Courseiva

Microsoft 365 Fundamentals MS-900 (MS-900) — Questions 151–225

794 questions total · 11pages · All types, answers revealed

Page 2

Page 3 of 11

Page 4
151
MCQmedium

A company runs a custom application on a cloud provider's infrastructure. The provider manages the physical servers, networking, and storage, but the company installs, configures, and patches the operating system and application. Which cloud service model is this?

A.Software as a Service (SaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Function as a Service (FaaS)
AnswerC

IaaS provides virtualized compute, storage, and networking as raw infrastructure blocks, with the provider maintaining only the physical data center, hosts, hypervisor, and network fabric. The customer provisions virtual machines, installs and patches the guest operating system, configures storage and firewall rules, and runs the custom application on top. In the scenario, the customer has control over the OS and app stack, which is exactly the IaaS responsibility model.

Why this answer

This scenario describes Infrastructure as a Service (IaaS) because the cloud provider manages the underlying physical infrastructure (servers, networking, storage), while the customer retains control over the operating system, middleware, and application. In IaaS, the customer is responsible for OS patching, configuration, and application management, which matches the given responsibilities.

Exam trap

The trap here is confusing IaaS with PaaS because both involve deploying applications, but the key differentiator is OS-level control and patching responsibility—IaaS gives you full OS access, while PaaS abstracts it away.

How to eliminate wrong answers

Option A is wrong because Software as a Service (SaaS) delivers a fully managed application to end users, where the provider handles everything including the OS and application, and the customer does not install or patch the OS. Option B is wrong because Platform as a Service (PaaS) provides a managed runtime environment where the provider manages the OS and middleware, and the customer only deploys code, not the OS or its patches. Option D is wrong because Function as a Service (FaaS) is an event-driven compute model where the provider manages the entire infrastructure and the customer only uploads individual functions, with no OS-level access or patching responsibility.

152
MCQmedium

A company with 200 users currently has Microsoft 365 Business Basic licenses. They need to add Microsoft Defender for Office 365 (Plan 1) and device management capabilities using Microsoft Intune. What is the most cost-effective licensing upgrade to obtain these features?

A.Upgrade to Microsoft 365 Business Premium
B.Add standalone Microsoft Defender for Office 365 Plan 1
C.Add standalone Microsoft Intune
D.Upgrade to Microsoft 365 E3
AnswerA

Microsoft 365 Business Premium combines the full Office 365 productivity suite with Azure AD Premium P1, Microsoft Intune, and Microsoft Defender for Office 365 Plan 1 under a single per-user license. This integrated bundle enables conditional access policies, mobile device management, and email threat protection without separate add-on purchases, making it the most direct and cost-effective upgrade for a 200-user small business. Its unified security stack also includes Microsoft Purview compliance features and automated attack simulation, which standalone products cannot replicate.

Why this answer

Microsoft 365 Business Premium includes both Microsoft Defender for Office 365 (Plan 1) and Microsoft Intune device management, making it the most cost-effective upgrade from Business Basic. Purchasing these as standalone add-ons would cost more per user than the bundled Business Premium license, which also provides additional security and productivity features.

Exam trap

The trap here is that candidates often assume adding individual add-ons is cheaper, but Microsoft bundles these features in Business Premium at a lower total cost per user than purchasing them separately, and they may overlook that E3 is an enterprise plan with unnecessary extras for a 200-user company.

How to eliminate wrong answers

Option B is wrong because adding standalone Microsoft Defender for Office 365 Plan 1 would provide email security but not device management via Intune, requiring a separate Intune license and increasing total cost. Option C is wrong because adding standalone Microsoft Intune would enable device management but not provide Defender for Office 365 Plan 1, necessitating an additional purchase for email protection. Option D is wrong because upgrading to Microsoft 365 E3 is significantly more expensive than Business Premium and includes features (like advanced eDiscovery and compliance) not required for the stated needs, making it less cost-effective.

153
MCQmedium

A development team uses a cloud service to run applications where the provider manages the runtime environment, operating system, and middleware. The team only writes and uploads code. Which service model are they using?

A.IaaS (Infrastructure as a Service)
B.PaaS (Platform as a Service)
C.SaaS (Software as a Service)
D.FaaS (Function as a Service)
AnswerB

PaaS provides a managed hosting environment in which the provider handles the operating system, runtime, middleware, and underlying hardware, allowing developers to focus exclusively on writing and deploying application code. This directly fits a development team that wants to run applications in the cloud without provisioning or maintaining servers, while still having full control over their code and configuration.

Why this answer

The scenario describes the team writing and uploading code while the provider manages the runtime environment, operating system, and middleware. This is the defining characteristic of Platform as a Service (PaaS), where the cloud provider abstracts the underlying infrastructure and platform layers, allowing developers to focus solely on application code. In PaaS, the provider handles OS patching, runtime updates, and middleware configuration, which matches the description exactly.

Exam trap

The trap here is that candidates often confuse PaaS with IaaS because both involve deploying applications, but the key differentiator is who manages the runtime and middleware — PaaS abstracts them away, while IaaS requires the user to manage them.

How to eliminate wrong answers

Option A (IaaS) is wrong because IaaS provides virtualized computing resources (e.g., VMs, storage, networks) but the user is responsible for managing the runtime environment, operating system, and middleware; the team would need to install and configure these themselves, not just upload code. Option C (SaaS) is wrong because SaaS delivers fully functional software applications over the internet (e.g., Office 365, Salesforce) where users consume the application without writing or uploading code; the team in the question is actively developing and uploading code. Option D (FaaS) is wrong because FaaS (Function as a Service) is a subset of serverless computing where developers upload individual functions that are executed in response to events, but the provider still manages the runtime environment; however, the question specifies the team runs 'applications' and manages the 'runtime environment, operating system, and middleware' at a higher abstraction level than individual functions, and FaaS typically involves event-driven, stateless functions rather than full application hosting.

154
MCQhard

A company uses Microsoft 365 (a SaaS offering). A security incident occurs where an employee's account is compromised because the employee reused their corporate password on a personal website. According to the shared responsibility model, who is primarily responsible for this security failure?

A.The customer (the company using Microsoft 365)
B.Microsoft, because they provide the SaaS platform
C.Both Microsoft and the customer share equal responsibility
D.It depends on the contract terms with Microsoft
AnswerA

The customer is accountable for the identity plane in the Microsoft 365 shared responsibility model. Entra ID (Azure AD) tenant configuration, user accounts, passwords, and access policies like MFA and Conditional Access are all customer-managed controls. Because the incident stemmed from weak password practices and password reuse, the failure resides in the customer's cloud-hosted data and identity responsibilities, not in Microsoft's infrastructure or code.

Why this answer

In the Microsoft 365 shared responsibility model, the customer is responsible for securing user identities, including password hygiene and multi-factor authentication (MFA). Since the employee reused their corporate password on a personal website, this is a customer-side identity management failure, not a platform vulnerability. Microsoft secures the SaaS infrastructure, but customer-managed credentials fall under the customer's responsibility.

Exam trap

The trap here is that candidates often assume SaaS means Microsoft handles all security, but the shared responsibility model clearly places identity and credential management on the customer, especially for user-caused password reuse incidents.

How to eliminate wrong answers

Option B is wrong because Microsoft is responsible for the security of the SaaS platform itself (e.g., physical data centers, network infrastructure, and service-level controls), not for how customers manage their own user credentials or enforce password policies. Option C is wrong because the shared responsibility model does not assign equal responsibility for all incidents; identity and access management (IAM) tasks like password policies and user training are explicitly customer obligations. Option D is wrong because the shared responsibility model is a standard framework defined by Microsoft for all Microsoft 365 tenants, not a negotiable contract term; while specific contractual clauses may add details, the core division of responsibilities is fixed.

155
MCQmedium

During a Microsoft 365 planning workshop, keep a workload on-premises while using Microsoft cloud collaboration services. Cloud concept or benefit best matches this requirement?

A.Hybrid cloud
B.Sensitivity labels
C.Microsoft Planner
D.Data Loss Prevention (DLP)
AnswerA

Hybrid cloud directly satisfies the requirement to keep a workload on-premises while consuming Microsoft cloud collaboration services. It combines on-premises infrastructure with public cloud resources such as Microsoft 365, enabling data residency or legacy dependencies to remain local while users access cloud collaboration.

Why this answer

A hybrid cloud model is the correct answer because it explicitly describes a scenario where an organization keeps certain workloads on-premises while integrating with Microsoft cloud collaboration services like Microsoft 365. This allows for a unified management plane, identity federation via Azure AD Connect, and seamless data synchronization between on-premises infrastructure and cloud services such as Exchange Online, SharePoint Online, or Teams.

Exam trap

The trap here is that candidates may confuse a specific Microsoft 365 feature (like sensitivity labels or DLP) with a cloud deployment model, failing to recognize that 'hybrid cloud' is the architectural concept that directly addresses the requirement of mixing on-premises and cloud services.

How to eliminate wrong answers

Option B is wrong because sensitivity labels are a Microsoft 365 compliance feature used to classify and protect data based on sensitivity, not a cloud deployment model that enables hybrid connectivity. Option C is wrong because Microsoft Planner is a task management application within Microsoft 365, not a cloud concept or benefit that supports keeping workloads on-premises. Option D is wrong because Data Loss Prevention (DLP) is a policy-based security feature to prevent unauthorized sharing of sensitive data, not a cloud architecture that allows hybrid workloads.

156
MCQmedium

A business stakeholder asks how Microsoft 365 can help them protect Windows endpoints with endpoint detection and response capabilities. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Planner
B.Microsoft Forms
C.Microsoft Stream
D.Microsoft Defender for Endpoint
AnswerD

Microsoft Defender for Endpoint delivers endpoint detection and response for Windows devices, including behavioural analytics, alerts and automated investigation. It is the Microsoft 365 security capability that satisfies the stakeholder's stated EDR requirement for Windows endpoints.

Why this answer

Microsoft Defender for Endpoint is the correct choice because it provides endpoint detection and response (EDR) capabilities specifically designed to protect Windows endpoints. It uses behavioral sensors, cloud analytics, and threat intelligence to detect, investigate, and respond to advanced threats in real time, aligning directly with the stakeholder's request.

Exam trap

The trap here is that candidates may confuse general productivity tools (Planner, Forms, Stream) with security capabilities, failing to recognize that only Microsoft Defender for Endpoint is purpose-built for endpoint detection and response (EDR) in Microsoft 365.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a project management tool for task assignment and scheduling, not a security capability. Option B is wrong because Microsoft Forms is a survey and data collection tool, lacking any endpoint detection or response functionality. Option C is wrong because Microsoft Stream is a video hosting and sharing platform, unrelated to endpoint security or threat detection.

157
MCQhard

An organization uses Microsoft 365 and wants to automatically detect and remediate security incidents across identities, endpoints, and cloud apps. Which Microsoft 365 service should they deploy?

A.Microsoft Sentinel
B.Microsoft Purview
C.Microsoft Defender for Office 365
D.Microsoft Defender XDR
AnswerD

Microsoft Defender XDR (formerly Microsoft 365 Defender) unifies telemetry from Defender for Identity, Defender for Endpoint, Defender for Office 365, and Defender for Cloud Apps into a single incident queue, automatically correlating suspicious activities across identities, endpoints, email, and cloud applications. It leverages built-in hunting and automated response playbooks to remediate threats with actions like isolating endpoints, pausing user accounts, or rolling back email messages. This integrated, portfolio-wide automation is exactly the native XDR capability that the organization needs.

Why this answer

Microsoft Defender XDR (Extended Detection and Response) is the correct choice because it provides a unified, cross-domain security solution that automatically detects and remediates security incidents across identities, endpoints, and cloud apps. It correlates signals from Microsoft Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps to deliver automated investigation and response, aligning directly with the scenario's requirement for holistic incident management.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with Microsoft Defender XDR (an XDR), but Sentinel requires manual configuration for automated remediation across domains, whereas Defender XDR provides built-in, cross-domain automated response out of the box.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution that ingests logs from multiple sources for threat detection and response, but it does not natively provide automated cross-domain remediation across identities, endpoints, and cloud apps without custom playbooks and integrations. Option B is wrong because Microsoft Purview is a data governance, compliance, and risk management solution focused on data classification, labeling, and protection, not on detecting and remediating security incidents across identities, endpoints, and cloud apps. Option C is wrong because Microsoft Defender for Office 365 is specifically designed to protect against threats in email, SharePoint, OneDrive, and Teams, and does not cover identity or endpoint security incidents, making it too narrow for the described requirement.

158
MCQeasy

During requirements gathering, an IT manager says the organization must let users provision resources from a portal without provider interaction. Cloud concept or benefit best matches this requirement?

A.On-demand self-service
B.Data Loss Prevention (DLP)
C.Microsoft Planner
D.Sensitivity labels
AnswerA

On-demand self-service lets users provision resources themselves through a portal or API without requiring interaction from the service provider. This precisely matches the IT manager's requirement that users obtain resources from a portal without provider involvement.

Why this answer

On-demand self-service is a core NIST-defined characteristic of cloud computing that allows users to provision computing resources—such as virtual machines, storage, or network capacity—automatically through a web portal or API without requiring human interaction from the service provider. This directly matches the IT manager's requirement for users to provision resources from a portal without provider interaction, making option A correct.

Exam trap

The trap here is that candidates may confuse a specific Microsoft 365 feature (like Planner or sensitivity labels) with a fundamental cloud computing characteristic, or mistakenly think DLP is a provisioning mechanism, when the question explicitly tests the NIST definition of on-demand self-service.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) is a security policy and technology used to prevent sensitive data from being leaked or shared inappropriately, not a cloud concept for self-service resource provisioning. Option C is wrong because Microsoft Planner is a task management and planning application within Microsoft 365, not a cloud computing characteristic or benefit related to provisioning resources without provider interaction. Option D is wrong because sensitivity labels are classification and protection mechanisms applied to documents and emails to enforce access controls and encryption, not a cloud concept for automated resource provisioning.

159
MCQhard

A global enterprise uses Microsoft 365 E5 and has users in Europe, Asia, and North America. They need to ensure that user data in Exchange Online and SharePoint Online remains within the European Union for EU users. They also want to apply a retention policy to keep all data for at least 7 years. Which combination of Microsoft 365 features should an administrator use?

A.Enforce data residency using Multi-Geo capabilities in Exchange Online and SharePoint Online, and apply a retention policy via Microsoft Purview Data Lifecycle Management.
B.Use Microsoft Purview Compliance Manager to configure data residency and retention settings.
C.Use Data Location for Exchange Online and a SharePoint multi-geo tenant, then create a retention policy in Purview for 7 years.
D.Configure Microsoft Entra ID Conditional Access policies to restrict data access based on location.
AnswerA

Multi-Geo in Microsoft 365 lets you designate satellite geographies for data-at-rest while keeping a single tenant; Exchange Online and SharePoint Online (including OneDrive) honor the user’s PreferredDataLocation to store content in the assigned EU region. Purview Data Lifecycle Management then applies a seven-year retention policy to that content, ensuring regulatory compliance without altering access controls. This is the direct, correct way to meet both residency and retention requirements in an E5 tenant.

Why this answer

Multi-Geo capabilities in Exchange Online and SharePoint Online allow the administrator to pin user data at the tenant level to a specific geographic location (e.g., the EU), ensuring data residency. A retention policy configured via Microsoft Purview Data Lifecycle Management can then be applied to retain all data for a minimum of 7 years, meeting both compliance requirements.

