microsoft Configuration Manager
C.Microsoft Intune
D.Office Deployment Tool (ODT)
AnswerD

The Office Deployment Tool (ODT) is the correct choice because it uses a configuration.xml file to specify exactly which Microsoft 365 Apps applications (e.g., Word, Excel, PowerPoint) to download or install, along with architecture, language, and update channel settings. During the /download mode, it retrieves only the selected apps and their dependencies from the Office Content Delivery Network, significantly reducing bandwidth compared to pulling down the entire suite. This granular control makes ODT ideal for creating a custom deployment with specified apps, and it supports both online and offline installation scenarios.

Why this answer

The Office Deployment Tool (ODT) allows IT administrators to download and deploy only the specific Microsoft 365 Apps (e.g., Word, Excel) needed by users, using an XML configuration file to control which products and languages are installed. This minimizes network traffic by avoiding the download of the full suite, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates may confuse the ODT with broader management tools like Intune or Configuration Manager, but the question specifically asks for the tool that directly controls which apps are downloaded, which is the ODT.

How to eliminate wrong answers

Option A is wrong because Microsoft Store for Business is designed for purchasing and distributing apps from the Store, not for customizing or selectively deploying Microsoft 365 Apps components. Option B is wrong because Microsoft Configuration Manager (formerly SCCM) can deploy Office, but it relies on the ODT under the hood for customization; it is a broader management tool and not the specific tool for minimizing traffic by selecting only needed apps. Option C is wrong because Microsoft Intune is a cloud-based MDM/MAM service that can deploy Office apps, but it also uses the ODT for customization; it is not the direct tool for granular control over which apps are downloaded during installation.

93
MCQeasy

Your organization is a non-profit. How can you obtain Microsoft 365 licenses at a reduced cost?

A.Purchase Microsoft 365 Business Basic from the Microsoft 365 admin center
B.Purchase Microsoft 365 Nonprofit Business Basic from the Microsoft 365 admin center
C.Apply for Microsoft’s non-profit program and purchase Microsoft 365 Business Premium at a discounted rate
D.Use volume licensing through a Microsoft partner
AnswerC

The correct method is to apply for Microsoft's Nonprofit Program through the Microsoft for Nonprofits portal and pass eligibility verification. Once approved, you gain access to donated or heavily discounted subscriptions, and Microsoft 365 Business Premium is one of the discounted plans available to qualified nonprofits. This plan includes desktop versions of Office apps plus advanced security and compliance features. The discount is exclusively tied to your verified nonprofit status, so this application-first approach is the only legitimate way to obtain the reduced pricing.

Why this answer

Microsoft offers a Nonprofit Program that provides eligible organizations with discounted or donated Microsoft 365 licenses. After applying and being approved, nonprofits can purchase Microsoft 365 Business Premium at a significantly reduced rate, which includes advanced security and compliance features beyond the basic plans.

Exam trap

The trap here is that candidates may assume any 'Nonprofit' labeled SKU (like Option B) is automatically available at a discount, when in reality the discount is contingent on prior enrollment in the Microsoft Nonprofit Program, not on selecting a specific product name.

How to eliminate wrong answers

Option A is wrong because purchasing Microsoft 365 Business Basic from the admin center at standard retail pricing does not provide the nonprofit discount; the organization must first be enrolled in the Microsoft Nonprofit Program to access reduced-cost licensing. Option B is wrong because Microsoft 365 Nonprofit Business Basic is not a valid product name; the correct nonprofit plan is called Microsoft 365 Business Basic (Nonprofit Staff Pricing) or similar, but the key is that the discount applies only after program approval, not by selecting a specific SKU directly. Option D is wrong because volume licensing through a Microsoft partner does not inherently offer nonprofit discounts; the nonprofit discount is tied to the Microsoft Nonprofit Program, not volume licensing agreements, and partners typically resell standard or volume licensing without the nonprofit benefit unless the organization is already enrolled.

94
MCQhard

Your organization uses Microsoft 365 E5 and wants to implement a solution that automatically detects and protects sensitive data in SharePoint Online, OneDrive, and Exchange Online. Which Microsoft 365 service should you configure?

A.Microsoft Defender for Cloud Apps
B.Microsoft 365 Copilot
C.Microsoft Intune
D.Microsoft Purview Information Protection
AnswerD

Microsoft Purview Information Protection applies sensitivity labels with encryption, and its auto-labelling policies detect sensitive data across SharePoint Online, OneDrive and Exchange Online. This satisfies the requirement for automatic detection and protection in those three workloads, whereas Defender for Cloud Apps governs access rather than labelling content.

Why this answer

Microsoft Purview Information Protection is the service within Microsoft 365 E5 that provides sensitivity labels and data loss prevention (DLP) to automatically detect and protect sensitive data across SharePoint Online, OneDrive, and Exchange Online. It allows you to classify and encrypt data based on sensitive information types.

Exam trap

MS-900 often tests the distinction between Purview Information Protection and Defender for Cloud Apps; candidates may confuse the two, but only Purview provides automatic labeling and protection for Microsoft 365 data.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility and control over cloud apps, but it does not automatically label and protect data in Microsoft 365 services; it focuses on threat protection and governance. Option B is wrong because Microsoft 365 Copilot is an AI assistant, not a data protection service. Option C is wrong because Microsoft Intune is for mobile device and application management, not for data classification and protection in Microsoft 365 workloads.

95
MCQmedium

A business stakeholder asks how Microsoft 365 can help them determine which apps a licensed user can access. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Enabled service plans within the assigned license
C.Microsoft Forms
D.Microsoft Whiteboard
AnswerB

Every Microsoft 365 license includes multiple service plans—such as Exchange Online, SharePoint Online, and Teams—that can be individually enabled or disabled to align with business requirements. Administrators can manage these service plans through the Microsoft 365 admin center or via PowerShell using the `Set-MgUserLicense` cmdlet, allowing granular control over which applications users can access without changing the overall license assignment. This directly addresses a stakeholder's need to tailor Microsoft 365 functionality per user or group.

Why this answer

Enabled service plans within a Microsoft 365 license define which specific applications and services a user can access. Administrators can view and manage these service plans via the Microsoft 365 admin center under 'Licenses' > 'Assignments', allowing granular control over app availability per user.

Exam trap

The trap here is that candidates confuse individual Microsoft 365 apps (like Stream or Forms) with the licensing admin tools that control app access, leading them to select a product name instead of the underlying licensing concept.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video service, not a tool for determining which apps a licensed user can access. Option C is wrong because Microsoft Forms is a survey and quiz application, unrelated to license management or service plan visibility. Option D is wrong because Microsoft Whiteboard is a collaborative canvas app, not a licensing or admin tool for app access control.

96
MCQhard

A company with 100 Microsoft 365 E3 users needs to add cloud access security broker capabilities to monitor and control user access to SaaS applications and shadow IT. They want the most cost-effective add-on. What should they purchase?

A.Microsoft Defender for Cloud Apps
B.Microsoft Defender for Microsoft 365 Plan 2
C.Microsoft Entra ID Premium P2
D.Microsoft 365 E5 Compliance
AnswerA

Microsoft Defender for Cloud Apps is the correct add-on because it functions as a Cloud Access Security Broker (CASB). It discovers shadow IT by analyzing user web traffic and logs, assesses the risk of thousands of SaaS applications, and enforces access and data-control policies such as session governance and app-level conditional access. For a tenant with M365 E3, adding this service directly addresses the need to monitor and control unsanctioned SaaS usage across the organization.

Why this answer

Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility into shadow IT, controls over user access to SaaS applications, and data protection policies. It is the most cost-effective add-on for this specific requirement because it can be licensed standalone without requiring higher-tier Microsoft 365 or Entra ID plans, and it directly addresses the need to monitor and control SaaS app usage.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps with Microsoft Defender for Microsoft 365 Plan 2, assuming the latter is required for CASB functionality, when in fact the standalone Defender for Cloud Apps license provides the same CASB capabilities at a lower cost.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Microsoft 365 Plan 2 includes Defender for Cloud Apps but bundles it with additional endpoint, email, and identity protection features at a higher cost, making it less cost-effective when only CASB capabilities are needed. Option C is wrong because Microsoft Entra ID Premium P2 provides identity governance and privileged identity management, not CASB functionality for monitoring and controlling SaaS applications or shadow IT. Option D is wrong because Microsoft 365 E5 Compliance focuses on data governance, eDiscovery, and compliance management, not on cloud access security broker capabilities for SaaS app access control.

97
MCQhard

A company uses Microsoft Forms to collect customer feedback. They want to automatically analyze sentiment from the responses using AI. Which Microsoft 365 service can integrate with Forms for this purpose?

A.Power BI
B.SharePoint Online
C.Azure Logic Apps
D.Power Automate
AnswerD

Power Automate is a Microsoft 365 cloud automation service that can trigger on new Forms responses and use AI Builder to analyze sentiment. AI Builder provides a prebuilt sentiment analysis model that can classify text as positive, negative, or neutral without extra custom code. You can create a flow that reads each response, applies the model, and then stores the result or sends an alert, making it the correct and efficient choice.

Why this answer

Power Automate (D) is the correct service because it can connect Microsoft Forms to Azure AI services (e.g., Azure Cognitive Services Text Analytics) to automatically analyze sentiment from form responses. When a new response is submitted, a Power Automate flow triggers, sends the response text to the AI sentiment analysis API, and stores or reports the result—all without manual intervention.

Exam trap

The trap here is that candidates may confuse Power Automate with Azure Logic Apps, but the question explicitly asks for a 'Microsoft 365 service,' and Power Automate is the correct Microsoft 365 offering, while Azure Logic Apps is an Azure service.

How to eliminate wrong answers

Option A is wrong because Power BI is a data visualization and business analytics tool, not a workflow automation or AI integration service; it can display sentiment data but cannot directly trigger AI analysis from a Forms submission. Option B is wrong because SharePoint Online is a document management and collaboration platform; it can store form responses but lacks built-in AI sentiment analysis or workflow triggers to process them automatically. Option C is wrong because Azure Logic Apps is a cloud-based integration service that could technically perform this task, but it is not a Microsoft 365 service—it is an Azure service—and the question specifically asks for a Microsoft 365 service that integrates with Forms; Power Automate is the correct Microsoft 365 service for this purpose.

98
MCQmedium

A company is planning to purchase Microsoft 365 subscriptions. They want to follow the recommended process. Which of the following sequences correctly represents the order of steps from start to finish?

A.Choose subscription, Assess needs, Assign licenses, Add licenses
B.Assess needs, Choose subscription, Add licenses, Assign licenses
C.Add licenses, Assign licenses, Assess needs, Choose subscription
D.Assess needs, Add licenses, Choose subscription, Assign licenses
AnswerB

This is the only valid ordering because lifecycle management of Microsoft 365 licenses must follow a dependency chain. First, assess needs to determine the required SKU (e.g., Microsoft 365 E3 vs Business Premium) and the number of users. Second, choose a subscription to establish the licensing platform and billing terms. Third, add license capacity (either through purchasing additional seats or adjusting the license count) so there are enough available units. Finally, assign licenses to individual users via the Microsoft 365 admin center or PowerShell, consuming the available capacity.

Why this answer

Option B is correct because the recommended process for purchasing Microsoft 365 subscriptions is to first assess the organization's needs, then choose the appropriate subscription, then add licenses to the tenant, and finally assign those licenses to users. This logical sequence ensures you purchase the right licenses and have them available before assignment.

Exam trap

MS-900 often tests the logical order of steps; candidates might assume that adding licenses comes before choosing a subscription, but you must choose a subscription to know what licenses to add.

How to eliminate wrong answers

Option A is wrong because it starts with choosing a subscription before assessing needs, which could lead to purchasing the wrong plan. Option C is wrong because it starts with adding licenses before assessing needs or choosing a subscription, which is illogical. Option D is wrong because it places adding licenses before choosing a subscription, which is impossible since you need to choose a subscription to know what licenses to add.

99
MCQmedium

A tenant administrator is advising a department that wants to grant temporary, approved privileged administrator access. Microsoft security, identity, or compliance capability should it use?

