Courseiva

Microsoft 365 Fundamentals MS-900 (MS-900) — Questions 226–300

794 questions total · 11pages · All types, answers revealed

Page 3

Page 4 of 11

Page 5
226
MCQmedium

A service owner is comparing Microsoft 365 capabilities and needs to prevent communication and collaboration between two business groups. Microsoft security, identity, or compliance capability should it use?

A.Information Barriers
B.Microsoft Forms
C.Microsoft Planner
D.Microsoft Stream
AnswerA

Information Barriers is a compliance and security capability in Microsoft 365 (part of Microsoft Purview) that lets administrators define policies to prevent specified user groups from communicating or collaborating with each other. It works across Teams, SharePoint, OneDrive, and other services to block chat, file sharing, and other interactions, making it the correct answer for a service owner who needs to restrict communication between defined groups.

Why this answer

Information Barriers (IB) in Microsoft 365 are specifically designed to prevent communication and collaboration between defined user groups, such as two business groups that must not interact. IB policies use segment-based rules to block chat, email, and file sharing across groups, enforced at the Exchange Online, Teams, and SharePoint levels. This directly meets the service owner's requirement to isolate groups, unlike the other options which are general-purpose tools without such isolation capabilities.

Exam trap

The trap here is that candidates may confuse Information Barriers with other compliance features like Data Loss Prevention (DLP) or sensitivity labels, but the question specifically asks for a capability that prevents communication and collaboration between groups, which is the exact purpose of Information Barriers, not data protection or classification.

How to eliminate wrong answers

Option B (Microsoft Forms) is wrong because it is a survey and data collection tool, not a security or compliance feature for blocking communication between groups. Option C (Microsoft Planner) is wrong because it is a task management and project planning tool, lacking any capability to enforce communication barriers. Option D (Microsoft Stream) is wrong because it is a video hosting and sharing platform, not designed for access control between business groups; it does not provide the required segmentation or policy enforcement.

227
MCQmedium

A security administrator needs to ensure that all guest users who access Microsoft Teams are required to accept a terms of use agreement before accessing any company resources. Which Microsoft 365 identity protection feature should they configure?

A.Conditional Access policy with session control
B.Microsoft Entra ID Identity Protection
C.Terms of Use in Microsoft Entra ID
D.Privileged Identity Management
AnswerC

Terms of Use in Microsoft Entra ID is the correct mechanism: you can create a PDF-based agreement, assign it to guest users (or groups containing guests) through a Conditional Access policy, and the user must accept it before accessing the target application, including Microsoft Teams. This acceptance is written to Microsoft Entra ID audit logs, and the feature supports versioned agreements with optional periodic re-acceptance, providing a compliant, auditable way to secure guest access. Unlike the other options, this is the only one that directly enforces and tracks consent to your terms.

Why this answer

Microsoft Entra ID Terms of Use is the specific feature designed to present a terms-of-use agreement to users before they can access resources. When combined with a Conditional Access policy that targets guest users and requires acceptance of the terms, it ensures that guests must accept the agreement before accessing Microsoft Teams or any other company resource.

Exam trap

The trap here is confusing the general concept of 'Conditional Access' (which is the policy engine) with the specific grant control 'Terms of Use' that must be configured within it, leading candidates to pick Option A instead of C.

How to eliminate wrong answers

Option A is wrong because a Conditional Access policy with session control enforces restrictions like sign-in frequency or app control, not the presentation and acceptance of a terms-of-use agreement. Option B is wrong because Microsoft Entra ID Identity Protection is focused on detecting and responding to identity risks (e.g., leaked credentials, anomalous sign-ins), not on requiring user acceptance of legal agreements. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role assignments and access reviews, not the enforcement of terms-of-use acceptance for guest users.

228
MCQeasy

A company's e-commerce website experiences a sudden surge in traffic during a promotional event. The cloud infrastructure automatically adds additional virtual servers to handle the load and removes them when traffic subsides, without any manual intervention from the IT team. Which cloud computing characteristic does this demonstrate?

A.Rapid elasticity
B.On-demand self-service
C.Resource pooling
D.Measured service
AnswerA

Rapid elasticity is the capability to provision and de-provision resources automatically and proportionally to demand. The infrastructure scaling servers up during the surge and removing them afterwards, with no manual intervention, matches this characteristic exactly.

Why this answer

The scenario describes the cloud infrastructure automatically scaling virtual servers up and down in response to traffic changes, which is the defining characteristic of rapid elasticity. This capability allows resources to be provisioned and released elastically, often automatically, to match demand at any given time, as defined by NIST SP 800-145.

Exam trap

The trap here is that candidates confuse 'on-demand self-service' (manual provisioning by a user) with 'rapid elasticity' (automatic scaling by the cloud platform), but the key differentiator is the lack of manual intervention in the scenario.

How to eliminate wrong answers

Option B is wrong because on-demand self-service refers to a user's ability to provision computing resources (e.g., spinning up a VM) without human interaction with the provider, not the automatic scaling of resources based on load. Option C is wrong because resource pooling describes the provider's multi-tenant model where physical and virtual resources are dynamically assigned to serve multiple customers, not the automatic scaling behavior. Option D is wrong because measured service involves metering and reporting resource usage for billing and optimization (e.g., pay-per-use), not the automatic addition or removal of servers in response to demand.

229
MCQhard

Your company has 10,000 users across multiple regions and uses Microsoft 365 E5. You need to ensure that all users have access to Microsoft Copilot for Microsoft 365 to boost productivity. However, due to licensing costs, management wants to minimize expenses by only assigning Copilot licenses to users who will actively use it. They also want to track usage to make informed renewal decisions. What should you do?

A.Assign Copilot licenses to a pilot group and use Microsoft 365 usage reports to identify active users before expanding.
B.Disable Copilot by default and allow users to request it via a helpdesk ticket.
C.Assign Copilot licenses to all users via group-based licensing in Microsoft Entra ID.
D.Use Power Automate to automatically assign Copilot licenses to users who send more than 50 emails per day.
AnswerA

Assigning Copilot licenses to a small pilot group first is a cost-controlled approach because it limits license spend while allowing you to measure real adoption. Use Microsoft 365 admin center usage reports or the Copilot Dashboard to track active users, feature usage, and business impact. This data-driven pilot lets you expand licenses only to users who demonstrably benefit, avoiding waste and tying investment to actual demand.

Why this answer

It aligns with the management's goal of minimizing costs by first assigning Copilot licenses to a pilot group, then using Microsoft 365 usage reports (which track Copilot-specific metrics like active users, sessions, and feature adoption) to identify active users before expanding license assignment. This approach ensures only engaged users receive licenses, optimizing spend while providing data for renewal decisions.

Exam trap

The trap here is that candidates may assume group-based licensing (Option C) is the most efficient method for large-scale deployment, but the question explicitly prioritizes cost minimization and usage tracking, making a pilot group with usage reports the correct choice over blanket assignment.

How to eliminate wrong answers

Option B is wrong because disabling Copilot by default and requiring helpdesk tickets creates administrative overhead and delays user access, failing to leverage Microsoft's built-in license management and usage analytics for cost-effective scaling. Option C is wrong because assigning Copilot licenses to all 10,000 users via group-based licensing contradicts the requirement to minimize expenses, as it would pay for inactive users without any usage tracking. Option D is wrong because using Power Automate to assign licenses based on email volume (e.g., >50 emails/day) is an arbitrary, unsupported metric that does not correlate with Copilot usage; Microsoft 365 usage reports are the correct tool for tracking actual Copilot adoption.

230
MCQhard

A company is deploying a cloud solution where they have the ability to quickly scale up resources during peak demand and scale down during off-peak hours, paying only for what they use. They also need the provider to automatically manage the underlying platform, including patching the operating system. Which combination of cloud characteristics and service model best describes this scenario?

A.Elasticity and PaaS
B.Scalability and IaaS
C.Rapid elasticity and SaaS
D.Measured service and PaaS
AnswerA

Elasticity automatically adjusts computing capacity in real time to match fluctuating demand, while PaaS offloads management of the underlying OS, runtime, and middleware to the provider. This combination fits the scenario because the customer can scale the application on demand without handling infrastructure patching, while the provider maintains the platform. Unlike IaaS, the OS is not the customer's responsibility; unlike SaaS, the application itself remains under customer control.

Why this answer

The scenario describes elasticity (the ability to scale resources up and down automatically based on demand) and Platform as a Service (PaaS), where the provider manages the underlying platform, including OS patching. Elasticity is a key cloud characteristic that enables dynamic scaling, and PaaS abstracts infrastructure management, aligning perfectly with the requirement for automatic platform maintenance.

Exam trap

The trap here is confusing scalability (a general capability) with elasticity (dynamic, automated scaling), and assuming IaaS includes platform management like patching, which it does not—IaaS only provides virtual machines where the customer handles the OS.

How to eliminate wrong answers

Option B is wrong because IaaS (Infrastructure as a Service) does not include automatic OS patching; the customer is responsible for managing the operating system and middleware. Option C is wrong because SaaS (Software as a Service) delivers fully managed applications, not a platform for deploying custom code, and the scenario requires platform-level control, not just application usage. Option D is wrong because measured service (metering and billing) is a cloud characteristic that applies to all service models, but it does not describe the automatic scaling or platform management mentioned in the scenario.

231
MCQmedium

A service owner is comparing Microsoft 365 capabilities and needs to reset user passwords without assigning Global Administrator. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Password Administrator
C.Microsoft Forms
D.Microsoft Stream
AnswerB

The Password Administrator role is a built-in Azure AD role that grants the ability to reset passwords for users who are non-admins, as well as for some limited admin roles, without assigning full Global Admin privileges. This makes it the correct choice when a service owner needs to delegate password reset tasks. It is explicitly scoped for identity management, unlike collaboration tools, and is the least-privileged role that can handle this requirement.

Why this answer

The Password Administrator role in Azure AD allows a service owner to reset user passwords without needing the highly privileged Global Administrator role. This aligns with the principle of least privilege, as it grants only the specific permissions required for password management while avoiding broader administrative access.

Exam trap

The trap here is that candidates may assume only Global Administrator can reset passwords, overlooking the existence of the Password Administrator role, which is specifically designed for delegated password management without full admin privileges.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a digital canvas collaboration tool, not an administrative role or licensing concept for password management. Option C is wrong because Microsoft Forms is a survey and data collection tool, unrelated to user administration or password reset capabilities. Option D is wrong because Microsoft Stream is a video management service, not an admin role or licensing feature for resetting passwords.

232
MCQhard

Refer to the exhibit. The JSON shows a device compliance policy assignment in Microsoft Intune. Based on the exhibit, what is the current compliance status of the devices in the target group?

A.Not compliant, only because the password setting is missing
B.Compliant, because both settings are compliant
C.Not compliant, because the encryption setting is not compliant
D.Compliant, because the password setting is compliant
AnswerC

The JSON clearly shows that the encryption setting is required but is not compliant, and in a device compliance policy, any single non-compliant setting causes the entire device to be flagged as not compliant. Even though the password setting is satisfied, the unresolved encryption requirement overrides that and results in a 'Not compliant' status. Microsoft Intune evaluates all rules collectively, so this device is correctly identified as non-compliant due to the encryption setting.

Why this answer

The exhibit shows a device compliance policy in Microsoft Intune with two settings: 'require device encryption' set to 'Required' and 'minimum password length' set to '6'. The compliance status for the target group is 'Not compliant, because the encryption setting is not compliant'. This is because the JSON indicates that the encryption requirement is not being met by the devices in the group, likely due to BitLocker or device encryption not being enabled.

The password setting alone does not override the encryption non-compliance, as all required settings must be satisfied for a device to be marked compliant.

Exam trap

The trap here is that candidates may focus on the password setting being present and compliant, overlooking that the encryption setting is explicitly non-compliant, and assume partial compliance is sufficient for an overall 'Compliant' status.

How to eliminate wrong answers

Option A is wrong because the password setting is present and configured (minimum length of 6), so the non-compliance is not due to a missing password setting; it is due to the encryption setting. Option B is wrong because both settings are not compliant; the encryption setting is explicitly non-compliant, as shown in the exhibit. Option D is wrong because compliance requires all settings to be compliant; even if the password setting is compliant, the encryption non-compliance makes the device not compliant overall.

233
MCQeasy

A user is unable to access Microsoft Teams because the tenant's subscription has expired. The administrator wants to restore access as quickly as possible while minimizing costs. What should the administrator do?

A.Extend the trial period for 30 additional days
B.Wait for the subscription to automatically renew within 30 days
C.Reactivate the expired subscription in the Microsoft 365 admin center
D.Purchase a new subscription and assign licenses to users
AnswerC

Reactivating in the Microsoft 365 admin center (navigate to Billing > Your products, select the expired subscription, then choose Reactivate) is the correct action because it is available during the grace period and the disabled state, so the original subscription ID, licenses, and configured tenant data are preserved. This restores Teams access immediately after the outstanding balance is paid, without re-assigning licenses or recreating users, making it faster and less disruptive than a new purchase.

Why this answer

The Microsoft 365 admin center provides a 'Reactivate subscription' option for expired subscriptions, typically within a grace period (e.g., 30 days for most paid subscriptions). This restores access immediately without requiring a new purchase, minimizing both cost and downtime. The administrator can simply navigate to Billing > Your products, select the expired subscription, and click Reactivate.

Exam trap

The trap here is that candidates may assume a new subscription is always required after expiration, overlooking the built-in grace period and reactivation feature that Microsoft provides to minimize disruption and cost.

How to eliminate wrong answers

Option A is wrong because extending a trial period is only possible for active trial subscriptions, not for an expired paid subscription; the tenant's subscription has already expired, so a trial extension is not applicable. Option B is wrong because Microsoft 365 subscriptions do not automatically renew after expiration; automatic renewal must be enabled before expiration, and waiting 30 days would result in prolonged downtime and potential data loss. Option D is wrong because purchasing a new subscription and reassigning licenses is unnecessary and more costly; the existing subscription can be reactivated within the grace period, preserving the existing configuration and data.

234
MCQmedium

A department head asks which Microsoft 365 option should be used to provide a cloud identity platform for Microsoft 365 and approved SaaS applications. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Planner
B.Microsoft Forms
C.Microsoft Entra ID
D.Microsoft Stream
AnswerC

Entra ID (formerly Azure AD) is the identity and access management backbone for Microsoft 365; it authenticates users and enforces conditional access, multi-factor authentication, and device restrictions. Because the department head needs a service to manage who can access Microsoft 365 resources, Entra ID is the correct platform, not just a tool with a task or content focus.

Why this answer

Microsoft Entra ID (formerly Azure Active Directory) is the correct choice because it is the cloud-based identity and access management service that provides authentication, single sign-on (SSO), and conditional access for Microsoft 365 and thousands of pre-integrated SaaS applications. It acts as the identity platform, managing user identities and controlling access to resources, which directly aligns with the department head's requirement for a cloud identity platform.

Exam trap

The trap here is that candidates often confuse productivity tools (like Planner, Forms, or Stream) with security or identity services, mistakenly thinking any Microsoft 365 app can serve as an identity platform, when only Microsoft Entra ID provides the required cloud identity and access management capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management and planning tool within Microsoft 365, not an identity platform; it cannot provide authentication or access control for SaaS applications. Option B is wrong because Microsoft Forms is a survey and data collection tool, used for creating forms and quizzes, with no identity or access management capabilities. Option D is wrong because Microsoft Stream is a video hosting and sharing service for enterprise video content, lacking any identity or security features for managing access to SaaS applications.