Exam trap

The trap here is confusing data residency enforcement (which requires Multi-Geo) with access control (Conditional Access) or compliance scoring (Compliance Manager), leading candidates to pick options that address only part of the requirement or use the wrong tool entirely.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Compliance Manager is a risk-assessment and compliance-scoring tool, not a feature for configuring data residency or retention policies; it does not enforce data location or set retention durations. Option C is wrong because 'Data Location for Exchange Online' is not a standalone feature—Multi-Geo is the correct mechanism for Exchange Online data residency, and the phrase 'SharePoint multi-geo tenant' is redundant and imprecise; the retention policy in Purview is correctly described, but the data residency part is misstated. Option D is wrong because Microsoft Entra ID Conditional Access policies control access based on location (e.g., blocking sign-ins from outside the EU), but they do not enforce where data is stored or apply retention; they are an identity and access control feature, not a data residency or lifecycle management tool.

160
MCQmedium

You need to provide external partners access to a single document without giving them access to your entire SharePoint site. What should you do?

A.Add the partners as guests to the SharePoint site
B.Email the document as an attachment
C.Create a Microsoft 365 group and add them
D.Share a direct link to the document with specific permissions
AnswerD

Sharing a direct link to the document with specific permissions (for example, 'Specific people' or 'Anyone with the link' with view or edit rights) scopes access to exactly that file, while allowing you to set an expiration date, require sign-in, or disable downloading. This uses SharePoint's granular sharing engine, which stores the link in the file's access control list, gives you the ability to revoke access at any time, and generates audit events in Microsoft Purview. It is the recommended method for granting external partners limited, document-specific access because it balances collaboration with security and least privilege.

Why this answer

Sharing a direct link with specific permissions allows you to grant external partners access to a single document without giving them broader access to the entire SharePoint site. This method uses SharePoint's granular permission model, where you can set the link to 'Specific people' and restrict permissions to 'View' or 'Edit' only on that document, ensuring no unintended access to other site content.

Exam trap

The trap here is that candidates often confuse 'guest access' (which grants site-level access) with 'document-level sharing' (which is granular), leading them to incorrectly choose Option A, assuming guest access can be scoped to a single document.

How to eliminate wrong answers

Option A is wrong because adding partners as guests to the SharePoint site grants them access to the entire site, including all documents, lists, and pages, which violates the requirement to restrict access to a single document. Option B is wrong because emailing the document as an attachment creates a separate copy outside SharePoint, losing version control, permissions management, and audit trails, and does not provide controlled access to the original document. Option C is wrong because creating a Microsoft 365 group and adding partners gives them access to all resources associated with that group (e.g., SharePoint site, Teams, Planner), which again exposes the entire site, not just the single document.

161
MCQeasy

Your company wants to run a phishing simulation to test employee awareness. Which Microsoft 365 tool can you use to create and launch a simulated phishing campaign?

A.Microsoft Defender for Cloud Apps
B.Microsoft Defender for Office 365 Attack Simulation Training
C.Microsoft Intune
D.Microsoft Purview Compliance Manager
AnswerB

Attack Simulation Training, part of Microsoft Defender for Office 365, provides built-in phishing payloads, landing pages and training assignments, letting administrators launch simulated campaigns and track employee interaction. This directly satisfies the requirement to create and launch a phishing simulation.

Why this answer

Microsoft Defender for Office 365 includes Attack Simulation Training, a feature specifically designed to create and launch simulated phishing campaigns. It provides realistic phishing emails, landing pages, and training assignments to educate users. This tool is part of the Threat Protection suite and is accessible via the Microsoft 365 Defender portal.

It allows administrators to select payloads, target users, and schedule simulations, then review results and assign training.

Exam trap

MS-900 often tests the confusion between Microsoft 365 security and compliance tools, expecting candidates to know that Attack Simulation Training is a feature of Defender for Office 365, not a standalone product or part of Purview or Intune.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility and control over cloud app usage, not phishing simulation. Option C is wrong because Microsoft Intune is a mobile device and application management service, focusing on endpoint configuration and compliance, not security awareness training. Option D is wrong because Microsoft Purview Compliance Manager helps assess and manage compliance risks and controls, but does not include phishing simulation capabilities.

162
MCQhard

A hospital uses Microsoft 365 and needs to comply with HIPAA by ensuring that patient health information in emails is encrypted both in transit and at rest. Which Microsoft 365 feature should they enable?

A.Microsoft Defender for Office 365
B.Microsoft Intune
C.Microsoft Purview Data Lifecycle Management
D.Office 365 Message Encryption
AnswerD

Office 365 Message Encryption is exactly the service for HIPAA because it uses Azure Rights Management to encrypt messages in transit and at rest for authorized recipients both inside and outside the organization. It supports configurable encrypted email templates and can be integrated with data loss prevention rules to automatically protect ePHI. This directly fulfills the HIPAA Security Rule's requirement to encrypt email containing protected health information.

Why this answer

Office 365 Message Encryption (OME) is the correct feature because it provides built-in encryption for emails both in transit (via TLS) and at rest (via Azure Rights Management), ensuring that patient health information (PHI) remains protected and compliant with HIPAA requirements. OME integrates with Azure Information Protection to apply persistent encryption that travels with the email, regardless of where it is stored.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Office 365 (a threat protection tool) with email encryption, because both are security-related, but Defender does not provide the persistent encryption required for HIPAA compliance.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Office 365 is a security service focused on threat protection (anti-phishing, anti-malware, safe attachments/links), not on encrypting email content at rest or in transit for compliance. Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) tool that manages devices and apps, but it does not directly encrypt email messages themselves. Option C is wrong because Microsoft Purview Data Lifecycle Management (formerly known as Microsoft 365 retention policies) manages data retention and deletion, not encryption of email content.

163
MCQhard

A company migrates its database to Azure SQL Database (PaaS). According to the shared responsibility model, which of the following is the customer's responsibility?

A.Managing user access and authentication
B.Patching the operating system of the database server
C.Maintaining the physical infrastructure
D.Managing the virtualization layer
AnswerA

In Azure SQL Database, a PaaS offering, the customer remains responsible for data plane security, specifically controlling who can authenticate and what privileges they hold. You manage SQL logins, contained database users, Azure Active Directory identities, and database/role permissions, while Microsoft never takes on that access governance. This includes configuring firewalls for client IPs only as part of network access control, but authentication and authorization decisions are exclusively the customer's duty. Therefore, managing user access and authentication is a customer-controlled function within the shared responsibility model.

Why this answer

In the shared responsibility model for Azure SQL Database (PaaS), the customer is responsible for managing user access and authentication because the customer controls who can connect to the database and what permissions they have. Microsoft manages the underlying infrastructure, including the operating system, physical hardware, and virtualization layer, while the customer must secure data access through Azure Active Directory or SQL authentication, configure firewall rules, and manage logins and users.

Exam trap

The trap here is that candidates often assume patching or infrastructure maintenance is shared in PaaS, but Microsoft fully manages the OS and physical layers, while the customer's responsibility is strictly limited to data, access, and application-level security.

How to eliminate wrong answers

Option B is wrong because patching the operating system of the database server is the responsibility of Microsoft, not the customer, as Azure SQL Database is a PaaS service where Microsoft handles OS-level updates and security patches. Option C is wrong because maintaining the physical infrastructure, such as servers, storage, and networking hardware, is entirely managed by Microsoft in the cloud model. Option D is wrong because managing the virtualization layer, including hypervisors and virtual machine orchestration, is also Microsoft's responsibility in a PaaS offering like Azure SQL Database.

164
MCQmedium

A legal team needs to store documents with strict retention policies and eDiscovery capabilities. Which Microsoft 365 workload should they primarily use?

A.Power BI
B.Microsoft Bookings
C.Microsoft Teams
D.SharePoint Online
AnswerD

SharePoint Online provides document libraries governed by retention labels and holds, and its content is indexed for Microsoft Purview eDiscovery searches and cases. This directly satisfies the legal team's strict retention and eDiscovery requirements, unlike Teams or Exchange, which lack equivalent document lifecycle management.

Why this answer

SharePoint Online is the Microsoft 365 workload that provides document libraries, retention labels, retention policies, and native eDiscovery (Content Search, eDiscovery cases, legal hold) capabilities. It is purpose-built for document storage and compliance, making it the correct primary workload for a legal team with strict retention and eDiscovery requirements. Retention policies configured in the Microsoft 365 compliance center apply directly to SharePoint sites and their document libraries.

Exam trap

The trap is that Microsoft Teams also stores files and supports compliance, so candidates pick Teams — but the question asks for the primary workload for document retention and eDiscovery, which is SharePoint Online (Teams files are actually stored in SharePoint behind the scenes).

How to eliminate wrong answers

Option A is wrong because Power BI is a business intelligence and data visualization service — it has no document storage, retention policy, or eDiscovery functionality. Option B is wrong because Microsoft Bookings is an appointment scheduling tool for service-based businesses; it does not store documents or support compliance workflows. Option C is wrong because while Microsoft Teams can host files (backed by SharePoint) and supports some compliance features, it is a collaboration and communication hub, not the primary workload for document retention and eDiscovery — the underlying storage and compliance engine is SharePoint Online.

165
MCQmedium

A mid-sized company, Fabrikam, uses Microsoft 365 Business Premium. The company has 500 users and wants to implement a solution to protect against phishing attacks that target user credentials. The solution must: 1. Automatically detect and block malicious links in emails and Teams messages. 2. Provide real-time protection when users click on links in emails. 3. Allow users to report suspicious emails to the security team. 4. Integrate with Microsoft Entra ID to enforce conditional access policies based on user risk. Which combination of Microsoft 365 services should Fabrikam deploy?

A.Deploy Microsoft Intune and enforce conditional access policies that require compliant devices.
B.Deploy Microsoft Sentinel and configure analytics rules for phishing.
C.Deploy Microsoft Purview Data Loss Prevention and set up an email policy.
D.Deploy Microsoft Defender for Office 365 and enable Microsoft Defender XDR.
AnswerD

Microsoft Defender for Office 365 is the correct choice because it provides comprehensive, pre-delivery and post-delivery protection against phishing through Safe Links (URL detonation and block-time verification), Safe Attachments, and anti-phishing policies that detect impersonation and spoofing. Additionally, enabling Microsoft Defender XDR aggregates signals from Defender for Office 365, Defender for Endpoint, and Defender for Identity, enabling automated investigation and response across the entire kill chain. This also integrates with Microsoft Entra ID to inform conditional access and identity risk policies, closing the loop between email threat detection and access control.

Why this answer

Microsoft Defender for Office 365 (formerly Office 365 ATP) provides Safe Links and Safe Attachments to automatically detect and block malicious links in email and Teams messages, and offers real-time protection when users click links. Microsoft Defender XDR (Extended Detection and Response) correlates signals across Defender for Office 365, Defender for Endpoint, and Microsoft Entra ID to enforce conditional access policies based on user risk, fulfilling all four requirements.

Exam trap

The trap here is that candidates often confuse Microsoft Purview (compliance/DLP) with email security, or think Intune's compliance policies can replace dedicated phishing protection, but only Defender for Office 365 provides the required link scanning and click-time protection for email and Teams.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune focuses on device management and compliance, not on detecting phishing links in emails or Teams messages, and it cannot automatically block malicious links in those channels. Option B is wrong because Microsoft Sentinel is a SIEM/SOAR tool for aggregating and analyzing security logs, not a real-time email/Teams phishing protection service; it lacks built-in Safe Links or click-time protection. Option C is wrong because Microsoft Purview Data Loss Prevention (DLP) is designed to prevent accidental or unauthorized sharing of sensitive data, not to detect or block phishing links in emails or Teams messages.

166
MCQeasy

A small company with 15 employees needs business-grade email, desktop versions of Office apps (Word, Excel, PowerPoint), and 1 TB of cloud storage per user. They do not need advanced security or compliance features. Which Microsoft 365 plan is the most cost-effective choice?

A.Microsoft 365 Business Basic
B.Microsoft 365 Business Standard
C.Microsoft 365 Business Premium
D.Microsoft 365 E3
AnswerB

Microsoft 365 Business Standard is the correct choice because it bundles the complete set of desktop Office applications (Word, Excel, PowerPoint, Outlook, Publisher, and Access on PC) with Exchange Online, Teams, SharePoint, and OneDrive with 1 TB of cloud storage per user. This plan directly satisfies the requirement for business-grade email, cloud storage, and full-featured desktop Office productivity for a 15-person company at a predictable per-user monthly cost.

Why this answer

Microsoft 365 Business Standard is the most cost-effective choice because it includes business-grade email (Exchange Online), desktop versions of Office apps (Word, Excel, PowerPoint), and 1 TB of cloud storage per user via OneDrive. It meets all stated requirements without the added cost of advanced security or compliance features found in higher-tier plans.

Exam trap

The trap here is that candidates often confuse 'Business Basic' with 'Business Standard,' assuming Basic includes desktop apps, when in fact Basic only offers web and mobile versions, not the full locally installed Office suite.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Basic provides only web and mobile versions of Office apps, not the desktop versions required by the question. Option C is wrong because Microsoft 365 Business Premium includes advanced security and compliance features (e.g., Microsoft Defender for Office 365, Azure Information Protection) that the company does not need, making it more expensive than necessary. Option D is wrong because Microsoft 365 E3 is an enterprise plan designed for larger organizations with advanced compliance, security, and analytics capabilities, and it costs significantly more than Business Standard without providing additional value for a 15-employee company.

167
MCQeasy

A small business wants to use email and collaboration software without maintaining servers, databases, or application updates. Which cloud service model best describes Microsoft 365?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.On-premises hosting
AnswerC

Software as a Service (SaaS) delivers fully functional, cloud-hosted applications on a subscription basis, with all underlying infrastructure, security updates, and patching handled by the provider. In Microsoft 365, Microsoft operates and maintains Exchange Online, SharePoint, and Teams, giving users complete email and collaboration tools without requiring any server management. This directly matches the user's stated requirement.

Why this answer

Microsoft 365 is a cloud-based suite that provides email (Exchange Online) and collaboration tools (Teams, SharePoint) as ready-to-use applications. This aligns with the SaaS model, where the provider manages the underlying infrastructure, platform, and software updates, allowing the customer to simply use the software without server maintenance.

Exam trap

The trap here is that candidates often confuse PaaS with SaaS because both are 'platforms' in a broad sense, but PaaS is for developers building apps (e.g., Azure App Service), while SaaS delivers finished applications like Microsoft 365.

How to eliminate wrong answers

Option A is wrong because IaaS provides virtualized computing resources (VMs, storage, networking) where the customer must still manage the OS, applications, and updates, which contradicts the 'without maintaining servers' requirement. Option B is wrong because PaaS offers a development platform (runtime, database, middleware) for building custom applications, not ready-to-use email and collaboration software like Microsoft 365. Option D is wrong because on-premises hosting requires the customer to own and maintain all hardware, software, and updates locally, which is the opposite of the cloud-based, no-maintenance model described.

168
MCQhard

An organization decides to implement Microsoft 365 Business Premium. The security team wants to ensure that all devices accessing company data are compliant with security policies. Which service should they use?

A.Microsoft Defender for Office 365
B.Microsoft Entra ID
C.Microsoft Intune
D.Microsoft Purview
AnswerC

Microsoft Intune enforces compliance policies, configuration profiles and conditional access on enrolled devices, so only devices meeting security baselines reach company data. It directly satisfies the stem's requirement that all devices accessing organisational data comply with security policies.

Why this answer

Microsoft Intune is the mobile device management (MDM) and mobile application management (MAM) service within Microsoft 365 that enforces compliance policies on devices accessing corporate data. It allows administrators to define security requirements such as PIN, encryption, OS version, and jailbreak/root detection, and then conditionally grant access only to compliant devices. Intune integrates with Microsoft Entra ID to evaluate device compliance during authentication, ensuring that only devices meeting security policies can access company resources.