A.Privileged Identity Management (PIM)
B.Microsoft Forms
C.Microsoft Stream
D.Microsoft Planner
AnswerA

Privileged Identity Management (PIM) provides time-bound, just-in-time activation of built-in roles in Microsoft Entra ID, such as Global Administrator or Privileged Role Administrator. By making a user eligible for a role, the tenant can require on-demand activation with optional approval, justification, and multi-factor authentication. This eliminates permanent standing privileged access and creates detailed audit records for every activation, directly supporting the department's need for controlled, temporary elevation of administrator rights.

Why this answer

Privileged Identity Management (PIM) is the correct choice because it provides just-in-time privileged access, allowing the tenant administrator to grant temporary, approved administrator roles with time-bound activation and approval workflows. PIM is part of Microsoft Entra ID Governance and directly addresses the requirement for temporary privileged access with oversight.

Exam trap

The trap here is that candidates may confuse PIM with other Microsoft 365 tools that have 'management' or 'planning' in their names, but only PIM provides the specific privileged access governance required for temporary administrator roles.

How to eliminate wrong answers

Option B (Microsoft Forms) is wrong because it is a survey and data collection tool, not designed for identity or access management. Option C (Microsoft Stream) is wrong because it is a video hosting and sharing platform, unrelated to privileged access control. Option D (Microsoft Planner) is wrong because it is a task management and planning tool, lacking any security or identity governance capabilities.

100
MCQmedium

A customer has 100 users on Microsoft 365 Business Basic and wants to add Microsoft Defender for Office 365 Plan 1. Which licensing approach should they use?

A.Purchase a separate Microsoft Defender for Office 365 Plan 1 subscription without underlying Microsoft 365 licenses
B.Upgrade all users to Microsoft 365 E3
C.Purchase Microsoft Defender for Office 365 Plan 1 as an add-on for each user
D.Upgrade to Microsoft 365 E5
AnswerC

Because Microsoft 365 Business Basic is an eligible base subscription, you can directly purchase Defender for Office 365 Plan 1 as an add-on for each of the 100 users and assign it to them through the Microsoft 365 admin center. This leaves the existing Business Basic licenses untouched, avoids any migration or plan-change overhead, and activates the advanced email threat protection capabilities you need: anti-phishing, anti-spam, and real-time suspicious message detection. With no extra Windows or mobility features, this is precisely the minimal licensing change that fulfills the customer's requirement.

Why this answer

Microsoft Defender for Office 365 Plan 1 is an add-on that can be purchased for users who already have a qualifying subscription like Microsoft 365 Business Basic. It provides advanced threat protection features such as Safe Attachments and Safe Links, and it must be assigned per user on top of an existing Microsoft 365 license. Option C is correct because it directly describes this additive licensing model.

Exam trap

The trap here is that candidates often assume Defender for Office 365 Plan 1 is a standalone product or that it is included in E3, when in fact it is an add-on that requires a qualifying base license and is not bundled with E3.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Office 365 Plan 1 is an add-on and cannot function without an underlying Microsoft 365 subscription (e.g., Business Basic, E3, or E5) that provides the base Exchange Online mailbox and core services. Option B is wrong because upgrading all users to Microsoft 365 E3 is unnecessary and more expensive; E3 includes Exchange Online but not Defender for Office 365 Plan 1 by default, so the customer would still need to purchase the add-on or a higher plan. Option D is wrong because upgrading to Microsoft 365 E5 is overkill; E5 includes Defender for Office 365 Plan 2 (which supersedes Plan 1) but is significantly more costly than simply adding Plan 1 to the existing Business Basic licenses.

101
Multi-Selecthard

A multinational corporation must comply with GDPR. They need to ensure that personal data of EU residents is retained for a specific period and then securely deleted. Additionally, they must be able to respond to data subject access requests (DSARs) within 30 days by finding and exporting relevant data. Which two Microsoft Purview solutions should they use together? (Choose two.)

Select 2 answers
A.Retention policies
B.Data Lifecycle Management (via sensitivity labels)
C.eDiscovery (Premium)
D.Audit (Standard)
AnswersA, C

Retention policies in Microsoft Purview are the primary mechanism for automatically enforcing GDPR's storage-limitation obligations. They can be configured to retain personal data for a defined period and then permanently delete it, operating consistently across Exchange, SharePoint, OneDrive, and Teams. By allowing you to set precise retention and deletion rules based on content age or sensitive data types, they directly satisfy data-minimization and erasure requirements without manual intervention. This makes them the correct answer for meeting GDPR retention and deletion obligations.

Why this answer

Retention policies (A) are correct because they allow organizations to define rules that retain personal data for a specific period and then automatically delete it, meeting GDPR retention and secure deletion requirements. eDiscovery (Premium) (C) is correct because it enables searching, collecting, and exporting data from various Microsoft 365 workloads to fulfill data subject access requests (DSARs) within the 30-day regulatory timeframe.

Exam trap

The trap here is that candidates confuse Data Lifecycle Management (via sensitivity labels) with retention policies, not realizing that sensitivity labels handle classification and protection, not automated time-based retention and deletion, while retention policies are the correct tool for that purpose.

102
MCQmedium

Your company has deployed Microsoft Defender XDR. A security analyst needs to investigate a suspicious email that was reported by a user. Which Microsoft 365 service should the analyst use to view the email's details and analyze threats?

A.Microsoft Sentinel
B.Microsoft Defender XDR
C.Microsoft Intune
D.Microsoft Purview
AnswerB

Microsoft Defender XDR is the unified security operations platform that correlates signals from emails, endpoints, identities, and collaboration tools into a single incident queue, enabling teams to investigate the full attack story of email threats such as phishing and malware. It natively relies on Defender for Office 365 for mail-flow protection, URL and attachment detonation, campaign views, and automated investigation and response for email incidents. Therefore, Defender XDR is the correct service for investigating email security incidents in a Microsoft 365 deployment.

Why this answer

Microsoft Defender XDR (Extended Detection and Response) is the correct service because it provides a unified investigation and response experience across email, endpoints, identities, and cloud apps. The security analyst can use the Microsoft Defender portal (security.microsoft.com) to view the full email details, including headers, attachments, URLs, and threat analysis results from automated investigation and advanced hunting queries.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with Microsoft Defender XDR (an XDR solution), not realizing that email investigation is a core function of Defender for Office 365 within Defender XDR, not Sentinel.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) that aggregates logs and alerts from multiple sources, but it is not the primary tool for investigating individual suspicious emails within Microsoft 365; that function belongs to Defender XDR. Option C is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service focused on managing devices and apps, not on email threat investigation. Option D is wrong because Microsoft Purview is a compliance and data governance solution (including data loss prevention, eDiscovery, and insider risk management), not a tool for analyzing email threats; email threat analysis is handled by Defender for Office 365, which is part of Defender XDR.

103
MCQmedium

A security administrator needs to ensure that all users accessing Microsoft 365 resources from unmanaged devices are prompted to sign in using multi-factor authentication (MFA) and are blocked from downloading sensitive files. Which conditional access policy should be configured?

A.Require MFA for all users
B.Block access from unknown locations
C.App protection policies
D.Conditional Access policy with device compliance and session controls
AnswerD

A Conditional Access policy can combine a device-compliance condition with grant controls that require MFA only for unmanaged devices, so compliant, Intune-enrolled devices get a smoother sign-in. Once access is granted, session controls—via app control in Microsoft Defender for Cloud Apps—can enforce real-time restrictions such as blocking download or print of sensitive files in the browser or desktop session. This directly addresses both the need to require stronger verification on unmanaged devices and the need to prevent sensitive file downloads, making it the correct answer.

Why this answer

A Conditional Access policy with device compliance and session controls allows the administrator to require MFA for sign-ins from unmanaged devices and use session controls (e.g., Microsoft Defender for Cloud Apps session policies) to block downloading sensitive files. This policy targets specific conditions (unmanaged devices) and applies granular access controls, meeting both requirements precisely.

Exam trap

The trap here is that candidates confuse App Protection Policies (MAM) with Conditional Access session controls, not realizing that MAM policies manage app-level data protection without controlling sign-in MFA or blocking downloads based on device compliance, while Conditional Access with session controls can enforce both conditions in a single policy.

How to eliminate wrong answers

Option A is wrong because requiring MFA for all users does not differentiate between managed and unmanaged devices, nor does it block file downloads; it only enforces MFA globally. Option B is wrong because blocking access from unknown locations restricts access based on geographic IP addresses, not device management status, and does not control file downloads. Option C is wrong because App Protection Policies (MAM) manage data protection within apps on devices (e.g., preventing copy/paste or save-as), but they do not enforce MFA at sign-in or block downloads based on device compliance; they are applied to apps, not sign-in conditions.

104
MCQmedium

A department head asks which Microsoft 365 option should be used to search, review, and export content for a legal investigation. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Forms
B.Microsoft Stream
C.Microsoft Purview eDiscovery
D.Microsoft Planner
AnswerC

Microsoft Purview eDiscovery is the native compliance solution in Microsoft 365 that supports identifying, preserving, collecting, reviewing, and exporting content for legal and regulatory investigations. Using the Purview portal, authorized eDiscovery managers can perform keyword and condition-based searches across Exchange Online, SharePoint, OneDrive, and Teams, then apply holds to preserve content in-place. This comprehensive workflow—including review sets and export—is exactly what a department head would request for litigation or compliance needs.

Why this answer

Microsoft Purview eDiscovery is the correct choice because it is the dedicated Microsoft 365 compliance solution for searching, reviewing, and exporting content in legal investigations. It provides advanced search capabilities across Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams, and supports legal hold, review sets, and export workflows to meet eDiscovery requirements.

Exam trap

The trap here is that candidates may confuse general productivity tools (Forms, Stream, Planner) with compliance capabilities, failing to recognize that only Microsoft Purview eDiscovery is designed for legal content search and export within the Microsoft 365 security and compliance center.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and data collection tool, not a compliance or security solution for legal content search and export. Option B is wrong because Microsoft Stream is a video hosting and sharing platform, lacking any eDiscovery or legal investigation capabilities. Option D is wrong because Microsoft Planner is a task management and project planning tool, with no features for searching, reviewing, or exporting content for legal purposes.

105
MCQmedium

Refer to the exhibit. What is the purpose of the 'classification' property in this Microsoft Purview sensitivity label policy?

A.To set the retention period for the labeled content
B.To define encryption settings for the label
C.To specify the sensitivity level of the content
D.To define user permissions for accessing the content
AnswerC

Classification defines the sensitivity level assigned to content, enabling protection actions such as encryption or access restrictions. It satisfies the stem's requirement by identifying how sensitive the labelled material is, distinguishing it from other label properties like content marking or protection settings.

Why this answer

In Microsoft Purview sensitivity labels, the 'classification' property (sometimes labeled 'Sensitivity level' in the label definition) is what determines the sensitivity tier the label represents — for example, Public, General, Confidential, or Highly Confidential. It drives how the label is presented to users and how downstream policies (DLP, auto-labeling) interpret the content's sensitivity. It is not the mechanism for retention, encryption, or permissions.

Exam trap

MS-900 often tests whether candidates conflate the different configuration surfaces of a sensitivity label — classification (sensitivity tier), encryption (protection), and retention (lifecycle) — causing them to pick the wrong property for the described purpose.

How to eliminate wrong answers

Option A is wrong because retention periods are configured in retention labels and retention policies, not in the sensitivity label's classification property. Option B is wrong because encryption is configured separately under the label's 'Encryption' settings (which invoke Azure Rights Management), not via the classification field. Option D is wrong because user permissions are defined within the encryption configuration (assigning specific users/groups rights), not through the classification property.

106
MCQeasy

Your organization has 500 users and uses Microsoft 365 Business Basic. The sales team frequently works remotely and needs to access their work files on mobile devices. They also need to conduct video meetings with customers. The IT department has been asked to recommend additional Microsoft 365 services to meet these needs without upgrading the existing plan if possible. Which action should the IT department take?