235
Multi-Selectmedium

Which TWO Microsoft 365 services can be used to create and manage custom business processes without writing code?

Select 2 answers
A.SharePoint Designer
B.Microsoft Power Automate
C.Microsoft Flow
D.Microsoft Lists
E.Microsoft Power Apps
AnswersB, E

Microsoft Power Automate is a low-code, cloud-based workflow automation service that lets you create automated processes called flows. With triggers and actions, you can connect to multiple services and data sources, making it a primary tool for business process automation in Microsoft 365. It supports both simple repetitive tasks and complex, multi-step business workflows.

Why this answer

Microsoft Power Automate is a low-code automation platform that enables users to create custom workflows and business processes by connecting various applications and services through pre-built connectors. It allows the design of automated processes without writing code, using a visual designer to define triggers, conditions, and actions.

Exam trap

The trap here is that candidates may confuse Microsoft Flow as a separate service when it is simply the former name of Power Automate, leading them to select both B and C as correct answers, but only Power Automate (B) is the current and valid service.

236
MCQmedium

A help desk lead is documenting the correct Microsoft 365 approach to build a simple mobile app for field workers to submit inspection results. Microsoft 365 app or service is the best fit?

A.Power Apps
B.Microsoft Planner
C.Microsoft Purview Audit
D.Microsoft Forms
AnswerA

Power Apps provides a low-code canvas environment for building simple mobile forms that capture and submit data, such as inspection results, and integrates directly with Microsoft 365 services and Dataverse for storage without custom native development.

Why this answer

Power Apps is the correct choice because it is a low-code platform specifically designed for building custom mobile apps that integrate with Microsoft 365 data sources, such as SharePoint, Dataverse, or SQL. Field workers can submit inspection results through a tailored app with forms, business logic, and offline capabilities, making it ideal for this scenario.

Exam trap

The trap here is that candidates often confuse Microsoft Forms (a simple survey tool) with Power Apps (a full app builder), assuming Forms can be used for mobile app development when it lacks the necessary customization, offline, and integration capabilities.

How to eliminate wrong answers

Option B (Microsoft Planner) is wrong because it is a task management tool for organizing work, not a platform for building custom mobile apps with data submission capabilities. Option C (Microsoft Purview Audit) is wrong because it is a compliance and auditing solution for tracking user activities, not an app development service. Option D (Microsoft Forms) is wrong because it creates simple surveys and quizzes with limited customization and no ability to build a full mobile app with offline support or complex business logic.

237
MCQhard

An administrator is assigned the Global Reader role in Microsoft Entra ID as shown in the exhibit. What can this administrator do?

A.View all user and group properties in the directory
B.Reset user passwords
C.Assign administrative roles to other users
D.Create new users in the directory
AnswerA

The Global Reader role in Microsoft Entra ID is granted read-only permissions across directory objects, so a holder can view all user and group properties, including display names, job titles, and directory settings, without any write capability. Because Global Reader is designed as the read-only counterpart to Global Administrator, it can enumerate these properties for every user and group in the tenant but cannot modify them or perform management tasks.

Why this answer

The Global Reader role in Microsoft Entra ID is a read-only role that allows viewing all directory settings, including user and group properties, but does not grant any write permissions. This enables the administrator to view but not modify user or group attributes, making option A correct.

Exam trap

The trap here is that candidates often confuse the Global Reader role with the Global Administrator role, assuming it includes some write capabilities like password resets or user creation, but Microsoft strictly separates read-only and write roles in Entra ID.

How to eliminate wrong answers

Option B is wrong because resetting user passwords requires the Privileged Authentication Administrator or Password Administrator role, which includes write permissions to authentication methods. Option C is wrong because assigning administrative roles requires the Privileged Role Administrator role, which has write access to role assignments. Option D is wrong because creating new users requires the User Administrator or Global Administrator role, which includes write permissions to the directory.

238
MCQmedium

A company uses Microsoft 365 Business Premium. A user reports that when they try to access a file in SharePoint Online, they receive an error that the file is blocked by policy. The IT admin needs to identify which policy is blocking the file. Which tool should the admin use?

A.Microsoft Intune compliance policies
B.Microsoft Entra ID Conditional Access policies
C.Microsoft Defender for Cloud Apps session policies
D.Microsoft Purview Data Loss Prevention policies
AnswerD

Microsoft Purview Data Loss Prevention (DLP) policies are designed to detect and protect sensitive data across Microsoft 365 workloads, including SharePoint. A DLP policy can analyze files for sensitive content types, such as personally identifiable information, and then trigger actions like blocking external sharing or restricting access to specific users. Because it operates directly on the file's content and can execute file-level restrictions, it is the correct solution for blocking files in SharePoint based on their data sensitivity.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies are specifically designed to detect and block the sharing or access of sensitive information, such as credit card numbers or personally identifiable information, in Microsoft 365 services like SharePoint Online. When a file is blocked with a 'blocked by policy' error, it is typically because a DLP rule has matched the file's content and applied an action to restrict access. The admin can use the Microsoft Purview compliance portal to review DLP policy matches and identify the exact rule that triggered the block.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps session policies (which control user actions in real-time) with SharePoint's native DLP enforcement, but the 'blocked by policy' error is a direct result of a DLP policy applied at the SharePoint level, not a session-level control.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune compliance policies are used to enforce device configuration and security requirements (e.g., requiring a PIN or encryption) for managed devices, not to block specific files based on content in SharePoint Online. Option B is wrong because Microsoft Entra ID Conditional Access policies control access at the authentication and authorization level (e.g., requiring MFA or blocking sign-ins from untrusted locations), not the content-level blocking of individual files. Option C is wrong because Microsoft Defender for Cloud Apps session policies monitor and control user actions in real-time via reverse proxy (e.g., blocking downloads of sensitive data), but they do not produce a 'blocked by policy' error on the file itself; that error originates from SharePoint's native DLP enforcement.

239
MCQmedium

Which cloud deployment model provides the highest level of control over resources and infrastructure?

A.Public cloud
B.Private cloud
C.Hybrid cloud
D.Community cloud
AnswerB

A private cloud is a single-tenant environment dedicated exclusively to one organization, even if it is hosted off premises. It gives the organization full control over physical hardware, virtualization layers, networking, patching, and security policy, and allows deep customization to meet regulatory or performance requirements. This dedicated, isolated architecture is why it maximizes infrastructure control and governance.

Why this answer

The private cloud deployment model provides the highest level of control over resources and infrastructure because it is dedicated to a single organization, allowing full customization of hardware, networking, and security policies. Unlike public or hybrid models, the organization retains exclusive administrative access and can enforce strict compliance requirements without sharing underlying physical resources with other tenants.

Exam trap

The trap here is that candidates often confuse 'control' with 'scalability' or 'cost efficiency,' assuming hybrid cloud offers the best of both worlds, but the question specifically asks for the highest level of control, which only a private cloud provides due to its single-tenant, fully customizable nature.

How to eliminate wrong answers

Option A is wrong because the public cloud model shares infrastructure across multiple tenants via a multi-tenant architecture, limiting control over underlying hardware and network configurations. Option C is wrong because the hybrid cloud model combines public and private clouds, but the public cloud portion inherently reduces overall control due to shared infrastructure and provider-managed services. Option D is wrong because the community cloud model is shared among several organizations with common concerns, which dilutes individual control compared to a dedicated private cloud.

240
MCQmedium

A company is deploying Microsoft 365 and needs to ensure that external sharing of sensitive documents is blocked. Which Microsoft Purview feature should they configure?

A.Data Loss Prevention (DLP) policies
B.Sensitivity labels
C.Information Barriers
D.Retention policies
AnswerA

DLP policies inspect content and apply protective actions when sensitive information is detected, including blocking external sharing in SharePoint, OneDrive and Exchange. This directly satisfies the stem's constraint: preventing sensitive documents from leaving the tenant. Sensitivity labels classify and protect, but enforcement of sharing blocks relies on DLP rule conditions and actions.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies are designed to detect and block sensitive information (credit cards, SSNs, custom sensitive types) from being shared externally across Exchange, SharePoint, OneDrive, and Teams. DLP can enforce actions like blocking external sharing, encrypting content, or notifying users, which directly addresses the requirement to prevent external sharing of sensitive documents.

Exam trap

MS-900 often tests the confusion between sensitivity labels (classification/protection) and DLP (enforcement/blocking), tempting candidates to pick labels when the requirement is to block sharing.

How to eliminate wrong answers

Option B is wrong because sensitivity labels classify and protect content (encryption, watermarking) but do not by themselves block external sharing — they rely on DLP or sharing policies to enforce restrictions. Option C is wrong because Information Barriers restrict communication between specific groups of users (e.g., traders vs. research), not external sharing of documents. Option D is wrong because retention policies govern how long content is kept or deleted, not who can share it externally.

241
MCQeasy

A cloud provider uses a multi-tenant model where physical and virtual resources are dynamically assigned and reassigned according to consumer demand. This is an example of which cloud computing characteristic?

A.Rapid elasticity
B.Resource pooling
C.On-demand self-service
D.Measured service
AnswerB

Resource pooling is the NIST cloud characteristic that directly captures the multi-tenant model described: the provider's physical and virtual resources are pooled and dynamically assigned and reassigned to multiple consumers according to demand, with each tenant having no knowledge or control over the exact underlying resource location. This allows multiple customers to share the same physical hardware, hypervisor, storage arrays, and network fabric while maintaining logical isolation. Because the question specifically asks about a model where physical resources are shared among customers, resource pooling is the correct identifier.

Why this answer

Resource pooling is the correct answer because the multi-tenant model described involves the cloud provider pooling physical and virtual resources (e.g., compute, storage, network) to serve multiple consumers, with resources dynamically assigned and reassigned based on demand. This is a core characteristic of cloud computing as defined by NIST SP 800-145, where the provider's resources are pooled to achieve economies of scale while maintaining logical isolation between tenants.

Exam trap

The trap here is that candidates often confuse resource pooling with rapid elasticity because both involve dynamic resource assignment, but resource pooling specifically focuses on the multi-tenant sharing of a provider's resource pool, not the speed or automation of scaling.

How to eliminate wrong answers

Option A is wrong because rapid elasticity refers to the ability to quickly scale resources up or down, often automatically, to meet demand, not the pooling of resources across multiple tenants. Option C is wrong because on-demand self-service allows a consumer to provision computing capabilities unilaterally without requiring human interaction with the provider, which is a separate characteristic from resource pooling. Option D is wrong because measured service involves metering and monitoring resource usage (e.g., CPU hours, bandwidth) for billing and optimization, not the dynamic assignment of pooled resources to tenants.

242
MCQmedium

A user reports that they cannot access a SharePoint site that contains sensitive data. The administrator confirms the user is licensed and the site permissions are correct. What should the administrator check next?

A.Microsoft Defender for Office 365 Safe Attachments
B.Microsoft Purview retention policies
C.Microsoft Intune device compliance policies
D.Conditional Access policies in Microsoft Entra ID
AnswerD

Conditional Access policies in Microsoft Entra ID are designed to evaluate real-time signals, including user identity, IP location, device health, and sign-in risk, before granting access to cloud applications such as SharePoint Online. If the user falls outside policy requirements — for example, coming from an untrusted IP or not satisfying multi-factor authentication — the policy can block access entirely. The correct troubleshooting step is to inspect the Conditional Access tab in the Entra ID sign-in logs to see which policy was applied and why access was denied.

Why this answer

Conditional Access policies in Microsoft Entra ID are evaluated at sign-in and can block access to SharePoint Online based on user, device, location, or risk conditions — even when licensing and site permissions are correct. If the user's device is non-compliant, from an untrusted location, or the user fails an MFA requirement, Conditional Access will deny access to the SharePoint resource, which matches the symptom described.

Exam trap

MS-900 often tests the confusion between Intune compliance policies (which only report device state) and Conditional Access (which actually enforces access decisions) — candidates pick Intune when the question is about blocking access.

How to eliminate wrong answers

Option A is wrong because Defender for Office 365 Safe Attachments inspects email attachments for malware and does not gate SharePoint site access. Option B is wrong because Purview retention policies govern how long content is kept or deleted, not whether a user can open a site. Option C is wrong because Intune device compliance policies only mark a device as compliant or non-compliant — they do not themselves block access; enforcement happens through Conditional Access, which is the actual gatekeeper.

243
Multi-Selectmedium

A project team needs to collaborate on forms-based surveys and quizzes and co-author related Office files. Which two Microsoft 365 capabilities are most relevant?

Select 2 answers
A.Exchange anti-malware policy
B.SharePoint Online document storage
C.Microsoft Forms
D.Microsoft Purview eDiscovery case
AnswersB, C

SharePoint Online provides the foundational document storage and versioning capabilities necessary for project teams to co-author Office files. Its integration across Microsoft 365 enables multiple users to simultaneously edit Word, Excel, or PowerPoint documents related to their forms-based surveys and quizzes. This directly satisfies the requirement for co-authoring related Office files, facilitating efficient collaboration and centralised access for the team.

Why this answer

SharePoint Online provides document storage and co-authoring capabilities, enabling team members to simultaneously edit Office files (e.g., Word, Excel, PowerPoint) stored in document libraries. Microsoft Forms allows the team to create forms-based surveys and quizzes, with responses automatically collected and easily exportable to Excel for analysis.

Exam trap

The trap here is that candidates may confuse Microsoft Forms with other survey tools like Excel Online or Microsoft Lists, or mistakenly think Exchange anti-malware policy is relevant for collaboration, when it is solely an email security control.

244
MCQhard

A global organization relies on Microsoft 365 for critical business operations. They require guaranteed response times for support incidents: critical severity issues must receive an initial response within 15 minutes, and high severity within 1 hour. They also need proactive monitoring and advice from a designated support account manager. Which support plan should they purchase?

A.Microsoft 365 Standard Support (included with subscription)
B.Microsoft ProDirect Support
C.Microsoft Unified Support
D.Microsoft Premier Support
AnswerB

ProDirect Support is the correct choice because it provides the fastest guaranteed critical-severity response in the Microsoft 365 portfolio—15 minutes, compared to the 1-hour standard—and pairs that with a dedicated support account manager. This manager delivers proactive services such as incident avoidance, readiness assessments, and architectural guidance, making it ideal for a global organization where downtime has immediate operational impact.

Why this answer

ProDirect Support is the correct choice because it offers guaranteed response times of 15 minutes for critical severity incidents and 1 hour for high severity incidents, along with proactive monitoring and a designated support account manager. This plan is specifically designed for organizations that require rapid, managed support for critical business operations, unlike the standard or legacy plans.

Exam trap

The trap here is that candidates often confuse ProDirect Support with Premier Support, assuming Premier is the only premium option, but ProDirect is the correct modern plan for cloud-focused organizations needing guaranteed response times and a designated account manager.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 Standard Support (included with subscription) does not provide guaranteed response times or a designated account manager; it offers only basic reactive support with no service level agreements (SLAs) for initial response. Option C is wrong because Microsoft Unified Support is a legacy plan that has been retired and replaced by ProDirect and Premier; it does not offer the specific 15-minute critical response guarantee or a dedicated account manager in the same way. Option D is wrong because Microsoft Premier Support is a separate, higher-cost plan typically for on-premises and hybrid environments, and while it offers fast response times, it is not the standard plan for Microsoft 365 cloud services and does not include proactive monitoring as a core feature like ProDirect does.