Exam trap

MS-900 often tests the confusion between identity management (Entra ID) and device management (Intune), leading candidates to choose Entra ID for device compliance when Intune is the actual enforcement tool.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Office 365 protects against threats in email, collaboration tools, and Office apps (e.g., phishing, malware) but does not manage device compliance. Option B is wrong because Microsoft Entra ID provides identity and access management, including conditional access, but it relies on Intune (or another MDM) to define and report device compliance; it does not itself enforce device security policies. Option D is wrong because Microsoft Purview focuses on data governance, compliance, and risk management (e.g., data classification, DLP), not on device compliance enforcement.

169
MCQmedium

A business stakeholder asks how Microsoft 365 can help them check feature availability by plan, region, or rollout status. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Official Microsoft service descriptions and licensing documentation
C.Microsoft Stream
D.Microsoft Forms
AnswerB

Official Microsoft service descriptions and licensing documentation list feature availability per plan, region and rollout status, giving the stakeholder an authoritative reference. This directly satisfies the need to check feature availability by plan, region or rollout status.

Why this answer

The stakeholder's question is about checking feature availability by plan, region, or rollout status, which is a licensing and documentation concern. Official Microsoft service descriptions and licensing documentation (such as the Microsoft 365 Licensing Datasheets and Service Descriptions on the Microsoft 365 admin center) provide the authoritative, up-to-date matrix of which features are available in which plans, supported regions, and current rollout phases. This is the correct resource for such inquiries, as it is maintained by Microsoft and directly addresses licensing and support concepts.

Exam trap

The trap here is that candidates may confuse a specific application (like Whiteboard, Stream, or Forms) with a licensing or documentation resource, because the question mentions 'feature availability' and they might think these apps have built-in feature checkers, but only the official service descriptions and licensing documentation provide the authoritative, plan- and region-specific data.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a collaboration application, not a resource for checking feature availability by plan, region, or rollout status; it has no licensing or documentation role. Option C is wrong because Microsoft Stream is a video service for enterprise content, not a source for licensing or feature availability documentation; it does not provide plan or region matrices. Option D is wrong because Microsoft Forms is a survey and quiz tool, not a licensing or support documentation resource; it cannot be used to check feature availability by plan or region.

170
MCQmedium

A company uses Microsoft 365 E5. The security team wants to automatically investigate and remediate advanced threats across email, endpoints, and identities. Which Microsoft 365 Defender workload should they enable?

A.Microsoft Defender for Identity
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Office 365
D.Microsoft Defender XDR
AnswerD

Microsoft Defender XDR is the correct solution because it is a unified, cross-domain security platform that aggregates and correlates alerts across identities, endpoints, email, collaboration, and cloud apps. Through the Microsoft 365 Defender portal, security teams can investigate a single incident timeline, automatically respond with AI-driven remediation, and leverage shared threat intelligence across all domains.

Why this answer

Microsoft Defender XDR (option D) is the correct answer because it is the unified, cross-domain security solution that correlates signals across email, endpoints, identities, and cloud apps to automatically investigate and remediate advanced threats. Unlike the individual Defender workloads, Defender XDR provides integrated incident response and automated actions across all these domains, which directly matches the requirement for automatic investigation and remediation across email, endpoints, and identities.

Exam trap

The trap here is that candidates often confuse the individual Defender workloads (Identity, Endpoint, Office 365) with the integrated cross-domain solution (Defender XDR), mistakenly thinking one of the single-domain tools can automatically investigate and remediate across all three domains simultaneously.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Identity focuses solely on on-premises Active Directory and hybrid identity threats using behavioral analytics and alerts, but it does not cover email or endpoint investigation and remediation. Option B is wrong because Microsoft Defender for Endpoint is limited to endpoint devices (Windows, macOS, Linux, Android, iOS) and does not include email or identity threat investigation and remediation. Option C is wrong because Microsoft Defender for Office 365 protects only email and collaboration workloads (Exchange Online, SharePoint, Teams) and does not extend to endpoint or identity threat investigation and remediation.

171
MCQeasy

A department asks for the Microsoft 365 service best suited for enterprise video publishing and town hall recordings. Which service should they use?

A.Microsoft Purview Compliance Manager
B.Microsoft Stream on SharePoint
C.Microsoft Entra Privileged Identity Management
D.Microsoft Defender for Endpoint
AnswerB

Microsoft Stream on SharePoint delivers enterprise video publishing, town hall recordings, transcripts and channel organisation within Microsoft 365. This satisfies the department's requirement for a service purpose-built for enterprise video publishing and town hall recordings.

Why this answer

Microsoft Stream on SharePoint is the correct service because it is designed for enterprise video publishing, including town hall recordings, live events, and on-demand video. It leverages SharePoint's storage and permissions model, allowing videos to be stored as files in document libraries with metadata, retention policies, and granular access controls, making it ideal for internal communications.

Exam trap

The trap here is that candidates may confuse Microsoft Stream (classic) with Stream on SharePoint, or think that Microsoft Purview Compliance Manager or Defender for Endpoint could handle video content due to their broad names, but the question specifically requires a service for enterprise video publishing and town hall recordings.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is a compliance management solution that provides risk assessments and controls for regulatory standards (e.g., GDPR, ISO 27001), not a video publishing or recording service. Option C is wrong because Microsoft Entra Privileged Identity Management is an identity governance tool for managing, monitoring, and auditing privileged roles and just-in-time access, not for video content. Option D is wrong because Microsoft Defender for Endpoint is a security solution for endpoint detection and response (EDR), antivirus, and threat hunting, not for video publishing or town hall recordings.

172
MCQhard

A multinational company needs to ensure that its Microsoft 365 tenant meets regional data residency requirements by storing data only in specific geographic locations. Which Microsoft 365 feature should they use?

A.Microsoft Purview Data Lifecycle Management
B.Microsoft Intune
C.Microsoft Entra ID Conditional Access
D.Multi-Geo Capabilities
AnswerD

Multi-Geo Capabilities is a Microsoft 365 feature that enables organizations to provision and store data for specific users and workloads, such as Exchange Online, OneDrive for Business, and SharePoint Online, in designated satellite regions. This directly addresses data residency requirements by ensuring that data at rest resides in approved geographic locations, independent of the default tenant location, making it the correct solution for the company's needs.

Why this answer

Multi-Geo Capabilities in Microsoft 365 allow organizations to provision and store data at rest in specific geographic locations (geo regions) to meet data residency requirements. This feature enables a single tenant to span multiple countries/regions, with user data (Exchange Online, SharePoint, OneDrive, Teams) stored in the chosen geo location, ensuring compliance with regional regulations.

Exam trap

The trap here is that candidates often confuse data residency (where data is stored) with data access control (Conditional Access) or data lifecycle management, leading them to pick a security or governance feature instead of the dedicated geo-location feature.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Data Lifecycle Management is a solution for governing data retention, deletion, and classification, not for controlling the geographic storage location of data. Option B is wrong because Microsoft Intune is a cloud-based endpoint management and mobile device management (MDM) service, not a tool for defining data residency or geo-location storage. Option C is wrong because Microsoft Entra ID Conditional Access is an identity-driven policy engine that controls access based on conditions like location, device, or risk, but it does not determine where data is stored at rest.

173
MCQmedium

A service owner is comparing Microsoft 365 capabilities and needs to understand which security tasks Microsoft handles and which remain with the customer. Cloud concept or benefit best matches this requirement?

A.Microsoft Planner
B.Data Loss Prevention (DLP)
C.Sensitivity labels
D.Shared responsibility model
AnswerD

The shared responsibility model defines which security tasks Microsoft handles, such as physical datacentre and host infrastructure, and which remain with the customer, such as data, identities and access. This directly answers the service owner's comparison requirement.

Why this answer

The shared responsibility model defines which security tasks are handled by Microsoft (e.g., physical security, hypervisor patching) and which remain with the customer (e.g., user access management, data classification). This directly matches the service owner's need to understand the division of security responsibilities in Microsoft 365.

Exam trap

The trap here is that candidates may confuse specific security features (like DLP or sensitivity labels) with the overarching responsibility framework, failing to recognize that the shared responsibility model is the foundational concept that explains the division of security tasks.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management and collaboration tool, not a security concept that defines responsibility boundaries. Option B is wrong because Data Loss Prevention (DLP) is a specific security feature that helps prevent data leaks, but it does not describe the overarching model of shared security responsibilities. Option C is wrong because sensitivity labels are used to classify and protect data based on policies, but they are a tool within the customer's responsibilities, not the model that explains which tasks Microsoft handles versus the customer.

174
MCQeasy

A sales manager wants to streamline the process of generating follow-up emails after customer meetings. Which Microsoft 365 app allows them to automatically create email drafts based on meeting notes using AI?

A.SharePoint Online
B.Copilot in Outlook
C.Microsoft Viva Insights
D.Microsoft Teams Premium
AnswerB

Copilot in Outlook is the correct choice because it uses AI grounded in the Microsoft Graph to turn meeting notes, conversation context, and previous threads into a polished email draft. A user can simply say "draft an email to the attendees summarizing these meeting notes" and set tone or length, and Copilot generates the message in the Outlook compose window. This is the only listed option whose purpose is directly to streamline the process of generating email correspondence.

Why this answer

Copilot in Outlook leverages AI to automatically generate email drafts based on meeting notes, transcripts, or summaries, directly within the Outlook interface. This allows the sales manager to streamline follow-up emails without manual composition, using natural language processing to extract key points and action items from the meeting context.

Exam trap

The trap here is that candidates may confuse Microsoft Teams Premium's intelligent recap feature (which summarizes meetings) with the AI email drafting capability, but Teams Premium does not generate email drafts; that is a distinct function of Copilot in Outlook.

How to eliminate wrong answers

Option A is wrong because SharePoint Online is a document management and collaboration platform, not an AI-powered email drafting tool; it lacks the integrated AI capabilities to generate email drafts from meeting notes. Option C is wrong because Microsoft Viva Insights focuses on personal productivity analytics, wellbeing, and meeting effectiveness insights, not on generating email content or drafts. Option D is wrong because Microsoft Teams Premium provides enhanced meeting features like intelligent recap, custom backgrounds, and advanced security, but it does not include AI-driven email draft generation; that capability is specific to Copilot in Outlook.

175
MCQhard

An organization with 50,000 users is planning to deploy Microsoft 365 E5. They want to use Microsoft Entra ID P2 features for identity protection and access reviews. However, they notice that Entra ID P2 is included in E5 but not in E3. They also need to ensure compliance with regulatory requirements for data residency. Which additional licensing or configuration is required?

A.Purchase Microsoft Purview Information Protection add-on
B.Enable data residency by configuring Azure Information Protection policies
C.Purchase Microsoft Entra ID P2 licenses separately for all users
D.Add Microsoft 365 Multi-Geo licenses for users who need data residency in other regions
AnswerD

Adding Microsoft 365 Multi-Geo licenses for users who need data residency in other regions is the correct action because Multi-Geo is the Microsoft 365 add-on specifically designed to let an organization extend its data sovereignty. With Multi-Geo, administrators can configure satellite regions and assign specific user mailboxes, OneDrive sites, and SharePoint sites to those regions, causing the data to be stored at rest in the chosen geographic location. This satisfies residency requirements for users whose data must remain in other regions, while the tenant's home location continues to host central metadata and other services.

Why this answer

Microsoft 365 Multi-Geo is the feature that allows an organization to store data at rest in specific geographic locations to meet data residency requirements. Since the organization has 50,000 users and needs data residency in other regions, they must add Multi-Geo licenses for those users. Entra ID P2 is already included in E5, so no separate purchase is needed.

Configuring Azure Information Protection policies does not address data residency.

Exam trap

MS-900 often tests the misconception that E5 includes everything; candidates may forget that Multi-Geo requires additional licenses even in E5.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Protection add-on is for data classification and protection, not data residency. Option B is wrong because Azure Information Protection policies do not control where data is stored; they control encryption and labeling. Option C is wrong because Entra ID P2 is already included in Microsoft 365 E5, so purchasing it separately is unnecessary and does not address data residency.

176
MCQmedium

A marketing team wants to create a centralized repository for brand assets, such as logos and templates, that can be accessed by all employees. Which Microsoft 365 service should they use?

A.SharePoint Online
B.Microsoft Stream
C.OneDrive for Business
D.Microsoft Lists
AnswerA

SharePoint Online is the correct choice because it provides team sites with document libraries designed for centralized file storage and collaboration. The default 'Documents' library in a SharePoint team site supports versioning, co-authoring, metadata, and permission-based access, making it an ideal repository for marketing assets. Unlike personal or video-specific tools, SharePoint is purpose-built for organizational content management and team-wide sharing.

Why this answer

SharePoint Online is the correct choice because it is designed as a cloud-based document management and storage platform that supports centralized repositories with granular permission controls. It allows the marketing team to create a dedicated site or document library for brand assets, enabling all employees to access, share, and collaborate on logos and templates while maintaining version history and compliance policies.

Exam trap

The trap here is that candidates often confuse OneDrive for Business with SharePoint Online, assuming OneDrive can serve as a team repository, but OneDrive is designed for personal storage and lacks the centralized management, site hierarchy, and enterprise-level sharing controls that SharePoint provides.

How to eliminate wrong answers

Option B (Microsoft Stream) is wrong because it is a video management service for storing, streaming, and sharing recorded content, not a repository for static brand assets like logos and templates. Option C (OneDrive for Business) is wrong because it is a personal cloud storage solution intended for individual file storage and sharing, lacking the centralized, team-wide access controls and site structure needed for a company-wide brand asset repository. Option D (Microsoft Lists) is wrong because it is a data-tracking application for creating lists of items (e.g., issues, contacts) with metadata and views, not a file storage system for binary assets like images and documents.

177
MCQmedium

A help desk lead is documenting the correct Microsoft 365 approach to improve employee experience through learning, insights, goals, and engagement experiences. Microsoft 365 app or service is the best fit?

A.Microsoft Viva
B.Microsoft Forms
C.Microsoft Planner
D.Microsoft Purview Audit
AnswerA

Microsoft Viva bundles the employee experience modules — Learning, Insights, Goals and Engage — directly inside Microsoft 365 and Teams, matching the stem's requirement for learning, insights, goals and engagement in one platform rather than separate standalone services.

Why this answer

Microsoft Viva is the correct answer because it is an integrated employee experience platform (EXP) within Microsoft 365 that explicitly combines learning (Viva Learning), insights (Viva Insights), goals (Viva Goals), and engagement (Viva Engage). This directly matches the help desk lead's requirement to improve employee experience through those four pillars, whereas the other options are single-purpose tools that do not cover the full scope.

Exam trap

The trap here is that candidates may confuse Microsoft Viva with a single-feature app like Planner or Forms, failing to recognize that Viva is the only option designed as a comprehensive employee experience platform covering all four specified areas.

How to eliminate wrong answers

Option B (Microsoft Forms) is wrong because it is a survey and data collection tool, not a platform for learning, insights, goals, or engagement experiences. Option C (Microsoft Planner) is wrong because it is a lightweight project management and task assignment tool, lacking any capabilities for learning analytics, goal tracking, or employee engagement. Option D (Microsoft Purview Audit) is wrong because it is a compliance and auditing solution for tracking user and admin activities, unrelated to improving employee experience through learning, insights, goals, or engagement.

178
Multi-Selecthard

An organization with 5,000 users has Microsoft 365 E3 licenses. They want to add Microsoft Defender for Office 365 (Plan 1) and Microsoft Purview Data Loss Prevention (DLP). Which THREE actions can achieve this?