A.Subscribe to a Microsoft Teams Rooms license for each user.
B.Upgrade all users to Microsoft 365 Business Standard to get desktop Office and additional features.
C.Deploy a third-party VPN solution to secure remote access to files.
D.Use the existing OneDrive and SharePoint mobile apps for file access and use Microsoft Teams for video meetings.
AnswerD

With Microsoft 365 Business Basic, users can access and collaborate on files through the native OneDrive and SharePoint mobile apps, which sync and share documents securely from any device. Microsoft Teams, also included in Business Basic, provides robust video meeting capabilities without requiring any additional licenses. This solution directly satisfies both requirements using existing subscriptions, avoiding extra costs and complexity.

Why this answer

Microsoft 365 Business Basic already includes OneDrive and SharePoint for mobile file access via their respective apps, and Microsoft Teams for video meetings. These services meet the sales team's requirements without any additional licensing or plan upgrade, as Teams supports video conferencing and OneDrive/SharePoint provide secure remote file access on mobile devices.

Exam trap

The trap here is that candidates often assume remote file access requires a VPN or that video meetings need a higher-tier plan like Business Standard, overlooking that Business Basic already includes Teams and OneDrive/SharePoint mobile apps for these exact scenarios.

How to eliminate wrong answers

Option A is wrong because a Microsoft Teams Rooms license is designed for dedicated meeting room hardware (e.g., cameras, microphones, displays), not for individual users' mobile devices or remote work scenarios; it would be an unnecessary cost and does not address file access. Option B is wrong because upgrading to Business Standard is not required; the existing Business Basic plan already includes Teams for video meetings and OneDrive/SharePoint for file access via mobile apps, and the question explicitly asks to avoid upgrading if possible. Option C is wrong because a third-party VPN is unnecessary; OneDrive and SharePoint already provide secure remote access to files using HTTPS and Azure AD authentication, and deploying a VPN adds complexity and cost without addressing the video meeting requirement.

107
MCQmedium

Your company uses Microsoft Defender for Office 365 and wants to prevent users from clicking malicious links in email. A user reports that a known phishing link was not blocked. Which step should you take to investigate?

A.Check the Microsoft Secure Score for recommendations.
B.Review the Safe Links policy to ensure it is enabled.
C.Search in Threat Explorer for the URL and review the verdict.
D.Run an attack simulation to test the link.
AnswerC

Threat Explorer in Microsoft Defender for Office 365 lets you search by URL and inspect the detection verdict, delivery action, and block status for that message. Reviewing the verdict reveals whether the link was allowed by policy or missed by detonation, directly addressing the reported phishing link.

Why this answer

Threat Explorer in Microsoft Defender for Office 365 provides detailed information about email threats, including URLs. Searching for the specific URL allows you to see if it was detected, what verdict was assigned, and why it might not have been blocked. This is the most direct way to investigate why a known phishing link was not blocked.

Exam trap

The trap is choosing to review policy configuration instead of using Threat Explorer to investigate a specific incident; candidates may think checking the policy is sufficient, but the question asks for investigation of a specific link that was not blocked.

How to eliminate wrong answers

Option A is wrong because Microsoft Secure Score provides recommendations but does not offer per-URL investigation. Option B is wrong because reviewing the Safe Links policy is a proactive check, but it does not tell you why a specific link was not blocked; it only shows configuration. Option D is wrong because attack simulation tests user awareness, not why a specific link was allowed.

108
MCQhard

Your organization uses Microsoft Teams and wants to allow external partners to participate in shared channels without giving them full tenant access. Which identity solution should you configure?

A.Microsoft Teams guest access
B.Microsoft Entra External ID
C.Active Directory Federation Services
D.Microsoft Entra ID B2C
AnswerB

Microsoft Entra External ID is the correct service for enabling collaboration with external partners using their own identities, such as another Microsoft Entra tenant or Microsoft account. It offers B2B collaboration for guest users and B2B direct connect for shared channels, allowing controlled access to resources without requiring a guest object in your directory for every partner. This service provides fine-grained conditional access policies and governance for each partner relationship, making it ideal for Teams shared channels and other partner scenarios.

Why this answer

Microsoft Entra External ID (formerly Azure AD External Identities) is the correct solution because it allows external partners to authenticate and access shared Teams channels without granting them full tenant access. Unlike guest access, which creates a B2B collaboration user object in the tenant, External ID enables cross-tenant access policies that limit partner identities to specific resources like shared channels, preserving tenant isolation.

Exam trap

The trap here is that candidates often confuse Microsoft Teams guest access (which creates a guest user in the tenant) with the more restrictive B2B direct connect for shared channels, leading them to select guest access when the question explicitly requires 'without giving them full tenant access.'

How to eliminate wrong answers

Option A is wrong because Microsoft Teams guest access creates a guest user object in your tenant, which grants broader directory access and is not scoped solely to shared channels. Option C is wrong because Active Directory Federation Services (AD FS) is an on-premises identity federation solution for internal users, not designed for external partner access to Microsoft 365 shared channels. Option D is wrong because Microsoft Entra ID B2C is a customer-facing identity service for consumer applications, not for business-to-business partner collaboration in Teams.

109
MCQeasy

A company's CFO is pleased that they only pay for the compute and storage resources consumed each month, with no upfront hardware costs. This billing model is a direct result of which cloud computing characteristic?

A.On-demand self-service
B.Broad network access
C.Measured service
D.Resource pooling
AnswerC

Measured service is the cloud characteristic that automatically monitors, controls, and reports resource usage, enabling providers to bill customers for exactly the compute, storage, or network capacity they consume. This metering capability makes pay-per-use pricing possible, so the CFO only pays for the compute actually used, avoiding fixed upfront costs. Without measured service, usage-based billing and cost optimization would not be feasible.

Why this answer

The CFO's observation that the company only pays for consumed compute and storage resources with no upfront hardware costs directly reflects the 'measured service' characteristic of cloud computing. Measured service means cloud providers meter resource usage (e.g., CPU hours, GB-months of storage) and bill based on actual consumption, typically using a pay-as-you-go model. This eliminates the need for capital expenditure on hardware, as costs are operational and tied to usage metrics.

Exam trap

The trap here is that candidates often confuse 'measured service' with 'resource pooling' because both involve multi-tenancy and efficiency, but measured service is specifically about usage metering and billing, not the underlying resource sharing architecture.

How to eliminate wrong answers

Option A is wrong because on-demand self-service refers to a user's ability to provision resources automatically without requiring human interaction with the provider, not to the billing or cost model. Option B is wrong because broad network access describes the availability of resources over the network via standard protocols (e.g., HTTP, HTTPS) and accessed by various devices, not the consumption-based pricing. Option D is wrong because resource pooling involves the provider's multi-tenant model where physical and virtual resources are dynamically assigned to serve multiple customers, which enables efficiency but does not directly result in pay-per-use billing.

110
MCQeasy

Your organization is using Microsoft 365 and wants to ensure that services remain accessible even if one datacenter experiences an outage. Which concept should they rely on?

A.Scalability
B.Disaster recovery
C.High availability
D.Elasticity
AnswerC

High availability ensures continuous service operation by architecting Microsoft 365 workloads and data with redundancy across multiple geographically dispersed datacenters. This design allows for automatic failover mechanisms to reroute user traffic to healthy datacenters if one experiences an outage. Consequently, users maintain uninterrupted access to their services, directly satisfying the organisation's requirement for accessibility despite a single datacenter failure.

Why this answer

High availability is the design principle that keeps services accessible by eliminating single points of failure and distributing workloads across multiple datacenters or availability zones, so an outage in one location does not take the service down. Microsoft 365 delivers this through geo-redundant datacenter pairs and automatic failover, which is exactly the scenario described.

Exam trap

MS-900 often tests the confusion between high availability (continuous uptime via redundancy) and disaster recovery (restoring service after a major failure), so candidates must read whether the question emphasizes 'remains accessible' versus 'recover after loss'.

How to eliminate wrong answers

Option A is wrong because scalability is about handling increased load by adding resources, not about surviving a datacenter outage. Option B is wrong because disaster recovery focuses on restoring service after a major failure, typically with some downtime and data loss tolerance (RTO/RPO), whereas the question asks about continuous accessibility during an outage. Option D is wrong because elasticity is the ability to automatically scale resources up and down with demand, which is a cost/performance concept, not an availability guarantee.

111
MCQmedium

A compliance team needs to prevent employees from copying sensitive data (such as financial records or customer PII) to USB drives and other removable media from their Windows 10/11 devices. When a user attempts to copy data to an unapproved USB device, the action should be blocked and an alert should be generated. Which Microsoft Purview solution should they configure?

A.Microsoft Purview Data Lifecycle Management (retention policies)
B.Microsoft Purview Information Protection (sensitivity labels)
C.Microsoft Purview Data Loss Prevention (DLP) with device policies
D.Microsoft Purview eDiscovery (Standard or Premium)
AnswerC

Endpoint DLP policies in Microsoft Purview Data Loss Prevention are purpose-built to monitor and block risky activities on devices, including copying sensitive data to removable storage such as USB drives. By leveraging configurable sensitive information types, these policies enforce real-time restrictions, display user notifications, and trigger security alerts when violations occur, directly addressing the compliance team's objective to prevent copying.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) with device policies is the correct solution because it is specifically designed to monitor and control actions like copying sensitive data to removable media on Windows 10/11 endpoints. DLP device policies can block the copy action to unapproved USB devices and generate alerts when a policy violation occurs, directly addressing the compliance team's requirement to prevent data exfiltration via USB drives.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which classify and protect data) with DLP policies (which enforce actions like blocking copy to USB), but sensitivity labels alone cannot block endpoint-level copy actions without DLP device policies.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Lifecycle Management (retention policies) governs how long data is retained and when it is deleted, not real-time blocking of copy actions to removable media. Option B is wrong because Microsoft Purview Information Protection (sensitivity labels) classifies and protects data with encryption or visual markings but does not enforce endpoint-level controls like blocking USB copy actions. Option D is wrong because Microsoft Purview eDiscovery (Standard or Premium) is used for legal discovery and search of content, not for preventing data exfiltration via removable media.

112
MCQmedium

A manager needs to create a custom dashboard that visualizes sales data from multiple data sources in real-time. Which service should they use?

A.Excel
B.Power Apps
C.Power BI
D.SharePoint
AnswerC

Power BI is a dedicated business analytics service that connects to a wide variety of on-premises and cloud data sources, such as SQL Server, Azure, Salesforce, and SharePoint. It enables real-time data refreshes, interactive visuals with cross-filtering and drill-downs, and secure sharing via the Power BI service. Its robust data modeling with DAX, row-level security, and integration with Microsoft Teams and SharePoint make it the correct choice for a custom, live sales dashboard.

Why this answer

Power BI is the correct choice because it is specifically designed for creating interactive, real-time dashboards that aggregate data from multiple sources, including databases, cloud services, and streaming data. It provides live tile updates and direct query capabilities, enabling real-time visualization of sales data without manual refresh.

Exam trap

The trap here is that candidates often confuse Power Apps with Power BI, assuming both are for dashboards, but Power Apps is for building apps, not for data visualization or real-time analytics.

How to eliminate wrong answers

Option A is wrong because Excel is a spreadsheet application for static data analysis and lacks native real-time data connectivity and live dashboard capabilities. Option B is wrong because Power Apps is a low-code platform for building custom business applications, not for data visualization or real-time dashboards. Option D is wrong because SharePoint is a document management and collaboration platform that does not support real-time data aggregation or interactive dashboard creation from multiple sources.

113
MCQmedium

A company uses Microsoft Purview Communication Compliance to detect inappropriate messages. Which action can an administrator take after reviewing a flagged message?

A.Apply a retention policy to the message
B.Create a DLP policy based on the message
C.Resolve the case with a notification to the sender
D.Recall the message from the recipient
AnswerC

Resolving with a notification lets the administrator close the flagged message and simultaneously inform the sender of the outcome, satisfying Communication Compliance's remediation workflow. This action records the resolution while alerting the involved user, rather than escalating or merely dismissing the alert.