245
MCQmedium

A compliance administrator needs to apply encryption and usage restrictions to confidential documents. Which Microsoft 365 capability is the best fit?

A.OneDrive sync client
B.Sensitivity labels
C.Microsoft Bookings
D.Microsoft Teams live events
AnswerB

Sensitivity labels apply persistent encryption and usage restrictions that travel with the document, satisfying the compliance requirement. They enforce protection regardless of where the file is stored or shared, unlike retention or DLP policies alone.

Why this answer

Sensitivity labels from Microsoft Purview Information Protection are the correct choice because they allow the compliance administrator to apply both encryption and usage restrictions (such as 'Do Not Forward' or custom permissions) directly to confidential documents. This capability integrates with Microsoft 365 apps to enforce protection persistently, even when the document is shared outside the organization.

Exam trap

The trap here is that candidates often confuse the OneDrive sync client's ability to sync encrypted files with the ability to apply encryption itself, or they mistakenly think Microsoft Teams live events can restrict document usage because it is a 'live' feature with attendee controls.

How to eliminate wrong answers

Option A is wrong because the OneDrive sync client is a file synchronization tool that syncs files between cloud and local devices; it does not apply encryption or usage restrictions to documents. Option C is wrong because Microsoft Bookings is a scheduling and appointment management tool, with no capability to enforce document-level encryption or usage restrictions. Option D is wrong because Microsoft Teams live events is a broadcast and streaming feature for large audiences; it does not provide document-level encryption or usage restriction controls.

246
Multi-Selecthard

Which TWO Microsoft 365 services are specifically designed to help organizations manage and monitor data compliance?

Select 2 answers
A.Microsoft Purview Communication Compliance
B.Microsoft Defender for Office 365
C.Microsoft Intune
D.Microsoft Sentinel
E.Microsoft Purview
AnswersA, E

Microsoft Purview Communication Compliance uses machine-learning classifiers to detect inappropriate or risky messages across Teams, Exchange and Viva Engage, surfacing them for reviewer triage. It satisfies the stem's requirement for a service specifically built to manage and monitor data compliance.

Why this answer

Microsoft Purview Communication Compliance (A) is a purpose-built compliance solution that uses policies and machine learning to detect, triage, and remediate inappropriate or risky communications across Teams, Exchange, and other channels, making it a core data-compliance monitoring service. Microsoft Purview (E) is the overarching compliance platform that provides data mapping, classification, sensitivity labels, Data Loss Prevention, Insider Risk Management, and audit/eDiscovery capabilities for managing and monitoring compliance across the organization's data estate. Microsoft Defender for Office 365 (B) is a threat-protection service focused on phishing, malware, and zero-day attacks rather than compliance management.

Microsoft Intune (C) is a mobile device and endpoint management (MDM/MAM) service for enforcing configuration and app policies, not a data-compliance monitoring tool. Microsoft Sentinel (D) is a cloud-native SIEM/SOAR platform for security analytics, threat detection, and incident response, not a dedicated compliance-management service.

Exam trap

MS-900 often tests the distinction between security and compliance services, causing candidates to confuse Defender for Office 365 or Sentinel as compliance tools when they are primarily security-focused.

247
MCQmedium

A multinational corporation uses Microsoft 365 E5. The IT team needs to provide users with a single integrated workspace that combines chat, file sharing, online meetings, and app integration, while also allowing external guests to collaborate on projects. Which Microsoft 365 service should they deploy?

A.SharePoint Online
B.Exchange Online
C.Microsoft Teams
D.Yammer
AnswerC

Microsoft Teams provides a hub for teamwork that integrates chat, file sharing, online meetings, and third-party and Microsoft app integration. It supports guest access, allowing external partners to collaborate in teams and channels. This matches the requirement for a single integrated workspace with external collaboration capabilities, making Teams the appropriate service.

Why this answer

Microsoft Teams is the correct service because it delivers a unified workspace with chat, file sharing, online meetings, and app integration, and it supports guest access for external collaboration. SharePoint Online, Exchange Online, and Yammer each provide only a subset of these capabilities and cannot serve as the integrated hub described.

Exam trap

The trap here is selecting SharePoint Online for collaboration because it handles files and external sharing, but it lacks integrated chat and meetings, which are central to the requirement.

248
MCQmedium

An administrator is reviewing a request from users who need to detect risky users and suspicious sign-ins. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Entra ID Protection
B.Microsoft Planner
C.Microsoft Stream
D.Microsoft Forms
AnswerA

Microsoft Entra ID Protection is the correct answer because it is the Microsoft Entra security service that detects identity-related risks, specifically risky users and risky sign-ins, in a Microsoft 365 tenant. It uses machine learning on authentication patterns, impossible travel, leaked credentials, and suspicious user behavior to generate risk detections, and these detections can be automated via Conditional Access policies to require MFA or block access.

Why this answer

Microsoft Entra ID Protection is the correct choice because it is specifically designed to detect risky users and suspicious sign-ins by analyzing signals such as leaked credentials, anonymous IP addresses, and atypical travel patterns. It uses risk-based conditional access policies to automatically block or require multi-factor authentication for high-risk sign-ins, directly addressing the administrator's requirement.

Exam trap

The trap here is that candidates may confuse Microsoft Entra ID Protection with other Microsoft 365 security tools like Defender for Cloud Apps or Azure AD Identity Governance, but the question specifically asks for the capability that detects risky users and suspicious sign-ins, which is uniquely Entra ID Protection's core function.

How to eliminate wrong answers

Option B (Microsoft Planner) is wrong because it is a task management and project planning tool, not a security or identity capability; it cannot detect risky users or sign-ins. Option C (Microsoft Stream) is wrong because it is a video sharing and management service for enterprise content, lacking any identity protection or risk detection features. Option D (Microsoft Forms) is wrong because it is a survey and data collection tool, with no capability to analyze sign-in risks or user behavior for security purposes.

249
MCQhard

A multinational organization has a Microsoft 365 E5 subscription for 10,000 users. Some users in a subsidiary require only email and basic office apps. The IT department wants to reduce costs by reassigning licenses without losing any existing functionality for those users. What is the most cost-effective licensing strategy?

A.Keep all users on E5 but reduce the number of licenses
B.Downgrade those users to Microsoft 365 E3 licenses
C.Switch to Microsoft 365 E1 licenses for those users
D.Assign Microsoft 365 Business Basic licenses to those users
AnswerB

Microsoft 365 E3 provides the same core productivity tools as E5—Exchange Online, Teams, SharePoint, and the fully installed Office desktop apps (Word, Excel, PowerPoint)—but omits E5-only advanced security, compliance, and analytics features. Downgrading the specified users to E3 replaces an expensive SKU with a lower-cost enterprise SKU that still meets the stated requirement for email and Office apps. This is the correct cost-optimization action because it reduces per-user licensing expense without sacrificing any required functionality.

Why this answer

Microsoft 365 E3 provides the same core functionality as E5—Exchange Online, SharePoint, Teams, and desktop Office apps—but lacks E5's advanced security and analytics features (e.g., Microsoft Defender for Office 365 Plan 2, Microsoft Purview, Power BI Pro). Downgrading users who need only email and basic Office apps to E3 reduces per-user licensing cost while preserving all required functionality, making it the most cost-effective strategy.

Exam trap

The trap here is that candidates may assume E1 is sufficient because it includes Exchange Online and web apps, but they overlook the explicit requirement for 'basic office apps'—which in Microsoft's licensing context means the desktop Office suite, available only in E3/E5 or Business versions, not in E1.

How to eliminate wrong answers

Option A is wrong because keeping all users on E5 but reducing the number of licenses does not address the subsidiary users' needs—they still require licenses, and reducing the total count would leave some users unlicensed, violating compliance. Option C is wrong because Microsoft 365 E1 lacks desktop Office apps (Word, Excel, PowerPoint), which the subsidiary users require per the scenario; E1 only includes web and mobile versions, not the full Office client. Option D is wrong because Microsoft 365 Business Basic is designed for organizations with up to 300 users, not for 10,000 users in an enterprise environment, and it also lacks desktop Office apps, failing the requirement for 'basic office apps.'

250
MCQeasy

A department asks for the Microsoft 365 service best suited for Teams channel conversations and meetings. Which service should they use?

A.Microsoft Entra Privileged Identity Management
B.Microsoft Defender for Endpoint
C.Microsoft Purview Compliance Manager
D.Microsoft Teams
AnswerD

Microsoft Teams is the central collaboration hub in Microsoft 365, bringing together persistent chat, online meetings, calling, and file sharing with coauthoring through SharePoint and OneDrive. It supports team channels, tabs for apps, and real-time communication, which are exactly the capabilities a department of coworkers needs to work together efficiently. This makes Teams the correct choice for the request.

Why this answer

Microsoft Teams is the correct service because it is specifically designed to host channel-based conversations and meetings within Microsoft 365. Teams provides persistent chat channels, audio/video conferencing, and meeting scheduling, directly fulfilling the department's request.

Exam trap

The trap here is that candidates may confuse Microsoft Teams with other Microsoft 365 services that have 'management' or 'compliance' in their names, assuming they support collaboration features, when in fact they are specialized for identity, security, or compliance tasks.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Privileged Identity Management is an identity governance tool for managing, controlling, and monitoring access to Azure AD roles, not for conversations or meetings. Option B is wrong because Microsoft Defender for Endpoint is a security solution for endpoint detection and response (EDR) and vulnerability management, not a collaboration platform. Option C is wrong because Microsoft Purview Compliance Manager is a compliance management solution for assessing and managing regulatory compliance risks, not for real-time communication.

251
MCQeasy

A user needs to access their work files from a personal device without storing a copy locally. Which Microsoft 365 app should they use?

A.Microsoft Outlook
B.OneDrive for Business
C.Microsoft Teams
D.Microsoft SharePoint
AnswerB

OneDrive for Business is the correct answer because it provides Files On-Demand, which lets users access all their work files in the cloud without requiring them to be downloaded to the device. When a user signs into OneDrive for Business with their work account on a personal device, they can stream files from the cloud, browse the entire library, and open files on demand, consuming minimal local storage. It is specifically designed to give users a personal document library that syncs across work and personal devices while maintaining compliance and security policies.

Why this answer

OneDrive for Business enables users to access work files from any device via the cloud, with the option to stream files on demand without downloading them locally. This is achieved through Files On-Demand, which uses placeholder files and syncs only metadata, ensuring no full copy is stored on the personal device unless explicitly made available offline.

Exam trap

The trap here is that candidates may confuse SharePoint's web-based access with the ability to prevent local storage, overlooking that OneDrive for Business is the only option with a dedicated Files On-Demand feature that explicitly avoids storing a full copy locally on personal devices.

How to eliminate wrong answers

Option A is wrong because Microsoft Outlook is an email and calendar client, not designed for file storage or remote access without local copies; it downloads attachments locally by default. Option C is wrong because Microsoft Teams primarily focuses on chat, meetings, and collaboration, and while it can access files from SharePoint or OneDrive, it does not provide a dedicated mechanism to prevent local storage of files on personal devices. Option D is wrong because Microsoft SharePoint is a web-based document management and collaboration platform that can be accessed via browser, but it does not natively offer a Files On-Demand feature to prevent local caching; files opened from SharePoint in a browser may still be cached locally by the browser or Office apps.

252
Multi-Selectmedium

Which TWO are key capabilities of Microsoft Defender for Cloud Apps? (Choose two.)

Select 2 answers
A.Email encryption and secure messaging
B.Device compliance policy enforcement
C.On-device malware scanning
D.Cloud Discovery to identify shadow IT
E.Session control to monitor and control app access in real-time
AnswersD, E

Cloud Discovery analyses traffic logs from firewalls and proxies to catalogue which cloud apps employees actually use, exposing unsanctioned shadow IT. That visibility is the capability the stem asks for, distinct from session or access controls.

Why this answer

Option D (Cloud Discovery to identify shadow IT) is correct because Defender for Cloud Apps uses Cloud Discovery to analyze traffic logs from firewalls and proxies (or via the Defender for Endpoint integration) to detect unsanctioned SaaS apps, giving organizations visibility into shadow IT. Option E (Session control to monitor and control app access in real-time) is correct because Conditional Access App Control uses a reverse proxy to enforce real-time session policies, such as blocking downloads or uploads, on cloud apps. Option A is incorrect because email encryption and secure messaging are capabilities of Microsoft Purview (Exchange Online/Message Encryption), not Defender for Cloud Apps.

Option B is incorrect because device compliance policy enforcement is handled by Microsoft Intune and Conditional Access, not Defender for Cloud Apps. Option C is incorrect because on-device malware scanning is provided by Microsoft Defender for Endpoint, not Defender for Cloud Apps.

Exam trap

MS-900 often tests the distinction between Defender for Cloud Apps and other Microsoft security services; candidates might confuse email encryption (Purview) or device compliance (Intune) as features of Defender for Cloud Apps.

253
MCQeasy

A team needs to create a shared online document and collaborate in real time with colleagues. They require built-in version history and the ability to access the document from any device. Which Microsoft 365 app should they use?

A.Microsoft Word (desktop)
B.Microsoft Word Online
C.Microsoft OneNote
D.Microsoft Teams
AnswerB

Microsoft Word Online is the correct choice because it runs entirely in a web browser, so no software installation is required and it works on any device with internet access. It provides full real-time co-authoring with presence indicators, automatic saving, and version history through OneDrive or SharePoint. This makes the shared document instantly accessible and lets multiple people edit simultaneously without extra setup.

Why this answer

Microsoft Word Online is the correct choice because it is a browser-based version of Word that enables real-time co-authoring, automatic version history, and access from any device with an internet connection. Unlike the desktop app, it does not require installation and syncs changes instantly via OneDrive or SharePoint, meeting all stated requirements.

Exam trap

The trap here is that candidates often confuse Microsoft Teams as the app for document collaboration, but Teams itself is a hub for communication and relies on integrated Office Online apps for actual document editing, making Word Online the direct answer for the specific requirements of shared document creation and real-time collaboration.

How to eliminate wrong answers

Option A is wrong because Microsoft Word (desktop) requires installation on a specific device, lacks built-in real-time co-authoring without additional configuration (e.g., saving to OneDrive with AutoSave enabled), and does not inherently provide cross-device access without manual file transfer. Option C is wrong because Microsoft OneNote is a digital notebook app designed for free-form note-taking and organization, not for creating structured shared documents with the same real-time collaboration and version history features as Word Online. Option D is wrong because Microsoft Teams is a collaboration platform for chat, meetings, and channel-based file sharing, but its document editing capabilities rely on integrated Office Online apps (like Word Online) rather than providing a standalone document creation and editing experience.

254
MCQmedium

A tenant administrator is advising a department that wants to deploy application code without maintaining the operating system or runtime platform. Cloud concept or benefit best matches this requirement?

A.Private cloud
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Software as a Service (SaaS)
AnswerB

PaaS supplies the managed runtime and operating system, so the department deploys only its application code. This removes the need to patch or maintain the OS and platform layers, matching the stated requirement; IaaS would still leave those responsibilities with the department.

Why this answer

Platform as a Service (PaaS) provides a platform for developing, running, and managing applications without the complexity of building and maintaining the underlying infrastructure. The department wants to deploy application code without managing the OS or runtime, which is exactly what PaaS offers. IaaS provides raw compute, storage, and network but requires OS management; SaaS provides fully functional applications; private cloud is a deployment model, not a service model.