Select 3 answers
A.Purchase Microsoft Purview DLP as an add-on
B.Upgrade all users to Microsoft 365 E5
C.Downgrade to Microsoft 365 E1 and add the features
D.Purchase Microsoft Defender for Office 365 (Plan 1) as an add-on
E.Switch to Microsoft 365 Business Premium
AnswersA, B, D

Purchasing Microsoft Purview DLP as an add-on is the correct, cost-effective way to add the required data loss prevention capability to your existing Microsoft 365 E3 deployment. E3 natively includes many compliance features, but advanced DLP policies, endpoint DLP, and related capabilities require this add-on license. By licensing only the DLP add-on for your 5,000 users, you avoid the per-user cost of upgrading to E5 while still meeting the compliance requirement. This approach is valid because Microsoft specifically makes Purview DLP available as an add-on to E3.

Why this answer

Microsoft 365 E3 licenses include Exchange Online Protection but not Defender for Office 365 (Plan 1) or Purview DLP. Both features can be added as standalone add-on subscriptions (Options A and D). Alternatively, upgrading all users to Microsoft 365 E5 bundles both features natively, making Option B correct.

This approach avoids per-user add-on costs and simplifies license management.

Exam trap

The trap here is that candidates often assume Microsoft 365 E1 or Business Premium can be scaled to 5,000 users, but E1 lacks the required features and Business Premium has a strict 300-user limit, making both invalid for this scenario.

179
MCQmedium

A help desk lead is documenting the correct Microsoft 365 approach to keep a workload on-premises while using Microsoft cloud collaboration services. Cloud concept or benefit best matches this requirement?

A.Hybrid cloud
B.Sensitivity labels
C.Microsoft Planner
D.Data Loss Prevention (DLP)
AnswerA

Hybrid cloud directly satisfies the requirement to keep a workload on-premises while extending into Microsoft cloud collaboration services. It combines on-premises infrastructure with public cloud resources such as Microsoft 365, enabling data residency where mandated while still using cloud collaboration. This differs from public or private cloud, which host entirely in one environment.

Why this answer

A hybrid cloud model is the correct approach because it allows an organization to keep a specific workload on-premises while leveraging Microsoft cloud collaboration services (such as Exchange Online, SharePoint Online, or Teams). This is achieved through integration technologies like Azure AD Connect for identity synchronization and Exchange Hybrid Configuration Wizard for mail routing, enabling a seamless coexistence between on-premises and cloud environments.

Exam trap

The trap here is that candidates confuse a specific Microsoft 365 service or feature (like Planner or DLP) with a cloud deployment model, failing to recognize that 'hybrid cloud' is the architectural concept that directly addresses the requirement of keeping a workload on-premises while using cloud services.

How to eliminate wrong answers

Option B (Sensitivity labels) is wrong because sensitivity labels are a Microsoft Information Protection feature used to classify and protect data based on sensitivity, not to architect a hybrid deployment where workloads remain on-premises. Option C (Microsoft Planner) is wrong because Planner is a cloud-based task management tool within Microsoft 365, not a concept or benefit that describes keeping workloads on-premises while using cloud services. Option D (Data Loss Prevention) is wrong because DLP is a security policy mechanism to prevent unauthorized sharing of sensitive data, not a cloud deployment model that supports hybrid scenarios.

180
Multi-Selectmedium

Which THREE of the following are security features included in Microsoft 365 Business Premium? (Choose three.)

Select 3 answers
A.Microsoft Entra ID Plan 1
B.Microsoft Sentinel
C.Microsoft Purview Data Loss Prevention
D.Microsoft Defender for Business
E.Microsoft Defender for Cloud Apps
AnswersA, C, D

Microsoft Entra ID Plan 1 provides identity and access management with features such as single sign-on, multi-factor authentication, conditional access, and self-service password reset. This license is a core component of Microsoft 365 Business Premium and is essential for enforcing identity-driven security policies. It is therefore correctly listed as an included security feature.

Why this answer

Microsoft Entra ID Plan 1 is included in Microsoft 365 Business Premium. It provides identity and access management capabilities such as single sign-on (SSO), multi-factor authentication (MFA), and conditional access policies. These features help secure user identities and control access to cloud resources, which is a core security requirement for business environments.

Exam trap

The trap here is that candidates often assume all Microsoft security products with 'Defender' or 'Security' in the name are bundled in Business Premium, but Microsoft Sentinel and Microsoft Defender for Cloud Apps require higher-tier licenses (E5 or standalone) and are not part of the Business Premium suite.

181
MCQmedium

An enterprise wants to allow employees to access corporate resources (emails, files, intranet) from unmanaged personal devices while ensuring that corporate data cannot be copied to personal apps. Which Microsoft 365 technology should be configured?

A.Microsoft Intune Mobile Device Management (MDM)
B.Microsoft Intune Mobile Application Management (MAM)
C.Microsoft Entra ID Conditional Access
D.Microsoft Baseline Protection
AnswerB

Microsoft Intune MAM allows administrators to apply data protection policies directly to apps such as Outlook, without requiring the user's device to be enrolled. These policies can restrict copy/paste, screen capture, and data saving to personal cloud services, while also enforcing an app-level PIN or managed access to corporate email. This provides a granular separation between corporate and personal data, making it ideal for allowing employees to access corporate resources on their personal devices.

Why this answer

Microsoft Intune Mobile Application Management (MAM) allows administrators to apply data protection policies directly to applications, such as Outlook and SharePoint, without enrolling the device itself. This enables employees to access corporate resources from unmanaged personal devices while preventing data from being copied or transferred to personal apps through features like multi-identity management and app-level PIN policies.

Exam trap

The trap here is that candidates often confuse MDM (device-level management) with MAM (app-level management), assuming that any data protection requires full device enrollment, when MAM provides the exact capability needed for unmanaged devices.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune MDM requires device enrollment, which gives the organization control over the entire device, conflicting with the requirement to keep personal devices unmanaged. Option C is wrong because Microsoft Entra ID Conditional Access controls access based on conditions like device compliance or location but does not provide the granular data-loss prevention controls within apps needed to block copying corporate data to personal apps. Option D is wrong because Microsoft Baseline Protection is not a real Microsoft 365 technology; it is a distractor that does not exist in the Microsoft 365 security portfolio.

182
Multi-Selecthard

Which TWO scenarios are best suited for a hybrid cloud deployment?

Select 2 answers
A.Extending on-premises Active Directory to Microsoft Entra ID
B.Using cloud bursting to handle peak load for an on-premises application
C.Storing archival data that is rarely accessed
D.Hosting a public-facing website with high traffic
E.Running a legacy application that requires physical hardware
AnswersA, B

Extending on-premises Active Directory to Microsoft Entra ID lets identities and authentication span both environments, which is the defining hybrid cloud pattern. This satisfies the scenario by keeping existing directory investment while gaining cloud services.

Why this answer

Option A is correct because extending on-premises Active Directory to Microsoft Entra ID is a classic hybrid cloud identity scenario: it keeps authoritative authentication on-premises while using a cloud identity provider (via Microsoft Entra Connect / password hash sync or federation) for cloud services, which inherently spans both environments. Option B is correct because cloud bursting is a defining hybrid cloud use case: an on-premises application overflows to public cloud compute during peak demand, requiring integration and orchestration between the private and public tiers. Option C is not specific to hybrid cloud—archival data is typically a public cloud storage or cold-storage (e.g., Azure Archive, S3 Glacier) decision and does not require an on-premises component.

Option D is not inherently hybrid; a high-traffic public website can be hosted entirely in public cloud without any private infrastructure. Option E is not hybrid cloud either—legacy applications requiring physical hardware are generally kept on-premises or in dedicated/private hosting, not deployed across a hybrid model.

Exam trap

The trap is that options C, D, and E are all valid cloud or on-premises scenarios, but the question asks specifically for hybrid scenarios — candidates must identify which options explicitly require both on-premises and cloud components working together, not just any cloud use case.

183
MCQmedium

A user accidentally shared a file containing credit card numbers with a partner organization. You need to prevent similar incidents and detect when such data is shared externally. What should you configure?

A.Azure Information Protection (AIP)
B.Microsoft Purview eDiscovery
C.Microsoft 365 Data Loss Prevention (DLP) policy
D.Information Rights Management (IRM)
AnswerC

Microsoft 365 DLP policies inspect content for sensitive information types such as credit card numbers, then block or warn on external sharing in SharePoint, OneDrive, and Teams. This directly satisfies the stem's requirement to both prevent accidental sharing and detect external disclosure of that data.

Why this answer

Microsoft 365 Data Loss Prevention (DLP) policies are specifically designed to identify sensitive information such as credit card numbers using sensitive information types and to prevent or detect when that data is shared externally. DLP can block sharing, generate alerts, and provide policy tips to users, directly addressing both prevention and detection requirements.

Exam trap

MS-900 often tests the confusion between DLP (content-based prevention/detection) and AIP/IRM (classification and encryption), leading candidates to pick AIP when the requirement is to detect and block sharing.

How to eliminate wrong answers

Option A is wrong because Azure Information Protection (AIP) focuses on classification and encryption of documents, not on detecting or blocking external sharing of sensitive data in real time. Option B is wrong because Microsoft Purview eDiscovery is used for legal discovery and investigation, not for proactive prevention or detection of data sharing incidents. Option D is wrong because Information Rights Management (IRM) applies persistent encryption and access restrictions to files but does not detect or prevent sharing based on content inspection like credit card numbers.

184
Multi-Selectmedium

Which THREE are features of Microsoft Purview Information Protection?

Select 3 answers
A.Auto-labeling for sensitive data
B.Encryption for emails and documents
C.Data loss prevention policies
D.Retention policies
E.Sensitivity labels
AnswersA, B, E

Auto-labelling applies sensitivity labels automatically by detecting sensitive information types or trainable classifiers, without manual user action. This satisfies the stem's feature requirement by scaling classification across Microsoft 365 workloads, applying protection consistently to content as it is created or modified.

Why this answer

Auto-labeling for sensitive data (A) is a core Microsoft Purview Information Protection feature that uses trainable classifiers and sensitive information types to automatically apply sensitivity labels to content at rest or in transit. Encryption for emails and documents (B) is provided through sensitivity labels, which can enforce Azure Rights Management (Azure RMS) encryption so that only authorized users can decrypt protected content. Sensitivity labels (E) are the foundational capability of Information Protection, allowing classification and protection settings (encryption, content marking, and restrictions) to travel with the data.

Data loss prevention policies (C) belong to Microsoft Purview Data Loss Prevention, a separate workload that detects and blocks risky sharing, and retention policies (D) belong to Microsoft Purview Data Lifecycle Management for retaining or deleting content, so neither is a feature of Information Protection itself.

Exam trap

MS-900 often tests the boundary between Purview workloads — candidates see 'data protection' and include DLP or retention policies, which belong to separate Purview modules, instead of sticking to Information Protection's label/encryption/auto-labeling triad.

185
MCQmedium

A non-profit organization with 200 employees needs to equip their staff with Microsoft 365 Business Premium, which includes desktop Office apps, Microsoft Intune, Microsoft Entra ID Premium P1, and Microsoft Defender for Office 365 Plan 1. They are eligible for non-profit pricing. What is the most cost-effective way to obtain these capabilities?

A.Microsoft 365 Business Premium (non-profit pricing)
B.Microsoft 365 Business Basic (non-profit) plus separate add-ons for Intune and Defender for Office 365
C.Microsoft 365 E3 (non-profit pricing)
D.Microsoft 365 Business Standard (non-profit) plus add-ons for Intune and Defender for Office 365
AnswerA

Business Premium bundles the full Office suite (desktop and online apps), Exchange Online, SharePoint, Teams, plus Microsoft Intune, Microsoft Entra ID P1, and Defender for Office 365 Plan 1. For a 200-employee nonprofit, this single subscription addresses all productivity, identity, security, and mobile device management needs without separate add-ons, and nonprofit pricing provides a significant discount. It is the most efficient and cost-effective option compared to assembling components.

Why this answer

Microsoft 365 Business Premium (non-profit pricing) is the most cost-effective option because it bundles all required capabilities—desktop Office apps, Microsoft Intune, Microsoft Entra ID Premium P1, and Microsoft Defender for Office 365 Plan 1—into a single per-user license at a significantly reduced non-profit rate. Purchasing separate add-ons or a higher-tier plan like E3 would incur unnecessary costs without providing additional needed features.

Exam trap

The trap here is that candidates may assume a lower-tier plan like Business Standard or Basic plus add-ons is cheaper, but they overlook that the bundled Business Premium license includes all required services at a discounted non-profit rate, making it the most cost-effective single SKU.

How to eliminate wrong answers

Option B is wrong because Microsoft 365 Business Basic does not include desktop Office apps, and adding Intune and Defender for Office 365 as separate add-ons would cost more than the bundled Business Premium license. Option C is wrong because Microsoft 365 E3 (non-profit pricing) is a more expensive enterprise-grade plan that includes capabilities beyond the organization's needs, such as advanced compliance and eDiscovery features, making it less cost-effective. Option D is wrong because Microsoft 365 Business Standard lacks Intune and Defender for Office 365, and purchasing those as add-ons would exceed the cost of the all-inclusive Business Premium license.

186
MCQeasy

A department head asks which Microsoft 365 option should be used to meter compute and storage usage for consumption-based billing. Cloud concept or benefit best matches this requirement?

A.Sensitivity labels
B.Microsoft Planner
C.Data Loss Prevention (DLP)
D.Measured service
AnswerD

Measured service is a core cloud computing characteristic defined by NIST, meaning the provider automatically meters resource usage (e.g., compute time, storage, bandwidth) at a granular level. Microsoft 365 applies this through tenant-level usage analytics and consumption-based billing for services like Power Platform API calls or additional storage. This lets customers optimize costs by aligning paid licenses with actual user and workload consumption, rather than a fixed performance guarantee.

Why this answer

Measured service is a core cloud computing concept where resource usage (compute, storage, network) is metered and billed based on actual consumption. In Microsoft 365, this aligns with consumption-based billing models like pay-as-you-go for Azure services or per-user licensing adjustments, enabling cost transparency and optimization.

Exam trap

The trap here is that candidates confuse operational tools (like DLP or Planner) with cloud service models, failing to recognize that 'measured service' is a fundamental characteristic of cloud computing defined by NIST SP 800-145, not a specific Microsoft 365 feature.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are used for classification and protection of data (e.g., encryption, marking) and have no role in metering compute or storage usage. Option B is wrong because Microsoft Planner is a task management and collaboration tool for organizing work, not a billing or metering mechanism. Option C is wrong because Data Loss Prevention (DLP) policies prevent unauthorized sharing of sensitive data and do not track or bill for resource consumption.

187
MCQhard

A company has 50 users with Microsoft 365 Business Basic licenses. They require the desktop versions of Office apps (Word, Excel, PowerPoint) for all 50 users. Additionally, 20 of those users need device management capabilities via Microsoft Intune. The company wants to minimize total licensing costs. Which licensing strategy is most cost-effective?

A.Upgrade all 50 users to Microsoft 365 Business Premium.
B.Upgrade all 50 users to Microsoft 365 Business Standard and purchase Microsoft Intune standalone licenses for the 20 users.
C.Upgrade 20 users to Microsoft 365 Business Premium and keep 30 users on Business Basic.
D.Upgrade all 50 users to Microsoft 365 Business Standard and purchase Microsoft Intune standalone licenses for all 50 users.
AnswerB

Microsoft 365 Business Standard includes the full Office desktop applications for every user, satisfying the requirement for all 50. Adding Microsoft Intune Plan 1 as a standalone per-user license lets you assign device-management capability only to the 20 users who need it, rather than paying for it across the entire tenant. This combination is the cheapest configuration that covers both requirements exactly, and it keeps licensing simple because the base SKU is uniform for all users.