Why this answer

In Microsoft Purview Communication Compliance, after a reviewer investigates a flagged message, they can resolve the case by taking actions such as notifying the sender, escalating, or marking as false positive. Resolving with a notification to the sender is a standard remediation action. Retention policies and DLP policies are separate Purview solutions and cannot be applied directly from a Communication Compliance case.

Exam trap

The trap is conflating Communication Compliance with other Purview solutions like Data Loss Prevention or Retention; candidates may think any Purview action can be taken from a Communication Compliance case.

How to eliminate wrong answers

Option A is wrong because retention policies are configured in Microsoft Purview Data Lifecycle Management, not within Communication Compliance, and they apply to locations (mailboxes, sites) rather than individual messages. Option B is wrong because DLP policies are created in Microsoft Purview Data Loss Prevention, not as an action inside a Communication Compliance case. Option D is wrong because message recall is an Exchange Online feature available to senders, not an administrative action in Communication Compliance.

114
MCQmedium

A department asks for the Microsoft 365 service best suited for interactive business dashboards. Which service should they use?

A.Microsoft Purview Compliance Manager
B.Power BI
C.Microsoft Defender for Endpoint
D.Microsoft Entra Privileged Identity Management
AnswerB

Power BI is Microsoft's dedicated business intelligence service, delivering interactive dashboards and reports from varied data sources. It directly satisfies the department's requirement for interactive business dashboards, unlike productivity or collaboration tools. Its visualisation engine supports drill-downs, filtering and real-time refresh, matching the stated scenario precisely.

Why this answer

Power BI is the correct choice because it is Microsoft's dedicated business analytics service that enables users to create interactive dashboards and reports from various data sources. It provides real-time data visualization, drill-down capabilities, and natural language querying, making it ideal for business intelligence needs within Microsoft 365.

Exam trap

The trap here is that candidates may confuse Microsoft Purview Compliance Manager's dashboard-like compliance score interface with a business dashboard, but it is strictly for compliance posture assessment, not interactive business analytics.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a compliance management tool that helps organizations assess and manage regulatory compliance, not for building interactive dashboards. Option C is wrong because Microsoft Defender for Endpoint is a security solution for endpoint protection, threat detection, and response, unrelated to dashboard creation. Option D is wrong because Microsoft Entra Privileged Identity Management is an identity governance service for managing, controlling, and monitoring privileged access to Azure AD resources, not for data visualization or dashboards.

115
MCQeasy

An organization wants to provide employees with a personalized news feed from internal and external sources. Which Microsoft 365 app should they use?

A.Microsoft Viva Insights
B.Microsoft Viva Engage
C.Microsoft Stream
D.Microsoft SharePoint
AnswerB

Microsoft Viva Engage is the correct answer because it provides an employee experience platform with a social news feed that aggregates posts, stories, and updates from internal communities and external sources. Built on Yammer, it delivers a personalized feed of relevant news, conversations, and leadership messages directly within Microsoft 365. This matches the organization's need to provide employees with personalized news.

Why this answer

Microsoft Viva Engage (formerly Yammer) is the correct app because it provides a personalized news feed that aggregates content from both internal sources (e.g., company announcements, community posts) and external sources (e.g., RSS feeds, external news). It enables employees to discover relevant updates in a social-style feed, aligning with the requirement for a unified internal and external news experience.

Exam trap

The trap here is that candidates often confuse Microsoft Viva Insights (which sounds like it provides personalized content) with Viva Engage, or they assume SharePoint’s news web part can aggregate external sources, but SharePoint lacks the social feed and external aggregation capabilities that Viva Engage offers.

How to eliminate wrong answers

Option A is wrong because Microsoft Viva Insights focuses on personal productivity and well-being analytics (e.g., focus time, meeting habits), not on delivering a personalized news feed from internal and external sources. Option C is wrong because Microsoft Stream is a video hosting and sharing platform for enterprise video content, not a news aggregation feed. Option D is wrong because Microsoft SharePoint is a document management and collaboration platform that can display news via web parts, but it lacks the built-in social feed and external source aggregation that Viva Engage provides for a personalized news experience.

116
Multi-Selecteasy

Which TWO of the following are examples of Microsoft's commitments to data privacy as outlined in the Microsoft Privacy Statement and related agreements? (Choose two.)

Select 2 answers
A.Microsoft uses customer data to train AI models by default.
B.Microsoft may share customer data with third parties for marketing purposes.
C.Customers can access and export their data.
D.Microsoft allows third parties to access customer data without consent.
E.Customer data is not used for advertising.
AnswersC, E

This is a core Microsoft privacy commitment. Under the Microsoft Privacy Statement and the Online Services Terms, customers can access, correct, export, and delete their data at any time. This right to data portability is enforced through tools like the Microsoft 365 admin center, Azure portal, and Microsoft Purview compliance portal, which provide self-service data export capabilities. This transparency and control are part of Microsoft's "customer data is your data" principle, satisfying the requirement of customer control over their data.

Why this answer

The Microsoft Privacy Statement explicitly grants customers the right to access, export, and delete their data, aligning with data portability and control principles under regulations like GDPR. This commitment ensures that customers maintain ownership and control over their data stored in Microsoft 365 services.

Exam trap

The trap here is that candidates often confuse Microsoft's default data usage policies with those of other cloud providers, mistakenly assuming that customer data is automatically used for AI training or advertising, when in fact Microsoft explicitly prohibits these uses by default.

117
MCQmedium

A compliance-aware administrator is selecting the right Microsoft 365 capability to check known incidents affecting Microsoft 365 services. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Forms
B.Microsoft Whiteboard
C.Microsoft Stream
D.Service health
AnswerD

Service health in the Microsoft 365 admin center (and Admin mobile app) provides a live, first-party view of the tenant's service availability, including active incidents, advisories, planned maintenance, and historical health. You can filter by workload, severity, and message type, and subscribe to email notifications, which gives a compliance-aware administrator authoritative signals of degraded availability directly relevant to regulatory support and communication commitments.

Why this answer

Service health in the Microsoft 365 admin center provides real-time status and historical incident information for all Microsoft 365 services, including known incidents, advisories, and post-incident reports. This is the correct tool for a compliance-aware administrator to check known incidents affecting services, as it directly aligns with monitoring service availability and reliability under the support domain.

Exam trap

The trap here is that candidates may confuse productivity tools (Forms, Whiteboard, Stream) with support or monitoring capabilities, overlooking that Service health is the dedicated feature under the 'Support' domain for tracking known incidents and service status.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and data collection tool, not a service health monitoring or incident-checking capability. Option B is wrong because Microsoft Whiteboard is a digital canvas for collaboration and has no function for tracking service incidents or health status. Option C is wrong because Microsoft Stream is a video hosting and sharing service, not a tool for checking service health or known incidents affecting Microsoft 365.

118
Multi-Selecteasy

Which THREE are core pillars of the Microsoft Trust Center?

Select 3 answers
A.Compliance
B.Reliability
C.Transparency
D.Security
E.Privacy
AnswersA, D, E

Compliance is one of the three core pillars of the Microsoft Trust Center, alongside privacy and security. It satisfies the stem's requirement by covering Microsoft's adherence to regulatory standards, certifications and audit reports, giving organisations verifiable assurance that services meet legal and industry obligations.

Why this answer

The Microsoft Trust Center is built on three core pillars: Security, Privacy, and Compliance. Option D (Security) is correct because Microsoft's trust framework centers on protecting customer data through encryption, identity controls, and threat protection across its cloud services. Option E (Privacy) is correct because Microsoft commits to being transparent about data collection and giving customers control over their data through privacy statements and data subject rights.

Option A (Compliance) is correct because the Trust Center provides compliance offerings, audit reports, and certifications (such as ISO 27001, SOC, and GDPR resources) that demonstrate adherence to regulatory standards. Option B (Reliability) is not one of the three pillars; while reliability is an important service quality, it is not part of the Trust Center's core trust pillars. Option C (Transparency) is also not one of the three pillars; transparency is a principle Microsoft emphasizes within its privacy and security practices, but it is not listed as a standalone core pillar of the Trust Center.

Exam trap

MS-900 often tests whether candidates confuse the three pillars (security, privacy, compliance) with related concepts like transparency or reliability, which are important but not pillars.

119
MCQmedium

A department head asks which Microsoft 365 option should be used to assign licenses automatically when users join a department group. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Microsoft Forms
C.Microsoft Whiteboard
D.Group-based licensing
AnswerD

Group-based licensing in Microsoft 365 leverages Azure AD security groups to automatically assign or remove licenses for all members of a group, eliminating the need for individual manual assignment. When a user joins a group, the appropriate licenses are provisioned automatically; when they leave, the licenses are revoked. This approach centralizes license management and is the correct option for a department head wanting to control licensing through membership, assuming the required Azure AD Premium license is available.

Why this answer

Group-based licensing in Microsoft 365 allows you to automatically assign or remove licenses when users are added to or removed from a security group. This is the correct solution for the department head's requirement because it directly ties license assignment to group membership, eliminating manual intervention.

Exam trap

The trap here is that candidates may confuse Microsoft 365 group types (e.g., distribution groups, security groups) or think that a collaboration tool like Stream or Whiteboard can somehow manage licensing, when only Azure AD security groups with group-based licensing can automate this task.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video service for recording, sharing, and managing videos, not a licensing or group management tool. Option B is wrong because Microsoft Forms is used to create surveys, quizzes, and polls, and has no capability to assign licenses based on group membership. Option C is wrong because Microsoft Whiteboard is a digital canvas for collaboration and brainstorming, and it does not handle license assignment or group-based automation.

120
MCQmedium

A department head asks which Microsoft 365 option should be used to access cloud resources from laptops, tablets, and phones over the internet. Cloud concept or benefit best matches this requirement?

A.Sensitivity labels
B.Microsoft Planner
C.Data Loss Prevention (DLP)
D.Broad network access
AnswerD

Broad network access directly satisfies the cross-device, internet-based requirement: cloud services are reachable over standard network protocols from laptops, tablets, and phones alike. Unlike private-datacentre access, it removes dependence on a fixed corporate network, matching the department head's need to reach Microsoft 365 resources from any device.

Why this answer

Broad network access is a core NIST cloud characteristic that enables resources to be accessed over the internet by standard protocols (e.g., HTTPS, TLS) from a wide range of client devices such as laptops, tablets, and phones. This directly matches the requirement for accessing cloud resources from multiple device types over the internet.

Exam trap

The trap here is that candidates confuse operational features (like sensitivity labels or DLP) with foundational cloud characteristics, failing to recognize that 'broad network access' is the specific NIST-defined term for multi-device internet-based access.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are a Microsoft Purview Information Protection feature used to classify and protect data based on sensitivity, not to enable network access from devices. Option B is wrong because Microsoft Planner is a task management and collaboration tool within Microsoft 365, not a cloud concept or benefit for device access. Option C is wrong because Data Loss Prevention (DLP) is a security policy mechanism to prevent unauthorized sharing of sensitive data, not a cloud characteristic for broad device connectivity.

121
MCQeasy

A company uses a cloud provider that bills them based on the exact amount of storage and compute hours they consume each month. They can increase or decrease their usage at any time without signing a long-term contract. Which cloud computing characteristic is most directly demonstrated by the billing model?

A.Scalability
B.Elasticity
C.Measured service
D.On-demand self-service
AnswerC

Measured service is the cloud computing characteristic whereby the provider automatically monitors, meters, and controls resource usage across CPU, storage, bandwidth, and active user accounts. This metering capability enables a pay-per-use billing model, because customers are charged only for the exact quantity of resources they actually consume. In platforms like Azure, usage data from telemetry feeds into billing systems, allowing transparent invoicing and usage reports. Therefore, it directly addresses the billing scenario described in the question, making it the correct answer.

Why this answer

The billing model described—paying for exactly the amount of storage and compute hours consumed, with no long-term contract—directly demonstrates the measured service characteristic. Measured service means that cloud resource usage is metered, monitored, and reported, allowing providers to charge customers based on actual consumption (pay-as-you-go). This is a core attribute of cloud computing as defined by NIST SP 800-145, where usage is tracked and billed transparently.