Exam trap

The trap is confusing PaaS with IaaS. Candidates might think that not managing the OS means IaaS, but IaaS still requires OS management; PaaS goes further by managing the runtime and middleware.

How to eliminate wrong answers

Option A is wrong because private cloud is a deployment model (dedicated to one organization) and does not specify the level of management abstraction. Option C is wrong because IaaS requires the customer to manage the OS and runtime, which contradicts the requirement. Option D is wrong because SaaS provides a complete application, not a platform for deploying custom code.

255
MCQhard

A legal team needs to preserve all data belonging to a former employee who is involved in litigation. The preservation must cover Exchange Online email, SharePoint sites, Teams messages, and OneDrive files. Which Microsoft Purview solution should they use to enforce the preservation?

A.eDiscovery (Standard) case hold
B.Data Lifecycle Management retention policy
C.Sensitivity label with retention marking
D.Audit log search
AnswerA

eDiscovery (Standard) case hold creates a preservation hold within a Microsoft Purview eDiscovery case. It lets the legal team target a former employee's Exchange Online mailbox, OneDrive for Business, SharePoint sites, and Teams content, and all items in those locations are held in place, including metadata and versions. Because the hold is Custodian-based and applies organization-wide to the employee's data, it satisfies the requirement to preserve all data for legal proceedings.

Why this answer

eDiscovery (Standard) case hold is the correct solution because it allows legal teams to place a legal hold on all data sources associated with a specific user, including Exchange Online mailboxes, SharePoint sites, OneDrive accounts, and Teams messages. This preserves the data in its current state, preventing modification or deletion, which is essential for litigation. Unlike other options, eDiscovery holds are designed specifically for legal preservation scenarios and can target multiple workloads simultaneously.

Exam trap

The trap here is that candidates often confuse a retention policy (which is automated and rule-based) with a legal hold (which is manual, case-specific, and preserves data for litigation), leading them to choose Data Lifecycle Management instead of eDiscovery.

How to eliminate wrong answers

Option B is wrong because Data Lifecycle Management retention policies are designed for automated data retention and deletion based on regulatory or business rules, not for ad-hoc legal holds triggered by litigation. Option C is wrong because sensitivity labels with retention markings are used to classify and optionally retain data based on sensitivity, but they cannot enforce a comprehensive legal hold across all user data sources like eDiscovery can. Option D is wrong because Audit log search is a tool for reviewing historical activity logs, not for preserving data; it does not prevent data modification or deletion.

256
MCQmedium

A school uses Microsoft 365 A3 for faculty and staff. They want to create a hub for teachers to share lesson plans, collaborate on documents, and communicate via instant messaging. They also need to integrate with third-party educational apps. Which Microsoft 365 service should they use as the primary platform?

A.Yammer
B.SharePoint Online
C.OneNote for Windows 10
D.Microsoft Teams
AnswerD

Microsoft Teams is purpose-built as the collaboration hub in Microsoft 365, combining persistent threaded chat, VoIP and video meetings, file sharing, and third-party app integration in one application surface. Teams uses SharePoint Online for files, Exchange Online for calendar/chat infrastructure, and OneNote for notebook tabs, but it is the orchestrating layer that presents those services cohesively. For a school on A3, Teams gives faculty and staff a single place to transition from chat to meeting to a shared document without switching tools.

Why this answer

Microsoft Teams is the correct primary platform because it integrates chat, document collaboration (via SharePoint and OneDrive), and third-party app connectors into a single hub. For teachers sharing lesson plans, collaborating on documents, and using instant messaging, Teams provides persistent chat, file sharing, and a rich app ecosystem that supports third-party educational app integration through tabs, connectors, and bots.

Exam trap

The trap here is that candidates often confuse Yammer's social networking features with Teams' real-time collaboration capabilities, or they assume SharePoint alone can fulfill all communication needs, missing the requirement for instant messaging and integrated third-party apps.

How to eliminate wrong answers

Option A is wrong because Yammer is an enterprise social network focused on broad organizational conversations and communities, not a real-time collaboration hub for instant messaging and document co-authoring. Option B is wrong because SharePoint Online is a document management and intranet platform; while it stores and shares files, it lacks native instant messaging and real-time chat capabilities. Option C is wrong because OneNote for Windows 10 is a digital note-taking app, not a platform for instant messaging, collaborative document editing, or third-party app integration.

257
Multi-Selecthard

Your company is adopting Microsoft 365 Copilot and wants to ensure that data security and compliance requirements are met. Which THREE considerations should be addressed? (Choose three.)

Select 3 answers
A.Configure policies in the Microsoft 365 admin center to manage Copilot features.
B.Disable Copilot for all users if any compliance requirement cannot be met.
C.Use sensitivity labels to control what data Copilot can access.
D.Verify that data processed by Copilot is stored in the same geographic region as the tenant.
E.Ensure that Microsoft 365 Copilot inherits the compliance settings from the underlying Microsoft 365 services.
AnswersA, C, E

Configuring policies in the Microsoft 365 admin centre directly governs which Copilot features surface to users, satisfying the stem's requirement to control Copilot behaviour. It also lets administrators restrict data access and apply compliance boundaries, ensuring Copilot operates within the company's security and regulatory constraints.

Why this answer

Option A is correct because the Microsoft 365 admin center is where administrators configure Copilot policies and controls, such as which users can access Copilot and how its features behave, which is essential for meeting security and compliance requirements. Option C is correct because sensitivity labels from Microsoft Purview Information Protection are honored by Microsoft 365 Copilot, so labeling content helps govern what data Copilot can surface and process, directly supporting data security and compliance. Option E is correct because Microsoft 365 Copilot does not have a separate compliance boundary; it inherits the compliance, security, and data-handling settings of the underlying Microsoft 365 services (for example, Purview, DLP, retention, and eDiscovery), so verifying this inheritance is a key consideration.

Option B is not correct because disabling Copilot for all users is a drastic, non-granular response rather than a proper compliance consideration, and Copilot can be scoped or governed through policies instead. Option D is not correct because Copilot data is processed within the Microsoft 365 service boundary and follows the tenant's existing data residency commitments; there is no separate requirement to verify that Copilot stores data in the same geographic region as the tenant.

Exam trap

MS-900 often tests the misconception that Copilot requires separate compliance configurations, when in fact it inherits existing Microsoft 365 compliance settings, and the key considerations are policy management, sensitivity labels, and inheritance.

258
MCQmedium

A compliance-aware administrator is selecting the right Microsoft 365 capability to guide assignment of Microsoft 365 admin roles. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Microsoft Stream
C.Least privilege
D.Microsoft Forms
AnswerC

Least privilege is the correct security principle, stating that users and administrators should receive only the permissions necessary for their assigned tasks. This minimizes the attack surface, limits exposure of sensitive data, and satisfies compliance obligations such as ISO/IEC 27001 and Microsoft's Zero Trust model. Unlike the product options, least privilege is an architectural concept that directly guides role and permission design within Microsoft 365.

Why this answer

The principle of least privilege is the most relevant concept for guiding assignment of Microsoft 365 admin roles because it dictates that administrators should be granted only the permissions necessary to perform their job functions, minimizing security risks. This directly aligns with compliance requirements by ensuring that no user has excessive access to sensitive administrative functions. The other options (Whiteboard, Stream, Forms) are productivity or collaboration tools unrelated to role-based access control or compliance.

Exam trap

The trap here is that candidates may confuse productivity tools (like Whiteboard, Stream, or Forms) with governance concepts, failing to recognize that 'least privilege' is the only option directly tied to role assignment and compliance in Microsoft 365.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a digital canvas collaboration tool, not a concept for assigning admin roles or managing permissions. Option B is wrong because Microsoft Stream is a video service for recording and sharing content, unrelated to role-based access control or least privilege. Option D is wrong because Microsoft Forms is a survey and quiz creation tool, which has no bearing on admin role assignment or compliance-driven access management.

259
MCQmedium

A product design team wants to conduct remote brainstorming sessions where participants can draw, write sticky notes, and add images on a shared canvas in real time. Which Microsoft 365 app should they use?

A.Microsoft To Do
B.Microsoft Whiteboard
C.Microsoft Forms
D.Microsoft Planner
AnswerB

Microsoft Whiteboard provides an infinite digital canvas in Microsoft 365 with real-time co-authoring, so multiple remote participants can simultaneously draw, write, and arrange sticky notes during a Teams meeting. It supports pressure-sensitive inking on pen-enabled devices, image insertion, and automatic cloud sync via the Whiteboard service, which makes it purpose-built for visual brainstorming and ad-hoc diagramming. This freeform environment is exactly what remote ideation demands.

Why this answer

Microsoft Whiteboard is the correct choice because it provides a free-form digital canvas that supports real-time collaboration, including drawing, sticky notes, and image insertion. This directly meets the requirement for remote brainstorming sessions where participants need to interact on a shared canvas simultaneously.

Exam trap

The trap here is that candidates may confuse Microsoft Planner's task boards with a collaborative canvas, but Planner is strictly for task tracking, not for free-form drawing or sticky note brainstorming.

How to eliminate wrong answers

Option A is wrong because Microsoft To Do is a task management app focused on personal to-do lists and reminders, not a collaborative canvas for drawing or sticky notes. Option C is wrong because Microsoft Forms is used for creating surveys, quizzes, and polls, not for real-time visual collaboration or drawing. Option D is wrong because Microsoft Planner is a project management tool for organizing tasks and plans with boards, not a shared canvas for brainstorming activities.

260
Multi-Selecteasy

A company uses Microsoft 365 Business Premium. They want to deploy a cloud-based phone system for their employees. Which TWO services should they use?

Select 2 answers
A.Teams Audio Conferencing
B.Direct Routing
C.Calling Plan
D.Microsoft Bookings
E.Microsoft Teams Phone System
AnswersC, E

A Calling Plan is the Microsoft-provided PSTN service that assigns a phone number and includes a pool of domestic or international minutes to make and receive external calls. It pairs directly with the Teams Phone System, and it is the simplest way to enable cloud calling in Microsoft 365 Business Premium. Without a Calling Plan (or Direct Routing), users can only make internal Teams calls, so it is a correct core component.

Why this answer

Microsoft Teams Phone System (formerly Cloud PBX) provides the core PBX functionality—call control, voicemail, and auto attendants—while a Calling Plan (Microsoft's first-party PSTN connectivity) supplies the phone numbers and minutes to make/receive external calls. Together they form a complete cloud phone system without any on-premises infrastructure.

Exam trap

The trap here is that candidates confuse Teams Audio Conferencing (meeting dial-in) with the phone system, or think Direct Routing is a cloud-only option when it actually requires on-premises hardware.

261
MCQmedium

A help desk lead is documenting the correct Microsoft 365 approach to allow browser access to SharePoint from unmanaged devices but restrict downloads. Microsoft security, identity, or compliance capability should it use?

A.Conditional Access access/session controls
B.Microsoft Forms
C.Microsoft Stream
D.Microsoft Planner
AnswerA

Conditional Access access/session controls are the correct security mechanism because they enforce organization-defined policies directly at the identity layer of Microsoft 365 and Azure AD. Access controls evaluate sign-in signals such as device compliance, user risk, and location to grant or block access, while session controls refine the user experience after authentication—for instance, limiting downloads or forcing reauthentication in cloud apps. Together, they enable a help desk to implement device state–based restrictions such as 'Allow only compliant devices,' which is exactly the documented requirement.

Why this answer

Conditional Access access/session controls allow administrators to enforce granular restrictions on browser access to SharePoint from unmanaged devices, such as blocking download of sensitive content while still permitting view-only access. This is achieved through session policies that integrate with Microsoft Defender for Cloud Apps (formerly Cloud App Security) to apply real-time controls at the protocol level, without requiring device enrollment or compliance.

Exam trap

The trap here is that candidates often confuse Conditional Access with device compliance policies or Intune, but session controls are specifically designed for unmanaged devices where you cannot enforce device-level restrictions, and they operate at the application layer rather than requiring device enrollment.

How to eliminate wrong answers

Option B (Microsoft Forms) is wrong because it is a survey and data collection tool, not a security or access control mechanism for SharePoint. Option C (Microsoft Stream) is wrong because it is a video hosting and sharing service, unrelated to managing device access or download restrictions for SharePoint. Option D (Microsoft Planner) is wrong because it is a task management and planning tool, lacking any capability to enforce conditional access or session-level policies.

262
MCQmedium

A cloud provider serves thousands of customers using the same physical hardware. Each customer's data and applications are isolated from one another through virtualization. The provider can dynamically allocate resources to customers based on demand. Which cloud characteristic does this describe?

A.Resource pooling
B.On-demand self-service
C.Rapid elasticity
D.Measured service
AnswerA

Resource pooling is the NIST cloud characteristic that directly describes the provider serving thousands of customers using the same physical infrastructure. In this multi-tenant model, the provider's computing, storage, network, and other resources are pooled and dynamically assigned and reassigned to consumers based on demand, with each tenant unaware of or lacking control over the exact underlying hardware location. This is precisely the scenario in the question, making it the correct answer.

Why this answer

This scenario describes resource pooling, where the cloud provider's computing resources (e.g., storage, processing, memory, network bandwidth) are pooled to serve multiple customers using a multi-tenant model. Virtualization isolates each customer's data and applications, while physical and virtual resources are dynamically assigned and reassigned according to consumer demand. This is a core characteristic of cloud computing as defined by NIST SP 800-145.

Exam trap

The trap here is that candidates often confuse 'resource pooling' with 'rapid elasticity' because both involve dynamic allocation, but resource pooling is about the multi-tenant sharing of physical infrastructure, while elasticity is about the speed and automation of scaling resources up or down.

How to eliminate wrong answers

Option B (On-demand self-service) is wrong because that characteristic describes a user's ability to provision computing capabilities automatically without requiring human interaction with the service provider, not the sharing of physical hardware. Option C (Rapid elasticity) is wrong because elasticity refers to the ability to scale resources up or down quickly and automatically in response to demand, not the underlying pooling of resources across tenants. Option D (Measured service) is wrong because measured service involves metering and monitoring resource usage for billing and optimization, not the isolation and dynamic allocation of shared physical hardware.

263
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to use provider-managed infrastructure shared by multiple customers. Cloud concept or benefit best matches this requirement?

A.Public cloud
B.Data Loss Prevention (DLP)
C.Sensitivity labels
D.Microsoft Planner
AnswerA

Public cloud delivers provider-managed compute, storage and networking shared across multiple tenants, exactly matching the shared-infrastructure requirement. Microsoft, Amazon and Google own and operate the hardware, so the organisation consumes pooled capacity rather than dedicated private resources.

Why this answer

The requirement for provider-managed infrastructure shared by multiple customers directly maps to the public cloud deployment model. In a public cloud, the cloud provider owns and manages the physical hardware, software, and supporting infrastructure, which is shared across multiple tenants (multi-tenancy). This is the core definition of public cloud as opposed to private or hybrid models.

Exam trap

The trap here is that candidates may confuse a specific Microsoft 365 feature (like DLP or sensitivity labels) with a cloud deployment model, failing to recognize that the question is asking about the fundamental cloud concept of shared, provider-managed infrastructure, not a security or productivity tool.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) is a security policy feature within Microsoft 365 that helps prevent sensitive information from being shared or leaked; it does not describe a cloud deployment model or infrastructure sharing concept. Option C is wrong because sensitivity labels are classification and protection tools applied to documents and emails to enforce access controls and encryption; they are not a cloud concept related to shared infrastructure. Option D is wrong because Microsoft Planner is a task management and collaboration application within Microsoft 365; it is a specific service, not a cloud concept or benefit describing how infrastructure is deployed or shared.