Why this answer

Microsoft 365 Business Standard includes the desktop versions of Office apps, fulfilling the requirement for all 50 users. For the 20 users needing device management, purchasing standalone Microsoft Intune licenses is the most cost-effective approach, as it avoids the higher cost of upgrading all users to Business Premium, which includes Intune but also additional security features not required here.

Exam trap

The trap here is that candidates may assume Business Premium is the only way to get Intune, overlooking the option to purchase Intune standalone licenses separately, or they may forget that Business Basic does not include desktop Office apps, leading them to choose an option that fails the core requirement.

How to eliminate wrong answers

Option A is wrong because upgrading all 50 users to Microsoft 365 Business Premium is unnecessarily expensive; it includes Intune and advanced security features for all users, but only 20 users need device management. Option C is wrong because upgrading only 20 users to Business Premium leaves the remaining 30 users on Business Basic, which lacks the desktop versions of Office apps required by all 50 users. Option D is wrong because purchasing Microsoft Intune standalone licenses for all 50 users is wasteful; only 20 users need device management, so buying Intune for the other 30 users incurs unnecessary cost.

188
MCQmedium

Your organization uses Microsoft 365 E5 licenses and wants to implement a data loss prevention (DLP) policy that blocks sharing of credit card numbers in email. Which Microsoft 365 admin center should you use to create and manage this DLP policy?

A.Microsoft Security Center
B.Microsoft Entra admin center
C.Microsoft Purview compliance portal
D.Microsoft 365 admin center
AnswerC

The Microsoft Purview compliance portal is the centralized hub for managing compliance and information-protection solutions, including Data Loss Prevention (DLP). In this portal, you can create and manage DLP policies that identify, monitor, and automatically protect sensitive data across Exchange, SharePoint, OneDrive, Teams, and endpoints. It provides unified policy management, integration with sensitivity labels, and detailed activity reports, making it the correct location for this task.

Why this answer

The Microsoft Purview compliance portal is the correct admin center for creating and managing Data Loss Prevention (DLP) policies because it provides the unified compliance management interface for data protection, including DLP for Exchange Online email. DLP policies that block sharing of sensitive information like credit card numbers are configured under the 'Data loss prevention' section within the Purview portal, which leverages built-in sensitive information types and rules to enforce actions such as blocking email transmission.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 admin center (general admin tasks) with the Purview compliance portal (compliance-specific tasks), leading them to select the wrong portal for DLP policy management.

How to eliminate wrong answers

Option A is wrong because the Microsoft Security Center focuses on threat protection, security posture management, and incident response (e.g., Microsoft Defender for Cloud), not on compliance-based data loss prevention policies for email. Option B is wrong because the Microsoft Entra admin center is used for identity and access management (e.g., user accounts, groups, conditional access policies), not for configuring DLP rules that govern data in transit. Option D is wrong because the Microsoft 365 admin center is for general tenant administration (e.g., user licensing, service health, billing) and does not include the compliance-specific tools needed to create or manage DLP policies.

189
MCQeasy

A company wants to use a cloud service where they can develop and run applications without managing the underlying infrastructure, including servers, operating systems, or storage. They only need to upload their code and the provider handles scaling and availability. Which cloud service model best describes this approach?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.On-premises deployment
AnswerB

PaaS provides a fully managed application hosting environment that includes the operating system, language runtime, web server, database, and auto-scaling capabilities. Developers simply deploy their code and the platform handles patching, high availability, and load balancing automatically. This removes the operational heavy lifting and directly matches the need to develop and run custom applications in the cloud, making it the correct answer.

Why this answer

Platform as a Service (PaaS) provides a managed hosting environment where developers can deploy applications without worrying about the underlying infrastructure. The provider automatically handles server provisioning, OS patching, storage management, and scaling based on demand. In this scenario, the company only needs to upload code, which is the defining characteristic of PaaS.

Exam trap

The trap here is that candidates confuse PaaS with IaaS because both involve deploying applications, but IaaS requires manual OS and runtime management, whereas PaaS abstracts all infrastructure away.

How to eliminate wrong answers

Option A is wrong because Infrastructure as a Service (IaaS) still requires the user to manage the operating system, middleware, and runtime; the provider only supplies virtualized hardware like compute, storage, and networking. Option C is wrong because Software as a Service (SaaS) delivers fully functional applications to end users over the internet, not a platform for developing and running custom code. Option D is wrong because on-premises deployment means the company owns and manages all hardware and software locally, which is the opposite of a cloud service where the provider handles infrastructure.

190
MCQeasy

Which cloud computing characteristic allows a company to access resources like storage and databases from any device with an internet connection without needing to manage the physical infrastructure?

A.Rapid elasticity
B.Measured service
C.Broad network access
D.Resource pooling
AnswerC

Broad network access is the cloud characteristic that makes resources available over the network through standard protocols, allowing access from laptops, mobile phones, and other devices with internet connectivity. This ensures that employees can securely connect to corporate applications and data from any location, fulfilling the need described in the question. It is one of the essential NIST-defined characteristics of cloud computing, distinct from scaling or metering.

Why this answer

Broad network access is the correct answer because it describes the ability to access cloud resources (such as storage and databases) over the network via standard protocols (e.g., HTTP/HTTPS, SMB, NFS) from any device (laptop, smartphone, tablet) with an internet connection, without requiring the customer to manage the underlying physical infrastructure. This characteristic is defined by NIST SP 800-145 as 'capabilities are available over the network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms.'

Exam trap

The trap here is that candidates often confuse 'broad network access' with 'resource pooling' because both involve multi-device scenarios, but resource pooling is about the provider's internal multi-tenant architecture, not the customer's ability to connect from any device.

How to eliminate wrong answers

Option A is wrong because rapid elasticity refers to the ability to automatically scale resources up or down quickly in response to demand, not to the network-based accessibility from any device. Option B is wrong because measured service involves metering and monitoring resource usage for billing and optimization (e.g., pay-per-use), not the capability to access resources from any device. Option D is wrong because resource pooling means the provider's computing resources are pooled to serve multiple customers using a multi-tenant model, with physical and virtual resources dynamically assigned and reassigned according to consumer demand; it does not describe device-independent network access.

191
MCQeasy

A company wants to enable employees to securely access work files and collaborate in real-time from any device. Which Microsoft 365 service should the company use?

A.Microsoft Teams
B.Exchange Online
C.SharePoint Online
D.OneDrive for Business
AnswerA

Microsoft Teams is a comprehensive collaboration hub that integrates persistent chat, video meetings, file storage, and real-time co-authoring within a single interface. It uses SharePoint and OneDrive for backend file storage while providing a unified workspace for team communication and project management. With Azure Active Directory integration, it enables secure access to organizational resources, making it the ideal solution for secure work collaboration.

Why this answer

Microsoft Teams is the correct choice because it provides a unified platform for real-time collaboration, including chat, video conferencing, and file sharing, with integrated security and compliance features. It allows employees to access and co-author work files from any device while leveraging Azure Active Directory for conditional access and data encryption in transit and at rest.

Exam trap

The trap here is that candidates often confuse SharePoint Online's document management capabilities with real-time collaboration, overlooking that Teams is the primary service for synchronous teamwork and integrated file access from any device.

How to eliminate wrong answers

Option B (Exchange Online) is wrong because it is primarily an email and calendaring service, not designed for real-time file collaboration or secure file access from any device. Option C (SharePoint Online) is wrong because while it enables file storage and sharing, it lacks native real-time collaboration features like persistent chat and video meetings that Teams provides. Option D (OneDrive for Business) is wrong because it is a personal cloud storage service for individual file sync and sharing, not a team-based collaboration hub with integrated real-time communication.

192
Multi-Selectmedium

Which TWO of the following are features of Microsoft Purview Information Protection?

Select 2 answers
A.Sensitivity labels
B.Data Loss Prevention (DLP) policies
C.Encryption for emails and documents
D.eDiscovery (Premium)
E.Azure Information Protection (AIP) scanner
AnswersA, C

Sensitivity labels are the cornerstone of Microsoft Purview Information Protection. They enable classification and protection by applying policy-driven settings such as encryption, visual markings, and access restrictions to emails and documents. These labels follow the content wherever it travels, and users can apply them manually or through auto-classification rules, ensuring consistent data governance across Microsoft 365 services.

Why this answer

Sensitivity labels are a core feature of Microsoft Purview Information Protection, allowing organizations to classify and protect sensitive data by applying labels that enforce encryption, access restrictions, and visual markings (e.g., headers/footers). These labels can be automatically applied based on content patterns or manually by users, and they persist with the data even when it leaves Microsoft 365, ensuring consistent protection across emails, documents, and other content.

Exam trap

The trap here is that candidates often confuse Data Loss Prevention (DLP) policies as a feature of Information Protection, but DLP is a separate workload that uses sensitivity labels as conditions rather than being a core component of Information Protection itself.

193
MCQmedium

A company with 200 users has Microsoft 365 Business Standard licenses. They need to add Microsoft 365 Defender for Office 365 (Plan 2) for increased protection against advanced threats. What should they purchase?

A.Upgrade each user to Microsoft 365 Business Premium
B.Purchase the Microsoft 365 Defender for Office 365 Plan 2 add-on
C.Purchase Microsoft 365 E3 licenses
D.Install the Microsoft Defender for Endpoint standalone subscription
AnswerB

The Microsoft 365 Defender for Office 365 Plan 2 add-on is the correct choice because it can be licensed per user directly onto an existing Microsoft 365 Business Standard subscription. This add-on supplies advanced email and collaboration protection that goes beyond the baseline Exchange Online Protection controls, including Threat Explorer, advanced hunting, automated investigation and response, and attack simulation training. It is designed for tenants that already have a qualifying base plan but need the higher tier of Defender for Office 365 without switching suites.

Why this answer

Microsoft 365 Business Standard licenses include basic email security but lack advanced threat protection features like automated investigation, threat hunting, and simulation training. Purchasing the Microsoft 365 Defender for Office 365 Plan 2 add-on directly adds these capabilities to existing Business Standard users without requiring a license upgrade, making it the most cost-effective and targeted solution.

Exam trap

The trap here is that candidates often confuse the licensing tiers and assume that upgrading to Business Premium is the only way to get advanced security, when in fact Microsoft offers targeted add-ons like Defender for Office 365 Plan 2 that can be layered onto existing Business Standard subscriptions without a full suite upgrade.

How to eliminate wrong answers

Option A is wrong because upgrading to Microsoft 365 Business Premium would replace the existing Business Standard licenses with a more expensive suite that includes Defender for Office 365 Plan 1 (not Plan 2) plus other features like Intune and Azure AD P1, which are unnecessary for the stated requirement. Option C is wrong because Microsoft 365 E3 licenses are a different licensing plan intended for enterprise customers, not a direct upgrade path from Business Standard, and they would require a full license migration and higher per-user cost without specifically adding Defender for Office 365 Plan 2. Option D is wrong because Microsoft Defender for Endpoint is a separate product focused on endpoint device protection (antivirus, EDR), not email and collaboration security, and does not provide the advanced threat protection for Exchange Online, SharePoint, and Teams that Defender for Office 365 Plan 2 delivers.

194
MCQeasy

Refer to the exhibit. You have a Conditional Access policy as shown. A user reports they cannot access Exchange Online from a non-compliant device. What is the most likely reason?

A.The device is not marked as compliant
B.The policy only applies to administrators
C.The user has not registered for MFA
D.The policy is disabled
AnswerA

The conditional access policy includes the grant control "Require device to be marked as compliant." If the device is not enrolled in Microsoft Intune or does not meet the configured compliance policy, this control is not satisfied, and access is denied. This is the immediate and technical reason the user is blocked, regardless of other grants like MFA.

Why this answer

The Conditional Access policy shown requires device compliance for Exchange Online access. When a device is non-compliant, the policy blocks access regardless of user identity or MFA status. The most likely reason for the user's inability to access Exchange Online is that the device is not marked as compliant, which is the condition explicitly enforced by the policy.

Exam trap

The trap here is that candidates may assume MFA or admin-only scoping is the issue, but the policy explicitly targets device compliance, which is the direct cause of the block.

How to eliminate wrong answers

Option B is wrong because the policy does not specify 'Only apply to administrators' — it applies to all users or a specific user group, not just admins. Option C is wrong because MFA registration is not the blocking factor; the policy targets device compliance, not authentication strength. Option D is wrong because if the policy were disabled, it would not enforce any restrictions, and the user would not be blocked.

195
MCQeasy

A sales manager wants to track customer interactions, manage leads, and automate follow-up emails from a single platform. Which Microsoft 365 service is specifically designed for customer relationship management (CRM)?

A.Microsoft Bookings
B.Microsoft Dynamics 365 Sales
C.Microsoft Power Automate
D.Microsoft To Do
AnswerB

Microsoft Dynamics 365 Sales is a purpose-built CRM application that leverages the Dataverse (Common Data Service) to store leads, contacts, accounts, and opportunities with full relationship hierarchies. It records customer interactions such as emails, calls, meetings, and notes as activities, while sales automation features—including workflows and Power Automate connectors—can trigger follow-up actions automatically. Its dashboards and built-in sales insights give managers the analytics needed to monitor pipeline health, making it the correct choice here.

Why this answer

Microsoft Dynamics 365 Sales is the dedicated CRM service within the Microsoft 365 ecosystem, purpose-built for tracking customer interactions, managing leads, and automating follow-up emails. Unlike general productivity tools, it provides a unified platform with lead scoring, opportunity management, and workflow automation specifically for sales processes.

Exam trap

The trap here is that candidates often confuse Microsoft Bookings (a scheduling tool) or Power Automate (an automation tool) with a full CRM solution, failing to recognize that Dynamics 365 Sales is the only option specifically designed for end-to-end customer relationship management.

How to eliminate wrong answers

Option A is wrong because Microsoft Bookings is a scheduling and appointment management tool, not a CRM platform; it lacks lead management and automated follow-up email capabilities. Option C is wrong because Microsoft Power Automate is a workflow automation service that can integrate with CRM systems but is not itself a CRM platform; it does not provide native lead tracking or customer interaction management. Option D is wrong because Microsoft To Do is a personal task management app with no CRM features such as lead tracking, customer history, or automated email sequences.

196
MCQhard

A compliance officer wants to proactively prevent users from sending emails that contain sensitive personal data (e.g., credit card numbers) to external recipients. When a user attempts to send such an email, they should see a policy tip explaining the restriction and be blocked from sending. Which Microsoft Purview feature should be configured?

A.Microsoft Purview Data Loss Prevention (DLP) policy
B.Microsoft Purview Information Barriers
C.Microsoft Purview Records Management
D.Microsoft Purview Communication Compliance
AnswerA

Microsoft Purview DLP policies use built-in sensitive information types (e.g., credit card numbers) to inspect message body and attachments as they are composed, then apply actions such as blocking the send action and displaying customizable policy tips. This prevents the exfiltration of sensitive data before it leaves the organization, satisfying the compliance officer's proactive prevention requirement.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policy is the correct feature because it is specifically designed to detect sensitive data (e.g., credit card numbers) in transit and enforce actions such as showing a policy tip and blocking the email. DLP policies use sensitive information types (e.g., Credit Card Number) and conditions to inspect email content in Exchange Online, triggering a block action with an end-user notification when a match occurs.

Exam trap

The trap here is that candidates often confuse Communication Compliance (which reviews messages after they are sent) with DLP (which proactively blocks messages in transit), leading them to select Communication Compliance when the question explicitly requires proactive blocking with a policy tip.