Exam trap

The trap here is that candidates confuse elasticity (the ability to scale dynamically) with measured service (the metering and billing of that usage), because both involve variable resource consumption, but measured service is specifically about the tracking and charging mechanism.

How to eliminate wrong answers

Option A is wrong because scalability refers to the ability to handle increased workload by adding resources, not to the billing model itself. Option B is wrong because elasticity is the ability to automatically scale resources up or down in response to demand, which is a separate operational characteristic from how usage is measured and billed. Option D is wrong because on-demand self-service means a user can provision resources without human interaction with the provider, which is about provisioning capability, not the metering and billing mechanism.

122
MCQmedium

A project team needs a centralized workspace that includes a shared calendar for deadlines, a document library for storing deliverables, and a task list with assignments. They also want threaded discussions about each item. Which Microsoft 365 service provides this integrated experience out of the box?

A.Microsoft Teams
B.SharePoint Online
C.Microsoft 365 Groups
D.Microsoft Outlook
AnswerC

A Microsoft 365 Group is the correct answer because it is the underlying identity and membership container that automatically provisions a complete set of collaboration services: a shared Outlook inbox and calendar, a SharePoint Online document library, a Planner plan for task management, and a shared workspace for threaded conversations. Everything is bound to the same group ID, so membership and permissions propagate consistently across all services. This meets the requirement of a centralized workspace with a calendar and tasks out of the box, without requiring manual assembly of separate tools.

Why this answer

Microsoft 365 Groups is the correct answer because it provides a unified, out-of-the-box workspace that includes a shared calendar, document library (via connected SharePoint), task list (via Planner or To Do), and a group mailbox with threaded conversations. Unlike standalone services, a Microsoft 365 Group bundles these resources together automatically when created, offering the integrated experience described without requiring manual configuration.

Exam trap

The trap here is that candidates often confuse Microsoft Teams as the integrated workspace, but Teams is actually a client that surfaces the underlying Microsoft 365 Group resources, not the service that provides them out of the box.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams is a chat-based collaboration hub that relies on a Microsoft 365 Group for its underlying calendar, document library, and task list; Teams itself does not natively provide a shared calendar or threaded discussions about each item without the group's resources. Option B is wrong because SharePoint Online provides document libraries and lists but lacks a built-in shared calendar and threaded discussions; it requires integration with other services like Outlook or Teams to achieve the full integrated experience. Option D is wrong because Microsoft Outlook is an email and calendar client that can display group resources but does not natively create or manage the document library, task list, or threaded discussions as a centralized workspace; it consumes the group's resources rather than providing them.

123
Multi-Selectmedium

Which three options are valid support options available to Microsoft 365 subscribers? (Choose three.)

Select 3 answers
.Community forums monitored by Microsoft experts and MVPs.
.Dedicated phone support available 24/7 for all subscription plans.
.Unlimited access to premier support engineers for all plans.
.Administrative support via the Microsoft 365 admin center for all paying subscribers.
.Self-help resources including online documentation and guided troubleshooting.
.In-person on-site support included with every Business Premium subscription.

Why this answer

Community forums monitored by Microsoft experts and MVPs are a valid support option for Microsoft 365 subscribers, providing peer-to-peer assistance with expert oversight. Self-help resources, including online documentation and guided troubleshooting, are available to all subscribers as a first-line support channel. Administrative support via the Microsoft 365 admin center is included for all paying subscribers, allowing them to create service requests for billing, account, and technical issues.

Exam trap

The trap here is that candidates often assume phone support is universally available 24/7 for all plans, but Microsoft restricts phone support to higher-tier subscriptions and imposes call-back scheduling for lower tiers.

124
MCQmedium

A sales representative needs to quickly create a professional-looking price quote that includes dynamic pricing from a company database and send it as a PDF to a customer. Which Microsoft 365 app is best suited for this?

A.Microsoft Word
B.Microsoft Excel
C.Microsoft Sway
D.Microsoft SharePoint Online
AnswerA

Word is a full-featured word processor that supports precise page layout, rich typography, tables, headers/footers, and embedded objects, all essential for a polished, branded sales quote. It can pull live data from Excel or external databases via linked content and mail merge fields, then export to a fixed-layout PDF via Save As, guaranteeing the recipient sees an identical professional document.

Why this answer

Microsoft Word is best suited because it supports mail merge and dynamic content from external data sources like a company database. Using Word's 'Insert Quick Parts' or mail merge features, a sales rep can pull live pricing data into a professional quote template and then export the document as a PDF directly from Word.

Exam trap

The trap here is that candidates often confuse Excel's data calculation capabilities with document creation, assuming a spreadsheet can produce a professional quote, but Word is the correct app for formatted, PDF-ready documents with dynamic content.

How to eliminate wrong answers

Option B is wrong because Microsoft Excel is a spreadsheet app optimized for data analysis and calculations, not for creating professional-looking documents with dynamic text and images; it lacks the rich layout and PDF export capabilities needed for a polished quote. Option C is wrong because Microsoft Sway is a presentation and storytelling app for interactive web-based content, not for generating static PDF documents with dynamic database-driven pricing. Option D is wrong because Microsoft SharePoint Online is a collaboration and document management platform, not a content creation app; it cannot directly create a formatted quote with dynamic pricing from a database.

125
Multi-Selecteasy

Which TWO of the following support options are available for Microsoft 365?

Select 2 answers
A.On-site support
B.Phone support
C.Chat support
D.Online support via the Microsoft 365 admin center
E.Email support
AnswersB, D

Phone support is a legitimate Microsoft 365 support channel for administrators, but it is not universally available on every license; for example, many Microsoft 365 Business and Enterprise plans include phone support, while some lower-tier plans might require a separate support plan or only offer online tickets. To use phone support, an admin typically enters the Microsoft 365 admin center, creates a service request, and selects 'Phone' or 'Request a call back', after which Microsoft support contacts them.

Why this answer

Phone support (B) is a standard support channel for Microsoft 365, available to all subscribers with a qualifying support plan, allowing users to call Microsoft directly for technical assistance. Online support via the Microsoft 365 admin center (D) is the primary self-service and ticket-based support portal where administrators can submit service requests, access health dashboards, and manage support cases.

Exam trap

The trap here is that candidates often confuse chat support (C) as a standard Microsoft 365 support option, but it is not explicitly listed in the official support channels, which are limited to phone and online via the admin center.

126
MCQhard

Refer to the exhibit. The exhibit shows a Conditional Access policy. Which requirement does this policy enforce?

A.Users from trusted IPs are blocked.
B.Users must provide MFA only.
C.Users must provide MFA and use a compliant device.
D.Users must provide MFA or use a compliant device.
AnswerC

The policy combines two grant controls in a single Conditional Access rule: require multifactor authentication and require the device to be marked compliant in Microsoft Entra ID. Both conditions must be satisfied before access is granted, matching the exhibit's configured grant controls exactly.

Why this answer

The policy enforces that users must provide MFA and use a compliant device. In Conditional Access, when both 'Require multi-factor authentication' and 'Require device to be marked as compliant' are selected under Grant controls, the user must satisfy both conditions to gain access.

Exam trap

MS-900 often tests whether candidates understand the AND/OR logic in Conditional Access grant controls, and whether they can interpret policy exhibits correctly.

How to eliminate wrong answers

Option A is wrong because the policy does not block users from trusted IPs; it enforces MFA and compliant device requirements. Option B is wrong because MFA alone is insufficient; the policy also requires a compliant device. Option D is wrong because the grant controls are combined with 'AND' logic, not 'OR', so both conditions must be met.

127
Multi-Selectmedium

Which TWO support plans provide access to Microsoft 365 technical support via phone and email with a guaranteed response time?

Select 2 answers
A.Microsoft Developer Support
B.Microsoft Unified Support
C.Microsoft 365 Business Support
D.Microsoft Premier Support
E.Microsoft Community Support
AnswersB, C

Microsoft Unified Support is the current enterprise-level support offering that consolidates all break-fix and proactive services into a single agreement. It provides 24/7 phone and email access to Microsoft engineers, defined response time SLAs, and account-level support management. This plan explicitly covers Microsoft 365 technical incidents, making it a valid answer for accessing M365 tech support.

Why this answer

Microsoft Unified Support (B) and Microsoft 365 Business Support (C) are the only plans that include phone and email technical support with guaranteed response times based on severity. Microsoft 365 Business Support is designed for organizations with fewer than 300 users, while Unified Support is an enterprise-grade plan that offers proactive services and faster SLAs. Both plans explicitly list phone and email as supported channels with defined response time commitments in their service descriptions.

Exam trap

The trap here is that candidates often confuse Microsoft Premier Support (a legacy plan) with Unified Support, or assume that Developer Support includes phone support for administrative issues, but the exam specifically tests that only Unified Support and Microsoft 365 Business Support offer phone and email with guaranteed response times.

128
Multi-Selecteasy

Which TWO Microsoft 365 services can be used to create and manage custom forms for data collection and surveys?

Select 2 answers
A.Microsoft Lists
B.Microsoft Forms
C.Excel Online
D.Power Apps
E.SharePoint Lists
AnswersB, D

Microsoft Forms is the dedicated service for building surveys, quizzes, and polls, providing a question editor, branching rules, and automatic result charts. It supports real-time response collection and can be embedded easily in Teams or SharePoint, making it the obvious choice for form creation. This service is purpose-built for the task described in the question.

Why this answer

Microsoft Forms is purpose-built for creating custom forms, surveys, and quizzes with automatic data collection into Excel Online. It provides a simple interface for designing forms, distributing them, and analyzing responses in real time, making it the primary tool for this task in Microsoft 365.

Exam trap

The trap here is that candidates often confuse Microsoft Lists or SharePoint Lists with form creation tools because they can display data in a form-like view, but they lack the native survey and data collection functionality that Microsoft Forms provides.

129
MCQmedium

A company wants monthly billing based on the number of Microsoft 365 users assigned licenses. Which cloud characteristic does this represent?

A.Fault tolerance
B.Resource pooling
C.Measured service
D.Rapid elasticity
AnswerC

Measured service is the cloud characteristic that provides usage metering, monitoring, and billing, allowing providers to charge for exactly the amount of service consumed or assigned—such as per-user Microsoft 365 licenses or per-hour virtual machine usage in Azure. It leverages telemetry and metering systems to track resource consumption, making it the direct answer to a requirement for monthly billing based on the number of Microsoft services. This is the only option that explicitly connects usage to financial invoicing, so it is correct.

Why this answer

Measured service is a cloud characteristic where usage is metered and billed based on consumption. In this scenario, the company is billed monthly based on the number of Microsoft 365 users assigned licenses, which directly reflects metered usage of the service. This aligns with the pay-per-use model defined by NIST SP 800-145 for cloud computing.

Exam trap

The trap here is that candidates confuse 'measured service' with 'rapid elasticity' because both involve dynamic changes, but measured service is specifically about metering and billing, not about scaling resources.

How to eliminate wrong answers

Option A is wrong because fault tolerance refers to a system's ability to continue operating after a component failure, not to billing or usage metering. Option B is wrong because resource pooling describes the provider's multi-tenant model where physical and virtual resources are dynamically assigned to multiple customers, not the billing mechanism. Option D is wrong because rapid elasticity involves the ability to quickly scale resources up or down based on demand, which is unrelated to how usage is measured and billed.

130
MCQmedium

A department head asks which Microsoft 365 option should be used to find Microsoft 365 training and adoption guidance. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Learn and adoption resources
B.Microsoft Stream
C.Microsoft Forms
D.Microsoft Whiteboard
AnswerA

Microsoft Learn is the centralized platform for role-based training, documentation, and adoption guidance for Microsoft 365. It includes learning paths for administrators and end users, plus adoption resources such as success kits and readiness checklists. This directly addresses the department head's need to understand and drive usage, whereas the other tools serve unrelated purposes.

Why this answer

Microsoft Learn and adoption resources are specifically designed to provide training, documentation, and adoption guidance for Microsoft 365. This includes step-by-step learning paths, interactive modules, and deployment guides that help organizations plan and execute user adoption strategies, directly matching the department head's request.