264
MCQhard

A global organization with 20,000 users is migrating from on-premises Exchange to Exchange Online. They have a mix of Microsoft 365 E3 and E5 licenses. The compliance team requires that all mailboxes be placed on litigation hold within 24 hours of the migration. Which licensing consideration is critical?

A.All users must have Microsoft 365 E5 licenses to use litigation hold
B.Downgrade E5 users to E3 to simplify licensing
C.Litigation hold is automatically enabled for all mailboxes in Exchange Online
D.Users with E3 licenses need an Exchange Online Plan 2 add-on for litigation hold
AnswerD

In Microsoft 365, litigation hold is a mailbox-specific compliance feature that requires the mailbox to be assigned Exchange Online Plan 2. Standard E3 licenses include Exchange Online Plan 1, which lacks the necessary capabilities for litigation hold. Therefore, an E3 user must purchase the Exchange Online Plan 2 add-on to enable litigation hold. This is the correct licensing approach for organizations needing this preservation feature without upgrading to E5.

Why this answer

Litigation hold in Exchange Online requires an Exchange Online Plan 2 license or an Exchange Online Plan 1 license with the Exchange Online Archiving add-on. Microsoft 365 E3 includes Exchange Online Plan 1, which does not support litigation hold by itself. Therefore, users with E3 licenses need the Exchange Online Plan 2 add-on (or the equivalent Archiving add-on) to enable litigation hold.

E5 licenses include Exchange Online Plan 2, so those users already have the necessary licensing.

Exam trap

The trap here is that candidates often assume litigation hold is a standard feature available with any Exchange Online license, but Microsoft specifically requires Exchange Online Plan 2 (included in E5 or as an add-on to E3) for this capability.

How to eliminate wrong answers

Option A is wrong because Microsoft 365 E5 licenses include Exchange Online Plan 2, which supports litigation hold, but E3 users can also get litigation hold via an add-on; E5 is not mandatory for all users. Option B is wrong because downgrading E5 users to E3 would remove their built-in litigation hold capability, requiring additional add-ons and complicating compliance. Option C is wrong because litigation hold is not automatically enabled for all mailboxes; it must be explicitly configured by an administrator, and it requires appropriate licensing.

265
MCQmedium

An organization uses Microsoft Defender XDR and wants to investigate a potential ransomware attack. Which portal should the security team use to see the full attack timeline?

A.Microsoft Purview compliance portal
B.Microsoft Sentinel
C.Azure portal
D.Microsoft 365 Defender portal
AnswerD

The Microsoft 365 Defender portal correlates alerts across endpoints, identities, email and cloud apps into a unified incident view, presenting the complete attack timeline. Defender XDR's cross-domain correlation is what surfaces the full ransomware progression the team needs to investigate.

Why this answer

The Microsoft 365 Defender portal (security.microsoft.com) is the unified investigation surface for Microsoft Defender XDR, where incidents, alerts, and the full attack timeline are correlated across endpoints, identities, email, and cloud apps. It provides the incident graph and timeline view needed to trace a ransomware attack end-to-end. Microsoft Sentinel is a SIEM/SOAR platform, not the native Defender XDR investigation portal.

Exam trap

MS-900 often tests the confusion between the Microsoft 365 Defender portal and Microsoft Sentinel — candidates pick Sentinel because it sounds like the 'security investigation' tool, missing that Defender XDR's native attack timeline lives in security.microsoft.com.

How to eliminate wrong answers

Option A is wrong because the Microsoft Purview compliance portal is for data governance, eDiscovery, compliance, and insider risk — it does not present the Defender XDR attack timeline. Option B is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR that ingests logs and builds its own incidents; it is not the portal where Defender XDR's native attack timeline is displayed. Option C is wrong because the Azure portal is the management plane for Azure resources and does not surface the unified Defender XDR incident timeline.

266
MCQmedium

A business stakeholder asks how Microsoft 365 can help them guide assignment of Microsoft 365 admin roles. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Whiteboard
B.Microsoft Stream
C.Least privilege
D.Microsoft Forms
AnswerC

Least privilege restricts each admin to only the permissions their role requires, directly guiding how Microsoft 365 admin roles are assigned. This limits blast radius from compromised or misused accounts, satisfying the stakeholder's need to govern role assignment securely rather than granting broad standing access.

Why this answer

The principle of least privilege is the most relevant concept for guiding assignment of Microsoft 365 admin roles. It dictates that users should be granted only the minimum permissions necessary to perform their job functions, which directly applies to assigning admin roles to reduce security risks. This is a core security and identity concept within Microsoft 365, not a specific application or service.

Exam trap

The trap here is that candidates may confuse productivity tools (Whiteboard, Stream, Forms) with security or administrative concepts, failing to recognize that 'least privilege' is a fundamental security principle directly tied to role assignment in Microsoft 365.

How to eliminate wrong answers

Option A is wrong because Microsoft Whiteboard is a digital canvas application for collaboration, not related to admin role assignment or security principles. Option B is wrong because Microsoft Stream is a video service for recording and sharing content, not a tool for managing admin permissions. Option D is wrong because Microsoft Forms is a survey and quiz creation tool, irrelevant to the principle of assigning admin roles with minimal permissions.

267
MCQmedium

A department asks for the Microsoft 365 service best suited for forms-based surveys and quizzes. Which service should they use?

A.Microsoft Entra Privileged Identity Management
B.Microsoft Forms
C.Microsoft Purview Compliance Manager
D.Microsoft Defender for Endpoint
AnswerB

Microsoft Forms provides purpose-built survey, quiz and poll creation with branching, response collection and built-in analytics, directly satisfying the department's forms-based requirement. It integrates with Microsoft 365 groups and Excel without needing separate third-party tooling.

Why this answer

Microsoft Forms is the correct service because it is specifically designed for creating forms-based surveys, quizzes, and polls. It provides real-time response tracking, automatic grading for quizzes, and seamless integration with Microsoft 365 apps like Excel and Teams, making it the ideal choice for the department's request.

Exam trap

The trap here is that candidates may confuse Microsoft Forms with other Microsoft 365 services that have 'management' or 'compliance' in their names, assuming they include survey capabilities, but only Forms is purpose-built for forms-based data collection and quizzes.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Privileged Identity Management is an identity governance tool for managing, controlling, and monitoring access to Azure AD resources, not for creating surveys or quizzes. Option C is wrong because Microsoft Purview Compliance Manager is a compliance management solution that helps organizations assess and manage their compliance posture, not a forms-based survey tool. Option D is wrong because Microsoft Defender for Endpoint is an enterprise endpoint security platform designed to protect devices from threats, not for building forms or quizzes.

268
MCQmedium

A compliance-aware administrator is selecting the right Microsoft 365 capability to brainstorm using a shared digital canvas during Teams meetings. Microsoft 365 app or service is the best fit?

A.Microsoft Planner
B.Microsoft Purview Audit
C.Microsoft Forms
D.Microsoft Whiteboard
AnswerD

Microsoft Whiteboard provides the shared digital canvas for real-time brainstorming during Teams meetings, satisfying the collaboration requirement in the stem. Unlike static note-taking tools, it supports simultaneous multi-user inking and ideation, and integrates natively with Teams, letting participants co-create visually without leaving the meeting.

Why this answer

Microsoft Whiteboard is the best fit because it provides a shared digital canvas that allows meeting participants to brainstorm, draw, and collaborate in real time during Teams meetings. It integrates directly with Teams, supports ink and sticky notes, and persists content across sessions, making it ideal for interactive brainstorming.

Exam trap

The trap here is that candidates may confuse Microsoft Planner's board view with a canvas, but Planner is strictly for task tracking, not freeform drawing or brainstorming.

How to eliminate wrong answers

Option A is wrong because Microsoft Planner is a task management tool for organizing work with boards and checklists, not a real-time shared canvas for brainstorming. Option B is wrong because Microsoft Purview Audit is a compliance and auditing solution that tracks user and admin activities, not a collaborative whiteboarding tool. Option C is wrong because Microsoft Forms is used to create surveys, quizzes, and polls, not a freeform digital canvas for brainstorming.

269
MCQmedium

Refer to the exhibit. An administrator creates a Conditional Access policy in Microsoft Entra ID. The AppId 00000003-0000-0ff1-ce00-000000000000 corresponds to Microsoft Graph. The policy requires MFA for all users accessing Microsoft Graph. However, users report that they are not prompted for MFA when using Microsoft Teams. What is the most likely reason?

A.The policy applies only to Microsoft Graph, not to the Teams service itself.
B.The policy is not enabled.
C.The policy should include the app ID for Office 365 Exchange Online.
D.The GrantControls should be set to RequireMFA for all resources.
AnswerA

Conditional Access targets the resource AppId in the token request. Teams requests its own service principal, not Microsoft Graph, so a policy scoped solely to the Graph AppId never evaluates during Teams sign-in, leaving users unprompted for MFA.

Why this answer

The Conditional Access policy targets the Microsoft Graph app ID (00000003-0000-0ff1-ce00-000000000000), which is used for programmatic access to Microsoft Graph APIs, not for the Microsoft Teams client itself. Teams uses its own service principals and app IDs for authentication, so the policy does not apply to Teams sign-ins, and users are not prompted for MFA.

Exam trap

MS-900 often tests the misconception that Microsoft Graph is a universal app ID that covers all Microsoft 365 services, when in fact each service has its own app ID and must be targeted separately.

How to eliminate wrong answers

Option B is wrong because if the policy were not enabled, it would not apply to any app, but the question implies the policy is active for Graph. Option C is wrong because including the Office 365 Exchange Online app ID would not affect Teams; Teams has its own app ID. Option D is wrong because GrantControls set to RequireMFA for all resources would apply to all apps, but the policy is scoped to Graph only.

270
Multi-Selectmedium

Which THREE Microsoft 365 services are part of Microsoft Purview compliance suite?

Select 3 answers
A.Microsoft Entra ID
B.Microsoft Defender for Cloud Apps
C.Data Lifecycle Management
D.Communication Compliance
E.Audit
AnswersC, D, E

Data Lifecycle Management is a core Microsoft Purview compliance solution for automating retention, preservation, and deletion of Microsoft 365 content using labels and policies. It helps organizations meet regulatory obligations and reduce legal risk by ensuring data is kept exactly as long as needed and then permanently removed. This extends across Exchange, SharePoint, OneDrive, and Teams, making it a key part of Purview's governance toolkit.

Why this answer

Data Lifecycle Management (C) is part of Microsoft Purview because it provides automated retention and deletion policies for sensitive data across Exchange, SharePoint, OneDrive, and Teams. It helps organizations comply with regulatory requirements by governing data from creation to disposal, directly supporting the Purview compliance portal's governance capabilities.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps (a security tool) with a compliance service, but Purview focuses on data governance, audit, and communication monitoring, not threat detection or identity management.

271
MCQmedium

An administrator is reviewing a request from users who need to analyze attachments in a protected environment before delivery. Microsoft security, identity, or compliance capability should it use?

A.Safe Attachments
B.Microsoft Forms
C.Microsoft Stream
D.Microsoft Planner
AnswerA

Safe Attachments is a Microsoft Defender for Office 365 feature that scans and detonates email attachments in a secure, isolated virtual environment before they reach the user. It uses behavioral analysis, machine learning, and real-time threat intelligence to block zero-day malware and malicious files, and it can be enforced through fine-grained policies and dynamic delivery for user safety.

Why this answer

Safe Attachments is the correct Microsoft 365 Defender capability that detonates email attachments in a virtual, protected environment before delivery. It uses behavioral analysis and machine learning to detect malicious content, ensuring that only safe attachments reach the user's inbox. This directly addresses the requirement to analyze attachments in a protected environment.

Exam trap

The trap here is that candidates may confuse Safe Attachments with other Microsoft 365 security features like Safe Links or anti-malware policies, but the question specifically requires a capability that analyzes attachments in a protected environment before delivery, which is uniquely provided by Safe Attachments.

How to eliminate wrong answers

Option B (Microsoft Forms) is wrong because it is a survey and data collection tool, not a security feature for analyzing attachments. Option C (Microsoft Stream) is wrong because it is a video sharing and management platform, unrelated to email attachment security. Option D (Microsoft Planner) is wrong because it is a task management and planning tool, with no capability to scan or detonate attachments.

272
Multi-Selectmedium

Which TWO of the following are required to use Microsoft 365 Apps for enterprise?

Select 2 answers
A.A supported operating system
B.Exchange Online mailbox
C.Persistent internet connectivity
D.A valid Microsoft 365 license
E.Microsoft Entra ID
AnswersA, D

Microsoft 365 Apps are compiled for specific operating systems, and the installer enforces this by checking the OS version before allowing installation. Windows 10/11 and recent macOS releases are the only supported platforms; older or unsupported versions will be blocked and receive no security updates. Therefore, having a supported OS is a non-negotiable technical prerequisite.

Why this answer

Option A is correct because Microsoft 365 Apps for enterprise (Word, Excel, PowerPoint, Outlook, etc.) can only be installed and run on a supported operating system, such as Windows 10/11, the current or previous two versions of Windows Server with RDS, or one of the three most recent major versions of macOS; an unsupported OS means the apps cannot be installed or receive updates. Option D is correct because the applications require a valid Microsoft 365 license (for example, Microsoft 365 E3/E5 or Apps for enterprise) assigned to a user; without an active license, the apps run in reduced-functionality or read-only mode and cannot be activated. Option B is not required, since Exchange Online is only needed for hosted mailboxes and not for installing or using the Office applications themselves.

Option C is not required, because the apps can be installed and used offline after activation, with internet connectivity needed only periodically for license revalidation and updates. Option E is not required, since Microsoft Entra ID (Azure AD) is used for identity and sign-in but is not a prerequisite for the apps to function.

Exam trap

The trap here is that candidates often confuse 'required for activation' with 'required for usage,' mistakenly thinking persistent internet or an Exchange mailbox is mandatory, when in fact the apps can be used offline and without email services as long as a valid license and supported OS are present.

273
Multi-Selecteasy

Which TWO Microsoft 365 apps are included in Microsoft 365 Business Basic?

Select 2 answers
A.Microsoft Teams
B.Exchange Online
C.Microsoft Power BI Pro
D.Microsoft Project Online Plan 3
E.Microsoft Word (desktop app)
AnswersA, B

Microsoft Teams is a core application in Microsoft 365 Business Basic, providing a shared workspace for persistent chat, voice and video meetings, file collaboration, and integration with other Microsoft 365 services like SharePoint and OneDrive. It allows teams to communicate and collaborate in real time across devices, making it essential for small and medium businesses using the subscription.

Why this answer

Microsoft Teams is included in Microsoft 365 Business Basic as a core app for chat, meetings, and collaboration. Exchange Online is also included, providing hosted email, calendars, and contacts with a 50 GB mailbox per user. Both are cloud-only services in this plan, with no desktop Office apps.

Exam trap

The trap here is that candidates often assume all Microsoft 365 plans include desktop Office apps, but Business Basic explicitly excludes them, offering only web and mobile versions.

274
MCQmedium

A business stakeholder asks how Microsoft 365 can help them host an intranet landing page with news, navigation links, and department content. Microsoft 365 app or service is the best fit?