How to eliminate wrong answers

Option B (Microsoft Purview Information Barriers) is wrong because Information Barriers are used to prevent communication between specific groups or users (e.g., to avoid conflicts of interest), not to scan for sensitive data patterns like credit card numbers. Option C (Microsoft Purview Records Management) is wrong because Records Management focuses on classifying, retaining, and disposing of records based on regulatory requirements, not on real-time content inspection and blocking of outbound emails. Option D (Microsoft Purview Communication Compliance) is wrong because Communication Compliance is designed to detect policy violations in communications (e.g., harassment, insider trading) by reviewing messages after they are sent, not to proactively block emails based on sensitive data patterns.

197
MCQeasy

A small business with 10 users needs the fully installed desktop versions of Office apps (Word, Excel, PowerPoint), business-class email, and 1 TB of cloud storage per user. They do not require advanced security or compliance features. Which Microsoft 365 plan is the most cost-effective choice?

A.Microsoft 365 Business Basic
B.Microsoft 365 Business Standard
C.Microsoft 365 E3
D.Office 365 E1
AnswerB

Microsoft 365 Business Standard is the correct choice because it bundles the fully installed Microsoft 365 desktop apps (Word, Excel, PowerPoint, Outlook, and others) with Exchange Online email, SharePoint, Teams, and 1 TB of OneDrive storage per user. It is designed for small businesses with up to 300 users, providing all the stated needs at a per-user cost that is lower than enterprise-level plans like E3. This makes it the optimal balance of functionality and price for a 10-user organization.

Why this answer

Microsoft 365 Business Standard is the most cost-effective plan for this small business because it includes the fully installed desktop versions of Office apps (Word, Excel, PowerPoint), business-class email (Exchange Online), and 1 TB of OneDrive cloud storage per user. It meets all stated requirements without the higher cost of E3 or the lack of desktop apps in Business Basic or Office 365 E1.

Exam trap

The trap here is that candidates often confuse 'Business Basic' (which has web-only apps) with 'Business Standard' (which includes desktop apps), or assume that 'E3' is always the best choice for any business due to its enterprise branding, overlooking the cost and feature overkill for small businesses without advanced security needs.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Business Basic provides only web and mobile versions of Office apps, not the fully installed desktop versions required. Option C is wrong because Microsoft 365 E3 includes advanced security and compliance features (e.g., Data Loss Prevention, eDiscovery) that the customer does not need, making it unnecessarily expensive for a 10-user business. Option D is wrong because Office 365 E1 lacks the desktop Office apps entirely, offering only web-based versions, and also includes advanced compliance features not required.

198
MCQmedium

A company with 120 users needs desktop Office apps, Intune device management, and enhanced security. Which option best matches the requirement?

A.Microsoft Defender for Cloud only
B.Azure Virtual Desktop only
C.A free personal Microsoft account only
D.Microsoft 365 Business Premium
AnswerD

Microsoft 365 Business Premium bundles desktop Office apps, Intune device management and Defender for Business security for up to 300 users, so 120 users qualify. It uniquely satisfies all three stated requirements in one licence.

Why this answer

Microsoft 365 Business Premium includes desktop Office apps (Office 365 E3 equivalent), Intune for device management, and advanced security features such as Microsoft Defender for Office 365, Azure Information Protection, and Conditional Access. This bundle directly satisfies all three requirements for a 120-user organization without needing separate subscriptions.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a security monitoring tool for cloud infrastructure) with Microsoft Defender for Office 365 (an email and collaboration security service), leading them to incorrectly select Option A when they see 'enhanced security' without recognizing the missing Office apps and device management.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud is a cloud workload protection platform (CWPP) for securing Azure, on-premises, and multi-cloud resources; it does not include desktop Office apps or Intune device management. Option B is wrong because Azure Virtual Desktop provides virtualized Windows desktops and apps, but it does not include Intune device management or the specific enhanced security features like Defender for Office 365; it also requires separate licensing for Office apps. Option C is wrong because a free personal Microsoft account offers no enterprise-grade desktop Office apps, no Intune device management, and no enhanced security controls; it is intended for individual consumer use only.

199
MCQmedium

A company uses Microsoft 365 E3. Employees need to co-author Word, Excel, and PowerPoint documents stored in SharePoint Online while working simultaneously. Which Microsoft 365 capability enables this real-time collaboration?

A.Microsoft 365 Groups membership
B.Microsoft SharePoint version history
C.Microsoft Exchange Online shared mailboxes
D.Microsoft Office co-authoring
AnswerD

Office co-authoring allows multiple users to edit the same Word, Excel, or PowerPoint file stored in SharePoint Online or OneDrive for Business at the same time, with changes merged automatically. It provides presence indicators and live cursors, directly enabling the simultaneous collaboration the employees require while keeping a single authoritative version of the document.

Why this answer

Office co-authoring is the native capability that lets several people edit the same Word, Excel, or PowerPoint document stored in SharePoint Online or OneDrive at the same time, merging changes automatically and showing who is working where. Shared mailboxes, version history, and group membership support communication, recovery, and access control respectively, but none of them enable real-time simultaneous editing.

Exam trap

The trap here is confusing access control or document recovery features with real-time editing, and selecting version history or group membership thinking that sharing a file is the same as co-authoring it.

200
MCQmedium

A company with 300 Microsoft 365 E3 users needs to add advanced identity protection features: Microsoft Entra ID Premium P2 and Microsoft Defender for Identity. They want to add these capabilities without upgrading all users to E5. What is the most cost-effective licensing strategy?

A.Upgrade all users to Microsoft 365 E5.
B.Add Microsoft Entra ID Premium P2 and Microsoft Defender for Identity as standalone add-ons.
C.Add the Microsoft 365 E5 Security add-on for each user.
D.Add Enterprise Mobility + Security E5 add-on.
AnswerC

The Microsoft 365 E5 Security add-on is the correct choice because it attaches the necessary proprietary workloads to E3 without a full E5 upgrade. This per-user add-on bundles Microsoft Entra ID Premium P2, Microsoft Defender for Identity, Defender for Office 365, Defender for Endpoint, and other advanced security tools explicitly designed to close the security gap. It provides the advanced protection the company requires while remaining more economical than upgrading to E5 or assembling separate add-ons.

Why this answer

The Microsoft 365 E5 Security add-on bundles Microsoft Entra ID Premium P2 and Microsoft Defender for Identity (along with other security features) at a lower per-user cost than purchasing them separately, and it can be added to an existing E3 subscription without upgrading the entire license. This provides the required identity protection capabilities cost-effectively for all 300 users.

Exam trap

The trap here is that candidates often confuse the Enterprise Mobility + Security E5 add-on with the E5 Security add-on, not realizing that EMS E5 lacks Microsoft Defender for Identity and is therefore insufficient for the stated requirements.

How to eliminate wrong answers

Option A is wrong because upgrading all users to Microsoft 365 E5 would be significantly more expensive than adding the E5 Security add-on, as E5 includes many additional features (e.g., advanced compliance, analytics) not required by the company. Option B is wrong because purchasing Microsoft Entra ID Premium P2 and Microsoft Defender for Identity as standalone add-ons would cost more per user than the bundled E5 Security add-on, which includes both plus additional security services like Microsoft Purview Information Protection and Microsoft 365 Defender. Option D is wrong because Enterprise Mobility + Security E5 includes Microsoft Entra ID Premium P2 and Microsoft Intune but does not include Microsoft Defender for Identity; it would require an additional purchase for that capability, making it less cost-effective than the E5 Security add-on.

201
MCQmedium

An administrator is reviewing a request from users who need to allocate Microsoft 365 license costs by department. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Forms
B.User department attributes and license assignment records
C.Microsoft Stream
D.Microsoft Whiteboard
AnswerB

User department attributes and license assignment records are the authoritative data sources for departmental cost allocation. In Microsoft 365, user accounts in Microsoft Entra ID (Azure AD) contain a 'Department' attribute, and license assignment records in the Microsoft 365 admin center or Entra ID licensing show which products are assigned to each user. Combining these two data streams allows finance teams to calculate licensing costs per department via PowerShell or cost-management tools, making it the only viable option.

Why this answer

User department attributes (e.g., the 'Department' field in Microsoft Entra ID) combined with license assignment records allow administrators to filter and report on license consumption by department. This is the standard method for cost allocation, as Microsoft 365 does not natively track license costs per department without custom reporting or PowerShell scripts that query the Get-AzureADUser and Get-MsolUser cmdlets.

Exam trap

The trap here is that candidates may confuse collaboration tools (Forms, Stream, Whiteboard) with administrative reporting features, assuming they have built-in cost allocation capabilities when they do not.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and quiz tool, not a licensing or cost allocation feature; it has no capability to track or report license costs by department. Option C is wrong because Microsoft Stream is a video hosting and sharing service, unrelated to license cost allocation or department-based reporting. Option D is wrong because Microsoft Whiteboard is a digital canvas for collaboration, with no functionality for managing or attributing license costs to departments.

202
MCQmedium

A company is preparing for a merger and wants to prevent communication between the Human Resources and Research departments regarding sensitive salary data during the due diligence period. They need a Microsoft Purview solution that can block all email and chat between users in these two groups, as well as prevent file sharing in Teams and SharePoint. Which solution should they configure?

A.Information Barriers
B.Data Loss Prevention (DLP)
C.Sensitivity Labels
D.eDiscovery (Premium)
AnswerA

Information Barriers in Microsoft Purview are purpose-built to restrict real-time and async collaboration between defined user segments. Admins define segments based on attributes like department or organization and create policy rules that block one-way or two-way communication; the policy is enforced by the service layer itself across Exchange Online, Microsoft Teams, and file-sharing workflows. This goes far beyond individual content protection—it prohibits the relationship itself, so an attempted email or Teams chat between barred users is rejected before the message is delivered.

Why this answer

Information Barriers (IB) in Microsoft Purview are specifically designed to prevent communication and collaboration between defined user groups, such as HR and Research, by blocking email, Teams chat, and SharePoint/OneDrive file sharing. This solution enforces policies at the transport and service level, ensuring that sensitive salary data is not inadvertently shared during the merger due diligence period.

Exam trap

The trap here is that candidates often confuse Information Barriers with DLP, assuming that blocking sensitive data patterns is equivalent to blocking all communication between groups, but DLP cannot enforce department-wide communication restrictions—it only acts on content matches.

How to eliminate wrong answers

Option B (Data Loss Prevention) is wrong because DLP policies monitor and prevent the sharing of sensitive data (e.g., credit card numbers) based on content inspection, but they do not block all communication between two entire departments—they only act on specific data patterns. Option C (Sensitivity Labels) is wrong because labels classify and protect data with encryption or visual markings, but they do not enforce communication blocks between groups; they require users to apply them and do not prevent chat or email between departments. Option D (eDiscovery Premium) is wrong because eDiscovery is used for searching, preserving, and exporting content for legal or investigative purposes, not for proactively blocking real-time communication or file sharing.

203
MCQmedium

A user reports that they cannot access their work email on their mobile device. The admin confirms the user has an Exchange Online license. What is the most likely cause?

A.The user is using the Outlook mobile app
B.The user is trying to access Outlook on the web
C.Exchange ActiveSync is disabled for the user
D.A Conditional Access policy requires app protection policies
AnswerD

A Conditional Access policy that requires an app protection policy (Intune MAM) is the likely cause because it blocks access to Exchange Online until the Outlook app has received the required policy from Intune. If the user's device does not have the Company Portal or the policy hasn't been applied, Outlook will indicate that the organization requires app protection and deny sign-in. This is a common conditional access control for personal devices to prevent data leakage without full device enrollment.

Why this answer

Conditional Access policies can require app protection policies (e.g., Intune MAM) to enforce data security on mobile devices. If the user's device does not have the required app protection policies applied, access to Exchange Online via mobile apps (including Outlook) will be blocked, even though the user has a valid Exchange Online license. This is a common scenario where licensing alone does not guarantee access when additional security controls are in place.

Exam trap

The trap here is that candidates often assume a valid license (Exchange Online) guarantees access, but Microsoft 365 security features like Conditional Access can override licensing and block access based on policy requirements, especially on mobile devices.

How to eliminate wrong answers

Option A is wrong because using the Outlook mobile app is not a cause of access failure; it is the intended client for mobile email access. Option B is wrong because accessing Outlook on the web (OWA) is a browser-based method, not a mobile device issue, and the question specifically states the user is on a mobile device. Option C is wrong because if Exchange ActiveSync were disabled for the user, the admin would typically see a specific error or setting in the Exchange admin center, and this is less likely than a Conditional Access policy blocking access due to missing app protection policies.

204
MCQeasy

A sales team uses Microsoft Copilot for Sales to draft emails. To ensure Copilot uses the most relevant customer data from Dynamics 365, what must be configured?

A.Microsoft Teams channels
B.Dynamics 365 records
C.Exchange Online mailboxes
D.Microsoft Viva Topics
AnswerB

Copilot for Sales is explicitly grounded in CRM data, and Dynamics 365 records are the first-party Microsoft CRM source it uses for email personalization. For a given recipient, Copilot retrieves account, contact, opportunity, and deal-stage fields from Dynamics 365, and then applies that context to draft a tailored message. Without an accurate Dynamics 365 record, the draft lacks customer-specific details such as past interactions, open deals, or relationship history.

Why this answer

Copilot for Sales relies on Dynamics 365 records to access customer data such as contacts, accounts, and opportunities. By configuring the appropriate Dynamics 365 records, Copilot can retrieve the most relevant information to draft personalized emails. Without this configuration, Copilot lacks the necessary data source to generate context-aware content.

Exam trap

The trap here is that candidates may confuse the general data sources available in Microsoft 365 (like Exchange or Teams) with the specific structured CRM data required by Copilot for Sales, leading them to select a broad but incorrect option.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams channels are used for collaboration and communication, not as a data source for Copilot to pull customer records from Dynamics 365. Option C is wrong because Exchange Online mailboxes store email messages and calendar items, but they do not contain structured customer relationship data like Dynamics 365 records. Option D is wrong because Microsoft Viva Topics uses AI to organize knowledge and content from across Microsoft 365, but it does not directly provide the specific customer data from Dynamics 365 that Copilot for Sales requires.

205
MCQmedium

A company wants to deploy a cloud solution where they have the maximum control over the operating system, installed software, and security configurations, but they do not want to manage physical servers or data center facilities. Which cloud service model best meets this requirement?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Hybrid cloud
AnswerA

Infrastructure as a Service (IaaS) delivers virtualized compute, storage, and networking on demand, with the provider managing only the physical data-center infrastructure. The customer retains full administrative control over the guest operating system, storage configurations, deployed applications, middleware, and security settings, enabling maximum control over software stack and runtime environment compared to PaaS or SaaS.

Why this answer

Infrastructure as a Service (IaaS) provides virtualized computing resources over the internet, giving the customer full administrative control over the operating system, installed software, and security configurations (e.g., firewall rules, patch management) while the cloud provider manages the physical servers, storage, and networking hardware. This model aligns with the requirement for maximum control without managing physical infrastructure.

Exam trap

The trap here is that candidates often confuse the deployment model (Hybrid cloud) with the service model, or they assume PaaS offers more control than it actually does because they overlook the provider-managed OS layer in PaaS.

How to eliminate wrong answers

Option B (PaaS) is wrong because it abstracts the underlying OS and runtime environment, limiting the customer's control over OS-level configurations, installed software, and security settings—the provider manages the OS and middleware. Option C (SaaS) is wrong because the customer has no control over the OS, software stack, or security configurations; they only use the application as provided. Option D (Hybrid cloud) is wrong because it is a deployment model (combining public and private clouds), not a service model, and does not inherently grant maximum control over OS and software—it describes where resources are located, not the level of control.