Exam trap

The trap here is that candidates may confuse general productivity tools (like Stream, Forms, or Whiteboard) with dedicated training and adoption platforms, overlooking that Microsoft Learn and adoption resources are the official, centralized sources for guidance.

How to eliminate wrong answers

Option B is wrong because Microsoft Stream is a video service for recording, sharing, and managing videos within an organization, not a platform for training or adoption guidance. Option C is wrong because Microsoft Forms is a survey and quiz creation tool used for collecting data, not for delivering training or adoption resources. Option D is wrong because Microsoft Whiteboard is a digital canvas for real-time collaboration and brainstorming, not a repository for training or adoption content.

131
MCQeasy

A tenant administrator applies the above configuration for Microsoft 365 Copilot. What is the result of this configuration?

A.Copilot will be enabled but will only use data from SharePoint and OneDrive; Exchange and Teams data are excluded.
B.Copilot will be enabled for all users and will access data from all Microsoft 365 services.
C.Copilot will be disabled because GraphConnectors is empty.
D.Copilot will only work for users in the European Union.
AnswerA

The configuration explicitly sets RestrictedContentSources to include only SharePoint and OneDrive, so Copilot remains enabled but its grounding data is limited to these two workloads. Exchange and Teams are not listed in the restricted sources, meaning their data cannot be retrieved or used by Copilot. The empty GraphConnectors list is irrelevant here because native Microsoft 365 sources are still available; it simply means no third-party or custom connectors were added.

Why this answer

The configuration shows that the 'Copilot' toggle is enabled, but the 'Data sources' section explicitly lists only SharePoint and OneDrive, with Exchange and Teams unchecked. This means Copilot will be active for users but will only index and retrieve data from SharePoint and OneDrive, excluding emails and Teams messages. The empty GraphConnectors list further confirms no external data sources are connected, but this does not disable Copilot itself.

Exam trap

The trap here is that candidates often assume an empty GraphConnectors list disables Copilot entirely, but in reality, Copilot remains enabled and functional with the internal Microsoft 365 data sources that are explicitly selected.

How to eliminate wrong answers

Option B is wrong because the configuration does not enable all data sources; Exchange and Teams are explicitly excluded, so Copilot will not access data from those services. Option C is wrong because an empty GraphConnectors list only means no external (third-party) data sources are connected; it does not disable Copilot, which still works with the selected Microsoft 365 data sources (SharePoint and OneDrive). Option D is wrong because there is no indication of any geographic restriction in the configuration; Copilot's availability is determined by licensing and tenant settings, not by a region-specific toggle in this UI.

132
MCQeasy

A company uses cloud resources and notices that their monthly bill is based on the exact amount of storage and compute hours they consumed. They did not pay for any fixed, unused capacity. Which cloud characteristic does this describe?

A.Rapid elasticity
B.Resource pooling
C.On-demand self-service
D.Measured service
AnswerD

Measured service is the cloud characteristic that monitors, controls, reports, and bills customers based on their actual resource consumption, such as processing time, storage, or bandwidth. This metering capability enables pay-as-you-go pricing, where the monthly invoice directly reflects the quantity and type of cloud resources used. It provides transparency and allows customers to align costs with usage, which is precisely the scenario of a monthly bill based on consumption.

Why this answer

Measured service is the cloud characteristic that enables usage-based billing, where customers pay only for the resources they actually consume (e.g., storage GB-hours, compute vCPU-hours) without any upfront or fixed costs for idle capacity. This is implemented through metering capabilities at the hypervisor or resource provider level, which track consumption in granular units and feed into billing systems. The scenario explicitly describes paying for exact consumption, which aligns directly with the pay-per-use model of measured service.

Exam trap

The trap here is that candidates confuse 'measured service' with 'on-demand self-service' because both involve user-driven provisioning, but measured service specifically addresses the metering and billing aspect, not the provisioning mechanism.

How to eliminate wrong answers

Option A is wrong because rapid elasticity refers to the ability to automatically scale resources up or down quickly in response to demand, not to billing based on consumption. Option B is wrong because resource pooling describes the provider's ability to serve multiple tenants from a shared physical infrastructure using multi-tenancy, not the metering or billing mechanism. Option C is wrong because on-demand self-service allows users to provision resources without human interaction via a web portal or API, but it does not inherently describe how those resources are billed or that unused capacity is not charged.

133
MCQeasy

A non-profit organization uses Microsoft 365 Business Basic. They have 50 staff members who need to collaborate on documents in real time. The executive director wants to set up a centralized repository for all organizational policies that can be accessed by staff both online and offline on their mobile devices. Which solution should the organization use?

A.Create a SharePoint Online document library with versioning and enable offline sync.
B.Store documents in Exchange Online mailboxes as attachments.
C.Create a Microsoft Teams team with a channel for policies and use the Files tab.
D.Use OneDrive for Business shared folders for each policy document.
AnswerA

A SharePoint Online document library is purpose-built for centralized policy management: it stores files in a secure, standards-based library with configurable major/minor versioning that retains a complete history of each change. Enabling offline sync via the OneDrive sync client or SharePoint mobile app ensures staff can access the latest approved versions even without connectivity. Because the library is a single source of truth in the Microsoft 365 Business Basic tenant, it meets both the version-control and offline-access requirements directly.

Why this answer

SharePoint Online document libraries support versioning, granular permissions, and offline sync via the OneDrive sync client or mobile app, making them ideal for a centralized, always-accessible policy repository. This meets the requirements for real-time collaboration and offline access on mobile devices.

Exam trap

The trap here is that candidates may confuse OneDrive for Business (personal storage) with SharePoint (organizational storage), or assume Teams' Files tab is a separate storage system rather than a SharePoint interface.

How to eliminate wrong answers

Option B is wrong because Exchange Online mailboxes are designed for email and calendar, not document storage; attachments are not versioned, cannot be synced offline, and lack centralized access controls. Option C is wrong because while Teams uses SharePoint for file storage, the Files tab in a channel is a front-end to a SharePoint library; however, the question asks for a centralized repository, and Teams channels are team-specific, not a single repository for all staff. Option D is wrong because OneDrive for Business is intended for individual file storage and sharing, not as a centralized organizational repository; shared folders require manual sharing and lack the governance features of a SharePoint library.

134
MCQmedium

An enterprise needs advanced analytics, voice, and advanced security/compliance capabilities beyond E3. Which option best matches the requirement?

A.Microsoft 365 E5
B.Microsoft Defender for Cloud only
C.Azure Virtual Desktop only
D.A free personal Microsoft account only
AnswerA

Microsoft 365 E5 is the correct answer because it is the premium Microsoft 365 enterprise suite that bundles the needed workloads: Power BI Pro for advanced analytics, Teams Phone System and audio conferencing for voice, plus advanced security and compliance tools like Defender for Microsoft 365 and Information Protection. While some voice capabilities depend on configuration (such as assigning Calling Plans), this single subscription provides the commercial tenant management, identity, and data governance foundation the enterprise requires.

Why this answer

Microsoft 365 E5 is the correct choice because it includes advanced analytics via Power BI Pro, voice capabilities through Phone System and Audio Conferencing, and advanced security/compliance features such as Microsoft Defender for Office 365, Microsoft Purview Information Protection, and Insider Risk Management. These capabilities are not available in E3, which lacks the advanced security, compliance, and voice features required by the enterprise.

Exam trap

The trap here is that candidates may confuse the limited security features in E3 (like basic threat management) with the advanced capabilities in E5, or assume that a standalone service like Defender for Cloud can replace the full suite of analytics, voice, and compliance tools bundled in E5.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Cloud only provides cloud security posture management and workload protection, lacking the advanced analytics, voice, and compliance capabilities required. Option C is wrong because Azure Virtual Desktop only delivers virtualized desktop and app experiences, with no built-in analytics, voice, or advanced security/compliance features. Option D is wrong because a free personal Microsoft account offers only basic consumer services like Outlook.com and OneDrive, with no enterprise-grade analytics, voice, or security/compliance capabilities.

135
MCQeasy

A system administrator at Contoso needs to ensure that all users are required to use multi-factor authentication when accessing Microsoft 365 services. Which Microsoft 365 feature should the administrator use to enforce this requirement?

A.Exchange Online mail flow rules
B.Microsoft Defender for Office 365 safe attachments policies
C.Microsoft Entra ID Conditional Access policies
D.Microsoft Purview Data Loss Prevention policies
AnswerC

Conditional Access policies in Microsoft Entra ID allow administrators to enforce multi-factor authentication based on conditions such as user group, location, device state, and application. This is the correct tool to require MFA for accessing Microsoft 365 services, providing granular control and integration with other security signals.

Why this answer

Conditional Access in Microsoft Entra ID is the centralized policy engine that evaluates signals like user, device, location, and application to enforce access controls, including requiring multi-factor authentication. It is the correct choice because it directly addresses authentication requirements for Microsoft 365 services, unlike the other options which focus on email security, data protection, or mail routing.

Exam trap

The trap here is confusing email security or data protection features with authentication controls, assuming that any security policy can enforce MFA.

136
MCQeasy

A financial services firm uses a public cloud provider for its customer-facing web application, but stores sensitive client data on its own on-premises servers. A secure VPN connection is used to transfer anonymized data from the public cloud to the on-premises environment for processing. Which cloud deployment model does this describe?

A.Public cloud
B.Private cloud
C.Hybrid cloud
D.Community cloud
AnswerC

Hybrid cloud is the correct model because it combines a private or on-premises environment with one or more public cloud providers, connected via a secure link such as a VPN or dedicated ExpressRoute. This architecture allows the financial services firm to keep sensitive data on-premises for regulatory compliance while leveraging public cloud scalability for non-sensitive workloads or burst capacity. It also enables workload portability between environments, which aligns directly with the scenario of integrating public cloud services with the firm's own on-premises servers.

Why this answer

This scenario describes a hybrid cloud because it combines a public cloud provider for the customer-facing web application with an on-premises private cloud for sensitive client data, connected via a secure VPN. The hybrid cloud model enables organizations to leverage the scalability and cost-efficiency of public cloud resources while maintaining strict control over sensitive data in a private environment. The use of a VPN to transfer anonymized data between the two environments is a key characteristic of hybrid cloud architecture, as it ensures secure communication across the boundary.

Exam trap

The trap here is that candidates may incorrectly choose 'Public cloud' because they focus on the customer-facing web application being hosted there, ignoring the on-premises storage of sensitive data, which is the defining characteristic of a hybrid deployment.

How to eliminate wrong answers

Option A is wrong because a public cloud model would have all resources, including sensitive client data, hosted and managed by the third-party cloud provider, not stored on-premises. Option B is wrong because a private cloud model would have all resources, including the web application, hosted on-premises or in a dedicated environment, not using a public cloud provider. Option D is wrong because a community cloud is shared by several organizations with common concerns (e.g., compliance or security requirements), but this scenario involves only one firm using both public and private infrastructure, not a multi-tenant community.

137
MCQmedium

A tenant administrator is advising a department that wants to use Microsoft 365 and another public cloud provider for different workloads. Cloud concept or benefit best matches this requirement?

A.Microsoft Planner
B.Sensitivity labels
C.Multi-cloud
D.Data Loss Prevention (DLP)
AnswerC

Multi-cloud is the correct answer because it describes an architecture in which an organization deliberately uses cloud services from two or more public cloud providers, such as Microsoft Azure, Amazon Web Services, and Google Cloud. This approach helps avoid vendor lock-in, improves resilience, and lets workloads run on the best-fit platform. If the department's goal is to operate across multiple cloud providers, multi-cloud is the technical term that matches that intent, not a Microsoft 365 workload or data protection feature.

Why this answer

C is correct because multi-cloud refers to using multiple public cloud providers (e.g., Microsoft 365 and another provider like AWS or Google Cloud) for different workloads, which directly matches the requirement. This allows the organization to avoid vendor lock-in, optimize costs, and leverage best-of-breed services across clouds.