A.SharePoint Online
B.Microsoft Purview Audit
C.Microsoft Forms
D.Microsoft Planner
AnswerA

SharePoint Online is the cloud-based hosting and intranet platform within Microsoft 365, providing communication sites, team sites, and modern pages that can be composed with web parts. It enables organizations to publish structured content, manage documents with versioning and approval workflows, and control access via granular permission settings. For a business stakeholder asking how Microsoft 365 can help host internal content or organization websites, SharePoint Online is the correct service.

Why this answer

SharePoint Online is the correct answer because it is a web-based platform specifically designed for creating intranet portals, team sites, and communication sites. It provides built-in web parts for news feeds, navigation links, and department content pages, making it the ideal service for hosting a company intranet landing page.

Exam trap

The trap here is that candidates may confuse Microsoft Planner's task lists with content organization, or assume Microsoft Forms can publish content, when in fact only SharePoint Online provides the structured site hierarchy and web part capabilities needed for an intranet landing page.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Audit is a compliance and auditing solution that tracks user and admin activities across Microsoft 365, not a tool for building intranet pages. Option C is wrong because Microsoft Forms is a survey and quiz creation tool, not a content management or intranet hosting platform. Option D is wrong because Microsoft Planner is a task management and project tracking application, not designed for publishing news or organizing department content.

275
MCQmedium

A business wants predictable annual subscription pricing and centralized license assignment. Which option best matches the requirement?

A.Microsoft Defender for Cloud only
B.Microsoft 365 admin center license management
C.A free personal Microsoft account only
D.Azure Virtual Desktop only
AnswerB

The Microsoft 365 admin center is the central portal for purchasing, assigning, and managing subscription licenses for a business tenant. Through Billing > Purchase services, an organization can select an annual commitment with monthly or full-year payment, giving exactly the predictable annual pricing required. The admin center also handles user license assignments, usage monitoring, renewal, and invoice management, making it the definitive answer.

Why this answer

The Microsoft 365 admin center provides centralized license assignment and management, allowing administrators to assign, revoke, and track licenses across users. It also supports predictable annual subscription pricing through Enterprise Agreement or CSP annual commitments, ensuring fixed costs for the billing period.

Exam trap

The trap here is that candidates may confuse a security or virtualization service (like Defender for Cloud or Azure Virtual Desktop) with a licensing management tool, overlooking that only the admin center directly handles subscription pricing and centralized license assignment.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud is a security solution for threat protection and compliance, not a licensing or subscription management tool; it does not handle license assignment or pricing. Option C is wrong because a free personal Microsoft account offers no subscription pricing or centralized license management; it is limited to individual use of free services. Option D is wrong because Azure Virtual Desktop is a desktop virtualization service that requires separate licensing (e.g., Microsoft 365 or Windows per-user licenses) and does not itself provide predictable annual subscription pricing or centralized license assignment.

276
MCQmedium

A company with 250 users has Microsoft 365 E3 licenses. They want to add advanced anti-phishing and anti-malware protection for email and also deploy endpoint detection and response (EDR) for all devices. What is the most cost-effective licensing add-on?

A.Microsoft 365 E5 Security add-on
B.Microsoft Defender for Microsoft 365 Plan 1 and Microsoft Defender for Endpoint Plan 1 add-ons
C.Microsoft 365 E5 Compliance add-on
D.Upgrade all users to Microsoft 365 E5
AnswerA

The Microsoft 365 E5 Security add-on is explicitly designed to extend E3 with advanced threat protection, bundling Defender for Microsoft 365 Plan 2 and Defender for Endpoint Plan 1. This bundle provides advanced hunting, automated investigation, and endpoint detection and response at a lower combined price than purchasing the components individually. It directly satisfies the company's security requirements without unnecessary extras, making it the optimal cost-effective choice.

Why this answer

Microsoft 365 E5 Security add-on provides advanced anti-phishing and anti-malware protection via Microsoft Defender for Office 365 Plan 2 and includes Microsoft Defender for Endpoint Plan 2 for EDR capabilities. This is the most cost-effective option because it adds exactly the required security features to existing E3 licenses without the higher cost of a full E5 upgrade or the redundancy of separate plan 1 add-ons.

Exam trap

The trap here is that candidates often confuse the 'Plan 1' vs 'Plan 2' tiers, assuming that any Defender add-on provides full EDR and advanced anti-phishing, when in reality Plan 1 lacks key features like automated investigation and advanced threat hunting.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Office 365 Plan 1 and Microsoft Defender for Endpoint Plan 1 do not include advanced anti-phishing (e.g., impersonation protection, campaign views) or full EDR capabilities (e.g., automated investigation and response, threat analytics) — those require Plan 2. Option C is wrong because Microsoft 365 E5 Compliance add-on focuses on data governance, eDiscovery, and information protection (e.g., DLP, retention labels), not on anti-phishing/anti-malware for email or endpoint EDR. Option D is wrong because upgrading all users to Microsoft 365 E5 is more expensive than adding the E5 Security add-on, which provides the same security features without the extra compliance and analytics features of full E5.

277
MCQeasy

Which characteristic of cloud computing allows a user to provision resources automatically without requiring human interaction with the service provider?

A.Rapid elasticity
B.Resource pooling
C.On-demand self-service
D.Measured service
AnswerC

On-demand self-service is the NIST-defined characteristic that lets a consumer unilaterally provision computing capabilities—such as virtual machines, storage, or network services—as needed automatically, without requiring human interaction with the service provider. This is typically delivered through a web portal, CLI, or API, meaning the user can spin up resources in minutes without opening a support ticket. It directly matches the scenario in the question: the user can obtain resources automatically and without manual intervention.

Why this answer

On-demand self-service is a fundamental characteristic of cloud computing defined by NIST (SP 800-145) that allows a user to unilaterally provision computing capabilities, such as server time and network storage, as needed automatically without requiring human interaction with each service provider. This is typically implemented through a web portal or API (e.g., AWS Console, Azure Portal, or RESTful APIs) that enables instant resource creation and configuration.

Exam trap

The trap here is that candidates often confuse 'rapid elasticity' with 'on-demand self-service' because both involve automation, but rapid elasticity focuses on scaling existing resources while on-demand self-service is about the initial provisioning without human intervention.

How to eliminate wrong answers

Option A is wrong because rapid elasticity refers to the ability to scale resources up or down quickly and automatically in response to demand, not to the initial provisioning without human interaction. Option B is wrong because resource pooling describes the provider's multi-tenant model where physical and virtual resources are dynamically assigned and reassigned according to consumer demand, not the user's ability to self-provision. Option D is wrong because measured service involves metering and monitoring resource usage (e.g., CPU hours, bandwidth, storage) for billing and optimization, not the automated provisioning process.

278
MCQmedium

A company uses Microsoft 365 Copilot to summarize a long email thread. Where does Copilot retrieve the email content from?

A.SharePoint Online
B.Exchange Online
C.OneDrive for Business
D.Microsoft Viva Topics
AnswerB

Exchange Online is the correct source because it hosts the user's mailbox, including email messages, and Copilot uses Microsoft Graph to access this data with the user's consented permissions. When summarizing a long email, Copilot reads the message content directly from the Exchange Online mailbox store, applying the same access controls and sensitivity labels that govern the user's normal mail operations. This ensures that the summary is based on the live, authoritative version of the email.

Why this answer

Microsoft 365 Copilot retrieves email content directly from Exchange Online, which is the Microsoft 365 service that stores and manages mailboxes, emails, and calendar items. When summarizing a long email thread, Copilot accesses the user's mailbox via Exchange Web Services (EWS) or the Microsoft Graph API, which provides programmatic access to email data. This allows Copilot to read the thread's messages and generate a concise summary without needing to store or index the content elsewhere.

Exam trap

The trap here is that candidates often confuse where email content is stored versus where documents or files are stored, mistakenly selecting SharePoint Online or OneDrive for Business because they associate Copilot with summarizing content from those services, but email specifically resides in Exchange Online.

How to eliminate wrong answers

Option A is wrong because SharePoint Online is a document management and collaboration platform for files, lists, and sites, not for storing individual email messages or threads. Option C is wrong because OneDrive for Business is a personal cloud storage service for files and documents, not for email content, which resides in Exchange Online mailboxes. Option D is wrong because Microsoft Viva Topics is a knowledge discovery service that uses AI to organize and surface topics from content across Microsoft 365, but it does not directly store or provide raw email thread data for Copilot summarization.

279
Multi-Selectmedium

Which THREE are benefits of using cloud services compared to on-premises infrastructure?

Select 3 answers
A.Limited scalability due to resource constraints
B.Elasticity to scale resources up or down automatically
C.High availability through redundant infrastructure
D.Built-in disaster recovery capabilities
E.Capital expenditure (CapEx) is eliminated
AnswersB, C, D

Elasticity lets cloud services automatically scale resources up or down to match demand, so organisations pay only for what they consume. This satisfies the stem's benefit requirement, contrasting with on-premises infrastructure, which needs pre-provisioned capacity sized for peak load.

Why this answer

Option B is correct because cloud providers offer elasticity, allowing resources to automatically scale up or down based on demand, which is difficult to achieve with fixed on-premises hardware. Option C is correct because cloud services are built on redundant, geographically distributed infrastructure that provides high availability and fault tolerance beyond what most on-premises environments can afford. Option D is correct because cloud providers offer built-in disaster recovery capabilities, such as cross-region replication and backup services, without requiring organizations to build and maintain a secondary site.

Option A is incorrect because limited scalability due to resource constraints describes an on-premises limitation, not a cloud benefit. Option E is incorrect because cloud services shift spending to operational expenditure (OpEx), but they do not eliminate capital expenditure entirely, as organizations may still incur upfront costs for devices, migration, or reserved capacity.

Exam trap

The trap is selecting 'Capital expenditure (CapEx) is eliminated' as a benefit; while cloud reduces CapEx, it does not eliminate it entirely, and the exam expects you to recognize that the three correct benefits are elasticity, high availability, and disaster recovery.

280
MCQhard

A company uses a third-party Human Resources (HR) system. Whenever a new employee is added to the HR system, they want to automatically create a user account in Microsoft 365, assign the appropriate license, and send a welcome email. Which Microsoft 365 service should be used to orchestrate this automation?

A.Microsoft Power Automate
B.Microsoft Identity Manager
C.Microsoft Entra ID Connect
D.Microsoft Graph API
AnswerA

Microsoft Power Automate enables no-code/low-code cloud flows that use built-in connectors and triggers to react to events in third-party HR systems. These flows can orchestrate user provisioning, send approval emails, and update Microsoft Entra ID or other systems automatically, making it the correct tool for automating HR-driven identity workflows.

Why this answer

Microsoft Power Automate is the correct service because it provides a low-code workflow automation platform that can trigger actions based on events in external systems (e.g., a new employee record in a third-party HR system) and then orchestrate a sequence of tasks in Microsoft 365, such as creating a user account via the Microsoft Graph API, assigning a license, and sending a welcome email. It integrates seamlessly with hundreds of connectors, including HR systems and Microsoft 365 services, making it the ideal tool for this cross-system automation scenario.

Exam trap

The trap here is that candidates often confuse the Microsoft Graph API (a development tool) with Power Automate (a no-code/low-code orchestration service), mistakenly thinking that because the Graph API can perform the individual actions, it is the correct answer for orchestrating the entire automated workflow.

How to eliminate wrong answers

Option B (Microsoft Identity Manager) is wrong because it is an on-premises identity and access management solution focused on synchronizing identities between on-premises directories and cloud directories, not on orchestrating event-driven workflows like creating users and sending emails. Option C (Microsoft Entra ID Connect) is wrong because it is a synchronization tool that replicates on-premises Active Directory objects to Microsoft Entra ID for hybrid identity scenarios; it does not provide workflow automation or trigger actions based on external HR system events. Option D (Microsoft Graph API) is wrong because while it can be used to programmatically create users, assign licenses, and send emails, it is a RESTful API that requires custom code and does not provide the orchestration, scheduling, or low-code workflow capabilities that Power Automate offers for automating a multi-step process triggered by an external system.

281
MCQeasy

Which cloud characteristic allows an organization to increase or decrease computing resources quickly based on demand, without requiring manual intervention?

A.Measured service
B.Rapid elasticity
C.Resource pooling
D.Broad network access
AnswerB

Rapid elasticity is the cloud characteristic that allows resources—such as virtual machines, storage, or bandwidth—to be provisioned and released quickly, often automatically, to scale in response to fluctuating demand. It gives organizations the ability to scale out (increase resources) and scale in (decrease resources) seamlessly, sometimes without human intervention using orchestration tools or auto-scaling policies. This directly supports dynamic workloads where usage spikes or drops, making it the correct answer for the question.

Why this answer

Rapid elasticity is the cloud characteristic that enables automatic, on-demand scaling of computing resources (such as virtual machines, storage, or network bandwidth) in response to fluctuating workload demands, without requiring manual provisioning or de-provisioning. This is a core feature of cloud computing defined by NIST SP 800-145, allowing resources to scale out (increase) or scale in (decrease) dynamically, often using orchestration tools like Azure Autoscale or AWS Auto Scaling. The key distinction is that the scaling happens quickly and automatically, based on predefined rules or metrics like CPU utilization or request count.

Exam trap

The trap here is that candidates often confuse 'rapid elasticity' with 'resource pooling' because both involve dynamic allocation, but resource pooling is about sharing resources among multiple tenants, not about automatically scaling a single tenant's resources on demand.

How to eliminate wrong answers

Option A (Measured service) is wrong because it refers to the metering and billing of cloud resource usage (e.g., pay-per-use or consumption-based pricing), not the ability to scale resources up or down automatically. Option C (Resource pooling) is wrong because it describes the multi-tenant model where provider resources are pooled to serve multiple customers, with physical and virtual resources dynamically assigned and reassigned according to demand, but it does not inherently provide automatic scaling of individual customer resources. Option D (Broad network access) is wrong because it defines the capability for resources to be accessed over the network via standard protocols (e.g., HTTPS, SSH) from a wide range of devices (e.g., laptops, smartphones), not the ability to adjust resource capacity on demand.

282
MCQhard

A compliance team needs to implement a Data Loss Prevention (DLP) policy to protect credit card information. What is the correct order of steps for a successful implementation?

A.Create policy, Identify locations, Deploy in production, Monitor alerts and refine
B.Identify locations, Create policy, Deploy in production, Monitor alerts and refine
C.Deploy in production, Monitor alerts and refine, Identify locations, Create policy
D.Identify locations, Deploy in production, Create policy, Monitor alerts and refine
AnswerB

This is the correct sequence because it mirrors a mature data governance lifecycle. Start by using Microsoft Purview's Content Explorer or data classification capabilities to map where sensitive data resides. Then create a DLP policy in test mode, targeting those locations and defining rules and actions, before deploying in production. Finally, monitor Activity Explorer and refine the policy based on real incidents—ensuring continuous alignment with evolving compliance requirements.

Why this answer

A successful DLP implementation starts with discovery: identifying where sensitive data such as credit card numbers actually resides across email, SharePoint, OneDrive, and endpoints. Only after locations are known can a policy be scoped correctly, deployed in production (often after a test/simulation mode), and then monitored and refined based on alerts and false positives. This order prevents blind deployment and reduces business disruption.

Exam trap

MS-900 often tests the misconception that policy creation comes first — candidates must remember that discovery/identification of sensitive data locations is the necessary first step before scoping and deploying DLP.

How to eliminate wrong answers

Option A is wrong because creating a policy before identifying locations means the policy may not cover the actual data repositories and may miss or over-block content. Option C is wrong because deploying in production before identifying locations and creating a policy is reckless and would either do nothing or cause widespread false positives. Option D is wrong because deploying in production before creating a policy is impossible — there is nothing to deploy, and it reverses the logical sequence.