206
Drag & Dropmedium

Drag and drop the steps to set up a Microsoft Teams meeting with external participants into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Creating a Teams meeting involves scheduling, adding attendees, setting options, and sending the invite.

207
MCQeasy

A company has 10 users who need only Exchange Online mailboxes and Microsoft Teams. They do not need desktop versions of Office apps. What is the most cost-effective Microsoft 365 plan for this requirement?

A.Microsoft 365 Business Basic
B.Microsoft 365 Apps for Business
C.Microsoft 365 Business Standard
D.Office 365 E1
AnswerA

Microsoft 365 Business Basic is the correct choice because it bundles hosted Exchange Online mailboxes with Microsoft Teams, and it does so at the lowest per-user price among plans that include both services. It also provides web and mobile versions of Office apps, which is sufficient for users who only need email and chat/collaboration. For a 10-person tenant, this plan avoids paying for desktop Office applications that are not required.

Why this answer

Microsoft 365 Business Basic provides Exchange Online mailboxes and Microsoft Teams, along with web and mobile versions of Office apps, without including desktop Office installations. This makes it the most cost-effective plan for the 10 users who need only email and Teams, as it offers the required services at the lowest per-user price among the options.

Exam trap

The trap here is that candidates often confuse 'Office 365 E1' as the cheapest option due to its 'E' enterprise branding, but Microsoft 365 Business Basic is actually the lowest-cost plan that includes both Exchange Online and Teams, and the exam tests the distinction between business and enterprise pricing tiers.

How to eliminate wrong answers

Option B (Microsoft 365 Apps for Business) is wrong because it includes only the desktop versions of Office apps (e.g., Word, Excel, PowerPoint) and does not include Exchange Online mailboxes or Microsoft Teams, so it fails to meet the core requirements. Option C (Microsoft 365 Business Standard) is wrong because it includes desktop Office apps, which are not needed, making it more expensive than necessary for the stated needs. Option D (Office 365 E1) is wrong because, while it provides Exchange Online and Teams, it is an enterprise plan with a higher per-user cost than Business Basic, and it is not the most cost-effective choice for a small group of 10 users who do not require enterprise-grade compliance or advanced features.

208
MCQmedium

A sales team frequently collaborates on proposals stored in Microsoft 365. They want to use an AI-powered tool to draft sections based on previous winning proposals. Which Microsoft 365 app should they use?

A.Microsoft Copilot for Microsoft 365
B.Microsoft Syntex
C.Microsoft Viva Topics
D.Microsoft Power Automate
AnswerA

Microsoft Copilot for Microsoft 365 is an AI assistant that combines large language models with your Microsoft Graph data to generate, summarize, and rewrite proposal content directly in Word, PowerPoint, or Outlook. Because it can retrieve and reason over existing proposal files, contracts, and sales documentation secured in your tenant, it can create new drafts tailored to your team's prior work rather than using generic public answers.

Why this answer

Microsoft Copilot for Microsoft 365 is the correct choice because it integrates large language models directly into the Microsoft 365 productivity apps, including Word, Excel, and PowerPoint. It can analyze existing content—such as previous winning proposals stored in SharePoint or OneDrive—and generate new draft sections based on that data, using natural language prompts. This makes it the ideal AI-powered tool for collaborative proposal writing.

Exam trap

The trap here is that candidates may confuse Microsoft Syntex's content understanding and classification capabilities with generative AI, leading them to select Syntex instead of recognizing that Copilot is the dedicated generative AI assistant for content creation in Microsoft 365.

How to eliminate wrong answers

Option B (Microsoft Syntex) is wrong because Syntex is a content AI service focused on content understanding, classification, and extraction of metadata from documents, not on generating new draft content based on prior examples. Option C (Microsoft Viva Topics) is wrong because Viva Topics is a knowledge discovery tool that automatically organizes content into topic pages and surfaces relevant information, but it does not generate new text or draft sections. Option D (Microsoft Power Automate) is wrong because Power Automate is a workflow automation platform for creating automated processes and integrations, not an AI content generation tool.

209
Multi-Selectmedium

Which TWO of the following are features of Microsoft Purview that help organizations meet compliance requirements for data lifecycle management? (Choose two.)

Select 2 answers
A.Retention policies
B.eDiscovery (Premium)
C.Records management
D.Insider Risk Management
E.Data Loss Prevention (DLP) policies
AnswersA, C

Retention policies in Microsoft Purview govern how long content is kept and when it is deleted, covering the full data lifecycle across Exchange, SharePoint, OneDrive, and Teams. This directly satisfies the compliance requirement for data lifecycle management.

Why this answer

Retention policies (A) are a core Microsoft Purview capability that let organizations keep or delete content for a defined period, directly supporting data lifecycle management by governing how long data is retained and when it is disposed of. Records management (C) extends this by letting organizations declare content as records, apply retention and disposition rules (including event-based retention and regulatory records), and manage the full lifecycle of high-value or regulated data. Together, A and C are the Purview features specifically designed for lifecycle governance from creation through disposal. eDiscovery (Premium) (B) focuses on identifying, preserving, collecting, and reviewing content for legal investigations rather than lifecycle retention.

Insider Risk Management (D) detects and mitigates risky user activity, and Data Loss Prevention policies (E) prevent sharing of sensitive data in motion — neither governs retention or disposition of data over its lifecycle.

Exam trap

MS-900 often tests the confusion between retention/lifecycle features (retention policies, records management) and adjacent Purview tools like DLP, eDiscovery, and Insider Risk Management, which solve different problems but are all branded under the same compliance umbrella.

210
MCQmedium

A service owner is comparing Microsoft 365 capabilities and needs to provide desktop Office apps when email is hosted elsewhere. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Forms
B.Microsoft Whiteboard
C.Microsoft Stream
D.Microsoft 365 Apps plan
AnswerD

The Microsoft 365 Apps plan is a dedicated user-based subscription that delivers the core Office applications—Word, Excel, PowerPoint, Outlook, and OneNote—across desktop, web, and mobile without requiring the full Microsoft 365 E3 or Business Premium bundle. It is intentionally designed for scenarios where users only need Office apps and not cloud services like Exchange Online mailboxes or Teams. This plan is the only option listed that is a true subscription plan rather than a discrete productivity feature, making it the correct choice for meeting an Office application licensing requirement.

Why this answer

The Microsoft 365 Apps plan (formerly Office 365 ProPlus) is a subscription-based licensing model that provides the full desktop versions of Office applications (Word, Excel, PowerPoint, etc.) without requiring email hosting from Microsoft. This makes it the correct choice for a service owner who needs desktop Office apps while email is hosted elsewhere, as it decouples Office from Exchange Online.

Exam trap

The trap here is that candidates often assume all Microsoft 365 plans require Exchange Online for email, but the Microsoft 365 Apps plan specifically separates desktop Office licensing from email hosting, making it the correct answer for this scenario.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a web-based survey and quiz tool, not a desktop Office application, and it requires a Microsoft 365 subscription that typically includes Exchange Online for email. Option B is wrong because Microsoft Whiteboard is a digital canvas app for collaboration, not a desktop Office suite, and it does not provide Word, Excel, or PowerPoint. Option C is wrong because Microsoft Stream is a video management and sharing service, not a desktop Office application, and it relies on Azure AD and SharePoint, not standalone Office licensing.

211
MCQeasy

A company uses a cloud service where they can provision virtual machines, install any operating system, and manage all software on those machines. The cloud provider is responsible for the physical hardware, data center security, and network infrastructure. Which cloud service model does this represent?

A.IaaS (Infrastructure as a Service)
B.PaaS (Platform as a Service)
C.SaaS (Software as a Service)
D.FaaS (Function as a Service)
AnswerA

In the Infrastructure-as-a-Service model, the cloud provider supplies fundamental computing resources such as virtual machines, storage, and virtual networks on demand. Subscribers can provision these VMs with their own operating system, middleware, and applications, retaining administrative control over the OS, security patching, and software configuration while the provider maintains the physical host hardware and datacenter infrastructure. This directly matches the scenario of provisioning a virtual machine.

Why this answer

This scenario describes Infrastructure as a Service (IaaS) because the customer has full control over virtual machines, including the operating system and all installed software, while the cloud provider manages the underlying physical hardware, data center security, and network infrastructure. In IaaS, the provider offers virtualized computing resources over the internet, and the customer is responsible for everything above the hypervisor layer, such as OS patches, application configuration, and middleware.

Exam trap

The trap here is that candidates often confuse IaaS with PaaS because both involve virtual machines, but the key differentiator is whether the customer manages the operating system and software stack (IaaS) or the provider manages them (PaaS).

How to eliminate wrong answers

Option B is wrong because PaaS (Platform as a Service) provides a managed platform where the provider handles the runtime, middleware, and OS, and the customer only deploys code; the customer cannot install or manage an arbitrary operating system on virtual machines. Option C is wrong because SaaS (Software as a Service) delivers fully managed applications accessed via a web browser or client, with no customer control over the underlying infrastructure, OS, or virtual machines. Option D is wrong because FaaS (Function as a Service) is a serverless compute model where customers deploy individual functions that execute in response to events, and they have no visibility or control over virtual machines or operating systems.

212
MCQhard

A company uses Microsoft 365 E5 and wants to implement a solution that automatically detects and remediates security incidents across endpoints, email, and identities. Which service should they use?

A.Microsoft Defender XDR
B.Microsoft Purview
C.Microsoft Defender for Cloud
D.Microsoft Sentinel
AnswerA

Microsoft Defender XDR is the correct choice because it is a unified extended detection and response (XDR) solution that automatically correlates alerts and signals across endpoints, email, identities, and cloud apps. It provides built-in, out-of-the-box automated response actions such as isolating devices, quarantining files, and blocking accounts, enabling rapid mitigation across the full attack surface. This cross-domain automation makes it an ideal single solution for implementing security incident response in a Microsoft 365 E5 environment.

Why this answer

Microsoft Defender XDR (Extended Detection and Response) is the correct choice because it provides a unified, cross-domain security solution that automatically detects, investigates, and remediates threats across endpoints, email, and identities. It leverages AI and automation to correlate signals from Microsoft Defender for Endpoint, Defender for Office 365, and Defender for Identity, enabling coordinated incident response without manual intervention.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a cloud workload protection tool) with Microsoft Defender XDR, or mistakenly think Microsoft Sentinel (a SIEM) is the primary automated remediation tool, when in fact Sentinel requires custom playbooks and is not designed for cross-domain automated remediation out of the box.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview is a data governance, compliance, and risk management solution, not a security incident detection and remediation tool; it focuses on data classification, retention, and eDiscovery. Option C is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) for multi-cloud environments (Azure, AWS, GCP), not for endpoint, email, and identity incident response. Option D is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) that ingests logs and requires custom analytics rules and manual or semi-automated playbooks for remediation, whereas Defender XDR provides built-in, automated detection and remediation across the specified domains.

213
Multi-Selectmedium

An organisation wants to identify documents containing credit card numbers and prevent users from sharing them externally from SharePoint Online and Exchange Online. Which two Microsoft Purview capabilities are most relevant? (Choose 2.)

Select 2 answers
A.Sensitive information types.
B.Data Loss Prevention policies.
C.Microsoft Bookings.
D.Windows Autopilot.
AnswersA, B

Sensitive information types are content classifiers that use built-in pattern recognition to identify data like credit card numbers, including validation via Luhn checksum and context keywords. These predefined or custom regex-based detectors can scan content in Exchange Online, SharePoint, and OneDrive, making them the direct mechanism for identifying documents containing credit card data.

Why this answer

Sensitive information types (A) are predefined or custom patterns that detect sensitive data like credit card numbers using regex and checksum validation. Data Loss Prevention policies (B) use these sensitive information types to enforce rules that block external sharing of documents containing credit card numbers in SharePoint Online and Exchange Online. Together, they identify the sensitive content and prevent its unauthorized external distribution.

Exam trap

The trap here is that candidates may confuse Microsoft Purview capabilities with unrelated Microsoft 365 services like Bookings or Autopilot, failing to recognize that only sensitive information types and DLP policies directly address content inspection and sharing controls for compliance scenarios.

214
MCQeasy

A project manager needs to assign tasks to team members, set deadlines, and track progress in a shared workspace. The workspace should integrate with Outlook and Teams. Which Microsoft 365 app is best suited for this requirement?

A.Microsoft To Do
B.Microsoft Planner
C.SharePoint
D.Microsoft Lists
AnswerB

Microsoft Planner is the correct workload because each plan is a shared canvas backed by a Microsoft 365 group, and every task can be assigned to a specific member of that group, given a deadline, placed in a bucket, and tracked with charts on the Plan tab. Its board, charts, and schedule views give teams a visual way to monitor progress per assignee and per bucket, and the same plan can be added as a tab in Microsoft Teams or surfaced in Outlook, making it a true collaborative task management service.

Why this answer

Microsoft Planner is best suited because it provides a shared workspace with task assignment, deadline setting, and progress tracking via Kanban boards, and it integrates natively with Outlook for task synchronization and with Teams as a tab app for collaborative access.

Exam trap

Microsoft often tests the distinction between personal task tools (To Do), collaborative task management (Planner), and data tracking (Lists), where candidates may confuse Lists' custom fields with Planner's task assignment capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft To Do is a personal task management app focused on individual to-do lists, lacking shared workspaces, team assignment, and progress tracking features. Option C is wrong because SharePoint is a document management and collaboration platform for sites and libraries, not designed for task assignment, deadline tracking, or Kanban-style progress views. Option D is wrong because Microsoft Lists is a data tracking app for creating custom lists (e.g., issue trackers, inventories), but it does not provide built-in task assignment, deadline management, or the integrated Kanban boards that Planner offers.

215
MCQmedium

A marketing team needs to collaborate on a presentation that will be updated frequently by multiple team members, and they want to ensure everyone always has the latest version without manual tracking. Which Microsoft 365 service should they use?

A.Exchange Online
B.SharePoint Online
C.Microsoft Teams
D.OneDrive for Business
AnswerB

SharePoint Online provides cloud-based team sites with document libraries that support simultaneous co-authoring, check-in/check-out, version history, and granular access controls. When users open a PowerPoint presentation from a SharePoint library, edits are tracked and saved back to the central location, enabling multiple marketing teammates to work on the same file in real time. This makes SharePoint Online the correct service for organized team collaboration on a presentation.

Why this answer

SharePoint Online is the correct choice because it provides a centralized document library with version history, co-authoring, and metadata management, ensuring all team members always access the latest version without manual tracking. Unlike OneDrive for Business, which is designed for individual use, SharePoint Online supports structured collaboration across a team with granular permissions and automated sync.

Exam trap

The trap here is that candidates often confuse Microsoft Teams as the collaboration service itself, but Teams relies on SharePoint Online for file storage and versioning, so the correct underlying service is SharePoint.

How to eliminate wrong answers

Option A is wrong because Exchange Online is an email and calendaring service, not a document collaboration platform; it lacks version control and co-authoring for files. Option C is wrong because Microsoft Teams is a chat-based workspace that integrates with SharePoint for file storage, but it is not the primary service for managing and versioning shared documents; files in Teams are stored in SharePoint, so the underlying service is SharePoint. Option D is wrong because OneDrive for Business is optimized for personal file storage and sharing, not for team-based collaboration with multiple simultaneous editors and automated version tracking across a group; it lacks team-level metadata and permissions management.