Exam trap

The trap here is that candidates may confuse multi-cloud with hybrid cloud (which combines public and private cloud) or think a specific Microsoft tool (like Planner) is the answer, when the question explicitly asks for a cloud concept or benefit.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management and planning tool within Microsoft 365, not a cloud concept or benefit for using multiple cloud providers. Option B is wrong because sensitivity labels are a Microsoft Purview Information Protection feature used to classify and protect data, not a cloud deployment model. Option D is wrong because Data Loss Prevention (DLP) is a security policy mechanism to prevent unauthorized data sharing, not a cloud concept for multi-cloud usage.

138
MCQhard

An organization with 10,000 users is planning to deploy Microsoft 365. They need to minimize monthly costs while ensuring all users have access to Exchange Online, SharePoint Online, Teams, and Microsoft Copilot for Microsoft 365. Which licensing approach should they adopt?

A.Purchase Microsoft 365 E3 for most users and Copilot for a subset
B.Purchase Microsoft 365 E5 for all users
C.Purchase Microsoft 365 Business Premium for all users and add Copilot licenses
D.Purchase Microsoft 365 E3 for all users and add Copilot licenses
AnswerD

Microsoft 365 E3 is an enterprise-grade qualifying base plan for Copilot with no 300-user ceiling, making it suitable for a 10,000-user organization. Adding the Microsoft 365 Copilot add-on to E3 provides the full Copilot experience for every user while avoiding the advanced security and compliance features in E5 that would increase cost. This combination of a lower-cost enterprise base license plus the Copilot add-on is the standard, recommended licensing path for this scenario.

Why this answer

Microsoft 365 E3 provides the core enterprise-grade capabilities for Exchange Online, SharePoint Online, and Teams for all 10,000 users, while Copilot for Microsoft 365 can be added as an add-on license only for the users who need it, minimizing monthly costs. This approach avoids paying for premium features (like advanced security in E5) or unnecessary Copilot licenses across the entire user base, aligning with the requirement to minimize costs while ensuring all users have the required services.

Exam trap

The trap here is that candidates often assume Business Premium is a cheaper alternative for large organizations, but it has a 300-user limit and lacks enterprise features, making E3 the correct base license for organizations with 10,000 users.

How to eliminate wrong answers

Option A is wrong because purchasing Microsoft 365 E3 for most users and Copilot for a subset does not guarantee all users have access to Exchange Online, SharePoint Online, and Teams—if 'most' excludes some users, those users would lack the required services. Option B is wrong because Microsoft 365 E5 includes advanced security and compliance features that are not required, leading to unnecessary higher monthly costs for all 10,000 users. Option C is wrong because Microsoft 365 Business Premium is limited to 300 users and cannot scale to 10,000 users; it also lacks enterprise-level capabilities like unlimited mailbox storage and advanced compliance features that E3 provides.

139
MCQeasy

A user is unable to send emails with attachments larger than 25 MB. The organization has Microsoft 365 Business Standard. What should you do to increase the attachment limit?

A.Modify the maximum message size in the Exchange admin center
B.Instruct the user to compress the file
C.Purchase an Exchange Online Kiosk add-on
D.Have the user upload the file to OneDrive and share a link
AnswerA

The correct solution is for an administrator to raise the organization's transport limit in the Exchange admin center (Mail flow > Message size limits). Exchange Online allows configuration of the maximum send/receive message size up to 150 MB, so changing this setting directly raises the attachment ceiling. Since the user was blocked by the default 25 MB policy, only this change at the service level resolves the issue for all users in the organization.

Why this answer

In Microsoft 365 Business Standard, the default maximum message size for email attachments is 25 MB. To increase this limit, you must modify the maximum message size setting in the Exchange admin center (EAC), which controls the transport limits for the organization. This is the correct administrative action to raise the attachment size threshold beyond the default.

Exam trap

The trap here is that candidates often confuse the 25 MB default limit with a hard-coded protocol restriction (like SMTP's theoretical limit), leading them to choose workarounds like compression or OneDrive instead of recognizing that the limit is an administrative policy configurable in the Exchange admin center.

How to eliminate wrong answers

Option B is wrong because compressing the file reduces its size but does not increase the actual attachment limit; it is a workaround, not a solution to change the policy. Option C is wrong because the Exchange Online Kiosk add-on is a low-cost plan with a 25 MB limit and does not provide a higher attachment limit; it is designed for basic email access, not for increasing size restrictions. Option D is wrong because uploading to OneDrive and sharing a link bypasses the email attachment limit entirely, but the question asks how to increase the attachment limit for sending emails directly, not how to share files via alternative methods.

140
MCQeasy

A business needs staff to access Microsoft 365 services from different locations using only an internet connection. Which cloud benefit is being used?

A.Capital expenditure spending
B.Manual provisioning
C.Broad network access
D.Server virtualization only
AnswerC

Broad network access is one of the five essential characteristics of cloud computing defined by NIST, and it refers to capabilities being available over the network through standard protocols from heterogeneous client platforms. In the Microsoft 365 context, this means staff can use the web portal, desktop apps, and mobile apps on Windows, macOS, iOS, Android, and other devices without requiring a specific on-premises location. This directly satisfies the business requirement for employees to access services from varied networks and devices, making it the correct response.

Why this answer

Broad network access is a core characteristic of cloud computing defined by NIST SP 800-145. It means that resources are available over the network and can be accessed by standard client platforms (e.g., laptops, tablets, smartphones) using only an internet connection, without requiring a dedicated private link or on-premises hardware. In this scenario, staff accessing Microsoft 365 from different locations via the internet directly demonstrates broad network access.

Exam trap

The trap here is that candidates confuse 'broad network access' with 'server virtualization' or 'CapEx spending,' because they think cloud benefits are about hardware consolidation or cost models, rather than the fundamental characteristic of network-based, ubiquitous access.

How to eliminate wrong answers

Option A is wrong because capital expenditure (CapEx) spending refers to upfront investment in physical infrastructure (e.g., servers, data centers), which is the opposite of the cloud's operational expenditure (OpEx) model; the question describes accessing services via the internet, not a financial model. Option B is wrong because manual provisioning involves human intervention to set up resources, whereas cloud services like Microsoft 365 are self-service and automatically provisioned; the scenario focuses on access, not provisioning. Option D is wrong because server virtualization is a technology that enables multiple virtual machines on a single physical server, but it is not a cloud benefit itself and does not describe the ability to access services from anywhere via the internet; broad network access is the correct benefit.

141
MCQhard

A sales team uses Microsoft Lists to track leads. They want to create a real-time dashboard that shows the number of leads by stage, the total deal value, and the win rate. The dashboard must update automatically when the list is changed. Which Microsoft 365 app should they use to build this dashboard?

A.Microsoft Power BI
B.Microsoft Excel
C.Microsoft SharePoint
D.Microsoft Power Automate
AnswerA

Microsoft Power BI is correct because Power BI includes a native Microsoft Lists (SharePoint Online) connector that can pull list data into a data model via Power Query. It supports scheduled refresh (up to 8 times per day with a Pro license, or via a gateway in Power BI Report Server) so dashboards can display near-live data without manual intervention. With DAX measures, you can aggregate leads by stage, owner, or time, and build interactive visualizations that update on refresh, making it the only option that combines connectivity, computational analytics, and automatic data refresh.

Why this answer

Microsoft Power BI is the correct choice because it is designed to create real-time, interactive dashboards that can connect directly to Microsoft Lists via the Power BI service or Power BI Desktop. It supports automatic data refresh when the underlying list changes, enabling live tracking of leads by stage, total deal value, and win rate without manual intervention.

Exam trap

The trap here is that candidates often confuse Microsoft Power Automate with a dashboarding tool because it can respond to list changes, but it cannot visualize data; the correct answer requires recognizing that Power BI is the dedicated analytics and visualization app for real-time dashboards.

How to eliminate wrong answers

Option B is wrong because Microsoft Excel, while capable of creating charts and dashboards, does not natively support real-time automatic updates from Microsoft Lists without manual refresh or complex VBA scripting, and it lacks the robust data modeling and live dashboard capabilities of Power BI. Option C is wrong because Microsoft SharePoint is a content management and collaboration platform, not a dashboarding tool; it can host lists but cannot build real-time analytical dashboards with automatic updates. Option D is wrong because Microsoft Power Automate is a workflow automation tool that can trigger actions based on list changes but cannot create or display dashboards; it would need to integrate with Power BI for visualization.

142
MCQmedium

Your organization has 500 users with Microsoft 365 E3 licenses. You want to add security features such as Microsoft Defender for Office 365 (Plan 1) and Microsoft Purview Information Protection. Which licensing approach should you recommend?

A.Keep E3 and add Microsoft 365 E5 Compliance add-on
B.Keep E3 and add Microsoft 365 E5 Security add-on
C.Upgrade all users to Microsoft 365 E5
D.Keep E3 and use the Security & Compliance Center for E3
AnswerC

Upgrading all users to Microsoft 365 E5 is the correct choice because E5 directly includes both Defender for Office 365 Plan 1 and Microsoft Purview Information Protection. E5 bundles all E3 features with advanced security and compliance workloads, eliminating the need for additional add-ons and ensuring both the email protection and information protection requirements are met under a single license.

Why this answer

Microsoft 365 E5 includes both Defender for Office 365 (Plan 1) and Purview Information Protection (formerly Azure Information Protection P2) natively, whereas E3 requires separate add-ons. Upgrading all users to E5 is the simplest and most cost-effective licensing approach when both security features are needed for all 500 users, as it avoids the complexity and potential per-user cost of stacking multiple add-on SKUs.

Exam trap

The trap here is that candidates assume the E5 Security add-on or E5 Compliance add-on alone can cover both requirements, but each add-on only covers its respective domain (security or compliance), and neither alone includes both Defender for Office 365 (Plan 1) and Purview Information Protection.

How to eliminate wrong answers

Option A is wrong because the Microsoft 365 E5 Compliance add-on provides Purview Compliance features (e.g., eDiscovery, Audit) but does not include Defender for Office 365 (Plan 1), which is a security feature. Option B is wrong because the Microsoft 365 E5 Security add-on includes Defender for Office 365 (Plan 1) but does not include Purview Information Protection (which requires the E5 Compliance add-on or full E5). Option D is wrong because the Security & Compliance Center in E3 only offers basic security and compliance capabilities (e.g., limited DLP, basic audit) and does not include Defender for Office 365 (Plan 1) or Purview Information Protection, which require additional licensing.

143
MCQeasy

A company needs to audit user activities in Microsoft 365 for compliance. Which tool should they use?

A.Microsoft Defender XDR
B.Microsoft Sentinel
C.Microsoft Purview Audit (Premium)
D.Microsoft Intune
AnswerC

Microsoft Purview Audit (Premium) retains audit logs for up to ten years and provides high-bandwidth access plus intelligent insights, meeting the compliance auditing requirement. Standard Audit only retains events for 90 days, insufficient for long-term regulatory investigations.

Why this answer

Microsoft Purview Audit (Premium) is specifically designed to retain and search audit logs for user and admin activities across Microsoft 365 services, meeting compliance and forensic investigation needs. It provides high-bandwidth access to the Office 365 Audit Log, supports custom retention policies (up to 10 years), and offers intelligent insights such as high-value events and access to critical events like MailItemsAccessed. This makes it the correct tool for auditing user activities for compliance.

Exam trap

MS-900 often tests the difference between security tools (Defender XDR, Sentinel) and compliance auditing tools (Purview Audit), so candidates may mistakenly choose a security information and event management (SIEM) solution like Sentinel when the requirement is specifically for auditing user activities for compliance.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender XDR is a threat protection and detection suite that correlates signals across endpoints, identities, email, and apps, but it does not provide the comprehensive audit log retention and search capabilities required for compliance auditing. Option B is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR platform that ingests data from various sources for security analytics, but it is not the primary tool for auditing native Microsoft 365 user activities for compliance; it relies on data connectors and does not replace Purview Audit. Option D is wrong because Microsoft Intune is a mobile device and application management service focused on endpoint configuration and compliance, not on auditing user activities across Microsoft 365 workloads.

144
MCQhard

A company with Microsoft 365 E5 wants to use AI to summarize email threads and draft replies automatically. Which Microsoft 365 service provides this capability?