283
MCQeasy

A training department wants to create interactive learning paths and track employee progress. Which Microsoft 365 service should they use?

A.Microsoft Viva Learning
B.Microsoft Viva Topics
C.Microsoft Stream
D.SharePoint Online
AnswerA

Microsoft Viva Learning is the correct answer because it is the M365/Viva module designed specifically for learning management. It aggregates content from LinkedIn Learning, Microsoft Learn, and third-party providers into a single Teams-based interface, and it provides core learning functionality such as learning paths, content assignments, and progress tracking. In this scenario, the training department's need to create interactive learning content and monitor learner progress aligns directly with Viva Learning's purpose.

Why this answer

Microsoft Viva Learning is the correct service because it provides a centralized hub within Microsoft Teams where organizations can create, assign, and track interactive learning paths and employee progress. It integrates with learning management systems (LMS) and content providers to surface training content, while also offering progress tracking and completion analytics for administrators.

Exam trap

The trap here is that candidates often confuse Viva Learning with SharePoint Online, assuming that SharePoint's document libraries and custom lists can replicate learning path functionality, but SharePoint lacks the integrated assignment engine, progress dashboards, and third-party content aggregation that Viva Learning provides natively.

How to eliminate wrong answers

Option B (Microsoft Viva Topics) is wrong because it is an AI-powered knowledge discovery service that automatically organizes content into topic pages from across Microsoft 365, not a tool for creating learning paths or tracking progress. Option C (Microsoft Stream) is wrong because it is a video hosting and sharing platform (formerly Azure Media Services-based) that does not include interactive learning path creation or progress tracking capabilities. Option D (SharePoint Online) is wrong because while it can host training documents and lists, it lacks native interactive learning path creation, assignment workflows, and built-in progress tracking features that Viva Learning provides.

284
MCQmedium

While preparing a Microsoft 365 adoption plan, a consultant is asked to manage billing without granting full tenant control. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.Microsoft Forms
C.Billing Administrator
D.Microsoft Whiteboard
AnswerC

The Billing Administrator is a built-in Microsoft 365 administrative role that grants least-privilege access to manage subscription purchases, billing accounts, invoices, and license assignments. This role is appropriate for a consultant preparing an adoption plan because it provides the necessary licensing and cost-management capabilities without the security risk of full Global Administrator rights. It directly addresses the requirement by enabling the consultant to modify licenses and monitor the organization's billing posture.

Why this answer

The Billing Administrator role in Microsoft 365 is specifically designed to manage billing tasks—such as invoices, payment methods, and subscription purchases—without granting broader tenant-wide administrative privileges. This aligns directly with the scenario of managing billing while avoiding full tenant control, making it the most relevant concept for the adoption plan.

Exam trap

The trap here is that candidates may confuse a Microsoft 365 service or application (like Stream, Forms, or Whiteboard) with an administrative role, failing to recognize that the question specifically asks for a licensing, admin, or support concept rather than a feature or app.

How to eliminate wrong answers

Option A (Microsoft Stream) is wrong because it is a video management and sharing service, not an administrative role or billing concept; it has no capability to manage billing or tenant permissions. Option B (Microsoft Forms) is wrong because it is a survey and data collection tool, unrelated to billing administration or tenant-level access control. Option D (Microsoft Whiteboard) is wrong because it is a collaborative digital canvas application, with no role in billing management or administrative delegation.

285
MCQmedium

A 200-user company needs desktop Office apps, Exchange Online mailboxes, Microsoft Teams, and Intune-based device management. Which Microsoft 365 plan is the best fit from the listed options?

A.Microsoft 365 Business Premium.
B.Microsoft 365 Business Basic.
C.Exchange Online Plan 1.
D.Microsoft Teams Essentials.
AnswerA

Microsoft 365 Business Premium is the correct choice because it bundles the fully installed desktop versions of Office applications (Word, Excel, PowerPoint, Outlook) together with Exchange Online, Teams, SharePoint, and advanced security/management capabilities. For a 200-user company, it also provides Microsoft Intune and Azure AD P1, making it a complete endpoint-management and identity-security solution beyond just email and productivity apps.

Why this answer

Microsoft 365 Business Premium is the correct choice because it bundles desktop Office apps (e.g., Word, Excel, Outlook), Exchange Online mailboxes, Microsoft Teams, and Intune-based device management into a single subscription. This plan is specifically designed for small-to-medium businesses needing full productivity, communication, and security/compliance capabilities, including mobile device management (MDM) via Intune.

Exam trap

The trap here is that candidates often confuse Microsoft 365 Business Basic (which lacks desktop apps) with Business Premium, or mistakenly think standalone plans like Exchange Online Plan 1 or Teams Essentials can cover all requirements, ignoring the need for integrated desktop apps and device management.

How to eliminate wrong answers

Option B (Microsoft 365 Business Basic) is wrong because it provides only web and mobile versions of Office apps, not the desktop Office apps required by the question. Option C (Exchange Online Plan 1) is wrong because it offers only Exchange Online mailboxes and lacks desktop Office apps, Microsoft Teams, and Intune-based device management. Option D (Microsoft Teams Essentials) is wrong because it is a standalone Teams-only plan with no Exchange Online mailboxes, desktop Office apps, or Intune device management.

286
MCQeasy

Which cloud deployment model exclusively uses resources that are owned and managed by a single organization, and is often chosen for its high level of control and compliance?

A.Public cloud
B.Private cloud
C.Hybrid cloud
D.Community cloud
AnswerB

A private cloud is provisioned for exclusive use by a single organization and may be managed by the organization itself or by a third party, and may be hosted on-premises or in a provider's data center. The infrastructure—including virtualized servers, storage, and networking—is dedicated to that one tenant, giving the organization full control over resource allocation, security policies, and compliance adherence. This exclusive, single-tenant nature is the defining characteristic that makes private cloud the correct answer.

Why this answer

The private cloud deployment model is correct because it is defined as a cloud infrastructure that is provisioned for exclusive use by a single organization. This model provides the highest level of control over data, security, and compliance, as the organization owns and manages the underlying hardware and software, often within its own data center or via a dedicated hosted environment.

Exam trap

The trap here is that candidates often confuse 'private cloud' with 'on-premises infrastructure' and may incorrectly select 'hybrid cloud' thinking it offers the same control, but the question specifically asks for a model that exclusively uses resources owned by a single organization, which is the defining characteristic of a private cloud.

How to eliminate wrong answers

Option A is wrong because the public cloud model uses resources owned and operated by a third-party cloud service provider (e.g., Microsoft Azure, AWS, Google Cloud) and is shared across multiple tenants, offering less control and compliance isolation. Option C is wrong because the hybrid cloud model combines both public and private clouds, allowing data and applications to be shared between them, which does not exclusively use resources owned by a single organization. Option D is wrong because the community cloud model is shared by several organizations with common concerns (e.g., compliance, security, policy), not exclusively owned and managed by a single organization.

287
MCQeasy

A user wants to access company email and documents from any device, anywhere. Which cloud model is Microsoft 365?

A.Platform as a Service (PaaS)
B.Software as a Service (SaaS)
C.Infrastructure as a Service (IaaS)
D.Desktop as a Service (DaaS)
AnswerB

Software as a Service (SaaS) delivers fully managed applications over the internet through a subscription. Microsoft 365 is the canonical example: Exchange Online hosts company mailboxes, and SharePoint Online/OneDrive host documents, all accessible from any device through a browser or Office client without manual patching or server maintenance. This directly matches the user’s requirement for ready-to-use email and document access from anywhere.

Why this answer

Microsoft 365 is a SaaS offering because Microsoft hosts and manages the applications (Exchange Online, SharePoint Online, Teams, Office apps) and the underlying infrastructure, and customers access them over the internet via subscription. Users consume the software without managing servers, patching, or platform configuration. This matches the SaaS model where the provider delivers a complete, ready-to-use application.

Exam trap

MS-900 often tests the difference between SaaS, PaaS, and IaaS by presenting a familiar product (Microsoft 365) and expecting candidates to recognise that the provider manages everything from the application down — candidates sometimes pick PaaS because they confuse 'cloud-hosted application' with 'platform'.

How to eliminate wrong answers

Option A is wrong because PaaS provides a development and hosting environment (e.g., Azure App Service) where customers deploy their own code, not a finished productivity suite. Option C is wrong because IaaS provides raw compute, storage, and networking (e.g., Azure VMs) that customers must configure and manage themselves. Option D is wrong because DaaS delivers virtual desktops (e.g., Azure Virtual Desktop) rather than a multi-tenant productivity application suite.

288
MCQeasy

A startup with 25 employees needs business-grade email (50 GB mailbox per user), web versions of Office apps, and 1 TB of cloud storage per user. They do not need the desktop versions of Office or advanced security features. Which Microsoft 365 plan is the most cost-effective choice?

A.Microsoft 365 Business Basic
B.Microsoft 365 Business Standard
C.Microsoft 365 Business Premium
D.Microsoft 365 Apps for business
AnswerA

Microsoft 365 Business Basic provides a 50 GB Exchange Online mailbox for business email, web and mobile versions of Office apps, and 1 TB OneDrive storage per user. It matches every stated requirement (business-grade email and 50 GB capacity) at the lowest available subscription price for this plan family. Desktop Office apps are not included, but they were not required by the startup, so this is the correct, cost-optimal plan.

Why this answer

Microsoft 365 Business Basic provides business-grade email with 50 GB mailboxes, web versions of Office apps (Word, Excel, PowerPoint, etc.), and 1 TB of cloud storage per user via OneDrive for Business. Since the startup does not need desktop Office apps or advanced security features, this plan meets all stated requirements at the lowest cost.

Exam trap

The trap here is that candidates often confuse 'web versions of Office apps' with 'desktop versions' and select Business Standard, or they assume that business-grade email requires a higher-tier plan like Business Premium, when in fact Business Basic includes Exchange Online mailboxes.

How to eliminate wrong answers

Option B (Microsoft 365 Business Standard) is wrong because it includes desktop versions of Office apps, which the startup does not need, making it more expensive than necessary. Option C (Microsoft 365 Business Premium) is wrong because it adds advanced security features (e.g., Microsoft Defender for Office 365, Intune) and desktop Office apps, exceeding the stated requirements and increasing cost. Option D (Microsoft 365 Apps for business) is wrong because it provides only desktop and web versions of Office apps without Exchange Online mailboxes (no business-grade email) and offers only 1 TB of cloud storage per user but lacks the 50 GB mailbox requirement.

289
MCQmedium

A compliance-aware administrator is selecting the right Microsoft 365 capability to evaluate Microsoft 365 before purchasing. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft Stream
B.A Microsoft 365 trial subscription
C.Microsoft Whiteboard
D.Microsoft Forms
AnswerB

A Microsoft 365 trial subscription is the correct choice because it provisions a temporary tenant with full administrative access, allowing the compliance-aware administrator to test licensing models, Security and Compliance Center policies, and technical support coverage before making a purchasing commitment. Trials typically include the same admin portals and service level as paid plans, making them the standard way to evaluate whether M365 meets regulatory and operational requirements.

Why this answer

A Microsoft 365 trial subscription is the correct choice because it allows an administrator to evaluate the full functionality of Microsoft 365 before making a purchase, directly addressing the requirement to 'evaluate Microsoft 365 before purchasing.' This aligns with the 'Describe Microsoft 365 pricing and support' domain, as trial subscriptions are a key licensing and evaluation concept. Other options like Stream, Whiteboard, and Forms are individual services within Microsoft 365, not mechanisms for pre-purchase evaluation.

Exam trap

The trap here is that candidates may confuse individual Microsoft 365 services (like Stream, Whiteboard, or Forms) with the licensing or evaluation concept, but the question specifically asks for the capability to evaluate the entire platform before purchasing, which only a trial subscription provides.

How to eliminate wrong answers

Option A is wrong because Microsoft Stream is a video service within Microsoft 365, not a licensing, admin, or support concept for evaluating the platform before purchase. Option C is wrong because Microsoft Whiteboard is a collaborative canvas app, unrelated to trial subscriptions or licensing evaluation. Option D is wrong because Microsoft Forms is a survey and quiz tool, not a mechanism for pre-purchase evaluation of Microsoft 365.

290
MCQmedium

An administrator is reviewing a request from users who need to avoid overprovisioning for a seasonal workload. Cloud concept or benefit best matches this requirement?

A.Data Loss Prevention (DLP)
B.Sensitivity labels
C.Microsoft Planner
D.Rapid elasticity
AnswerD

Rapid elasticity matches the requirement because it lets resources scale out automatically during seasonal peaks and scale back in afterwards, so capacity tracks demand rather than being provisioned for worst-case load. This directly prevents overprovisioning, since you pay only for what the workload actually consumes.

Why this answer

Rapid elasticity is a core cloud computing characteristic defined by NIST (SP 800-145) that allows resources to scale out and in automatically based on demand. For a seasonal workload, this means the cloud can provision additional compute or storage capacity during peak periods and release it when demand drops, preventing overprovisioning and optimizing costs.

Exam trap

The trap here is that candidates confuse operational tools (like Planner) or security features (like DLP and sensitivity labels) with core cloud architectural benefits, failing to recognize that rapid elasticity is the specific NIST-defined characteristic that directly addresses overprovisioning for variable workloads.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) is a security feature in Microsoft Purview that monitors and protects sensitive data from unauthorized sharing or leakage, not a mechanism for scaling resources. Option B is wrong because sensitivity labels are classification and protection controls applied to documents and emails to enforce encryption or access restrictions, unrelated to workload elasticity. Option C is wrong because Microsoft Planner is a task management and collaboration tool within Microsoft 365, not a cloud infrastructure feature for dynamic resource allocation.

291
MCQmedium

A service owner is comparing Microsoft 365 capabilities and needs to make sign-in decisions based on risk, location, and device compliance. Microsoft security, identity, or compliance capability should it use?

A.Microsoft Forms
B.Microsoft Planner
C.Conditional Access policy
D.Microsoft Stream
AnswerC

Conditional Access is the correct capability because it operates at the identity layer, collecting signals such as user or group membership, location, device compliance, and real-time risk before allowing access. It enforces granular controls like requiring multi-factor authentication, blocking access from untrusted networks, or restricting to compliant devices. This is precisely the Azure AD/Entra ID security feature designed to protect resources, making it the appropriate choice for identity-based access enforcement.

Why this answer

Conditional Access policy is the correct answer because it is the Microsoft Entra ID (formerly Azure AD) feature that enforces sign-in decisions based on risk, location, and device compliance. It allows administrators to create policies that require multi-factor authentication, block access from untrusted locations, or require compliant devices before granting access to Microsoft 365 resources.

Exam trap

The trap here is that candidates may confuse Microsoft 365 productivity tools (Forms, Planner, Stream) with security or identity services, failing to recognize that Conditional Access is the only option that directly controls sign-in decisions based on risk, location, and device compliance.

How to eliminate wrong answers

Option A is wrong because Microsoft Forms is a survey and data collection tool, not an identity or security policy engine; it cannot evaluate sign-in risk, location, or device compliance. Option B is wrong because Microsoft Planner is a task management and project tracking tool within Microsoft 365; it has no capability to enforce conditional access or evaluate authentication context. Option D is wrong because Microsoft Stream is a video hosting and sharing platform; it does not provide any identity-based access control logic beyond what is inherited from the underlying tenant policies.