216
MCQmedium

An administrator is reviewing a request from users who need to enterprise licensing options for an organization with more complex or larger-scale requirements. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Microsoft Forms
C.Microsoft 365 Enterprise plans
D.Microsoft Stream
AnswerC

Microsoft 365 Enterprise plans (E3, E5) bundle advanced compliance, security, analytics and voice capabilities for larger organisations with complex requirements, unlike Business or Frontline tiers. They deliver the enterprise licensing, administration and support scope the request describes.

Why this answer

Microsoft 365 Enterprise plans (E3, E5) are designed for organizations with complex or large-scale requirements, offering advanced security, compliance, analytics, and voice capabilities beyond the Business plans. The question specifically asks about enterprise licensing options, making C the most relevant concept.

Exam trap

The trap here is that candidates may confuse a specific application (like Whiteboard, Forms, or Stream) with a licensing plan, when the question explicitly asks for the 'licensing, admin, or support concept' relevant to enterprise-scale requirements.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a collaboration app, not an enterprise licensing plan or support concept. Option B is wrong because Microsoft Forms is a survey and data collection tool, not a licensing or support offering. Option D is wrong because Microsoft Stream is a video service, not an enterprise licensing plan or support concept.

217
MCQhard

Your company has a mix of on-premises and cloud users. You plan to move to Microsoft 365 and need to support hybrid identity with password hash synchronization. Which licensing is minimally required?

A.Microsoft Entra ID P1
B.Microsoft 365 E3
C.Microsoft Entra ID P2
D.Microsoft Entra ID Free
AnswerD

The Microsoft Entra ID Free tier only supports cloud-only identities and does not support password hash synchronization from on-premises Active Directory. It also provides no Microsoft 365 workloads, so it cannot handle the hybrid directory requirements or deliver the needed productivity services to the organization's users.

Why this answer

Password hash synchronization (PHS) is a feature of Microsoft Entra ID available in all editions, including the free tier. It is part of the directory synchronization capabilities provided by Azure AD Connect. Therefore, Microsoft Entra ID Free is the minimum licensing required to support hybrid identity with PHS.

Microsoft 365 E3 also works but is not minimal.

Exam trap

The trap is to assume PHS requires a premium license. In reality, PHS is available in the Free edition. Premium editions like P1 add features like conditional access, MFA, or password write-back, but not PHS itself.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID P1 is a standalone license, but the question asks for the minimally required licensing to support hybrid identity with PHS in a Microsoft 365 plan; Entra ID P1 alone does not include Microsoft 365 services like Exchange Online or SharePoint, which are typically part of the migration plan. Option C is wrong because Microsoft Entra ID P2 includes advanced features like Identity Protection and Privileged Identity Management, which are not required for basic PHS hybrid identity; it is overkill and not the minimal license. Option D is wrong because Microsoft Entra ID Free does not support password hash synchronization; PHS requires at least Entra ID P1, which is not included in the Free tier.

218
MCQeasy

Refer to the exhibit. A SharePoint admin views site properties in JSON format. What type of site is this?

A.Communication site
B.Classic team site
C.Hub site
D.Team site (group-connected)
AnswerD

The GROUP#0 template defines a modern team site connected to a Microsoft 365 group, which is exactly what the exhibit shows. This site type includes group membership, a shared mailbox and calendar, and group-based permissions, and it is created when a user provisions 'Team site' from SharePoint. It is the correct classification because GROUP#0 directly matches the group-connected team site template.

Why this answer

The JSON output includes the 'GroupId' property, which is a GUID that uniquely identifies the Microsoft 365 Group associated with the site. This property is only present on team sites that are connected to a Microsoft 365 Group (group-connected team sites). Communication sites and classic team sites do not have a GroupId, and hub sites are a site association feature, not a site template.

Exam trap

The trap here is that candidates may confuse the presence of a 'GroupId' with a hub site's association ID, or assume that any modern site (including communication sites) would have a group ID, when in fact only group-connected team sites include this property in their JSON output.

How to eliminate wrong answers

Option A is wrong because communication sites do not have a 'GroupId' property in their JSON representation; they are designed for broadcasting information and are not group-connected. Option B is wrong because classic team sites (without a Microsoft 365 Group) lack the 'GroupId' property; they use SharePoint-specific permissions and are not backed by a Microsoft 365 Group. Option C is wrong because a hub site is a site that has been designated as a hub for navigation and search aggregation, but it is not a distinct site template; the JSON shown does not include a 'HubSiteId' or 'IsHubSite' property, and hub sites can be either communication sites or group-connected team sites.

219
MCQmedium

A compliance administrator needs to retain mailbox content for legal investigation. Which Microsoft 365 capability is the best fit?

A.Microsoft Teams live events
B.Microsoft Bookings
C.OneDrive sync client
D.eDiscovery and retention capabilities in Microsoft Purview
AnswerD

Microsoft Purview eDiscovery and retention preserve mailbox content in place for legal investigation, satisfying the compliance requirement. Retention policies and holds prevent deletion, while eDiscovery search and legal hold capabilities support case review without altering user mailboxes.

Why this answer

eDiscovery and retention capabilities in Microsoft Purview are designed specifically for legal investigations, allowing compliance administrators to preserve mailbox content via legal holds, search across mailboxes, and export data for litigation. This directly meets the requirement to retain mailbox content for legal investigation, unlike the other options which serve unrelated business functions.

Exam trap

The trap here is that candidates may confuse general data storage or communication tools (like OneDrive or Teams) with compliance-specific features, overlooking that only Purview provides the legal hold and search capabilities required for retaining mailbox content in investigations.

How to eliminate wrong answers

Option A is wrong because Microsoft Teams live events is a broadcast and meeting feature for large audiences, not a compliance tool for retaining mailbox content. Option B is wrong because Microsoft Bookings is a scheduling and appointment management app, lacking any data retention or eDiscovery functionality. Option C is wrong because the OneDrive sync client is for synchronizing files between a local device and cloud storage, not for preserving or searching mailbox content for legal purposes.

220
MCQeasy

A company uses Microsoft SharePoint Online for intranet and wants to display important company announcements on the home page. Which SharePoint feature should they use?

A.Pages
B.Document libraries
C.Lists
D.News posts
AnswerD

News posts are a dedicated content type in SharePoint Online built for organizational announcements. They leverage the page infrastructure but add specialized features: they automatically appear in the News web part on the site home page, can be rolled up from multiple sites, support rich media, scheduling, and audience targeting, and allow engagement through comments and reactions. This makes News posts the correct and intended tool for announcements on an intranet.

Why this answer

News posts are the correct feature because they are specifically designed to display timely, engaging announcements on a SharePoint intranet home page. They support rich formatting, images, and web parts that surface news content prominently, making them ideal for company-wide communications. Unlike other options, News posts are optimized for visibility and user engagement on the home page.

Exam trap

The trap here is that candidates confuse 'Pages' (option A) with 'News posts' because both use the same underlying page infrastructure, but News posts are a distinct feature with specific properties for announcements, not general-purpose pages.

How to eliminate wrong answers

Option A is wrong because Pages are used for creating static, structured content like landing pages or detailed information, not for dynamic, time-sensitive announcements. Option B is wrong because Document libraries store files and documents, not announcements, and lack the formatting and visibility features needed for home page news. Option C is wrong because Lists are for structured data (e.g., tasks, contacts) and require custom formatting or web parts to display as announcements, making them less suitable for immediate, engaging news.

221
MCQmedium

A compliance officer needs to automatically detect when an employee attempts to send an email containing a social security number (SSN) to an external recipient. The solution should block the email from being sent and notify the employee with a policy tip. Which Microsoft Purview solution should be configured?

A.Microsoft Purview Data Loss Prevention (DLP)
B.Microsoft Purview Information Protection
C.Microsoft Purview eDiscovery
D.Microsoft Purview Audit
AnswerA

Microsoft Purview Data Loss Prevention (DLP) in Exchange Online includes policies that scan email content in transit for sensitive information types such as social security numbers. When a match occurs, DLP can enforce an action like blocking the message from being sent and generating a policy tip to the sender, which satisfies the automatic detection and remediation requirement.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect sensitive information (such as social security numbers) in emails and other data in transit. When a DLP policy is configured with a rule that matches the SSN condition and an action to block the message, it automatically prevents the email from being sent and displays a policy tip to the user, notifying them of the violation. This aligns directly with the requirement to both block the email and provide real-time user notification.

Exam trap

The trap here is that candidates often confuse Information Protection (labeling) with Data Loss Prevention (enforcement), assuming that applying a sensitivity label automatically blocks data exfiltration, when in fact DLP policies are required to enforce actions like blocking and policy tips.

How to eliminate wrong answers

Option B (Microsoft Purview Information Protection) is wrong because it focuses on classifying and labeling sensitive data (e.g., applying sensitivity labels) but does not include the ability to block email transmission or enforce real-time actions like policy tips; it is a classification and protection layer, not a blocking enforcement mechanism. Option C (Microsoft Purview eDiscovery) is wrong because it is used for searching and exporting content for legal or investigative purposes, not for preventing data exfiltration or providing user notifications during email composition. Option D (Microsoft Purview Audit) is wrong because it logs user and admin activities for forensic review but cannot block emails or display policy tips; it is a passive logging tool, not an active enforcement solution.

222
MCQmedium

A legal firm needs to send a confidential document to a client via email. The firm requires that the client cannot forward or print the email and that the email expires after seven days. Which Microsoft Purview solution should they use?

A.Microsoft Purview Message Encryption
B.Data Loss Prevention (DLP) policies
C.Sensitivity labels
D.eDiscovery (Premium)
AnswerA

Microsoft Purview Message Encryption is the correct choice because it uses Azure Rights Management (Azure RMS) to encrypt email messages and apply persistent usage restrictions on the client's copy, even after they are sent. It can prevent forwarding, disable printing, and set an expiration date that revokes access to the message after a specified time. This works seamlessly with external recipients regardless of their email provider, making it ideal for a legal firm sending confidential documents to a client.

Why this answer

Microsoft Purview Message Encryption (A) is the correct solution because it allows the legal firm to apply usage restrictions such as preventing forwarding and printing, and to set an expiration period of seven days on the email. This is achieved through Azure Rights Management (Azure RMS) templates that enforce these controls directly on the encrypted message, ensuring the client cannot bypass the restrictions.

Exam trap

The trap here is that candidates often confuse sensitivity labels with Message Encryption, not realizing that while labels can apply encryption, they do not natively support per-message expiration or granular usage restrictions like 'do not forward' and 'do not print' without additional configuration via Azure RMS templates, which is exactly what Message Encryption provides out-of-the-box.

How to eliminate wrong answers

Option B (Data Loss Prevention (DLP) policies) is wrong because DLP policies are designed to detect and prevent the accidental sharing of sensitive information (e.g., credit card numbers) by blocking or warning users, but they do not provide granular post-delivery controls like 'do not forward' or 'expire after 7 days'. Option C (Sensitivity labels) is wrong because while sensitivity labels can apply encryption and visual markings, they do not natively support per-message expiration or specific usage restrictions like 'do not forward' or 'do not print' without being combined with Azure RMS templates; the question asks for a solution that directly provides these controls, which is Message Encryption. Option D (eDiscovery Premium) is wrong because eDiscovery is used for legal hold, search, and export of content for litigation or investigation, not for controlling how an email is used after it is sent.

223
Multi-Selectmedium

Which four of the following are key components of the Microsoft 365 defense-in-depth security strategy? (Choose all that apply. There are four correct answers.)

Select 4 answers
.Physical security of datacenters, including biometric access controls and 24/7 monitoring.
.User identity protection via Azure AD Multi-Factor Authentication (MFA) and Conditional Access.
.Data encryption at rest and in transit, using technologies like BitLocker and TLS.
.Automated rollback of all user changes to previous versions within 24 hours.
.Advanced Threat Protection (ATP) for email, SharePoint, and Teams, including anti-malware and anti-phishing.
.Unrestricted access for Microsoft engineers to all customer data for continuous security scanning.

Why this answer

The Microsoft 365 defense-in-depth strategy relies on multiple layers of security controls. Physical security of datacenters (biometric access, 24/7 monitoring) is the foundational layer. User identity protection via Azure AD MFA and Conditional Access secures the authentication layer.

Data encryption at rest (BitLocker) and in transit (TLS) protects data confidentiality. Advanced Threat Protection (ATP) for email, SharePoint, and Teams defends against malware and phishing at the workload layer. These four components collectively implement a layered security model.

Exam trap

The trap here is that candidates may confuse operational features like versioning or backup with core security layers, or mistakenly believe Microsoft has unrestricted access to customer data, when in fact the shared responsibility model and strict access controls are fundamental to the defense-in-depth strategy.

224
MCQmedium

An administrator needs to restrict access to Microsoft 365 admin centers based on user location. Which Microsoft Entra ID feature should they configure?

A.Conditional Access
B.Identity Protection
C.Entra ID Governance
D.Privileged Identity Management (PIM)
AnswerA

Conditional Access is the Microsoft Entra ID policy engine that blocks or grants access by evaluating conditions such as user, device, application, risk, and location. You can define a named location based on IP ranges or country/geo coordinates and set an access control to 'Block access' or 'Require MFA' when users connect from certain regions. This is the directly intended mechanism for restricting Microsoft 365 access based on location.

Why this answer

Conditional Access is the correct feature because it allows administrators to enforce policies that grant or block access to Microsoft 365 admin centers based on conditions such as user location (IP address ranges or countries). By configuring a Conditional Access policy with a location condition, you can restrict access to sensitive admin portals like the Microsoft 365 admin center or Exchange admin center to trusted networks only.

Exam trap

The trap here is that candidates often confuse Identity Protection (which also uses location signals for risk detection) with Conditional Access, but Identity Protection does not enforce access policies—it only provides risk assessments that Conditional Access can consume.

How to eliminate wrong answers

Option B (Identity Protection) is wrong because it focuses on detecting and responding to identity-based risks (e.g., leaked credentials, sign-ins from anonymous IPs) but does not directly restrict access to admin centers based on location. Option C (Entra ID Governance) is wrong because it manages identity lifecycle, access reviews, and entitlement management, not real-time location-based access control. Option D (Privileged Identity Management) is wrong because it provides just-in-time privileged access and approval workflows for roles, but does not enforce location-based restrictions on accessing admin centers.

225
MCQmedium

During a Microsoft 365 planning workshop, allow access to Exchange Online only from compliant devices. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Forms
B.Microsoft Intune compliance policies with Conditional Access
C.Microsoft Stream
D.Microsoft Planner
AnswerB

Microsoft Intune compliance policies evaluate devices against baselines such as OS version, encryption, jailbreak, and threat-check statuses, publishing a signal to Azure AD. Conditional Access then consumes that signal through a 'Require device to be marked compliant' grant, blocking or allowing access to Microsoft 365 services accordingly. It is the only option here that directly implements both evaluation and enforcement for security-aware access control.

Why this answer

Microsoft Intune compliance policies define the security requirements (e.g., device encryption, jailbreak detection, minimum OS version) that a device must meet. When combined with Conditional Access in Azure AD, you can create a policy that blocks access to Exchange Online unless the device is marked as compliant by Intune. This ensures only compliant devices can connect, directly meeting the requirement.

Exam trap

The trap here is that candidates confuse productivity apps (Forms, Stream, Planner) with security services, failing to recognize that only Intune compliance policies combined with Conditional Access can enforce device-based access controls for Exchange Online.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and data collection tool, not a security or compliance capability—it cannot enforce device compliance or control access to Exchange Online. Option C is wrong because Microsoft Stream is a video hosting and sharing service; it has no role in device compliance enforcement or Conditional Access policies. Option D is wrong because Microsoft Planner is a task management and project planning tool; it provides no security controls for device-based access restrictions.

Page 2

Page 3 of 11

Page 4

All pages