A.Microsoft Viva Insights
B.Microsoft 365 Copilot
C.Microsoft Search
D.Microsoft Editor
AnswerB

Microsoft 365 Copilot is a generative AI assistant embedded across Word, Outlook, Teams, and other M365 apps that uses large language models and your organizational data from Microsoft Graph to understand context. It can summarize a lengthy email thread, synthesize a meeting's key points, or draft a response in Outlook, making it the proper choice for AI-driven summarization.

Why this answer

Microsoft 365 Copilot integrates with Outlook and other Microsoft 365 apps to provide AI-powered email thread summarization and draft reply generation. It uses large language models (LLMs) combined with your Microsoft Graph data to understand context and produce relevant, personalized responses. This capability is not available in other Microsoft 365 services like Viva Insights or Microsoft Editor.

Exam trap

The trap here is that candidates may confuse Microsoft Viva Insights (which provides 'insights' and 'suggestions' about work patterns) with AI-powered content generation, or assume Microsoft Editor's grammar suggestions include drafting capabilities, when in fact only Copilot uses generative AI for these tasks.

How to eliminate wrong answers

Option A is wrong because Microsoft Viva Insights focuses on personal productivity analytics, wellbeing, and work patterns (e.g., meeting time, focus hours), not on generating email summaries or drafts. Option C is wrong because Microsoft Search provides enterprise search across files, messages, and sites using the Microsoft Graph, but it does not generate AI summaries or draft replies. Option D is wrong because Microsoft Editor is a writing assistant that checks spelling, grammar, and style in documents and emails, but it lacks the generative AI capabilities to summarize threads or draft replies from scratch.

145
MCQeasy

A department needs a shared document library with version history, permissions, and co-authoring for team files. Which service should they primarily use?

A.SharePoint Online.
B.OneDrive for Business.
C.Microsoft Forms.
D.Microsoft Planner.
AnswerA

SharePoint Online is Microsoft 365's dedicated content-management service, offering team document libraries with built-in version history, co-authoring, metadata columns, and granular permissions. Versioning in SharePoint retains previous versions of files and allows restore or compare, which directly meets the department's need for a shared, versioned document repository. It is the standard backend for shared files in Teams, Outlook, and many other M365 workloads.

Why this answer

SharePoint Online is the correct choice because it provides a centralized, team-based document library with built-in version history, granular permission management, and real-time co-authoring. Unlike OneDrive for Business, which is designed for personal file storage, SharePoint Online supports shared workspaces where multiple users can collaborate simultaneously on the same documents while maintaining full audit trails and access controls.

Exam trap

The trap here is that candidates often confuse OneDrive for Business with SharePoint Online, assuming OneDrive can serve as a team library, but OneDrive lacks the centralized permission management and team-level version history that SharePoint provides for departmental collaboration.

How to eliminate wrong answers

Option B (OneDrive for Business) is wrong because it is primarily a personal cloud storage service for individual users, not designed for team-based shared libraries with centralized permissions and version history across a department. Option C (Microsoft Forms) is wrong because it is a survey and quiz creation tool, not a document storage or collaboration platform. Option D (Microsoft Planner) is wrong because it is a task management and project planning tool, lacking document library, versioning, and co-authoring capabilities.

146
MCQhard

An organization wants to use AI to summarize long email threads and suggest replies in Outlook. Which Microsoft 365 feature provides this capability?

A.Microsoft Copilot for Microsoft 365
B.Microsoft Editor
C.Microsoft Search
D.Microsoft Viva Insights
AnswerA

Microsoft Copilot for Microsoft 365 is embedded in Outlook and uses the Microsoft Graph plus large language models to summarise lengthy email threads and draft suggested replies directly within the mailbox, matching the stated requirement.

Why this answer

Microsoft Copilot for Microsoft 365 integrates AI directly into Outlook to summarize long email threads and generate suggested replies. It uses large language models and the Microsoft Graph to analyze conversation context, extract key points, and draft responses, all within the user's mailbox. This is the only Microsoft 365 feature designed specifically for these natural language processing tasks in Outlook.

Exam trap

The trap here is that candidates often confuse Microsoft Editor's basic AI writing assistance with Copilot's advanced generative AI capabilities, assuming Editor can handle complex tasks like summarization and reply generation, but Editor lacks the underlying large language model and Graph integration required for those features.

How to eliminate wrong answers

Option B is wrong because Microsoft Editor is a writing assistant that provides grammar, spelling, and style suggestions, but it cannot summarize email threads or generate suggested replies. Option C is wrong because Microsoft Search helps users find content across Microsoft 365 (e.g., emails, files, people) via a search index, but it does not perform AI-driven summarization or reply generation. Option D is wrong because Microsoft Viva Insights focuses on productivity and wellbeing analytics (e.g., focus time, meeting habits) and does not include capabilities for summarizing conversations or suggesting replies.

147
MCQmedium

A company with 100 users wants to provide all users with Microsoft Teams and cloud file storage, but only the sales team of 20 users needs access to Dynamics 365. Which licensing approach is most cost-effective?

A.Purchase Microsoft 365 Business Basic for all 100 users and Dynamics 365 Sales Professional for the 20 sales users.
B.Purchase Microsoft 365 Business Premium for all 100 users.
C.Purchase Microsoft 365 E3 for all 100 users and add Dynamics 365 for the sales team.
D.Purchase Microsoft 365 Business Basic for all users and Dynamics 365 Business Central for the 20 sales users.
AnswerA

Microsoft 365 Business Basic provides the necessary cloud productivity foundation—Exchange Online email, Teams, and SharePoint—for all 100 employees at a low per-user cost. Dynamics 365 Sales Professional is a separate, per-user CRM license required only for the 20 sales representatives who need opportunity and pipeline management. This hybrid licensing approach ensures every user is appropriately licensed without paying for capabilities that non-sales staff do not consume.

Why this answer

Microsoft 365 Business Basic provides Teams and cloud file storage (SharePoint/OneDrive) for all 100 users at the lowest per-user cost, and Dynamics 365 Sales Professional is the correct Dynamics SKU for a sales team needing CRM functionality. This combination matches each user's actual needs without paying for capabilities they will not use. It is the most cost-effective approach because licensing is scoped to the smallest sufficient SKU per user group.

Exam trap

MS-900 often tests the confusion between Dynamics 365 Sales (CRM) and Dynamics 365 Business Central (ERP), and candidates frequently pick Business Central thinking it is the general-purpose Dynamics product for any business need.

How to eliminate wrong answers

Option B is wrong because Microsoft 365 Business Premium includes Intune, Defender, and advanced security features that are not required by the stated scenario, so it over-licenses all 100 users. Option C is wrong because Microsoft 365 E3 is an enterprise SKU with a much higher per-user cost and includes features (like advanced compliance and Windows E3) that the company did not ask for, and it still requires adding Dynamics separately. Option D is wrong because Dynamics 365 Business Central is an ERP solution for finance and operations, not a CRM for a sales team — the sales team needs Dynamics 365 Sales, not Business Central.

148
MCQmedium

A field service team needs a mobile-friendly app that allows technicians to view customer information from a central database, log completed tasks, and capture photos on-site. The IT department has limited development resources and wants to build this app quickly without writing extensive code. Which Microsoft 365 app is best suited for this requirement?

A.Microsoft Power Apps
B.Microsoft Forms
C.Microsoft Power Automate
D.Microsoft Power BI
AnswerA

Power Apps provides a low-code canvas and model-driven builder, letting technicians view central data, log tasks and capture photos through a mobile app with minimal hand-written code. This directly satisfies the stem's limited development resource and rapid delivery constraint.

Why this answer

Microsoft Power Apps is the correct choice because it enables rapid development of custom mobile-friendly apps with minimal code, allowing the field service team to view customer data from a central database (e.g., Dataverse or SharePoint), log completed tasks, and capture photos on-site. Its low-code platform provides pre-built connectors and templates that directly address the need for a data-driven, mobile-first application without extensive development resources.

Exam trap

The trap here is that candidates often confuse Power Automate with Power Apps, thinking that automation alone can build an app, but Power Automate only orchestrates workflows and cannot provide the interactive user interface required for field technicians to view data, log tasks, and capture photos.

How to eliminate wrong answers

Option B (Microsoft Forms) is wrong because it is designed for creating surveys and forms for data collection, not for building a multi-functional mobile app that integrates with a central database and supports task logging and photo capture. Option C (Microsoft Power Automate) is wrong because it focuses on workflow automation and process orchestration, not on creating a user-facing mobile application with custom UI and data interaction. Option D (Microsoft Power BI) is wrong because it is a business analytics and visualization tool, not an app development platform; it cannot provide the interactive, data-entry functionality required for field technicians.

149
MCQhard

An organization is reconciling their Microsoft 365 invoice and notices charges for 'Microsoft 365 Copilot' that they did not expect. The administrator suspects that users may have inadvertently enabled Copilot via self-service purchase. How should they prevent this in the future?

A.Remove Copilot licenses from all users
B.Disable self-service purchasing in the Microsoft 365 admin center
C.Cancel the Copilot subscription
D.Set up billing alerts for unexpected charges
AnswerB

Disable self-service purchasing in the Microsoft 365 admin center to prevent users from buying Copilot or other add-on licenses without admin approval. A Global or Billing Admin must change this tenant-level billing control, which addresses the root of the invoice discrepancy by stopping unauthorized future purchases. This is the only preventative option because it closes the purchasing channel users are exploiting.

Why this answer

Disabling self-service purchasing in the Microsoft 365 admin center is the direct method to prevent users from acquiring Copilot licenses on their own. Self-service purchasing allows users to buy subscriptions like Microsoft 365 Copilot without admin approval, leading to unexpected charges. By disabling this feature, the administrator regains control over license procurement, ensuring no future inadvertent Copilot activations occur.

Exam trap

The trap here is that candidates may confuse reactive billing controls (like alerts or license removal) with the proactive administrative setting that actually blocks the self-service purchase mechanism, leading them to choose a non-preventive option.

How to eliminate wrong answers

Option A is wrong because removing Copilot licenses from all users is a reactive measure that does not prevent users from re-enabling Copilot via self-service purchase; it only cleans up existing assignments. Option C is wrong because canceling the Copilot subscription removes the service entirely but does not address the root cause—self-service purchasing remains enabled, allowing users to re-subscribe. Option D is wrong because setting up billing alerts only notifies the administrator of unexpected charges after they occur, rather than preventing the self-service purchase from happening in the first place.

150
MCQmedium

Refer to the exhibit. An admin runs the PowerShell command shown. What is the implication for the user's mailbox?

A.The retention policy is not effective
B.The mailbox has no retention policy applied
C.The mailbox is on litigation hold
D.The mailbox will automatically delete items after 30 days
AnswerC

The mailbox is correctly identified as being on litigation hold because the LitigationHoldEnabled property returns True. A litigation hold preserves all mailbox content indefinitely, including deleted items and previous versions, and prevents any permanent deletion or expiry. This is the direct and accurate interpretation of the output.

Why this answer

The PowerShell command `Set-Mailbox -LitigationHoldEnabled $true` places the user's mailbox on litigation hold. This preserves all mailbox content, including deleted items and original versions of modified items, for eDiscovery purposes. The hold overrides any retention policy that would otherwise delete or archive items, ensuring data is retained indefinitely until the hold is removed.

Exam trap

The trap here is that candidates confuse litigation hold with a retention policy or assume the command removes the policy, when in fact litigation hold is a separate preservation mechanism that overrides deletion behavior without altering the applied retention policy.

How to eliminate wrong answers

Option A is wrong because litigation hold overrides retention policies, making the retention policy temporarily ineffective for deletion or archiving, but the policy itself remains applied and will take effect once the hold is removed. Option B is wrong because the command does not remove or prevent a retention policy from being applied; it only enables litigation hold, which coexists with any existing policy. Option D is wrong because litigation hold prevents automatic deletion of items after any period, including 30 days; items are retained indefinitely regardless of retention tags or settings.

Page 1

Page 2 of 11

Page 3

All pages