292
MCQmedium

During requirements gathering, an IT manager says the organization must manage users, licenses, billing, and tenant settings. Microsoft 365 licensing, admin, or support concept is most relevant?

A.Microsoft 365 admin center
B.Microsoft Whiteboard
C.Microsoft Forms
D.Microsoft Stream
AnswerA

The Microsoft 365 admin center is the web portal where administrators manage user accounts, assign licences, view billing and configure tenant-wide settings. It directly satisfies all four stated requirements, unlike the Microsoft 365 Apps or Entra admin centres, which cover narrower scopes.

Why this answer

The Microsoft 365 admin center is the centralized web portal for managing users, licenses, billing, and tenant-wide settings. It provides administrators with a single pane of glass to perform tasks such as adding or removing users, assigning licenses, viewing invoices, and configuring tenant-level policies. This directly matches the IT manager's stated requirements for managing users, licenses, billing, and tenant settings.

Exam trap

The trap here is that candidates may confuse collaboration tools (Whiteboard, Forms, Stream) with administrative tools, assuming any Microsoft 365 service can manage users and licenses, when only the admin center provides the required centralized management capabilities.

How to eliminate wrong answers

Option B is wrong because Microsoft Whiteboard is a digital canvas collaboration tool, not an administrative interface for managing users, licenses, billing, or tenant settings. Option C is wrong because Microsoft Forms is a survey and data collection tool, not a platform for administrative management of licensing or billing. Option D is wrong because Microsoft Stream is a video management and sharing service, not a tool for managing users, licenses, billing, or tenant configurations.

293
MCQeasy

An organization is using Microsoft 365 Business Premium. They want to add Microsoft 365 Copilot for 10 users to enhance productivity with AI features. How should the administrator procure the Copilot licenses?

A.Purchase standalone Microsoft 365 Copilot licenses
B.Upgrade all users to Microsoft 365 E5 to get Copilot included
C.Add Microsoft 365 Copilot as an add-on to the existing subscription
D.Purchase a new Microsoft 365 E3 subscription and add Copilot
AnswerC

The correct approach is to add Microsoft 365 Copilot as an add-on to the existing Business Premium subscription. Business Premium is an eligible base plan, and Copilot is licensed as a per-user add-on that can be assigned alongside the existing user licenses. This preserves the tenant's current licensing topology and avoids duplicate investments in other base plans. The add-on integrates directly with the Business Premium workload, enabling Copilot features across Word, Excel, PowerPoint, Outlook, and Teams.

Why this answer

Microsoft 365 Copilot is available as an add-on to qualifying Microsoft 365 subscriptions, including Business Premium. This allows the administrator to license only the 10 users who need Copilot without changing the base subscription for all users. Option C correctly identifies this add-on licensing model.

Exam trap

The trap here is that candidates often assume Copilot is included in higher-tier plans like E5 or that it can be purchased as a standalone product, but Microsoft requires it to be an add-on to a qualifying base subscription.

How to eliminate wrong answers

Option A is wrong because standalone Microsoft 365 Copilot licenses do not exist; Copilot is only available as an add-on to an existing qualifying subscription. Option B is wrong because Microsoft 365 E5 does not include Copilot; Copilot requires a separate add-on license even on E5. Option D is wrong because purchasing a new E3 subscription would not include Copilot and would require an unnecessary subscription change; the existing Business Premium subscription already qualifies for the Copilot add-on.

294
MCQmedium

A company uses Microsoft 365 E5 licenses. The security team wants to automatically remediate advanced threats detected on endpoints without manual intervention. Which Microsoft 365 service should they use?

A.Microsoft Intune
B.Microsoft Purview
C.Microsoft Defender XDR
D.Microsoft Sentinel
AnswerC

Microsoft Defender XDR (formerly Microsoft 365 Defender) is the correct answer because it is a unified security platform that provides automated investigation and remediation across endpoints, email, identities, and cloud apps. It uses the Microsoft Defender for Endpoint EDR engine, which continuously monitors endpoint behaviors, detects advanced threats using AI and machine learning, and automatically executes response actions such as quarantining malicious files, isolating compromised devices, blocking indicators, and rolling back registry changes. These automated response playbooks reduce the time to respond and are precisely what the security team needs for proactive threat remediation.

Why this answer

Microsoft Defender XDR (Extended Detection and Response) is the correct service because it provides automated investigation and remediation capabilities for advanced threats detected on endpoints. It uses AI-driven playbooks to automatically contain or remove threats without manual intervention, which aligns directly with the security team's requirement.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel's SIEM/SOAR capabilities with automated endpoint remediation, but Sentinel requires integration with Defender XDR to execute such actions, whereas Defender XDR provides native automated remediation directly on endpoints.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service focused on policy enforcement and device compliance, not automated threat remediation. Option B is wrong because Microsoft Purview is a data governance, compliance, and risk management solution (formerly Microsoft 365 Compliance), not designed for endpoint threat detection or automated response. Option D is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) service that aggregates logs and alerts from multiple sources, but it does not natively perform automated remediation on endpoints; it requires integration with other tools like Defender XDR for that capability.

295
MCQeasy

A cloud user can access their files from a work desktop, a personal laptop at home, and a mobile phone while traveling. Which essential characteristic of cloud computing does this scenario best illustrate?

A.On-demand self-service
B.Broad network access
C.Resource pooling
D.Rapid elasticity
AnswerB

Broad network access means cloud capabilities are available over the network through standard protocols and can be used by a diverse range of client platforms, including work desktops, laptops, tablets, and smartphones. The NIST definition of cloud computing highlights that access is via standard mechanisms, which is exactly the scenario in the question: a user can reach the same stored files from a work desktop and other network-connected devices. This is the distinguishing characteristic that makes this option correct.

Why this answer

Broad network access is the correct answer because it describes the ability to access cloud resources from diverse client platforms (work desktop, personal laptop, mobile phone) over the network using standard protocols such as HTTPS, SSH, or VPN. This characteristic ensures that services are available from any location with internet connectivity, not just from a single device or network.

Exam trap

The trap here is that candidates confuse 'access from multiple devices' with 'on-demand self-service' because both involve user-initiated actions, but on-demand self-service specifically means provisioning resources without provider intervention, not multi-device connectivity.

How to eliminate wrong answers

Option A is wrong because on-demand self-service refers to a user provisioning compute resources automatically without requiring human interaction with the cloud provider, not the ability to access files from multiple devices. Option C is wrong because resource pooling describes the provider's multi-tenant model where physical and virtual resources are dynamically assigned to serve multiple consumers, not the user's multi-device access. Option D is wrong because rapid elasticity focuses on the ability to scale resources up or down quickly based on demand, such as adding virtual machines during a traffic spike, not the user's ability to connect from different endpoints.

296
MCQhard

Refer to the exhibit. A SharePoint admin is reviewing a policy JSON snippet. Which statement accurately describes the effect of this policy?

A.External sharing is allowed only for existing guests who expire in 30 days.
B.External sharing is allowed but guests expire after 30 days.
C.External sharing is allowed but only for users in the same tenant.
D.External sharing is completely disabled.
AnswerD

This is correct. The policy sets sharingCapability to Disabled and allowExternalSharing to false, which completely turns off external sharing for the tenant or site. No new guest invites can be sent, no external links can be created, and existing external access will be blocked, while internal sharing continues to work normally.

Why this answer

The policy JSON snippet sets the 'sharingCapability' to 'Disabled', which completely disables external sharing for the SharePoint environment. This means no external users can be invited, and any existing external sharing links will cease to function. The 'expirationTime' value of 30 days is irrelevant because sharing is disabled entirely.

Exam trap

The trap here is that candidates see the 'expirationTime' of 30 days and assume external sharing is allowed with an expiration, but they overlook that the 'sharingCapability' is set to 'Disabled', which nullifies any expiration settings.

How to eliminate wrong answers

Option A is wrong because it suggests external sharing is allowed only for existing guests with a 30-day expiration, but the policy disables sharing entirely, not just for new guests. Option B is wrong because it implies external sharing is allowed with a 30-day guest expiration, but the 'sharingCapability' is set to 'Disabled', overriding any expiration settings. Option C is wrong because it claims sharing is allowed only for users in the same tenant, which is the default behavior when external sharing is disabled; however, the policy explicitly disables all sharing, not just external.

297
MCQhard

An organization uses Microsoft 365 E5 and wants to implement a solution that automatically detects and remediates security incidents across identities, endpoints, and email. Which Microsoft 365 service should they use?

A.Microsoft Defender XDR
B.Microsoft Defender for Endpoint
C.Microsoft Sentinel
D.Microsoft Entra ID Protection
AnswerA

Microsoft Defender XDR is the correct choice because it natively unifies telemetry from Microsoft 365 E5 across endpoints, email, identities, cloud apps, and data into a single incident queue. Its AI-driven correlation and automated response capabilities allow security teams to detect and remediate multi-stage attacks that span these domains, which is the very definition of extended detection and response (XDR).

Why this answer

Microsoft Defender XDR (Extended Detection and Response) is the correct choice because it provides a unified, cross-domain security solution that automatically correlates alerts and orchestrates remediation across identities, endpoints, email, and cloud apps. This aligns directly with the requirement to detect and remediate security incidents across identities, endpoints, and email, leveraging the Microsoft 365 Defender portal to break down silos between individual security products.

Exam trap

The trap here is that candidates often confuse Microsoft Defender XDR with its individual component products (like Defender for Endpoint or Defender for Office 365), mistakenly assuming that a single-domain solution can meet a cross-domain requirement, or they overestimate Microsoft Sentinel's out-of-the-box automation capabilities versus its actual SIEM-centric, custom-playbook nature.

How to eliminate wrong answers

Option B (Microsoft Defender for Endpoint) is wrong because it focuses solely on endpoint detection and response (EDR) for devices, lacking the cross-domain correlation and automated remediation for identities and email that the question specifies. Option C (Microsoft Sentinel) is wrong because it is a cloud-native SIEM (Security Information and Event Management) that ingests logs and requires custom analytics rules and playbooks for automation; it does not provide built-in, automatic cross-domain incident correlation and remediation across identities, endpoints, and email out of the box. Option D (Microsoft Entra ID Protection) is wrong because it is limited to identity-based risk detection and conditional access policies for user accounts, with no capability to monitor or remediate threats on endpoints or in email.

298
Multi-Selecthard

Which TWO of the following are capabilities of Microsoft Priva? (Choose two.)

Select 2 answers
A.Automate subject rights requests
B.Configure retention labels
C.Assess privacy risks in data transfers
D.Monitor network traffic
E.Detect malware in email attachments
AnswersA, C

Priva's Subject Rights Requests automates the entire DSR workflow—discovering personal data across Exchange, SharePoint, OneDrive, and Teams, verifying the requester's identity, applying suppression and redaction, and generating auditable completion reports. It uses AI to help classify and locate data, and its template library maps directly to GDPR and CCPA rights, reducing manual effort and legal risk.

Why this answer

Microsoft Priva includes Subject Rights Requests, which lets organizations automate the intake, tracking, and fulfillment of data subject requests (DSRs) under regulations like GDPR and CCPA, so option A is correct. Priva also provides Privacy Risk Management capabilities, including the ability to assess and remediate privacy risks in data transfers across tenants and regions, making option C correct. Option B is not a Priva capability; retention labels are configured through Microsoft Purview records management and data lifecycle management.

Option D is incorrect because network traffic monitoring is handled by tools such as Microsoft Defender for Cloud Apps or network security solutions, not Priva. Option E is incorrect because malware detection in email attachments is performed by Microsoft Defender for Office 365, not Priva.

Exam trap

MS-900 often tests the distinction between Priva and Purview capabilities, causing candidates to select retention labels, which are a Purview feature, not Priva.

299
MCQmedium

A company wants to securely share a large video file (2 GB) with an external partner without using email attachments. Which Microsoft 365 service should they use?

A.Microsoft SharePoint
B.Microsoft Teams
C.Microsoft Stream
D.Microsoft OneDrive
AnswerD

Microsoft OneDrive provides personal cloud storage with a dedicated 'Share' workflow that generates secure links for external recipients, including an option to set an expiry date and require a password. A 2GB file is well within OneDrive's file-size limit of 250GB, and the service supports both view and edit permissions without requiring external users to have a Microsoft account. This makes OneDrive the optimal choice for a single, secure, ad-hoc large-file transfer to an external partner.

Why this answer

Microsoft OneDrive is the correct choice because it allows sharing large files (up to 250 GB per file) via secure, expiring links with external users, without relying on email attachments. It integrates with Azure AD for access control and supports granular permissions like view or edit, making it ideal for ad-hoc external file sharing.

Exam trap

The trap here is that candidates often confuse Microsoft Stream as the service for sharing video files because of the word 'video,' but Stream is for hosting and streaming, not for secure file sharing with external partners, which requires a storage and sharing service like OneDrive.

How to eliminate wrong answers

Option A is wrong because Microsoft SharePoint is designed for team collaboration and document management within a site, not for ad-hoc sharing of a single large file with an external partner; it requires setting up a site and managing permissions, which is overkill for this scenario. Option B is wrong because Microsoft Teams is a chat-based collaboration platform that uses SharePoint or OneDrive for file storage; sharing a 2 GB file via Teams would still rely on underlying storage and is not optimized for direct external sharing without a Teams guest account. Option C is wrong because Microsoft Stream is a video hosting and management service for enterprise video content, not for sharing raw video files; it is designed for streaming and playback, not secure file download or external partner access.

300
MCQmedium

A team wants to build a custom business app to track inventory with minimal custom code. They need a cloud-based database that can store structured data and is tightly integrated with the low-code app platform. Which Microsoft 365 service should they use as the database?

A.Microsoft Dataverse
B.Microsoft SharePoint Online list
C.Microsoft Excel Online
D.Microsoft Forms
AnswerA

Microsoft Dataverse is the correct choice because it serves as the enterprise-grade data platform beneath the Power Platform, providing relational tables, rich metadata, security roles, and built-in business rules that are essential for a custom inventory-tracking app. It supports calculated columns, rollup fields, and relationships between products, warehouses, and stock transactions — capabilities that go beyond simple file storage. Dataverse integrates natively with Power Apps and Power Automate, enabling low-code app logic without requiring a custom database. Because it offers row-level security and auditing, it satisfies compliance and scalability needs for multi-user business applications.

Why this answer

Microsoft Dataverse is the correct choice because it is a cloud-based, scalable data service designed specifically for Power Platform and Microsoft 365 low-code app development. It stores structured data in tables with rich metadata, supports relationships, business logic, and security at the row/column level, and integrates natively with Power Apps, Power Automate, and Power BI. This tight integration enables building custom business apps with minimal code, exactly as required for inventory tracking.

Exam trap

MS-900 often tests the misconception that SharePoint lists or Excel are sufficient databases for low-code apps, but the exam expects candidates to recognize Dataverse as the dedicated, scalable database service for Power Platform.

How to eliminate wrong answers

Option B is wrong because SharePoint Online lists, while integrated with Power Apps, are not a true relational database and have limitations in data types, relationships, and scalability for complex inventory scenarios; they are better for simple lists and document management. Option C is wrong because Excel Online is a spreadsheet tool, not a database; it lacks relational integrity, concurrency controls, and robust security, and is not designed for building custom business apps with minimal code. Option D is wrong because Microsoft Forms is a data collection tool for surveys and quizzes, not a database; it cannot store structured relational data or serve as a backend for custom apps.

Page 3

Page 4 of 11

Page 5

All pages